Posts by briankrebs@infosec.exchange
(DIR) Post #B4YmCouitGJcA0GnWy by briankrebs@infosec.exchange
0 likes, 1 repeats
This is a crazy, developing story. And here you thought *your* organization's patch management routines were strict: From Christopher Kunz at Heise:"A serious security vulnerability in the Windchill and FlexPLM products prompted a nationwide police response over the weekend. At the behest of the Federal Criminal Police Office (BKA), officers from across Germany were dispatched to alert affected companies – an unprecedented move. Administrators, whose weekends were disrupted, expressed their irritation – some of whom don't even use the compromised software.""When the editorial team received a tip late Sunday morning about a critical security vulnerability in Windchill and FlexPLM , it sounded like a routine report: A deserialization vulnerability in specialized software, even with a CVSS score of 10, doesn't cause any alarm at heise security. The situation was apparently quite different at the Federal Criminal Police Office (BKA): By that time, they had already alerted the state criminal police offices (LKA) in various federal states, which dispatched police officers to affected companies during the night. As several readers reported to us in the forum , police officers were standing outside company and private premises in the dead of night."https://www.heise.de/news/WTF-Polizei-rueckte-Samstagnacht-wegen-Zero-Day-aus-11221345.html
(DIR) Post #B4YmCpauMQ3kGq0UHg by briankrebs@infosec.exchange
0 likes, 0 repeats
New, breaking: Feds Disrupt IoT Botnets Behind Huge DDoS AttacksThe U.S. Justice Department joined authorities in Canada and Germany in dismantling the online infrastructure behind four highly disruptive botnets that compromised more than three million Internet of Things (IoT) devices, such as routers and web cameras. The feds say the four botnets — named Aisuru, Kimwolf, JackSkid and Mossad — are responsible for a series of recent record-smashing distributed denial-of-service (DDoS) attacks capable of knocking nearly any target offline.No word yet on which botmasters got a visit from feds, but the DOJ statement references law enforcement actions against against botmasters in Canada and Germany. Last month, I reported on a likely identity behind Dort, the main individual behind the Kimwolf botnet. The other suspect was a 15 y/o from Germany.https://krebsonsecurity.com/2026/03/feds-disrupt-iot-botnets-behind-huge-ddos-attacks/
(DIR) Post #B4YmCpj3s6a6g7ozzc by briankrebs@infosec.exchange
0 likes, 0 repeats
New, by me: 'CanisterWorm' Springs Wiper Attack Targeting IranA financially motivated data theft and extortion group is attempting to inject itself into the Iran war, unleashing a worm that spreads through poorly secured cloud services and wipes data on infected systems that use Iran’s time zone or have Farsi set as the default language.https://krebsonsecurity.com/2026/03/canisterworm-springs-wiper-attack-targeting-iran/
(DIR) Post #B4YyPuplOFH5jexdho by briankrebs@infosec.exchange
0 likes, 4 repeats
Whoa, that escalated quickly. This just got sent out by the press folks at the Federal Communications Commission (FCC). The FCC says it has decided that all foreign-made consumer-grade Internet routers are henceforth prohibited from receiving FCC authorization and are therefore prohibited from being imported for use or sale in the United States. "Update Follows Determination by Executive Branch Agencies that Consumer-Grade Routers Produced in Foreign Countries Threaten National Security WASHINGTON, March 23, 2026—Today, the Federal Communications Commission updated its Covered List to include all consumer-grade routers produced in foreign countries. Routers are the boxes in every home that connect computers, phones, and smart devices to the internet. This followed a determination by a White House-convened Executive Branch interagency body with appropriate national security expertise that such routers “pose unacceptable risks to the national security of the United States or the safety and security of United States persons.” "The Executive Branch determination noted that foreign-produced routers (1) introduce “a supply chain vulnerability that could disrupt the U.S. economy, critical infrastructure, and national defense” and (2) pose “a severe cybersecurity risk that could be leveraged to immediately and severely disrupt U.S. critical infrastructure and directly harm U.S. persons.”"This action does not affect any previously-purchased consumer-grade routers. Consumers can continue to use any router they have already lawfully purchased or acquired.""Producers of consumer-grade routers that receive Conditional Approval from DoW or DHS can continue to receive FCC equipment authorizations. Interested applicants are encouraged to submit applications to conditional-approvals@fcc.gov."Not sure how many consumer-grade routers will be left for sale if it really is a ban on approvals for any foreign-made consumer routers like they said, and not just a bunch of already restricted Chinese makers like Huawei and ZTE.https://www.fcc.gov/document/fcc-updates-covered-list-include-foreign-made-consumer-routersFCC's "covered list" of "thou shalt not entities": https://www.fcc.gov/supplychain/coveredlist
(DIR) Post #B4rIVlLH5YDDxn2nei by briankrebs@infosec.exchange
0 likes, 0 repeats
IDK who Deb Eskew is, but I certainly glanced askew when reading this. See how many red flags you can spot. This one seems to have them all:-unbidden attachment (which couldn't be auto-scanned for malware btw)-no actual greeting or salutation-a password needed to unlock the attachment-relevant (if a bit on-the-nose) social engineering involving a podcast ostensibly focused on fraud;-Google is clearly glancing askew here, too, but kind of tapping out on a verdict because it ultimately made it through.
