Krebs

ShinyHunters Extorted Boeing Spin-off Prior to Arrests

A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion groupShinyHuntershas been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang. KrebsOnSecurity has learned that the suspect, who uses the hacker handle “Rey,” was detained as ShinyHunters was in the process of extorting a business unit recently divested by the global aerospace companyBoeing, which manufactures the fleet of planes used by the employer of Rey’s fat

Read More
ReversingLabs

CRA compliance will be judged by the binary you ship

Many organizations still talk about the EU Cyber Resilience Act (CRA) as a 2027 problem. It stopped being one on Sept. 11, 2026. Since that date, manufacturers must report actively exploited vulnerabilities and severe incidents in products already on the EU market, legacy releases included. Full applicationfollows on Dec. 11, 2027, when every new product must meet the Annex I essential requirements, carry technical documentation, and bear the CE mark.Most CRA programs are being built from polici

Read More
ReversingLabs

Dependency installation security measure already defeated on npm

Key takeawaysnpm’s July fix has already been bypassed.Version 12 stopped running install scripts by default, but the malicious indexed-btree package hides its trigger in a prototype method. The malware runs when the app uses the library, not when it’s installed.A clean package.json is no longer a trust signal.Having no install hooks gave reviewers false comfort. This campaign targets that blind spot, and it backs the package with a fake GitHub repo and developer profile.Install-time checks aren’

Read More
Krebs

Canadian Man Pleads Guilty in Snowflake Extortions

A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud providerSnowflake.Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers.A surveillance photo of Connor Riley Moucka, a.k.a. “Judische” and “Waifu,” dated Oct 21, 2024, 9 days before Mouck

Read More
Krebs

Microsoft Plugs Nearly 400 Security Holes

Microsofttoday released updates to remedy at least 398 security vulnerabilities in itsWindowsoperating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.Image: Shutterstock, Mallika Home Studio.August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release ofmore than 570 security updates last month, but it is double June’s then-record batch ofnearly 200

Read More
Krebs

Who’s Tracking You? Use This New Service to Find Out

It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service calledDecryptAdsscrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that a

Read More
ReversingLabs

Why the smartest LLMs are not-so-smart pen testers

Key takeawaysThe harness matters more than the model:Ridge Security’s benchmark of eight leading LLMs found that how well an AI does at autonomous pen testing depends more on the system around the model than on how smart the model is.Higher coverage costs a lot more:Grok 4.5 had the highest coverage at 77%, and Claude Opus 4.6 reached 63% at $217 per run. Smaller and open-source models like Gemini 3 Flash and GPT-OSS-120B cost a fraction of that, and a well-built harness can close much of the ga

Read More
Krebs

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Authorities in Australia have arrested two men believed to be members ofTeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever.Ina statementreleased today, theAustralian Federal Police(AFP) said two men from Western Australia, aged 21 and 23, were arrested in connection with a “sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.”The

Read More