‘Starkiller’ Phishing Service Proxies Real Login Pages, MFA

• Starkiller is a new phishing-as-a-service offering that dynamically loads real login pages and relays user inputs and MFA credentials. • The service allows for real-time session monitoring, keylogging, and automated alerts, effectively bypassing traditional security measures.
Source

Kimwolf Botnet Swamps Anonymity Network I2P

- Kimwolf botnet disrupted the I2P network by overwhelming it with infected routers. - The disruption was caused by a Sybil attack, where the botnet tried to join 700,000 nodes on I2P. - I2P is a decentralized, privacy-focused communications network.
Source

Patch Tuesday, February 2026 Edition

Microsoft released critical updates for Windows operating systems and other software, addressing six zero-day vulnerabilities. These include security feature bypasses in various components like Windows Shell, MSHTML, Microsoft Word, Remote Desktop Services, DWM, and a denial-of-service vulnerability in the Windows Remote Access Connection Manager.
Source

Please Don’t Feed the Scattered Lapsus ShinyHunters

- Scattered Lapsus ShinyHunters (SLSH) uses a unique playbook involving harassment and threats beyond typical ransom demands. - Engaging with SLSH is discouraged as it may escalate the situation further.
Source

Who Operates the Badbox 2.0 Botnet?

- Kimwolf botmasters compromised the control panel for Badbox 2.0. - The screenshot shows seven authorized users, including one named 'ABCD' who may be Dort. - Badbox 2.0 has a history of infecting Android TV streaming boxes and engaging in advertising fraud.
Source

Kimwolf Botnet Lurking in Corporate, Govt. Networks

The Kimwolf botnet has infected over 2 million devices and can scan local networks for additional targets. It primarily affects residential proxies, especially Android TV streaming boxes, but also compromises corporate and government networks. Infoblox found that nearly 25% of its customers made queries to Kimwolf-related domains.
Source

Patch Tuesday, January 2026 Edition

Microsoft issued critical patches for 113 security holes in Windows and supported software. One of the vulnerabilities (CVE-2026-20805) is actively exploited, targeting ASLR protection mechanisms. Two Microsoft Office bugs with remote code execution are also critical. Legacy modem drivers were removed due to potential elevation of privilege vulnerabilities.
Source

Who Benefited from the Aisuru and Kimwolf Botnets?

The Kimwolf botnet infected over two million devices and was used for DDoS attacks and residential proxy services. The same cybercriminals were responsible for both the Aisuru and Kimwolf botnets, with evidence pointing to Lehi, Utah-based Resi Rack LLC as a key player in the operation.
Source

The Kimwolf Botnet is Stalking Your Local Network

The Kimwolf botnet has infected over 2 million devices globally, with a significant concentration in the United States. The malware spreads through residential proxy networks and unsecured Android TV boxes, posing a serious threat to internal network security. These devices can be compromised by issuing a single command across the...
Source

Happy 16th Birthday, KrebsOnSecurity.com!

KrebsOnSecurity.com celebrated its 16th anniversary in 2025 with a focus on entities involved in cybercrime, including Stark Industries Solutions Ltd., Cryptomus, and Funnull. The article details enforcement actions against these entities by regulatory bodies such as the European Union and Canadian financial regulators.
Source

Dismantling Defenses: Trump 2.0 Cyber Year in Review

The Trump administration has issued several directives and memos aimed at restricting free speech and limiting social media activity. These include NSPM-7, which targets anti-American activities, and a memo from Attorney General Pam Bondi advising the FBI to compile a list of Americans whose activities may constitute domestic terrorism. Additionally,...
Source

Most Parked Domains Now Serving Malicious Content

Most parked domains now redirect visitors to malicious content; redirects often occur via a chain of domains and can be influenced by the visitor's IP address. Visitors using residential IPs are more likely to be redirected to scams, malware, or other unwanted content.
Source

Microsoft Patch Tuesday, December 2025 Edition

- Microsoft released 56 security patches for Windows and supported software in the final Patch Tuesday of 2025, including a zero-day bug. - The vulnerabilities include privilege escalation flaws that are likely to be exploited, as well as remote code execution bugs.
Source

Drones to Diplomas: How Russia’s Largest Private University is Linked to a $25M Essay Mill

The article discusses a large-scale academic cheating network linked to Russia's largest private university. The network uses Google Ads to generate nearly $25 million in revenue and has multiple rebrands to avoid detection. Students can purchase term papers through these services, which claim to offer tutoring but often deliver completed...
Source

SMS Phishers Pivot to Points, Taxes, Fake Retailers

Phishing groups are pivoting from package delivery and toll fee scams to mass-create fake e-commerce websites for mobile wallet conversion. They are also using SMS lures related to unclaimed tax refunds and rewards points. These phishing domains can be hard to detect, especially those mimicking legitimate e-commerce sites.
Source

Meet Rey, the Admin of ‘Scattered Lapsus$ Hunters’

- Rey, the technical operator and public face of Scattered LAPSUS$ Hunters, has confirmed his real-life identity. - The group is known for launching social engineering campaigns and data leak portals, targeting major corporations including Toyota, FedEx, Disney/Hulu, and UPS.
Source

Is Your Android TV Streaming Box Part of a Botnet?

The article discusses the potential risks associated with using Superbox media streaming devices. These devices force users' networks to relay internet traffic, often tied to cybercrime activities such as advertising fraud and account takeovers. The article highlights that while the sale or use of these devices is not illegal, the...
Source

Mozilla Says It’s Finally Done With Two-Faced Onerep

Mozilla will discontinue its partnership with Onerep in December 2025 after ongoing issues related to the founder's involvement in multiple data broker services. Current Monitor Plus subscribers will receive prorated refunds for unused portions of their subscriptions.
Source

The Cloudflare Outage May Be a Security Roadmap

- Security experts recommend organizations review their web application firewall logs during the Cloudflare outage as it may have exposed vulnerabilities. - The outage provides a real-world test of how organizations handle security when primary defenses are bypassed.
Source