Sign in

Sergiu Gatlan

@serghei.bsky.social
5.6K followers 897 following 100 posts

Cybersecurity/tech reporter @BleepingComputer / serghei.ro

PostsRepliesMedia
Sergiu Gatlan @serghei.bsky.social · 4h
An international law enforcement operation dubbed “Operation KillSwitch” seized the KillSec ransomware gang’s data leak site and servers, led to three arrests, and identified a 16-year-old as the group’s alleged administrator. www.bleepingcomputer.com/news/securit... vimeo.com/1232032220?f...
vimeo.com
Operation KillSwitch video
Video created as part of Operation KillSwitch, the international law enforcement operation that took down the KillSec ransomware group.
111
Reposted by Sergiu Gatlan
BleepingComputer @bleepingcomputer.com · 26/09/2026
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers.
bleepingcomputer.com
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers.
064
Reposted by Sergiu Gatlan
BleepingComputer @bleepingcomputer.com · 25/09/2026
​Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets.
bleepingcomputer.com
Hackers steal $351.6 million in Bitget crypto exchange hack
​Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets.
033
Reposted by Sergiu Gatlan
Catalin Cimpanu @campuscodi.risky.biz · 22/09/2026
The Irish Presidency of the EU has proposed member states to allow AI companies unfettered access to the data of EU citizens. According to leaked docs, the proposal would effectively exempt AI companies from any of the GDPR rules and deny EU citizens data protection rights noyb.eu/en/ai-eu-mem...
noyb.eu
AI: EU Member States plan “digital expropriation” of Europeans in the interest of AI companies
In a leaked document, the Irish Presidency proposes to EU Member States that the interest of AI companies to make profits should take precedence over the fundamental rights of Europeans.
21623
Sergiu Gatlan @serghei.bsky.social · 19/09/2026
Timeline of "rogue AI events" www.wsj.com/tech/ai/gemi...
Rogue Al events timeline
072
Sergiu Gatlan @serghei.bsky.social · 17/09/2026
Oil company warns coal is bad 🤦‍♂️
020
Reposted by Sergiu Gatlan
Raphael Satter @raphae.li · 17/09/2026
Maritime cybersecurity experts, your time has come. www.reuters.com/world/two-us...
The FBI said a joint Coast Guard-FBI team boarded ⁠the vessels after receiving "indications that the networks of both vessels were compromised." The Coast Guard, ​which referred only to the August 21 boarding, said that "foreign cyber actors" were involved ​but did not identify them.
021
Reposted by Sergiu Gatlan
Cynthia Brumfield @metacurity.com · 17/09/2026
I feel like this is using the term "cyberattack" very expansively. Port of LA Foiled Around 120 Million Cyberattacks Last Month www.bloomberg.com/news/article...
bloomberg.com
Port of LA Foiled Around 120 Million Cyberattacks Last Month
The US’s busiest container port for global trade foiled more than 120 million cyberattack attempts in August, posing a persistent threat to its operations as it grapples with shifting tariff policies.
341
Reposted by Sergiu Gatlan
BleepingComputer @bleepingcomputer.com · 27/08/2026
ATF, the regulatory agency that enforces federal laws governing firearms and explosives in the United States, has confirmed that one of its systems was compromised after breach claims made by the Qilin ransomware gang.
bleepingcomputer.com
ATF confirms “major incident” after recent Qilin breach claims
ATF, the regulatory agency that enforces federal laws governing firearms and explosives in the United States, has confirmed that one of its systems was compromised after breach claims made by the Qilin ransomware gang.
055
Reposted by Sergiu Gatlan
Zack Whittaker @zackwhittaker.com · 18/08/2026
By enabling the new Xfinity Wi-Fi motion sensing tech, Comcast says it may disclose information generated from a customer’s use of the feature to outside parties under a broad array of reasons — and Comcast also says it doesn’t have to tell you. Ad-block bypass: web.archive.org/web/20260818...
techcrunch.com
Comcast adds motion sensing to millions of its newer routers, with a privacy catch | TechCrunch
A new feature added to Comcast's newest routers can detect if there is motion is inside your home without needing traditional motion sensors.
22617
Reposted by Sergiu Gatlan
Joseph Cox @josephcox.bsky.social · 17/08/2026
New from 404 Media: we solved which AI company is buying massive shipments of rare books, scanning and destroying them to train AI. We put an Apple AirTag in a rare book, followed it. It ended up at an Amazon facility. Its logo is a dinosaur ripping through a book www.404media.co/we-tracked-a...
