ClickFix: How to Infect Your PC in Three Easy Steps

Credit to Author: BrianKrebs| Date: Fri, 14 Mar 2025 22:15:27 +0000

A clever malware deployment scheme first spotted in targeted attacks last year has now gone mainstream. In this scam, dubbed “ClickFix,” the visitor to a hacked or malicious website is asked to distinguish themselves from bots by pressing a combination of keyboard keys that causes Microsoft Windows to download password-stealing malware.

Read more

‘People Are Scared’: Inside CISA as It Reels From Trump’s Purge

Credit to Author: Eric Geller| Date: Thu, 13 Mar 2025 09:30:00 +0000

Employees at the Cybersecurity and Infrastructure Security Agency tell WIRED they’re struggling to protect the US while the administration dismisses their colleagues and poisons their partnerships.

Read more

Microsoft: 6 Zero-Days in March 2025 Patch Tuesday

Credit to Author: BrianKrebs| Date: Tue, 11 Mar 2025 23:53:01 +0000

Microsoft today issued more than 50 security updates for its various Windows operating systems, including fixes for a whopping six zero-day vulnerabilities that are already seeing active exploitation.

Read more

Alleged Co-Founder of Garantex Arrested in India

Credit to Author: BrianKrebs| Date: Tue, 11 Mar 2025 16:49:02 +0000

Authorities in India today arrested the alleged co-founder of Garantex, a cryptocurrency exchange sanctioned by the U.S. government in 2022 for facilitating tens of billions of dollars in money laundering by transnational criminal and cybercriminal organizations. Sources close to the investigation told KrebsOnSecurity the Lithuanian national Aleksej Besciokov, 46, was apprehended while vacationing on the coast of India with his family.

Read more

Feds Link $150M Cyberheist to 2022 LastPass Hacks

Credit to Author: BrianKrebs| Date: Sat, 08 Mar 2025 01:20:05 +0000

In September 2023, KrebsOnSecurity published findings from security researchers who concluded that a series of six-figure cyberheists across dozens of victims resulted from thieves cracking master passwords stolen from the password manager service LastPass in 2022. In a court filing this week, U.S. federal agents investigating a spectacular $150 million cryptocurrency heist said they had reached the same conclusion.

Read more