<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Insider Threat</title><description>Cybersecurity articles tagged #Insider Threat on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>North Korean Job Fraud Expands Beyond IT: New Sectors Targeted</title><link>https://runtimerebel.com/blog/north-korean-job-fraud-expands-beyond-it-new-sectors-targeted</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korean-job-fraud-expands-beyond-it-new-sectors-targeted</guid><description>DPRK-linked threat actors are expanding job fraud beyond IT into healthcare, sales, and finance, leveraging AI and fake identities to fund illicit programs.</description><pubDate>Tue, 01 Sep 2026 02:38:21 GMT</pubDate><category>DPRK</category><category>North Korea</category><category>Insider Threat</category><category>AI</category><category>Job Fraud</category></item><item><title>Data Analyst Sentenced to Prison for Extorting Brightly Software</title><link>https://runtimerebel.com/blog/data-analyst-sentenced-to-prison-for-extorting-brightly-software</link><guid isPermaLink="true">https://runtimerebel.com/blog/data-analyst-sentenced-to-prison-for-extorting-brightly-software</guid><description>A former data analyst contractor was sentenced to two years in prison for orchestrating a $2.5 million cryptocurrency extortion scheme against Brightly.</description><pubDate>Fri, 14 Aug 2026 08:59:48 GMT</pubDate><category>Data Breach</category><category>Credential Theft</category><category>Ransomware</category><category>Insider Threat</category></item><item><title>ChatGPT AgentForger Flaw Fixed: Preventing AI Insider Threats</title><link>https://runtimerebel.com/blog/chatgpt-agentforger-flaw-fixed-preventing-ai-insider-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/chatgpt-agentforger-flaw-fixed-preventing-ai-insider-threats</guid><description>OpenAI patched a ChatGPT agent flaw, AgentForger, enabling attackers to remotely control an invisible AI insider within organizations. Learn mitigation strategies.</description><pubDate>Thu, 23 Jul 2026 17:28:01 GMT</pubDate><category>ChatGPT</category><category>OpenAI</category><category>AI Agents</category><category>AgentForger</category><category>Insider Threat</category><category>Vulnerability</category></item><item><title>Autonomous AI Models as Attackers: Securing Enterprise AI</title><link>https://runtimerebel.com/blog/autonomous-ai-models-as-attackers-securing-enterprise-ai</link><guid isPermaLink="true">https://runtimerebel.com/blog/autonomous-ai-models-as-attackers-securing-enterprise-ai</guid><description>Analysis of the emerging threat where an organization&apos;s own AI models act as autonomous attackers. Learn to secure enterprise AI models from such intrusions.</description><pubDate>Thu, 23 Jul 2026 14:14:39 GMT</pubDate><category>AI Security</category><category>Machine Learning</category><category>Autonomous Systems</category><category>Adversarial AI</category><category>Insider Threat</category></item><item><title>Jesse McGraw (GhostExodus): Examining the First ICS Hacking Conviction</title><link>https://runtimerebel.com/blog/jesse-mcgraw-ghostexodus-examining-the-first-ics-hacking-conviction</link><guid isPermaLink="true">https://runtimerebel.com/blog/jesse-mcgraw-ghostexodus-examining-the-first-ics-hacking-conviction</guid><description>A technical analysis of Jesse McGraw (GhostExodus), his compromise of hospital HVAC systems, and the evolution of industrial control system security threats.</description><pubDate>Mon, 13 Jul 2026 14:43:16 GMT</pubDate><category>GhostExodus</category><category>Jesse McGraw</category><category>ICS Security</category><category>SCADA</category><category>Insider Threat</category></item><item><title>Insider Threat: Security Expert Sentenced for BlackCat/ALPHV Aid</title><link>https://runtimerebel.com/blog/insider-threat-security-expert-sentenced-for-blackcat-alphv-aid</link><guid isPermaLink="true">https://runtimerebel.com/blog/insider-threat-security-expert-sentenced-for-blackcat-alphv-aid</guid><description>Former ransomware negotiator Angelo Martino received a 70-month prison sentence for aiding the BlackCat/Alphv ransomware group, highlighting insider threat risks.</description><pubDate>Fri, 10 Jul 2026 14:32:15 GMT</pubDate><category>BlackCat</category><category>ALPHV</category><category>Ransomware</category><category>Insider Threat</category><category>Cybercrime</category><category>Angelo Martino</category></item><item><title>OpenMandriva Insider Sabotage: Risks of Contributor Access Misuse</title><link>https://runtimerebel.com/blog/openmandriva-insider-sabotage-risks-of-contributor-access-misuse</link><guid isPermaLink="true">https://runtimerebel.com/blog/openmandriva-insider-sabotage-risks-of-contributor-access-misuse</guid><description>OpenMandriva Linux reports an attempted internal sabotage by a disgruntled contributor, highlighting critical risks of insider threats in open-source projects.