Kerbs on Security

February Updates from Adobe, Microsoft

23 hours 27 minutes ago
A handful of readers have inquired as to the whereabouts of Microsoft's usual monthly patches for Windows and related software. Microsoft opted to delay releasing any updates until next month, even though there is a zero-day vulnerability in Windows going around. However, Adobe did push out updates this week as per usual to fix critical issues in its Flash Player software
BrianKrebs

Men Who Sent Swat Team, Heroin to My Home Sentenced

3 days ago
It's been a remarkable week for cyber justice. On Thursday, a Ukrainian man who hatched a plan in 2013 to send heroin to my home and then call the cops when the drugs arrived was sentenced to 41 months in prison for unrelated cybercrime charges. Separately, a 19-year-old American who admitted to being part of a hacker group that sent a heavily-armed police force to my home in 2013 was sentenced to three years probation.
BrianKrebs

Who Ran Leakedsource.com?

5 days 2 hours ago
Late last month, multiple news outlets reported that unspecified law enforcement officials had seized the servers for Leakedsource.com, perhaps the largest online collection of usernames and passwords leaked or stolen in some of the worst data breaches -- including billions of credentials for accounts at top sites like LinkedIn, Myspace, and Yahoo. In a development that may turn out to be deeply ironic, it seems that the real-life identity of Leakedsource's principal owner may have been exposed by many of the same stolen databases he's been peddling.
BrianKrebs

Fast Food Chain Arby’s Acknowledges Breach

1 week 4 days ago
Sources at nearly a half-dozen banks and credit unions independently reached out over the past 48 hours to inquire if I'd heard anything about a data breach at Arby's fast-food restaurants. Asked about the rumors, Arby's told KrebsOnSecurity that it recently remediated a breach involving malicious software installed on payment card systems at hundreds of its restaurant locations nationwide.
BrianKrebs

‘Top 10 Spammer’ Indicted for Wire Fraud

1 week 5 days ago
Michael A. Persaud, a California man profiled in a Nov. 2014 KrebsOnSecurity story about a junk email purveyor tagged as one of the World's Top 10 Worst Spammers, was indicted this week on federal wire fraud charges tied to an alleged spamming operation.
BrianKrebs

House Passes Long-Sought Email Privacy Bill

1 week 5 days ago
The U.S. House of Representatives on Monday approved a bill that would update the nation's email surveillance laws so that federal investigators are required to obtain a court-ordered warrant for access to older stored emails. Under the current law, U.S. authorities can legally obtain stored emails older than 180 days using only a subpoena issued by a prosecutor or FBI agent without the approval of a judge.
BrianKrebs

InterContinental Confirms Breach at 12 Hotels

2 weeks ago
InterContinental Hotels Group (IHG), the parent company for thousands of hotels worldwide including Holiday Inn, acknowledged Friday that a credit card breach impacted at least a dozen properties nationwide. News of the breach was first reported by KrebsOnSecurity more than a month ago.
BrianKrebs

How Google Took on Mirai, KrebsOnSecurity

2 weeks 2 days ago
The third week of September 2016 was a dark and stormy one for KrebsOnSecurity. Wave after wave of huge denial-of-service attacks flooded this site, forcing me to pull the plug on it until I could secure protection from further assault. The site resurfaced three days later under the aegis of Google's Project Shield, an initiative which seeks to protect journalists and news sites from being censored by these crippling digital sieges. Damian Menscher, a Google security engineer with whom I worked very closely on the migration to Project Shield, spoke publicly for the first time this week about the unique challenges involved in protecting a small site like this one from very large, sustained and constantly morphing attacks.
BrianKrebs

IRS: Scam Blends CEO Fraud, W-2 Phishing

2 weeks 4 days ago
Most regular readers here are familiar with CEO fraud -- e-mail scams in which the attacker spoofs the boss and tricks an employee at the organization into wiring funds to the fraudster. Loyal readers also have heard an earful about W-2 phishing, in which crooks impersonate the boss and request a copy of all employee tax forms. According to a new "urgent alert" issued by the U.S. Internal Revenue Service, scammers are now combining both schemes and targeting a far broader range of organizations than ever before.
BrianKrebs

Shopping for W2s, Tax Data on the Dark Web

2 weeks 5 days ago
The 2016 tax season is now in full swing in the United States, which means scammers are once again assembling vast dossiers of personal data and preparing to file fraudulent tax refund requests on behalf of millions of Americans. But for those lazy identity thieves who can't be bothered to phish or steal the needed data, there is now another option: Buying stolen W-2 tax forms from other crooks who have phished the documents wholesale from corporations.
BrianKrebs

