Ryan Gallagher's Avatar

Ryan Gallagher

@rjgallagher.co.uk

Investigative reporter @Bloomberg.com covering technology & cybersecurity. Anonymous tips: https://tips.hushline.app/to/ryan Email: ryan@rjgallagher.co.uk Signal/WhatsApp: +44 737-678-6842

3,956
Followers
420
Following
58
Posts
11.11.2024
Joined
Posts Following

Latest posts by Ryan Gallagher @rjgallagher.co.uk

Preview
ICE to Gain Access to Paragon Spyware After Biden Order Dropped US Immigration and Customs Enforcement is on track to gain access to controversial spyware designed to hack phones and read private messages after the Trump administration jettisoned a Biden-era order...

New: US Immigration and Customs Enforcement to gain access to controversial Israeli spyware designed to hack phones & read private messages after Trump administration jettisons Biden-era order: www.bloomberg.com/news/article...

02.09.2025 13:52 πŸ‘ 18 πŸ” 14 πŸ’¬ 5 πŸ“Œ 1

In 2012, yes! Microsoft accused a company called Hangzhou DPtech Technologies of leaking a Windows vulnerability and booted it out of MAPP

20.08.2025 16:39 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Microsoft Curbs Early Access for Chinese Firms to Notifications About Cybersecurity Flaws Microsoft Corp. has curtailed Chinese companies’ access to advance notifications about cybersecurity vulnerabilities in its technology after investigating whether a leak led to a series of hacks explo...

New: Microsoft curbs Chinese companies’ access to info on cybersecurity vulnerabilities after investigating whether a leak led to a global hacking campaign that exploited flaws in its SharePoint software: www.bloomberg.com/news/article...

20.08.2025 15:11 πŸ‘ 9 πŸ” 7 πŸ’¬ 1 πŸ“Œ 2
Preview
Microsoft Probing If Chinese Hackers Learned of Flaws Via Alert Microsoft Corp. is investigating whether a leak from its early alert system for cybersecurity companies allowed Chinese hackers to exploit flaws in its SharePoint service before they were patched, acc...

Microsoft said in a statement it would "review this incident, find areas to improve, and apply those improvements broadly." Full story: www.bloomberg.com/news/article...

25.07.2025 18:41 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Victims of the SharePoint attacks, which were first detected on July 7, now total more than 400 government agencies and corporations worldwide, including the US's National Nuclear Security Administration, the division responsible for designing and maintaining the country's nuclear weapons.

25.07.2025 18:41 πŸ‘ 0 πŸ” 2 πŸ’¬ 3 πŸ“Œ 0

Some of the Chinese companies that are involved in MAPP are also members of a Chinese government vulnerability reporting program, the China National Vulnerability Database, which is operated by the country’s Ministry of State Security.

25.07.2025 18:41 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Microsoft has attributed SharePoint breaches to state-sponsored hackers from China, and at least a dozen Chinese companies participate in the alert sharing initiative, called the Microsoft Active Protections Program, or MAPP.

25.07.2025 18:41 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
Microsoft Probing If Chinese Hackers Learned of Flaws Via Alert Microsoft Corp. is investigating whether a leak from its early alert system for cybersecurity companies allowed Chinese hackers to exploit flaws in its SharePoint service before they were patched, acc...

New: Microsoft is investigating whether a leak from its early alert system for cybersecurity companies allowed Chinese hackers to exploit flaws in SharePoint before they were patched, enabling a global campaign of cyberattacks, according to people familiar: www.bloomberg.com/news/article...

25.07.2025 18:34 πŸ‘ 9 πŸ” 8 πŸ’¬ 1 πŸ“Œ 0
Preview
How a Tiny Middleman Could Access Two-Factor Login Codes From Tech Giants An investigation into the complexity of the global telecom system shows weaknesses in the transmission of secret codes sent via SMS.

A whistleblower shared 1 million two-factor authentication codes that had been sent to people by SMS from the world's largest tech companies, such as Google, Meta, & Amazon. We found the codes had been routed via an obscure Swiss company with links to spy agencies: www.bloomberg.com/news/article...