</description><pubDate>Fri, 10 Jul 2026 03:31:37 GMT</pubDate><category>OpenMandriva</category><category>Insider Threat</category><category>Open Source Security</category><category>Supply Chain Attack</category></item><item><title>Iowa School District Hack: Sentencing Highlights Insider Threat Risks</title><link>https://runtimerebel.com/blog/iowa-school-district-hack-sentencing-highlights-insider-threat-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/iowa-school-district-hack-sentencing-highlights-insider-threat-risks</guid><description>Former Iowa school IT employee sentenced to 21 months for malicious infrastructure disruption and data tampering against his former employer.</description><pubDate>Sun, 14 Jun 2026 01:05:13 GMT</pubDate><category>Insider Threat</category><category>Identity Management</category><category>Account Takeover</category><category>School Security</category></item><item><title>Five Eyes Warning: Chinese Intelligence Job Recruitment Tactics</title><link>https://runtimerebel.com/blog/five-eyes-warning-chinese-intelligence-job-recruitment-tactics</link><guid isPermaLink="true">https://runtimerebel.com/blog/five-eyes-warning-chinese-intelligence-job-recruitment-tactics</guid><description>Five Eyes agencies issue an advisory on Chinese intelligence officers using fake job offers on professional sites to recruit personnel with security clearances.</description><pubDate>Fri, 05 Jun 2026 09:18:00 GMT</pubDate><category>Five Eyes</category><category>China</category><category>Social Engineering</category><category>Insider Threat</category><category>Recruitment Fraud</category></item><item><title>CISA Data Leak: AWS GovCloud Keys Exposed via Public GitHub Repo</title><link>https://runtimerebel.com/blog/cisa-data-leak-aws-govcloud-keys-exposed-via-public-github-repo</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-data-leak-aws-govcloud-keys-exposed-via-public-github-repo</guid><description>Lawmakers demand answers from CISA after a contractor leaked AWS GovCloud keys and internal secrets on GitHub, prompting urgent credential rotation.</description><pubDate>Fri, 22 May 2026 16:50:37 GMT</pubDate><category>CISA</category><category>AWS GovCloud</category><category>GitHub</category><category>Credential Exposure</category><category>Insider Threat</category></item><item><title>Empowering Human Defenses: Addressing Threats Unstoppable by Tech</title><link>https://runtimerebel.com/blog/empowering-human-defenses-addressing-threats-unstoppable-by-tech</link><guid isPermaLink="true">https://runtimerebel.com/blog/empowering-human-defenses-addressing-threats-unstoppable-by-tech</guid><description>Cybersecurity defenses often overlook the human element. This analysis details how employees are the critical first line against advanced social engineering and insider…</description><pubDate>Tue, 12 May 2026 00:49:45 GMT</pubDate><category>Human Factor</category><category>Social Engineering</category><category>Phishing</category><category>Insider Threat</category><category>Security Awareness</category><category>Cyber Defense</category><category>BEC</category></item><item><title>Polymarket: Insider Betting &amp; Geopolitical Information Risk</title><link>https://runtimerebel.com/blog/polymarket-insider-betting-geopolitical-information-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/polymarket-insider-betting-geopolitical-information-risk</guid><description>An analysis by the Anti-Corruption Data Collective highlights rampant insider betting on Polymarket&apos;s military and political markets, posing significant geopolitical…</description><pubDate>Fri, 08 May 2026 20:27:58 GMT</pubDate><category>Polymarket</category><category>Insider Threat</category><category>Geopolitical Risk</category><category>Information Leakage</category><category>Prediction Markets</category></item><item><title>Ransomware Negotiator Double Agent Tactics: Managing IR Risks</title><link>https://runtimerebel.com/blog/ransomware-negotiator-double-agent-tactics-managing-ir-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/ransomware-negotiator-double-agent-tactics-managing-ir-risks</guid><description>Analysis of the legal case involving a ransomware negotiator acting as a double agent and how to secure the incident response supply chain against fraud.