Normal view
Supply chain challenges loom large in quantum race, White House official says
One of the most difficult obstacles to overcome in the quantum race will be the supply chain, given how diffuse it is, a top White House official said Wednesday.
βSupply chain is one of the biggest challenges in my mind, and really, the challenge with the quantum supply chain is that quantum is not defined by a single hardware platform,β said Brad Blakestad, director of the National Quantum Coordination Office within the White House Office of Science and Technology Policy.
βIf you look at the quantum computing technologies, the quantum sensing technologies, the networking β those are all different,β he said in a webinar hosted by Inside Cybersecurity and USTelecom. βAnd even within computing, thereβs seven different modalities that use completely different components. So we have this not just one monolithic supply chain, but just a bunch of different supply chains that are kind of intertwined in various ways.β
Blakestad made his remarks a little more than a month after President Donald Trump signed two executive orders on quantum computing. He referenced proposed ways to address the supply chain challenge in one of the orders.
βThe other major issue or challenge that we face right now is that weβre on the cusp of quantum exploding from a commercialization perspective, but weβre not quite there yet,β he said. βSo thereβs not the funding, the revenue coming from large-scale quantum companies at this point to really make the supply chain as robust as you would want. So thinking about it from the government perspective, itβs just [that] there are too many places that I would want to bolster and not enough funding to do it.β
Blakestad touted steps to help that along such as the government buying widgets from a company that makes them to certain specifications, or prize challenges.
The quantum supply chain isnβt just diffuse in the United States, an International Institute for Strategic Studies policy paper noted Wednesday. Itβs βinherently international: no single country dominates the supply chain, whether specialised materials, cryogenic equipment, hardware, software, fabrication or algorithms,β the authors, Dongyoun Cho and Maria Shagina, wrote.
And a March report from the Center for a New American Security identified strengthening the quantum supply chain as pivotal to the United States seizing the benefits of the technology, citing gaps in the U.S. supply chain and reliance on foreign suppliers such as China and Russia.Β
Supply chain wasnβt the only obstacle Blakestad mentioned as looming large.
βThe encryption challenge is a real challenge, and we want to make sure that we are aware of when quantum computers will ultimately get to a scale that they start having these sorts of implications and move as quickly as we can,β he said. βSo, just by owning the technologies, by owning the workforce, by making the United States the place that people want to come to be on the cutting edge of this technology, I think that kind of addresses both of those issues, and thatβs what makes it so critical.β
Another difficulty is measuring progress, Blakestad said: βItβs also very, very hard to benchmark, and to know that youβre actually doing what youβre supposed to, what you are intending to do.β
The post Supply chain challenges loom large in quantum race, White House official says appeared first on CyberScoop.
-
CyberScoop
- Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries
Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries
A Russian state-sponsored threat group has been stealing sensitive data from governments and commercial organizations since July 2025 via a novel exploit in popular Linux-based enterprise software, U.S. authorities and cyber officials from more than a dozen other countries warned in a joint cybersecurity advisory Thursday.
Laundry Bearβs most recent espionage campaign involves the exploitation of a zero-day vulnerability in Zimbra Collaboration Suite that wasnβt patched until November 2025, five months after attacks were well underway, officials said.Β
The exploit just requires a view β no clicks β and allows attackers to steal the previous 90 daysβ worth of email, the accountβs password, search history, the victim organizationβs email directory, two-factor authentication tokens and other newly created passwords.
βThe covert and persistent nature of this activity, along with the absence of any known financial extortion, almost certainly indicates this groupβs involvement in espionage activities with Russian government backing,β officials wrote in the advisory.Β
βAdditionally, extensive Ukrainian targeting, prior to use against U.S. and other NATO allies, outlines an increasing trend within Russian cyber threat groups to target Ukrainian users firstβboth as a priority target and as a testbench for malicious cyber techniques before broader global deployment.β
The state-sponsored espionage group, also known as Void Blizzard, has compromised governments and organizations in the defense, education, energy, law enforcement, media, finance, transportation and technology sectors.Β
Laundry Bearβs year-long campaign involving the exploitation of CVE-2025-66376 showcases more technical capabilities, including a custom JavaScript payload it delivers to targeted victims via phishing emails. The threat group could also likely adapt the novel data exfiltration and aggregation capability, dubbed βbeehive,β to exploit other vulnerabilities, officials warned.
