#cybersecurity
Search
Items tagged with: Cybersecurity
#cybersecurity
Today's story is the result of an ungodly amount of research, and I am very glad to finally be able to share it with you.
Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever.
In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a “sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.”
The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old suspect’s real identity in June, and has been communicating with him ever since. This story includes interviews with TeamPCP’s self-described spokesperson, and examines clues left behind by the TeamPCP leader that likely led to his undoing.
Chinese hackers disrupted U.S. Justice Department, NASA, Federal Reserve, U.S. says
Your Expired Visa Card Could Be 'Zombified' to Make Contactless Payments
wired.com/story/security-news-…
Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments
Plus: Apple sends out an “unprecedented” number of spyware warnings, Ukraine hits a Russian ecommerce giant with cyber and drone attacks, and more.Andy Greenberg (WIRED)
Wildberries and sellers' combined losses from Ukrainian drone attacks estimated at hundreds of billions of rubles
#UkraineWar #Wildberries #DroneAttacks #EconomicLoss #CyberSecurity
meduza.io/en/news/2026/08/13/w…
Wildberries and sellers’ combined losses from Ukrainian drone attacks estimated at hundreds of billions of rubles — Meduza
Rebuilding Wildberries’ warehouses and other infrastructure destroyed in Ukrainian drone attacks could cost the online retailer between 147 billion and 223 billion rubles, Sergei Semko, lead analyst at the Data Insight research agency, told Forbes Ru…Meduza
That Chrome Update Pop-Up May Actually Be Malware
#OnlineSafety #Cybersecurity #Malware #TechAlert #GoogleChrome
lifehacker.com/tech/that-chrom…
That Chrome Update Pop-Up May Actually Be Malware
Compromised browser extensions appear to be distributing malicious scripts disguised as critical security updates.Emily Long (Lifehacker)
DEF CON crowd suspected in fake-hotspot attack on Delta flight
#CyberSecurity #CyberAttackInvestigation #DEFCON #TechNews #InformationSecurity
arstechnica.com/information-te…
DEF CON crowd suspected in fake-hotspot attack on Delta flight
FBI Atlanta confirms it's looking into the incident, no arrests made.Ars Contributors (Ars Technica)
Cyber Vulnerability Sweep Picks Up Royal Navy Drones Sending Data To China
#CyberVulnerability #CyberSecurity #UKDefense #Infosec #NationalSecurity
tech.slashdot.org/story/26/08/…
Cyber Vulnerability Sweep Picks Up Royal Navy Drones Sending Data To China - Slashdot
A routine security assessment found that cameras aboard Royal Navy Kraken unmanned surface vessels were sending "heartbeat" signals to an IP address in China.tech.slashdot.org
The Guardian: ‘It’s dangerous and it’s going to erode trust’: redesign of US government websites stokes surveillance fears
The National Design Studio, staffed by Doge veterans, installed visitor-tracking software on vital federal websites
"...An opaque White House office staffed largely by veterans of Elon Musk’s “department of government efficiency” (Doge) has quietly rebuilt some of the federal government’s most sensitive websites – for passport applications, voter registration, prescription-drug pricing and children’s savings – in ways critics say appear to violate federal law...."
LOL
circumstances.run/@davidgerard…
David Gerard (@davidgerard@circumstances.run)
Attached: 1 image SearchLeak: Prompt-inject enterprise Copilot with a search with the help of the 100% trusted Microsoft Bing https://www.youtube.com/watch?v=1lR5qpHPwNw&list=UU9rJrMVgcXTfa8xuMnbhAEA - video https://pivottoai.libsyn.David Gerard (GSV Sleeper Service)
Fortinet, is that the company that sells security breaches? 🤔
arstechnica.com/security/2026/…
Massive breach spills credentials for thousands of sensitive networks
The affected include Oracle, Lenovo, FedEx, a NATO contractor, and Fortinet.Dan Goodin (Ars Technica)
✈️ New Blog Post: Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn't Care.
Frontier's mobile API returns full passport numbers, home addresses, children's DOB, credit card details, and KTNs for any booking. The only auth? A PNR and last name. Printed on every boarding pass.
Reported March 3rd. 105 days later, still live. They fixed the least important vuln and ghosted me on the rest. They also updated the website code and somehow made the leaks worse.
Full writeup: bobdahacker.com/blog/frontier-…
#InfoSec #BugBounty #ResponsibleDisclosure #FrontierAirlines #Security #CyberSecurity #Privacy #Aviation #PCIDSS #DataExposure
Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn't Care.
How I found that anyone with a boarding pass photo can pull full passport numbers, home addresses, children's dates of birth, credit card details, and Known Traveler Numbers for every passenger on a Frontier Airlines booking. Reported March 3rd.bobdahacker.com
Oh, good thing it's so hard to install packages in Arch Linux, I hadn't yet loaded AUR 🤪
404 Media: This Company Will Add Phone, AirPod, and Smartwatch Trackers to License Plate Readers
404media.co/this-company-will-…
#alpr #privacy #cybersecurity #bigbrother
This Company Will Add Phone, AirPod, and Smartwatch Trackers to License Plate Readers
SignalTrace “links devices that regularly travel together, correlating them to license plate.” It is a surveillance product that will sweep up and add all sorts of Bluetooth and other data to license plate readers, linking specific devices—and people…Joseph Cox (404 Media)
Wired: Meta Silently Added Face-Recognition Code for Its Smart Glasses to Millions of Phones
Code reviewed by WIRED uncovered an unreleased face-recognition system embedded in Meta’s smart glasses platform. It’s designed to identify people via biometric data stored on users’ phones.
LOL Meta AI is hackable to change someone's registered email,, classic.
Malwarebytes: "A convincing fake website is impersonating OpenAI’s ChatGPT download page and infecting visitors with malware designed to steal passwords, browser data, cryptocurrency wallets, and other sensitive information."
malwarebytes.com/blog/threat-i…
#chatgpt #ai #cybersecurity #malware
Fake ChatGPT download site infects Windows and Mac users with malware
Searching for ChatGPT? This fake download site serves malware to both Windows and Mac users, using separate payloads tailored to each platform.Stefan Dasic (Malwarebytes)
Bwahahahahahahaha
404 Media: Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked
404media.co/hackers-simply-ask…
#aipocalypse #ai #cybersecurity
Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked
The exploit shows the extreme risk of offloading technical support to AI.Jason Koebler (404 Media)
😬
"...How bad is this?
A minimal POC:
curl -i -H ‘Host: foo’ http://target/admin # 403, blocked
curl -i -H ‘Host: foo?’ http://target/admin # 200, served
"
ostif.org/disclosing-the-badho…
Disclosing the BADHOST Vulnerability in Starlette – OSTIF.org
Disclosing the BADHOST Vulnerability in StarletteOSTIF.org
LOL
"...“A single character injected into the HTTP Host header bypasses path-based authorization in Starlette, the routing core of FastAPI,”..."
Arstechnica: Millions of AI agents imperiled by critical vulnerability in open source package
arstechnica.com/information-te…
#ai #cybersecurity #vulnerability
Millions of AI agents imperiled by critical vulnerability in open source package
BadHost" was found in Starlette, a package with 325 million weekly downloads.Dan Goodin (Ars Technica)
Oooh, this could be loads of fun.
IEEE Spectrum: Voice AI Systems Are Vulnerable to Hidden Audio Attacks
Research shows sounds unheard by human ears can hijack models’ behavior
❗ We’ve observed a scammer clearly abusing Microsoft's 'msonlineservicesteam@microsoftonline[. ]com' for spam distribution.
The header and message body appear completely legitimate - the abuse is happening through injection into the Subject:
✉️ Here's an example:
"Your PayPal order for 0.0092 BTC ($699.99) is complete. Not you? Call +1 (803) 237-5050 account email verification code."
At this point, it appears the attacker may have simply set the malicious text as either the account name or the organization name.
This also appears to line up with what @zackwhittaker TechCrunch Security Editor identified last week:
mastodon.social/@zackwhittaker…
....although the activity we’re seeing appears to stretch back several months.
Takeaway: automated notification systems should not allow this level of customization.
Microsoft has been informed of this abusive activity.
