Krebs on Security

Krebs on Security In-depth security news and investigation

  • Mozilla Says It’s Finally Done With Two-Faced Onerep
    by BrianKrebs on 20 November 2025 at 7:06 pm

    In March 2024, Mozilla said it was winding down its collaboration with Onerep -- an identity protection service offered with the Firefox web browser that promises to remove users from hundreds of people-search sites -- after KrebsOnSecurity revealed Onerep's founder had created dozens of people-search services and was continuing to operate at least one of them. Sixteen months later, however, Mozilla is still promoting Onerep. This week, Mozilla announced their partnership with Onerep will officially end next month.

  • The Cloudflare Outage May Be a Security Roadmap
    by BrianKrebs on 19 November 2025 at 2:07 pm

    An intermittent outage at Cloudflare on Tuesday briefly knocked many of the Internet's top destinations offline. Some affected Cloudflare customers were able to pivot away from the platform temporarily so that visitors could still access their websites. But security experts say doing so may have also triggered an impromptu network penetration test for organizations that have come to rely on Cloudflare to block many types of abusive and malicious traffic.

  • Microsoft Patch Tuesday, November 2025 Edition
    by BrianKrebs on 16 November 2025 at 9:47 pm

    Microsoft this week pushed security updates to fix more than 60 vulnerabilities in its Windows operating systems and supported software, including at least one zero-day bug that is already being exploited. Microsoft also fixed a glitch that prevented some Windows 10 users from taking advantage of an extra year of security updates, which is nice because the zero-day flaw and other critical weaknesses patched today affect all versions of Windows, including Windows 10.

  • Google Sues to Disrupt Chinese SMS Phishing Triad
    by BrianKrebs on 13 November 2025 at 2:47 pm

    Google is suing more than two dozen unnamed individuals allegedly involved in peddling a popular China-based mobile phishing service that helps scammers impersonate hundreds of trusted brands, blast out text message lures, and convert phished payment card data into mobile wallets from Apple and Google.

  • Drilling Down on Uncle Sam’s Proposed TP-Link Ban
    by BrianKrebs on 9 November 2025 at 6:14 pm

    The U.S. government is reportedly preparing to ban the sale of wireless routers and other networking gear from TP-Link Systems, a tech company that currently enjoys an estimated 50% market share among home users and small businesses. Experts say while the proposed ban may have more to do with TP-Link's ties to China than any specific technical threats, much of the rest of the industry serving this market also sources hardware from China and ships products that are insecure fresh out of the box.