The defectβs medium-severity rating of 6.1 underscores the challenge defenders regularly confront in prioritizing patching schedules based on measure of severity alone.
The Russian state-supported group, which has been active since at least 2024, is still actively exploiting Zimbra Collaboration Suite instances that remain unpatched, officials said.
Authorities shared Thursday indicators of compromise, mitigation steps and urged organizations to update their vulnerable software.
βThis campaignβs targeted victimology and limited exploitation capabilities likely indicate this group manually identifies and targets the victim organizationsβ by identifying organizations with public-facing infrastructure, officials wrote in the advisory.
Once a target is identified, Laundry Bear also likely compiles email addresses for users to target with the exploit via phishing emails. Officials did not identify specific victims or describe the volume of organizations already compromised.
The joint cybersecurity advisory was issued by the United States, Australia, Canada, New Zealand, the United Kingdom, Czech Republic, Denmark, Estonia, Finland, France, Italy, Moldova, the Netherlands, Poland, Spain and Sweden.
The post Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries appeared first on CyberScoop.
Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks
Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and disinformation campaigns inside the European Union. The two men were the focus of a 2025 KrebsOnSecurity story about how their hosting companies had assumed control over the technical infrastructure of Stark Industries Solutions, an Internet service provider sanctioned last year by the EU as a frequent staging ground for cyber mischief from Russiaβs intelligence agencies.
An investigator with the Tax Intelligence and Investigation Service (FIOD), the Dutch financial crimes agency, during the raid. Image: FIOD.
The Dutch daily news outlet de Volkskrant reports that the Dutch financial crime agency FIOD on May 18 arrested a 57-year-old from Amsterdam and a 39-year-old from The Hague, charging them with violating sanctions law by directly or indirectly making economic resources available to EU-sanctioned entities.
The Dutch investigation focuses on Stark Industries, a sprawling hosting provider that materialized just two weeks before Russia invaded Ukraine. As detailed in this May 2024 deep-dive, Stark quickly became the source of massive distributed denial-of-service (DDoS) attacks against European targets, and emerged as a top supplier of proxy and anonymity services that showed up time and again in cyberattacks linked to Russia-backed hacking groups.
That report identified two Moldovan brothers β Ivan and Yuri Neculiti and their company PQHosting β who were providing one of Starkβs two main conduits to the larger Internet. In May 2025, the EU sanctioned PQHosting and the Neculiti brothers for aiding Russiaβs hybrid warfare efforts. But as KrebsOnSecurity observed in September 2025, those sanctions failed to target Starkβs remaining connection to the Internet β an Internet service provider based in the Netherlands called MIRhosting.
MIRhosting is operated by Andrey Nesterenko, a 39-year-old Russian native who runs the business out of the Netherlands.Β News that PQHosting and the Neculiti brothers were about to be sanctioned by the EU leaked in the media nearly two weeks before the sanctions were announced last year. During that time, the Stark network assets were transferred from PQHosting to a new entity called the[.]hosting, under the control of the Dutch entity WorkTitans BV.
And as our September 2025 report showed, WorkTitans was controlled by Nesterenko and a 57-year-old from Amsterdam named Youssef Zinad. On top of that, WorkTitans was getting connectivity to the larger Internet solely through MIRhosting, where Zinad had worked previously.
On May 18, Dutch financial crime investigators arrested Nesterenko and Zinad, and searched three businesses in Enschede and Almere and two data centers in Dronten and Schiphol-Rijk. A statement from the Dutch authorities said they also seized laptops, telephones and more than 800 servers.