404media.co
We Tracked a Shipment of Rare Books. It Ended at an Amazon AI Training Facility
We placed a tracking device in a shipment of rare books to see which AI company was buying it, and found an Amazon facility where Amazon scans and destroys books.
12537932368
Reposted by Sergiu Gatlan
BleepingComputer @bleepingcomputer.com · 14/08/2026
Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data.
bleepingcomputer.com
Shell investigates 'potential incident' after Clop data theft claims
Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data.
024
Sergiu Gatlan @serghei.bsky.social · 13/08/2026
New "Plug and Pwn" attack grants Windows SYSTEM privileges via fake USB devices www.bleepingcomputer.com/news/securit...
030
Reposted by Sergiu Gatlan
Maggie Miller @maggiemiller.bsky.social · 13/08/2026
President Trump tonight signed a memorandum that allows authorized private companies to carry out operations combatting foreign-enabled cybercrime. Participating groups would be vetted and sign contracts with DOJ/DHS. Massive sea change in cyber policy: www.whitehouse.gov/presidential...
whitehouse.gov
Expanding Capabilities to Combat Transnational Cyber-Enabled Crime
MEMORANDUM FOR THE VICE PRESIDENT THE SECRETARY OF STATE THE SECRETARY OF THE TREASURY THE SECRETARY OF WAR THE ATTORNEY GENERAL THE SECRETARY OF COMMERCE
165
Reposted by Sergiu Gatlan
Andy Greenberg @agreenberg.bsky.social · 12/08/2026
A hacking device the size of a quarter can be plugged into a port accessible from the exterior of a Boeing 737 to change its autopilot navigation or tamper with values used to calculate its takeoff speed, a group of security researchers has shown. 🧵👇 www.wired.com/story/this-c...
wired.com
This Coin-Sized Device Can Hack a Boeing 737
Security researchers found that in less than 60 seconds, they could open a hatch on a plane’s exterior, plug in a tiny device, and redirect the aircraft’s autopilot or sabotage its flight plan.
23425
Sergiu Gatlan @serghei.bsky.social · 12/08/2026
Looks like anyone can log in to the FortiWeb GUI/CLI with a random username and password if the Wildcard option is enabled for Administrators 🤷‍♂️ fortiguard.fortinet.com/psirt/FG-IR-... www.cve.org/CVERecord?id...
Broken access control in the RADIUS type admin group [CVE-2026-26035]: An Improper Authentication vulnerability [CWE-287] in the FortiWeb Remote Radius Type Admin Authentication configured with specific, non-default settings may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password.
011
Reposted by Sergiu Gatlan
Jason Koebler @jasonkoebler.bsky.social · 10/08/2026
Banger after banger after banger in Zuckerberg’s delusional AI fever dream essay www.404media.co/mark-zuckerb...
404media.co
Mark Zuckerberg Posts Deranged 6,500-Word Essay About Giving Everyone AI Superintelligence
"The future is for everyone," Zuckerberg says, describing future that is primarily good for Meta.
1591210295
Reposted by Sergiu Gatlan
Kevin Beaumont @doublepulsar.com · 10/08/2026
Two things at play - ClickFix (website asks user to press Windows key + R, run a command) is *incredibly successful*, and just phoning the helpdesk and asking for password reset. The GenAI research stuff being pushed out by security and AI vendors is completely absent in the real world trenches.
49034
Reposted by Sergiu Gatlan
BleepingComputer @bleepingcomputer.com · 10/08/2026
Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, CEVA Logistics.
bleepingcomputer.com
Valve notifies Steam hardware customers of a data breach
Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, CEVA Logistics.
094
Reposted by Sergiu Gatlan
Zack Whittaker @zackwhittaker.com · 07/08/2026
By me, at this.weekinsecurity.com: Microsoft wins "lamest vendor response" award at this year's Pwnie Awards, for publishing a blog post earlier this year threatening security researchers with legal action if they published zero-days. Also: Meta wins "epic fail" award after its Meta AI hijack bug.
this.weekinsecurity.com
Microsoft wins 'lamest vendor' at Pwnie Awards 2026 for threatening security researchers with legal action
"This is a shame award. Don't forget to feel that shame."
06018
Sergiu Gatlan @serghei.bsky.social · 24/07/2026
Google Threat Intelligence Group (GTIG) announces a new naming schema for tracking threat actors. cloud.google.com/blog/topics/...
Google Threat Intelligence Group (GTIG) announces a new naming schema for tracking threat actors that uses a cryptonym-based approach, employing memorable two-word combinations for each distinct threat actor.
