Skip to main content

Trending In Library Management

Bookend: A Library of Laughs

Jenny Robb at the Billy Ireland Cartoon Library and Museum at Ohio State University in Columbus. Photo: Stephen Takacs Jenny Robb says we are living in the golden age of cartoons and comics. “When I was growing up, we didn’t have graphic novels for a children’s audience,” says Robb, head curator of the Billy Ireland […]

Reading for Our Lives

In mid-March, I spoke on a panel at the South by Southwest EDU conference in Texas to discuss the alarming and increasingly weaponized attempts to ban and remove books from public and school libraries. Joining me on the panel were Carolyn Foote, retired school librarian and FReadom Fighters cofounder; Kelvin Watson, executive director of Las […]

Newsmaker: Kelly Yang

Kelly Yang Photo: Jessica Sample As a kid, the library was the first place Kelly Yang felt invited to “dream bigger.” Yang, now a bestselling and award-winning middle-grade and YA author, spent her childhood moving from city to city, making it difficult to find her footing. But everywhere she went, she could find familiar stories […]

Many Public Salesforce Sites a1

A shocking number of organizations — including banks and healthcare providers — are leaking private and sensitive information from their public Salesforce Community websites, KrebsOnSecurity has learned. The data exposures all stem from a misconfiguration in Salesforce Community that allows an unauthenticated user to access records that should only be available after logging in. A […]

Have you trained an AI?

Thanks to Mita Williams for pointing to this Washington Post article that makes it trivial to search and see whether any sites you’re affiliated with have been used to train “Google’s C4 data set, a massive snapshot of the contents of 15 million websites that have been used to instruct some high-profile English-language AIs, called […]

3CX Breach Was a Double Supply1

We learned some remarkable new details this week about the recent supply-chain attack on VoIP software provider 3CX. The lengthy, complex intrusion has all the makings of a cyberpunk spy novel: North Korean hackers using legions of fake executive accounts on LinkedIn to lure people into opening malware disguised as a job offer; malware targeting Mac […]

Giving a Face to the Malware P1

For the past seven years, a malware-based proxy service known as “Faceless” has sold anonymity to countless cybercriminals. For less than a dollar per day, Faceless customers can route their malicious traffic through tens of thousands of compromised systems advertised on the service. In this post we’ll examine clues left behind over the past decade […]

Why is ‘Juice Jacking’ Suddenl

KrebsOnSecurity received a nice bump in traffic this week thanks to tweets from the Federal Bureau of Investigation (FBI) and the Federal Communications Commission (FCC) about “juice jacking,” a term first coined here in 2011 to describe a potential threat of data theft when one plugs their mobile device into a public charging kiosk. It […]

Microsoft (& Apple) Patch Tues

Microsoft today released software updates to plug 100 security holes in its Windows operating systems and other software, including a zero-day vulnerability that is already being used in active attacks. Not to be outdone, Apple has released a set of important updates addressing two zero-day vulnerabilities that are being used to attack iPhones, iPads and […]

FBI Seizes Bot Shop ‘Genesis M

Several domain names tied to Genesis Market, a bustling cybercrime store that sold access to passwords and other data stolen from millions of computers infected with malicious software, were seized by the Federal Bureau of Investigation (FBI) today. The domain seizures coincided with more than a hundred arrests in the United States and abroad targeting […]

A Serial Tech Investment Scamm1

John Clifton Davies, a 60-year-old con man from the United Kingdom who fled the country in 2015 before being sentenced to 12 years in prison for fraud, has enjoyed a successful life abroad swindling technology startups by pretending to be a billionaire investor. Davies’ newest invention appears to be “CodesToYou,” which purports to be a […]

German Police Raid DDoS-Friend1

Authorities in Germany this week seized Internet servers that powered FlyHosting, a dark web offering that catered to cybercriminals operating DDoS-for-hire services, KrebsOnSecurity has learned. FlyHosting first advertised on cybercrime forums in November 2022, saying it was a Germany-based hosting firm that was open for business to anyone looking for a reliable place to host […]

Librarian of the Millennium: ‘

In this week’s Princh Library Blog post, guest writer Dr. Gopal Mohan Shukla shares the story and achievements of the ‘Librarian of the Millenium’, Palam Kalyanasundaram. Palam Kalyanasundaram Palam Kalyanasundaram, an 82-year-old retired librarian and social worker is often admired for his exceptional dedication in the field of social work. On the eve of republic […]

UK Sets Up Fake Booter Sites T1

The United Kingdom’s National Crime Agency (NCA) has been busy setting up phony DDoS-for-hire websites that seek to collect information on users, remind them that launching DDoS attacks is illegal, and generally increase the level of paranoia for people looking to hire such services. The warning displayed to users on one of the NCA’s fake […]