Coinbase’s insider breach is a reminder that our biggest risks sit inside the tools we trust most. One contractor overpowered support access & customer data on Telegram. 🔗 https://zurl.co/vsIJh #InsiderThreats #CyberSecurity #Coinbase #SaaS #vCISO #ZeroTrust #ThirdPartyRisk
Coinbase confirms insider breach linked to leaked support tool screenshots

Coinbase has confirmed an insider breach after a contractor improperly accessed the data of approximately thirty customers, which BleepingComputer has learned is a new incident that occurred in December.

BleepingComputer

✅ Data Security Plus centralises your platform to discover, classify, and protect sensitive data. By monitoring user behaviour, generating detailed audit reports, sending risk-based alerts, and proactively detecting threats, your team can stay ahead of risks and keep data secure — all from one platform. 

#ManageEngine #DataSecurityPlus #DataSecurity #CyberSecurity #InfoSec #DataProtection #InsiderThreats #Compliance #AuditReports #RiskManagement #SecureWorkplace #BusinessSafety

Aurora Johnson, Manager of Security Research & Partnerships at SpyCloud, on why ransomware relies on ecosystems - not lone actors.

“Corrupt insiders are monetizing privileged access for personal profit.”

https://www.technadu.com/facing-hardened-defenses-vs-easy-incentives-why-insider-abuse-is-becoming-commonplace-in-ransomware-operations/617348/

#InsiderThreats #ThreatIntel #Ransomware #IdentitySecurity

Seoul’s cyber investigation unit has raided Coupang’s HQ after the company disclosed a breach affecting 33.7M users.

Authorities suggest a former employee with privileged access obtained a private encryption key and generated forged customer tokens.
Digital evidence seized during the raid is expected to clarify the breach’s full method and scope.

The situation highlights ongoing debates in South Korea about corporate accountability, insider risk management, and security governance.

Source: https://therecord.media/seoul-cyber-investigators-seize-data-korea-tech-giant

What controls matter most for preventing privileged-access misuse?

Follow us for more insights.

#CyberSecurity #DataBreach #Coupang #InsiderThreats #DigitalForensics #InfoSec #RiskManagement #SouthKorea #TechNadu

Weekly Cyber: AI misuse, darknet takedowns, hypervisor intrusions & insider access headline the week

https://www.technadu.com/shifting-threats-and-tension-between-offense-and-defense/615252/

• DMSoldiersNDD operator jailed
• 33M impacted in Coupang breach
• Cryptomixer seized (€25M)
• WARP PANDA ESXi/vCenter intrusion
• €700M fraud network dismantled
• Gov DBs wiped by contractors
• FAA contractor insider threat
• Discord child-exploitation ring busted
• Poetic prompts bypass AI guardrails

#CyberSecurity #ThreatIntel #WeeklyCyber #CloudSecurity #AIJailbreak #DarkWeb #InsiderThreats

Insider threats aren’t theoretical anymore—they’re happening inside organizations just like yours.

This week on Cyberside Chats, Sherri and Matt break down major insider cases—from the new CrowdStrike leak and DigitalMint ransomware indictments to Tesla’s multi-year insider problems, and the crackdown on North Korean operatives using stolen identities to get hired.

Attackers are buying, recruiting, and embedding insiders faster than organizations are adapting their defenses.

Watch this week’s full episode for actionable strategies to reduce your organization’s risk.

Watch: https://youtu.be/s7QW_BkkAvM

Listen: https://www.chatcyberside.com/e/when-security-fails-crowdstrike-insider-leaks-and-the-threat-within/?token=80d65859eee83d3963239e2310e4d035

#Ransomware #InsiderThreats #Cybersecurity #CrowdStrike #DigitalMint #Tesla #Cyberaware #Infosec

Insider threats are a real enterprise risk—ask CrowdStrike, who recently caught an employee leaking screenshots to hackers. Even top cybersecurity firms aren’t immune. #InsiderThreats #Cybersecurity #RiskManagement 🔗 Read more - https://zurl.co/BjGvs
CrowdStrike catches insider feeding information to hackers

American cybersecurity firm CrowdStrike has confirmed that an insider shared screenshots taken on internal systems with hackers after they were leaked on Telegram by the Scattered Lapsus$ Hunters threat actors.

BleepingComputer

We cannot abandon "innocent until proven guilty" but, if proven, to these allegations are yet another concerning example of the insider threat. Whether child abuse, fraud, corporate or government espionage, etc., the insider, the one with you behind the fortress walls, is almost always the most dangerous.

https://www.bleepingcomputer.com/news/security/us-cybersecurity-experts-indicted-for-blackcat-ransomware-attacks/

#security #technology #cybersecurity #insiderthreats

US cybersecurity experts indicted for BlackCat ransomware attacks

Three former employees of cybersecurity incident response companies DigitalMint and Sygnia have been indicted for allegedly hacking the networks of five U.S. companies in BlackCat (ALPHV) ransomware attacks between May 2023 and November 2023.

BleepingComputer

When the very experts trusted to protect our digital world cross a dangerous line. The shocking BlackCat case forces us to ask: How did guardians become the threat?

https://thedefendopsdiaries.com/ethics-on-the-edge-the-blackcat-ransomware-case-and-the-responsibilities-of-cybersecurity-professionals/

#blackcatransomware
#cybersecurityethics
#insiderthreats
#ransomwareattacks
#ethicalhacking

Aanvallen op Bagnoles (NL) en gas- en waterbedrijven illustreren groeiende digitale kwetsbaarheid

YouTube