Elektrine lite

← Feed

BrianKrebs

briankrebs@infosec.exchange

<p>Independent investigative journalist. Covers cybercrime, security, privacy. Author of &#39;Spam Nation,&#39; a NYT bestseller. Former Washington Post reporter, &#39;95-&#39;09. Signal: briankrebs.07 <br />krebsonsecurity @ gmail .com<br />Linkedin: <a href="https://www.linkedin.com/in/bkrebs" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://www.</span><span class="">linkedin.com/in/bkrebs</span><span class="invisible"></span></a></p>

Posts

  • View post

    Exclusive, breaking: Dutch Police Arrest &quot;Reformed&quot; Hacker in ShinyHunters investigation Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect’s arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p. ht...

  • View post

    New, exclusive (and cathartic), from me: The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides for hefty fines against data brokers that publish personal information on state law enforcement officials. In the face of repeated stonewalling and prevarica...

  • View post

    The POTUS says we&#39;re doomed

  • View post

    I recently published a story about a cybersecurity startup run by Jack Burkman and Jacob Wohl, two convicted fraudsters and con men who&#39;ve been selling the ability for wealthy convicts to gain a presidential pardon. 60 Minutes just featured an interview with these two in tonight&#39;s show. https://www.cbsnews.com/news/trump-pardon-economy-60-minutes-transcript/?ftag=CNM-00-10aab7d&amp;linkId=1008528987 https://www.youtube.com/watch?v=cRxNh21Edr0 https://www.cbsnews.com/news/trump-pardon-...

  • View post

    Guess which of the bazillion tabs open in my browser is consuming the largest amount of system RAM by far? Ten points if you guessed LinkedIn. Resource Monitor said the tab was consuming a whopping 1.6 gigs of memory just now. In fairness, I guess all that tracking and AI garbage does require a lot of resources.

  • View post

    Golly, you can practically smell the cognitive dissonance happening here. I wonder who it could be?

  • View post

    Breaking, exclusive and spicy, from me: A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Fe...

  • View post

    I love how the reason for all the proposed new data centers is about &quot;winning the AI race with China.&quot; Meanwhile opposing the creation of new data centers means you fell for China&#39;s bot farm propaganda that is seeking to turn public opinion against US advancement in AI. The implication is that people who oppose new data centers are both anti-American and gullible tools.

  • View post

    Today&#39;s story is the result of an ungodly amount of research, and I am very glad to finally be able to share it with you. Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in con...

  • View post

    The fastest way to get VIP treatment when you land...seriously, how dumb do you have to be to try something like this? This person on Reddit stole my thoughts verbatim: &quot;committing federal crimes from inside a sealed metal tube that lands exactly where the feds are waiting is certainly a strategy.&quot; https://www.reddit.com/r/delta/comments/1vl52vr/dl591_lasatl_arrival_met_by_federal_agents/

  • View post

    I&#39;m not in Vegas this week, but I&#39;ve been trying to keep up w/ the most interesting stuff. I&#39;m reading this timeline from LinkedIn that summarizes the talk about how OpenAI&#39;s agents started weakening their own guardrails and finding ways to communicate and scheme to get further access and privileges. The talk is on Youtube now and is well worth a watch, despite being a little too jargony for such a sensitive and important topic. https://www.youtube.com/watch?v=87DyyMV0kCY I&#3...

  • View post

    New, by me: Canadian Man Pleads Guilty in Snowflake Data Extortions: A 26-year-old Canadian man described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&amp;T customers. https://krebsonsecurity.com/2...

  • View post

    @jrsofty@mstdn.party @jerry@infosec.exchange Yep. If you check their bio, a lot of them say &quot;open to chat&quot;. Kind of a dead giveaway but who cares.

  • View post

    Another wave of sultry followers with no followers. I guess @jerry@infosec.exchange will be subtracting from my follower count again soon lol.

  • View post

    @Natasha_Jay@tech.lgbt A conference I am speaking at later this year just announced they are banning these smart glasses. I&#39;m glad they made that explicit, but they really shouldn&#39;t have to. IMHO, anyone who is infosec or aspires to be in this profession who is walking around a conference w/ these on needs just keep walking into a new profession.

