Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Latest News

Your Company's Phishing Tests Are Measuring the Wrong Thing

  When a phishing simulation returns a low click rate, security teams tend to relax. Leadership checks a compliance box. The program gets re...

All the recent news you need to know

Lost Phone Reporting Flaws Could Let Hackers Block Any Mobile Device for $4


A new security investigation has revealed serious weaknesses in the systems used by mobile carriers to block lost or stolen phones. Researchers found that an attacker could exploit these flaws to disconnect another person’s smartphone—or even a cellular-connected home alarm—from mobile networks for as little as $2.50 to $4. The attack reportedly took between 20 and 80 seconds, raising concerns about the reliability of a process designed to protect phone owners. 

When a customer reports a phone as lost or stolen, the carrier records the handset’s unique International Mobile Equipment Identity (IMEI) number in an Equipment Identity Register, or EIR. Mobile networks then use this database to reject the device and prevent it from registering for calls, messages and data services. The system is also designed to discourage theft because a blacklisted phone may become unusable, even if someone replaces its SIM card. However, researchers discovered that the process contains weaknesses across multiple layers. 

The study identified six flaws affecting devices, carrier reporting systems and the infrastructure used by telecom companies to exchange blocked-device lists. These weaknesses could allow criminals to submit fraudulent reports or manipulate information without proving that they own the targeted handset. In addition to smartphones, the problem may affect connected security systems and other Internet of Things devices that rely on cellular networks. A malicious actor could potentially disrupt a home alarm, surveillance system or other connected equipment by falsely reporting its IMEI as stolen. 

The findings highlight the risks of trusting a single identifier as proof of ownership. Although IMEI-based blocking can be useful, carriers may need stronger verification, better monitoring and faster recovery procedures for legitimate customers. Providers could require additional account checks, detect unusual reporting patterns and notify owners before permanently adding a device to a blacklist. They should also make it easier for customers to challenge fraudulent blocks and restore service quickly. 

For phone owners, the investigation is a reminder to secure accounts and keep evidence of ownership. If a device disappears, users should immediately activate Android’s Find My Device or Apple’s Find My service, remotely lock the handset and contact their carrier to suspend the SIM or eSIM. They should change important passwords, monitor banking accounts and report suspected theft to the police. Customers who discover that their device has been wrongly blocked should contact the carrier, request an investigation and provide purchase records, account details and the handset’s IMEI number.

Study Warns Enterprise AI Rollouts Are Outpacing Data Security Checks

 

Companies are adopting AI tools faster than they are testing whether their underlying data is appropriately secure, a new report from governance firm Syskit suggests. Based on a survey of 327 IT and security decision-makers at U.S. and U.K. organizations with at least 500 workers, Syskit's State of Microsoft 365 Governance Report, published Sept. 10, found that 76% of the companies surveyed had deployed or tested enterprise AI tools such as Copilot in their Microsoft 365 environments, but less than half (43%) had conducted a thorough review of file permissions and potential oversharing risks prior to deployment, and the rest skipped the review process or reviewed only partially.  

There was a similar gap for oversight over AI agents. While 91% of respondents said they were confident about their knowledge of what AI agents were and had access to, in practice, barely one in five companies (22%) had a formal policy outlining permitted agents' access, and roughly one in 10 (9%) had an agent that had inherited all the permissions of the person who had deployed it. "If you look at tools such as Copilot, you can see the value it can bring," said Syskit CEO Toni Frankola, noting that some content could be exposed purely based on permissions that had been set years ago and then simply forgotten about, and that AI had removed the friction that had previously prevented accidental exposure. 

"Permission audits may be the most critical and least desirable step in preparing a safe and secure AI deployment." The report also highlighted areas of weakness in Microsoft 365 environments overall. Roughly 41% of organizations had SharePoint sites that were publicly available with no access restrictions, 35% had visible files for past employees, and a third had files shared publicly with "Everyone." Ownerless content was the biggest concern, with 47% of organizations citing orphaned teams, groups and sites, which had no one accountable for reviewing or securing them, despite being accessible to an AI just as readily as any other content.  

