Krebs on Security In-depth security news and investigation
- MasterCard DNS Error Went Unnoticed for Yearsby BrianKrebs on January 22, 2025 at 3:24 pm
The payment card giant MasterCard just fixed a glaring error in its domain name server settings that could have allowed anyone to intercept or divert Internet traffic for the company by registering an unused domain name. The misconfiguration persisted for nearly five years until a security researcher spent $300 to register the domain and prevent it from being grabbed by cybercriminals.
- Chinese Innovations Spawn Wave of Toll Phishing Via SMSby BrianKrebs on January 16, 2025 at 9:18 pm
Residents across the United States are being inundated with text messages purporting to come from toll road operators like E-ZPass, warning that recipients face fines if a delinquent toll fee remains unpaid. Researchers say the surge in SMS spam coincides with new features added to a popular commercial phishing kit sold in China that makes it simple to set up convincing lures spoofing toll road operators in multiple U.S. states.
- Microsoft: Happy 2025. Here’s 161 Security Updatesby BrianKrebs on January 14, 2025 at 10:50 pm
Microsoft today unleashed updates to plug a whopping 161 security vulnerabilities in Windows and related software, including three "zero-day" weaknesses that are already under active attack. Redmond's inaugural Patch Tuesday of 2025 bundles more fixes than the company has shipped in one go since 2017.
- A Day in the Life of a Prolific Voice Phishing Crewby BrianKrebs on January 7, 2025 at 11:41 pm
Besieged by scammers seeking to phish user accounts over the telephone, Apple and Google frequently caution that they will never reach out unbidden to users this way. However, new details about the internal operations of a prolific voice phishing gang show the group routinely abuses legitimate services at Apple and Google to force a variety of outbound communications to their users, including emails, automated phone calls and system-level messages sent to all signed-in devices.
- U.S. Army Soldier Arrested in AT&T, Verizon Extortionsby BrianKrebs on December 31, 2024 at 4:05 am
Federal authorities have arrested and indicted a 20-year-old U.S. Army soldier on suspicion of being Kiberphant0m, a cybercriminal who has been selling and leaking sensitive customer call records stolen earlier this year from AT&T and Verizon. As first reported by KrebsOnSecurity last month, the accused is a communications specialist who was recently stationed in South Korea.