Mastodon Digest
for the past
scorer
threshold
Posts

🚨 Teenagers suspected of leading ransomware group arrested in international operation

Authorities from nine countries have disrupted KillSec, a ransomware group linked to almost 1,000 attacks worldwide.
β €
A 16-year-old is suspected of serving as the group’s administrator and main operator.

Another suspected developer recently turned 18 and was a minor during several of the alleged offenses.
β €
The operation resulted in:

β€’ Three arrests
β€’ Eight searches in Spain, Greece, the UK and Romania
β€’ Five servers seized
β€’ KillSec-operated domains seized
β€’ At least 110 TB of stolen data secured
β €
KillSec allegedly exploited poorly secured access points, particularly cloud storage, to steal sensitive data.

Victims were threatened with publication unless they paid a ransom.

The investigation remains ongoing.

Source: eurojust.europa.eu/news/teenag

Well done to Microsoft for having two different mobile apps called Copilot which do different things.

RE: infosec.exchange/@BleepingComp

Big ransomware group ran by a *checks notes* 16 year old teen.

Went thru a Dunkin drive-through today and couldn't scrounge enough change to pay for a coffee in cash and felt like an ass for a second. When I handed over my credit card, the lady at the payment window handed me the payment terminal and told me how to operate it, saying select your tip amount and then hit pay. I was floored.

IDK if this is Dunkin policy, but if it is that's abhorrent and embarrassing for everyone involved. Not just because I'm getting sick of everyone expecting a tip for everything, but because companies apparently encourage this kind of crap instead of paying a living wage.

This weekend, was at a Giant near the beach and only one lane was open but they had about 12 self-checkouts, and all of them had people who were clearly very confused about using these machines, and almost all of them had "assistance requested" yellow blinking lights above their registers. After watching this for a few minutes, the guy behind me goes, "I'm not sure they're getting the efficiency gains they expect with this whole self checkout thing." I replied, well, it's hard. You see, they have to train each customer how to do a job that was once done by employees.

Boosts

New hardcoded credential CVE!
CVE-2026-13043 - cve.org/CVERecord?id=CVE-2026-
WatchGuard - Endpoint Security
A missing authentication vulnerability in the Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products allows a local, authenticated attacker to bypass the driver's access-control handshake and issue arbitrary privileged commands to the driver, resulting in disclosure of kernel and process memory.