A message to the-hosting customers immediately after 800 of its servers were seized by Dutch authorities. The message says that unfortunately data stored on the server has been lost and cannot be recovered.
De Volkskrant said it reviewed data showing WorkTitans and MIRhosting were the most-used networks in pro-Russian attacks on Danish government bodies between November 13 and 19, 2025, the week of Denmarkβs municipal elections.
The publication wrote that prior to Nesterenkoβs arrest, the MIRhosting founder denied that he knew his servers had been misused by pro-Russian cybercriminals. βHe said he had ended all services with the Neculiti brothers when the EU sanctions came into force in May 2025,β and the he βreserved all rights to take action against βharmful and incorrect publications,β de Volkskrant wrote.
MIRhosting released a statement saying it has initiated an internal investigation into the alleged facts concerning the elections in Denmark, and that it has temporarily paused services to WorkTitans as a precautionary measure while the matter is being reviewed further.
βBased on our preliminary findings, there are no indications that the services over which we exercise control were actually used to influence the Danish elections,β the statement reads. βNo anomalies or spikes were observed in our network traffic during the period mentioned in the publication; had large-scale DDoS attacks occurred, such activity would have been evident. Furthermore, prior to the media publication, we had not received any complaints, abuse reports, or official requests regarding suspicious activities or misuse of our network. Meanwhile, our regular operational activities continue, and our service to our other clients remains fully intact.β
Born in Nizhny Novgorod, Russia, Mr. Nesterenko grew up as a piano prodigy who performed publicly at a young age. In 2004, Nesterenko founded MIRhostingβs parent Innovation IT Solutions Corp., which has the notable distinction of being the company responsible for hosting stopgeorgia[.]ru, a hacktivist website for organizing cyberattacks against Georgia that appeared at the same time Russian forces invaded the former Soviet nation in 2008. That conflict was thought to be the first war ever fought in which a notable cyberattack and an actual military engagement happened simultaneously.
Responding to questions shared via email, Nesterenko said MIRhosting does not support cybercrime, sanctions evasion, or illegal activity, and that the allegations and arrest by Dutch authorities have been extremely harmful to him and his company.
βThe transition to the.hosting was not intended to evade sanctions,β Nesterenko wrote. βThe hardware and customer portfolio had already been transferred to WorkTitans before the sanctions appeared. Closing or damaging a legitimate Dutch infrastructure company will not stop cybercrime, but it will harm many people who have done nothing wrong.β
Far less is public about the 57-year-old Zinad, who reportedly has been keeping a low profile since our story last year. De Volkskrant reported that Zinad blocked access to his LinkedIn account, had gone months without responding to emails, WhatsApp messages and phone calls, and told a colleague that illness was forcing him to lead a somewhat more reclusive life.
Mr. Zinadβs now-defunct LinkedIn profile. It was full of posts for MIRhostingβs services.
Mr. Nesterenko claims Zinad was never an employee of MIRhosting.
βHe helped me and MIRhosting with certain business tasks under a normal business-to-business arrangement between companies,β Nesterenko explained.
However, in previous emails to KrebsOnSecurity, Nesterenko carbon copied Mr. Zinad (who had a @mirhosting.com email), explaining that he was part of the companyβs legal team. Also, the Dutch website stagemarkt[.]nl lists Youssef Zinad as an official contact for MIRhostingβs offices in Almere.
Mr. Zinad has never responded to requests for comment. Nor did de Volkskrant have any luck tracking him down. The publication said it repeatedly asked Mr. Zinad (referred to here as simply βZβ), but he reportedly avoided every form of contact.
