Happy 14th Birthday, KrebsOnSecurity!

Nor do I wish to hold forth about whatever cyber horrors may await us in 2024.
I do want to thank you all for your continued readership, encouragement and support, without which I could not do what I do.
As of this birthday, I've officially been an independent investigative journalist for longer than I was a reporter for The Washington Post.
Of course, not if you count the many years I worked as a paperboy schlepping The Washington Post to dozens of homes in Springfield, Va. True story: At the time I was hired as a lowly copy aide by The Washington Post, all new hires - everyone from the mailroom and janitors on up to the executives - were invited to a formal dinner in the Executive Suite with the publisher Don Graham.
On the evening of my new hires dinner, I was feeling underdressed, undershowered and out of place.
After wolfing down some food, I tried to slink away to the elevator with another copy aide, but was pulled aside by the guy who hired me.
I was 23 years old, and I had no clue what to say except to tell him that paper route story, and that I'd already been working for him for half my life.
Mr. Graham laughed and told me that was the best thing he'd heard all day.
Which of course made my week, and made me feel more at ease among the suits.
I remain grateful to WaPo for instilling many skills, such as how to distill technobabble into plain English for a general audience.
How to make people the focus of highly technical stories.
Because people - and their eternal struggles - are imminently relatable, regardless of whether one has a full grasp of the technical details.
Words fail me when trying to describe how grateful I am that this whole independent reporter thing still works, financially and otherwise.
I mostly just keep my head down researching stuff and sharing what I find, and somehow loads of people keep coming back to the site.
Another milestone of sorts: We've now amassed more than 52,000 subscribers to our email newsletter, which is a fancy term for a plain text email that goes out immediately whenever a new story is published here.
Subscribing is free, we never share anyone's email address, and we don't send emails other than new story notifications.
A friendly reminder that while you may see ads at the top of this website, all two-dozen or so ad creatives we run are vetted by me and served in-house.
Our advertising partners are how we keep the lights on over here.
In case you missed any of them, here are some of the most-read stories published by KrebsOnSecurity in 2023.


This Cyber News was published on krebsonsecurity.com. Publication date: Fri, 29 Dec 2023 22:25:25 +0000


Cyber News related to Happy 14th Birthday, KrebsOnSecurity!