"There seems to be a disconnect between confidence and reality with regard to the management and control of data and information," said Frankola. "While eight in 10 (83%) organizations feel confident that they know exactly who can access specific sensitive information, only 4% could provide a complete access report for an auditor within an hour if asked ... and more than half would need at least a day to prepare one." Perhaps most concerningly, 90% of organizations said they had suffered or suspected a security incident related to incorrectly configured permissions or excessive access in the last two years, and 39% confirmed that a security incident had definitely occurred.

Android Simplifies Secure Migration of Saved Logins


With the advent of Android's new credential transfer feature, passwords and passkeys can be transferred directly between supported password managers without the creation of an unencrypted file. This feature resolves a problem longstanding with migration. 

In the past, it was often necessary to export stored credentials into a text or CSV file that was unencrypted, so that a temporary copy could remain visible on the device while the password was transferred. Previously, users were not able to transfer passwords between password managers, requiring them to recreate them if they changed providers. 

The new transfer process is handled by Android itself. Migrations begin with the password manager receiving the credentials, and an import or transfer option is offered to initiate the migration. Upon identifying supported password managers installed on the device, Android passes control to the existing manager, allowing them to review and authorize credentials that have been selected for transfer. 

The new system facilitates the transfer of passwords and passkeys, eliminating the need to create plaintext credentials as part of the migration process. This approach aims to reduce the exposure of sensitive authentication data during the switch of password managers. 

With Android's new credential transfer feature, users can move passwords and passkeys directly between password management applications without having to create an unencrypted file in the process. This feature addresses the long-standing issue of migration between password management applications. 

Passwords were traditionally exported into an unencrypted text or CSV file when transferring stored credentials, creating a temporary copy that could remain exposed on the device while the passwords were being transferred. Passkeys, however, cannot be transferred between password managers, so users must recreate them when switching providers. New transfer procedures are managed by Android itself. 

When a password manager receives credentials, it will offer the option of importing or transferring credentials, which will initiate the migration process. Android identifies supported password managers on the device and passes control to those managers in order for the stored credentials to be reviewed and authorized for transfer. 

Passwords and passkeys can be transferred with this new system, removing the requirement to prepare a plaintext credential file during migration. This approach is intended to minimize the potential for exposing sensitive authentication information. 

Support Remains Limited

Four password managers are currently supported by the feature: Google Password Manager, 1Password, Bitwarden, and Dashlane Google has indicated that additional providers are planned, although no specific deadline has been announced. It will still be necessary to use conventional export and import methods when using password managers outside the supported group. This system utilizes a standardized credential exchange approach so that participating password managers can communicate through Android devices. 

Additionally, migration support for passkeys is now available, removing the barrier that previously existed when changing password management services. This feature is accessible on Android 8 or later devices, allowing older supported devices to benefit from this capability, rather than being restricted to recent releases. 

The change is part of a larger effort by Google to improve the security of account information and device migration. The Android platform also includes requirements that are intended to improve the way applications restore the state of their sign-ins when users switch devices. During device migration, eligible applications will use Android's Restore Credentials API to restore authentication under the Zero-Tap Sign-In standard. 

With the introduction of this system, supported applications will be able to recognize existing sign-in states on new devices without requiring additional login steps. Google plans to begin enforcing the Zero-Tap Sign-In requirement by April 2027 while that initiative focuses on application authentication during device upgrades, the password-manager feature allows credentials to be transferred between different password management services. 

There are currently limited provider support options, however, wider adoption could facilitate easier transitions between password managers while reducing the security risks associated with manually handling exported credentials.

