Last week was interesting. Law enforcement worldwide was busy and engaged in multiple operations against cybercriminals. Several domains were closed, arrests were made, and equipment, infrastructure, and cryptocurrency were seized.
Panzura and Grau Data have announced a partnership to transform data management. The announcement came at Gartner’s IT Infrastructure, Operations & Cloud Strategies Conference in Las Vegas. The two companies will integrate Panzura Symphony and Grau Data’s MetadataHub. The expectation is that it will deliver metadata-driven insights to enable AI and deep analytics.
Semperis has announced Lightning Intelligence, a security posture assessment tool as part of Lightning platform. It works with multi-forest Active Directory (AD) and multi-tenant Entra ID environments to deliver security trend reports. The reports focus on any identity-related risks, which account for 90% of cyber security incidents.
Gentrace has raised $8 million in a Series A funding round led by Matrix Partners. Also participating in the funding round were Headline and K9 Ventures. It brings the total funding raised by Gentrace to $14 million.
27 Distributed Denial of Service (DDoS) for hire platforms have been given the boot before they cause Christmas mayhem. Operation PowerOFF was led by Europol and supported by law enforcement in 15 countries worldwide.
noyb
noyb has filed a complaint against the social media platform BeReal over the latest “dark pattern” to get consent. Opening the app results in a pop-up asking for consent. Say “yes,” and the banner disappears forever. Say “no” and it will appear like nagware until you give up. noyb says that this behaviour started in July 2024.
It highlights that in 2022 the European Data Protection Board (EDPB) addressed this type of dark pattern. Lisa Steinfeld, Data Protection Lawyer at noyb: “The GDPR makes it crystal clear that consent is only valid if it’s freely given. Unfortunately, BeReal doesn’t seem to care and would rather pressure people to give their consent even if they don’t want to be tracked.”
The EU has been found guilty of political microtargeting. The case was brought by noyb after the EU ran advertising specifically targeting one group of voters in a recent election in The Netherlands. In its decision, the EDPB decided that a simple reprimand rather than a fine or other action was appropriate, as the Commission had stopped the practice.
US Department of Justice
The Justice Department has seized Rydox and participated in the arrest of three administrators. Two were arrested in Kosovo and one in Albania, and the US has applied for extradition of two. The third will be tried in Albania.
Rydox is an illicit website and marketplace dedicated to selling stolen personal information, access devices, and other tools for carrying out cybercrime and fraud. It is alleged to have over 18,000 customers, and the US has identified over 7,600 sales of PII and devices belonging to US citizens. Overall, the Justice Department says Rydox offered at least 321,372 cybercrime products, including PII, to over 18,000 users.
Principal Deputy Assistant Attorney General Nicole M. Argentieri, head of the Justice Department’s Criminal Division, said, “The indictment alleges that, for more than eight years, the defendants administered an illicit online marketplace that sold PII, credit card information, and login credentials that had been stolen from thousands of U.S. victims.”
An indictment against Chinese national Guan Tianfeng, has been unsealed in the US. He is alleged to have been part of a cybercrime gang that exploited a zero-day vulnerability in firewalls sold by Sophos. The malware stole information from computers and, if detected, immediately encrypted those computers.
Assistant Attorney General for National Security Matthew G. Olsen, said, “The defendant and his conspirators compromised tens of thousands of firewalls and then continued to hold at risk these devices, which protect computers in the United States and around the world.”

















