ABC has some maps of what scam compounds have been built this year in Myanmar, despite a promised government crackdown "The scam industry in Myanmar is morphing and heading into the jungle, according to satellite imagery, victim testimony and local investigators." www.abc.net.au/news/2026-07...
Moonshot's Kimi K3 AI model performs significantly below the cyber capabilities of AI models released by US frontier labs Kimi guardrails also failed to stop users from developing exploits www.aisi.gov.uk/blog/prelimi...
-GitHub announces VIP bug bounty program -Github pays $100k for RCE bug -Oracle has its own bugpocalypse with 1,400 bugs -Check Point patches zero-day -Windmill bug enters active exploitation -New RefluXFS and HermeticReader vulnerability -Wansview cameras ship with 24yo vuln -New Meta CISO
-Clop targets PTC Windchill and FlexPLM servers -New AfterCall adware -New Dolphin X Stealer and msaRAT -OpSec leak exposes JadeProx operations -UAC-0099 distributes malicious Notepad++ plugins -DPRK job interviews adopt ClickFix -Lots of Kimsuky ops -Review of the Iran cyber war landscape
-70% of US cyber report rules are overlapping -US to impose visa restrictions on scammers -CISA 2015 extension passes House -Snapchat hacker sentenced to jail -Major fraudster detained in India -China extradites Silver Fox member from Vietnam -New XEntry Team group -TAG-195 gets new malware
-Stadler Rail held for ransom for $12m -Breaches at Origin Energy, UpBound, Chick-fil-A -Wanchain hacked for $10m -AFX Trade hacked for $24m -Verus hacked for $7.5m, second time this year -LG to suspend proxy apps from TVs -EU fines Google $1b -PyPI adds upload restriction -Firefox 153 is out
-Western cyber agencies warn of Russian hacks of Zimbra servers -US accuses Moonshot AI of distillation attacks -Iran is targeting more PLC vendors -Google adds selfie video login -Thailand's Ministry of Finance hacked with an AI agent P: risky.biz/RBNEWS591/ N: news.risky.biz/risky-bullet...
-JadePuffer ransomware updated to target LLMs -New Cruciferra crypter -More DPRK remote worker stuff and money trail -WP RCE enters active exploitation -New SharePoint exploitation -AI models like to cheat -Google releases Gemini 3.5 Flash Cyber -Cisco releases Antares cyber LLM -SteelCon '26 videos
-App Store down in Russia, likely banned -Canada signs new UN cybercrime convention -New White House EO covers software supply chains -NSO owner had diplomatic passport -New AgentBaiting campaign -PAN OS bug used to push Qilin ransomware -DevMan (Funky Mantis) profile
-Craneware healthcare billing software hack -Allbridge crypto-heist -DeepSeek shared chats leak online -Ttareungyi to compensate hack victims with free rides -Nextcloud dismisses hack rumors -Parental controls coming to Threads -LG monitors silently install adware
-Linux kernel discloses 442 CVEs as AI bugpocalypse settles in -OpenAI was behind the Hugging Face breach -France passes kids social media ban -Germany takes down Kratos PhaaS -Hackers breached South Korea's MFA for months N: news.risky.biz/risky-bullet... Pod: risky.biz/RBNEWS590/
More DPRK remote IT worker reports covering: -the money trail (www.dtex.ai/blog/dprk-it...) -new infrastructure (kudelskisecurity.com/research/dpr...)
-Hacker wipes Romania's entire land registry database -Graykey maker sues former employee for leaking exploit at rival company -Hugging Face was hacked using an autonomous AI agent -unauth RCE finally found in WordPress, expect mayhem P: risky.biz/podcasts/ N: news.risky.biz/risky-bullet...
