Cybersecurity

‘The Manipulaters’ Improve Phishing, Still Fail at Opsec

   ​ Roughly nine years ago, KrebsOnSecurity profiled a Pakistan-based cybercrime group called “The Manipulaters,” a sprawling web hosting network of phishing and spam delivery platforms. In January 2024, The Manipulaters pleaded with this author to unpublish previous stories about their work, claiming the group had turned over a new leaf and gone legitimate. But new …

‘The Manipulaters’ Improve Phishing, Still Fail at Opsec Read More »

Thread Hijacking: Phishes That Prey on Your Curiosity

   ​ Thread hijacking attacks. They happen when someone you know has their email account compromised, and you are suddenly dropped into an existing conversation between the sender and someone else. These missives draw on the recipient’s natural curiosity about being copied on a private discussion, which is modified to include a malicious link or attachment. …

Thread Hijacking: Phishes That Prey on Your Curiosity Read More »

Recent ‘MFA Bombing’ Attacks Targeting Apple Users

   ​ Several Apple customers recently reported being targeted in elaborate phishing attacks that involve what appears to be a bug in Apple’s password reset feature. In this scenario, a target’s Apple devices are forced to display dozens of system-level prompts that prevent the devices from being used until the recipient responds “Allow” or “Don’t Allow” …

Recent ‘MFA Bombing’ Attacks Targeting Apple Users Read More »

Mozilla Drops Onerep After CEO Admits to Running People-Search Networks

   ​ The nonprofit organization that supports the Firefox web browser said today it is winding down its new partnership with Onerep, an identity protection service recently bundled with Firefox that offers to remove users from hundreds of people-search sites. The move comes just days after a report by KrebsOnSecurity forced Onerep’s CEO to admit that …

Mozilla Drops Onerep After CEO Admits to Running People-Search Networks Read More »

CEO of Data Privacy Company Onerep.com Founded Dozens of People-Search Firms

   ​ The data privacy company Onerep.com bills itself as a Virginia-based service for helping people remove their personal information from almost 200 people-search websites. However, an investigation into the history of onerep.com finds this company is operating out of Belarus and Cyprus, and that its founder has launched dozens of people-search services over the years.​ …

CEO of Data Privacy Company Onerep.com Founded Dozens of People-Search Firms Read More »

Patch Tuesday, March 2024 Edition

   ​ Apple and Microsoft recently released software updates to fix dozens of security holes in their operating systems. Microsoft today patched at least 60 vulnerabilities in its Windows OS. Meanwhile, Apple’s new macOS Sonoma addresses at least 68 security weaknesses, and its latest updates for iOS fixes two zero-day flaws.​ ​[[{“value”:” Apple and Microsoft recently …

Patch Tuesday, March 2024 Edition Read More »

Incognito Darknet Market Mass-Extorts Buyers, Sellers

   ​ Borrowing from the playbook of ransomware purveyors, the darknet narcotics bazaar Incognito Market has begun extorting all of its vendors and buyers, threatening to publish cryptocurrency transaction and chat records of users who refuse to pay a fee ranging from $100 to $20,000. The bold mass extortion attempt comes just days after Incognito Market …

Incognito Darknet Market Mass-Extorts Buyers, Sellers Read More »

BlackCat Ransomware Group Implodes After Apparent $22M Payment by Change Healthcare

   ​ There are indications that U.S. healthcare giant Change Healthcare has made a $22 million extortion payment to the infamous BlackCat ransomware group (a.k.a. “ALPHV”) as the company struggles to bring services back online amid a cyberattack that has disrupted prescription drug services nationwide for weeks. However, the cybercriminal who claims to have given BlackCat …

BlackCat Ransomware Group Implodes After Apparent $22M Payment by Change Healthcare Read More »

Scroll to Top