Newsletters

Written content from the Risky Business Media team

Risky Bulletin: Canada’s spy agency allowed to remove a botnet from Canadian devices

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Canada's main intelligence service obtained a court warrant this week to proactively remove a mysterious botnet's malware from Canadian systems such as servers, home routers, and smart devices.

The devices were allegedly part of an unnamed proxy botnet. These types of botnets are very common these days and allow hackers to disguise the origin of their attacks and their identities, making their malicious traffic appear as coming from a local residential network.

According to a copy of the court order obtained by The Canadian Press, the botnet was allegedly being used by a threat actor to "advance their financial, political, ideological and economic interests."

Srsly Risky Biz: Anthropic Lacks Emotional Intelligence

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

The stoush between Anthropic and the US government has erupted once again, this time over concerns about how the release of new AI models is being managed.

Early last week, Anthropic rolled out two new models, Mythos 5 and Fable 5. By Friday, they'd been pulled.

The Wall Street Journal reported their withdrawal was kicked off by conversations on Thursday last week between Amazon CEO Andy Jassy and US officials, including Treasury Secretary Scott Bessent. Jassy raised the possibility that the models could be jailbroken and by Friday evening the Commerce Department told Anthropic that its models would be subject to export controls. These controls prohibit the models from being used by any foreign national, regardless of whether they are inside or outside of the US. 

Risky Bulletin: China arrests members of Silver Fox cybercrime group

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Chinese police have arrested 67 suspects linked to Silver Fox, the country's largest and most active cybercrime group targeting its domestic audiences.

Arrests took place across five provinces and targeted everyone from developers to phishing site operators and various affiliates.

Authorities identified a man named Ji Moufei as the main individual who wrote and sold the group's malware, the eponymous Silver Fox trojan. Ji and four associates were arrested in Zhejiang.

Risky Bulletin: Arch Linux supply chain attack spreads to 1,900+ AUR packages

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

More than 1,900 Arch Linux packages have been hijacked over the weekend as part of a massive supply chain attack designed to infect users with a rootkit and a credentials harvester.

The attacker(s) targeted Arch Linux packages hosted on the AUR portal, an unofficial repository of Arch packages created by the community. The portal hosts a massive 100,000 entries, but almost a tenth have been abandoned by their maintainers in what AUR calls "orphaned packages."

The attack exploited an AUR mechanism that allowed the hacker to "adopt" the abandoned packages and become a maintainer.

Risky Bulletin: In the age of AI, CISA changes federal patching rules

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

The US Cybersecurity and Infrastructure Security Agency (CISA) issued a new binding operational directive (BOD) this week that updates the patching rules for federal civilian agencies.

The new order cites the rise of AI-automated attacks as the main reason to prioritize bugs based on the risk they pose to federal networks and shorten patching deadlines.

The order introduces a new decision tree (pictured below) that will prioritize vulnerabilities that are exploited in the wild, are easy to exploit and automate, and grant broad access to a system if they have been exploited.

Srsly Risky Biz: Europe Wants To Wean Itself Off US Tech

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

The European Union Commission has proposed a tech sovereignty package that covers a range of initiatives around semiconductors, cloud computing and AI. We'd be surprised if these initiatives have a major impact in the short term, but this is still a good move for Europe. 

The key initiative of the proposed package, in our view, is the Open Source Strategy which aims to "strengthen digital autonomy through open source". Although it's not stated explicitly, the intent here is to wean Europe off the US tech stack by encouraging open source alternatives. 

The strategy says it will take "concrete actions", for example reforming government procurement rules to make them more open source friendly. EU governments will also award grants to open source projects under the strategy. 

Risky Bulletin: Meta says NSO violated court order with new campaign targeting WhatsApp

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Social media company Meta says it found and disrupted a new NSO Group hacking campaign targeting WhatsApp users, in violation of a US court order issued last October.

The campaign was a spear-phishing operation that tried to lure certain users into clicking a malicious link sent to their WhatsApp accounts that took them to an external site.

Meta filed a legal complaint against the Israeli spyware company on Monday, asking the court to hold NSO in contempt.

Risky Bulletin: RubyGems adds dependency cooldowns to counter supply chain attacks

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

The RubyGems package manager has added support for dependency cooldowns as a way to counter a recent spate of supply chain attacks. The move copies similar efforts made in the JavaScript and Python ecosystem this year.

Dependency cooldowns are parameters that tell the package manager to install dependencies only if they are of a certain age in days. For example, a dependency cooldown of "7" will only install packages that are at least a week old.

The idea behind dependency cooldowns is to allow security tools, the admins of package repositories, and library maintainers time to detect compromises and pull down malicious versions.

Risky Bulletin: The EU debuts digital sovereignty plan

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

The European Commission unveiled on Wednesday a plan to decouple from American companies and boost the bloc's tech sovereignty.

The plan would boost chip production, triple data center capacity, and fund open-source projects as alternatives to US-dominated software.

The proposals cut the typical EU red tape around developing new infrastructure, such as data centers, and provide generous funding for homegrown solutions.

Srsly Risky Biz: NATO's Cyber Approach Needs Change

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

Last week, The Grugq and I travelled to Estonia for CyCon, NATO CCDCOE's conference on Cyber Conflict. Our biggest takeaway from the conversations we had there is that NATO, unsurprisingly, is well prepared for one-off, large-scale military attacks. But it is failing to counter small, unremitting cyberattacks, and this needs to change.

NATO was created to deter the Soviet Union from military aggression. It still defines itself as a defensive alliance that can deliver a "resounding response" in the event of an unlikely but devastating Russian military attack.  

Russian cyber operations, however, are continuous and conducted well below the threshold of armed conflict. Individual operations just aren't damaging enough to attract a robust response. These continuous aggressive incursions are favoured by states like Russia and China as a way to harass their adversaries during peacetime.