ββI am unavailable but will respond to your message as soon as possible,β reads an automated reply on WhatsApp on 2 October 2025,β de Volkskrant reported. βIt is the only response de Volkskrant would receive in months. He did not pick up his phone and did not call back. When an acquaintance asked him via LinkedIn to contact the reporter, he blocked access to his LinkedIn page. At an address in Almere where Z.βs personal limited company is registered, no one was present in April. The corner houseβs blinds were drawn, and a pile of rubbish bags lay outside next to a container, as if someone had recently left. A neighbour said he knew the man but did not know where he was staying. Z. was later arrested at a residence in Amsterdam.β
Alleged Kimwolf Botmaster βDortβ Arrested, Charged in U.S. and Canada
Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for use in a series of massive distributed denial-of-service (DDoS) attacks over the past six months. KrebsOnSecurity publicly named the suspect in February 2026 after the accused launched a volley of DDoS, doxing and swatting campaigns against this author and a security researcher. He now faces criminal hacking charges in both Canada and the United States.
A criminal complaint unsealed today in an Alaska district court charges Jacob Butler, a.k.a. βDort,β of Ottawa, Canada with operating the Kimwolf DDoS botnet. A statement from the Department of Justice says the complaint against Butler was unsealed following the defendantβs arrest in Canada by the Ontario Provincial Police pursuant to a U.S. extradition warrant. Butler is currently in Canadian custody awaiting an initial court hearing scheduled for early next week.
The government said Kimwolf targeted infected devices which were traditionally βfirewalledβ from the rest of the internet, such as digital photo frames and web cameras. The infected systems were then rented to other cybercriminals, or forced to participate in record-smashing DDoS attacks, as well as assaults that affected Internet address ranges for the Department of Defense. Consequently, the DoDβs Defense Criminal Investigative Service is investigating the case, with assistance from the FBI field office in Anchorage.
βKimWolf was tied to DDoS attacks which were measured at nearly 30 Terabits per second, a record in recorded DDoS attack volume,β the Justice Department statement reads. βThese attacks resulted in financial losses which, for some victims, exceeded one million dollars. The KimWolf botnet is alleged to have issued over 25,000 attack commands.β
On March 19, U.S. authorities joined international law enforcement partners in seizing the technical infrastructure for Kimwolf and three other large DDoS botnets β named Aisuru, JackSkid and Mossad β that were all competing for the same pool of vulnerable devices.
On February 28, KrebsOnSecurity identified Butler as the Kimwolf botmaster after digging through his various email addresses, registrations on the cybercrime forums, and posts to public Telegram and Discord servers. However, Dort continued to threaten and harass researchers who helped track down his real-life identity and dramatically slow the spread of his botnet.
Dort claimed responsibility for at least two swatting attacks targeting the founder of Synthient, a security startup that helped to secure a widespread critical security weakness that Kimwolf was using to spread faster and more effectively than any other IoT botnet out there. Synthient was among many technology companies thanked by the Justice Department today, and Synthientβs founder Ben Brundage told KrebsOnSecurity heβs relieved Butler is in custody.
βHopefully this will end the harassment,β Brundage said.
An excerpt from the criminal complaint against Butler, detailing how he ordered a swatting attack against Ben Brundage, the founder of the security firm Synthient.
The government says investigators connected Butler to the administration of the KimWolf botnet through IP address, online account information, transaction records, and online messaging application records obtained through the issuance of legal process. The criminal complaint against Butler (PDF) shows he did little to separate his real-life and cybercriminal identities (something we demonstrated in our February unmasking of Dort).
In April, the Justice Department joined authorities across Europe in seizing domain names tied to nearly four-dozen DDoS-for-hire services, although because of a bureaucratic mix-up the list of seized domains has remain sealed until today. The DOJ said at least one of those services collaborated with Butlerβs Kimwolf botnet.
A statement from the Ontario Provincial Police said a search warrant was executed on March 19 at Butlerβs address in Ottawa, where they seized multiple devices. As a result of that investigation, Butler was arrested and charged this week with unauthorized user of computer; possession of device to obtain unauthorized use of computer system or to commit mischief; and mischief in relation to computer data. He is scheduled to remain in custody until a hearing on May 26.
In the United States, Butler is facing one count of aiding and abetting computer intrusion. If extradited, tried and convicted in a U.S. court, Butler could face up to 10 years in prison, although that maximum sentence would likely be heavily tempered by considerations in the U.S. Sentencing Guidelines, which make allowances for mitigating factors such as youth, lack of criminal history and level of cooperation with investigators.
