IT Security News

  • Why 8kun Went Offline During the January 6 Hearings

    The latest Jan. 6 committee hearing on Tuesday examined the role of conspiracy theory communities like 8kun[.]top and TheDonald[.]win in helping to organize and galvanize supporters who responded to former President Trump's invitation to "be wild" in Washington, D.C. on that chaotic day. At the same time the committee was hearing video testimony from 8kun founder Jim Watkins, 8kun and a slew of similar websites were suddenly yanked offline. Watkins suggested the outage was somehow related to the work of the committee, but the truth is KrebsOnSecurity was responsible and the timing was pure coincidence.

    read more 

  • Emerging H0lyGh0st Ransomware Tied to North Korea

    Microsoft has linked a threat that emerged in June 2021 and targets small-to-mid-sized businesses to state-sponsored actors tracked as DEV-0530.

    read more 

  • Journalists Emerge as Favored Attack Target for APTs

    Since 2021, various state-aligned threat groups have turned up their targeting of journalists to siphon data and credentials and also track them.

    read more 

  • Large-Scale Phishing Campaign Bypasses MFA

    Attackers used adversary-in-the-middle attacks to steal passwords, hijack sign-in sessions and skip authentication and then use victim mailboxes to launch BEC attacks against other targets.

    read more 

  • Microsoft Patch Tuesday, July 2022 Edition

    Microsoft today released updates to fix at least 86 security vulnerabilities in its Windows operating systems and other software, including a weakness in all supported versions of Windows that Microsoft warns is actively being exploited. The software giant also has made a controversial decision to put the brakes on a plan to block macros in Office documents downloaded from the Internet.

    read more 

  • How War Impacts Cyber Insurance

    Chris Hallenbeck, CISO for the Americas at Tanium, discusses the impact of geopolitical conflict on the cybersecurity insurance market.

    read more 

  • ‘Callback’ Phishing Campaign Impersonates Security Firms

    Victims instructed to make a phone call that will direct them to a link for downloading malware.

    read more 

  • Rethinking Vulnerability Management in a Heightened Threat Landscape

    Find out why a vital component of vulnerability management needs to be the capacity to prioritize from Mariano Nunez, CEO of Onapsis and Threatpost Infosec Insiders columnist.

    read more 

  • Popular NFT Marketplace Phished for $540M

    In March, a North Korean APT siphoned blockchain gaming platform Axie Infinity of $540M.

    read more 

  • Experian, You Have Some Explaining to Do

    Twice in the past month KrebsOnSecurity has heard from readers who've had their accounts at big-three credit bureau Experian hacked and updated with a new email address that wasn't theirs. In both cases the readers used password managers to select strong, unique passwords for their Experian accounts. Research suggests identity thieves were able to hijack the accounts simply by signing up for new accounts at Experian using the victim's personal information and a different email address.

    read more