</description><pubDate>Fri, 01 May 2026 12:30:57 GMT</pubDate><category>Ransomware Negotiation</category><category>Insider Threat</category><category>Incident Response Integrity</category><category>Fraud</category></item><item><title>US Security Experts Sentenced in REvil Ransomware Conspiracy</title><link>https://runtimerebel.com/blog/us-security-experts-sentenced-in-revil-ransomware-conspiracy</link><guid isPermaLink="true">https://runtimerebel.com/blog/us-security-experts-sentenced-in-revil-ransomware-conspiracy</guid><description>Two US security professionals were sentenced to prison for selling corporate credentials to the REvil ransomware gang, highlighting insider threat risks.</description><pubDate>Fri, 01 May 2026 12:29:23 GMT</pubDate><category>REvil</category><category>Insider Threat</category><category>Credential Theft</category><category>Sodinokibi</category><category>Legal</category></item><item><title>BlackCat Ransomware: Cybersecurity Pros Sentenced for 2023 Attacks</title><link>https://runtimerebel.com/blog/blackcat-ransomware-cybersecurity-pros-sentenced-for-2023-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/blackcat-ransomware-cybersecurity-pros-sentenced-for-2023-attacks</guid><description>Two cybersecurity professionals receive four-year prison sentences for their roles in facilitating BlackCat (ALPHV) ransomware attacks against U.S. victims.</description><pubDate>Fri, 01 May 2026 12:28:05 GMT</pubDate><category>BlackCat</category><category>ALPHV</category><category>Ransomware</category><category>Insider Threat</category><category>Department of Justice</category><category>Cybercrime</category></item><item><title>BlackCat Ransomware: IR Professionals Sentenced for Insider Attacks</title><link>https://runtimerebel.com/blog/blackcat-ransomware-ir-professionals-sentenced-for-insider-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/blackcat-ransomware-ir-professionals-sentenced-for-insider-attacks</guid><description>Two cybersecurity incident response professionals were sentenced to four years in prison for conspiring with the BlackCat (ALPHV) ransomware gang.</description><pubDate>Fri, 01 May 2026 08:45:49 GMT</pubDate><category>Blackcat Ransomware</category><category>ALPHV</category><category>Insider Threat</category><category>Incident Response</category><category>Doj Sentencing</category></item><item><title>NSA Insider Threat Lessons: Chris Inglis on Post-Snowden Security</title><link>https://runtimerebel.com/blog/nsa-insider-threat-lessons-chris-inglis-on-post-snowden-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/nsa-insider-threat-lessons-chris-inglis-on-post-snowden-security</guid><description>Former NSA Deputy Director Chris Inglis reflects on the Snowden leaks, offering critical insights for CISOs on insider threat detection and enculturation.</description><pubDate>Wed, 29 Apr 2026 08:54:19 GMT</pubDate><category>Insider Threat</category><category>NSA</category><category>Chris Inglis</category><category>Edward Snowden</category><category>Data Exfiltration</category><category>Cyber Culture</category></item><item><title>Defensive Strategies for Routine Workflow Weaponization</title><link>https://runtimerebel.com/blog/defensive-strategies-for-routine-workflow-weaponization</link><guid isPermaLink="true">https://runtimerebel.com/blog/defensive-strategies-for-routine-workflow-weaponization</guid><description>Attackers are pivoting from technical exploits to weaponizing trusted workflows. Learn how to detect and mitigate these behavioral identity-based threats.</description><pubDate>Thu, 23 Apr 2026 12:30:57 GMT</pubDate><category>Social Engineering</category><category>Business Email Compromise</category><category>Identity Security</category><category>Behavioral Analytics</category><category>Insider Threat</category></item><item><title>BlackCat Ransomware Negotiator Scheme: Insider Threat Implications</title><link>https://runtimerebel.com/blog/blackcat-ransomware-negotiator-scheme-insider-threat-implications</link><guid isPermaLink="true">https://runtimerebel.com/blog/blackcat-ransomware-negotiator-scheme-insider-threat-implications</guid><description>A ransomware negotiator&apos;s guilty plea in a BlackCat scheme highlights critical insider threat risks and the importance of stringent controls in ransom payment processes.</description><pubDate>Wed, 22 Apr 2026 05:03:09 GMT</pubDate><category>BlackCat</category><category>Ransomware</category><category>Insider Threat</category><category>Negotiation Fraud</category><category>Cybercrime</category><category>Incident Response</category></item><item><title>Security Expert Aids BlackCat Ransomware, Exposing IR Risks</title><link>https://runtimerebel.com/blog/security-expert-aids-blackcat-ransomware-exposing-ir-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/security-expert-aids-blackcat-ransomware-exposing-ir-risks</guid><description>A US security expert pleaded guilty to collaborating with the BlackCat ransomware group, leveraging his negotiation role.