18.06.2025 15:22 πŸ‘ 9 πŸ” 7 πŸ’¬ 2 πŸ“Œ 0
Preview
How a Tiny Middleman Could Access Two-Factor Login Codes From Tech Giants An investigation into the complexity of the global telecom system shows weaknesses in the transmission of secret codes sent via SMS.

New: How a Tiny Middleman Could Access Two-Factor Login Codes From Tech Giants www.bloomberg.com/news/article...

16.06.2025 11:58 πŸ‘ 4 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Preview
β€˜DragonForce’ Hacking Gang Takes Credit for UK Retail Attacks A criminal hacking gang has taken credit for a disruptive campaign of cyberattacks targeting British retailers over the last two weeks.

β€˜DragonForce’ Hacking Gang Takes Credit for UK Retail Attacks: www.bloomberg.com/news/article...

02.05.2025 16:15 πŸ‘ 2 πŸ” 3 πŸ’¬ 1 πŸ“Œ 1

Portugal's National Cybersecurity Centre says: "There is no evidence to date pointing to a cyberattack. We would like to draw attention to the circulation of disinformation that occurs in these situations, and we therefore advise that every information should be confirmed with reliable sources."

28.04.2025 14:34 πŸ‘ 51 πŸ” 40 πŸ’¬ 1 πŸ“Œ 1

Initial probe into cause of power outages in Spain & Portugal today suggests fault rather than cyberattack, according to the European Union Agency for Cybersecurity (ENISA). β€œFor the moment the investigation seems to point out to a technical/cable issue,” a spokesperson for the agency tells me.

28.04.2025 13:45 πŸ‘ 99 πŸ” 55 πŸ’¬ 8 πŸ“Œ 4
Preview
Ukraine Is an `Easy Target' for Russian Hackers After US Aid Pullback American cybersecurity assistance has been crucial to helping war-torn country fend off hacks, experts say.

Full story: www.bloomberg.com/news/article...

25.04.2025 16:27 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

The end result is that Ukraine's digital front lines are weaker now, making the country an β€œeasy target” for Russia, said Yegor Aushev, a Kyiv-based cybersecurity expert. The β€œsudden & unannounced shutdown” of cyber operations, he said, β€œhas created a significant challenge.”

25.04.2025 16:27 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

β€œMany projects were stopped halfway, contractors were let go before finishing their work, & a lot of plans didn’t get the chance to reach their full potential,” Mankish said.

25.04.2025 16:27 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Andrii Mankish, a Ukrainian cybersecurity expert who worked on US-funded projects to identify Russian hacking attempts, said the US's cyber pullback was likely to β€œimpact our efforts & slow down progress in key areas.” Long-planned cybersecurity projects had suddenly ended, he said.

25.04.2025 16:27 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

That work is now paused & it's unclear whether it will resume -- Ukrainians say they have been left in the dark. Equipment & services that were to be provided to the country for ongoing initiatives, such as a project to strengthen the country’s central election commission, are now not going ahead.

25.04.2025 16:27 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

US cybersecurity assistance had included specialist support, training, equipment & software to organizations across Ukraine, including to dozens of government offices & departments & to key gas & electricity providers, the national bank & nuclear facilities such as Chernobyl.

25.04.2025 16:27 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
US Aid Pullback is Making Ukraine More Vulnerable to Russian Hacks American cybersecurity assistance has been crucial to helping war-torn country fend off hacks, experts say.

New: US cuts to foreign aid are impacting Ukraine's cybersecurity. Dozens of people have had to stop work protecting the country from Russian hackers & shipments of vital cyber equipment have stopped, according to people familiar with the situation: www.bloomberg.com/news/article...

25.04.2025 10:13 πŸ‘ 11 πŸ” 7 πŸ’¬ 1 πŸ“Œ 1

Awesome news Will, congrats!

09.04.2025 17:58 πŸ‘ 4 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
UK Effort to Keep Apple Encryption Fight Secret Blocked in Court A court has blocked a British government attempt to keep secret a legal case over its demand to access Apple Inc. user data in a victory for privacy advocates.

