Loading summary
A
Dutch police take down a botnet of 17 million devices US military staff have been tracked with AdTech location data. A Google engineer is arrested for insider trading on polymarket and gogs and the Casdor IAM leave major bugs unpatched. This is the Risky Bulletin prepared by Catalyn Kimparnu and read by me, Claire Clare aired today is the 29th of May and this podcast episode is brought to you by Sondera. In today's top story, Dutch authorities have taken down a botnet that infected more than 17 million devices globally. The country's national cybersecurity agency and local police seized more than 200 command and control service in the operation. The botnet was made up of computers, tablets and smartphones and and was linked to spam, phishing and DDoS attacks. Authorities didn't name the botnet, but local media claimed it was also the backbone of the ASOCS residential proxy service. The botnet is one of the largest ever disrupted by law enforcement. In other news, American military officials say Iran used commercially available location data to target American troops. The data is believed to have been used to direct strikes against US bases in the Middle East. US lawmakers are seeking further details from the Pentagon. CISA has told federal agencies to check whether their systems have been compromised through recent supply chain attacks. Agencies have been advised to look for malicious artefacts related to the Demon Tools, Tanstack and NX console incidents. Apple and Google are pushing for an amendment to Canada's new surveillance bill. The proposed C22 bill would allow Canadian authorities to force foreign tech companies to help investigate security threats. Apple and Google's amendment adds judicial oversight and and includes explicit language to protect encryption. IBM has announced it will spend $5 billion to help find and fix vulnerabilities in open source software packages. The company will deploy more than 20,000 engineers and AI tools as part of the new project, which is named Lightwell. The initial focus will be the Maven and Java ecosystem. It'll then expand to PyPi, npm and go. US authorities have arrested a Google software engineer for using internal company data to win bets on polymarket. Michele Spenuolo, an Italian national, was arrested on Wednesday in New York. He allegedly made $1.2 million of winning bets on Google's most popular search terms. A Canadian man has been sentenced to 33 years in a U.S. prison for conducting a sextortion campaign. Ramanan Pathmanitan's campaign targeted more than 100 throughout the U.S. it began in 2014 and continued until he was caught in 2021 he coerced children into performing sexually explicit acts and threatened to share recorded footage if they did not continue. He targeted boys and girls. Some were as young as 6. His US sentence will begin once he completes a 12 year prison term in Canada for the same crimes. I think I speak for the entire Risky Business team when I say we hope every every day he spends there is just miserable. A US man has been sentenced to 10 years and one month in prison for selling the personal information of elderly Americans. Troy Murray sold data on millions of Americans to scammers in Jamaica, who then targeted them in lottery fraud scams. Murray made over $5.2 million from the sales. A Romanian national has been sentenced to four years and eight months in prison for selling access to American networks. Catalan Dragomir made at $250,000 as initial access broker before he was arrested in 2024 and extradited to America. His victims included an Oregon state government office. An Albanian man has been extradited from Greece to face hacking related charges in France. The 39 year old used the online handle Venom. He's accused of developing and selling the Venom rat malware. He was detained last November during Europol's Operation Endgame. A commercial UK immigration website is leaking the personal data of visa applicants. According to TechCrunch, more than 100,000 documents containing selfies and passport scans are leaking from the UK visa portal. The site is not an official government portal. It has not yet fixed the leak. Hackers have stolen $15 million worth of crypto tokens from the Super Fortune Web3 app. The funds were taken from a central wallet designed to store unclaimed user airdrops. Superfortune is still invest investigating how the tokens were hijacked. Spain's data protection agency has fined travel software company Amadeus 18 million euros for GDPR violations. The AEPD says the Spanish IT company collected and stored too much user data and failed to notify users about how the data was used. The fine was discounted to 14.4 million euros after the company agreed to pay it in advance. UK citizens lost more than 102 million pounds to romance scams last year. Britons lose almost 280,000 pounds each day. Reported individual losses were as high as 1 million pounds last year. Most of the victims were located around London. A malicious app bundled with Superbox Android streaming devices is turning them into residential proxy nodes. The CyberFlix TVapp enrolls user systems into a residential proxy service called Poppanet. The proxy enrolment is not disclosed by the app and is likely used to route malicious traffic. The devices are sold at major US retailers. Security firm Profero says Iranian state sponsored hackers are behind the fake hacktivist group the Cyber Isnad Front. The group, also known as Cyber Support Front, uses the GRAT wiper in data wiping attacks against Israeli companies. Profero says the group is operated by the Iranian cyber contractor Arya Separ. Ayanda Sarzin, a suspected Russian E crime group, is targeting Ukrainian organisations in what appears to be an intelligence gathering operation. The campaign has been going on since last August. According to With Secure, the group uses AI tools to develop some of its malware and has made several OPSEC mistakes and the company tracks the group as Greyvibe. Malicious code hidden in source code repositories can trick AI coding agents into overwriting their own configuration files and performing malicious actions. The so called simjack technique was successfully tested against six AI coding agents including Claud, Code Gemini, cli, GitHub, Copilot Cli and OpenAI Codec cli. Only Anthropic has released patches or hardened its agents against the attack software so far. A recently disclosed vulnerability allows threat actors to Hijack self hosted GOG's Git servers. The bug is unpatched and GOG's developers have stopped responding to security researchers. The vulnerability allows attackers to run malicious code on gogs instances and take over the servers. A valid account is needed to run the exploit, but gogs ships with open registration enabled by default. A collection of nine vulnerabilities allows attackers to bypass authentication and take over cazdor identity and access management platforms. The issues impact the platform's SAML processing, account binding and token exchange systems. The bugs remain unpatched after researchers could not contact CASDL maintainers. And finally, Microsoft is improving memory safety features for its C programming language. The company is changing how C handles Unsafe, a class that runs code outside the main. NET runtime and its security guardrails. The new features were inspired by Rust and was shipped with C16 and that is all for this podcast edition. Today's show was brought to you by our sponsor Sondera. Find them@sondera AI. Thanks for your company.
Podcast: Risky Bulletin (Risky Business Media)
Episode Date: May 29, 2026
Host/Reader: Claire Clare
Prepared by: Catalyn Kimparnu
This episode delivers a rapid-fire overview of major cybersecurity news stories for late May 2026. The lead story is the Dutch authorities’ disruption of a massive botnet comprising 17 million devices. Other major topics include the use of commercial AdTech data to target U.S. military personnel, big tech’s response to Canadian surveillance law reforms, IBM’s $5B vulnerability project, high-profile cybercrime convictions, notable vulnerabilities in open-source software, and emerging threats in the AI and streaming device sectors.
Sexual Exploitation & Sextortion
Elder Scams Data Broker
Network Access Broker
Malware Developer Extradition
UK Visa Applicant Data Leak
Web3 Crypto Theft
UK Romance Scam Losses
Malware in Streaming Devices
Iranian State Hackers & Wiper Attacks
Russian E-Crime & Opsec Mistakes
Simjack Attacks on AI Agents
Gogs Git Server RCE Bug
Cazdor IAM Bugs
On the scale of the Dutch botnet takedown:
"The botnet is one of the largest ever disrupted by law enforcement."
— Claire Clare [00:36]
On sextortion sentencing:
"I think I speak for the entire Risky Business team when I say we hope every day he spends there is just miserable."
— Claire Clare [04:09]
The reporting is brisk, factual, and at times dryly pointed—especially when commenting on egregious criminal activity. The language is direct and technical, with occasional editorial side notes expressing moral clarity.
This concise yet comprehensive rundown equips listeners (and readers) with a fast pulse on the week’s most significant security developments and their broader implications.