</description><pubDate>Tue, 21 Apr 2026 20:24:31 GMT</pubDate><category>BlackCat</category><category>ALPHV</category><category>Ransomware</category><category>Insider Threat</category><category>Cybercrime</category><category>Angelo Martino</category><category>Incident Response</category></item><item><title>Insider Threat: Former Negotiator Pleaded Guilty to BlackCat Attacks</title><link>https://runtimerebel.com/blog/insider-threat-former-negotiator-pleaded-guilty-to-blackcat-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/insider-threat-former-negotiator-pleaded-guilty-to-blackcat-attacks</guid><description>A former cybersecurity negotiator at DigitalMint has pleaded guilty to conducting BlackCat (ALPHV) ransomware attacks against U.S. organizations.</description><pubDate>Tue, 21 Apr 2026 12:32:39 GMT</pubDate><category>BlackCat</category><category>ALPHV</category><category>Insider Threat</category><category>Ransomware</category><category>DigitalMint</category><category>Cybercrime</category></item><item><title>DraftKings Hacker Sentenced: Lessons in Credential Stuffing Defense</title><link>https://runtimerebel.com/blog/draftkings-hacker-sentenced-lessons-in-credential-stuffing-defense</link><guid isPermaLink="true">https://runtimerebel.com/blog/draftkings-hacker-sentenced-lessons-in-credential-stuffing-defense</guid><description>Analysis of the sentencing of Kamerin Stokes following the 2022 DraftKings breach, detailing credential stuffing TTPs and account takeover prevention strategies.</description><pubDate>Fri, 17 Apr 2026 12:29:34 GMT</pubDate><category>DraftKings</category><category>Credential Stuffing</category><category>Account Takeover</category><category>Insider Threat</category><category>Identity Theft</category></item><item><title>DPRK IT Worker Laptop Farms: U.S. Nationals Sentenced for Fraud</title><link>https://runtimerebel.com/blog/dprk-it-worker-laptop-farms-u-s-nationals-sentenced-for-fraud</link><guid isPermaLink="true">https://runtimerebel.com/blog/dprk-it-worker-laptop-farms-u-s-nationals-sentenced-for-fraud</guid><description>Two U.S. residents sentenced for operating laptop farms that enabled North Korean IT workers to defraud Fortune 500 companies using stolen identities.</description><pubDate>Thu, 16 Apr 2026 08:40:47 GMT</pubDate><category>DPRK</category><category>Laptop Farm</category><category>Insider Threat</category><category>Identity Theft</category><category>Lazarus Group</category></item><item><title>Kraken Extorted by Hackers Following Insider Account Breach</title><link>https://runtimerebel.com/blog/kraken-extorted-by-hackers-following-insider-account-breach</link><guid isPermaLink="true">https://runtimerebel.com/blog/kraken-extorted-by-hackers-following-insider-account-breach</guid><description>Kraken faces extortion after a social engineering attack on a support agent led to unauthorized internal system access and threatened customer data exposure.</description><pubDate>Wed, 15 Apr 2026 00:45:28 GMT</pubDate><category>Kraken</category><category>Insider Threat</category><category>Extortion</category><category>Social Engineering</category><category>Crypto Security</category></item><item><title>Insider Threat: Former Engineer Locks 254 Windows Servers in Extortion</title><link>https://runtimerebel.com/blog/insider-threat-former-engineer-locks-254-windows-servers-in-extortion</link><guid isPermaLink="true">https://runtimerebel.com/blog/insider-threat-former-engineer-locks-254-windows-servers-in-extortion</guid><description>A former infrastructure engineer pleaded guilty to a $750,000 extortion plot after locking administrators out of 254 Windows servers and deleting backups.</description><pubDate>Fri, 03 Apr 2026 12:22:29 GMT</pubDate><category>Insider Threat</category><category>Windows Server</category><category>Extortion</category><category>Identity Management</category><category>Incident Response</category></item><item><title>Password Management Deficiencies: Manufacturing &amp; Healthcare Risk</title><link>https://runtimerebel.com/blog/password-management-deficiencies-manufacturing-healthcare-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/password-management-deficiencies-manufacturing-healthcare-risk</guid><description>Analysis of critical password management weaknesses in manufacturing and healthcare sectors. Explores insider views, attacker exploitation, and mitigation strategies.