Skip to main content

‘The Manipulaters’ Improve Phi

Roughly nine years ago, KrebsOnSecurity profiled a Pakistan-based cybercrime group called “The Manipulaters,” a sprawling web hosting network of phishing and spam delivery platforms. In January 2024, The Manipulaters pleaded with this author to unpublish previous stories about their work, claiming the group had turned over a new leaf and gone legitimate. But new research […]

Thread Hijacking: Phishes That1

Thread hijacking attacks. They happen when someone you know has their email account compromised, and you are suddenly dropped into an existing conversation between the sender and someone else. These missives draw on the recipient’s natural curiosity about being copied on a private discussion, which is modified to include a malicious link or attachment. Here’s […]

Recent ‘MFA Bombing’ Attacks T

Several Apple customers recently reported being targeted in elaborate phishing attacks that involve what appears to be a bug in Apple’s password reset feature. In this scenario, a target’s Apple devices are forced to display dozens of system-level prompts that prevent the devices from being used until the recipient responds “Allow” or “Don’t Allow” to […]

Mozilla Drops Onerep After CEO1

The nonprofit organization that supports the Firefox web browser said today it is winding down its new partnership with Onerep, an identity protection service recently bundled with Firefox that offers to remove users from hundreds of people-search sites. The move comes just days after a report by KrebsOnSecurity forced Onerep’s CEO to admit that he […]

Learning From Lived Experience1

In this week’s Princh Library Blog post, the Public Library Accessibility Resource Center (PLARC) project team discusses their history, why accessible libraries are important, and how you can start assessing your library’s accessibility. Enjoy! “I went to where the audiobooks were and looked for some titles to borrow.  I was using my hand-held magnifier and […]

The Not-so-True People-Search 1

It’s not unusual for the data brokers behind people-search websites to use pseudonyms in their day-to-day lives (you would, too). Some of these personal data purveyors even try to reinvent their online identities in a bid to hide their conflicts of interest. But it’s not every day you run across a US-focused people-search network based […]

CEO of Data Privacy Company On1

The data privacy company Onerep.com bills itself as a Virginia-based service for helping people remove their personal information from almost 200 people-search websites. However, an investigation into the history of onerep.com finds this company is operating out of Belarus and Cyprus, and that its founder has launched dozens of people-search services over the years. Onerep’s […]

Bookish Networking: Joining Li1

Have you moved recently and looking to make friends in your new community? Or perhaps, are you looking to expand your network with like-minded people? Then you should consider joining a literary circle in your community! In this week’s Princh Library Blog post, guest writer Jaydon Tanner gives his tips on how and why you […]

Patch Tuesday, March 2024 Edit1

Apple and Microsoft recently released software updates to fix dozens of security holes in their operating systems. Microsoft today patched at least 60 vulnerabilities in its Windows OS. Meanwhile, Apple’s new macOS Sonoma addresses at least 68 security weaknesses, and its latest update for iOS fixes two zero-day flaws. Last week, Apple pushed out an […]

Incognito Darknet Market Mass-1

Borrowing from the playbook of ransomware purveyors, the darknet narcotics bazaar Incognito Market has begun extorting all of its vendors and buyers, threatening to publish cryptocurrency transaction and chat records of users who refuse to pay a fee ranging from $100 to $20,000. The bold mass extortion attempt comes just days after Incognito Market administrators […]

Making Libraries More Digitall1

In this week’s Princh Library Blog post, guest writer Sam L. Bowman expands on what digital accessibility means for libraries, and suggest potential avenues for making your library more accessible. Enjoy! Equal access to literary resources, open thought, and learning is foundational to libraries. It’s what makes them vital to society and local communities. Resources […]

BlackCat Ransomware Group Impl1

There are indications that U.S. healthcare giant Change Healthcare has made a $22 million extortion payment to the infamous BlackCat ransomware group (a.k.a. “ALPHV“) as the company struggles to bring services back online amid a cyberattack that has disrupted prescription drug services nationwide for weeks. However, the cybercriminal who claims to have given BlackCat access […]

Fulton County, Security Expert1

The ransomware group LockBit told officials with Fulton County, Ga. they could expect to see their internal documents published online this morning unless the county paid a ransom demand. LockBit removed Fulton County’s listing from its victim shaming website this morning, claiming the county had paid. But county officials said they did not pay, nor […]

4 Tips for Streamlining Design1

In this week’s Princh Library Blog post, guest writer MiKayla Carter gives advices on how you can make your library’s design practices more efficient and cohesive. Enjoy! In today’s libraries, graphic design plays an important role in making books, technology, classes, and other resources more accessible to the communities we serve. Building managers use flyers […]

Calendar Meeting Links Used to1

Malicious hackers are targeting people in the cryptocurrency space in attacks that start with a link added to the target’s calendar at Calendly, a popular application for scheduling appointments and meetings. The attackers impersonate established cryptocurrency investors and ask to schedule a video conference call. But clicking the meeting link provided by the scammers prompts […]

FBI’s LockBit Takedown Postpon

The FBI’s takedown of the LockBit ransomware group last week came as LockBit was preparing to release sensitive data stolen from government computer systems in Fulton County, Ga. But LockBit is now regrouping, and the gang says it will publish the stolen Fulton County data on March 2 unless paid a ransom. LockBit claims the […]

New Leak Shows Business Side o1

A new data leak that appears to have come from one of China’s top private cybersecurity firms provides a rare glimpse into the commercial side of China’s many state-sponsored hacking groups. Experts say the leak illustrates how Chinese government agencies increasingly are contracting out foreign espionage campaigns to the nation’s burgeoning and highly competitive cybersecurity […]