Metacurity

Metacurity.com (metacurity.com) is the one-stop destination for leading infosec news and cybersecurity developments. Run by infosec writer and columnist Cynthia Brumfield, Metacurity draws from thousands of sources every day to deliver aggregated summaries of the latest infosec developments. If anyone wants to get in touch with me, on or off the record, you can reach me at cynthia [at] digitalcrazytown.com or on Signal via Cynthia.507. Sign up for our free daily emails at metacurity.com/subscribe. Searchable

2025-07-09

I had my browser set to autotranslate, so I read this piece in English (although ironically I can read German too, but perhaps not well on this topic), but if you don't have this feature, here's an English language piece on the hack.

caliber.az/en/post/media-russi

2025-07-09

A satellite firm and an engineering firm that supplies critical technology to Germany's military forces has been reportedly hacked by Russian hackers, although allegedly of the "hacktivist" kind.
tagesschau.de/investigativ/ndr

2025-07-08

How in the heck is it Patch Tuesday again?

Metacurity boosted:
Rick Turoczyturoczy@pdx.social
2025-07-08

With layoffs continuing to impact our community, it seemed like a good time to refresh this primer. If you've been directly impacted by these layoffs, I'm incredibly sorry. That sucks. But we're here for you. siliconflorist.com/2025/07/08/

2025-07-08

The Treasury’s Office of Foreign Assets Control (OFAC) sanctioned Song Kum Hyok (Song), a malicious cyber actor associated with the sanctioned Democratic People’s Republic of Korea (DPRK) Reconnaissance General Bureau (RGB) hacking group Andariel.
home.treasury.gov/news/press-r

Metacurity boosted:
Lorenzo Franceschi-Bicchierailorenzofb@infosec.exchange
2025-07-08

NEW: The chairman of UK retail giant Marks & Spencer refused to say whether the company paid ransom to hackers who caused outages and empty shelves.

“We don't think it's in the public interest to go into that," Archie Norman told UK parliament members.

techcrunch.com/2025/07/08/mark

2025-07-08

The US holiday is a memory now, so time to check out today's Metacurity to get briefed on the most critical infosec developments you should know, including

--Italian cops arrest FBI-wanted Chinese hacker who tried to steal COVID-19 vaccine
--Brazilian cops bust IT worker connected to $100m banking systems hack,
--Call of Duty: WWII yanked offline after RCE rumors,
--OpenAI beefs up corporate spying protections,
--DragonForce battles RansomHub,
--Cambodia accuses Thai hackers of attacks,
--Trump's tax bill contains cyber money,
--Hackers used Shellter Elite product in attacks,
--Researchers release PoC for Citrix NetScaler flaw,
--Nigeria fines pay TV company $500K for violating data protection,
--New ransomware group called Bert emerges,
--287 companies are at high risk of Scattered Spider attacks,
--Vendor to Ballad Health hit with data breach,
--AI protection program Anubis downloaded 200K times,
--New Batavia spyware targets Russian OT enterprises,
--SatanLock ransomware group says hi and bye,
--280K people affected by Nova Scotia Power breach,
--Russian custom drone firmware firm hit with cyberattack,
--Coinbase hacker plays the crypto markets for profit,
--Google to allow GeminiAI to interact with apps,
--Domain Tools offer free grants to needy journos, others,
--Number of malicious open source packages doubled in Q1
metacurity.com/italian-cops-ar

Metacurity boosted:
2025-07-08

For the past few weeks, @DomainTools Investigations worked with OSINT analyst and investigative journalist grantees to help uncover connections between websites involved in the harassment of Ukrainian personnel and their families, and the people and infrastructure involved.

We provide a technical writeup below on the observables and data involved.

#infosec #cybersecurity #threatintel #disinformation

domaintools.com/resources/blog

Metacurity boosted:
Alexandre Dulaunoyadulau@infosec.exchange
2025-07-08

VLAI: A RoBERTa-Based Model for Automated Vulnerability Severity Classification.

This paper presents VLAI, a transformer-based model that predicts software vulnerability severity levels directly from text descriptions. Built on RoBERTa, VLAI is fine-tuned on over 600,000 real-world vulnerabilities and achieves over 82% accuracy in predicting severity categories, enabling faster and more consistent triage ahead of manual CVSS scoring. The model and dataset are open-source and integrated into the Vulnerability-Lookup service.

We ( @cedric and I) decided to make a paper to better document how VLAI is implemented. We hope it will give other ideas and improvements in such model.

#vulnerability #cybersecurity #vulnerabilitymanagement #ai #nlp #opensource

@circl

🔗 arxiv.org/abs/2507.03607

2025-07-08

cyberscoop.com/gop-domestic-po

GOP domestic policy bill includes hundreds of millions for military cyber

Metacurity boosted:
2025-07-08

DOJ Finds Man in Photo with Epstein was Actually Biden

borowitzreport.com/p/doj-finds

2025-07-08

crypto-economy.com/hacker-behi
The hacker who stole $300 million from Coinbase is out there carefully managing trades to capitalize on future bullish cycles.

2025-07-08

therecord.media/cyberattack-ru

“Russian developers behind a custom firmware used to convert consumer drones for military use in Ukraine have reported a cyberattack on their infrastructure, disrupting the system that distributes the software.”

2025-07-08

cyberscoop.com/call-of-duty-re

Call of Duty takes PC game offline after multiple reports of RCE attacks on players

2025-07-08

reuters.com/world/china/italia

Italian police arrest Chinese national wanted by FBI for alleged industrial espionage

2025-07-08
Metacurity boosted:
2025-07-07

Closing hospitals to fund concentration camps.

That’s it. That’s what it boils down to.

Metacurity boosted:
David Graeber InstituteDGI@graeber.social
2025-07-07

Think about this for a moment.

Capitalism has invented 
something called "cost of living" 
where your very existence 
is an ever-inflating expense 
that you must overcome 
to survive.

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst