Risky Bulletin: Russia starts blocking DoH and DoT
In other news: NoName057 leaks data on Spanish police and military; China and South Korea detain vishing gang; AI malware is not that common.
This newsletter is brought to you by Push Security. You can subscribe to an audio version of this newsletter as a podcast by searching for "Risky Business" in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here.
Russian internet users started reporting issues with connecting to DNS-over-HTTPS (DoH) and DNS-over-TLS (DoT) servers, suggesting the government might have cracked down on the two protocols.
Both DoH and DoT are privacy-centric versions of the DNS protocol that hide a user's DNS queries and intended destination from ISPs and other threat actors on the wire.
Both protocols have seen increased usage in Russia. They are typically used together with a VPN client as a way to bypass the Kremlin's ever-increasing and overbearing internet censorship, and access Western websites.
The bans cover Cloudflare's 1.1.1.1 and Google's 8.8.8.8 DNS servers.
Although blocks have been reported across several regions, the Roskomnadzor has not confirmed an official block—but they rarely ever do, to be honest.
The agency seems to have tested the block earlier this year, in March, on the network of Beeline, one of the country's largest telcos. While the ISP denied the block, there were enough tech experts to catch and document what happened at the time.
Even before its invasion of Ukraine and the tightening of internet control, the Roskomnadzor said it was planning to block any protocols that hid a user's intended destination, naming DoH as a prime candidate back in 2021.
Russia started blocking DoT and DoH for it's citizens. Rejoice, this couldn mean we'd see less war criminal animals posting online (hopefully).
— Dredgen Dale (@xn--eck9c3e.zone) August 25, 2026 at 4:05 PM
Risky Business Podcasts
In this edition of Between Two Nerds, Tom Uren and The Grugq talk about whether the increasing use of AI will make it harder for forensics teams to determine who is responsible for a hack.
Breaches, hacks, and security incidents
Hackers target high-ranking EU officials: Foreign state-sponsored hackers have tried to hack the messaging accounts of high-ranking European Union officials, according to a closed CERT-EU presentation. Details are muddy, but this appears to be related to Russia's Signal and WhatsApp phishing ops from earlier this year. [Politico Europe]
ReliaQuest denies ShinyHunters hack: Security firm ReliaQuest has denied getting hacked by ShinyHunters after the group listed its name on its dark web leak site over the weekend. The company says the group phished one employee and accessed an Okta backend in view-only mode. ReliaQuest said the hackers repeatedly tried to access apps in the backend but were always denied. [ReliaQuest]

DDoS attack targets Norway's government network: A massive DDoS attack has crippled the services of Digdir, an IT provider for the Norwegian government. The attack prevented users from logging into government portals for a few hours on Monday. [Digdir]
NoName057 leaks data on Spanish police and military: A pro-Kremlin hacktivist group has leaked the names of nearly 1,000 members of the Spanish military and police forces. A group known as NoName057 leaked the data on Telegram, citing Spain's support for Ukraine. Authorities believe the data was compiled and released by Enrique Arias Gil, a former Spanish university professor who joined the group to help spread its content to Spanish speaking audiences. Gil fled to Russia after Spanish authorities issued an arrest warrant in his name last year. He has since filed for Russian citizenship. [Estrella Digital] [h/t Lukasz Olejnik, KitsuneK]
Autism Services of Saskatoon ransomware incident: The Autism Services of Saskatoon in Canada has notified 2,100 individuals whose data was stolen in a ransomware attack last year. The stolen data included names, dates of birth, addresses, social insurance numbers, medical information, and credit card information. The agency says it restored its servers a day after the attack. It says it monitored the dark web but didn't find any leaks of its data. [CBC // Saskatchewan Information and Privacy Commissioner] [h/t Alex Rudolph]
Paylogix ransomware attack: And speaking of old ransomware attacks, employee benefits platform Paylogix has disclosed its Akira ransomware incident from last year. [The Record]
Nutex Health data breach: American healthcare provider Nutex Health says hackers breached its internal network and stole confidential and sensitive data. The company disclosed the breach to the SEC but did not provide any other details. Nutex operates 27 medical facilities across 12 US states. [SEC filing // MiniChart]
General tech, AI, and privacy
Internet is drowning in AI: Almost a third of all internet web pages published since ChatGPT was released in 2023 are now written using AI. [Pew Research]
AliExpress fingerprints users using inaudible sounds: Chinese online retailer AliExpress is using inaudible sounds to fingerprint website visitors. Security researcher Matthew Callaghan spotted the hidden behavior after his Bluetooth headphones stopped working when visiting the site. Callaghan says the technique is one of several the retailer is using on its sites. [ArsTechnica // Laserphile]
Granular per-app controls coming to Windows 11: Microsoft is testing granular per-app access control features in a Windows 11 Insiders build. The controls will allow users to grant access to their microphone, camera, and location data on a per-app basis, similar to smartphones. [Microsoft]
WhatsApp adds new security features: Meta has added two new security features to its WhatsApp IM, such as more background context for new callers and a stronger one-time passcode, which was updated from a six-digit code to a full password format. [Meta]

Government, politics, and policy
