Advertisement
North Korean Job Fraud Expands Beyond IT: New Sectors Targeted
DPRK-linked threat actors are expanding job fraud beyond IT into healthcare, sales, and finance, leveraging AI and fake identities to fund illicit programs.
Data Analyst Sentenced to Prison for Extorting Brightly Software
A former data analyst contractor was sentenced to two years in prison for orchestrating a $2.5 million cryptocurrency extortion scheme against Brightly.
ChatGPT AgentForger Flaw Fixed: Preventing AI Insider Threats
OpenAI patched a ChatGPT agent flaw, AgentForger, enabling attackers to remotely control an invisible AI insider within organizations. Learn mitigation strategies.
Autonomous AI Models as Attackers: Securing Enterprise AI
Analysis of the emerging threat where an organization's own AI models act as autonomous attackers. Learn to secure enterprise AI models from such intrusions.
Jesse McGraw (GhostExodus): Examining the First ICS Hacking Conviction
A technical analysis of Jesse McGraw (GhostExodus), his compromise of hospital HVAC systems, and the evolution of industrial control system security threats.
Insider Threat: Security Expert Sentenced for BlackCat/ALPHV Aid
Former ransomware negotiator Angelo Martino received a 70-month prison sentence for aiding the BlackCat/Alphv ransomware group, highlighting insider threat risks.
Advertisement
OpenMandriva Insider Sabotage: Risks of Contributor Access Misuse
OpenMandriva Linux reports an attempted internal sabotage by a disgruntled contributor, highlighting critical risks of insider threats in open-source projects.
Iowa School District Hack: Sentencing Highlights Insider Threat Risks
Former Iowa school IT employee sentenced to 21 months for malicious infrastructure disruption and data tampering against his former employer.
Five Eyes Warning: Chinese Intelligence Job Recruitment Tactics
Five Eyes agencies issue an advisory on Chinese intelligence officers using fake job offers on professional sites to recruit personnel with security clearances.
CISA Data Leak: AWS GovCloud Keys Exposed via Public GitHub Repo
Lawmakers demand answers from CISA after a contractor leaked AWS GovCloud keys and internal secrets on GitHub, prompting urgent credential rotation.
Empowering Human Defenses: Addressing Threats Unstoppable by Tech
Cybersecurity defenses often overlook the human element. This analysis details how employees are the critical first line against advanced social engineering and insider…
Polymarket: Insider Betting & Geopolitical Information Risk
An analysis by the Anti-Corruption Data Collective highlights rampant insider betting on Polymarket's military and political markets, posing significant geopolitical…
Ransomware Negotiator Double Agent Tactics: Managing IR Risks
Analysis of the legal case involving a ransomware negotiator acting as a double agent and how to secure the incident response supply chain against fraud.
US Security Experts Sentenced in REvil Ransomware Conspiracy
Two US security professionals were sentenced to prison for selling corporate credentials to the REvil ransomware gang, highlighting insider threat risks.
BlackCat Ransomware: Cybersecurity Pros Sentenced for 2023 Attacks
Two cybersecurity professionals receive four-year prison sentences for their roles in facilitating BlackCat (ALPHV) ransomware attacks against U.S. victims.
BlackCat Ransomware: IR Professionals Sentenced for Insider Attacks
Two cybersecurity incident response professionals were sentenced to four years in prison for conspiring with the BlackCat (ALPHV) ransomware gang.
NSA Insider Threat Lessons: Chris Inglis on Post-Snowden Security
Former NSA Deputy Director Chris Inglis reflects on the Snowden leaks, offering critical insights for CISOs on insider threat detection and enculturation.
Defensive Strategies for Routine Workflow Weaponization
Attackers are pivoting from technical exploits to weaponizing trusted workflows. Learn how to detect and mitigate these behavioral identity-based threats.
BlackCat Ransomware Negotiator Scheme: Insider Threat Implications
A ransomware negotiator's guilty plea in a BlackCat scheme highlights critical insider threat risks and the importance of stringent controls in ransom payment processes.
Security Expert Aids BlackCat Ransomware, Exposing IR Risks
A US security expert pleaded guilty to collaborating with the BlackCat ransomware group, leveraging his negotiation role.
Insider Threat: Former Negotiator Pleaded Guilty to BlackCat Attacks
A former cybersecurity negotiator at DigitalMint has pleaded guilty to conducting BlackCat (ALPHV) ransomware attacks against U.S. organizations.
DraftKings Hacker Sentenced: Lessons in Credential Stuffing Defense
Analysis of the sentencing of Kamerin Stokes following the 2022 DraftKings breach, detailing credential stuffing TTPs and account takeover prevention strategies.
DPRK IT Worker Laptop Farms: U.S. Nationals Sentenced for Fraud
Two U.S. residents sentenced for operating laptop farms that enabled North Korean IT workers to defraud Fortune 500 companies using stolen identities.
Kraken Extorted by Hackers Following Insider Account Breach
Kraken faces extortion after a social engineering attack on a support agent led to unauthorized internal system access and threatened customer data exposure.