Ryan Gallagher
@rjgallagher.co.uk
3.8K followers 420 following 58 posts
Investigative reporter @Bloomberg.com covering technology & cybersecurity. Anonymous tips: https://tips.hushline.app/to/ryan Email: [email protected] Signal/WhatsApp: +44 737-678-6842
Posts Media Videos Starter Packs
rjgallagher.co.uk
In 2012, yes! Microsoft accused a company called Hangzhou DPtech Technologies of leaking a Windows vulnerability and booted it out of MAPP
rjgallagher.co.uk
Victims of the SharePoint attacks, which were first detected on July 7, now total more than 400 government agencies and corporations worldwide, including the US's National Nuclear Security Administration, the division responsible for designing and maintaining the country's nuclear weapons.
rjgallagher.co.uk
Some of the Chinese companies that are involved in MAPP are also members of a Chinese government vulnerability reporting program, the China National Vulnerability Database, which is operated by the country’s Ministry of State Security.
rjgallagher.co.uk
Microsoft has attributed SharePoint breaches to state-sponsored hackers from China, and at least a dozen Chinese companies participate in the alert sharing initiative, called the Microsoft Active Protections Program, or MAPP.
rjgallagher.co.uk
New: Microsoft is investigating whether a leak from its early alert system for cybersecurity companies allowed Chinese hackers to exploit flaws in SharePoint before they were patched, enabling a global campaign of cyberattacks, according to people familiar: www.bloomberg.com/news/article...
Microsoft Probing If Chinese Hackers Learned of Flaws Via Alert
Microsoft Corp. is investigating whether a leak from its early alert system for cybersecurity companies allowed Chinese hackers to exploit flaws in its SharePoint service before they were patched, acc...
www.bloomberg.com
rjgallagher.co.uk
A whistleblower shared 1 million two-factor authentication codes that had been sent to people by SMS from the world's largest tech companies, such as Google, Meta, & Amazon. We found the codes had been routed via an obscure Swiss company with links to spy agencies: www.bloomberg.com/news/article...
How a Tiny Middleman Could Access Two-Factor Login Codes From Tech Giants
An investigation into the complexity of the global telecom system shows weaknesses in the transmission of secret codes sent via SMS.
www.bloomberg.com
rjgallagher.co.uk
Portugal's National Cybersecurity Centre says: "There is no evidence to date pointing to a cyberattack. We would like to draw attention to the circulation of disinformation that occurs in these situations, and we therefore advise that every information should be confirmed with reliable sources."
rjgallagher.co.uk
Initial probe into cause of power outages in Spain & Portugal today suggests fault rather than cyberattack, according to the European Union Agency for Cybersecurity (ENISA). “For the moment the investigation seems to point out to a technical/cable issue,” a spokesperson for the agency tells me.
rjgallagher.co.uk
The end result is that Ukraine's digital front lines are weaker now, making the country an “easy target” for Russia, said Yegor Aushev, a Kyiv-based cybersecurity expert. The “sudden & unannounced shutdown” of cyber operations, he said, “has created a significant challenge.”
rjgallagher.co.uk
“Many projects were stopped halfway, contractors were let go before finishing their work, & a lot of plans didn’t get the chance to reach their full potential,” Mankish said.
rjgallagher.co.uk
Andrii Mankish, a Ukrainian cybersecurity expert who worked on US-funded projects to identify Russian hacking attempts, said the US's cyber pullback was likely to “impact our efforts & slow down progress in key areas.” Long-planned cybersecurity projects had suddenly ended, he said.
rjgallagher.co.uk
That work is now paused & it's unclear whether it will resume -- Ukrainians say they have been left in the dark. Equipment & services that were to be provided to the country for ongoing initiatives, such as a project to strengthen the country’s central election commission, are now not going ahead.
rjgallagher.co.uk
US cybersecurity assistance had included specialist support, training, equipment & software to organizations across Ukraine, including to dozens of government offices & departments & to key gas & electricity providers, the national bank & nuclear facilities such as Chernobyl.
rjgallagher.co.uk
New: US cuts to foreign aid are impacting Ukraine's cybersecurity. Dozens of people have had to stop work protecting the country from Russian hackers & shipments of vital cyber equipment have stopped, according to people familiar with the situation: www.bloomberg.com/news/article...
US Aid Pullback is Making Ukraine More Vulnerable to Russian Hacks
American cybersecurity assistance has been crucial to helping war-torn country fend off hacks, experts say.
www.bloomberg.com
rjgallagher.co.uk
Awesome news Will, congrats!
rjgallagher.co.uk
A UK court has blocked the UK government's attempt to keep secret a legal case over its demand to access Apple users' encrypted data. Judges said in a ruling Monday that authorities’ efforts were a “fundamental interference with the principle of open justice”: www.bloomberg.com/news/article...
UK Effort to Keep Apple Encryption Fight Secret Blocked in Court
A court has blocked a British government attempt to keep secret a legal case over its demand to access Apple Inc. user data in a victory for privacy advocates.
www.bloomberg.com
rjgallagher.co.uk
Researchers find evidence suggesting spyware from Israeli firm Paragon has been obtained by Australia, Canada, Cyprus, Denmark & Singapore. The technology - used to hack phones & read private msgs - was recently linked to hacks of Italian journalists & activists: www.bloomberg.com/news/article...
Paragon Spyware Tool Linked to Canadian Police, Watchdog Says
A Canadian law enforcement agency is suspected to have used spyware designed to hack into mobile phones and eavesdrop on messages, according to cybersecurity researchers from the University of Toronto...
www.bloomberg.com