Risky Bulletin: Sanctions force CAs to revoke TLS certs in Iran, Russia

In other news: ShinyHunters member arrested in the Netherlands; Apple fixes iOS zero-day found by Meta; Citrix zero-days see mass exploitation within hours.

Share
Risky Bulletin: Sanctions force CAs to revoke TLS certs in Iran, Russia

This newsletter is brought to you by PortSwigger. You can subscribe to an audio version of this newsletter as a podcast by searching for "Risky Business" in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here.

For the past three months, certificate authorities have revoked TLS certificates for government and critical sector entities in countries sanctioned by the US.

Disruptions to government networks, agencies, and the banking sectors have been reported in Russia and Iran.

GlobalSign mass-revoked TLS certs for Russian customers in June and Russian banks had to switch to a state-run certificate authority in August to keep their apps and websites running.

Similar issues were reported in Iran where the state-run news agency was refused by all major SSL providers in July and Iranian banks had to switch to Chinese providers to keep their sites online this month.

All the issues trace back to new US Treasury sanctions issued in May that tightened the noose around services provided in countries the US sees as adversaries.

As Let's Encrypt explained it in June, Certificate Authorities are still allowed to issue certs in those countries, but only to "non-governmental people and organizations." Everything else is prohibited.

"Under applicable sanctions, we are not permitted to issue certificates to certain prohibited or restricted parties. However, there are critical authorizations designed to promote the continued availability of Internet communication services that we rely on to provide services to permitted users in sanctioned countries and territories.
These exemptions and authorizations allow services like Let’s Encrypt to issue certificates to non-governmental people and organizations in several of the comprehensively sanctioned countries and territories. As a result, we have not, and do not, block the use by non-governmental people and entities in comprehensively sanctioned countries and territories where those exemptions and authorizations are in place."

For the most part, companies and government agencies in both Russia and Iran have dealt with the TLS cert bans pretty well. While they faced short outages, they often quickly realized that they can't renew TLS certs anymore and switched to home alternatives.

The actual issues have been passed down to consumers, who still use Western-made operating systems and browsers, which typically don't trust the local and state-run CAs to which banks and government agencies switched.

Risky Business Podcasts

In this edition of Between Two Nerds, Tom Uren and The Grugq talk about the rise of fully automated LLM-driven hacking campaigns among criminals and even state hacking groups. For those with the right risk appetite, a move fast and break things hacking approach using AI can pay off.


Breaches, hacks, and security incidents

Hackers exploit security product in Bitget crypto-heist: Hackers exploited a zero-day in a third-party security product to breach cryptocurrency platform Bitget last week. The attackers extracted valid admin credentials from the device and then pivoted to the platform's internal network. Bitget says the hackers injected fraudulent withdrawal commands and then deleted their tracks after stealing $388 million worth of assets. [The Block]

Belnet hack: Hackers have used a zero-day to breach Belgian internet service provider Belnet and steal email inboxes. The attacker stole emails sent to Belnet itself and one of its customers between July 22 and the morning of September 25. Belnet says it's working with authorities to investigate the hack. The company is a government-funded internet provider that caters to the Belgian government, educational institutions, and science and research centres. [Belnet]

Arizona courts hit by cyberattack: Hackers have breached the Arizona courts system and copied backup court files. The Arizona Supreme Court disclosed the breach on Friday. Most of the stolen files are considered public. The personal data of "many Arizonans" was also stolen but the Supreme Court didn't provide a number of affected individuals. [Arizona Courts // Arizona Courts, PDF]

MEP sues NSO over hacks: Former MEP Stelios Kouloglou has sued four executives from Israeli spyware maker NSO Group over the hacking of his phone with the Pegasus spyware. [DNews // Middle East Monitor]

General tech and privacy

Open Agent Safety Platform: NVIDIA has launched a new sandboxing platform to secure AI agents and prevent incidents like the HuggingFace hack. The Open Agent Safety Platform will provide AI companies with secure runtimes and out-of-band monitoring technologies to keep AI agents in their containers and keep tabs on what they're doing. All the major AI frontier labs and 100 other tech companies have pledged their support for the platform. [NVIDIA]

Muse is a dox machine: Apparently, you can use Meta's new Muse AI agent for doxing internet users, if they left enough of a trail online. [Hunterbrook]

Firefox 157: Mozilla has released Firefox 157. New features and security fixes are included. The biggest feature in this release is the new Nova UI, a major redesign of the Firefox browser user interface.