Happy 14th Birthday, KrebsOnSecurity! - Nor do I wish to hold forth about whatever cyber horrors may await us in 2024. I do want to thank you all for your continued readership, encouragement and support, without which I could not do what I do. As of this birthday, I've officially been an ...
1 year ago Krebsonsecurity.com
Happy DOM Vulnerability: What You Need to Know - The Happy DOM vulnerability is a critical security flaw affecting web applications that utilize the DOM (Document Object Model) extensively. This vulnerability allows attackers to manipulate the DOM in ways that can lead to cross-site scripting (XSS) ...
1 month ago Cybersecuritynews.com
ID Theft Service Resold Access to USInfoSearch Data - One of the cybercrime underground's more active sellers of Social Security numbers, background and credit reports has been pulling data from hacked accounts at the U.S. consumer data broker USinfoSearch, KrebsOnSecurity has learned. Since at least ...
1 year ago Krebsonsecurity.com Hunters
Ten Years Later, New Clues in the Target Breach - On Dec. 18, 2013, KrebsOnSecurity broke the news that U.S. retail giant Target was battling a wide-ranging computer intrusion that compromised more than 40 million customer payment cards over the previous month. Ten years later, KrebsOnSecurity has ...
1 year ago Krebsonsecurity.com
Who is the DOGE and X Technician Branden Spikes? – Krebs on Security - Branden Spikes California Russian Association Congress of Russian Americans Constellation of Humanity Cyberinc Department of Government Efficiency Diana Fishman Donald J. Prior to founding Spikes Security, Branden Spikes was married to a native ...
8 months ago Krebsonsecurity.com
Whistleblower: DOGE Siphoned NLRB Case Data – Krebs on Security - “Our acting chief information officer told us not to adhere to standard operating procedure with the DOGE account creation, and there was to be no logs or records made of the accounts created for DOGE employees, who required the highest level ...
6 months ago Krebsonsecurity.com
Juniper Support Portal Exposed Customer Device Info - Until earlier this week, the support website for networking equipment vendor Juniper Networks was exposing potentially sensitive information tied to customer products, including which devices customers bought, as well as each product's warranty ...
1 year ago Krebsonsecurity.com
CEO of Data Privacy Company Onerep.com Founded Dozens of People-Search Firms - The data privacy company Onerep.com bills itself as a Virginia-based service for helping people remove their personal information from almost 200 people-search websites. An investigation into the history of onerep.com finds this company is operating ...
1 year ago Krebsonsecurity.com
Chinese Hackers Attacking Windows Systems in Targeted Campaign to Deploy Ghost RAT and PhantomNet Malwares - Threat researchers are warning of twin Chinese-nexus espionage operations—“Operation Chat” and “Operation PhantomPrayers”—that erupted in the weeks preceding the Dalai Lama’s 90th birthday, exploiting heightened traffic to ...
3 months ago Cybersecuritynews.com
Happy 34th Birthday, Linux! - Linux, the open-source operating system kernel, celebrates its 34th anniversary, marking over three decades of innovation and impact in the tech world. Since its inception by Linus Torvalds in 1990, Linux has grown from a hobby project to a ...
2 months ago Cybersecuritynews.com
CVE-2024-51757 - happy-dom is a JavaScript implementation of a web browser without its graphical user interface. Versions of happy-dom prior to 15.10.2 may execute code on the host via a script tag. This would execute code in the user context of happy-dom. Users are ...
1 year ago Tenable.com
CVE-2025-49372 - Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Remote Code Inclusion.This issue affects HAPPY: from n/a through <= 1.0.7. ...
1 week ago
Arrests in $400M SIM-Swap Tied to Heist at FTX? - Three Americans were charged this week with stealing more than $400 million in a November 2022 SIM-swapping attack. The U.S. government did not name the victim organization, but there is every indication that the money was stolen from the now-defunct ...
1 year ago Krebsonsecurity.com Scattered Spider
Treasury Sanctions Creators of 911 S5 Proxy Botnet - The U.S. Department of the Treasury today unveiled sanctions against three Chinese nationals for allegedly operating 911 S5, an online anonymity service that for many years was the easiest and cheapest way to route one's Web traffic through ...
1 year ago Krebsonsecurity.com
When Getting Phished Puts You in Mortal Danger – Krebs on Security - In August 2024, security researcher Artem Tamoian posted on Twitter/X about how he received startlingly different results when he searched for “Freedom of Russia legion” in Russia’s largest domestic search engine Yandex versus ...
7 months ago Krebsonsecurity.com
xAI Dev Leaks API Key for Private SpaceX, Tesla LLMs – Krebs on Security - An employee at Elon Musk’s artificial intelligence company xAI leaked a private key on GitHub that for the past two months could have allowed anyone to query private xAI large language models (LLMs) which appear to have been custom made for ...
6 months ago Krebsonsecurity.com
CVE-2016-2183 - The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a ...
2 years ago
CVE-2013-6241 - The Birthday widget in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev25 and 7.4.x before 7.4.0-rev14, in certain user-id sharing scenarios, does not properly construct a SQL statement for next-year birthdays, which allows remote ...
10 years ago
CVE-2021-24292 - The Happy Addons for Elementor WordPress plugin before 2.24.0, Happy Addons Pro for Elementor WordPress plugin before 1.17.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as ...
4 years ago
CVE-2023-41236 - Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Happy addons Happy Elementor Addons Pro plugin < 2.8.0 versions. ...
2 years ago
CVE-2023-51676 - Server-Side Request Forgery (SSRF) vulnerability in Leevio Happy Addons for Elementor.This issue affects Happy Addons for Elementor: from n/a through 3.9.1.1. ...
1 year ago
CVE-2023-6632 - The Happy Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via DOM in all versions up to and including 3.9.1.1 (versions up to 2.9.1.1 in Happy Addons for Elementor Pro) due to insufficient input sanitization ...
1 year ago Tenable.com
CVE-2024-29108 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leevio Happy Addons for Elementor allows Stored XSS.This issue affects Happy Addons for Elementor: from n/a through 3.10.1. ...
1 year ago Tenable.com
CVE-2024-32698 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leevio Happy Addons for Elementor allows Stored XSS.This issue affects Happy Addons for Elementor: from n/a through 3.10.4. ...
1 year ago
CVE-2024-24833 - Missing Authorization vulnerability in Leevio Happy Addons for Elementor.This issue affects Happy Addons for Elementor: from n/a through 3.10.1. ...
1 year ago

Cyber Trends (last 7 days)