Brunswick, ME • (207) 245-1010 • contact@johnzblack.com
Mostly security stuff...
Make sure you check out my main blog at https://gnerdsec.com/blog
Telegram hosts a functioning commercial stalkerware market in EU jurisdictions. Amazon filed 1.1 million CSAM reports with zero location or suspect data. UK regulators are now threatening platform executives personally with jail time. Three countries, three harms, one pattern.
Read More
A named Microsoft threat actor is rerouting Canadian paychecks via MFA-bypassing AiTM phishing. An international operation IDed 20,000 crypto fraud victims in a week. And MITRE just published the first ATT&CK-equivalent framework for financial fraud. Three stories that belong together.
Read More
World Leaks didn't touch LAPD's network. They breached a third-party file-sharing app connected to the LA City Attorney's Office that apparently had no password protecting it. 337,000 files including Internal Affairs records and witness names are now in an extortion group's hands.
Read More
Iran's internet blackout hit 1,055 hours, the second-longest national shutdown on record. The detail that makes this a security story: Iranian intelligence services ran active cyber operations throughout, using foreign-hosted infrastructure the blackout doesn't touch.
Read More
FlamingChina claims to have stolen 10 petabytes from China's National Supercomputing Center in Tianjin, including missile schematics and weapons testing data. CNN showed samples to cybersecurity experts. They declined to dismiss it. This has not been confirmed.
Read More
CPUID's official site served a malicious installer for hours. A fake WakaTime extension has been spreading across dev machines for months. Two separate campaigns, one shared trick: they got inside the thing you already trusted.
Read More