Loading summary
A
The EU unveils its digital sovereignty plan, an American law firm pays a $20 million ransom, authorities take down millions of email and social media scam accounts, and a new DOSBug can crash service within seconds. This is the Risky Bulletin prepared by Catalyn Kimparnu and read by me, Claire aird. Today is the 5th of June and this podcast episode is brought to you by Truffle Security, the makers of Truffle Hog. The European Commission has unveiled its plan to decouple from American companies in the name of tech sovereignty. The plan would boost chip production, triple data centre capacity and fund the development of open source projects as alternatives to American software. The EU says it won't ban American companies from its market, but will help local alternatives to compete. In other news, the Chinese government has imposed travel restrictions on top AI talent Executives and top professionals at Chinese AI firms must get approval from officials ahead of any overseas travel. The measure is meant to prevent top talent from fleeing to other countries. Travel bans are often imposed on state officials in China, but almost never on the private sector. Anthropics says that threat actors are getting better at abusing its services for more sophisticated actions like lateral movement and data exfiltration. Previously, most threat actors just used Anthropic's AI to develop and obfuscate malware. The company observed the trend by looking at data from the 832 accounts it suspended for malicious activity in the year to March 2026. Two Russian telcos are lobbying the government to allow them to sell VPN services to Russian citizens. Beeline and T2 are creating VPN services that are compliant with Kremlin censorship guideline. The VPNs will be provided to Russian citizens and businesses who want to access services that are blocked by Western companies but permitted under Russia's censorship regime. The Russian government blocks VPN apps to prevent citizens from getting uncensored news about the war in Ukraine. Meantime, the Russian government has filed a lawsuit to designate two hacking groups as extremist organisations, the Belarusian hacktivist group Cyber Partisans and the pro Ukrainian group Silent Crow. Russia is seeking their designation over the group's attacks on Aeroflot, Ros Telecom and Cartography and Cadastra agency Ros resta. The designation would allow the government to prosecute individuals who support or help the groups. The case will be heard by Russia's Supreme Court on July 21. China's military intelligence agency is using LinkedIn and online jobs portals to recruit individuals with access to classified or privileged information. Intelligence agencies from the Five Eyes countries issued a joint warning on Wednesday about China's aggressive recruitment operation. The campaigns target former government officials, military personnel, academics, think tank employees and journalists, according to the advisory. Individuals were paid hundreds or thousands of dollars to disclose sensitive information. The U.S. treasury Department has sanctioned Iranian cryptocurrency exchange NOBATEX. Officials say the platform was used to evade Sanct and finance terrorist groups. It was also used by Iranian cyber operators, including several ransomware groups. Sanctions were also imposed on Wallix, Bitpin and Ramsonex, three smaller Iranian exchanges. Blockchain analysis firm Elliptic says the four had sent or received at least $40 billion in crypto assets over their lifetime. New DHS Secretary Mark Wayne Mullen intends to hire 600 more employees into CISA, the agency currently 2,200 staff, down from its peak of 3,400 staff during the Biden administration. Mullen told Congress he plans to continue offloading some of SISA's work to local and state municipalities. A major American law firm has paid hackers an estimated $20 million to prevent the release of stolen data, while Gottschal and Manji says customer data was stolen from an external cloud storage site this year, but by a group known as the Silent Ransom Group. The FBI sent out a private industry alert last year warning that the group was specifically targeting US law firms in extortion campaigns, while Gottschal and Manges reported revenue of more than $2 billion last year. Hackers have stolen user data from wearables company Ultra Human in a hack in March. The company says no passwords or financial data was compromised. It notified affected users this week. Ultrahuman sells smart rings and metabolic health tracking devices. Hackers have allegedly launched DDoS attacks against a new Indian student platform hours after its launch on Tuesday. The attack hit cbse, an online portal that allows students to request a re evaluation of certain exams. Several students also reported breaking into the platform using basic vulnerabilities. Hackers compromised the update infrastructure of the Hola browser to bundle a crypto miner with browser updates. Security firm Sophos discovered the hack during a third party certification procedure. The Hola browser team said the malicious Update only reached 0.1% of its users. A judge has ruled that Belgian banks must reimburse phishing victims as soon as a loss is reported. The judge ruled in favour of an elderly couple who lost a €50,000 to a hacker posing as a bank employee in Portugal. The ruling is expected to have broad consequences to the entire banking industry in the country. Belgian banks have historically refused to reimburse phishing victims or only did so after long waits or lawsuits, tech companies and law enforcement agencies have suspended millions of email and social media accounts that were being used by scam operations. More than $3.8 million in