224
Reposted by Sergiu Gatlan
—>realhackhistory.org @bsky.realhackhistory.org · 24/07/2026
Periodic reminder that if you are being asked by a captcha to type any kind of combinations of keys & especially if they look like shortcut key stroke combinations it is an attack called ClickFix. Basically the prompt is to fool you into downloading & installing malicious software. Stay vigilant!
216398
Reposted by Sergiu Gatlan
Matt Burgess (WIRED) @mattburgess1.bsky.social · 24/07/2026
NEW: After a purported crackdown on scam compounds last year, researchers now say at least 25 new scamming sites have opened or expanded in Myanmar. Satellite images show trees being razed and land cleared, with large compounds appearing months later
wired.com
Satellite Images Reveal How Suspected Scam Compounds Appear Out of Nowhere
Analysis of satellite images of Myanmar shows dozens of alleged scam compounds have appeared in recent months, despite a purported crackdown on the criminal organizations.
32521
Reposted by Sergiu Gatlan
BleepingComputer @bleepingcomputer.com · 24/07/2026
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign.
bleepingcomputer.com
Clop ransomware targets Windchill, FlexPLM in data theft attacks
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign.
033
Reposted by Sergiu Gatlan
BleepingComputer @bleepingcomputer.com · 21/07/2026
Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems.
bleepingcomputer.com
Windows LegacyHive zero-day flaw gets free, unofficial patches
Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems.
055
Reposted by Sergiu Gatlan
BleepingComputer @bleepingcomputer.com · 21/07/2026
The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf.
bleepingcomputer.com
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf.
074
Reposted by Sergiu Gatlan
Mike Eckel @mikeeckel.bsky.social · 17/07/2026
It's unusual for former FSB employees to be arrested outside of Russia (and extradited) these days. But what's also unusual about Denis Obrezko -- charged with the "Laundry Bear" hack of computers in the U.S. and Europe-- is how careless he appeared to have been online. www.rferl.org/a/russia-hac...
rferl.org
An Alleged Russian FSB Hacker Traveled To Thailand. Now He's Facing 10 Years In A US Prison.
What’s unusual about the arrest of Denis Obrezko is how relatively rare it is for Russian hackers to be detained abroad these days. What’s also unusual: Obrezko used to work for Russia’s FSB. And it a...
12920
Reposted by Sergiu Gatlan
BleepingComputer @bleepingcomputer.com · 12/06/2026
Maine has taken its public data breach reporting portal offline after fraudulent breach disclosures were published on the state's website, prompting a review of procedures to prevent abuse in the future.
bleepingcomputer.com
Maine disables data breach notification portal after fake disclosures
Maine has taken its public data breach reporting portal offline after fraudulent breach disclosures were published on the state's website, prompting a review of procedures to prevent abuse in the future.
023
Reposted by Sergiu Gatlan
BleepingComputer @bleepingcomputer.com · 12/06/2026
Danish pharmaceutical giant Novo Nordisk, the world's largest producer of insulin, disclosed a data breach affecting patient information from some clinical trials.
bleepingcomputer.com
Pharma giant Novo Nordisk discloses breach of clinical trials data
Danish pharmaceutical giant Novo Nordisk, the world's largest producer of insulin, disclosed a data breach affecting patient information from some clinical trials.
063
Reposted by Sergiu Gatlan
BleepingComputer @bleepingcomputer.com · 11/06/2026
In an unusual misinformation campaign, fraudulent data breach disclosures were submitted to Maine's official breach portal and publicly posted before their legitimacy could be verified, prompting companies to deny the claims.
bleepingcomputer.com
Maine breach portal abused to publish fake data breach disclosures
In an unusual misinformation campaign, fraudulent data breach disclosures were submitted to Maine's official breach portal and publicly posted before their legitimacy could be verified, prompting companies to deny the claims.
024
Reposted by Sergiu Gatlan
BleepingComputer @bleepingcomputer.com · 11/06/2026
Oracle is warning about a critical PeopleSoft Suite zero-day vulnerability tracked as CVE-2026-35273 that allows unauthenticated remote code execution, with the flaw actively exploited in ShinyHunter data theft attacks.
bleepingcomputer.com
Oracle mitigates PeopleSoft zero-day exploited in data theft attacks
Oracle is warning about a critical PeopleSoft Suite zero-day vulnerability tracked as CVE-2026-35273 that allows unauthenticated remote code execution, with the flaw actively exploited in ShinyHunter data theft attacks.