South Korean Startup Suffers Breach Due to Encryption Management Failure


Modu-ui, a South Korean government backed startup support platform, suffered a data breach in July. The breach later disclosed a critical encoding key management compromise, showing how encoded information can still become vulnerable when enterprises can’t protect encoding keys properly. 

About Modu-ui

Modu-ui stores participants’ personal details such as email addresses, names, and startup ideas, and the platform also supports a nationwide startup audition overseen by SMEs and Startups (MSS) of the South Korean Ministry.

Suspicions were already raised a month prior to the reported data breach that applicants’ personal data could be structured and exposed via API responses inside the platform. The government said it had taken prompt action but did not reveal if it had upgraded Modu-ui’s security infrastructure.

Startup details leaked

In June, the Ministry of SMEs and Startups disclosed that summaries of startup ideas and personal details had been exposed. Later, it started a detailed enquiry along with National Police Agency, National Intelligence Service, and the Cyber Security Center.

In July, the agencies confirmed that the leak of encoding keys via an API was the reason for the startup idea and personal data leak.

About the breach

The exposed data had already been encoded but the encoded data needs an encoding key decoding.

In this case, the encoding key was leaked along with the API data, causing in the leak of evaluation comments, startup idea summaries and email addresses related to 5000 successful applicants. 

According to the Ministry, the encoding key had been included inside the API and a third party retrieved API data via methods like web crawling, causing the exposure of the key.

Private email addresses were not shown on the public-facing interface but officials believed they could be retrieved via AI-based web crawling. 

Impact on organizations

The incidents also demonstrate the dangers of hard-coding encoding keys as fixed values inside databases, application code, similar environments, or databases.

When businesses follow this method, the keys can become vulnerable in addition to the data or systems they are meant to protect. The main reason for this incident can be viewed as security infrastructure failure in incorporating  robust encoding key management.

Officials found 39 IP addresses related to the access of the exposed data coming from South Korea. Authorities also said that investigations led to more details such as potential connections to AI solution providers.

Conti Ransomware Ties Lead to Four-Year Prison Sentence


Ukrainian nationals have been sentenced to four years in U.S. prison for participating in the Conti ransomware operation. Between 2020 and 2022, the company was carrying out attacks against organizations throughout the United States and other countries. 

In addition to serving as a hacker and developer, Oleksii Oleksiyovych Lytvynenko, 44, was also an integral part of the operation. According to prosecutors, he personally targeted at least 12 companies, handled stolen information obtained from victims, and helped develop tools used during Conti's ransomware attacks. 

Lytvynenko pleaded guilty in June 2026 to conspiracy to commit wire fraud. She was responsible for controlling the theft of data from eight U.S. victims and four foreign victims. A ransom demand was also sent by him during Conti's double-extortion attacks, during which stolen information was used in conjunction with file encryption to pressure victims into paying.

According to the investigation, Lytvynenko also played a role in creating the malware loader for the group. This tool allows attackers to launch or load other malicious software onto compromised systems, providing attackers with another means of executing ransomware operations. 

Conti's Global Ransomware Campaign

In the course of its operation, Conti attacked companies across 47 U.S. states, Washington, D.C., Puerto Rico, and 31 other countries, making it one of the most active ransomware operations of its time. As reported by the FBI, ransom payments associated with Conti exceeded $150 million by January 2022. 

The group targeted hospitals, government agencies, and business entities among its target groups. According to its operations, Lytvynenko stole sensitive information and encrypted systems before demanding cryptocurrency payments from victims. Following a U.S. request, Lytvynenko was arrested in July 2023 at his Cork, Ireland, residence. 

After contesting extradition, he was ultimately transferred to the United States and held in Irish custody for a short period of time. The court's decision adds to the law enforcement response against the Conti ransomware network, which successfully shut down in 2022 in response to mounting pressure and the release of its internal communications. 

