Loading summary
A
Russia's FSB calls out a Western spyware operation High profile Instagram accounts hijacked via Meta's AI support agents. Red Hat NPM packages were compromised in another supply chain attack and 10% of domains registered last year were malicious. This is the risky bulletin prepared by Katalyn Kimpanu and read by me, Claire Claire aird today is the 3rd of June and this podcast episode is brought to you by Truffle Security, the makers of Truffle Hog. In today's top story, Russia's FSB intelligence service says it's discovered foreign spyware on senior government officials phones. Retired FSB officials hinted at US and UK involvement when speaking to local media. The FSB has described it as one of the biggest such operations to ever target Russia. In other news, the Trump administration has signed an executive order that puts security and safety requirements on AI models. It's a scaled back version of the EO that Donald Trump was due to sign last month. The EO asks larger AI companies to voluntarily submit new models for government testing for up to 30 days before they're released publicly. The earlier EO called for 90 days of testing. AI company Anthropic has expanded access to its Mythos model. In April, 50 organisations were permitted to test the model. Around 150 more from 15 countries were granted access this week. One of the first to be identified was Anisa, the EU's cybersecurity agency. Hackers are hijacking high profile Instagram accounts by abusing Meta's AI Support Assistant, a pro Iranian hacktivist group took credit for some of the takeovers in a telegram post. The exploit involved asking Meta's AI assistant to change the account's email address. The attacker needed a VPN with an IP address close to the target's normal location. No other verification was needed. Victims include the accounts of metal band Korn, Space Force officials and even Barack Obama's White House account. Hackers appear to have stolen customer data from at least 100 Dutch hotels. The stolen information has been used to conduct fraud and phishing campaigns in recent weeks. Dutch hospitality experts are still investigating the breach. They believe a shared hotel software provider could be the source of the stolen data. Some hotels in Belgium and Ireland have also reported attacks against their customers. Around 20 dashlane password manager users had their encrypted password vaults stolen in a brute force attack that also caused other users to be locked out of their accounts. The lockouts were the result of Dashlane's security systems responding to and stopping the attack. Access to those accounts has been restored. Hackers stole the personal information of 600,000 Palestinians who registered for assistance through the UN World Food Program. The breach occurred on May 14, and the UN agency notified affected individuals last week. The agency said the hacked portal was only used in Palestine. Hackers have leaked data from the GTA 5 Cheating Service Menu Atlas. The details of 64,000 users of the cheat provider were posted on GitHub last month. The leaked data included usernames, emails and IP addresses. Microsoft says it won't pursue legal action against bug bounty hunters, but it will report them to law enforcement if they break the law. The company's clarification comes after it threatens security researchers with criminal prosecution in a blog post last week. Meanwhile, another security researcher dropped a zero day in Microsoft products without prior disclosure. On Monday, Emma askar published a one click exploit that can steal GitHub tokens via the Visual Studio code editor. Askar said previous bug reports were dismissed and fixed without any reward or Credit. More than 30 Red Hat Cloud related NPM packages were compromised in a supply chain attack on Monday. The malicious packages shipped with malware that stole CI CD secrets and cloud access tokens. They also included a worm component that would spread itself itself to Victims packages. One in 10 new domains registered last year were involved in malicious activity. Of the 85 million top level domain names registered in 2025, 8.5 million were added to at least one cybersecurity blocklist. Five registrars accounted for half the blocklisted domains. Spanish police have arrested an individual who published government workers personal data. The suspect is accused of doxxing employees of the country's police, national Cyber Security Agency, prosecutors and other government employees. Published details included names, phone numbers, home addresses and emails. They were arrested on Saturday. In the province of Granada, Hungarian police have arrested a Jordanian national accused of stealing Johnny Depp's credit card information. The suspect made more than 300 transactions with the card totalling nearly $700,000. A US bank notified authorities of the suspicious transactions last Two New Jersey men have been charged in the US over their involvement in a major BEC incident. Jason McNeill and Ryan Talisford are accused of laundering proceeds