Krebs on Security

Krebs on Security In-depth security news and investigation

  • Oregon Man Charged in ‘Rapper Bot’ DDoS Service
    by BrianKrebs on August 19, 2025 at 8:51 pm

    A 22-year-old Oregon man has been arrested on suspicion of operating “Rapper Bot,” a massive botnet used to power a service for launching distributed denial-of-service (DDoS) attacks against targets — including a March 2025 DDoS that knocked Twitter/X offline. The Justice Department asserts the suspect and an unidentified co-conspirator rented out the botnet to online extortionists, and tried to stay off the radar of law enforcement by ensuring that their botnet was never pointed at KrebsOnSecurity.

  • Mobile Phishers Target Brokerage Accounts in ‘Ramp and Dump’ Cashout Scheme
    by BrianKrebs on August 15, 2025 at 6:27 pm

    Cybercriminal groups peddling sophisticated phishing kits that convert stolen card data into mobile wallets have recently shifted their focus to targeting customers of brokerage services, new research shows. Undeterred by security controls at these trading platforms that block users from wiring funds directly out of accounts, the phishers have pivoted to using multiple compromised brokerage accounts in unison to manipulate the prices of foreign stocks.

  • Microsoft Patch Tuesday, August 2025 Edition
    by BrianKrebs on August 12, 2025 at 10:14 pm

    Microsoft today released updates to fix more than 100 security flaws in its Windows operating systems and other software. At least 13 of the bugs received Microsoft’s most-dire “critical” rating, meaning they could be abused by malware or malcontents to gain remote access to a Windows system with little or no help from users.

  • KrebsOnSecurity in New ‘Most Wanted’ HBO Max Series
    by BrianKrebs on August 8, 2025 at 9:38 pm

    A new documentary series about cybercrime airing next month on HBO Max features interviews with Yours Truly. The four-part series follows the exploits of Julius Kivimäki, a prolific Finnish hacker recently convicted of leaking tens of thousands of patient records from an online psychotherapy practice while attempting to extort the clinic and its patients.

  • Who Got Arrested in the Raid on the XSS Crime Forum?
    by BrianKrebs on August 6, 2025 at 12:12 pm

    On July 22, 2025, the European police agency Europol said a long-running investigation led by the French Police resulted in the arrest of a 38-year-old administrator of XSS, a Russian-language cybercrime forum with more than 50,000 members. The action has triggered an ongoing frenzy of speculation and panic among XSS denizens about the identity of the unnamed suspect, but the consensus is that he is a pivotal figure in the crime forum scene who goes by the hacker handle “Toha.” Here’s a deep dive on what’s knowable about Toha, and a short stab at who got nabbed.

  • Scammers Unleash Flood of Slick Online Gaming Sites
    by BrianKrebs on July 30, 2025 at 6:46 pm

    Fraudsters are flooding Discord and other social media platforms with ads for hundreds of polished online gaming and wagering websites that lure people with free credits and eventually abscond with any cryptocurrency funds deposited by players. Here’s a closer look at the social engineering tactics and remarkable traits of this sprawling network of more than 1,200 scam sites.

  • Phishers Target Aviation Execs to Scam Customers
    by BrianKrebs on July 24, 2025 at 5:57 pm

    KrebsOnSecurity recently heard from a reader whose boss’s email account got phished and was used to trick one of the company’s customers into sending a large payment to scammers. An investigation into the attacker’s infrastructure points to a long-running Nigerian cybercrime group that is actively targeting established companies in the transportation and aviation industries.

  • Microsoft Fix Targets Attacks on SharePoint Zero-Day
    by BrianKrebs on July 21, 2025 at 2:45 pm

    On Sunday, July 20, Microsoft Corp. issued an emergency security update for a vulnerability in SharePoint Server that is actively being exploited to compromise vulnerable organizations. The patch comes amid reports that malicious hackers have used the Sharepoint flaw to breach U.S. federal and state agencies, universities, and energy companies.

  • Poor Passwords Tattle on AI Hiring Bot Maker Paradox.ai
    by BrianKrebs on July 18, 2025 at 1:23 am

    Security researchers recently revealed that the personal information of millions of people who applied for jobs at McDonald’s was exposed after they guessed the password (“123456”) for the fast food chain’s account at Paradox.ai, a company that makes artificial intelligence based hiring chatbots used by many Fortune 500 companies. Paradox.ai said the security oversight was an isolated incident that did not affect its other customers, but recent security breaches involving its employees in Vietnam tell a more nuanced story.

  • DOGE Denizen Marko Elez Leaked API Key for xAI
    by BrianKrebs on July 15, 2025 at 1:23 am

    Marko Elez, a 25-year-old employee at Elon Musk’s Department of Government Efficiency (DOGE), has been granted access to sensitive databases at the U.S. Social Security Administration, the Treasury and Justice departments, and the Department of Homeland Security. So it should fill all Americans with a deep sense of confidence to learn that Mr. Elez over the weekend inadvertently published a private key that allowed anyone to interact directly with more than four dozen large language models (LLMs) developed by Musk’s artificial intelligence company xAI.

Share Websitecyber
We are an ethical website cyber security team and we perform security assessments to protect our clients.