NEW: Google has filed a lawsuit against an alleged AI-powered massive cybercrime operation it calls Outsider Enterprise.
The operation sent 2.5 million scam texts to Android users in a two week period, according to Google.
Real-time cyber historian of the late capitalist era @TechCrunch, writing about the intersection of hackers, human rights, and spies.
Also writing a book about Hacking Team and the history of government spyware.
Posts about infosec, surveillance by day. 🍕, ⚽️, 🎸, 🎮 by night.
☎️ Signal: +1 917 257 1382
💻 Keybase/Telegram: @ lorenzofb
✉️ [email protected]
Previously: VICE Motherboard, Mashable, WIRED's Danger Room.
| https://twitter.com/lorenzofb | |
| Personal Site | https://lorenzofb.com |
| Pronouns | He/him |
| Searchable via | tootfinder |
| TechCrunch | https://techcrunch.com/author/lorenzo-franceschi-bicchierai/ |
I just updated this story with details from Google's lawsuit complaint, which included a lot of fascinating details on how the operation worked behind the scenes.
Court document here: https://www.documentcloud.org/documents/28239704-google-v-outsider-enterprise-complaint/
NEW: Google has filed a lawsuit against an alleged AI-powered massive cybercrime operation it calls Outsider Enterprise.
The operation sent 2.5 million scam texts to Android users in a two week period, according to Google.
NEW: Oracle is warning customers of an unpatched bug in its PeopleSoft software, which Google says is the flaw that the cybercrime group ShinyHunters is exploiting in its latest mass hacking campaign.
Google said it notified more than 100 organizations worldwide that they had exposed and vulnerable PeopleSoft servers, most of them colleges and universities.

The tech giant warned of a security flaw that a cybercrime gang said it's exploiting as part of a mass-hacking campaign. Google said it notified more than 100 organizations that had potentially vulnerable servers.
NEW: Oracle is warning customers of an unpatched bug in its PeopleSoft software, which Google says is the flaw that the cybercrime group ShinyHunters is exploiting in its latest mass hacking campaign.
Google said it notified more than 100 organizations worldwide that they had exposed and vulnerable PeopleSoft servers, most of them colleges and universities.

The tech giant warned of a security flaw that a cybercrime gang said it's exploiting as part of a mass-hacking campaign. Google said it notified more than 100 organizations that had potentially vulnerable servers.
NEW: Cybercrime group ShinyHunters claimed to have hacked into more than 100 organizations' Oracle PeopleSoft servers, including several universities.
The hackers said they stole student data, including home addresses, phone numbers, emails, and dates of birth.
NEW: Cybersecurity researchers are not happy about the guardrails on Anthropic’s new model Fable.
Researchers say that the new LLM basically blocks anything related to cybersecurity, including code reviews and prompts asking for help writing secure code.
“[Fable] rejects any request that could be tangentially cyber related. Even innocuous tasks like reading a blog post,” said one researcher.
New, by me: ServiceNow appears to have notified some enterprise customers that there was outside access to their data, after a security bug left instances exposed to the web.
The company has hidden its notice behind a login wall, but was shared by network defenders on Reddit.
NEW: WhatsApp said it caught and disrupted a new hacking campaign by NSO Group against its users.
The Meta-owned messaging giant said this phishing campaign violates a court decision that ordered NSO to stop targeting WhatsApp and its users. WhatsApp is seeking to hold NSO in contempt of court because of this violation.
NEW: A former cybersecurity executive turned whistleblower accused IBM of getting breached three times and trying to cover up the hacks.
IBM was “routinely hacked by foreign state actors and others,” and data was frequently stolen and government agencies were “never notified,” he said in a lawsuit.

IBM and two of its subsidiary companies were allegedly breached during the mid-2010s — a lawsuit filed by a former cybersecurity executive accuses IBM of not disclosing and actively covering it up.