0:00
Apple adds a click-fixed warning to Mac OS, and Dala hacks Kash Patel's personal email.
0:11
Balance the crypto platform shuts down after last year's hack, and the EU proposes a ban
0:16
on AI-neutrify apps.
0:19
This is The Risky Bulletin, prepared by Ketlin Kimpanu and read by me, Claire Eard.
0:25
Today is the 30th of March, and this podcast episode is brought to you by Knock Knock.
0:30
In today's top story, Apple has added a warning about click-fixed attacks to Mac OS.
0:36
Users will see an alert anytime they copy-paste commands from a browser into the terminal window.
0:41
The click-fixed technique became popular in 2024. It relies on tricking users into running malicious
0:47
commands. It initially targeted Windows, but expanded to Mac OS last year.
0:53
In other news, Iranian hackers have breached FBI Director Kash Patel's personal Gmail account.
0:59
The Handala Hacking Group has taken credit and leaked some of Patel's emails.
1:05
The FBI confirmed the breach on Friday.
1:07
Previous reports have linked the Handala Group to Iran's intelligence service, the MOIS.
1:14
The European Commission is investigating a hack of its website and cloud infrastructure.
1:19
The Shiny Hunters Hacking Group claims to have stolen more than 350 gigabytes of data from
1:24
the Commission's AWS environment. The group says stolen material includes email server dumps,
1:31
databases, internal documents and contracts. The commission also suffered a separate hack in
1:36
January. That incident was via its Avanti mobile device management server.
1:42
The Balancer DeFi platform has shut down months after hackers stole $110 million.
1:48
The company cited increased legal liability after the hack in November last year.
1:53
The company will continue operating its token.
1:57
Thread Actors are launching attacks against a recently patched vulnerability in Citrix
2:02
net-scaler devices. Watched our labs spotted exploitation in Honeypots last week,
2:07
days after the patch was made available. The vulnerability allows attackers to leak data from memory
2:13
similar to the earlier Citrix bleed attacks. Citrix has yet to confirm the activity.
2:19
Hackers have breached US Health Record Provider Care Cloud. The incident earlier this month
2:25
impacted one of the company's six electronic health record platforms. The company says it evicted
2:30
the attackers eight hours after they gained access. The fifth incarnation of breach forums has been
2:37
hacked just days after its launch. The Shiny Hunters Group has leaked registration data and
2:42
private messages of more than 340,000 users. The group was involved in earlier iterations of
2:49
the site. It said it will hack and leak any future versions. It deems fake.
2:55
A UK man has accused his estranged wife of stealing $176 million worth of crypto assets.
3:02
Ping Fire UN claims his wife used a security camera to record his crypto wallet password.
3:07
She then emptied his wallet. Ping presented the court with an audio recording of his wife
3:12
planning the hack with her sister. The funds have not moved since being stolen.
3:18
A ransomware attack has crippled the Jackson County Sheriff's Department in Indiana. The attack
3:23
took down the Wi-Fi network, the police report filing system and all of the department's computers.
3:29
The incident occurred last week and has been traced back to a malicious file received via email.
3:34
The department website was still down on Monday. Hackers have inserted malicious
3:40
code into the desktop client of Chinese web dev service API Fox. The attackers compromised
3:46
Java script files hosted on the app's CDN. According to security firm Slow Mist,
3:52
the code stole users credentials and left a backdoor.
3:56
Hack and Group team PCP has backdoored the Python library of a voice AI provider.
4:02
The hack against TelNix impacted the company's official SDK on the PyPy Portal.
4:07
Team PCP has breached thousands of organisations this month in an ongoing supply chain attack.
4:14
Europe has proposed an amendment to its AI Act that would ban nudify apps.
4:19
The law would cover any app that creates sexualised deepfakes without consent.
4:24
Earlier this year, XAI's GROC generated explicit images of women and children
4:29
leading to public demand for regulation. EU lawmakers have been instructed
4:34
to leave their phones at home when travelling to China next month.
4:38
The commission's security team cited concerns over possible hacking attempts.
4:42
Lawmakers will receive burner phones and laptops for the Beijing visit.
4:47
NSA and Cybercommands new chief has told staff to increase intelligent sharing with allies.
4:54
General Josh Rudd has also instructed staff to keep a close eye on China and Russia,
4:59
even though the White House has prioritised the southern border.
5:02
The directors were part of General Rudd's first NSA or hands meeting.
5:08
A second Russian APT group has started using the Darksword iOS hacking framework.
5:13
Spear-fishing emails lowered Lithuanian victims to sites hosting the exploit kit.
5:18
Proofpoint says it's linked the emails to the Russian FSB Intelligence Service.
5:23
Darksword was previously spotted being used by a unit from Russia's military intelligence service.
5:29
The US State Department is offering rewards of up to $10 million for information on Iranian
5:36
hacking groups. It's seeking information on groups, acting in support of Iran,
5:41
such as Handala Hack and Parjan Afsaray and Borner.
5:45
The department is interested in group members' names and locations.
5:51
A social media disinformation campaign is telling Taiwanese audiences that the Iran conflict
5:56
would deplete the country's LNG reserves. The campaign was traced back to a cluster of accounts
6:02
based in China. Taiwan's Minister of Economic Affairs said the claims were untrue.
6:07
A similar campaign also targeted Australian audiences. That one was linked to an Iranian news
6:12
agency. And finally, threat actors are hacking corporate networks via a vulnerability in F5
6:19
big IP devices. The attacks exploit a remote code execution bug that was patched as denial of
6:25
service in October last year. On Friday, Sissel warned federal agencies about the attacks
6:31
and ordered them to install patches by the end of Monday.
6:35
And that is all for this podcast edition. Today's show was brought to you by Knock Knock.
6:39
Find them at Knock Knock. That's K-N-O-C-K-N-O-C.io.