Scattered Spider key figure pleads guilty to hacking and crypto theft
Tyler Buchanan and his co-conspirators targeted at least a dozen companies and stole at least $8 million from victims across the US.
The attacker posed as an external IT support worker using a fake Microsoft 365 domain designed to appear legitimate.
Tyler Buchanan and his co-conspirators targeted at least a dozen companies and stole at least $8 million from victims across the US.
More recent incidents show a shift toward social engineering and alternative entry points.
Attackers are exploiting a known vulnerability (CVE-2024-3721) affecting TBK DVR-4104 and DVR-4216 devices.
In brief: Microsoft and Adobe fix zero-days, the Russian Grinex crypto exchange hacked for 1 billion rubles, and more.
CERT-UA believes the attacks may also target individuals connected to Ukraineu2019s Defense Forces
Once inside a system, the malware targets cloud metadata services to extract temporary credentials.