News Gist .News

Articles | Politics | Finance | Stocks | Crypto | AI | Technology | Science | Gaming | PC Hardware | Laptops | Smartphones | Archive

The Secretive Ransomware Group's Downfall Through Leaked Chat Logs

Researchers are uncovering internal conflicts and power struggles within the secretive ransomware group Black Basta through leaked chat logs, which have raised concerns about the personal interests of its leader Oleg Nefedov driving operational decisions. The heightened tensions have contributed to growing rifts between Nefedov and his subordinates, potentially putting other members at risk of being tracked down by law enforcement. As a result, Black Basta's operations are under scrutiny, with some experts warning that the group's actions could provoke reactions from authorities.

See Also

Human Rights Abused: Governments Exploit Vulnerabilities to Silence Critics Δ1.75

Amnesty International has uncovered evidence that a zero-day exploit sold by Cellebrite was used to compromise the phone of a Serbian student who had been critical of the government, highlighting a campaign of surveillance and repression. The organization's report sheds light on the pervasive use of spyware by authorities in Serbia, which has sparked international condemnation. The incident demonstrates how governments are exploiting vulnerabilities in devices to silence critics and undermine human rights.

Ransomware Dominates Cybersecurity Threats in 2024 Δ1.74

The modern-day cyber threat landscape has become increasingly crowded, with Advanced Persistent Threats (APTs) becoming a major concern for cybersecurity teams worldwide. Group-IB's recent research points to 2024 as a 'year of cybercriminal escalation', with a 10% rise in ransomware compared to the previous year, and a 22% rise in phishing attacks. The "Game-changing" role of AI is being used by both security teams and cybercriminals, but its maturity level is still not there yet.

NSO Group Executives Can Be Charged in Spyware Investigation Δ1.73

A Barcelona court has ruled that two NSO Group co-founders and a former executive of two affiliate companies can be charged as part of an investigation into the alleged hacking of Catalan lawyer Andreu Van den Eynde. The ruling marks an important legal precedent in Europe's fight against spyware espionage, with Iridia spokesperson Lucía Foraster Garriga stating that the individuals involved will now be held personally accountable in court. The charges stem from a complaint filed by Barcelona-based human rights nonprofit Iridia, which initially requested the judge charge NSO Group executives, but had its request initially rejected.

North Korean Hackers Cash Out Hundreds of Millions From $1.5bn ByBit Hack Δ1.72

Hackers have successfully laundered at least $300m of their record-breaking $1.5bn crypto heist, leaving only unrecoverable funds in the process. The infamous Lazarus Group, thought to be working for the North Korean regime, is believed to be working nearly 24 hours a day to confuse the money trail and convert the digital tokens into usable cash. ByBit has replenished some of the stolen coins with loans from investors but is waging war on Lazarus.

More Reports Claim 2024 Was the Worst Year for Ransomware Attacks Yet. Δ1.72

2024 has been marked as a record-breaking year for ransomware attacks, with a 65% increase in detected groups and 44 new malware variants contributing to almost a third of undisclosed attacks. The healthcare, government, and education sectors were disproportionately affected, while emerging groups like LockBit and RansomHub accounted for a significant number of incidents, highlighting the growing sophistication of cybercriminals. As organizations face escalating financial and reputational risks, the need for proactive cybersecurity measures has never been more urgent.

The Fate of Garantex Hangs in the Balance Δ1.72

An international coalition of law enforcement agencies has seized the official website of Garantex, a Russian cryptocurrency exchange accused of being associated with darknet markets and ransomware hackers. The U.S. Secret Service, working with a coalition of international law enforcement agencies, took down and seized the website following a warrant by the U.S. Attorney’s Office for the Eastern District of Virginia. This move is part of a broader effort to disrupt Garantex's operations in response to its alleged ties to illicit activities.

Snail Mail Spam Takes Center Stage in Ransomware Campaigns Δ1.71

A company's executives received an extortion letter in the mail claiming to be from BianLian ransomware group, demanding payment of $250,000 to $350,000 in Bitcoin within ten days. However, cybersecurity researchers have found that the attacks are likely fake and the letter's contents bear no resemblance to real ransom notes. Despite this, the scammers are using a new tactic by sending physical letters, potentially as part of an elaborate social engineering campaign.