from a $7.7 million property transaction that was hijacked by hackers. The incident occurred in December. The Cryptomas cryptocurrency exchange has rebranded after receiving a record fine from the Canadian government. The platform now uses the name Heliket. Last year the company was fined $177 million by the Canadian government for failing to comply with anti money laundering regulations. A Brian Krebs investigation reported that Kryptomis acted as a payment processor for dozens of Russian cryptocurrency exchanges and cybercrime websites. An Iranian Haktivist group is recruiting individuals in the US And Israel to conduct physical attacks, espionage, sabotage and assassinations. According to Recorded Future, the Handala Group is behind four online Personas recruiting people for the tasks. The group has offered rewards of up to $500,000 for attacks on selected individuals. Previous reporting has linked the Handala group to Iran's MOIS intelligence agency. Iran is using Western AI to help with phishing campaigns, malware development and military research. Iranian cyber units have used AI to scan the Internet for vulnerabilities and disinformation campaigns. Iran is also building its own models. Work on domestic models began in March at the Sharif University of Technology. According to analysts, AI has helped Iran turbocharge its cyber operations since the beginning of the U. S Israeli war. The recent takedown of a bulletproof hosting provider in the Netherlands has disrupted the operations of at least three Iranian APTs. Last month, Dutch authorities seized Worktitan's servers for hosting server infrastructure for Russian hackers and disinformation operations. Groups including Agrius, Muddy Water and Nimbus Manticore had used servers rented from work titans. Google has patched a zero day vulnerability in Android Traktors CVE 2020 548595. The zero day can let attackers elevate privileges on a compromised device. Google said. The bug was spotted in limited targeted attacks. It was one of 124 Android bugs patched this month. Hackers are exploiting a major vulnerability in the Windows Netlogon authentication service. The vulnerability allows attackers to run malicious code on Windows domain controllers. The bug was patched in Microsoft's May security update. The first attacks were reported last week by Belgium's cybersecurity agency. Security firm Fortinet has reported a spike in attacks targeting Citrix, netscaler and gateway appliances. The attacks are targeting a bug that can leak the device's memory. The bug came under active exploitation days after it was patched back in March, a US Government audit has found. NIST is responsible for the NVD database vulnerability backlog. The Department of Commerce Inspector general says NIST lacked strategic planning and decisive action when dealing with an increasing number of unprocessed vulnerabilities submitted to NVD systems. The Office estimated that an investment of just $800,000 would have resolved the backlog. The audit was ordered in May of last year. Since then, NIST has given up on the NVD backlog and plans to only enrich a small number of important bugs. The European Parliament will switch to Quant as the default search Engine on all EU government devices. Quant will replace Google Search on Thursday 4 June. Officials cited privacy concerns over how Google handles search data as the reason for the switch. Cybersecurity company Mitre has transferred ownership of the Caldera platform to the Apache Software Foundation. Mitre developed and open sourced the platform in the 2010s to allow cybersecurity teams to emulate adversaries, run Red Team exercises and automate incident response. And finally, the Rust programming language will ban contributors from submitting AI generated code. Rust developers will be allowed to use AI for assistance assistance, but not to write the actual code. The move comes after the Zig programming language and several Linux distros also banned the use of AI to submit code contributions. And that is all for this podcast edition. Today's show was brought to you by our sponsor, Truffle Security. Find them at trufflesecurity.com thanks for your company, Sam.
Risky Business Media
Episode Date: June 3, 2026
Prepared by: Catalin Cimpanu | Read by: Claire
This episode of Risky Bulletin delivers a rapid, info-rich roundup of the week’s most consequential cybersecurity news. Key topics include the FSB’s allegations of a large-scale Western spyware operation targeting Russian officials, AI-driven social engineering, supply chain threats, significant data breaches, legislative shifts in AI regulation, the intersection of AI and state-sponsored cyber-operations, and ongoing vulnerability exploitations. The tone is brisk and authoritative, aimed at cybersecurity professionals and informed listeners.
This episode delivers an efficient, intelligence-focused summary of recent, high-impact cybersecurity developments, offering professionals actionable awareness of evolving threats, regulatory changes, and technology shifts.