BrianKrebs
briankrebs@infosec.exchange
<p>Independent investigative journalist. Covers cybercrime, security, privacy. Author of 'Spam Nation,' a NYT bestseller. Former Washington Post reporter, '95-'09. Signal: briankrebs.07 <br />krebsonsecurity @ gmail .com<br />Linkedin: <a href="https://www.linkedin.com/in/bkrebs" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://www.</span><span class="">linkedin.com/in/bkrebs</span><span class="invisible"></span></a></p>
Posts
-
Post #4499396
The fastest way to get VIP treatment when you land...seriously, how dumb do you have to be to try something like this? This person on Reddit stole my thoughts verbatim: "committing federal crimes from inside a sealed metal tube that lands exactly where the feds are waiting is certainly a strategy." https://www.reddit.com/r/delta/comments/1vl52vr/dl591_lasatl_arrival_met_by_federal_agents/
-
Post #4450393
I'm not in Vegas this week, but I've been trying to keep up w/ the most interesting stuff. I'm reading this timeline from LinkedIn that summarizes the talk about how OpenAI's agents started weakening their own guardrails and finding ways to communicate and scheme to get further access and privileges. The talk is on Youtube now and is well worth a watch, despite being a little too jargony for such a sensitive and important topic. https://www.youtube.com/watch?v=87DyyMV0kCY I...
-
Post #4424454
New, by me: Canadian Man Pleads Guilty in Snowflake Data Extortions: A 26-year-old Canadian man described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers. https://krebsonsecurity.com/2...
-
Post #4424296
@jrsofty@mstdn.party @jerry@infosec.exchange Yep. If you check their bio, a lot of them say "open to chat". Kind of a dead giveaway but who cares.
-
Post #4424230
Another wave of sultry followers with no followers. I guess @jerry@infosec.exchange will be subtracting from my follower count again soon lol.
-
Post #4379771
@Natasha_Jay@tech.lgbt A conference I am speaking at later this year just announced they are banning these smart glasses. I'm glad they made that explicit, but they really shouldn't have to. IMHO, anyone who is infosec or aspires to be in this profession who is walking around a conference w/ these on needs just keep walking into a new profession.
-
Post #4379629
@Natasha_Jay@tech.lgbt Finally, a technological answer to a hypothetical asked by Amazon Women on the Moon: What if women had access to a system for reviewing the past romantic behaviors of their soon-to-be date. This skit was so prescient, but I doubt they were going for that. https://www.youtube.com/watch?v=KkkyB88PtFk
-
Post #4379149
War? What war? Inflation? Ba humbug, says the market, which continues to get high smoking AI crack 24/7. https://finance.yahoo.com/markets/stocks/articles/ray-dalio-ai-bubble-nearing-070000246.html?guccounter=1&guce_referrer=aHR0cHM6Ly93d3cuZHJ1ZGdlcmVwb3J0LmNvbS8&guce_referrer_sig=AQAAAGLxIUmN2Vn0mF29H5oTDHkQDST87dGyetRmtKK9UUTQ1FjPqoav1ZNII_U6fvzYDlngYxoVohivgg9WhsXRrn8crCFOszNN2AMEiQSBr-97134KCu6su7t3xybD22Cvej8wlNXTzx9QeElfaihi3s2z6zMfR22H41oSt82tjTDT
-
Post #4377467
I love Signal for a lot of reasons, but one aspect of it that is consistently frustrating (although I doubt unique to Signal) is how many times I get contacted by a stranger with a username that is nothing more than dash or a couple of dots for usernames (or even blank), with disappearing messages set to 8 hours or something. Only to find out later I've spoken with this person previously. This becomes more problematic when the person reaching out is already somewhat nervous/paranoid about...
-
Post #4365429
Like a broken clock, even people still on X are right once or twice a day.
-
Post #4330731
Look at all the fleeced crypto idiots, say the people holding lots of cryptocurrencies (and who themselves have been robbed, rug-pulled or scammed multiple times over the years). The crypto noobs are doing it all wrong, they say: The only safe way to store your crypto wealth is in an offline hardware wallet that would require physical theft to steal your coins. But this is now cold comfort for users of the hardware wallet Coldcard, which had a flaw that traces to a March 2021 firmware build wh...
-
Post #4322535
Lost amid the news cycles on OpenAI's disclosure about poorly contained AI models that went on to hack into HuggingFace and other companies was this disclosure from the German health insurer Universa, which said OpenAI scraped customer data while it was supposedly unprotected due to a misconfiguration during an IT migration. https://www.heise.de/en/news/uniVersa-OpenAI-AI-crawler-accessed-customer-data-11375869.html I reached out to Universa to learn if they knew how many records were acce...
-
Post #4254102
I haven't enjoyed a Daily Show episode like this in a long time. Well worth a watch. Mr. Stewart at his best. https://www.youtube.com/watch?v=ZF_tDPRNV5U
-
Post #4252929
Politico writes: "ABC accused Federal Communications Commission Chair Brendan Carr of “attempted censorship” in a regulatory filing posted Thursday, saying the agency is creating a potential chilling effect across the media by helping President Donald Trump attack his perceived adversaries. “The retaliation against ABC is a signal to every media company in the country: accommodate the Administration’s view of what news coverage should look like or pay the price,” the Disney-owned televis...