crypto was also seized as part of the coordinated crackdown this week. The so called scam disruption week involved the U.S. justice Department, Thai police and companies like Meta, Microsoft, Coinbase and Starlink. The crackdown was enacted following a White House executive order passed in March that instructed the DoJ to prioritise the fight against scams and cybercrime. Europol has detained 29 suspects for running illegal streaming services. The services ran on 169 domains and broadcast sporting events, film and television channels. Officials also went after the wider criminal ecosystem supporting these services. European authorities had dismantled an online portal that sold fake identity documents. The fake document factory operated out of an apartment in the city of Alicante, Spain. Most of the fake documents were ordered by criminal groups running migrant smuggling operations. The site's administrator was detained in a raid. At the end of May, the Nova Ransomware group posted a public apology to a victim after discovering it was a company located in Uzbekistan, a former Soviet republic and Russian ally. The group apologised to the Ariel Group, a company operating out of Uzbekistan and Moscow. Nova promised not to leak its data as long as the company doesn't file a report with authorities. A new Chinese E crime group is adopting the same social engineering tactics as groups like Lapsus and Shiny hunters. The new TA4922 group primarily targets East Asian countries, but has also expanded this year to Europe and South Africa. In addition to using social engineering, the group has rotated through a plethora of malware payloads and hasn't yet settled on a fixed tool set. A hacking group is targeting Russian soldiers deployed in and near Ukraine. The hackers have used military and dating related themes to Phish soldiers on Telegram. The goal is to deploy malware on their devices and collect their local information. Russian security firm F6 tracks the new group under the codename of Siribclone. Any denial of service bug can crash most of today's web service within seconds. The HTTP 2 bomb attack impacts nginx, the Apache HTTP server, Microsoft IIS Envoy and Cloudflare's Pingora. The attack targets the HPAC compression scheme of the HTP HTTP 2 protocol to exhaust tens of gigabytes of server memory. HTTP 2 bomb attacks can be carried out using a single machine over a normal Internet connection. All servers are vulnerable in their default configurations if HTTP 2 support is enabled, only Nginx and Apache have released patches. The Envoy project accused the researchers of ignoring responsible disclosure and not giving them enough time to patch. Microsoft has released security updates for its Microsoft 365 Android apps to remove a development flag that was accidentally left enabled in the code. The flag could have allowed any other app on the same smartphone to steal a user's Microsoft token and hijack their account. A vulnerability in the Comodo Internet Security firewall can be used to crash Windows systems with a single packet. The bug is caused by an IP parsing issue in the firewall's Windows driver. The vulnerability remains unpatched after the vendor has failed to respond to security researcher Marcus Hutchins. A new worm is spreading on the npm JavaScript ecosystem. Einworm is inspired by the Shai Hulud worm, but is written in Rust just like the original. It infects a developer machine, steals credentials, and then spreads to that developer's open source coding projects. So far, Ironworm has been spotted in 37 packages. More than 116,000 users have been infected with a new infostealer named Weedhack. Most of the infections have been traced to a campaign targeting Minecraft players, according to security firm McAfee. The malware is a commercial infostealer sold online for $5 a month. Russian cybersecurity company Kaspersky claims it's developing a smartphone. The device will run an OS developed by the company with no Android components. The company's founder, Eugene Kaspersky, showcased a prototype of the device this week at the St. Petersburg International Economic Forum. And finally, Microsoft has announced Scout, an always on enterprise AI agent built on top of OpenClaw. The agent is already integrated in Microsoft 365 apps. The launch comes weeks after the company's own executives admitted almost no one was using its previous Copilot AI on Windows Windows. And that is all for this podcast edition. Today's show was brought to you by our sponsor, Truffle Security. Find them at trufflesecurity.com thanks to your company.
Date: June 5, 2026
Host: Claire Aird (Risky Business Media)
Prepared by: Catalyn Kimparnu
This episode covers major cybersecurity and tech policy developments including the EU's bold push for digital sovereignty, global ransomware and hacking incidents, regulatory changes, and the latest vulnerability discoveries. News items span across the EU, U.S., Russia, China, and beyond, giving listeners a fast-paced, up-to-the-minute snapshot of risk, policy shifts, and high-profile cyberattacks impacting the digital ecosystem.
[00:04 - 01:00]
[01:00 - 01:30]
[01:30 - 02:00]
[02:00 - 03:00]
[03:00 - 03:30]
[03:30 - 04:00]
[04:00 - 04:20]
[04:20 - 04:50]
[04:50 - 05:20]
[05:20 - 05:40]
[05:40 - 06:00]
[06:00 - 06:20]
[06:20 - 06:40]
[06:40 - 07:00]
[07:00 - 08:00]
[08:00 - End]
On EU Digital Sovereignty:
On Law Firm Ransomware:
On Nova Ransomware’s Apology:
On HTTP/2 Bomb Attack:
This episode provides a concise roundup of the latest and most significant stories in global cybersecurity, from major policy shifts in Europe and ground-breaking court decisions, to newly uncovered vulnerabilities and the ongoing evolution of cybercriminal tactics.