Government, politics, and policy

Pentagon unleashes Cyber Command on election threats: The Pentagon has directed US Cyber Command to prioritize and deploy its cyber capabilities against foreign threat actors seeking to interfere in the US midterm elections. [Department of War]

Agencies sabotage GAO's DOGE investigation: Six US federal agencies refused to provide records to a US government watchdog investigating DOGE activity. Two agencies, the SEC and NOAA, claimed that GAO did not have the authority to investigate DOGE. GAO says it's still unclear the level of access DOGE had to US government networks and if secure access rules were followed. [GAO // NextGov]

Meta blocks Lulla's election ads: Social media giant Meta pulled down Brazilian President Lula's Facebook page and blocked his campaign from running political ads while also allowing paid ads calling for a military coup. The move came a week before the first round of the general election. In August, a report found that Meta was also not removing election-related disinformation. Election meddling and ad revenue, Meta's current sole purpose for existence. [Metropoles // Novara Media // Panamerican Dispatch // Amnesty International]

China expands AI travel bans: The Chinese government has expanded its travel ban for AI executives and top engineers to also cover family members. [Bloomberg]

Sometimes we forget the difference between free societies, and not.

[image or embed]

— Kevin Hardiman (@kevinhardiman.bsky.social) September 28, 2026 at 1:55 PM

In this Risky Business sponsor interview, James Wilson chats to Kieron Hughes and Andrzej Matykiewicz from PortSwigger about the company’s latest AI pen-testing product, Burp AT. 

Arrests, cybercrime, and threat intel

ShinyHunters member arrested in the Netherlands: Dutch authorities have arrested a suspected member of the ShinyHunters hacking group. Dutch police detained Pepijn Van der Stap, a 24-year-old hacker who went on hacking forums as Umbreon. He was arrested on September 16, days before the group tried to extort the FBI. Van der Stap was out on probation from prison after serving almost three years from a previous hacking-related sentence. In a video message, the FBI described him as one of the group's leaders. It also encouraged other ShinyHunters members to rat-out their friends or get arrested. Dutch police are investigating Van der Stap for attempting to arrange two murders. [RTL // DataBreaches.net // KrebsOnSecurity // FBI // RTL]

A spokesperson for ShinyHunters, the prolific cyber extortionists who hacked the FBI's job portal last week, tells me they now won't release any more data from that hack. They also sent this somewhat confusing statement that indicates they maybe think they've bitten off more than they can chew.

[image or embed]

— Kevin Collier (@kevincollier.bsky.social) September 28, 2026 at 11:12 PM

Two UK telcos under investigation: The UK's communications watchdog has launched an investigation into two telecom providers for failing to prevent their phone numbers from being misused by scammers. Ofcom says Vonage Business Limited and Voxbone SA have failed to implement Know-Your-Customer checks when allocating phone numbers. The numbers were later used for scam calls and texts. [UK Ofcom]

US Air Force members sentenced to prison for scams: A US judge has sentenced two Delaware men to 111 and 78 months in prison for a BEC scheme. Chijioke Timothy Odimegwu and Harafat Mogaji broke into business email accounts and hijacked payments from business partners. Both were members of the US Air Force at the time of their crimes. [DOJ]

Vietnamese charged for pig-butchering scams: The US Justice Department has charged a Vietnamese national for defrauding victims as part of crypto investment scams. Trung Nguyen Van engaged in fictitious romantic relationships with victims and duped them into making crypto investments through malicious platforms. He allegedly received more than $53 million from scams, with more than $16 million from one victim alone. [DOJ]

npm malware adds users to WhatsApp channels: A cluster of 101 npm libraries are secretly enlisting users into WhatsApp spam channels. The libraries are abusing the Baileys WhatsApp open source library to secretly interact with a victim's account. The campaign has been going since August and most of the spam channels are run out of Indonesia. [Ox Security // Xygeni]

Another threat actor open directory leak: Over the past months, security researchers have learned to find open directories with threat actor tooling. The latest of these findings is from a suspected Chinese threat actor using the leaked Coruna iOS exploit kit. [C2 Hunters Research]

Malicious browser extensions: Security researchers have discovered a cluster of more than 30 malicious Chrome extensions posing as financial advice tools. The extensions use a dual structure where they show benign behavior to scanners and reviewers but redirect real users to phishing sites. The extensions are available on the Web Store, and some are still active. [Akamai]

Text salting grows 9x: Threat actors are using text salting techniques to hide malicious emails and get them passed AI security filters. The technique involves using large blocks of benign text that are only visible to AI and security tools but invisible to humans. The large text hides malicious phishing lures, which remain visible to human operators. According to email security firm Ironscales, text salting usage grew nine times in the first half of the year, compared to last year. [Ironscales]

Custom GPT abuse: Security firm Huntress is investigating at least 40 incidents where threat actors used a new ChatGPT feature named Custom GPT to create personalized versions of ChatGPT. These malicious ChatGPT versions have been spotted redirecting users through modified prompts to malicious sites. [Huntress]

Nigerian scammer campaign: Proofpoint look at a scammer group operating out of Nigeria that is compromising university email accounts to carry out an assortment of scam activity. [Proofpoint]

Ransomware dip during Xmas: A new academic study has found that the activity of ransomware gangs falls by over 40% around the winter holidays, between 25 December and 15 January. The largest fall in activity is around the Western New Year, with 60% less activity. The research team says the periods of inactivity on public-facing ransomware infrastructure suggests groups are "less automated than commonly assumed." [SSRN]

