Newsletters

Written content from the Risky Business Media team

Risky Bulletin: The EU publishes its upcoming cybersecurity standards

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

The European Telecommunication Standards Institute has released 17 cybersecurity standards that vendors will have to follow to sell products in the EU when the EU Cyber Resilience Act enters into effect in December of 2027.

The standards cover 17 core technologies for major product categories such as:

The standards describe a list of minimum security features each product category must implement to be CRA-compliant.

Risky Bulletin: White House lets private companies carry out offensive cyber ops

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

In a presidential memo this week, the White House has directed the Department of Homeland Security to establish a program through which private sector companies can carry out offensive cyber operations on behalf of the US government against cybercrime organizations.

The new program will run under the DHS National Coordination Center (DHS NCC) and under oversight of both the Department of Justice and the Department of Homeland Security.

Private companies will be able to apply and receive specific tasks from the two agencies on what and who they can hack—to prevent rogue behavior from the private sector.

Srsly Risky Biz: Data Theft Extortion Is Booming! Hooray!

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

The cybercriminal ecosystem is increasingly focussing on data theft and extortion rather than locking up victims' files. That criminals have stumbled across a new lucrative business model is a bittersweet win in the fight against disruptive, encrypting ransomware. Data theft extortion isn't great, but it doesn't leave widespread chaos in its wake like ransomware can.

Silent Ransom, aka Luna Moth, is one group currently making big bucks from data theft extortion. Last week The Cyber Risk Insurer reported two law firms had paid substantial ransoms to the group this year: Goodwin Procter and WilmerHale, which paid USD$10 million and $USD18 million respectively. 

Silent Ransom has been targeting law firms since 2023. It historically used phishing and convinced victims to install legitimate remote access software which was then used to steal sensitive data. In the last year, however, they've brazenly sent people to compromise systems in person by posing as IT support staff.

Risky Bulletin: Russian hackers adopt the fake job interview tactics

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

One of Russia's elite military hacker groups is targeting system administrators and IT professionals in Ukraine using fake job interviews as a malware delivery vector.

Ukraine's CERT says the campaign began in May and is ongoing.

The attacks have been linked to UAC-0145, a sub-group of Sandworm, a veteran cyber unit inside Russia's GRU military intelligence agency.

Risky Bulletin: Pwnie Awards 2026 winners

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

If there's one thing that has annoyed me as someone who doesn't attend the yearly BlackHat & DEFCON conferences, it's that I could never find out who won the Pwnie Awards for days and sometimes weeks after the event had concluded.

The Pwnie team would never update their website in time, tweet the winners, attendees would rarely share details on social media, and very few infosec news sites would bother writing about it.

It's kind of a ridiculous situation where the Pwnie Awards Wikipedia page doesn't even list last year's winners, probably because nobody reported on them anywhere.

Risky Bulletin: Meta's AI joins Anthropic and OpenAI in the hacky-hacky

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

The UK's AI Security Institute has disclosed a security incident after two AI models it was evaluating performed actions the agency wasn't expecting and tried to hack real-world organizations.

The incident took place at the end of last month and the malicious actions were performed by Anthropic's Mythos 5 and OpenAI's GPT-5.6-Sol models, which were among the several models being tested at the time.

AISI says it was evaluating the models as part of a special test where it intentionally granted them internet access and turned off their safety features.

Srsly Risky Biz: Being a North Korean Hacker Is About to Be Less Fun

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

North Korea will have to rein in its pet hackers after seemingly losing control over them. 

Last week we covered the news that a group of former North Korean military intelligence operatives had been caught hacking into the country's banks to steal funds for their personal benefit. 

Daily NK reports Pyongyang's elite are shocked at "the scale and audacity of the scheme". Punishment for those involved will reportedly be extreme, with one official saying "It will be hard for the entire family line to survive". Grim.

Risky Bulletin: Hacker breaches Hungary's State Treasury

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

The same hacker who hit and wiped Romania's land registry database has now hacked Hungary's State Treasury in another brazen intrusion into an extremely sensitive government system.

The incident took place last week and portions of the stolen data have since been put up for sale on an underground hacking forum.

The intrusion was confirmed to local journalists by Hungary's State Treasury over the weekend. 

Risky Bulletin: Russia is behind the recent hotel WiFi hacks

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

A Russian state-sponsored hacking group is behind a recent hacking wave that has targeted and compromised hotel WiFi gateways across the globe.

Microsoft says the campaign is far larger and more complex than it was initially covered in a ReliaQuest report two weeks ago.

ReliaQuest said the hackers were modifying DNS traffic on hotel networks to redirect users to Microsoft-themed phishing sites. Microsoft says the attacks also redirected users to malware downloads, often using ClickFix pages to trick users into downloading and running the payloads.

Risky Bulletin: Non-profit offers $22,000 bounty for INC ransomware group

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

An international crime-fighting non-profit organization is offering a $22,000 bounty for any information on members of the INC ransomware group.

To be eligible for a payout, the provided information must lead to the identification, arrest, or disruption of the gang's operations.

Crime Stoppers International is the international branch of Crime Stoppers, a US foundation that was established in the 70s to allow anonymous and private individuals to provide aid in US law enforcement investigations that may lack manpower or resources.