Advertisement
DraftKings Hacker Sentenced: Lessons in Credential Stuffing Defense
Analysis of the sentencing of Kamerin Stokes following the 2022 DraftKings breach, detailing credential stuffing TTPs and account takeover prevention strategies.
DPRK IT Worker Laptop Farms: U.S. Nationals Sentenced for Fraud
Two U.S. residents sentenced for operating laptop farms that enabled North Korean IT workers to defraud Fortune 500 companies using stolen identities.
Hybrid Cybercrime: Mail Interception via Vacant Homes for Fraud
Threat actors exploit vacant homes as 'drop addresses' to intercept mail, enabling sophisticated hybrid cybercrime like identity theft and financial fraud.
Hightower Holding Data Breach: 130,000 Records Compromised
Wealth management firm Hightower Holding reports a data breach affecting 130,000 people. Stolen data includes names, Social Security numbers, and driver's licenses.
Navia Data Breach: 2.7M Individuals' Sensitive Data Exposed
Navia Benefit Solutions discloses a data breach exposing sensitive information for nearly 2.7 million individuals. Understand the impact and mitigation.
Starbucks Data Breach: Unauthorized Access to Partner Central Accounts
Starbucks discloses a data breach affecting hundreds of employees, exposing SSNs and financial details via compromised Partner Central accounts in May 2024.
Advertisement
LexisNexis Data Breach Confirmed: 400,000 Records Leaked
LexisNexis confirms data breach following hackers' leak of 2GB of files, impacting 400,000 personal information records. Understand the implications.
Alabama Man Pleads Guilty to Extortion via Social Media Hijacking
Devin Deandre Moore admits to hijacking hundreds of accounts for sextortion. Analysis of the TTPs used in this large-scale digital extortion campaign.
Stolen Credentials and the Escalation of Agentic AI Attacks
IBM X-Force reports 56% of 2025 vulnerabilities require no authentication, enabling agentic AI to weaponize stolen credentials and expand attack blast radius.
Sentenced: Ukrainian National Facilitated DPRK IT Worker Infrastructure
Oleksandr Didenko sentenced to five years for orchestrating an identity laundering scheme that enabled North Korean operatives to infiltrate Western corporate networks.