TeamPCP, the threat actor behind an unrelenting flurry of attacks on open-source software this year, has been active much longer than previously thought, according to research Oligo Security shared exclusively with CyberScoop. Read more by @mattkapko.com: cyberscoop.com/teampcp-long...
Matt Kapko
@mattkapko.com
Cybercrime reporter @ CyberScoop • Grateful lifelong Californian • matt.49 on Signal • matt.kapko@cyberscoop.com • mattkapko.com
A former DigitalMint ransomware negotiator was sentenced to 70 months in jail for deceiving his clients and conspiring with ransomware affiliates to extort a combined $75.3 million from five U.S. companies he was entrusted to aid during their moments of extreme crisis. cyberscoop.com/digitalmint-...
Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail
Angelo Martino exploited his insider position and fed confidential information to ransomware co-conspirators to extort a combined $75.3 million from five U.S.-based victims.
cyberscoop.com
Peter Stokes boasted on social media about the luxurious globetrotting life he enjoyed while he was still a child. via @mattkapko.com cyberscoop.com/scattered-sp...
Alleged longstanding member of Scattered Spider extradited to US
Alleged Scattered Spider hacker Peter Stokes, 19, has been extradited to the U.S. after flaunting a lavish lifestyle funded by $100M in cyber extortion.
cyberscoop.com
TeamPCP is on a rampage through open-source software, striking defensive vulnerabilities the software industry has known about for years. The open source trust model is broken and susceptible to sabotage. Yet, the software industry has not fixed this problem. cyberscoop.com/teampcp-brea...
How software development's speed obsession enabled TeamPCP’s chaos crusade
The threat group’s remarkable success targeting open-source software was inevitable and fueled by the industry’s decision to prioritize code shipping over security.
cyberscoop.com
More of my thoughts on the public vulnerability disclosure fight Microsoft picked with the researcher Nightmare Eclipse in this piece by @mattkapko.com for @cyberscoop.bsky.social . @andrewmorr.is of @greynoise.io Intelligence shares perspective too. cyberscoop.com/microsoft-co...
Nightmare Eclipse incident shows the researcher-vendor fights may never fully go away
When a researcher went public with Microsoft vulnerabilities, it laid bare a conflict that has never really been solved.
cyberscoop.com
Thanks for letting me comment @mattkapko.com! And…yea, I made an Arby’s joke 😂
FBI warns US-based law firms to be on the lookout for cybercrime group that steals data in person
Silent Ransom Group isn’t prolific, but it's demonstrated a knack for attacking the legal services sector with an extraordinary dual use of social engineering and in-person visits to victims’ workstat...
cyberscoop.com
Fox Tempest, a financially-motivated threat group, allowed ransomware operators and other cybercriminals to slip malware-laced software past security controls. via @mattkapko.com cyberscoop.com/microsoft-di...
Microsoft disrupts cybercrime service that abused software verification systems en masse
Fox Tempest, a financially-motivated threat group, allowed ransomware operators and other cybercriminals to slip malware-laced software past security controls.
cyberscoop.com
Researchers found artifacts in the code that proved AI was heavily involved. A prominent cybercrime group planned to exploit the zero-day en masse for financial gain. via @mattkapko.com www.youtube.com/watch?v=Rywb... | cyberscoop.com/google-threa...
Google spotted an AI-developed zero-day before attackers could use it
YouTube video by CyberScoop
youtube.com
My colleague Aaron Parsley just won a Pulitzer for this story, written days after he survived the July 4 floods that killed his nephew. It's one of the most gutwrenching and memorable things you'll ever read. Please do.
“The River House Broke. We Rushed in the River.”
The July 4 Texas flooding ripped our Kerr County home from its pillars, pulling us into the water and into the night. Then morning came.
texasmonthly.com
"...the seeds of the attack were planted in February when a Context.ai employee’s computer was infected with Lumma Stealer malware after they searched for Roblox game exploits, a common vector for infostealer deployments." cyberscoop.com/vercel-secur...
Vercel's security breach started with malware disguised as Roblox cheats
The attack, which originated at Context.ai, showcases the pitfalls of interconnected cloud applications and SaaS integrations with overly privileged permissions.
cyberscoop.com
Inside the FBI’s router takedown that cut off APT28’s ‘tremendous access’: FBI cyber chief Brett Leatherman told CyberScoop the Russian GRU campaign was unique in how it could propagate from routers to beyond. cyberscoop.com/fbi-operatio...
Inside the FBI’s router takedown that cut off APT28’s ‘tremendous access’
FBI Assistant Director Brett Leatherman reveals how "Operation Masquerade" dismantled a "virtually invisible" Russian GRU cyber campaign that hijacked 18,000 routers to spy on home and office traffic worldwide.
cyberscoop.com
A systemic numbness to cyberattacks has exposed the U.S. economy and its institutions to ever-widening threats. Retired four-star military officials worry the worst day in cyber is yet to come. via @mattkapko.com www.youtube.com/watch?v=Kv-h... | cyberscoop.com/former-nsa-c...
Former NSA chiefs worry American offensive edge in cybersecurity is slipping
YouTube video by FedScoop
youtube.com
A systemic numbness to cyberattacks has exposed the U.S. economy and its institutions to ever-widening threats. Retired four-star military officials worry the worst day in cyber is yet to come. via @mattkapko.com cyberscoop.com/former-nsa-c...
