Loading summary
A
A European MP's phone was infected by Pegasus spyware Android drops its PIN guessing limit from 1,800 attempts to 20 Alibaba bans employees from using Claude at work and there's a new vulnerability in the Linux kernel. This is the risky bulletin prepared by Catalyn Kim Panu and read by me, Claire aird. Today is the 6th of July and this podcast episode is brought to you by Sublime Security.
B
In today's top story, Pegasus spyware was used to compromise a device owned by a member of the European Parliament. Stelios Kuloghlu's phone was attacked while he was on the PEGA committee, which investigated spyware abuses in EU member states.
A
The attacks occurred in 2022 and 2023 while the committee was active and compiling reports. CitizenLab researchers discovered the infections but have not attributed the attacks.
B
The latest version of Android includes strict protections against PIN and password guessing attacks. Google has reduced the maximum number of device unlock attempts from 1,800 to 20.
A
Additionally, five attempts are allowed in the first minute before a timeout is enforced. Google applies longer timeouts after each failed attempt. The change was added to Android 17,
B
which was released last month. Chinese tech company Alibaba has reportedly banned employees from using Anthropic's Claude at work. Reports said Alibaba imposed the ban after researchers found code inside Claude identifying China based users. Anthropic said the code was added in March to identify unauthorised resellers and distillation attacks. The American company also accused Alibaba of using 25,000 accounts to to distil its Claude model. A new register designed to counter SMS scams has started operations in Australia. Businesses planning to send branded SMS messages to Australians will have to apply for listing on the SMS sender ID register. The register is shared with Australian telcos and used to verify bulk senders. Companies on the register will have their messages labelled as verified with when sent to Australian phones. American medical equipment maker Adapt Health has notified investors and the SEC of a security breach. An intruder accessed internal documents and patient data stored in a cloud platform. The hackers told the company about the breach on June 15. To date, no hacking or ransomware group has taken credit for the attack. A Ukrainian hacktivist group claims to have attacked one of Russia's largest construction companies. The Cyber Anarchy Squad said it wiped 3,000 servers and workstations as well as 700 virtual machines from Russian company Grandline. The intruders also said they deleted all backups and stole more than 650 terabytes of sensitive documents. The alleged breach occurred in May, but the group only recently disclosed its activity. The Kairos data extortion group appears to have abruptly shut down. The group, which started in November 2024, has been inactive and its websites offline close to a month. Despite its leak site showing a seizure banner from Ukraine intelligence agency, the country's officials never announced a takedown. Researchers have identified a Chinese influence operation targeting men in Taiwan. The campaign launched in May with 300 social media accounts claiming to be young women looking to date only Taiwanese men. NewsGuard says the cluster uses the same account naming pattern as a February campaign that also also targeted Taiwan. A local privilege escalation bug in the Linux kernel has been patched. The bug affected Linux servers, workstations and Android. The bad EPOL bug was a race condition in the Linux kernel EPOL IO subsystem security researcher Jae Yang Chung said while the race condition window was small, an exploit he created was 99% reliable. The GNU Linux package manager Gaix released critical security updates last week. The updates patch vulnerabilities that can be exploited via malicious packages or compromised substitute servers. The vulnerabilities can be used to gain root access or implant malicious binaries. Opera has patched a security flaw that attackers could use to compromise the GX gaming browser. The flaw would allow a malicious site to force install a browser modify without requiring user interaction or consent. Once installed, the mod could inject code into other sites and steal user credentials. Opera said the bug was reported through its bug bounty program and had not been abused in the wild. And finally, the U Blocks Origin ad blocker will allow blocking of websites known to show malicious click fix pop ups. Clickfix pop ups trick users into running malicious commands that install malware. These attacks have surged in popularity over the past year, and that is all for this podcast edition. Today's show was brought to you by our sponsor, Sublime Security. Find them at Sublime Security. Thanks to your company.
This episode of Risky Bulletin, presented by Claire Aird and prepared by Catalyn Kim Panu, delivers a rapidfire roundup of the latest cybersecurity headlines. The discussion centers on the recent Pegasus spyware infection of an EU official’s phone, new Android security protections, corporate AI bans, significant vulnerabilities, and notable cyber incidents worldwide.
[00:33]
Memorable Quote:
“Pegasus spyware was used to compromise a device owned by a member of the European Parliament.”
— Claire, [00:33]
[01:03]
Memorable Quote:
“Google has reduced the maximum number of device unlock attempts from 1,800 to 20.”
— Claire, [01:03]
[01:27]
[01:44]
[02:00]
[02:17]
[02:35]
[02:45]
[02:54]
[03:13]
[03:20]
[03:31]
This episode provides a succinct yet comprehensive snapshot of global cybersecurity news as of early July 2026, hitting each headline with clarity and detail for busy listeners and professionals alike.