A UK court has blocked the UK government's attempt to keep secret a legal case over its demand to access Apple users' encrypted data. Judges said in a ruling Monday that authorities’ efforts were a β€œfundamental interference with the principle of open justice”: www.bloomberg.com/news/article...

07.04.2025 12:45 πŸ‘ 7 πŸ” 7 πŸ’¬ 0 πŸ“Œ 0
Preview
Trump envoy Steve Witkoff dismisses Starmer plan for Ukraine Steve Witkoff says the UK plans for an international force to support a ceasefire are a "posture".

Trump envoy dismisses UK peacekeeping plan for Ukraine, says: "I don't regard Putin as a bad guy. He's super smart." www.bbc.com/news/article...

23.03.2025 14:29 πŸ‘ 2 πŸ” 2 πŸ’¬ 0 πŸ“Œ 1
Preview
Exclusive: US suspends some efforts to counter Russian sabotage as Trump moves closer to Putin Several U.S. national security agencies have halted work on a coordinated effort to counter Russian sabotage, disinformation and cyberattacks, easing pressure on Moscow as the Trump Administration pushes Russia to end its war in Ukraine.

US national security agencies have halted work on a coordinated effort to counter Russian sabotage, disinformation & cyberattacks. Initiative had involved at least seven agencies working w/ European allies to disrupt plots targeting Europe & the US, Reuters reports: www.reuters.com/world/us-sus...

19.03.2025 20:12 πŸ‘ 29 πŸ” 31 πŸ’¬ 1 πŸ“Œ 3
Preview
Paragon Spyware Tool Linked to Canadian Police, Watchdog Says A Canadian law enforcement agency is suspected to have used spyware designed to hack into mobile phones and eavesdrop on messages, according to cybersecurity researchers from the University of Toronto...

Researchers find evidence suggesting spyware from Israeli firm Paragon has been obtained by Australia, Canada, Cyprus, Denmark & Singapore. The technology - used to hack phones & read private msgs - was recently linked to hacks of Italian journalists & activists: www.bloomberg.com/news/article...

19.03.2025 19:55 πŸ‘ 12 πŸ” 8 πŸ’¬ 0 πŸ“Œ 1
Preview
DHS Workers Tasked With Curbing Hacks Ousted in DOGE Squeeze Cybersecurity experts who worked to secure US government computers from Russian and Chinese hackers have been ousted from their roles following pressure from Elon Musk’s Department of Government Effic...

New: Cybersecurity experts who worked to secure US government computers from Russian & Chinese hackers have been ousted from their roles following pressure from DOGE. One senior official resigned in protest over move sources say has created "massive security gaps": www.bloomberg.com/news/article...

13.03.2025 22:30 πŸ‘ 12 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0

Very sad news πŸ˜₯

13.03.2025 10:21 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
X’s Attackers Hit Servers Faulted for Lacking Key Protection A cyberattack that brought down Elon Musk’s X targeted servers that were insufficiently protected from malicious traffic, according to cybersecurity analysts.

New: A cyberattack that brought down Elon Musk’s X targeted servers that were insufficiently protected from malicious traffic & β€œshould not be exposed on the internet”: www.bloomberg.com/news/article...

11.03.2025 18:03 πŸ‘ 6 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Preview
Sweden is investigating a damaged cable in the Baltic Sea Swedish authorities say they are investigating a damaged cable that was discovered in the Baltic Sea, the latest in a string of recent incidents of ruptured undersea cables that have heightened fears ...

Swedish authorities investigate damaged cable discovered in the Baltic Sea between Germany & Finland, the latest in a string of similar incidents that have heightened fears of Russian sabotage & spying in the region: apnews.com/article/swed...

21.02.2025 16:18 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Apple Removes Cloud Encryption Feature From UK After Backdoor Order Apple Inc. is removing its most advanced, end-to-end encrypted security feature for cloud data in the United Kingdom, in a stunning development after the government ordered the company to build a back...

Apple pulls encrypted data storage feature from UK after government backdoor demand. Development comes after Apple criticized β€œunprecedented overreach" of UK surveillance powers: www.bloomberg.com/news/article...

21.02.2025 16:11 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0