Catalin Cimpanu

Cybersecurity reporter for Risky Business

Catalin Cimpanucampuscodi
2026-02-03

Canadian IT retailer Canada Computers has suffered a security breach

Customers who used the guest checkout option on its website had their personal and card data collected

The malicious code was live between December 29 to January 22

canadacomputers.com/en/content

Catalin Cimpanucampuscodi
2026-02-03

Meta is now using a Rust component to safely process media files shared on WhatsApp

engineering.fb.com/2026/01/27/

Catalin Cimpanucampuscodi
2026-02-03

I deleted the previous post. The Paris Prosecution Office left the platform on its own. They didn't get banned.

Catalin Cimpanu boosted:
2026-02-03

A fun one about the Notepad++ incident is, although my toots about it auto deleted (I have my toots set to auto delete unless I bookmark them), it was first revealed on the Fediverse in followers only mode a few months ago - I had a thread running for it back then.

When in follower only mode, the C2 infrastructure was still up so I was still able to track it - they only burnt it down when I wrote the blog. So follow me to see nation state espionage get live tooted, I guess.

Catalin Cimpanucampuscodi
2026-02-03
Catalin Cimpanucampuscodi
2026-02-03

There's a bug in the ESXi version of the Nitrogen ransomware that permanently destroys files... so don't pay the ransom

coveware.com/blog/2026/2/2/nit

Catalin Cimpanucampuscodi
2026-02-03

Interesting report here from GreyNoise on how CISA silently updated 59 KEV entries last year, flipping their "knownRansomwareCampaignUse" tag, meaning the bugs were being abused for ransomware attacks

greynoise.io/blog/unmasking-ci

Catalin Cimpanucampuscodi
2026-02-03

Dear f***ing lord!

Nearly one every three Meta ads showed in the EU and UK over 23 days pointed to online scams

This should be the easiest layup for govt agencies in the history of enforcements

gendigital.com/blog/insights/r

Catalin Cimpanucampuscodi
2026-02-03

Cyber groups survive takedowns even from Russian authorities.

The NyashTeam is alive and well after Russia's national domain registrar seized 110 domains last year.

f6.ru/blog/nyashteam-legion/

Catalin Cimpanucampuscodi
2026-02-03

Kaspersky has a list of individuals targeted in the Notepad++ incident

securelist.com/notepad-supply-


    Individuals located in Vietnam, El Salvador and Australia;
    A government organization located in the Philippines;
    A financial organization located in El Salvador;
    An IT service provider organization located in Vietnam.
Catalin Cimpanucampuscodi
2026-02-03

Russian security firm F6 (which splintered from Group-IB) has published its yearly threat report

The company says it tracks 27 APTs targeting Russian and the CIS space. It also reported a six-time increase in Android trojans.

f6.ru/cybercrime-trends-annual

Catalin Cimpanucampuscodi
2026-02-03

Russian GRU-linked cyber-espionage group APT28 is now using an Office zero-day disclosed last week for spear-phishing campaigns targeting Ukrainian targets, per a new Ukraine CERT report

cert.gov.ua/article/6287250

Catalin Cimpanu boosted:
2026-02-02

Notepad++ have today confirmed their auto process was compromised by Chinese nation state threat actors, in a supply chain hack: notepad-plus-plus.org/news/hij

This backs up my blog from late last year, with #GAYINT threat actor mapping to Funky Stamen.

The infrastructure and update mechanisms have since been tightened. For what it’s worth - entry was to telcos and financial services with interests aligned to China. Notepad++ dev did a great job treating issue seriously.

Catalin Cimpanu boosted:
2026-02-02

RE: techhub.social/@Techmeme/11600

One way to make sure xAI is too big to fail before the AI bubble bursts - put it inside SpaceX, which is critical to US national security and interests.

Catalin Cimpanu boosted:
2026-02-02

From @campuscodi at @riskybiz:

Fidesz disinformation network: A Facebook troll farm pushing pro-Orban disinformation has ties to a local non-profit organization with ties to the Fidesz political party. Hungarian journalists claim more than 100 employees of the Digital Democracy Development Agency manage Facebook accounts that promote the party and attack the opposition online. The agency allegedly buys Facebook groups and accounts and then floods discussions with their comments. Hungary is set to hold parliamentary elections in April.

translate.kagi.com/444.hu/2026

news.risky.biz/risky-bulletin-

Catalin Cimpanu boosted:
an image with the text "nice argument, however" on the top, followed by a close-up of a white cat sticking out its tongue
Catalin Cimpanu boosted:
Zack Whittakerzackwhittaker
2026-02-02

NEW: A few weeks ago, @PogoWasRight and I ran a survey asking security researchers and journalists about the legal and criminal threats they have received for doing their jobs.

Over 100 people responded, and we now have our results.

One of our key findings is that while legal threats and criminal threats are common, most researchers & journalists stood their ground and did not give in to threats.

More: this.weekinsecurity.com/new-su

Results: databreaches.net/2026/02/02/un

PDF: databreaches.net/wp-content/up

Catalin Cimpanu boosted:
Catalin Cimpanucampuscodi
2026-02-02

-StopICE blames hack on "CBP agent here in SoCal"
-Microsoft will disable NTLM in the next Windows version
-Poland bans Chinese cars from military bases
-Ivanti patches two zero-days
-Cyberattack disrupted Russian oil company
-Chat & Ask AI leaks chatbot messages
-Nobel Committee investigates hack
-Data leak at the Ttareungyi bike-sharing service
-Comcast agrees to $117.5m settlement over 2023 breach
-US investigates WhatsApp

Podcast: risky.biz/RBNEWS520/
Newsletter: news.risky.biz/risky-bulletin-

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst