Menu Close
  • Russian FSB Counterintelligence Chief Gets 9 Years in Cybercrime Bribery Scheme
    by BrianKrebs on April 22, 2024 at 8:07 pm

    The head of counterintelligence for a division of the Russian Federal Security Service (FSB) was sentenced last week to nine years in a penal colony for accepting a USD $1.7 million bribe to ignore the activities of a prolific Russian cybercrime group that hacked thousands of e-commerce websites. The protection scheme was exposed in 2022 when Russian authorities arrested six members of the group, which sold millions of stolen payment cards at flashy online shops like Trump’s Dumps.

  • Who Stole 3.6M Tax Records from South Carolina?
    by BrianKrebs on April 16, 2024 at 11:26 am

    For nearly a dozen years, residents of South Carolina have been kept in the dark by state and federal investigators over who was responsible for hacking into the state’s revenue department in 2012 and stealing tax and bank account information for 3.6 million people. The answer may no longer be a mystery: KrebsOnSecurity found compelling clues suggesting the intrusion was carried out by the same Russian hacking crew that stole of millions of payment card records from big box retailers like Home Depot and Target in the years that followed.

  • Crickets from Chirp Systems in Smart Lock Key Leak
    by BrianKrebs on April 15, 2024 at 2:51 pm

    The U.S. government is warning that smart locks securing entry to an estimated 50,000 dwellings nationwide contain hard-coded credentials that can be used to remotely open any of the locks. The lock’s maker Chirp Systems remains unresponsive, even though it was first notified about the critical weakness in March 2021. Meanwhile, Chirp’s parent company, RealPage, Inc., is being sued by multiple U.S. states for allegedly colluding with landlords to illegally raise rents.

  • Why CISA is Warning CISOs About a Breach at Sisense
    by BrianKrebs on April 11, 2024 at 8:48 pm

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) said today it is investigating a breach at business intelligence company Sisense, whose products are designed to allow companies to view the status of multiple third-party online services in a single dashboard. CISA urged all Sisense customers to reset any credentials and secrets that may have been shared with the company, which is the same advice Sisense gave to its customers Wednesday evening.

  • Twitter’s Clumsy Pivot to X.com Is a Gift to Phishers
    by BrianKrebs on April 10, 2024 at 2:28 pm

    On April 9, Twitter/X began automatically modifying links that mention “twitter.com” to redirect to “x.com” instead. But over the past 48 hours, dozens of new domain names have been registered that demonstrate how this change could be used to craft convincing phishing links — such as fedetwitter[.]com, which is currently rendered as fedex.com in tweets.

  • April’s Patch Tuesday Brings Record Number of Fixes
    by BrianKrebs on April 9, 2024 at 8:28 pm

    If only Patch Tuesdays came around infrequently — like total solar eclipse rare — instead of just creeping up on us each month like The Man in the Moon. Although to be fair, it would be tough for Microsoft to eclipse the number of vulnerabilities fixed in this month’s patch batch — a record 147 flaws in Windows and related software.

  • Fake Lawsuit Threat Exposes Privnote Phishing Sites
    by BrianKrebs on April 4, 2024 at 2:12 pm

    A cybercrook who has been setting up websites that mimic the self-destructing message service Privnote.com accidentally exposed the breadth of their operations recently when they threatened to sue a software company. The disclosure revealed a profitable network of phishing sites that behave and look like the real Privnote, except that any messages containing cryptocurrency addresses will be automatically altered to include a different payment address controlled by the scammers.

  • Cyber Security Operation Center Guidelines for best practices SOC Design
    by Cyber Security Consultant on January 30, 2024 at 4:32 pm

    Cyber Security is become most needed services for all business and industries in 2024. Every business is concerned about Cyber Security. Security operations (SecOps) leaders face a multifaceted challenge: detecting elusive and novel threats using outdated tools, mitigating the risks posed by unexplored dark data, and managing the resource-intensive nature of staying ahead of evolving

  • HOW TO BECOME CERTIFIED LEAD IMPLEMENTER – ISO 27001
    by Cyber Security Consultant on January 26, 2023 at 11:21 am

    ABOUT CERTIFIED LEAD IMPLEMENTER TRAINING AND EXAMINATION FOR INFORMATION SECURITY MANAGEMENT SYSTEM ISO / IEC 27001 Learn and get certified as a professional in implementation of ISO 27001 standard through our self-paced E-learning interactive course which comprises of 4 modules. Upon completion of these modules, you can appear for an examination and get certified as

  • YouTube disrupted in Pakistan as former PM Imran Khan streams speech
    by Cyber Security Consultant on August 22, 2022 at 5:04 am

    NetBlocks metrics confirm the disruption of YouTube on multiple internet providers in Pakistan on Sunday 21 August 2022. The disruption comes as former Prime Minister Imran Khan makes a live broadcast to the public, despite a ban issued by the Pakistan Electronic Media Regulatory Authority (PEMRA). Real-time network data show the disruption in effect on

  • Recommendations for Parents about Cyber Bullying
    by Cyber Security Consultant on October 20, 2021 at 6:36 am

    Here are some dedicated tips for keeping younger children safe online. One of these training tips goes into the risks of young children on the Internet, covers cyber bullying and other risky Internet behavior. Here are the suggestions parents should take into account regarding kids online. • Talk with your kids about online safety and

  • WhatsApp, Facebook, Instagram server down in Pakistan?
    by Cyber Security Consultant on October 4, 2021 at 5:32 pm

    Facebook-owned social media platforms, WhatsApp, Facebook, and Instagram are facing a worldwide outage, according to Downdetector, which offers real-time status and outage information for all kinds of services. .https://d-31038805491725975734.ampproject.net/2109102127000/frame.html Downdetector showed that WhatsApp outage was reported at 8:23 pm (Pakistan Standard Time) and it shot up to 1,082 complaints by 8:38 pm. The website mentioned that

  • Cloudflare reports record-breaking HTTP-request DDoS attack
    by Cyber Security Consultant on August 22, 2021 at 7:26 pm

    Cloudflare reports thwarting the largest known HTTP-request distributed denial of service attack in history, approximately three times larger than any other previously reported. The attack in July reached 17.2 million requests per second, the company wrote in a blog post. For scale, the entirety of the Cloudflare network typically sees around 25 million requests per second

  • Microsoft announces recipients of academic grants for AI research on combating phishing
    by Cyber Security Consultant on June 19, 2021 at 3:34 pm

    Every day in the ever-changing technology landscape, we see boundaries shift as new ideas challenge the old status quo. This constant shift is observed in the increasingly sophisticated and connected tools, products, and services people and organizations use on a daily basis, but also in the security that needs to be built into these technologies