Loading summary
Claire Aird
Law enforcement agencies take down A V Check 4 US senators urge for the reinstatement of the Cyber Safety Review Board Germany identifies the leader of the Trickbot gang and an AI Vibe coding platform leaks user data and API keys. This is the risky bulletin prepared by Catalyn Kimpanu and read by me, Claire aird. Today is the 2nd of June and this podcast episode is brought to you by Acid Inventory and network visibility company run zero law enforcement agencies have seized the cybercrime service AVcheck. The service was active for more than a decade. It was used to test malware against a range of antivirus software before deploying it in real attacks. The seizure was part of multinational Operation Endgame. Law enforcement agencies from Finland, the Netherlands and the US Also seized a malware obfuscation service managed by the same team. No charges have been announced. In other news, four Democrat senators have urged for the Cyber Safety Review Board to be reinstated. The board was established in 2022. It investigated serious cybersecurity breaches and made recommendations to government agencies and the private sector. It was disbanded after President Donald Trump took office in January. In a letter to Homeland Security Secretary Kristi Noem, the senators requested that DHS and CISA work together immediately to reinstate the board. The White House chief of staff's phone contacts have been breached and attackers have used deepfakes to impersonate her. The unknown attackers posed as Susie Wiles and contacted Republican lawmakers. A White House official said the attackers hacked her phone contacts, but it's unclear if they breached her phone or an online account. Federal investigators told the Wall Street Journal they do not believe a foreign nation was involved. The EU will launch a New Age verification app in July. It will confirm users ages without disclosing personal details to tech platforms. The announcement comes as several member states are pushing to implement an EU wide age limit for social media. Israel's intelligence agency says it's thwarted 85 Iranian cyber operations designed to gather intelligence for assassinations. The Shin Bet agency says the cyber attacks sought to gather data on senior Israeli security officials, politicians, journalists and academics. The targets were invited to a Google Meet in which Iranian agents attempted to obtain their home addresses and details of their routines. That information would then be handed to operatives on the ground in Israel. German authorities have identified the leader of the Trikbot cybercrime gang as 36 year old Russian Vitaly Nikolaevich Kovalyov. He used the pseudonyms Bentley and Stern in the gang. Kovalyov was charged and sanctioned by the US in 2023 for his role in the group but wasn't identified as its main administrator. The trickbot botne was first taken down in 2020 and again in 2024. The developers of the Llama Stealer malware say they're making significant efforts to restore servers. The malware has been down since law enforcement seized the majority of its infrastructure in late May. Checkpoint researchers say the operation has suffered damage to its reputation. South Korean Internet cafe computers have been infected with cryptocurrency miners. Hackers are using the cafe's management platform to spread the T Rex crypto miner. It's unclear how the attackers the necessary access security firm ARM Lab said the threat actor behind the attacks has been active for three years. The BitMEX cryptocurrency exchange says it stopped an intrusion attempt by North Korean hacking group Lazarus. BitMEX's security team gained access to one of the group's servers and traced an operator back to the Chinese city of Jiaxing. The company spotted the attempt when a Lazarus operator tried to lure one of its developers into running a malicious GitHub project. ChatGPT has been observed reproducing Russian propaganda from the pro Kremlin network Pravda. The group has been posting large quantities of English language fake news on Russian social media network vk. From there, it's ingested by AI training systems. Last week, researchers warned that Pravda was laying the groundwork for having its propaganda indexed by AI assistance. A vulnerability in AI based Vicod platform Lovable is leaking sensitive customer information. Attackers can craft requests that expose the content of some customer databases, such as user data and API keys. Engineers from two separate companies independently found the issue and retrieved data from apps developed with Lovable. Details about the bug were published last week after the company failed to patch the issue for more than two months. Hackers are exploiting two recently disclosed vulnerabilities to take over V bulletin forums. The bugs were patched in April last year, but attacks began last week after security researcher Egidio Romano published proof of concept code. The Linux kernel has added support for a new mechanism to securely store cryptographic keys. The hardware wrapped inline encryption keys feature stores keys in a secure enclave and prevents them from appearing in system memory in the clear. The feature was initially developed for Android to block cold boot attacks. It's now shipped with the Linux kernel 6.16 and finally, Google will no longer trust certificates issued by Chinese telco Tsunghua Telecom and Hungarian firm Netlock. The root certificates will be removed from Chrome and Chrome OS in version 139 at the end of July, Google said it's lost confidence in the two companies. And that is all for this podcast edition. Today's show was brought to you by our sponsor, Runzero. Find them@runzero.com Thanksg Company.
Podcast Information
Hosts:
Timestamp: [00:04]
The episode opens with significant news about the takedown of AVCheck, a notorious cybercrime service that had been operational for over a decade. AVCheck specialized in testing malware against various antivirus software, allowing cybercriminals to refine their malicious code before launching attacks.
Key Points:
Notable Quote:
"The seizure was part of multinational Operation Endgame," Claire Aird explains, highlighting the collaborative international effort behind the operation. [00:04]
Timestamp: [00:04]
In a move to bolster national cybersecurity oversight, four Democratic senators have formally requested the reinstatement of the Cyber Safety Review Board.
