Author: admin

IndependentKrebs

xAI Dev Leaks API Key for Private SpaceX, Tesla LLMs

Credit to Author: BrianKrebs| Date: Fri, 02 May 2025 00:52:00 +0000

A employee at Elon Musk’s artificial intelligence company xAI leaked a private key on GitHub that for the past two months could have allowed anyone to query private xAI large language models (LLMs) which appear to have been custom made for working with internal data from Musk’s companies, including SpaceX, Tesla and Twitter/X, KrebsOnSecurity has learned.

Read More
IndependentKrebs

Alleged ‘Scattered Spider’ Member Extradited to U.S.

Credit to Author: BrianKrebs| Date: Wed, 30 Apr 2025 21:54:59 +0000

A 23-year-old Scottish man thought to be a member of the prolific Scattered Spider cybercrime group was extradited last week from Spain to the United States, where he is facing charges of wire fraud, conspiracy and identity theft. U.S. prosecutors allege Tyler Robert Buchanan and co-conspirators hacked into dozens of companies in the United States and abroad, and that he personally controlled more than $26 million stolen from victims.

Read More
IndependentKrebs

DOGE Worker’s Code Supports NLRB Whistleblower

Credit to Author: BrianKrebs| Date: Wed, 23 Apr 2025 20:45:04 +0000

A whistleblower at the National Labor Relations Board (NLRB) alleged last week that denizens of Elon Musk’s Department of Government Efficiency (DOGE) siphoned gigabytes of data from the agency’s sensitive case files in early March. The whistleblower said accounts created for DOGE at the NLRB downloaded three code repositories from GitHub. Further investigation into one of those code bundles shows it is remarkably similar to a program published in January 2025 by Marko Elez, a 25-year-old DOGE employee who has worked at a number of Musk’s companies.

Read More
IndependentKrebs

Whistleblower: DOGE Siphoned NLRB Case Data

Credit to Author: BrianKrebs| Date: Tue, 22 Apr 2025 01:48:27 +0000

A security architect with the National Labor Relations Board (NLRB) alleges that employees from Elon Musk’s Department of Government Efficiency (DOGE) transferred gigabytes of sensitive data from agency case files in early March, using short-lived accounts configured to leave few traces of network activity. The NLRB whistleblower said the unusual large data outflows coincided with multiple blocked login attempts from an Internet address in Russia that tried to use valid credentials for a newly-created DOGE user account.

Read More
IndependentKrebs

Funding Expires for Key Cyber Vulnerability Database

Credit to Author: BrianKrebs| Date: Wed, 16 Apr 2025 03:59:18 +0000

A critical resource that cybersecurity professionals worldwide rely on to identify, mitigate and fix security vulnerabilities in software and hardware is in danger of breaking down. The federally funded, non-profit research and development organization MITRE warned today that its contract to maintain the Common Vulnerabilities and Exposures (CVE) program — which is traditionally funded each year by the Department of Homeland Security — expires on April 16.

Read More
IndependentKrebs

Trump Revenge Tour Targets Cyber Leaders, Elections

Credit to Author: BrianKrebs| Date: Tue, 15 Apr 2025 03:27:51 +0000

President Trump last week revoked security clearances for Chris Krebs, the former director of the Cybersecurity and Infrastructure Security Agency (CISA) who was fired by Trump after declaring the 2020 election the most secure in U.S. history. The White House memo, which also suspended clearances for other security professionals at Krebs’s employer SentinelOne, comes as CISA is facing huge funding and staffing cuts.

Read More
IndependentKrebs

China-based SMS Phishing Triad Pivots to Banks

Credit to Author: BrianKrebs| Date: Thu, 10 Apr 2025 15:31:58 +0000

China-based purveyors of SMS phishing kits are enjoying remarkable success converting phished payment card data into mobile wallets from Apple and Google. Until recently, the so-called “Smishing Triad” mainly impersonated toll road operators and shipping companies. But experts say these groups are now directly targeting customers of international financial institutions, while dramatically expanding their cybercrime infrastructure and support staff.

Read More
IndependentKrebs

Patch Tuesday, April 2025 Edition

Credit to Author: BrianKrebs| Date: Wed, 09 Apr 2025 03:09:36 +0000

Microsoft today released updates to plug at least 121 security holes in its Windows operating systems and software, including one vulnerability that is already being exploited in the wild. Eleven of those flaws earned Microsoft’s most-dire “critical” rating, meaning malware or malcontents could exploit them with little to no interaction from Windows users.

Read More