Transcript
Claire Aird (0:04)
Law enforcement agencies take down A V Check 4 US senators urge for the reinstatement of the Cyber Safety Review Board Germany identifies the leader of the Trickbot gang and an AI Vibe coding platform leaks user data and API keys. This is the risky bulletin prepared by Catalyn Kimpanu and read by me, Claire aird. Today is the 2nd of June and this podcast episode is brought to you by Acid Inventory and network visibility company run zero law enforcement agencies have seized the cybercrime service AVcheck. The service was active for more than a decade. It was used to test malware against a range of antivirus software before deploying it in real attacks. The seizure was part of multinational Operation Endgame. Law enforcement agencies from Finland, the Netherlands and the US Also seized a malware obfuscation service managed by the same team. No charges have been announced. In other news, four Democrat senators have urged for the Cyber Safety Review Board to be reinstated. The board was established in 2022. It investigated serious cybersecurity breaches and made recommendations to government agencies and the private sector. It was disbanded after President Donald Trump took office in January. In a letter to Homeland Security Secretary Kristi Noem, the senators requested that DHS and CISA work together immediately to reinstate the board. The White House chief of staff's phone contacts have been breached and attackers have used deepfakes to impersonate her. The unknown attackers posed as Susie Wiles and contacted Republican lawmakers. A White House official said the attackers hacked her phone contacts, but it's unclear if they breached her phone or an online account. Federal investigators told the Wall Street Journal they do not believe a foreign nation was involved. The EU will launch a New Age verification app in July. It will confirm users ages without disclosing personal details to tech platforms. The announcement comes as several member states are pushing to implement an EU wide age limit for social media. Israel's intelligence agency says it's thwarted 85 Iranian cyber operations designed to gather intelligence for assassinations. The Shin Bet agency says the cyber attacks sought to gather data on senior Israeli security officials, politicians, journalists and academics. The targets were invited to a Google Meet in which Iranian agents attempted to obtain their home addresses and details of their routines. That information would then be handed to operatives on the ground in Israel. German authorities have identified the leader of the Trikbot cybercrime gang as 36 year old Russian Vitaly Nikolaevich Kovalyov. He used the pseudonyms Bentley and Stern in the gang. Kovalyov was charged and sanctioned by the US in 2023 for his role in the group but wasn't identified as its main administrator. The trickbot botne was first taken down in 2020 and again in 2024. The developers of the Llama Stealer malware say they're making significant efforts to restore servers. The malware has been down since law enforcement seized the majority of its infrastructure in late May. Checkpoint researchers say the operation has suffered damage to its reputation. South Korean Internet cafe computers have been infected with cryptocurrency miners. Hackers are using the cafe's management platform to spread the T Rex crypto miner. It's unclear how the attackers the necessary access security firm ARM Lab said the threat actor behind the attacks has been active for three years. The BitMEX cryptocurrency exchange says it stopped an intrusion attempt by North Korean hacking group Lazarus. BitMEX's security team gained access to one of the group's servers and traced an operator back to the Chinese city of Jiaxing. The company spotted the attempt when a Lazarus operator tried to lure one of its developers into running a malicious GitHub project. ChatGPT has been observed reproducing Russian propaganda from the pro Kremlin network Pravda. The group has been posting large quantities of English language fake news on Russian social media network vk. From there, it's ingested by AI training systems. Last week, researchers warned that Pravda was laying the groundwork for having its propaganda indexed by AI assistance. A vulnerability in AI based Vicod platform Lovable is leaking sensitive customer information. Attackers can craft requests that expose the content of some customer databases, such as user data and API keys. Engineers from two separate companies independently found the issue and retrieved data from apps developed with Lovable. Details about the bug were published last week after the company failed to patch the issue for more than two months. Hackers are exploiting two recently disclosed vulnerabilities to take over V bulletin forums. The bugs were patched in April last year, but attacks began last week after security researcher Egidio Romano published proof of concept code. The Linux kernel has added support for a new mechanism to securely store cryptographic keys. The hardware wrapped inline encryption keys feature stores keys in a secure enclave and prevents them from appearing in system memory in the clear. The feature was initially developed for Android to block cold boot attacks. It's now shipped with the Linux kernel 6.16 and finally, Google will no longer trust certificates issued by Chinese telco Tsunghua Telecom and Hungarian firm Netlock. The root certificates will be removed from Chrome and Chrome OS in version 139 at the end of July, Google said it's lost confidence in the two companies. And that is all for this podcast edition. Today's show was brought to you by our sponsor, Runzero. Find them@runzero.com Thanksg Company.