Microsoft Teams and Other Windows Tools Hijacked to Hack Corporate Networks Δ1.71

Hackers are exploiting Microsoft Teams and other legitimate Windows tools to launch sophisticated attacks on corporate networks, employing social engineering tactics to gain access to remote desktop solutions. Once inside, they sideload flawed .DLL files that enable the installation of BackConnect, a remote access tool that allows persistent control over compromised devices. This emerging threat highlights the urgent need for businesses to enhance their cybersecurity measures, particularly through employee education and the implementation of multi-factor authentication.

Zapier Data Breach Raises Concerns Over Customer Information Security. Δ1.71

Zapier, a popular automation tool, has suffered a cyberattack that resulted in the loss of sensitive customer information. The company's Head of Security sent a breach notification letter to affected customers, stating that an unnamed threat actor accessed some customer data "inadvertently copied to the repositories" for debugging purposes. Zapier assures that the incident was isolated and did not affect any databases, infrastructure, or production systems.

Microsoft Names Cybercriminals Who Created Explicit Deepfakes Δ1.71

Microsoft has identified and named four individuals allegedly responsible for creating and distributing explicit deepfakes using leaked API keys from multiple Microsoft customers. The group, dubbed the “Azure Abuse Enterprise”, is said to have developed malicious tools that allowed threat actors to bypass generative AI guardrails to generate harmful content. This discovery highlights the growing concern of cybercriminals exploiting AI-powered services for nefarious purposes.

Finland's Secret Service Says Frequency of Cable Incidents Is 'Exceptional'. Δ1.71

Finland's intelligence service has reported an "exceptional" rise in cable incidents within the Baltic Sea, attributing these breaches to heightened regional tensions following Russia's invasion of Ukraine. While ongoing investigations are probing specific incidents, the chief of Finland's security agency emphasized that state actors possess more sophisticated methods for underwater sabotage than simple anchor dragging. The situation has prompted increased military vigilance from NATO, highlighting the strategic significance of underwater infrastructure amid concerns of a Russia-backed "shadow fleet" operating in the area.

Tata Technologies Hacked by Ransomware Group for 1.4TB Dataset Δ1.71

Tata Technologies has been targeted by a ransomware group that has listed a 1.4TB dataset for sale online, allegedly containing over 730,000 files stolen during the attack in February 2025. The dataset was initially offered for $6.8 million, but its price has since dropped to an unknown amount due to a countdown timer set by the hackers. The firm's investigation into the incident is ongoing, and no further details have been provided about the type of information that was stolen.

Researchers Uncover Unknown Android Flaws Used to Hack Into a Student's Phone Δ1.71

Amnesty International said that Google fixed previously unknown flaws in Android that allowed authorities to unlock phones using forensic tools. On Friday, Amnesty International published a report detailing a chain of three zero-day vulnerabilities developed by phone-unlocking company Cellebrite, which its researchers found after investigating the hack of a student protester’s phone in Serbia. The flaws were found in the core Linux USB kernel, meaning “the vulnerability is not limited to a particular device or vendor and could impact over a billion Android devices,” according to the report.

Malware Hijacks Nearly 1 Million Windows Devices in Advanced Malvertising Attack Δ1.71

A broad overview of the four stages shows that nearly 1 million Windows devices were targeted by a sophisticated "malvertising" campaign, where malware was embedded in ads on popular streaming platforms. The malicious payload was hosted on platforms like GitHub and used Discord and Dropbox to spread, with infected devices losing login credentials, cryptocurrency, and other sensitive data. The attackers exploited browser files and cloud services like OneDrive to steal valuable information.

YouTube Warns of Phishing Video Using Its CEO as Bait Δ1.71

YouTube has issued a warning to its users about an ongoing phishing scam that uses an AI-generated video of its CEO, Neal Mohan, as bait. The scammers are using stolen accounts to broadcast cryptocurrency scams, and the company is urging users not to click on any suspicious links or share their credentials with unknown parties. YouTube has emphasized that it will never contact users privately or share information through a private video.

