Cybersecurity

Oops: DanaBot Malware Devs Infected Their Own PCs

   ​ The U.S. government today unsealed criminal charges against 16 individuals accused of operating and selling DanaBot, a prolific strain of information-stealing malware that has been sold on Russian cybercrime forums since 2018. The FBI says a newer version of DanaBot was used for espionage, and that many of the defendants exposed their real-life identities …

Oops: DanaBot Malware Devs Infected Their Own PCs Read More »

Breachforums Boss to Pay $700k in Healthcare Breach

   ​ In what experts are calling a novel legal outcome, the 22-year-old former administrator of the cybercrime community Breachforums will forfeit nearly $700,000 to settle a civil lawsuit from a health insurance company whose customer data was posted for sale on the forum in 2023. Conor Brian Fitzpatrick, a.k.a. “Pompompurin,” is slated for resentencing next …

Breachforums Boss to Pay $700k in Healthcare Breach Read More »

Patch Tuesday, May 2025 Edition

   ​ Microsoft on Tuesday released software updates to fix at least 70 vulnerabilities in Windows and related products, including five zero-day flaws that are already seeing active exploitation. Adding to the sense of urgency with this month’s patch batch from Redmond are fixes for two other weaknesses that now have public proof-of-concept exploits available.​ ​[[{“value”:” …

Patch Tuesday, May 2025 Edition Read More »

xAI Dev Leaks API Key for Private SpaceX, Tesla LLMs

   ​ A employee at Elon Musk’s artificial intelligence company xAI leaked a private key on GitHub that for the past two months could have allowed anyone to query private xAI large language models (LLMs) which appear to have been custom made for working with internal data from Musk’s companies, including SpaceX, Tesla and Twitter/X, KrebsOnSecurity has …

xAI Dev Leaks API Key for Private SpaceX, Tesla LLMs Read More »

Alleged ‘Scattered Spider’ Member Extradited to U.S.

   ​ A 23-year-old Scottish man thought to be a member of the prolific Scattered Spider cybercrime group was extradited last week from Spain to the United States, where he is facing charges of wire fraud, conspiracy and identity theft. U.S. prosecutors allege Tyler Robert Buchanan and co-conspirators hacked into dozens of companies in the United …

Alleged ‘Scattered Spider’ Member Extradited to U.S. Read More »

DOGE Worker’s Code Supports NLRB Whistleblower

   ​ A whistleblower at the National Labor Relations Board (NLRB) alleged last week that denizens of Elon Musk’s Department of Government Efficiency (DOGE) siphoned gigabytes of data from the agency’s sensitive case files in early March. The whistleblower said accounts created for DOGE at the NLRB downloaded three code repositories from GitHub. Further investigation into …

DOGE Worker’s Code Supports NLRB Whistleblower Read More »

Whistleblower: DOGE Siphoned NLRB Case Data

   ​ A security architect with the National Labor Relations Board (NLRB) alleges that employees from Elon Musk’s Department of Government Efficiency (DOGE) transferred gigabytes of sensitive data from agency case files in early March, using short-lived accounts configured to leave few traces of network activity. The NLRB whistleblower said the unusual large data outflows coincided …

Whistleblower: DOGE Siphoned NLRB Case Data Read More »

Funding Expires for Key Cyber Vulnerability Database

   ​ A critical resource that cybersecurity professionals worldwide rely on to identify, mitigate and fix security vulnerabilities in software and hardware is in danger of breaking down. The federally funded, non-profit research and development organization MITRE warned today that its contract to maintain the Common Vulnerabilities and Exposures (CVE) program — which is traditionally funded …

Funding Expires for Key Cyber Vulnerability Database Read More »

Scroll to Top