FBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts – no password required

So, you’ve enabled multi-factor authentication. You’ve taught your staff never to type their passwords into dodgy-looking login pages. Surely your Microsoft 365 accounts are safe now?

Well, think again.

Read more in my article on the Hot for Security… Continue reading FBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts – no password required

Defenders fall behind, as AI rewrites the rules of a data breach

For almost 20 years, stolen credentials have been the most common route for attackers into organizations, according to the Verizon Data Breach Investigations Report (DBIR). But that’s no longer the case.

Read more in my article on the Fortra blog. Continue reading Defenders fall behind, as AI rewrites the rules of a data breach

Smashing Security podcast #468: High-speed train hacks and homicidal lawnmowers

A 23-year-old radio enthusiast spent £300 on a piece of kit from the internet, and used it to bring four packed high-speed trains to a screeching halt. His defence in court? Possibly the most creative excuse we’ve heard all year.

Meanwhile, owners of … Continue reading Smashing Security podcast #468: High-speed train hacks and homicidal lawnmowers

FBI warns students and staff that ShinyHunters may come knocking after Canvas breach

Having receive a ransom payment for its attack on Canvas, ShinyHunters and other extortion gangs are only likely to be further incentivised to launch similar attacks in future.

Read more in my article on the Hot for Security blog. Continue reading FBI warns students and staff that ShinyHunters may come knocking after Canvas breach

When ransomware gets physical: cybercriminals turn to threats of violence

Pay up, or we’ll pay someone to pay you a visit. Cybercrime gangs are increasingly turning to real-world threats – and even hiring local muscle to deliver the message.

Read more in my article on the Hot for Security blog. Continue reading When ransomware gets physical: cybercriminals turn to threats of violence

Smashing Security podcast #467: How ShinyHunters hacked the world’s biggest universities

Welcome to the largest educational data breach in history – affecting nearly 9,000 institutions, every Ivy League university, and 30 million students mid-finals. When Canvas’s parent company refused to pay and announced they had deployed “security patc… Continue reading Smashing Security podcast #467: How ShinyHunters hacked the world’s biggest universities

One in eight UK workers has sold their company passwords, and bosses think it’s fine

One in eight UK workers admits to selling their company login credentials – or knowing someone who has – in the past 12 months.

The really alarming bit? Their bosses are even more relaxed about it.

Read more in my article on the Fortra blog. Continue reading One in eight UK workers has sold their company passwords, and bosses think it’s fine

Inside Department 4: Russia’s secret school for hackers

Most universities have a careers fair. At Bauman Moscow State Technical University, however, an elite group of students appear to have something rather more unusual: a direct pipeline into some of the world’s most notorious state-sponsored hacking grou… Continue reading Inside Department 4: Russia’s secret school for hackers

Sri Lanka makes 37 arrests as it raids another scam centre

You don’t need to live near a scam compound for it to wreck your life. Americans lost $5.8 billion to crypto investment scams last year alone – and a raid in Sri Lanka this month shows exactly how the operations behind them keep finding new places to h… Continue reading Sri Lanka makes 37 arrests as it raids another scam centre