Skip to main content

LeakedSource Owner Quit Ashley1

[This is Part III in a series on research conducted for a recent Hulu documentary on the 2015 hack of marital infidelity website AshleyMadison.com.] In 2019, a Canadian company called Defiant Tech Inc. pleaded guilty to running LeakedSource[.]com, a service that sold access to billions of passwords and other data exposed in countless data breaches. […]

SEO Expert Hired and Fired By 1

[This is Part II of a story published here last week on reporting that went into a new Hulu documentary series on the 2015 Ashley Madison hack.] It was around 9 p.m. on Sunday, July 19, when I received a message through the contact form on KrebsOnSecurity.com that the marital infidelity website AshleyMadison.com had been […]

Apple & Microsoft Patch Tuesda

Microsoft Corp. today released software updates to quash 130 security bugs in its Windows operating systems and related software, including at least five flaws that are already seeing active exploitation. Meanwhile, Apple customers have their own zero-day woes again this month: On Monday, Apple issued (and then quickly pulled) an emergency update to fix a […]

Top Suspect in 2015 Ashley Mad1

When the marital infidelity website AshleyMadison.com learned in July 2015 that hackers were threatening to publish data stolen from 37 million users, the company’s then-CEO Noel Biderman was quick to point the finger at an unnamed former contractor. But as a new documentary series on Hulu reveals [SPOILER ALERT!], there was just one problem with […]

Who’s Behind the DomainNetwork

If you’ve ever owned a domain name, the chances are good that at some point you’ve received a snail mail letter which appears to be a bill for a domain or website-related services. In reality, these misleading missives try to trick people into paying for useless services they never ordered, don’t need, and probably will […]

Russian Cybersecurity Executiv1

Nikita Kislitsin, formerly the head of network security for one of Russia’s top cybersecurity firms, was arrested last week in Kazakhstan in response to 10-year-old hacking charges from the U.S. Department of Justice. Experts say Kislitsin’s prosecution could soon put the Kazakhstan government in a sticky diplomatic position, as the Kremlin is already signaling that […]

Secure and Safe Printing at Pu1

Public libraries serve as vital community resources, offering a wide range of services, including printing facilities. However, as libraries continue to embrace technology, it becomes increasingly important to ensure the security and privacy of patrons’ and the libraries’ printing activities. A recent example that illustrates this topic was the critical vulnerability found in PaperCut products. […]

U.K. Cyber Thug “PlugwalkJoe”

Joseph James “PlugwalkJoe” O’Connor, a 24-year-old from the United Kingdom who earned his 15 minutes of fame by participating in the July 2020 hack of Twitter, has been sentenced to five years in a U.S. prison. That may seem like harsh punishment for a brief and very public cyber joy ride. But O’Connor also pleaded […]

SMS Phishers Harvested Phone N1

The United Parcel Service (UPS) says fraudsters have been harvesting phone numbers and other information from its online shipment tracking tool in Canada to send highly targeted SMS phishing (a.k.a. “smishing”) messages that spoofed UPS and other top brands. The missives addressed recipients by name, included details about recent orders, and warned that those orders […]

Extraordinary Libraries in Une1

In this week’s Princh Library Blog post, guest writer Nina Grant encourages everyone to visit their local library but has a few specific libraries she wants to shed some light on. Check them out. Extraordinary Libraries in Unexpected Places The digital craze has made people infinitely more dependent on their phones and other devices, but […]

Why Malware Crypting Services 1

If you operate a cybercrime business that relies on disseminating malicious software, you probably also spend a good deal of time trying to disguise or “crypt” your malware so that it appears benign to antivirus and security products. In fact, the process of “crypting” malware is sufficiently complex and time-consuming that most serious cybercrooks will […]

CISA Order Highlights Persiste1

The U.S. government agency in charge of improving the nation’s cybersecurity posture is ordering all federal civilian agencies to take new measures to restrict access to Internet-exposed networking equipment. The directive comes amid a surge in attacks targeting previously unknown vulnerabilities in widely used security and networking appliances. Under a new order from the Cybersecurity […]

Microsoft Patch Tuesday, June 1

Microsoft Corp. today released software updates to fix dozens of security vulnerabilities in its Windows operating systems and other software. This month’s relatively light patch load has another added bonus for system administrators everywhere: It appears to be the first Patch Tuesday since March 2022 that isn’t marred by the active exploitation of a zero-day […]

Barracuda Urges Replacing — No

It’s not often that a zero-day vulnerability causes a network security vendor to urge customers to physically remove and decommission an entire line of affected hardware — as opposed to just applying software updates. But experts say that is exactly what transpired this week with Barracuda Networks, as the company struggled to combat a sprawling […]

Service Rents Email Addresses 1

One of the most expensive aspects of any cybercriminal operation is the time and effort it takes to constantly create large numbers of new throwaway email accounts. Now a new service offers to help dramatically cut costs associated with large-scale spam and account creation campaigns, by paying people to sell their email account credentials and […]

Ask Fitis, the Bear: Real Croo1

Code-signing certificates are supposed to help authenticate the identity of software publishers, and provide cryptographic assurance that a signed piece of software has not been altered or tampered with. Both of these qualities make stolen or ill-gotten code-signing certificates attractive to cybercriminal groups, who prize their ability to add stealth and longevity to malicious software. […]

2023 Annual Conference Preview

Illustration: ©greens87/Adobe Stock It’s been five years since librarianship’s largest event has taken place in Chicago, the hometown of the American Library Association (ALA). So much, both in the profession and the world around us, has changed since then. But so much of the 2023 Annual Conference and Exhibition will feel familiar—including top-tier authors, educational […]

Second to None

From left: Deep-dish pizza at Pizano’s Pizza and Pasta, Hudson Valley foie gras at Moody Tongue, and wood-roasted pig face at Girl & the Goat. Photos: Pizano’s Pizza and Pasta (pizza); Moody Tongue (foie gras); Galdones Photography (pig face) Welcome to Chicago! We have no doubt the American Library Association’s 2023 Annual Conference will provide […]