This Windows PowerShell Phish Has Scary Potential: Many GitHub users this week received a novel phishing email warning of critical security holes in their code. Those who clicked the link for details were asked to distinguish themselves from bots by… https://t.co/0E8j7LZ9sP
Scam ‘Funeral Streaming’ Groups Thrive on Facebook: Scammers are flooding Facebook with groups that purport to offer video streaming of funeral services for the recently deceased. Friends and family who follow the links for the streaming services are… https://t.co/EW6wA4duWx
The Dark Nexus Between Harm Groups and ‘The Com’: A cyberattack that shut down some of the top casinos in Las Vegas last year quickly became one of the most riveting security stories of 2023: It was the first known case of native English-speaking hackers… https://t.co/OHCtUF5cFB
Bug Left Some Windows PCs Dangerously Unpatched: Microsoft Corp. today released updates to fix at least 79 security vulnerabilities in its Windows operating systems and related software, including multiple flaws that are already showing up in active… https://t.co/i0urbsam5f
Sextortion Scams Now Include Photos of Your Home: An old but persistent email scam known as "sextortion" has a new personalized touch: The missives, which claim that malware has captured webcam footage of recipients pleasuring themselves, now include a… https://t.co/tKrnpFYhx1
Owners of 1-Time Passcode Theft Service Plead Guilty: Three men in the United Kingdom have pleaded guilty to operating otp[.]agency, a once popular online service that helped attackers intercept the one-time passcodes (OTPs) that many websites require as… https://t.co/3X0Psu90Sz
When Get-Out-The-Vote Efforts Look Like Phishing: Multiple media reports this week warned Americans to be on guard against a new phishing scam that arrives in a text message informing recipients they are not yet registered to vote. A bit of digging… https://t.co/fNw6hn8V5q
New 0-Day Attacks Linked to China’s ‘Volt Typhoon’: Malicious hackers are exploiting a zero-day vulnerability in Versa Director, a software product used by many Internet and IT service providers. Researchers believe the activity is linked to Volt… https://t.co/rjJy5EIodb
Local Networks Go Global When Domain Names Collide: The proliferation of new top-level domains (TLDs) has exacerbated a well-known security weakness: Many organizations set up their internal Microsoft authentication systems years ago using domain names… https://t.co/kL3ztqwME1
National Public Data Published Its Own Passwords: New details are emerging about a breach at National Public Data (NPD), a consumer data broker that recently spilled hundreds of millions of Americans' Social Security Numbers, addresses, and phone numbers… https://t.co/qBeergRaWC
https://t.co/G5HjnnUF6r Hack Exposes a Nation’s Data: A great many readers this month reported receiving alerts that their Social Security Number, name, address and other personal information were exposed in a breach at a little-known but aptly-named… https://t.co/9qF2vVFJT3
Six 0-Days Lead Microsoft’s August 2024 Patch Push: Microsoft today released updates to fix at least 90 security vulnerabilities in Windows and related software, including a whopping six zero-day flaws that are already being actively exploited by… https://t.co/rgTYFtluFo
Cybercrime Rapper Sues Bank over Fraud Investigation: In January, KrebsOnSecurity wrote about rapper Punchmade Dev, whose music videos sing the praises of a cybercrime lifestyle. That story showed how Punchmade's social media profiles promoted… https://t.co/aX4d8W8sNx
Low-Drama ‘Dark Angels’ Reap Record Ransoms: A ransomware group called Dark Angels made headlines this past week when it was revealed the crime group recently received a record $75 million data ransom payment from a Fortune 50 company. Security experts… https://t.co/2N3yqrYvm8
U.S. Trades Cybercriminals to Russia in Prisoner Swap: Twenty-four prisoners were freed today in an international prisoner swap between Russia and Western countries. Among the eight Russians repatriated were five convicted cybercriminals. In return,… https://t.co/2GuYSaBMKL
Don’t Let Your Domain Name Become a “Sitting Duck”: More than a million domain names -- including many registered by Fortune 100 firms and brand protection companies -- are vulnerable to takeover by cybercriminals thanks to authentication weaknesses at a… https://t.co/uOwX5GrALP
Crooks Bypassed Google’s Email Verification to Create Workspace Accounts, Access 3rd-Party Services: Google says it recently fixed an authentication weakness that allowed crooks to circumvent email verification needed to create a Google Workspace… https://t.co/qMelHD1uuq
Phish-Friendly Domain Registry “.top” Put on Notice: The Chinese company in charge of handing out domain names ending in “.top” has been given until mid-August 2024 to show that it has put in place systems for managing phishing reports and suspending… https://t.co/T0ABtKO95r
Global Microsoft Meltdown Tied to Bad Crowdstrike Update: A faulty software update from cybersecurity vendor Crowdstrike crippled countless Microsoft Windows computers across the globe today, disrupting everything from airline travel and financial… https://t.co/7fIZMvlgrl
Researchers: Weak Security Defaults Enabled Squarespace Domains Hijacks: At least a dozen organizations with domain names at domain registrar Squarespace saw their websites hijacked last week. Squarespace bought all assets of Google Domains a year ago,… https://t.co/XgSaK6x1jP