(DIR) Post #B5IYBQ0hXCvEXxezqa by briankrebs@infosec.exchange
0 likes, 1 repeats
This discussion atop Hackernews right now about how someone bought 30 WordPress plugins and planted a backdoor in all of them has me wondering, is there a plugin that blocks plugins from being automagically updated if the plugin's ownership changes?https://news.ycombinator.com/item?id=47755629#47756259
(DIR) Post #B5QEBwNyigQB8fCOi8 by briankrebs@infosec.exchange
1 likes, 0 repeats
Pretty wild mural painted over the men's room urinals at a restaurant we went to last night (if they don't call it a "murinal" they should). I thought it was hilarious but I wonder how many others would have a very different reaction.
(DIR) Post #B6Cjx6OHlKuzwgO4no by briankrebs@infosec.exchange
0 likes, 0 repeats
New, from me: Canvas Breach Disrupts Schools and Colleges Nationwide"An ongoing data extortion attack targeting the widely-used education technology platform Canvas disrupted classes and coursework at school districts and universities across the United States today, after a cybercrime group defaced the service’s login page with a ransom demand that threatened to leak data from 275 million students and faculty across nearly 9,000 educational institutions." "Canvas parent firm Instructure responded to today's defacement attacks by disabling the platform, which is used by thousands of schools, universities and businesses to manage coursework and assignments, and to communicate with students."Lots more here:https://krebsonsecurity.com/2026/05/canvas-breach-disrupts-schools-colleges-nationwide/#canvas #breach #shinyhunters #instructure
(DIR) Post #B6Cjx6pa7qkjJL9sLg by briankrebs@infosec.exchange
0 likes, 1 repeats
Instructure says it paid a ransom. SMH"STATUS UPDATE 5/11/26We know that concerns about the potential publication of data related to this incident remain top of mind for many customers. We understand how unsettling situations like this can be, and protecting our community remains our top priority.""With that responsibility in mind, Instructure reached an agreement with the unauthorized actor involved in this incident. As part of that agreement:""The data was returned to us.We received digital confirmation of data destruction (shred logs).We have been informed that no Instructure customers will be extorted as a result of this incident, publicly or otherwise."'This agreement covers all impacted Instructure customers, and there is no need for individual customers to attempt to engage with the unauthorized actor.While there is never complete certainty when dealing with cyber criminals, we believe it was important to take every step within our control to give customers additional peace of mind, to the extent possible. We continue to work with expert vendors to support our forensic analysis, further harden our environment, and conduct a comprehensive review of the data involved. We will continue to provide updates as that work progresses."https://www.instructure.com/incident_update
(DIR) Post #B6Eh4wHXJsplMcCC9Y by briankrebs@infosec.exchange
0 likes, 1 repeats
We've come to an icky time in security when the concern about using outdated, unpatched software starts to become overshadowed by the fear of downloading some backdoored update.
(DIR) Post #B6TQT0W2RhDpayGicS by briankrebs@infosec.exchange
1 likes, 0 repeats
New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHubUntil this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/
(DIR) Post #B6TQT0uqxR4UpvsXIW by briankrebs@infosec.exchange
0 likes, 0 repeats
It's possible this set of instructions by the CISA contractor might have caused all the trouble:
(DIR) Post #B6cvxgzDx0oH0NffGK by briankrebs@infosec.exchange
0 likes, 1 repeats
Feeling pretty good about stocking up on 4 of these bad boys at the end of 2024, when they could be had for ~$350 each. Now, just one of these drives costs as much as I paid for all 4. Thanks, AI!
(DIR) Post #B6cvxhixCzODID4BXc by briankrebs@infosec.exchange
0 likes, 1 repeats
Come to think of it, that could be a great AI awareness campaign. Just get 1000 different scenarios where people are demonstrably less well-off because of AI: Polluted, diverted or drained water supplies; immense air, noise and heat pollution from countless new gas powered turbines; young grads $500k in debt and watching their field of study evaporate; farmers having trouble being able to buy fertilizer; small businesses literally having trouble keeping the lights on because electricity has skyrocketed in price; and they all just look at the camera and say thanks AI.
