Brutkey

Catalin Cimpanu
@campuscodi@mastodon.social
Catalin Cimpanu
@campuscodi@mastodon.social

For the RU-speaking people in here. Is that "dropper/dropping" term translated correctly? Or is there a better translation?

Catalin Cimpanu
@campuscodi@mastodon.social

The Justice Department is trying to claw back $1 million worth of crypto stolen from a US company last year by three North Korean IT workers

(via CourtWatchNews)

https://www.courtlistener.com/docket/71030908/united-states-v-approximately-1008902606307-usdt/

Catalin Cimpanu
@campuscodi@mastodon.social

Russian authorities have opened the country's first investigation for the crime of "dropping."

A Moscow man was charged with paying intermediaries to open bank accounts in their names that would be used to store or launder stolen funds.

https://t.me/IrinaVolk_MVD/5029

Catalin Cimpanu
@campuscodi@mastodon.social

Analyst1 has published a profile of Yaroslav Vasinskyi, a Ukrainian national and member of the REvil gang that hacked Kaseya in 2021.

He is currently serving a 13-year prison sentence in the US.

The profile also includes a rare interview with Vasinskyi.

https://analyst1.com/ransomware-diaries-volume-7-i-had-to-take-the-guilt-for-everyone-the-kaseya-hacker-breaks-his-silence/

Catalin Cimpanu
@campuscodi@mastodon.social

New WinRAR zero-day: https://www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews[tt_news]=283&cHash=a64b4a8f662d3639dec8d65f47bc93c5

Found by ESET, but BI.ZONE suggests this is the Paper Werewolf APT:
https://bi.zone/news/kibershpiony-paper-werewolf-ispolzuyut-dlya-atak-uyazvimosti-v-winrar/

Catalin Cimpanu
@campuscodi@mastodon.social

A California man has sued Microsoft over its plans to discontinue Windows 10 in October this year.

Plaintiff Lawrence Klein claims the Windows 10 End-of-Life is part of Microsoft's plans to monopolize the generative AI market.

https://www.courthousenews.com/microsoft-sued-for-discontinuing-windows-10-support/

Catalin Cimpanu
@campuscodi@mastodon.social

WinRAR patches another zero-day

By who reported the bug, I'd say this is a zero-day exploited by some Russian APT

https://www.win-rar.com/singlenewsview.html?&tx_ttnews%5Btt_news%5D=283&cHash=ff1fa7198ad19261efb202dafd7be691

Catalin Cimpanu
@campuscodi@mastodon.social

lol... typical

https://research.eye.security/consent-and-compromise/

Catalin Cimpanu
@campuscodi@mastodon.social

Security firm Trail of Bits has open-sourced Buttercup, a Cyber Reasoning System (CRS) developed for the AIxCC (AI Cyber Challenge).

It is designed to find and patch software vulnerabilities in open-source code repositories.

https://blog.trailofbits.com/2025/08/08/buttercup-is-now-open-source/

https://github.com/trailofbits/buttercup

Catalin Cimpanu
@campuscodi@mastodon.social

Anthropic has released Claude Code Security Reviewer, a GitHub action to automate code reviews with its Claude AI agent

https://www.anthropic.com/news/automate-security-reviews-with-claude-code

https://github.com/anthropics/claude-code-security-review