Malware technical reports

NeedyMantis: Microsoft's security team looks at NeedyMantis, a malware strain used in "a limited number of targeted operations" by a suspected Chinese espionage group. Researchers spotted the malware while pivoting from the Daemon Tools incidents from earlier this year. [Microsoft]

OpenSUpdater: A threat actor is hiding the OpenSUpdater loader inside recompiled open source software tools like 7zip. [G Data]

SIXZUT and JITTERLY: Newly launched security firm VirLabs looks at SIXZUT and JITTERLY, a Linux implant and a rootkit that are being planted by the Red Heron group on Gitea servers. [VirLabs]

RatHat evolution: Cleafy researchers have traced the new RatHat Android banking trojan to the old BlackCat to Panda Workshop strains, of which RatHat is a rebrand, although with a relatively new codebase. [Cleafy]

In this sponsored interview, James Wilson talks with James Kettle and Daf Stuttard from PortSwigger about the new LLM they added to Burp Suite and the window into the future of AI-enabled hacking and security testing.

APTs, cyber-espionage, and info-ops

Mimbrob targets Russia's defense companies: A new cyber-espionage group named Mimbrob is targeting Russia's military industrial complex and IT companies. The group has been sending spear-phishing campaigns since at least April. Mimbrob's malware is coded to run only if Russian and other languages of the former Soviet republics are found on a device, suggesting a very targeted attack. [F6 // F6 on Habr]

Star Blizzard changes tactics: Russian cyber-espionage group Star Blizzard has updated its tactics this year and has moved from targeted spear-phishing attacks to conducting mass-scale phishing campaigns. The attacks have continued to target Ukraine and its allies. The phishing emails are delivering malicious archive files that use virtual hard disks to create scheduled tasks that periodically run the group's malware. Microsoft says Star Blizzard has abandoned ClickFix for this new infection technique. [Microsoft]

Russian info-op runs wild on Twitter: A massive and pretty visible Russian influence operation promoting identical "Russia is not my enemy" messages is going wild on Twitter. Twitter is doing nothing about it. Stuff like this wouldn't be happening right now if authorities would have cracked down on this s**t with huge fines and penalties a decade ago. But no, [insert first amendment bullshit]. [Center for Countering Disinformation]

Vulnerabilities, security research, and bug bounty

Security updates: IBM, Dell, Firefox, iOS, Kiteworks, SUSE, VLC, wolfSSL.

Apple patches iOS zero-day: Apple has released an emergency security update to patch  an actively exploited iOS zero-day. The zero-day allows attackers to run malicious code on iPhones using malicious files. Apple says the zero-day was exploited "in an extremely sophisticated attack against specific targeted individuals on [...] iOS before iOS 27." The zero-day was discovered by Meta's security team. [iOS 26.7.1 and iPadOS 26.7.1]

Kiteworks lifts shutdown recommendation: American software company KiteWorks has released a security fix for its file-transfer platform. The company is telling customers it is safe to reconnect their servers to the internet. Kiteworks told customers to take servers offline last week after it received a warning from law enforcement  agencies that hackers were preparing to launch attacks against its products. [Kiteworks]

Unpatched Authlib bypass: The Authlib Python library has failed to patch an empty-signature-field bug that can allow threat actors to bypass signature verification checks, and possibly bypass OAuth and OpenID authentication operations. [CMU CERT/CC]

New BTR CPU attack: Academics have discovered a new attack that can leak data from modern CPUs. The new Branch Target Reuse (BTR) attack targets just-in-time (JIT) code compilers. It works against JIT engines used in web browsers, language runtimes, and OS kernels. It can leak data from CPUs due to how JIT compilers reuse allocated memory. [VUSec]

PS5 Relapse: Software developer Nathan Fargo has released Relapse, an exploit to jailbreak recent versions of the PS5 firmware. [GitHub]

Citrix zero-days see mass-exploitation within a day: Two recently patched Citrix NetScaler zero-days are seeing widespread mass-exploitation. Attacks began hours after detailed write-ups and POCs were published on Monday. Citrix patched both zero-days over the weekend after attacks were first spotted last week. According to Google, the original attacks last week targeted government agencies, financial services, education and legal sectors in Europe and North America. [GreyNoise // Lupovis // Google // WatchTowr CVE-2026-88771 write-up // WatchTowr CVE-2026-88772 write-up]

Infosec industry

Threat/trend reports: Counterpoint, Pindrop, and Trend Micro have recently published reports and summaries covering various emerging threats and industry trends.

Israeli spyware vendor Paragon to go public: Israeli spyware vendor Paragon will go public through a merger with a Nasdaq-listed SPAC. [Calcalist Tech]

New tool—OperTraitor: Security firm Palo Alto Networks has released OperTraitor, a tool to scan Kubernetes operators for risky RBAC permissions.

New tool—Forge: Cloudflare has open-sourced Forge, a tool for generating SDKs, CLIs, docs, libraries, and more.

Risky Business podcasts

In this episode of Risky Business Features, investigative journalist Geoff White joins James Wilson to talk about what happens to the money after ransomware gangs get a payday.