Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area.…
The duo were key members of a prolific cybercrime group known as Scatt…
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR].…
The action comes roughly two weeks after KrebsOnSecurity published fin…
The NetNut homepage today was replaced by this seizure banner from the…
On June 19, three different security firms issued similar findings: Th…
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a recent data leak in which a contractor published dozens of internal CISA credentials — including AWS Govcloud keys — in a public GitHub repository for almost six months before being notified by KrebsOnSecurity.…
Experts say the gaps identified in the agency’s initial response provi…
On May 15, 2026, the security firm GitGuardian asked for help in notif…
One of the exposed files, titled “importantAWStokens,” included the ad…
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.…
The X/Twitter account IRIS C2 (@C2IRIS) has gained more than 4,000 fol…
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user’s Internet connection out to strangers.…
But a groundbreaking new analysis finds these devices also routinely s…
Pedro Falé is a threat researcher with the security firm Bitsight.
Falé told KrebsOnSecurity he was able to peer inside a vast and comple…
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node.…
The move comes less than a month after researchers found that more tha…
Proxy SDK prevalence among smart TV apps for LG (webOS) and Samsung (T…
Canadian Man Pleads Guilty in Snowflake Extortions
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud provider Snowflake.…
Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing …
A surveillance photo of Connor Riley Moucka, a.
“Judische” and “Waifu,” dated Oct 21, 2024, 9 days before Moucka’s arr…
Who’s Tracking You? Use This New Service to Find Out
It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day.…
That information is already semi-public, but it is not easily parsed a…
Not anymore: A powerful and free new service called DecryptAds scrapes…
A Decryptads summary of the advertising partnerships declared by espn.
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.…
Image: Shutterstock, Mallika Home Studio.
August’s overstuffed bundle of patch joy from Microsoft did not eclips…
Microsoft has attributed the recent patch deluge to vulnerability disc…