LATEST POST
DOGE software engineer’s computer infected by info-stealing malware
Ars Technica reports on another concerning security issue involving DOGE: Login credentials belonging to an employee at both the Cybersecurity and Infrastructure Security Agency and the Department of Government Efficiency have appeared in multiple public leaks from info-stealer malware, a strong indication that devices belonging to him have been hacked in recent years. Kyle Schutt […]
UK’s MoJ investigating ‘data breach’ at Legal Aid Agency
The Law Society Gazette in the UK reports: The Ministry of Justice has revealed it is working with the National Crime Agency and National Cyber Security Centre to investigate a data breach at the Legal Aid Agency. According to Sky News, the LAA told law firms in a letter last week that it identified a ‘security incident’. […]
Messaging app seen in use by Mike Waltz suspends service after hackers claim breaches
The messaging app seen in use by Mike Waltz suspended service after hackers claimed to have breached it. But how many hackers gained access to it? On May 5, NBC News reported: TeleMessage, the app that President Donald Trump’s former national security adviser, Mike Waltz, appeared to use to archive his group chats, has suspended all services […]
GlobalX, Airline for Trump’s Deportations, Hacked
404 Media reports: Hackers have targeted GlobalX Air, one of the main airlines the Trump administration is using as part of its deportation efforts, and stolen what they say are flight records and passenger manifests of all of its flights, including those for deportation, 404 Media has learned. The data, which the hackers contacted 404 […]
Inside the cyberattack that cost M&S £650 million in days
The Independent reports: Hackers who targeted Marks & Spencer and the Co-op tricked IT workers to gain access into their companies systems, according to a report. The “social engineering” attack on the Co-op allowed cybercriminals to reset an employee’s password before breaching the network, with a similar tactic used against M&S, sources revealed to BleepingComputer website. Hundreds of agency workers […]
Luna Moth extortion hackers pose as IT help desks to breach US firms
Bleeping Computer reports: The data-theft extortion group known as Luna Moth, aka Silent Ransom Group, has ramped up callback phishing campaigns in attacks on legal and financial institutions in the United States. According to EclecticIQ researcher Arda Büyükkaya, the ultimate goal of these attacks is data theft and extortion. Luna Moth, known internally as Silent […]
Defending Against UNC3944/Scattered Spider: Cybercrime Hardening Guidance from the Frontlines – Mandiant
Background UNC3944, which overlaps with public reporting on Scattered Spider, is a financially-motivated threat actor characterized by its persistent use of social engineering and brazen communications with victims. In early operations, UNC3944 largely targeted telecommunications-related organizations to support SIM swap operations. However, after shifting to ransomware and data theft extortion in early 2023, they impacted […]