Black Basta’s alleged ringleader identified as authorities raid homes of other members

Oleg Evgenievich Nefedov, a 35-year-old Russian national, is accused of forming and running the ransomware outfit since 2022. He’s now on Europol and Interpol’s most-wanted lists.

The post Black Basta’s alleged ringleader identified as authorities raid homes of other members appeared first on CyberScoop.

Continue reading Black Basta’s alleged ringleader identified as authorities raid homes of other members

The thin line between saving a company and funding a crime

Ransomware negotiators dish on being in a ‘moral gray zone,’ unrestricted by accountability or industrywide rules of engagement.

The post The thin line between saving a company and funding a crime appeared first on CyberScoop.

Continue reading The thin line between saving a company and funding a crime

Jordanian national pleads guilty after unknowingly selling FBI agent access to 50 company networks

Authorities linked the 40-year-old to multiple crimes by tracing the email address he used for a cybercrime forum to the same account he used to apply for a U.S. visa in 2016.

The post Jordanian national pleads guilty after unknowingly selling FBI agent access to 50 company networks appeared first on CyberScoop.

Continue reading Jordanian national pleads guilty after unknowingly selling FBI agent access to 50 company networks

Kimwolf botnet’s swift rise to 2M infected devices agitates security researchers

The botnet took an unusual path by abusing residential proxy networks, allowing it to control an untapped collection of unofficial Android TV devices.

The post Kimwolf botnet’s swift rise to 2M infected devices agitates security researchers appeared first on CyberScoop.

Continue reading Kimwolf botnet’s swift rise to 2M infected devices agitates security researchers

Microsoft Patch Tuesday addresses 112 defects, including one actively exploited zero-day

Researchers said the information disclosure zero-day exposes sensitive information that attackers can use to undermine defenses and make other exploits more reliable.

The post Microsoft Patch Tuesday addresses 112 defects, including one actively exploited zero-day appeared first on CyberScoop.

Continue reading Microsoft Patch Tuesday addresses 112 defects, including one actively exploited zero-day

Spanish police disrupt Black Axe, arrest alleged leaders in action spanning four cities

The criminal organization specialized in business email compromise scams and generated billions of dollars in criminal proceeds annually from many small-scale operations, officials said.

The post Spanish police disrupt Black Axe, arrest alleged leaders in action spanning four cities appeared first on CyberScoop.

Continue reading Spanish police disrupt Black Axe, arrest alleged leaders in action spanning four cities

Inside Vercel’s sleep-deprived race to contain React2Shell

Talha Tariq quickly found his company at the center of a fast-moving, high-stakes mitigation effort. The result: a bounty program, a cat-and-mouse patch fight, and a debate about open-source security coordination.

The post Inside Vercel’s sleep-deprived race to contain React2Shell appeared first on CyberScoop.

Continue reading Inside Vercel’s sleep-deprived race to contain React2Shell

Researchers rush to warn defenders of max-severity defect in n8n

Roughly 100,000 servers running the automated workflow platform for AI and other enterprise tools are potentially exposed to exploitation.

The post Researchers rush to warn defenders of max-severity defect in n8n appeared first on CyberScoop.

Continue reading Researchers rush to warn defenders of max-severity defect in n8n

MongoBleed defect swirls, stamping out hope of year-end respite

The high-severity vulnerability is under active exploitation and affects many versions of MongoDB, a nearly ubiquitous open-source database.

The post MongoBleed defect swirls, stamping out hope of year-end respite appeared first on CyberScoop.

Continue reading MongoBleed defect swirls, stamping out hope of year-end respite