023
Reposted by Sergiu Gatlan
Nate Raymond @nateraymond.bsky.social · 10/06/2026
New out of Boston: A suspected Russian hacker who was arrested last year in Thailand at the FBI's behest is now in U.S. custody and has been charged ​with facilitating a campaign of cyberattacks carried out by a Russia-aligned ‌group called Void Blizzard. www.reuters.com/legal/govern...
reuters.com
US charges suspected Russian hacker with facilitating cyber campaign
A suspected Russian hacker is now in U.S. custody following his arrest in Thailand last year and has been charged ​with facilitating a campaign of cyberattacks carried out by a Russia-aligned ‌group t...
024
Reposted by Sergiu Gatlan
BleepingComputer @bleepingcomputer.com · 10/06/2026
Oracle PeopleSoft servers are being targeted in ongoing data theft attacks by the ShinyHunters extortion gang, which claims to have stolen data from over 100 organizations.
bleepingcomputer.com
Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks
Oracle PeopleSoft servers are being targeted in ongoing data theft attacks by the ShinyHunters extortion gang, which claims to have stolen data from over 100 organizations.
043
Reposted by Sergiu Gatlan
Thomas Brewster @thomasbrewster.bsky.social · 09/06/2026
🚨 NEW 🚨 The Justice Department gagged Apple from talking about surveillance on a senior Republican staffer that's been going on for at least the last three years. Apple fought the non-disclosure orders and won. It's now informed the target. www.forbes.com/sites/the-wi...
forbes.com
The FBI Gagged Apple About Surveilling A Republican Aide. Apple Took It To Court And Won.
The DOJ served Apple with repeated gag orders related to extensive surveillance of a senior Republican Congressional staffer in a Qatari-influence investigation.
25040
Reposted by Sergiu Gatlan
BleepingComputer @bleepingcomputer.com · 10/06/2026
bleepingcomputer.com
Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges
064
Reposted by Sergiu Gatlan
BleepingComputer @bleepingcomputer.com · 09/06/2026
ServiceNow is warning about a security incident after attackers exploited an unauthenticated access flaw through a vulnerable API endpoint, allowing them to query data from customer instances.
bleepingcomputer.com
ServiceNow discloses security incident exposing customer data
ServiceNow is warning about a security incident after attackers exploited an unauthenticated access flaw through a vulnerable API endpoint, allowing them to query data from customer instances.
094
Reposted by Sergiu Gatlan
BleepingComputer @bleepingcomputer.com · 04/06/2026
The United Nations' World Food Programme (WFP), the world's largest humanitarian organization, revealed over the weekend that its self-registration application (SRA) for Palestine was breached.
bleepingcomputer.com
UN food agency discloses breach affecting 600,000 Gaza households
The United Nations' World Food Programme (WFP), the world's largest humanitarian organization, revealed over the weekend that its self-registration application (SRA) for Palestine was breached.
062
Reposted by Sergiu Gatlan
Patrick Gray @patrick.risky.biz · 04/06/2026
Microsoft's digital crimes unit said it would pursue security researchers who "irresponsibly" disclose 0day. But it's simple: Redmond can't dictate what researchers do with bugs. If you can't entice hackers to disclose bugs via your preferred channels, that's a you problem! (aka skill issue)
34614
Reposted by Sergiu Gatlan
BleepingComputer @bleepingcomputer.com · 03/06/2026
A security researcher has released exploit code for a Visual Studio Code (VS Code) zero-day vulnerability that allows attackers to steal GitHub authentication tokens by tricking users into clicking a link.
bleepingcomputer.com
VS Code zero-day lets hackers steal GitHub tokens in one click
A security researcher has released exploit code for a Visual Studio Code (VS Code) zero-day vulnerability that allows attackers to steal GitHub authentication tokens by tricking users into clicking a link.
0911
Reposted by Sergiu Gatlan
BleepingComputer @bleepingcomputer.com · 30/05/2026
Palo Alto Networks is warning that hackers are now exploiting a PAN-OS GlobalProtect authentication bypass flaw, tracked as CVE-2026-0257, in attacks attempting to breach corporate networks.
bleepingcomputer.com
Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks
Palo Alto Networks is warning that hackers are now exploiting a PAN-OS GlobalProtect authentication bypass flaw, tracked as CVE-2026-0257, in attacks attempting to breach corporate networks.
052
Reposted by Sergiu Gatlan
​ @cyberworm.uk · 28/05/2026
Are Microsoft arguing that releasing proof of concept is a crime if you don't get their approval first? Because this seems to lump a security researcher not going along with their preferred disclosure process in with "criminal activity".
consequences. Our security teams across the company work tirelessly tracking threat actors who look for weaknesses just like these to attack Microsoft and our customers. Our Digital Crimes Unit will continue bringing cases against these actors and those that enable their criminal activity – coordinating as needed with law enforcement around the world.