(DIR) Post #B6cvxhyYGzrm4aMdqy by briankrebs@infosec.exchange
0 likes, 0 repeats
New, from me: Alleged Kimwolf Botmaster 'Dort' Arrested, Charged in U.S. and CanadaCanadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for use in a series of massive distributed denial-of-service (DDoS) attacks over the past six months. KrebsOnSecurity publicly named the suspect in February 2026 after the accused launched a volley of DDoS, doxing and swatting campaigns against this author and a security researcher. He now faces criminal hacking charges in both Canada and the United States.https://krebsonsecurity.com/2026/05/alleged-kimwolf-botmaster-dort-arrested-charged-in-u-s-and-canada/#botnet #ddos #kimwolf #cybercrime
(DIR) Post #B6cvxi3VyXpuJygbaa by briankrebs@infosec.exchange
0 likes, 0 repeats
New, by me: Lawmakers Demand Answers as CISA Tries to Contain Data Leak"Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a vast trove of other agency secrets on a public GitHub account. The inquiry comes as CISA is still struggling to contain the breach and invalidate the leaked credentials."From the story: "KrebsOnSecurity has learned that more a week after CISA was first notified of the data leak by the security firm GitGuardian, the agency is still working to invalidate and replace many of the exposed keys and secrets.""On May 20, KrebsOnSecurity heard from Dylan Ayrey, the creator of TruffleHog, an open-source tool for discovering private keys and other secrets buried in code hosted at GitHub and other public platforms. Ayrey said CISA still hadn’t invalidated an RSA private key exposed in the Private-CISA repo that granted access to a GitHub app which is owned by the CISA enterprise account and installed on the CISA-IT GitHub organization with full access to all code repositories."https://krebsonsecurity.com/2026/05/lawmakers-demand-answers-as-cisa-tries-to-contain-data-leak/
(DIR) Post #B6cvximBITZ6YVaHD6 by briankrebs@infosec.exchange
0 likes, 0 repeats
There's a tendency for organizations to react to inadvertently exposing secrets in public code repositories by disabling the repo in question on GitHub, but then taking their time to rotate the exposed credentials. I guess the thinking is that well, maybe nobody noticed. And that's pure folly. From today's story:"Ayrey said his company Truffle Security monitors GitHub and a number of other code platforms for exposed keys, and attempts to alert affected accounts to the sensitive data exposure(s). They can do easily on GitHub because the platform publishes a live feed which includes a record of all commits and changes to public code repositories. But he said cybercriminal actors also monitor these public feeds, and are often quick to pounce on API or SSH keys that get inadvertently published in code commits.""In practical terms, it is likely that cybercrime groups or foreign adversaries also noticed the publication of these CISA secrets, the most egregious of which appears to have happened in late April 2025, Ayrey said.“We monitor that firehose of data for keys, and we have tools to try to figure out whose they are,” he said. “We have evidence attackers monitor that firehose as well. Anyone monitoring GitHub events could be sitting on this information.”"
(DIR) Post #B6eohVZuHvz7cu5Jiq by briankrebs@infosec.exchange
0 likes, 1 repeats
New, by me:Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and disinformation campaigns inside the European Union. The two men were the focus of a 2025 KrebsOnSecurity story about how their hosting companies had assumed control over the technical infrastructure of Stark Industries Solutions, an Internet service provider sanctioned last year by the EU as a frequent staging ground for cyber mischief from Russia’s intelligence agencies.https://krebsonsecurity.com/2026/05/netherlands-seizes-800-servers-arrests-2-for-aiding-cyberattacks/Previous reporting on Stark Industries:May 2024: Stark Industries Solutions: An Iron Hammer in the Cloud: https://krebsonsecurity.com/2024/05/stark-industries-solutions-an-iron-hammer-in-the-cloud/July 2024: The Stark Truth Behind the Resurgence of Russia's Fin7: https://krebsonsecurity.com/2024/07/the-stark-truth-behind-the-resurgence-of-russias-fin7/September 2025: Bulletproof Host Stark Industries Evades EU Sanctions: https://krebsonsecurity.com/2025/09/bulletproof-host-stark-industries-evades-eu-sanctions/#russia #cybercrime #arrest #sanctions
(DIR) Post #B6fDXLL4Tld1Bv95gO by briankrebs@infosec.exchange
0 likes, 0 repeats
So, I guess now that Google has officially shit the bed w/ their AI search, this is going to be my new browser start page from now on. https://udm14.org/
(DIR) Post #B6lFLoa9IFszGkaX68 by briankrebs@infosec.exchange
0 likes, 0 repeats
@GossiTheDog yeah that reads as pretty hostile to researchers in general and labels as "threat actors" those who don't choose to play by Microsoft's rules.