Krebs on Security

Krebs on Security In-depth security news and investigation

  • Microsoft Patch Tuesday, December 2025 Edition
    by BrianKrebs on 9 December 2025 at 11:18 pm

    Microsoft today pushed updates to fix at least 56 security flaws in its Windows operating systems and supported software. This final Patch Tuesday of 2025 tackles one zero-day bug that is already being exploited, as well as two publicly disclosed vulnerabilities.

  • Drones to Diplomas: How Russia’s Largest Private University is Linked to a $25M Essay Mill
    by BrianKrebs on 6 December 2025 at 2:45 pm

    A sprawling academic cheating network turbocharged by Google Ads that has generated nearly $25 million in revenue has curious connections to a Kremlin-connected oligarch whose Russian university builds drones for Russia's war against Ukraine.

  • SMS Phishers Pivot to Points, Taxes, Fake Retailers
    by BrianKrebs on 4 December 2025 at 11:02 pm

    China-based phishing groups blamed for non-stop scam SMS messages about a supposed wayward package or unpaid toll fee are promoting a new offering, just in time for the holiday shopping season: Phishing kits for mass-creating fake but convincing e-commerce websites that convert customer payment card data into mobile wallets from Apple and Google. Experts say these same phishing groups also are now using SMS lures that promise unclaimed tax refunds and mobile rewards points.

  • Meet Rey, the Admin of ‘Scattered Lapsus$ Hunters’
    by BrianKrebs on 26 November 2025 at 5:22 pm

    A prolific cybercriminal group that calls itself "Scattered LAPSUS$ Hunters" made headlines regularly this year by stealing data from and publicly mass extorting dozens of major corporations. But the tables seem to have turned somewhat for "Rey," the moniker chosen by the technical operator and public face of the hacker group: Earlier this week, Rey confirmed his real life identity and agreed to an interview after KrebsOnSecurity tracked him down and contacted his father.

  • Is Your Android TV Streaming Box Part of a Botnet?
    by BrianKrebs on 24 November 2025 at 6:44 pm

    On the surface, the Superbox media streaming devices for sale at retailers like BestBuy and Walmart may seem like a steal: They offer unlimited access to more than 2,200 pay-per-view and streaming services like Netflix, ESPN and Hulu, all for a one-time fee of around $400. But security experts warn these TV boxes require intrusive software that forces the user's network to relay Internet traffic for others, traffic that is often tied to cybercrime activity such as advertising fraud and account takeovers.