  • View post

    @Natasha_Jay@tech.lgbt Finally, a technological answer to a hypothetical asked by Amazon Women on the Moon: What if women had access to a system for reviewing the past romantic behaviors of their soon-to-be date. This skit was so prescient, but I doubt they were going for that. https://www.youtube.com/watch?v=KkkyB88PtFk

  • View post

    War? What war? Inflation? Ba humbug, says the market, which continues to get high smoking AI crack 24/7. https://finance.yahoo.com/markets/stocks/articles/ray-dalio-ai-bubble-nearing-070000246.html?guccounter=1&amp;guce_referrer=aHR0cHM6Ly93d3cuZHJ1ZGdlcmVwb3J0LmNvbS8&amp;guce_referrer_sig=AQAAAGLxIUmN2Vn0mF29H5oTDHkQDST87dGyetRmtKK9UUTQ1FjPqoav1ZNII_U6fvzYDlngYxoVohivgg9WhsXRrn8crCFOszNN2AMEiQSBr-97134KCu6su7t3xybD22Cvej8wlNXTzx9QeElfaihi3s2z6zMfR22H41oSt82tjTDT

  • View post

    I love Signal for a lot of reasons, but one aspect of it that is consistently frustrating (although I doubt unique to Signal) is how many times I get contacted by a stranger with a username that is nothing more than dash or a couple of dots for usernames (or even blank), with disappearing messages set to 8 hours or something. Only to find out later I&#39;ve spoken with this person previously. This becomes more problematic when the person reaching out is already somewhat nervous/paranoid about...

  • View post

    Like a broken clock, even people still on X are right once or twice a day.

  • View post

    Look at all the fleeced crypto idiots, say the people holding lots of cryptocurrencies (and who themselves have been robbed, rug-pulled or scammed multiple times over the years). The crypto noobs are doing it all wrong, they say: The only safe way to store your crypto wealth is in an offline hardware wallet that would require physical theft to steal your coins. But this is now cold comfort for users of the hardware wallet Coldcard, which had a flaw that traces to a March 2021 firmware build wh...

  • View post

    Lost amid the news cycles on OpenAI&#39;s disclosure about poorly contained AI models that went on to hack into HuggingFace and other companies was this disclosure from the German health insurer Universa, which said OpenAI scraped customer data while it was supposedly unprotected due to a misconfiguration during an IT migration. https://www.heise.de/en/news/uniVersa-OpenAI-AI-crawler-accessed-customer-data-11375869.html I reached out to Universa to learn if they knew how many records were acce...

  • View post

    I haven&#39;t enjoyed a Daily Show episode like this in a long time. Well worth a watch. Mr. Stewart at his best. https://www.youtube.com/watch?v=ZF_tDPRNV5U

  • View post

    Politico writes: &quot;ABC accused Federal Communications Commission Chair Brendan Carr of “attempted censorship” in a regulatory filing posted Thursday, saying the agency is creating a potential chilling effect across the media by helping President Donald Trump attack his perceived adversaries. “The retaliation against ABC is a signal to every media company in the country: accommodate the Administration’s view of what news coverage should look like or pay the price,” the Disney-owned televis...

  • View post

    New, by me: Read This Before You Buy That TV Streaming Stick Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user&#39;s Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud...

  • View post

    Oh my. A trusted source who enabled Google&#39;s new AI feature for Gmail just received this nudge from the service today, which encouraged him as part of his suggested to-dos list to fall for a cryptocurrency scam waiting in his inbox. IDK why, but when I saw this I was reminded of that Seinfeld episode where Kramer gets a new phone number but it&#39;s the old Moviephone number, and so he starts answering the phone and reading the listings. &quot;Why don&#39;t you just tell me what scams to cl...

  • View post

    Man, I feel like an idjit. Spent the last 10 minutes frantically searching our home for whatever gadget might be emitting a regularly spaced emergency beep (yes, we have a few of those). At first I thought it was the fridge left open. Then I thought it sounded like same frequency the smoke alarm/CO2 detector makes when its batteries are low (we have more than a few those those, too). Nope. It was just a cricket.

  • View post

    Apple just sent my iPhone (and probably half the planet) a pop up message explaining that you can now lease Apple hardware so that you can can always have the latest Apple products. It&#39;s an interesting idea, although I can&#39;t escape the conclusion that the real impetus behind this is just how expensive their products are becoming because AI is eating the supply chain, etc. e.g. the offer talks about leasing a new iPhone, iPad, Mac or Apple Watch with &quot;pocket-friendly payments.&quot;

  • View post

    &quot;LinkedIn is better on the app,&quot; says the email that arrives about 20x a week. Yeah, better for LinkedIn. I wouldn&#39;t install that app with your phone lol.

  • View post

    Hohoho the plot thickens. WASHINGTON, July 28 (Reuters) - The rogue agent that escaped from OpenAI and went on a days-long hacking spree at the AI firm Hugging Face also compromised a customer at a second tech company — New York-based Modal Labs — according to a Modal executive and two ​other sources familiar with the matter. https://www.reuters.com/business/openais-rogue-agent-compromised-an-account-second-tech-firm-sources-say-2026-07-28/

  • View post

    Another day, another botnet that pokes fun at my giant fivehead. https://www.bleepingcomputer.com/news/security/new-dysphoria-ddos-botnet-spreads-to-200k-devices-worldwide/ https://blog.xlab.qianxin.com/dysphoria/