-
Krebs on Security
- Drones to Diplomas: How Russiaβs Largest Private University is Linked to a $25M Essay Mill
Drones to Diplomas: How Russiaβs Largest Private University is Linked to a $25M Essay Mill
A sprawling academic cheating network turbocharged by Google Ads that has generated nearly $25 million in revenue has curious ties to a Kremlin-connected oligarch whose Russian university builds drones for Russiaβs war against Ukraine.
The Nerdify homepage.
The link between essay mills and Russian attack drones might seem improbable, but understanding it begins with a simple question: How does a human-intensive academic cheating service stay relevant in an era when students can simply ask AI to write their term papers? The answer β recasting the business as an AI company β is just the latest chapter in a story of many rebrands that link the operation to Russiaβs largest private university.
Search in Google for any terms related to academic cheating services β e.g., βhelp with exam onlineβ or βterm paper onlineβ β and youβre likely to encounter websites with the words βnerdβ or βgeekβ in them, such as thenerdify[.]com and geekly-hub[.]com. With a simple request sent via text message, you can hire their tutors to help with any assignment.
These nerdy and geeky-branded websites frequently cite their βhonor code,β which emphasizes they do not condone academic cheating, will not write your term papers for you, and will only offer support and advice for customers. But according to This Isnβt Fine, a Substack blog about contract cheating and essay mills, the Nerdify brand of websites will happily ignore that mantra.
βWe tested the quick SMS for a price quote,β wrote This Isnβt Fine author Joseph Thibault. βThe honor code references and platitudes apparently stop at the website. Within three minutes, we confirmed that a full three-page, plagiarism- and AI-free MLA formatted Argumentative essay could be ours for the low price of $141.β
A screenshot from Joseph Thibaultβs Substack post shows him purchasing a 3-page paper with the Nerdify service.
Google prohibits ads that βenable dishonest behavior.β Yet, a sprawling global essay and homework cheating network run under the Nerdy brands has quietly bought its way to the top of Google searches β booking revenues of almost $25 million through a maze of companies in Cyprus, Malta and Hong Kong, while pitching βtutoringβ that delivers finished work that students can turn in.
When one Nerdy-related Google Ads account got shut down, the group behind the company would form a new entity with a front-person (typically a young Ukrainian woman), start a new ads account along with a new website and domain name (usually with βnerdyβ in the brand), and resume running Google ads for the same set of keywords.
UK companies belonging to the group that have been shut down by Google Ads since Jan 2025 include:
βProglobal Solutions LTD (advertised nerdifyit[.]com);
βAW Tech Limited (advertised thenerdify[.]com);
βGeekly Solutions Ltd (advertised geekly-hub[.]com).
Currently active Google Ads accounts for the Nerdify brands include:
-OK Marketing LTD (advertising geekly-hub[.]netβ©), formed in the name of Olha Karpenko, a young Ukrainian woman;
βTwo Sigma Solutions LTD (advertising litero[.]ai), formed in the name of Olekszij (Alexey) Pokatilo.
Googleβs Ads Transparency page for current Nerdify advertiser OK Marketing LTD.
Mr. Pokatilo has been in the essay-writing business since at least 2009, operating a paper-mill enterprise called Livingston Research alongside Alexander Korsukov, who is listed as an owner. According to a lengthy account from a former employee, Livingston Research mainly farmed its writing tasks out to low-cost workers from Kenya, Philippines, Pakistan, Russia and Ukraine.
Pokatilo moved from Ukraine to the United Kingdom in Sept. 2015 and co-founded a company called Awesome Technologies, which pitched itself as a way for people to outsource tasks by sending a text message to the serviceβs assistants.
The other co-founder of Awesome Technologies is 36-year-old Filip Perkon, a Swedish man living in London who touts himself as a serial entrepreneur and investor. Years before starting Awesome together, Perkon and Pokatilo co-founded a student group called Russian Business Week while the two were classmates at the London School of Economics. According to the Bulgarian investigative journalist Christo Grozev, Perkonβs birth certificate was issued by the Soviet Embassy in Sweden.
