Former NSA chiefs worry American offensive edge in cybersecurity is slipping

A systemic numbness to cyberattacks has exposed the U.S. economy and its institutions to ever-widening threats. Retired four-star military officials worry the worst day in cyber is yet to come.

The post Former NSA chiefs worry American offensive edge in cybersecurity is slipping appeared first on CyberScoop.

Continue reading Former NSA chiefs worry American offensive edge in cybersecurity is slipping

Experts warn of a ‘loud and aggressive’ extortion wave following Trivy hack

Attackers compromised the open-source security tool and published malicious versions of the software. Mandiant warns the fallout could impact up to 10,000 downstream victims.

The post Experts warn of a ‘loud and aggressive’ extortion wave following Trivy hack appeared first on CyberScoop.

Continue reading Experts warn of a ‘loud and aggressive’ extortion wave following Trivy hack

Experts insist Trump administration’s cyber strategy is already paying off

Leaders from various cybersecurity institutions were quick to defend and evangelize the administration’s strategic pivots in cyberspace.

The post Experts insist Trump administration’s cyber strategy is already paying off appeared first on CyberScoop.

Continue reading Experts insist Trump administration’s cyber strategy is already paying off

The phone call is the new phishing email

Voice-based phishing was at the root of multiple attack sprees Mandiant responded to last year, reflecting a concerning shift in tactics.

The post The phone call is the new phishing email appeared first on CyberScoop.

Continue reading The phone call is the new phishing email

Trio sentenced for facilitating North Korean IT worker scheme from their homes

The men facilitated about $1.28 million in salary from victim U.S. companies by hosting laptop farms and helping remote IT workers assume fake identities.

The post Trio sentenced for facilitating North Korean IT worker scheme from their homes appeared first on CyberScoop.

Continue reading Trio sentenced for facilitating North Korean IT worker scheme from their homes

Ubiquiti defect poses account takeover risk for UniFi Networking Application users

The maximum-severity vulnerability, which hasn’t been exploited in the wild yet, affects software customers use to manage networking devices.

The post Ubiquiti defect poses account takeover risk for UniFi Networking Application users appeared first on CyberScoop.

Continue reading Ubiquiti defect poses account takeover risk for UniFi Networking Application users

Justice Department disrupts botnet networks that hijacked 3 million devices

The Aisuru, Kimwolf, JackSkid and Mossad botnets enabled cybercriminals to initiate thousands of attacks. A crackdown targeting large-scale botnets continues amid growing challenges.

The post Justice Department disrupts botnet networks that hijacked 3 million devices appeared first on CyberScoop.

Continue reading Justice Department disrupts botnet networks that hijacked 3 million devices

North Carolina tech worker found guilty of insider attack netting $2.5M ransom

Cameron Nicholas Curry, also known as “Loot,” stole a trove of corporate data from a D.C.-based tech company as his six-month contract gig came to a close.

The post North Carolina tech worker found guilty of insider attack netting $2.5M ransom appeared first on CyberScoop.

Continue reading North Carolina tech worker found guilty of insider attack netting $2.5M ransom

Cisco’s latest vulnerability spree has a more troubling pattern underneath

Cisco’s response to the latest SD-WAN and firewall defects has been fast, but the harder question is how long sophisticated actors had a head start — and what’s already compromised.

The post Cisco’s latest vulnerability spree has a more troubling pattern underneath appeared first on CyberScoop.

Continue reading Cisco’s latest vulnerability spree has a more troubling pattern underneath

Zero lessons learned: Convicted scammer allegedly ran another athlete-focused phishing scam from federal prison

Kwamaine Jerell Ford allegedly impersonated an adult film star and tricked his high-profile victims into sharing their iCloud credentials and MFA codes under false pretenses.

The post Zero lessons learned: Convicted scammer allegedly ran another athlete-focused phishing scam from federal prison appeared first on CyberScoop.

Continue reading Zero lessons learned: Convicted scammer allegedly ran another athlete-focused phishing scam from federal prison