US Treasury sanctions more Iran hackers: The US Treasury Department has imposed new sanctions on Iranian hackers as part of what officials have described as an Economic D-Day against the Tehran regime. Sanctions were imposed on individuals working for the Tehran-based Mabna Institute, a cyber contractor for the Iranian government. The sanctions come a week after the Justice Department unveiled a superseding indictment that charged additional individuals involved with the group. [US Treasury // OFAC // CyberScoop]
US Navy tells sailors to improve opsec: The US Navy has told sailors, reserves, and civilian staff to remove any mentions of their military ties from social media. The security alert applies to the members directly, but also to family members. The Navy fears social media accounts could be used to trace military movements or for physical attacks on sailors and their families. [Military.com // US Navy alert, PDF]
MSS tells agencies to uninstall Windows 10: China's internal security service has told state agencies to uninstall Windows 10 and move systems to Chinese-run Linux distros. State agencies are running a version of Windows 10 customized by Chinese company C&M Information Technologies. The company was planning to retire the operating system from use in February next year. Windows 10 reached end-of-life in October of last year. The Chinese government ordered state agencies to phase out US technologies due to national security risks. [Bloomberg] [h/t covid26]
UK wants new amendment to Cyber Security and Resilience Bill: The UK government wants to modify one of its cybersecurity bills in the aftermath of an Iranian hack that forced a power plant offline for four days last month. Under a new amendment to the Cyber Security and Resilience Bill, the government wants to ban companies in critical sectors from buying products from foreign adversaries. The bill was proposed in 2024 and is under parliamentary review after its second reading. [Financial Times]
New Zealand to ban <16 from social media: New Zealand's government has proposed a law to ban children under the age of 16 from social media. The bill would require platforms to screen a user's age. [Stuff]
Sponsor section
In this Risky Business sponsor interview, James Wilson chats with Push Security’s VP of Research Luke Jennings about how stronger authentication is pushing attackers towards the authorization layer.
Arrests, cybercrime, and threat intel
China and South Korea detain vishing gang: Chinese and South Korean police forces have disrupted a voice phishing group operating out of China. According to authorities, the group stole more than $7.2 million from elderly South Koreans by calling and posing as police officers and credit card delivery drivers. Police arrested ten suspects, six South Korean and four Chinese. [Yonhap News]
ATM jackpotter sentenced to 8 years: A US court has sentenced a Venezuelan man to eight years in prison for his role in an ATM jackpotting scheme. Juan Manuel Gouveia-Aguilera worked with multiple accomplices to deploy the Ploutus malware on ATMs in the United States. The group stole more than $3.5 million. Gouveia-Aguilera received the longest ATM jackpotting-related sentence in US history. [DOJ]
Operation Jackal IV: A global law enforcement led by Interpol has dismantled multiple West African criminal networks involved in cyber scams, BEC, and violent crimes. Police forces in 22 countries have detained 58 individuals and identified 263 other suspects involved in the crimes. Some of the suspects were linked to Black Axe, a notorious Nigerian criminal syndicate. [Interpol]
Major Nigerian scam operation uncovered: A Nigeria-based investment scam operation has defrauded more than 5,000 investors of almost $74 million. The group is behind more than 300 fake investment portals. Norwegian journalists say the sites share source code and are hosted on the servers of Nigerian web hosting company iSkySoftic. NRK reporters believe the company's CEO might be directly involved in the operation because his online nickname was found on some of the scam portals. [NRK] [h/t Martin Gundersen]
NSA TAO impersonator arrested: US authorities have detained a man who impersonated the head of the NSA's offensive hacking unit and a Supreme Court justice. Joshua Culver posed as the head of the NSA's Tailored Access Operations team in an attempt to have a case dismissed in Lake County, Indiana. He also posed as a regular NSA officer in an earlier incident and as Supreme Court Chief Justice John Roberts. [CyberScoop]
BRIDGEHEAD: A cluster of 40 npm packages typosquatting more popular ones are using the Windows Subsystem for Linux to deploy a Rust-based infostealer on Windows hosts outside the reach of security tools. [CloudSEK]
CERT-FR tells Apple spyware victims to reach out: France's cybersecurity agency has urged users who received Apple mercenary spyware notifications to contact the country's CERT. [CERT-FR // CERT-FR tweet]
ClickFix campaign abuses npm: A ClickFix campaign is using the npm repo as a mirror to store some of its resources. The 24 packages in this campaign are benign when installed on their own. [Ox Security]
AI malware is not there yet: The vast majority of malware that integrates AI technology is at an experimental and proof-of-concept stage. A Palo Alto Networks study of over 405 AI malware samples has found that only 12 were detected in real-world infections. The rest were found only in security testing sandboxes and VirusTotal, and appear to be tests or security research. [Palo Alto Networks]
"The gap between the volume of AI malware samples in public repositories and the volume observed in production environments reflects the current state of AI-enabled threats. AI lowers the barrier to creating malware, and the number of samples in our dataset confirms that many people are experimenting with the technique. But creating a sample and successfully deploying it against a defended environment are different problems, and malware authors have not to date succeeded at using AI to solve the second one."
