Cybercrime groups that specialize in stealing corporate data and demanding a ransom not to publish it have tried countless approaches to shaming their victims into paying. The latest innovation in ratcheting up the heat comes from the ALPHV/BlackCat ra…
Tag: The Coming Storm
Europe, Global Security News, North America
Senators Urge FTC to Probe ID.me Over Selfie Data
by BrianKrebs •
Some of more tech-savvy Democrats in the U.S. Senate are asking the Federal Trade Commission (FTC) to investigate identity-proofing company ID.me for “deceptive statements” the company and its founder allegedly made over how they handle facial recognit…
Europe, Global Security News, North America
Fighting Fake EDRs With ‘Credit Ratings’ for Police
by BrianKrebs •
When KrebsOnSecurity last month explored how cybercriminals were using hacked email accounts at police departments worldwide to obtain warrantless Emergency Data Requests (EDRs) from social media and technology providers, many security experts called i…
Europe, Global Security News, North America
The Original APT: Advanced Persistent Teenagers
by BrianKrebs •
Many organizations are already struggling to combat cybersecurity threats from ransomware purveyors and state-sponsored hacking groups, both of which tend to take days or weeks to pivot from an opportunistic malware infection to a full blown data breac…
Europe, Global Security News, North America
Hackers Gaining Power of Subpoena Via Fake “Emergency Data Requests”
by BrianKrebs •
There is a terrifying and highly effective “method” that criminal hackers are now using to harvest sensitive customer data from Internet service providers, phone companies and social media firms. It involves compromising email accounts and websites tie…
Europe, Global Security News, North America
Pro-Ukraine ‘Protestware’ Pushes Antiwar Ads, Geo-Targeted Malware
by BrianKrebs •
Researchers are tracking a number of open-source “protestware” projects on GitHub that have recently altered their code to display “Stand with Ukraine” messages for users, or basic facts about the carnage in Ukraine. The group also is tracking several …
Europe, Global Security News, North America
Report: Recent 10x Increase in Cyberattacks on Ukraine
by BrianKrebs •
As their cities suffered more intense bombardment by Russian military forces this week, Ukrainian Internet users came under renewed cyberattacks, with one Internet company providing service there saying they blocked ten times the normal number of phish…
Europe, Global Security News, North America
Conti Ransomware Group Diaries, Part I: Evasion
by BrianKrebs •
A Ukrainian security researcher this week leaked several years of internal chat logs and other sensitive data tied to Conti, an aggressive and ruthless Russian cybercrime group that focuses on deploying its ransomware to companies with more than $100 m…
Europe, Global Security News, North America
Russia Sanctions May Spark Escalating Cyber Conflict
by BrianKrebs •
President Biden joined European leaders this week in enacting economic sanctions against Russia in response its military invasion of Ukraine. The West has promised tougher sanctions are coming, but experts warn these will almost certainly trigger a Rus…
Europe, Global Security News, North America
Scary Fraud Ensues When ID Theft & Usury Collide
by BrianKrebs •
What’s worse than finding out that identity thieves took out a 546 percent interest payday loan in your name? How about a 900 percent interest loan? Or how about not learning of the fraudulent loan until it gets handed off to collection agents? One rea…
Europe, Global Security News, North America
At Request of U.S., Russia Rounds Up 14 REvil Ransomware Affiliates
by BrianKrebs •
The Russian government said today it arrested 14 people accused of working for “REvil,” a particularly aggressive ransomware group that has extorted hundreds of millions of dollars from victim organizations. The Russian Federal Security Service (FSB) s…
Europe, Global Security News, North America
The Internet is Held Together With Spit & Baling Wire
by BrianKrebs •
Imagine being able to disconnect or redirect Internet traffic destined for some of the world’s largest companies — just by spoofing an email. This is the nature of a threat vector recently removed by a Fortune 500 firm that operates one of the world’s…
Europe, Global Security News, North America
‘Trojan Source’ Bug Threatens the Security of All Code
by BrianKrebs •
Virtually all compilers — programs that transform human-readable source code into computer-executable machine code — are vulnerable to an insidious attack in which an adversary can introduce targeted vulnerabilities into any software without being de…
Europe, Global Security News, North America
KrebsOnSecurity Hit By Huge New IoT Botnet “Meris”
by BrianKrebs •
On Thursday evening, KrebsOnSecurity was the subject of a rather massive (and mercifully brief) distributed denial-of-service (DDoS) attack. The assault came from “Meris,” the same new “Internet of Things” (IoT) botnet behind record-shattering attacks …
Europe, Global Security News, North America
Microsoft: Attackers Exploiting Windows Zero-Day Flaw
by BrianKrebs •
Microsoft Corp. warned Tuesday that attackers are exploiting a previously unknown vulnerability in Windows 10 and many Windows Server versions to seize control over PCs when users open a malicious document or visit a booby-trapped website. There is cur…