Key Points:
Notable Quote:
"The board was established to investigate serious cybersecurity breaches and make crucial recommendations," Claire Aird notes, emphasizing the board's vital role. [00:04]
Timestamp: [00:04]
A concerning security breach has targeted the phone contacts of the White House Chief of Staff, leading to attackers utilizing deepfakes to impersonate her.
Key Points:
Notable Quote:
"Attackers have used deepfakes to impersonate her," Claire Aird reports, underscoring the sophistication of the breach. [00:04]
Timestamp: [00:04]
The European Union is set to introduce a New Age Verification App in July, aiming to balance user privacy with age verification needs.
Key Points:
Notable Quote:
"The EU will launch a new age verification app to confirm users' ages without disclosing personal details," Claire Aird explains. [00:04]
Timestamp: [00:04]
Israel's intelligence agency, Shin Bet, has successfully foiled 85 Iranian cyber operations aimed at gathering intelligence for potential assassinations.
Key Points:
Notable Quote:
"The Shin Bet agency says the cyber attacks sought to gather data on senior Israeli officials," Claire Aird summarizes. [00:04]
Timestamp: [00:04]
German authorities have pinpointed the leader of the infamous Trickbot gang—Vitaly Nikolaevich Kovalyov, a 36-year-old Russian national.
Key Points:
Notable Quote:
"German authorities have identified the leader of the Trickbot cybercrime gang as Vitaly Nikolaevich Kovalyov," Claire Aird states, revealing the breakthrough in the investigation. [00:04]
Timestamp: [00:04]
Developers behind the Llama Stealer malware are reportedly striving to restore their servers after a significant portion of their infrastructure was seized by law enforcement in late May.
Key Points:
Notable Quote:
"The developers of the Llama Stealer malware say they're making significant efforts to restore servers," Claire Aird notes, highlighting the malware's resilience. [00:04]
Timestamp: [00:04]
South Korean internet cafes have fallen victim to cryptocurrency miner infections, with hackers leveraging the cafes' management platforms to deploy the T Rex crypto miner.
Key Points:
Notable Quote:
"Hackers are using the cafe's management platform to spread the T Rex crypto miner," Claire Aird explains, shedding light on the attack mechanism. [00:04]
Timestamp: [00:04]
The BitMEX cryptocurrency exchange successfully repelled an intrusion attempt by the notorious North Korean hacking group, Lazarus.
Key Points:
Notable Quote:
"BitMEX's security team gained access to one of the group's servers," Claire Aird reveals, emphasizing the proactive defense measures taken. [00:04]
Timestamp: [00:04]
Recent observations indicate that ChatGPT has been inadvertently reproducing Russian propaganda disseminated by the pro-Kremlin network, Pravda.
Key Points:
Notable Quote:
"ChatGPT has been observed reproducing Russian propaganda from the pro-Kremlin network Pravda," Claire Aird notes, highlighting the unintended consequences of AI training data. [00:04]
Timestamp: [00:04]
A critical vulnerability in the AI-based Vicod platform Lovable has been discovered, allowing attackers to access sensitive customer information, including user data and API keys.
Key Points:
Notable Quote:
"Attackers can craft requests that expose the content of some customer databases," Claire Aird explains, underscoring the severity of the vulnerability. [00:04]
Timestamp: [00:04]
Hackers are actively exploiting two recently disclosed vulnerabilities to commandeer V Bulletin forums.
Key Points:
Notable Quote:
"Hackers are exploiting two recently disclosed vulnerabilities to take over V Bulletin forums," Claire Aird reports, highlighting the ongoing security challenges despite previous patches. [00:04]
Timestamp: [00:04]
The Linux kernel has introduced support for a new mechanism aimed at securely storing cryptographic keys, enhancing system security.
Key Points:
Notable Quote:
"The Linux kernel has added support for a new mechanism to securely store cryptographic keys," Claire Aird details the technical advancement. [00:04]
Timestamp: [00:04]
In a significant security move, Google has declared that it will no longer trust certificates issued by Tsunghua Telecom (a Chinese telco) and Netlock (a Hungarian firm).
Key Points:
Notable Quote:
"Google will no longer trust certificates issued by Chinese telco Tsunghua Telecom and Hungarian firm Netlock," Claire Aird announces, highlighting the trust breach. [00:04]
This episode of Risky Bulletin, prepared by Catalyn Kimpanu and narrated by Claire Aird, delivers a comprehensive overview of the latest developments in the cybersecurity landscape as of June 2, 2025. From significant law enforcement actions against cybercrime operations like AVCheck and Trickbot to legislative efforts to reinstate crucial cybersecurity oversight bodies, the bulletin underscores the multifaceted efforts to combat evolving cyber threats. Additionally, technological advancements and vulnerabilities in AI platforms and cryptographic systems are addressed, reflecting the ongoing challenges in maintaining digital security.