Krebs on Security In-depth security news and investigation

  • Scattered Spider Hackers Plead Guilty on Day 1 of Trial
    by BrianKrebs on June 23, 2026 at 4:12 pm

    Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial.

  • ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
    by BrianKrebs on June 18, 2026 at 5:37 pm

    For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a "residential proxy" provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR].

  • Who Runs the Ransomware Group ‘The Gentlemen?’
    by BrianKrebs on June 10, 2026 at 2:03 pm

    A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group.

  • A Record-Breaking Patch Tuesday for June 2026
    by BrianKrebs on June 9, 2026 at 10:07 pm

    Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company's monthly Patch Tuesday cycle. Nearly three dozen of those bugs earned Microsoft's most dire "critical" rating, and exploit code for at least three of the weaknesses is now publicly available.

  • Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
    by BrianKrebs on June 1, 2026 at 5:32 pm

    The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on Telegram showing how to trick Meta's "AI support assistant" bot into resetting account passwords.



BleepingComputer BleepingComputer - All Stories



The Hacker News Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to admin@thehackernews.com

  • CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited
    by info@thehackernews.com (The Hacker News) on June 24, 2026 at 5:19 pm

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation of a critical security flaw impacting Lantronix EDS5000 Series devices, urging Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 26, 2026. The vulnerability in question is CVE-2025-67038 (CVSS score: 9.8), a code injection flaw that could result in the execution

  • Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered
    by info@thehackernews.com (The Hacker News) on June 24, 2026 at 3:59 pm

    A coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft, has resulted in the takedown of criminal infrastructure powering Amadey and StealC. "The main common goal was to disrupt the 'assembly lines' cybercriminals use to launch ransomware, financial fraud, and attacks on critical infrastructure," Europol said in

  • Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
    by info@thehackernews.com (The Hacker News) on June 24, 2026 at 12:48 pm

    Cybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source supply chains. The "critical exploitable pattern" has been codenamed Cordyceps by Novee Security. The issue can allow full attacker control of repositories at dozens of the largest organizations worldwide, including Microsoft, Google, Apache, and

  • Dawn of the Apex Agentic Adversary
    by info@thehackernews.com (The Hacker News) on June 24, 2026 at 11:30 am

    We are standing at the end of an era we never thought to mourn: the era of human-speed threats. For years, cybersecurity moved to a rhythm organizations could follow. A researcher found a bug, a CVE was cataloged, a vendor navigated a patch cycle, and weeks or even months later, a fix was deployed. In this era, dwell time was measured in days, sometimes weeks. We are now approaching an

  • DoJ Seizes Huione Cloud Account Tied to Cyber Scam Money Laundering
    by info@thehackernews.com (The Hacker News) on June 24, 2026 at 8:55 am

    The U.S. Department of Justice (DoJ) on Tuesday announced the seizure of a cloud computing account put to use by subsidiaries of Cambodia-based corporate conglomerate HuiOne Group, as the Treasury unveiled fresh sanctions against nine individuals and 26 entities linked to Prince Group. "These subsidiaries are alleged to have assisted individuals and organizations in transferring proceeds of