The Internet Archive was breached twice by the same threat actor — first when an exposed GitLab configuration file (publicly accessible for nearly two years) enabled theft of 33 million users’ records, then again through a Zendesk support token that was among the leaked GitLab secrets and was never rotated, exposing 800,000 support tickets dating […]
Blog
Chinese Hackers Hijack US Telecom Networks via CALEA Backdoors | HN 41
Chinese state-backed hackers (Salt Typhoon) breached the wiretap systems of AT&T, Lumen (formerly CenturyLink), and Verizon — gaining access through the legally mandated CALEA backdoors that US law has required telecoms to build into their infrastructure since 1994. The breach represents the security community’s long-predicted outcome: a backdoor built for law enforcement becomes a backdoor […]
Kaspersky Auto-Removes Itself, Installs UltraAV Overnight | HN 40
Kaspersky quietly uninstalled itself from US customers’ computers on September 19, 2024 — and silently installed UltraAV in its place. No consent prompt. No opt-out. Users woke up to find a different antivirus on their machines. The cause: a US government ban on Kaspersky’s Russian-linked operations, which forced the company out of the American market […]
Apple Drops NSO Lawsuit: Spyware Market Too Fragmented to Win in Court | HN 39
Apple is dropping its three-year-old lawsuit against NSO Group, the Israeli maker of Pegasus spyware — not because it won, but because winning no longer matters. The spyware market has proliferated so dramatically that eliminating NSO would simply clear space for dozens of competitors who would continue the same attacks, potentially armed with detection-evasion insights […]
NGate Android Malware Clones Tap-to-Pay Cards via NFC Relay | HN 38
ESET researchers discovered NGate — an Android malware that weaponizes NFC technology to steal tap-to-pay data from physical credit and debit cards and relay it to an attacker’s device. The attack chains social engineering, phishing, and NFC relay together, ending with fraudulent ATM withdrawals using a victim’s cloned card — no physical card theft required. […]
OpenAI Blocks Iran’s Storm 2035 AI Election Propaganda Operation | HN 37
OpenAI banned accounts linked to Iran’s covert influence operation Storm 2035, which used ChatGPT to generate social media content targeting the US presidential election from both sides of the political spectrum. Simultaneously, Google disrupted APT42 (linked to Iran’s IRGC) spear-phishing campaigns aimed at US presidential campaign accounts. Nation-state actors are using AI to scale election […]