Evidence Linked Lytvynenko to Continued Ransomware Activity

It was discovered that Lytvynenko's online accounts contained much more than stolen victim information. Prosecutors alleged that the accounts contained Conti malware and ransom notes, as well as material relating to malware and hacking. As evidenced by his accounts, he searched for potential targets, indicating a deeper involvement than the development side of the operation. Court records also indicated his involvement in cryptocurrency transactions.

A transfer of about $25,042 worth of Bitcoin, involving 0.4 bitcoin, was traced to a victim associated with Lytvynenko's Conti activities. The court imposed a forfeiture of the same amount. Evidence recovered from Lytvynenko's computer after the arrest in 2023 also raised concerns regarding his continued involvement in cybercriminalism.

Investigators discovered Cobalt Strike running on the device and a Rocket.Chat session connected through Tor. Prosecutors said the forensic evidence indicated that Lytvynenko continued to participate in ransomware attacks after Conti ceased to operate. 

Conti's Collapse Did Not End Its Criminal Network

Following the release of internal chats and source code, Conti disbanded in 2022, which revealed details regarding the ransomware group and its members. As a result of the group's public support of Russia after the invasion of Ukraine, investigators were able to gain additional insight into its structure and activities by investigating the leak. 

While the shutdown was initiated, prosecutions did not immediately cease. Four additional Conti members were charged in separate indictments in 2023, and in 2024 Ukrainian authorities arrested another suspected Conti member in Kyiv. Lytvynenko's case contributes to the ongoing legal action against those involved in the ransomware operation by adding another conviction.

Florida Says Motor Vehicle Data Breach Tied to Credentials Stolen From Officer's Personal Device

 

Officials in Florida confirmed Thursday that the state Department of Motor Vehicles suffered a data breach after credentials were stolen from a police officer who had stored login information on a personal device. The ShinyHunters cybercriminal organization claimed on Monday that it had obtained access to data from the Florida Department of Highway Safety and Motor Vehicles (FLHSMV). 

The department did not respond to repeated requests for comment throughout the week but publicly confirmed the breach's legitimacy on Thursday night. Officials said they first learned of the breach on September 4 and initially attributed it to an unnamed "international cybercriminal organization." 

According to the department, an investigation determined that a criminal actor exploited a single Plant City Police Department user's credentials, which had been improperly stored on the employee's personal electronic device. Plant City is a small suburb outside Tampa. FLHSMV has since notified other Florida government offices and is partnering with the Florida Digital Service to investigate the incident. 

As proof of access, ShinyHunters shared alleged photos of a DMV record tied to American financier and convicted child sex offender Jeffrey Epstein. When claims of the breach first surfaced, some cybersecurity experts speculated it might be connected to the recently confirmed breach involving 153 million driver's licenses leaked by identity verification firm IDScan. ShinyHunters had previously attempted to purchase the ID database from the hackers behind the IDScan breach.

The group has recently claimed responsibility for attacks on bank IT provider Jack Henry, as well as pharmaceutical and healthcare technology company McKesson, which told regulators that data from its oncology and surgical business units had been stolen. ShinyHunters also caused widespread disruption across the U.S. in May with an attack on a widely used educational software suite and stole the information of more than four million people after targeting the world's largest medical device company in April. 

Other victims linked to the group include Carnival Cruises, Ticketmaster, AT&T, McGraw Hill, ADT, and gaming company Rockstar. In a related development, artificial intelligence company Anthropic released a report Thursday stating that suspected affiliates of ShinyHunters used AI to scan for credentials, map unfamiliar systems, and steal data from victims for extortion purposes. 

The report noted that in one case, an operator escalated from a stolen developer token to full administrative access over a victim's cloud environment in approximately three hours. Incident responders at Google also confirmed last week that members of the group are using Anthropic's AI tools at various stages of their attacks. 

The Florida breach adds to a growing list of incidents tied to ShinyHunters, underscoring the group's persistent targeting of both government systems and major corporations, as well as its evolving use of AI tools to accelerate and scale its intrusions.

Featured