Tag Archives: security

Arizona woman accused of helping North Koreans get remote IT jobs at 300 companies

Getty Images | the-lightwriter reader comments 49 An Arizona woman has been accused of helping generate millions of dollars for North Korea’s ballistic missile program by helping citizens of that country land IT jobs at US-based Fortune 500 companies. Christina Marie Chapman, 49, of Litchfield Park, Arizona, raised $6.8 million in the scheme, federal prosecutors… Read More »

BreachForums, an online bazaar for stolen data, seized by FBI

Enlarge / The front page of BreachForums. reader comments 18 The FBI and law enforcement partners worldwide have seized BreachForums, a website that openly trafficked malware and data stolen in hacks. The site has operated for years as an online trading post where criminals could buy and sell all kinds of compromised data, including passwords,… Read More »

Linux maintainers were infected for 2 years by SSH-dwelling backdoor with huge reach

reader comments 16 Infrastructure used to maintain and distribute the Linux operating system kernel was infected for two years, starting in 2009, by sophisticated malware that managed to get a hold of one of the developers’ most closely guarded resources: the /etc/shadow files that stored encrypted password data for more than 550 system users, researchers… Read More »

Black Basta ransomware group is imperiling critical infrastructure, groups warn

Getty Images reader comments 22 Federal agencies, health care associations, and security researchers are warning that a ransomware group tracked under the name Black Basta is ravaging critical infrastructure sectors in attacks that have targeted more than 500 organizations in the past two years. One of the latest casualties of the native Russian-speaking group, according… Read More »

Google patches its fifth zero-day vulnerability of the year in Chrome

reader comments 23 Google has updated its Chrome browser to patch a high-severity zero-day vulnerability that allows attackers to execute malicious code on end user devices. The fix marks the fifth time this year the company has updated the browser to protect users from an existing malicious exploit. The vulnerability, tracked as CVE-2024-4671, is a… Read More »

Dell warns of “incident” that may have leaked customers’ personal info

reader comments 32 For years, Dell customers have been on the receiving end of scam calls from people claiming to be part of the computer maker’s support team. The scammers call from a valid Dell phone number, know the customer’s name and address, and use information that should be known only to Dell and the… Read More »

Critical vulnerabilities in BIG-IP appliances leave big networks open to intrusion

Getty Images reader comments 15 Researchers on Wednesday reported critical vulnerabilities in a widely used networking appliance that leaves some of the world’s biggest networks open to intrusion. The vulnerabilities reside in BIG-IP Next Central Manager, a component in the latest generation of the BIG-IP line of appliances, which organizations use to manage traffic going… Read More »

Ransomware mastermind LockBitSupp reveled in his anonymity—now he’s been ID’d

Enlarge / Dmitry Yuryevich Khoroshev, aka LockBitSupp UK National Crime Agency reader comments 62 Since at least 2019, a shadowy figure hiding behind several pseudonyms has publicly gloated for extorting millions of dollars from thousands of victims he and his associates had hacked. Now, for the first time, “LockBitSupp” has been unmasked by an international… Read More »

Novel attack against virtually all VPN apps neuters their entire purpose

Getty Images reader comments 123 Researchers have devised an attack against nearly all virtual private network applications that forces them to send and receive some or all traffic outside of the encrypted tunnel designed to protect it from snooping or tampering. TunnelVision, as the researchers have named their attack, largely negates the entire purpose and… Read More »