-New Helix data extortion group -Crypto-wallet extensions can link you to your crypto-funds: -Cisco advance notification for patches next week -GhostLock Linux vulnerability -HalluSquatting attack -GhostApproval attack -GitLost attack -RoguePlanet gets a patch
-New malware: GodDamn ransomware, Forg365 PhaaS, GigaWiper, CrySome RAT, SCMBANKER, Remus Stealer, Apex2 and c2c/meow botnets -Vidar is still alive -RedHook returns -Two APTs target Balochistan Police -Microsoft expects increase in patches due to AI -Gitea and Joomla plugins exploited in the wild
-Police suspect Dutch national involved in Odido hack -5.8k scam suspect arrested -Iris C2's shady ownership -Injective SDK supply chain attack -Cybersecurity startup publishes infostealers to npm -GitHub API abuse wave -Hacked websites host OnlyFans content -New Password-spraying campaign hits M365
-India bans app used to hack e-rickshaws in viral videos -NSA TAO is back -Leak exposes another suspected Chinese cyber contractor -China considering blocking foreign access to its AI models -Accenture has another data breach Newsletter: news.risky.biz/risky-bullet... Podcast: risky.biz/RBNEWS588/
-More AI spotted in SpectrePaste malware delivery -Pink group registers passkeys on behalf of its victims -Most crypto-hacks this year target DeFi platforms -New RedWing Android MaaS -New Cavern Manticore APT -UAT-7810 builds ORBs for other APTs -UNK_MassTraction targets Roundcube servers
-Godot bans AI code slop -Tech platforms fail to deploy age restrictions in Australia -EU RT ban also applies to websites and persons -Spain arrests CARR and Z-Pentest member -15yo teen arrested for hacking anime site with ChatGPT -Profile on Lurking Lizard proxy operator and Scattered Spider
-UK Foreign Office impacted by Fortibleed -Prince Harry loses Daily Mail hacking lawsuit -Predator victims sue Intellexa -US Army defacements -BONK meme coin hacked for $20m -Ctrl Wallet shuts down after exploit -Ill Bloom bug exploited to steal $3.1m -Class-action accuses RAM makers of price fixing
-All new cars to include a camera aimed at the driver's face -Canada hacked a ransomware gang -Taiwan charges execs for helping Chinese hackers -Vuln can bork Hoymiles solar panels -DHSIG investigates forced CISA reassignments Podcast: risky.biz/RBNEWS587/ Newsletter: news.risky.biz/risky-bullet...
Hoymiles inverters used with those super-popular solar panels installed on balconies across Europe can be switched on or off, or even permanently disabled via a newly discovered vulnerability PDF: www.ccc.de/system/uploa...
-New CitrixBleed-like bug exploited in the wild within 24h -New SharePoint RCE enters exploitation phase -New AirDrop and Quick Share vulnerabilities -Spotify abused as C2 -EPM poisoning comes back -Loads of security updates
-New ChocoPoC, TONResolver RAT, and BeepRAT -The Gentlemen ransomware abuses a zero-day to disable EDRs -New ARToken phishing kit -Roska Bridge info-op active on Mastodon and BlueSky -Apple Hide My Email bug exposes email addresses -New InkJect attack -DuneSlide vulns
-EU schedules another Chat Control vote next week -India tells WhatsApp to pause username rollout -Opera rolls out paste ClickFix protection -FBI shuts down NetNut proxy and Popa botnet -LLM backends targeted by mass-recon campaign -Password spray attack targets M365 to bypass MFA
-40% of crypto heists linked to private keys incidents -Pi Mobile data breach -EU top court confirms Google mega-fine -Chrome 150 is out -US lifts Anthropic export controls -US tries to pressure South Korea over Coupang breach -Belgian police set up phishing squad -Spain quiet-bans Palantir
-FatFs bugs enable physical access attacks on a load of devices -Password spray attack targets M365 and bypasses MFA -AI agent caught deploying ransomware in live hacks -Webinar platform sues security firms over bad IOCs Newsletter: news.risky.biz/risky-bullet... Podcast: risky.biz/RBNEWS585/
A Russian influence operation uses the Brid[.]gy service to cross-post simultaneously on Bluesky and on Mastodon The campaign has been active since September last year checkfirst.network/roska-bridge...