A Shakeup in Russia’s Top Cybercrime Unit

3 weeks 1 day ago
A chief criticism I heard from readers of my book, Spam Nation: The Inside Story of Organized Cybercrime, was that it dealt primarily with petty crooks involved in petty crimes, while ignoring more substantive security issues like government surveillance and cyber war. But now it appears that the chief antagonist of Spam Nation is at the dead center of an international scandal involving the hacking of U.S. state electoral boards in Arizona and Illinois, the sacking of Russia's top cybercrime investigators, and the slow but steady leak of unflattering data on some of Russia's most powerful politicians.
BrianKrebs

ATM ‘Shimmers’ Target Chip-Based Cards

3 weeks 2 days ago
Several readers have called attention to warnings coming out of Canada about a supposed new form of ATM skimming called "shimming." Shimming attacks are not new (KrebsOnSecurity first wrote about them in August 2015), but they are likely to become more common as a greater number of banks in the United States shift to issuing chip-based cards. Here's a brief primer on shimming attacks, and why they succeed.
BrianKrebs

Who is Anna-Senpai, the Mirai Worm Author?

1 month ago
On September 22, 2016, this site was forced offline for nearly four days after it was hit with “Mirai,” a malware strain that enslaves poorly secured Internet of Things (IoT) devices like wireless routers and security cameras into a botnet for use in large cyberattacks. Roughly a week after that assault, the individual(s) who launched that attack -- using the name “Anna Senpai” -- released the source code for Mirai, spawning dozens of copycat attack armies online. After months of digging, KrebsOnSecurity is now confident to have uncovered Anna Senpai’s real-life identity, and the identity of at least one co-conspirator who helped to write and modify the malware.
BrianKrebs

Adobe, Microsoft Push Critical Security Fixes

1 month 1 week ago
Adobe and Microsoft on Tuesday each released security updates for software installed on hundreds of millions of devices. Adobe issued an update for Flash Player and for Acrobat/Reader. Microsoft released just four updates to plug some 15 security holes in Windows and related software.
BrianKrebs

Extortionists Wipe Thousands of Databases, Victims Who Pay Up Get Stiffed

1 month 1 week ago
Tens of thousands of personal and possibly proprietary databases that were left accessible to the public online have just been wiped from the Internet, replaced with ransom notes demanding payment for the return of the files. Adding insult to injury, it appears that virtually none of the victims who have paid the ransom have gotten their files back because multiple fraudsters are now wise to the extortion attempts and are competing to replace each other's ransom notes.
BrianKrebs

Krebs’s Immutable Truths About Data Breaches

1 month 1 week ago
I've had several requests for a fresh blog post to excerpt something that got crammed into the corner of a lengthy story published here Sunday: A list of immutable truths about data breaches, cybersecurity and the consequences of inaction.
BrianKrebs

Stolen Passwords Fuel Cardless ATM Fraud

1 month 2 weeks ago
Some financial instutitions are now offering so-called "cardless ATM" transactions that allow customers to withdraw cash using nothing more than their mobile phones. But as the following story illustrates, this new technology also creates an avenue for thieves to quickly and quietly convert stolen customer bank account usernames and passwords into cold hard cash. Worse still, fraudulent cardless ATM withdrawals may prove more difficult for customers to dispute because they place the victim at the scene of the crime.
BrianKrebs

The FTC’s Internet of Things (IoT) Challenge

1 month 2 weeks ago
One of the biggest cybersecurity stories of 2016 was the surge in online attacks caused by poorly-secured "Internet of Things" (IoT) devices such as Internet routers, security cameras, digital video recorders (DVRs) and smart appliances. Many readers here have commented with ideas about how to counter vulnerabilities caused by out-of-date software in IoT devices, so why not pitch your idea for money? Who knows, you could win up to $25,000 in a new contest put on by the U.S. Federal Trade Commission (FTC).
BrianKrebs

The Download on the DNC Hack

1 month 2 weeks ago
Over the past few weeks, I've been inundated with questions from readers asking why I haven't written much about two stories that have consumed the news media of late: The alleged Russian hacking attacks against the Democratic National Committee (DNC) and, more recently, the discovery of malware on a laptop at a Vermont power utility that has been attributed to Russian hacker groups. I've avoided covering these stories mainly because I don't have any original reporting to add to them, and because I generally avoid chasing the story of the day -- preferring instead to focus on producing original journalism on cybercrime and computer security.
BrianKrebs
Checked
1 hour 17 minutes ago
In-depth security news and investigation
Subscribe to Kerbs on Security feed