Alexey Pokatilo (left) and Filip Perkon at a Facebook event for startups in San Francisco in mid-2015.
Around the time Perkon and Pokatilo launched Awesome Technologies, Perkon was building a social media propaganda tool called the Russian Diplomatic Online Club, which Perkon said would βturbo-chargeβ Russian messaging online. The clubβs newsletter urged subscribers to install in their Twitter accounts a third-party app called Tweetsquad that would retweet Kremlin messaging on the social media platform.
Perkon was praised by the Russian Embassy in London for his efforts: During the contentious Brexit vote that ultimately led to the United Kingdom leaving the European Union, the Russian embassy in London used this spam tweeting tool to auto-retweet the Russian ambassadorβs posts from supportersβ accounts.
Neither Mr. Perkon nor Mr. Pokatilo replied to requests for comment.
A review of corporations tied to Mr. Perkon as indexed by the business research service North Data finds he holds or held director positions in several U.K. subsidiaries of Synergy University, Russiaβs largest private education provider. Synergy has more than 35,000 students, and sells T-shirts with patriotic slogans such as βCrimea is Ours,β and βThe Russian Empire β Reloaded.β
The president of Synergy University is Vadim Lobov, a Kremlin insider whose headquarters on the outskirts of Moscow reportedly features a wall-sized portrait of Russian President Vladimir Putin in the pop-art style of Andy Warhol. For a number of years, Lobov and Perkon co-produced a cross-cultural event in the U.K. called Russian Film Week.
Synergy President Vadim Lobov and Filip Perkon, speaking at a press conference for Russian Film Week, a cross-cultural event in the U.K. co-produced by both men.
Mr. Lobov was one of 11 individuals reportedly hand-picked by the convicted Russian spy Marina Butina to attend the 2017 National Prayer Breakfast held in Washington D.C. just two weeks after President Trumpβs first inauguration.
While Synergy University promotes itself as Russiaβs largest private educational institution, hundreds of international students tell a different story. Online reviews from students paint a picture of unkept promises: Prospective students from Nigeria, Kenya, Ghana, and other nations paying thousands in advance fees for promised study visas to Russia, only to have their applications denied with no refunds offered.
βMy experience with Synergy University has been nothing short of heartbreaking,β reads one such account. βWhen I first discovered the school, their representative was extremely responsive and eager to assist. He communicated frequently and made me believe I was in safe hands. However, after paying my hard-earned tuition fees, my visa was denied. Itβs been over 9 months since that denial, and despite their promises, I have received no refund whatsoever. My messages are now ignored, and the same representative who once replied instantly no longer responds at all. Synergy University, how can an institution in Europe feel comfortable exploiting the hopes of Africans who trust you with their life savings? This is not just unethical β itβs predatory.β
This pattern repeats across reviews by multilingual students from Pakistan, Nepal, India, and various African nations β all describing the same scheme: Attractive online marketing, promises of easy visa approval, upfront payment requirements, and then silence after visa denials.
Reddit discussions in r/Moscow and r/AskARussian are filled with warnings. βItβs a scam, a diploma mill,β writes one user. βThey literally sell exams. There was an investigation on Rossiya-1 television showing students paying to pass tests.β
The Nerdify websiteβs βAbout Usβ page says the company was co-founded by Pokatilo and an American named Brian Mellor. The latter identity seems to have been fabricated, or at least there is no evidence that a person with this name ever worked at Nerdify.
Rather, it appears that the SMS assistance company co-founded by Messrs. Pokatilo and Perkon (Awesome Technologies) fizzled out shortly after its creation, and that Nerdify soon adopted the process of accepting assignment requests via text message and routing them to freelance writers.