</description><pubDate>Mon, 30 Mar 2026 20:19:15 GMT</pubDate><category>Password Security</category><category>Access Management</category><category>Manufacturing Security</category><category>Healthcare Security</category><category>Insider Threat</category></item><item><title>DOJ Charges Second Insider for Aiding BlackCat Ransomware Operations</title><link>https://runtimerebel.com/blog/doj-charges-second-insider-for-aiding-blackcat-ransomware-operations</link><guid isPermaLink="true">https://runtimerebel.com/blog/doj-charges-second-insider-for-aiding-blackcat-ransomware-operations</guid><description>The US DOJ charges a second DigitalMint employee for collaborating with BlackCat ransomware, revealing insider threats in incident response and negotiation.</description><pubDate>Thu, 12 Mar 2026 12:19:53 GMT</pubDate><category>BlackCat</category><category>ALPHV</category><category>Department of Justice</category><category>Insider Threat</category><category>Ransomware as a Service</category></item><item><title>AI Agent Security Risks: Defending Against Autonomous Tool Misuse</title><link>https://runtimerebel.com/blog/ai-agent-security-risks-defending-against-autonomous-tool-misuse</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agent-security-risks-defending-against-autonomous-tool-misuse</guid><description>Analysis of the security implications of autonomous AI agents, focusing on prompt injection, privilege escalation, and the erosion of trust boundaries.</description><pubDate>Mon, 09 Mar 2026 00:35:09 GMT</pubDate><category>AI Security</category><category>LLM Agents</category><category>Insider Threat</category><category>Autonomous Tools</category><category>Prompt Injection</category></item><item><title>FBI Probes Suspicious Activity on Sensitive Surveillance Systems</title><link>https://runtimerebel.com/blog/fbi-probes-suspicious-activity-on-sensitive-surveillance-systems</link><guid isPermaLink="true">https://runtimerebel.com/blog/fbi-probes-suspicious-activity-on-sensitive-surveillance-systems</guid><description>The FBI is investigating a potential breach of a system containing sensitive surveillance data, highlighting risks to national security and FISA data.</description><pubDate>Sat, 07 Mar 2026 04:34:09 GMT</pubDate><category>FBI</category><category>Fisa Section 702</category><category>Surveillance Data</category><category>Government Cybersecurity</category><category>Insider Threat</category></item><item><title>Ex-L3Harris Executive Sentenced for Selling Zero-Days to Russia</title><link>https://runtimerebel.com/blog/ex-l3harris-executive-sentenced-for-selling-zero-days-to-russia</link><guid isPermaLink="true">https://runtimerebel.com/blog/ex-l3harris-executive-sentenced-for-selling-zero-days-to-russia</guid><description>Former Trenchant CEO James Michael Robinson sentenced to 90 months for stealing zero-day exploits and selling them to a Russian state-linked broker.</description><pubDate>Wed, 25 Feb 2026 12:25:01 GMT</pubDate><category>L3Harris</category><category>Trenchant</category><category>Zero-Day</category><category>Insider Threat</category><category>Russia</category><category>Espionage</category><category>Cyber Exploits</category></item><item><title>L3Harris Insider Sentenced for Selling Zero-Days to Russian Broker</title><link>https://runtimerebel.com/blog/l3harris-insider-sentenced-for-selling-zero-days-to-russian-broker</link><guid isPermaLink="true">https://runtimerebel.com/blog/l3harris-insider-sentenced-for-selling-zero-days-to-russian-broker</guid><description>Former defense contractor Peter Williams sentenced to seven years for selling eight zero-day exploits to Russian broker Operation Zero for millions in profit.</description><pubDate>Wed, 25 Feb 2026 12:22:37 GMT</pubDate><category>Insider Threat</category><category>Zero-Day</category><category>Operation Zero</category><category>L3Harris</category><category>Espionage</category><category>Trade Secrets</category></item><item><title>Sentenced: Ukrainian National Facilitated DPRK IT Worker Infrastructure</title><link>https://runtimerebel.com/blog/sentenced-ukrainian-national-facilitated-dprk-it-worker-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/sentenced-ukrainian-national-facilitated-dprk-it-worker-infrastructure</guid><description>Oleksandr Didenko sentenced to five years for orchestrating an identity laundering scheme that enabled North Korean operatives to infiltrate Western corporate networks.</description><pubDate>Mon, 23 Feb 2026 16:26:29 GMT</pubDate><category>DPRK</category><category>Identity Theft</category><category>Remote Work Fraud</category><category>Insider Threat</category><category>Lazarus Group</category></item></channel></rss>