mathstodon.xyz is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Mastodon instance for maths people. We have LaTeX rendering in the web interface!

Server stats:

2.8K
active users

#espionage

17 posts15 participants1 post today

Spa town spies: Czech church linked to a Kremlin kompromat campaign.

Karlovy Vary is famous for its hot springs – but its Russian orthodox church is a hotbed of spies.

The church was used by operatives from Russia's GRU military intelligence agency for covert meetings and influence operations aimed at destabilising the EU, the Czech Security Information Service (BIS) has revealed.

mediafaro.org/article/20250420

An aerial view of the West Bohemian spa town of Karlovy Vary and its Russian Orthodox Church. |Photo by Marcos del Mazo/LightRocket via Getty Images
Euractiv · Spa town spies: Czech church linked to a Kremlin kompromat campaign.By Aneta Zachová
Continued thread

2/ ...and it just so happens that #PaloAlto released a long investigation into a newer and less well known North Korean crypto operation called "Slow Pisces" and/or "Jade Sleet" at the same time.

This time the #DRPK's crypto thieves pose as recruiters on LinkedIn and try to lure developers into doing various coding challenges hosted on #GitHub as part of a job interview. Doing a challenge leads to infection with custom Python #malware.

unit42.paloaltonetworks.com/sl

Unit 42 · Slow Pisces Targets Developers With Coding Challenges and Introduces New Customized Python MalwareBy Prashil Pattni

1/ Deep dive case study of the kind of open source contributions and #GitHub astroturfing that North Korean hackers employ to try get jobs as devs at crypto companies, this time in an attempt to infiltrate #onlyDust.

tl;dr DPRK hackers use contributions to FOSS projects to build cred, after which, armed with AI video avatars, they try to leverage the cred into success in interviews for blockchain development jobs.

I've said it before but i'll say it again: the one real upside of crypto is that the industry draws close to 100% of the incoming fire from sophisticated #DPRK threat actors like Lazarus Group who would otherwise be hacking banks.

ketman.org/dprk-it-workers-in-

Replied in thread

@randahl and someone from a city in Russia tried to access the newly created Doege accounts 20 or more times within minutes of them being created, but we’re blocked because they NLRB blocks all foreign IP addresses. Otherwise they would have been in. I guess those doesn’t know as much as they think they know about how secure we try to keep our information. This is #espionage #uspol

"The European Commission is issuing burner phones and basic laptops to some US-bound staff to avoid the risk of espionage, a measure traditionally reserved for trips to China.

Commissioners and senior officials travelling to the IMF and World Bank spring meetings next week have been given the new guidance, according to four people familiar with the situation.

They said the measures replicate those used on trips to Ukraine and China, where standard IT kit cannot be brought into the countries for fear of Russian or Chinese surveillance.

“They are worried about the US getting into the commission systems,” said one official.

The treatment of the US as a potential security risk highlights how relations have deteriorated since the return of Donald Trump as US president in January.

Trump has accused the EU of having been set up to “screw the US” and announced 20 per cent so-called reciprocal tariffs on the bloc’s exports, which he later halved for a 90-day period.

At the same time, he has made overtures to Russia, pressured Ukraine to hand over control over its assets by temporarily suspending military aid and has threatened to withdraw security guarantees from Europe, spurring a continent-wide rearmament effort.

“The transatlantic alliance is over,” said a fifth EU official.""

ft.com/content/20d0678a-41b2-4

Financial Times · EU issues US-bound staff with burner phones over spying fearsBy Andy Bounds