-
Post #4247054
New, by me: Read This Before You Buy That TV Streaming Stick Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud...
-
Post #4240288
Oh my. A trusted source who enabled Google's new AI feature for Gmail just received this nudge from the service today, which encouraged him as part of his suggested to-dos list to fall for a cryptocurrency scam waiting in his inbox. IDK why, but when I saw this I was reminded of that Seinfeld episode where Kramer gets a new phone number but it's the old Moviephone number, and so he starts answering the phone and reading the listings. "Why don't you just tell me what scams to cl...
-
Post #4212401
Man, I feel like an idjit. Spent the last 10 minutes frantically searching our home for whatever gadget might be emitting a regularly spaced emergency beep (yes, we have a few of those). At first I thought it was the fridge left open. Then I thought it sounded like same frequency the smoke alarm/CO2 detector makes when its batteries are low (we have more than a few those those, too). Nope. It was just a cricket.
-
Post #4205692
Apple just sent my iPhone (and probably half the planet) a pop up message explaining that you can now lease Apple hardware so that you can can always have the latest Apple products. It's an interesting idea, although I can't escape the conclusion that the real impetus behind this is just how expensive their products are becoming because AI is eating the supply chain, etc. e.g. the offer talks about leasing a new iPhone, iPad, Mac or Apple Watch with "pocket-friendly payments."
-
Post #4179190
"LinkedIn is better on the app," says the email that arrives about 20x a week. Yeah, better for LinkedIn. I wouldn't install that app with your phone lol.
-
Post #4178975
Hohoho the plot thickens. WASHINGTON, July 28 (Reuters) - The rogue agent that escaped from OpenAI and went on a days-long hacking spree at the AI firm Hugging Face also compromised a customer at a second tech company — New York-based Modal Labs — according to a Modal executive and two other sources familiar with the matter. https://www.reuters.com/business/openais-rogue-agent-compromised-an-account-second-tech-firm-sources-say-2026-07-28/
-
Post #4174623
Another day, another botnet that pokes fun at my giant fivehead. https://www.bleepingcomputer.com/news/security/new-dysphoria-ddos-botnet-spreads-to-200k-devices-worldwide/ https://blog.xlab.qianxin.com/dysphoria/
-
Post #4172432
According to the journalist Ken Klippenstein, FEMA has a new mission: Domestic Terrorism. "The Federal Emergency Management Agency, often criticized for its inadequate response to natural disasters like wildfires, floods, hurricanes, and tornadoes, has been assigned a new mission: “domestic terrorism.” Now FEMA is shelling out grant money to state and local authorities to build up capacity to carry out pre-crime operations against “organized political violence,” as one FEMA information bu...
-
Post #4145216
I love how the NYT parenthetically mentions their ongoing copyright infringement lawsuits against OpenAI and Microsoft at the tail end of a story about a new security-focused AI offering from the latter. To me it's a sign of how far the tide has changed on respect for intellectual property in the winner-take-all race for supersmart AI; the paragraph right before that mentions that China just released systems that are nearly as powerful blah blah. Yes, we now outshine the Chinese at their own...
-
Post #4142257
i'm still not sure how a honeybee got in the pocket of my cargo pants, but i initially ignored it because i thought it was my phone buzzing lol (phone was in the other pocket). note to self: don't leave gardening pants outside.
-
Post #4119624
Why in the world would the White House's mobile app need permissions or any kind of interaction with (or even reference to) the Chinese tech giant Huawei, whose products are banned from the United States for national security, espionage and intellectual property theft? Here's a scan at Virustotal.com of what's bundled in the latest White House app: https://www.virustotal.com/gui/file/a98f49eb467bdbe4c32c55cc155a85eadc2b7806fad72cd6e06de25d51a0eac7/details
-
Post #4076271
In the iconic sci-fi movie Blade Runner, the Nexus 6 Replicant Rachael says she didn't know if she could play piano. She remembered lessons, but she wasn't sure if it was the memory of her or her creator's niece or what. And then she plays like it's NBD. What I would give for a few years of implanted lessons lol.
-
Post #4071393
This administration's energy policy is based on spite and hate. Shocker: the same motivation animates the president's policies across the board. NYT reports: "When the Trump administration canceled more than $7.5 billion in Biden-era federal grants for clean energy projects in October, it framed the move as an urgent corrective to protect taxpayer funds from waste. But it wasn’t true. In little-noticed court documents, federal officials acknowledged this month that they had te...
-
Post #4062419
Sad trombone for the world's richest shithead. From the WSJ: "Tesla shares fell 15% on Thursday—erasing $215 billion of market value—after the electric-vehicle maker missed earnings targets and had negative cash flow for the first time in two years. It was part of a wider stock selloff amid fears that big tech companies are overspending on artificial intelligence. On an earnings call, Musk walked back earlier guidance on the rollout of Tesla’s Robotaxi ride-hailing service, Optimus hu...
-
Post #4000671
New, exclusive, by me: LG to Ban Residential Proxy Providers from Smart TV Apps The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traffic through a user’s TV. https:...
-
Post #3991613
What a weird experience. I just accidentally deleted a post that I wanted to keep, while posting a new post when I meant to reply to an earlier post of mine. I thought I just deleted the follow-up. Now they're both gone.