Cyberattack Rocks Polish Space Agency's Email Systems Δ1.70

The Polish Space Agency (POLSA) has confirmed it suffered a cyberattack that compromised its email systems, forcing it to shut down its IT infrastructure. The attack appears to be an email compromise, with insiders suggesting that relevant authorities have been notified and the agency is analyzing the situation. POLSA's machines were disconnected from the internet as part of the incident.

Eight Sleep Beds Seemingly Suffer From Serious Security Liabilities Δ1.70

High-tech Eight Sleep pods allow Elon Musk and DOGE staff to rest at work, but security flaws have been discovered, including an AWS key and remote access. Hackers could exploit the beds to infiltrate home networks and connected devices, raising concerns about personal privacy and entire home network security. The company's lack of oversight has allowed unauthorized access, potentially leading to financial losses and compromised data.

Microsoft Discoveries Vulnerable Software Attack. Δ1.70

Microsoft has confirmed that its Windows drivers and software are being exploited by hackers through zero-day attacks, allowing them to escalate privileges and potentially drop ransomware on affected machines. The company patched five flaws in a kernel-level driver for Paragon Partition Manager, which were apparently found in BioNTdrv.sys, a piece of software used by the partition manager. Users are urged to apply updates as soon as possible to secure their systems.

Deepfakes Scam YouTube Creators with AI-Generated Videos Δ1.70

YouTube creators have been targeted by scammers using AI-generated deepfake videos to trick them into giving up their login details. The fake videos, including one impersonating CEO Neal Mohan, claim there's a change in the site's monetization policy and urge recipients to click on links that lead to phishing pages designed to steal user credentials. YouTube has warned users about these scams, advising them not to click on unsolicited links or provide sensitive information.

Inside Look at Meta's Dark Side to Be Revealed in Memoir Δ1.70

A former Meta executive is set to publish a memoir detailing her experiences at the social media giant over seven critical years. The book, titled "Careless People," promises an insider's account of the company's inner workings, including its dealings with China and efforts to combat hate speech. The author's criticisms of Meta's leadership may have implications for Zuckerberg's legacy and the direction of the company.

Panama to Request Legal, Financial Documents on CK Hutchison-BlackRock Port Deal Δ1.70

The Panama Maritime Authority will analyze the key transaction between CK Hutchison and a consortium backed by BlackRock to ensure protection of public interest in two ports strategically located near the Panama Canal. The deal has raised concerns about China's influence in the region amid pressure from U.S. President Donald Trump. The Panamanian government aims to safeguard the interests of its citizens amidst the changing ownership landscape.

Fired US Government Workers with Top Security Clearances Were Not Given Exit Briefings Δ1.70

Recent mass layoffs at Elon Musk's Department of Government Efficiency have resulted in some U.S. government workers with top security clearances not receiving standard exit briefings, raising significant security concerns. Typically, these briefings remind employees of their non-disclosure agreements and provide guidance on handling potential foreign approaches, which is critical given their access to sensitive information. The absence of these debriefings creates vulnerabilities, particularly as foreign adversaries actively seek to exploit gaps in security protocols.

Private API Keys and Passwords Found in AI Training Dataset - Nearly 12,000 Details Leaked Δ1.70

Truffle Security found thousands of pieces of private info in Common Crawl dataset.Common Crawl is a nonprofit organization that provides a freely accessible archive of web data, collected through large-scale web crawling. The researchers notified the vendors and helped fix the problemCybersecurity researchers have uncovered thousands of login credentials and other secrets in the Common Crawl dataset, compromising the security of various popular services like AWS, MailChimp, and WalkScore.

Finland to Release Oil Tanker Suspected of Power Cable Breach Δ1.70

Finland will release an oil tanker suspected of breaking a Baltic Sea power cable and four internet lines late last year, and will escort the vessel to international waters even as the investigation continues. The Cook Islands-registered Eagle S was boarded by Finland's coast guard on December 26 and has been held in custody while authorities probed the case, which remains under investigation on suspicion of sabotage. Three crew members remain subject to a travel ban and are not allowed to leave Finland.