One frustrating aspect of email phishing is the frequency with which scammers fall back on tried-and-true methods that really have no business working these days. Like attaching a phishing email to a traditional, clean email message, or leveraging link redirects on LinkedIn, or abusing an encoding method that makes it easy to disguise booby-trapped Microsoft […]
How Malicious Android Apps Slip Into Disguise – Krebs on Security
Researchers say mobile malware purveyors have been abusing a bug in the Google Android platform that lets them sneak malicious code into mobile apps and evade security scanning tools. Google says it has updated its app malware detection mechanisms in response to the new research. At issue is a mobile malware obfuscation method identified by […]
Who and What is Behind the Malware Proxy Service SocksEscort? – Krebs on Security
Researchers this month uncovered a two-year-old Linux-based remote access trojan dubbed AVrecon that enslaves Internet routers into botnet that bilks online advertisers and performs password-spraying attacks. Now new findings reveal that AVrecon is the malware engine behind a 12-year-old service called SocksEscort, which rents hacked residential and small business devices to cybercriminals looking to hide […]
Russia Sends Cybersecurity CEO to Jail for 14 Years – Krebs on Security
The Russian government today handed down a treason conviction and 14-year prison sentence on Iyla Sachkov, the former founder and CEO of one of Russia’s largest cybersecurity firms. Sachkov, 37, has been detained for nearly two years under charges that the Kremlin has kept classified and hidden from public view, and he joins a growing […]
Cost of a Data Breach for UK Businesses Averages £3.4m
UK organisations that extensively use security AI and automation reduced data breach costs by £1.6m on average; Globally, ransomware victims that chose not to involve law enforcement faced $470,000 in extra costs Jul 24, 2023 LONDON, UK. 24 July 2023 – IBM Security today released its annual Cost of a Data Breach Report,1 which revealed […]
Few Fortune 100 Firms List Security Pros in Their Executive Ranks – Krebs on Security
Many things have changed since 2018, such as the names of the companies in the Fortune 100 list. But one aspect of that vaunted list that hasn’t shifted much since is that very few of these companies list any security professionals within their top executive ranks. The next time you receive a breach notification letter […]
LeakedSource Owner Quit Ashley Madison a Month Before 2015 Hack – Krebs on Security
[This is Part III in a series on research conducted for a recent Hulu documentary on the 2015 hack of marital infidelity website AshleyMadison.com.] In 2019, a Canadian company called Defiant Tech Inc. pleaded guilty to running LeakedSource[.]com, a service that sold access to billions of passwords and other data exposed in countless data breaches. […]
As Consumers Shift Towards A ‘Smarter’ Digital Life, Reliability, Security and Sustainability Emerge as Key Needs
News Summary: Consumer expectations will reshape the needs and economics of the internet. Today, more than 60% of consumers in EMEA expect to connect cars, appliances, energy and water to the internet, and broadband networks must scale to support this. Increased dependence on broadband for everyday tasks, however, means that while speed is […]
SEO Expert Hired and Fired By Ashley Madison Turned on Company, Promising Revenge – Krebs on Security
[This is Part II of a story published here last week on reporting that went into a new Hulu documentary series on the 2015 Ashley Madison hack.] It was around 9 p.m. on Sunday, July 19, when I received a message through the contact form on KrebsOnSecurity.com that the marital infidelity website AshleyMadison.com had been […]
Apple & Microsoft Patch Tuesday, July 2023 Edition – Krebs on Security
Microsoft Corp. today released software updates to quash 130 security bugs in its Windows operating systems and related software, including at least five flaws that are already seeing active exploitation. Meanwhile, Apple customers have their own zero-day woes again this month: On Monday, Apple issued (and then quickly pulled) an emergency update to fix a […]