#ThreatIntel #Spam #InfoSec #CyberSecurity
Zack Whittaker (@zackwhittaker@mastodon.social)
Attached: 2 images Looks like hackers/scammers/asshats are abusing Microsoft's systems to send out crude phishing messages as two-factor emails. Emails are sent from msonlineservicesteam@microsoftonline[.Zack Whittaker (Mastodon)
Ooooh--found it!
So, this URL
hxxp://www.lwfinger.com/b43-firmware/ resolves to a URL that has been taken over by... who knows what. The below package has not been touched in 11 years.
github.com/mikhirev/b43-firmwa…
The firmware install then installs whatever it finds there. If it's got the right SHA checksum...
Anyone know what the right approach here is... (this is not my day job, lol).
cc @Viss
b43-firmware-install/b43-firmware-install at master · mikhirev/b43-firmware-install
Script to automate installing firmware for b43 driver - mikhirev/b43-firmware-installGitHub
This smacks of a compromised something or other... why is an apt upgrade of firmware-b43-installer going to a childcare blog. A violin shop? Hmm... reinstalling this entirely.
(Update: this apparently WAS a bug, but has been fixed in more recent versions of Debian... but not old ones h/t @alienghic )
salsa.debian.org/debian/b43-fw…
Update remote site where firmware can be fetched (5a328aad) · Commits · Debian / b43-fwcutter · GitLab
Utility for extracting Broadcom 43xx firmwareGitLab
Oops
Grafana Labs Security Breach – Hackers Access GitHub and Download Codebase
cybersecuritynews.com/grafana-…
Grafana Labs Security Breach - Hackers Access GitHub and Download Codebase
A threat actor infiltrated Grafana Labs' GitHub environment, stealing a privileged token to download the company's private codebase, and then attempted to extort the open-source observability giant with an unanswered ransom demand.Guru Baran (Cyber Security News)
Hmm, having heard of people who couldn't recover their computer (no bitlocker key), actually, that could be handy, lol. (ps. BACK UP YOUR BITLOCKER RECOVERY KEY if you have a Windows PC, lest you suddenly lose access to your PC because of some hardware repair...)
Anyway, the answer (after signing in) is searching for "Calculator.app" is a straightforward way of finding where people have posted CVE exploit code, lol. (all the cybersecurity people probably knew this, but I did not)
Oh boy, this is going to put a dent in the semester...
LA Times: Massive Canvas data breach hits colleges across California and nation, crippling student work
latimes.com/california/story/2…
Massive Canvas data breach hits colleges across California and nation, crippling student work
A massive data breach of the Instructure Canvas learning system hit UC, CSU, USC, Stanford and Los Angeles community colleges, among other schools across the nation. A criminal group called ShinyHunters claimed credit for the hack.Jaweed Kaleem (Los Angeles Times)
Wow... interesting these things work by overloading cell phone towers.
techcrunch.com/2026/05/07/poli…
Police arrest SMS blaster crew that sent malicious messages to thousands across Toronto | TechCrunch
Toronto police said this is the "first known instance" of an SMS blaster being used in Canada.Zack Whittaker (TechCrunch)
I can’t believe with Mastodon being as techie as it is, that I am one of the only people warning about this new bill in #Canada 🇨🇦
#tech #cdnpoli #privacy #cybersecurity
reclaimthenet.org/cybersecurit…
Cybersecurity Experts Demand Canada Scrap Bill C-22 Backdoor
The bill that promises not to surveil Canadians requires a year of every Canadian's location data sitting on private servers.Cindy Harper (Reclaim The Net)
We've all seen those obvious deepfakes online picturing Trump or Musk getting arrested by the FBI. The latest AI tools are now so advanced that looking for the usual signs like extra digits on hands is no longer helpful when trying to spot them. The Atlantic's Lila Shroff experiments with photorealistic images of bank alerts, passports and tax forms and explains how deepfakes are coming for our bank accounts.
#AI #Deepfakes #Cybersecurity #PersonalFinance #Scams
Deepfakes Are Coming for Your Bank Account
OpenAI made the perfect tool for scammers.Lila Shroff (The Atlantic)
New book, released under a Creative Commons BY-NC-ND license: "Don't Get Hacked! Protecting Yourself at Home": cs.columbia.edu/~smb/homesec/i…
Retoot for reach!