A closer look at an early βAbout Usβ page for Nerdify in The Wayback Machine suggests that Mr. Perkon was the real co-founder of the company: The photo at the top of the page shows four people wearing Nerdify T-shirts seated around a table on a rooftop deck in San Francisco, and the man facing the camera is Perkon.
Filip Perkon, top right, is pictured wearing a Nerdify T-shirt in an archived copy of the companyβs About Us page. Image: archive.org.
Where are they now? Pokatilo is currently running a startup called Litero.Ai, which appears to be an AI-based essay writing service. In July 2025, Mr. Pokatilo received pre-seed funding of $800,000 for Litero from an investment program backed by the venture capital firms AltaIR Capital, Yellow Rocks, Smart Partnership Capital, and I2BF Global Ventures.
Meanwhile, Filip Perkon is busy setting up toy rubber duck stores in Miami and in at least three locations in the United Kingdom. These βDuck Worldβ shops market themselves as βthe worldβs largest duck store.β
This past week, Mr. Lobov was in India with Putinβs entourage on a charm tour with Indiaβs Prime Minister Narendra Modi. Although Synergy is billed as an educational institution, a review of the companyβs sprawling corporate footprint (via DNS) shows it also is assisting the Russian government in its war against Ukraine.
Synergy University President Vadim Lobov (right) pictured this week in India next to Natalia Popova, a Russian TV presenter known for her close ties to Putinβs family, particularly Putinβs daughter, who works with Popova at the education and culture-focused Innopraktika Foundation.
The website bpla.synergy[.]bot, for instance, says the company is involved in developing combat drones to aid Russian forces and to evade international sanctions on the supply and re-export of high-tech products.
A screenshot from the website of synergy,bot shows the company is actively engaged in building armed drones for the war in Ukraine.
KrebsOnSecurity would like to thank the anonymous researcher NatInfoSec for their assistance in this investigation.
Update, Dec. 8, 10:06 a.m. ET: Mr. Pokatilo responded to requests for comment after the publication of this story. Pokatilo said he has no relation to Synergy nor to Mr. Lobov, and that his work with Mr. Perkon ended with the dissolution of Awesome Technologies.
βI have had no involvement in any of his projects and business activities mentioned in the article and he has no involvement in Litero.ai,β Pokatilo said of Perkon.
Mr. Pokatilo said his new company Litero βdoes not provide contract cheating services and is built specifically to improve transparency and academic integrity in the age of universal use of AI by students.β
βI am Ukrainian,β he said in an email. βMy close friends, colleagues, and some family members continue to live in Ukraine under the ongoing invasion. Any suggestion that I or my company may be connected in any way to Russiaβs war efforts is deeply offensive on a personal level and harmful to the reputation of Litero.ai, a company where many team members are Ukrainian.β
Update, Dec. 11, 12:07 p.m. ET: Mr. Perkon responded to requests for comment after the publication of this story. Perkon said the photo of him in a Nerdify T-shirt (see screenshot above) was taken after a startup event in San Francisco, where he volunteered to act as a photo model to help friends with their project.
βI have no business or other relations to Nerdify or any other ventures in that space,β Mr. Perkon said in an email response. βAs for Vadim Lobov, I worked for Venture Capital arm at Synergy until 2013 as well as his business school project in the UK, that didnβt get off the ground, so the company related to this was made dormant. Then Synergy kindly provided sponsorship for my Russian Film Week event that I created and ran until 2022 in the U.K., an event that became the biggest independent Russian film festival outside of Russia. Since the start of the Ukraine war in 2022 I closed the festival down.β
βI have had no business with Vadim Lobov since 2021 (the last film festival) and I donβt keep track of his endeavours,β Perkon continued. βAs for Alexey Pokatilo, we are university friends. Our business relationship has ended after the concierge service Awesome Technologies didnβt work out, many years ago.β
Why Use a Macro Pad?
![]()
Compression is everywhereβin files, videos, storage, and networksβso itβs only natural it should also be in your workflow too. You can βcompressβ a series of tedious, repetitive tasks requiring multiple steps and several configurations into a single button press with a macro pad such as the Stream Deck or a fully software-customizable mechanical keyboard.Β
The post Why Use a Macro Pad? appeared first on Black Hills Information Security, Inc..
