The phone call is the new phishing email

Voice-based phishing was at the root of multiple attack sprees Mandiant responded to last year, reflecting a concerning shift in tactics.

The post The phone call is the new phishing email appeared first on CyberScoop.

Continue reading The phone call is the new phishing email

Trio sentenced for facilitating North Korean IT worker scheme from their homes

The men facilitated about $1.28 million in salary from victim U.S. companies by hosting laptop farms and helping remote IT workers assume fake identities.

The post Trio sentenced for facilitating North Korean IT worker scheme from their homes appeared first on CyberScoop.

Continue reading Trio sentenced for facilitating North Korean IT worker scheme from their homes

Ubiquiti defect poses account takeover risk for UniFi Networking Application users

The maximum-severity vulnerability, which hasn’t been exploited in the wild yet, affects software customers use to manage networking devices.

The post Ubiquiti defect poses account takeover risk for UniFi Networking Application users appeared first on CyberScoop.

Continue reading Ubiquiti defect poses account takeover risk for UniFi Networking Application users

Justice Department disrupts botnet networks that hijacked 3 million devices

The Aisuru, Kimwolf, JackSkid and Mossad botnets enabled cybercriminals to initiate thousands of attacks. A crackdown targeting large-scale botnets continues amid growing challenges.

The post Justice Department disrupts botnet networks that hijacked 3 million devices appeared first on CyberScoop.

Continue reading Justice Department disrupts botnet networks that hijacked 3 million devices

North Carolina tech worker found guilty of insider attack netting $2.5M ransom

Cameron Nicholas Curry, also known as “Loot,” stole a trove of corporate data from a D.C.-based tech company as his six-month contract gig came to a close.

The post North Carolina tech worker found guilty of insider attack netting $2.5M ransom appeared first on CyberScoop.

Continue reading North Carolina tech worker found guilty of insider attack netting $2.5M ransom

Cisco’s latest vulnerability spree has a more troubling pattern underneath

Cisco’s response to the latest SD-WAN and firewall defects has been fast, but the harder question is how long sophisticated actors had a head start — and what’s already compromised.

The post Cisco’s latest vulnerability spree has a more troubling pattern underneath appeared first on CyberScoop.

Continue reading Cisco’s latest vulnerability spree has a more troubling pattern underneath

Zero lessons learned: Convicted scammer allegedly ran another athlete-focused phishing scam from federal prison

Kwamaine Jerell Ford allegedly impersonated an adult film star and tricked his high-profile victims into sharing their iCloud credentials and MFA codes under false pretenses.

The post Zero lessons learned: Convicted scammer allegedly ran another athlete-focused phishing scam from federal prison appeared first on CyberScoop.

Continue reading Zero lessons learned: Convicted scammer allegedly ran another athlete-focused phishing scam from federal prison

The ransomware economy is shifting toward straight-up data extortion

Google’s research report on ransomware activity last year underscores how cybercrime is evolving and clouding a collective understanding of its full impact and scale.

The post The ransomware economy is shifting toward straight-up data extortion appeared first on CyberScoop.

Continue reading The ransomware economy is shifting toward straight-up data extortion

Authorities takedown global proxy network SocksEscort

The botnet, which compromised routers and IoT devices in 163 countries, claimed about 369,000 victims and $5.8 million from its cybercriminal customers, officials said.

The post Authorities takedown global proxy network SocksEscort appeared first on CyberScoop.

Continue reading Authorities takedown global proxy network SocksEscort

Feds say another DigitalMint negotiator ran ransomware attacks and extorted $75 million

Angelo Martino is accused of playing both sides — committing attacks and conducting ransomware negotiations on some of the same cases on behalf of his former employer.

The post Feds say another DigitalMint negotiator ran ransomware attacks and extorted $75 million appeared first on CyberScoop.

Continue reading Feds say another DigitalMint negotiator ran ransomware attacks and extorted $75 million