Former NSA chiefs worry American offensive edge in cybersecurity is slipping
A systemic numbness to cyberattacks has exposed the U.S. economy and its institutions to ever-widening threats. Retired four-star military officials worry the worst day in cyber is yet to come.
cyberscoop.com
Four former NSA chiefs worry that a systemic numbness to cyberattacks has exposed the U.S. economy and its institutions to ever-widening threats. The retired four-star military officials worry the worst day in cyber is yet to come. cyberscoop.com/former-nsa-c...
Former NSA chiefs worry American offensive edge in cybersecurity is slipping
A systemic numbness to cyberattacks has exposed the U.S. economy and its institutions to ever-widening threats. Retired four-star military officials worry the worst day in cyber is yet to come.
cyberscoop.com
Second drop from the RSA Conference in San Francisco.
Attackers compromised the open-source security tool and published malicious versions of the software. Mandiant warns the fallout could impact up to 10,000 downstream victims. via @mattkapko.com cyberscoop.com/trivy-supply...
My first drop from this week’s RSA conference is out. Leaders from various cybersecurity institutions were quick to defend and evangelize the administration’s strategic pivots in cyberspace, claiming the freshly-released document is already paying off. cyberscoop.com/cyber-strate...
Experts insist Trump administration's cyber strategy is already paying off
Leaders from various cybersecurity institutions were quick to defend and evangelize the administration’s strategic pivots in cyberspace.
cyberscoop.com
Good morning to everyone but botnet admins! Great piece from @mattkapko.com, appreciate having a few of my comments in it! 🖖🌩️⚖️ cyberscoop.com/botnet-disru...
Justice Department disrupts botnet networks that hijacked 3 million devices
The Aisuru, Kimwolf, JackSkid and Mossad botnets enabled cybercriminals to initiate thousands of attacks. A crackdown targeting large-scale botnets continues amid growing challenges.
cyberscoop.com
Maybe a criminal convicted of computer fraud and aggravated identity theft shouldn't have access to a computer while they're in prison for those crimes? Am I missing something here? cyberscoop.com/nba-nfl-athl...
Zero lessons learned: Convicted scammer allegedly ran another athlete-focused phishing scam from federal prison
Kwamaine Jerell Ford allegedly impersonated an adult film star and tricked his high-profile victims into sharing their iCloud credentials and MFA codes under false pretenses.
cyberscoop.com
Angelo Martino is accused of playing both sides — committing attacks and conducting ransomware negotiations on some of the same cases on behalf of his former employer. www.youtube.com/watch?v=MlK6... | cyberscoop.com/digitalmint-...
Feds say another DigitalMint negotiator ran ransomware attacks and helped extort $75 million
YouTube video by CyberScoop
youtube.com
Some stories are so strange and so wild, they defy imagination. My latest digs into how a cybersecurity professional allegedly moonlighted as a cybercriminal -- committing attacks and conducting ransomware negotiations for his employer on some of the same cases. cyberscoop.com/digitalmint-...
Feds say another DigitalMint negotiator ran ransomware attacks and extorted $75 million
Federal prosecutors have unsealed charges against Angelo John Martino III, a Florida ransomware negotiator accused of playing "both sides" by orchestrating attacks on his own clients.
cyberscoop.com
The administration also released an executive order on cybercrime and fraud. via @timstarks.bsky.social cyberscoop.com/trump-cybers...
The long-awaited Trump cyber strategy has arrived
President Donald Trump released his administration's cyber strategy Friday, promoting offense operations in cyberspace, securing federal networks and critical infrastructure, streamlining regulations,...
cyberscoop.com
In this episode of Safe Mode, @gregotto.bsky.social dives in with @timstarks.bsky.social to unpack what’s happened inside CISA—and what it could mean for the country’s ability to withstand the next major cyber crisis. www.youtube.com/watch?v=ZUDX... | cyberscoop.com/cisa-personn...
The operational impact of worforce reductions at CISA
YouTube video by CyberScoop
youtube.com
Seeing the lengthy list of changes/cutbacks to CISA catalogued in this one piece makes it clear there is little left of it. The agency is less than a decade old and struggled for years to find its footing before it started to make progress. But all advances it made have been gutted in last 12 months
Across party lines and industry, the verdict is the same: CISA is in trouble
One year into the second Trump administration, CISA faces a 33% loss in personnel and shuttered divisions. Experts warn of "decimated" capabilities and a leadership vacuum as the agency struggles to m...
cyberscoop.com
Gottumukkala out, Andersen in as acting CISA director cyberscoop.com/cisa-leaders...
Gottumukkala out, Andersen in as acting CISA director
Madhu Gottumukkala steps down as acting director of CISA, replaced by Nick Andersen. The move follows criticism of agency performance and leadership shifts at DHS.
cyberscoop.com
The global campaign marks the second series of multiple actively exploited zero-day vulnerabilities in Cisco edge technology since last spring. The similarities don’t end there. via @mattkapko.com cyberscoop.com/cisco-zero-d...
Governments issue warning over Cisco zero-day attacks dating back to 2023
Hackers exploited zero-day flaws in Cisco network devices for three years undetected. CISA issued an emergency directive as the global campaign continues.
cyberscoop.com
Tim dug up all the dirt on CISA. His reporting captures the agency's decline and serves stark warnings about the messes that could unravel when the next major crisis hits.
I spoke to a ton of people for this comprehensive story about CISA one year into the Trump administration, and all sorts were VERY unsparing in their criticism. cyberscoop.com/cisa-personn...