Krebs on Security In-depth security news and investigation

  • Canvas Breach Disrupts Schools & Colleges Nationwide
    by BrianKrebs on May 8, 2026 at 2:58 am

    An ongoing data extortion attack targeting the widely-used education technology platform Canvas disrupted classes and coursework at school districts and universities across the United States today, after a cybercrime group defaced the service's login page with a ransom demand that threatened to leak data from 275 million students and faculty across nearly 9,000 educational institutions.

  • Anti-DDoS Firm Heaped Attacks on Brazilian ISPs
    by BrianKrebs on April 30, 2026 at 2:04 pm

    A Brazilian tech firm that specializes in protecting networks from distributed denial-of-service (DDoS) attacks has been enabling a botnet responsible for an extended campaign of massive DDoS attacks against other network operators in Brazil, KrebsOnSecurity has learned. The firm's chief executive says the malicious activity resulted from a security breach and was likely the work of a competitor trying to tarnish his company's public image.

  • ‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty
    by BrianKrebs on April 21, 2026 at 2:53 pm

    A 24-year-old British national and senior member of the cybercrime group "Scattered Spider" has pleaded guilty to wire fraud conspiracy and aggravated identity theft. Tyler Robert Buchanan admitted his role in a series of text-message phishing attacks in the summer of 2022 that allowed the group to hack into at least a dozen major technology companies and steal tens of millions of dollars worth of cryptocurrency from investors.

  • Patch Tuesday, April 2026 Edition
    by BrianKrebs on April 14, 2026 at 9:47 pm

    Microsoft today pushed software updates to fix a staggering 167 security vulnerabilities in its Windows operating systems and related software, including a SharePoint Server zero-day and a publicly disclosed weakness in Windows Defender dubbed "BlueHammer." Separately, Google Chrome fixed its fourth zero-day of 2026, and an emergency update for Adobe Reader nixes an actively exploited flaw that can lead to remote code execution.

  • Russia Hacked Routers to Steal Microsoft Office Tokens
    by BrianKrebs on April 7, 2026 at 5:02 pm

    Hackers linked to Russia's military intelligence units are using known flaws in older Internet routers to mass harvest authentication tokens from Microsoft Office users, security experts warned today. The spying campaign allowed state-backed Russian hackers to quietly siphon authentication tokens from users on more than 18,000 networks without deploying any malicious software or code.



BleepingComputer BleepingComputer - All Stories



The Hacker News Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to admin@thehackernews.com