Newsletters

Written content from the Risky Business Media team

Risky Bulletin: Academics find source code overlaps between Geedge and China's Great Firewall

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

A team of American academics have found source code overlaps between the products of a Chinese tech company and the country's Great Firewall traffic filtering and censorship system.

According to research presented at this year's USENIX security conference, the Chinese government is using the Geedge Networks Tiangou Secure Gateway (TSG) device as one of the Great Firewall's three known traffic filtering capabilities.

Researchers linked Geedge's device to the Great Firewall after more than 100,000 files leaked from Geedge's network last year.

Srsly Risky Biz: Trump's Private Hacker Memo Is the Right Idea

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

The US government’s plan to enlist private sector hackers to target cybercriminals is controversial, but it addresses a real problem and is surprisingly measured.  

Last week, a presidential memo directed the Department of Homeland Security to establish a program authorising private companies to conduct cyber operations against so-called "Cyber-Enabled Transnational Crime Organisations" or CE-TCOs. The memo sets out the broad shape of the arrangement and a classified annex further details the logistics. 

The huge policy shift here is that private companies will be authorised to conduct cyber operations that were previously restricted to state entities. This includes what the memo calls "cyber surveillance" (intelligence gathering operations) and "cyber effects" operations, (intended to manipulate or to cause disruption).

Risky Bulletin: Slovakia finds Russian backdoor in traffic speed cameras

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Slovakia's national security service NBU has issued a security alert against the use of NERO R-ONE high-speed traffic cameras.

The agency says the cameras contain a backdoor mechanism that grants shell and network access to the devices via an SMS message received from a list of hardcoded Russian phone numbers.

The NBU started an investigation into the devices after the country's opposition accused the government of buying the cameras from Russia and after multiple reports in Slovak media that linked the purchase to a Cyprus shell company with fake certifications.

Risky Bulletin: The EU publishes its upcoming cybersecurity standards

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

The European Telecommunication Standards Institute has released 17 cybersecurity standards that vendors will have to follow to sell products in the EU when the EU Cyber Resilience Act enters into effect in December of 2027.

The standards cover 17 core technologies for major product categories such as:

The standards describe a list of minimum security features each product category must implement to be CRA-compliant.

Risky Bulletin: White House lets private companies carry out offensive cyber ops

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

In a presidential memo this week, the White House has directed the Department of Homeland Security to establish a program through which private sector companies can carry out offensive cyber operations on behalf of the US government against cybercrime organizations.

The new program will run under the DHS National Coordination Center (DHS NCC) and under oversight of both the Department of Justice and the Department of Homeland Security.

Private companies will be able to apply and receive specific tasks from the two agencies on what and who they can hack—to prevent rogue behavior from the private sector.

Srsly Risky Biz: Data Theft Extortion Is Booming! Hooray!

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

The cybercriminal ecosystem is increasingly focussing on data theft and extortion rather than locking up victims' files. That criminals have stumbled across a new lucrative business model is a bittersweet win in the fight against disruptive, encrypting ransomware. Data theft extortion isn't great, but it doesn't leave widespread chaos in its wake like ransomware can.

Silent Ransom, aka Luna Moth, is one group currently making big bucks from data theft extortion. Last week The Cyber Risk Insurer reported two law firms had paid substantial ransoms to the group this year: Goodwin Procter and WilmerHale, which paid USD$10 million and $USD18 million respectively. 

Silent Ransom has been targeting law firms since 2023. It historically used phishing and convinced victims to install legitimate remote access software which was then used to steal sensitive data. In the last year, however, they've brazenly sent people to compromise systems in person by posing as IT support staff.

Risky Bulletin: Russian hackers adopt the fake job interview tactics

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

One of Russia's elite military hacker groups is targeting system administrators and IT professionals in Ukraine using fake job interviews as a malware delivery vector.

Ukraine's CERT says the campaign began in May and is ongoing.

The attacks have been linked to UAC-0145, a sub-group of Sandworm, a veteran cyber unit inside Russia's GRU military intelligence agency.

Risky Bulletin: Pwnie Awards 2026 winners

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

If there's one thing that has annoyed me as someone who doesn't attend the yearly BlackHat & DEFCON conferences, it's that I could never find out who won the Pwnie Awards for days and sometimes weeks after the event had concluded.

The Pwnie team would never update their website in time, tweet the winners, attendees would rarely share details on social media, and very few infosec news sites would bother writing about it.

It's kind of a ridiculous situation where the Pwnie Awards Wikipedia page doesn't even list last year's winners, probably because nobody reported on them anywhere.

Risky Bulletin: Meta's AI joins Anthropic and OpenAI in the hacky-hacky

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

The UK's AI Security Institute has disclosed a security incident after two AI models it was evaluating performed actions the agency wasn't expecting and tried to hack real-world organizations.

The incident took place at the end of last month and the malicious actions were performed by Anthropic's Mythos 5 and OpenAI's GPT-5.6-Sol models, which were among the several models being tested at the time.

AISI says it was evaluating the models as part of a special test where it intentionally granted them internet access and turned off their safety features.

Srsly Risky Biz: Being a North Korean Hacker Is About to Be Less Fun

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

North Korea will have to rein in its pet hackers after seemingly losing control over them. 

Last week we covered the news that a group of former North Korean military intelligence operatives had been caught hacking into the country's banks to steal funds for their personal benefit. 

Daily NK reports Pyongyang's elite are shocked at "the scale and audacity of the scheme". Punishment for those involved will reportedly be extreme, with one official saying "It will be hard for the entire family line to survive". Grim.