Attack Tactics 9: Shadow Creds for PrivEsc w/ Kent & Jordan
![]()
In this video, Kent Ickler and Jordan Drysdale discuss Attack Tactics 9: Shadow Credentials for Primaries, focusing on a specific technique used in penetration testing services at Black Hills Information Security
The post Attack Tactics 9: Shadow Creds for PrivEsc w/ Kent & Jordan appeared first on Black Hills Information Security, Inc..
PlumHound Reporting Engine for BloodHoundAD
Kent Ickler // Itβs been over two years since Jordan and I talked about a Blue Teamβs perspective on Red Team tools.Β Β A Blue Teamβs Perspective on Red Team Hack [β¦]
The post PlumHound Reporting Engine for BloodHoundAD appeared first on Black Hills Information Security, Inc..
-
Black Hills Information Security
- Webcast: How to attack when LLMNR, mDNS, and WPAD attacks fail β eavesarp (Tool Overview)
Webcast: How to attack when LLMNR, mDNS, and WPAD attacks fail β eavesarp (Tool Overview)
![]()
Click on the timecodes to jump to that part of the video (on YouTube) 2:26 Introduction, background history covering LaBrea Tar Pits and ARP Cache Poisoning and how they relate [β¦]
The post Webcast: How to attack when LLMNR, mDNS, and WPAD attacks fail β eavesarp (Tool Overview) appeared first on Black Hills Information Security, Inc..
How to Weaponize the Yubikey
![]()
Michael Allen // A couple of years ago, I had a YubiKey that was affected by a security vulnerability, and to fix the issue, Yubico sent me a brand new [β¦]
The post How to Weaponize the Yubikey appeared first on Black Hills Information Security, Inc..
-
Black Hills Information Security
- Active Directory Best Practices to Frustrate Attackers: Webcast & Write-up
Active Directory Best Practices to Frustrate Attackers: Webcast & Write-up
![]()
Kent Ickler & Jordan Drysdale // BHIS Webcast and Podcast This post accompanies BHISβs webcastΒ recorded on August 7, 2018,Β Active Directory Best Practices to Frustrate Attackers, which you can view below. [β¦]
The post Active Directory Best Practices to Frustrate Attackers: Webcast & Write-up appeared first on Black Hills Information Security, Inc..
How To Disable LLMNR & Why You Want To
![]()
Kent Ickler // Link-Local Multicast Name Resolution (LLMNR) This one is a biggie, and youβve probably heard Jordan, John, me, and all the others say it many many times. LLMNR [β¦]
The post How To Disable LLMNR & Why You Want To appeared first on Black Hills Information Security, Inc..
-
Black Hills Information Security
- WEBCAST: Active Domain Active Defense (Active DAD) Primer with John Strand
WEBCAST: Active Domain Active Defense (Active DAD) Primer with John Strand
![]()
This is the in-studio version of our live in DC event from July. In this webcast, John covers how to set up Active Directory Active Defense (ADAD) using tools in [β¦]
The post WEBCAST: Active Domain Active Defense (Active DAD) Primer with John Strand appeared first on Black Hills Information Security, Inc..
Defusing a Bomb Through Trigger Bypasses and Sensors
![]()
Mike Felch // MeetΒ βThe Boxβ Bomb For the last few years at the security conference DEF CON in Las Vegas, the Tamper Resistant Village has hosted a challenging contest called [β¦]
The post Defusing a Bomb Through Trigger Bypasses and Sensors appeared first on Black Hills Information Security, Inc..
How to Build Super Secure Active Directory Infrastructure*
![]()
CJ Cox // We frequently get requests from customers asking us if we provide consultation defending their systems. The other day I got a question from a customer asking us [β¦]
The post How to Build Super Secure Active Directory Infrastructure* appeared first on Black Hills Information Security, Inc..