1165
Reposted by Sergiu Gatlan
BleepingComputer @bleepingcomputer.com · 26/05/2026
U.S. telecommunications giant Charter Communications has confirmed it suffered a data breach after the ShinyHunters extortion group threatened to leak stolen data unless a ransom is paid.
bleepingcomputer.com
Charter confirms data breach after ShinyHunters extortion threat
U.S. telecommunications giant Charter Communications has confirmed it suffered a data breach after the ShinyHunters extortion group threatened to leak stolen data unless a ransom is paid.
035
Reposted by Sergiu Gatlan
BleepingComputer @bleepingcomputer.com · 27/05/2026
The FBI warned on Tuesday that the Silent Ransom Group (SRG) extortion gang is now targeting U.S.-based law firms in in-person data theft attacks.
bleepingcomputer.com
FBI warns of in-person data theft attacks from extortion gang
The FBI warned on Tuesday that the Silent Ransom Group (SRG) extortion gang is now targeting U.S.-based law firms in in-person data theft attacks.
053
Reposted by Sergiu Gatlan
Alexander Martin @alexmartin.bsky.social · 20/05/2026
Huawei has not explained why no CVE has been issued for the vulnerability that caused Luxembourg’s nationwide telecoms outage. Ten months later, it remains unclear whether the vuln was ever fully patched, how many operators may have been exposed or whether similar systems remain vulnerable today.
087
Reposted by Sergiu Gatlan
BleepingComputer @bleepingcomputer.com · 20/05/2026
GitHub has confirmed that roughly 3,800 internal repositories were breached after one of its employees installed a malicious VS Code extension.
bleepingcomputer.com
GitHub confirms breach of 3,800 repos via malicious VSCode extension
GitHub has confirmed that roughly 3,800 internal repositories were breached after one of its employees installed a malicious VS Code extension.
01110
Reposted by Sergiu Gatlan
BleepingComputer @bleepingcomputer.com · 14/05/2026
OpenAI says two employees' devices were breached in the recent TanStack supply chain attack that impacted hundreds of npm and PyPI packages, causing the company to rotate code-signing certificates for its applications as a precaution.
bleepingcomputer.com
OpenAI confirms security breach in TanStack supply chain attack
OpenAI says two employees' devices were breached in the recent TanStack supply chain attack that impacted hundreds of npm and PyPI packages, causing the company to rotate code-signing certificates for its applications as a precaution.
044
Reposted by Sergiu Gatlan
TrendAI Zero Day Initiative @thezdi.bsky.social · 14/05/2026
Confirmed! Orange Tsai (@orange_8361) of DEVCORE Research Team (@d3vc0r3) chained 4 logic bugs to achieve a sandbox escape on Microsoft Edge, earning $175,000 and 17.5 Master of Pwn points. Full win! #Pwn2Own #P2OBerlin
053
Reposted by Sergiu Gatlan
BleepingComputer @bleepingcomputer.com · 13/05/2026
The U.S. House Committee on Homeland Security is calling on Instructure executives to testify about two cyberattacks by the ShinyHunters extortion group that targeted the company's Canvas platform, allowing threat actors to steal student data and disrupt schools during final exams.
bleepingcomputer.com
US govt seeks Instructure testimony on massive Canvas cyberattack
The U.S. House Committee on Homeland Security is calling on Instructure executives to testify about two cyberattacks by the ShinyHunters extortion group that targeted the company's Canvas platform, allowing threat actors to steal student data and disrupt schools during final exams.
196
Reposted by Sergiu Gatlan
BleepingComputer @bleepingcomputer.com · 08/05/2026
The attack on the Trellix source code repository disclosed last week has been claimed by the RansomHouse threat group, which leaked a small set of images as proof of the intrusion. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Trellix source code breach claimed by RansomHouse hackers
The attack on the Trellix source code repository disclosed last week has been claimed by the RansomHouse threat group, which leaked a small set of images as proof of the intrusion.
042
Reposted by Sergiu Gatlan
BleepingComputer @bleepingcomputer.com · 08/05/2026
A new Linux zero-day vulnerability, named Dirty Frag, allows local attackers to gain root privileges on most major Linux distributions with a single command.
bleepingcomputer.com
New Linux 'Dirty Frag' zero-day gives root on all major distros
A new Linux zero-day vulnerability, named Dirty Frag, allows local attackers to gain root privileges on most major Linux distributions with a single command.
0174