Supply chain attacks intensify: A supply chain attack has taken place this year every three days, according to a new report published by DevSecOps firm Step Security. Fifty of the 56 supply chain attacks that took place since August 2025 happened this year. Most were powered by self-replicating worms. [Step Security]

Malware technical reports
Rhysida ransomware decrypted: Adam Taguirov of Sigreturn claims he broke the Rhysida ransomware gang's encryption back in 2023, a year before South Korea's KISA did it. [Sigreturn // 2024 KISA decrypter // Adam Taguirov tweets]
Play (aka PlayCrypt) ransomware: Researchers look over the tactics of the Play/PlayCrypt group, a double-extortion ransomware operation that's been around since 2022. [GuidePoint Security]
SLEEPWALKER: Security researcher Dominik Reichel has discovered a super-advanced and stealthy backdoor that comes with its own command language. The SLEEPWALKER malware was found on VirusTotal and it's unclear who developed it and where it was used. The malware works as an implant on infected systems where it waits for specifically crafted network packets to activate. The packets carry commands in a custom language to be executed on the infected hosts. [Dominik Reichel]
ZeroTokens PhaaS: There's a new phishing platform available to cybercriminals that specializes in running real-time phishing campaigns, where the threat actor is at the keyboard or on the phone with a victim and guiding them through the phishing process. [AbnormalAI]
AnonyMousKIT PhaaS: A threat actor is renting access to a new phishing kit designed to collect special authorization codes from Apple users who had their iPhones stolen. The collected codes are used to disable Apple's Activation Lock feature, wipe the device, and prepare it to be resold. The AnonyMousKIT has been active since 2024 and has been linked to more than 500 malicious phishing domains. According to SOCRadar, the kit uses AI voice agents to automate calls to iPhone owners and pose as Apple support. [SOCRadar]
WeedHack returns: A new campaign spreading the WeedHack infostealer to Minecraft players has been spotted in the wild, leveraging SEO poisoning to lure users on Minecraft-themed malicious sites. [McAfee]
ERMAC to HookBot: Censys researchers have published a report on the evolution of how the HookBot Android banking trojan has evolved from the leak source code of the ERMAC strain, which itself is an evolution from Cerberus. [Censys]

Sponsor section
In this wholly sponsored Soap Box edition of the show, Patrick Gray chats with Adam Bateman and Luke Jennings from Push Security.
APTs, cyber-espionage, and info-ops
Armenian disinformation: DFRLab takes another look at the gigantic, and sometimes ridiculously idiotic, wave of Russian disinformation that targeted Armenia ahead of its June parliamentary election. [DFRLab]
Vulnerabilities, security research, and bug bounty
Security updates: Adobe, DrayTek, FreeBSD, Notepad++, OpenSSL, Shopware, Sonicwall.
WP force-pushes plugin security update: The WordPress security team has force-pushed a security update for the Pods third-party plugin. The emergency update fixes a bug that lets remote attackers gain admin rights over WordPress sites. The Pods plugin is installed on more than 100,000 sites. The forced-update system has been in the WordPress code for almost a decade but is only used for serious vulnerabilities. [Wordfence // Pods changelog]
Oracle bug enters exploitation: Hackers are exploiting an Oracle WebLogic vulnerability to gain access to corporate environments. The attacks are targeting an WebLogic bug patched back in January. The vulnerability allows attackers to modify or steal critical data from WebLogic servers. [CISA // CVE-2026-21962]
SharePoint RCE chain write-up: Security researchers have published a write-up on two SharePoint bugs that can be chained for RCE attacks. One of them, CVE-2026-55040, has already been reported as exploited in the wild last week after POC code was published online. [VulnCheck // Rapid7 // Rapid7]
Infosec industry
Threat/trend reports: Fable Security, Palo Alto Networks, Pew Research, Step Security, and Zimperium have recently published reports and summaries covering various emerging threats and industry trends.
Minimus shuts down: Israeli cybersecurity startup Minimus has shuttered operations and is returning the remaining funds to investors. The company raised $51 million but failed to acquire enough customers. The company provided distroless and security-hardened container images. Existing clients will have 60 days to move to a new platform. [CTech // Minimus]
New tool—Fortitool: Security researcher Ali Mosajjal has released Fortitool, a tool to decrypt and unpack Fortinet FortiOS firmware.
New tool—WinFlesher: Security researcher Mindsflee has published WinFlesher, an attack surface security assessment framework designed to analyze, evaluate, and report on security postures, attack paths, and remediation strategies in complex environments.
Risky Business podcasts
In this episode of Risky Business Features, James Wilson chats with PortSwigger’s Director of Research James Kettle about using an LLM to develop genuinely new attack techniques.