Security awareness training is needed now more than ever. At Huntress, we analyzed countless #SAT solutions and found some common characteristics that inhibit them from achieving their stated goals around security. Check out our blog to read more about the 7 SATuations to avoid. https://bit.ly/3IPUcVL
⚠️ 26 teens have been murdered by Nigerian cybercriminals known as the "Yahoo Boys" in the past 18 months. They're on a mass killing spree, and there's no end in sight.
👻 17-year-old Harry Burke died by suicide just hours after he was approached by a new contact on Snapchat, who posed as a girl and coerced him into sharing intimate images. Once those pictures were sent, the criminal threatened to ruin Harry's military career and destroy his life if he didn't send money.
💬 "Dad, I screwed up," he said. "I had shared pictures and now this person wants money." https://lnkd.in/dFB79X3Q
📲 They sat down as a family to discuss it. During the discussion, an alert went off on his mother's phone. "This is how nasty these criminals can get," she said. "This person that had been threatening Harry actually messaged me when Harry was speaking to us, saying they were going to ruin him. And I really wish Harry hadn't seen that message."
📲 Harry called one of his military friends, who told him some pictures had already been sent to him. "You could see it wear on Harry, on his face. He was defeated."
💥The next morning, Harry's mother found him dead in his bedroom.
⚠️ In 2021, there were only 139 cases of financial sextortion reported to NCMEC. But in 2023, there were over 26,000 reported cases.
That's a 18,700% increase over two years. This is a public safety emergency.
Here's what's happening every single day:
📈 The Yahoo Boys are sending hundreds of thousands of fake friend requests to teens on Instagram and Snapchat.
📈 Tens of thousands of teens engage with a sextortion scammer.
📈 Thousands of teens are coerced into sending an explicit photo and are blackmailed.
📈 Hundreds will pay the criminals and get hooked into a long-term blackmail situation.
📈 Dozens will consider suicide as the only way out.
This is the deadliest scam in human history and it must be stopped.
⚡So we're going to stop it. Y'all asked for a coalition on my last post. On April 24, we're teaming up to stop this crime once and for all. Who's in? Register here: https://lnkd.in/eisYuw5m
A BIGTIME GAFFE: Microsoft accidentally granted global admin privileges to a random legacy test account.
Which then got hacked by Russia.
Granting the hackers read access to every Office 365 account in the world.
From the comments at Ars Technica —
To summarize the fuckups:
Created test tenant with access to prod data
Created test account with weak password
Made test account accessible from internet
Never enabled 2FA on test account
Gave test account admin role
Did not monitor for slow password sprays (a known technique)
Failed to disable test account at end of testing
Failed to monitor for unused/test accounts in production environment
Did not monitor executives' accounts for surreptitious access
Did not monitor internal test account (that apparently hadn't been accessed in years) for "unusual login activity"
Did I miss anything? By my count, that's ten fuckups. It's kind of impressive!
Without technical mitigations in place, the deployment of Chinese-manufactured drones in our nation’s key sectors is a national security concern, carrying the risk of unauthorized access to data. Read this advisory from the #FBI and the Cybersecurity and Infrastructure Security Agency (CISA) on safely procuring and operating drones, also known as unmanned aircraft systems (UAS): https://lnkd.in/eNhn7X6r
The FBI is releasing a Private Industry Notification on ransomware initial access trends, including the use of third-party and legitimate system tools as attack vectors. Companies should follow the latest recommended mitigations to limit potential adversarial use of common system and network discovery techniques and to reduce the risk of compromise by ransomware: https://lnkd.in/djcdQ7fz