Cybercriminals, Drone Dances, and Forgotten Recordings

5

Your phone gets stolen. Not just the theft hurts. The phishing attacks come next. Targeting your friends. Your family. New research confirms it. It’s an entire ecosystem now. Tools exist just to unlock your iPhone. Criminals want your contacts list.

Foxconn admits it got hit. Nitrogen ransomware claims they took 8 TB of data. Foxconn is a huge target. Unavoidable, really. They build iPhones. Where better to look?

Meanwhile. Drones over the US-Canada border. 5G connected. DHS and Canadian researchers test this fall. Battlefield intelligence? Maybe. Just an experiment for now.

Look east. Iran’s Revolutionary Guard blocks the Strait of Hormuz. Small boats. A mosquito fleet. While bombs drop. The route is blocked.

Stay safe out there.

The Teams Incident

Lesson for hackers. Or rogue employees. Close your Microsoft Teams meeting first. Especially if you’re being fired. Especially if you have a twin.

Muneeb and Sohaib Akret. They destroyed 96 government databases. Pleaded guilty. Well, Muneeb pleaded guilty then tried to take it back. Handwritten notes to the judge. Charming.

Their boss, Opexus, fired them. Criminal records came up. Wire fraud. Stealing airline miles? Petty crimes, but real ones. Both 34. Brothers.

The firing meeting was short. Minutes, maybe. The revenge? Hours long. And recorded. The brothers forgot to close the meeting link. So Ars Technica saw the transcript.

Sohaib asked his brother, still in the house: “Still connected? Still on the VPN? Delete all their databases?”

Muneeb’s reply was honest.

“We are doing petty shit now.”

Ransomware Deals

Instructure has a deal. With the hackers. The gang is ShinyHunters. They broke into Canvas. Thousands of US schools affected. Ransom messages popped up everywhere.

Instructure says data was returned. 275 million student records? Supposedly destroyed by the hackers. No more extortion. At least that’s what they claim.

Did Instructure pay? They won’t say how much. Or if at all.

Glad it’s settled. Until the next massive disruption. Which comes quickly. Because money talks.

Dark Web Closures

Dream Market is gone. But its boss was found. In Germany. Owe Martin Andresen arrested at his home.

He ran the biggest dark web drug site ever. Until 2019. Before the raids. Seven years later, they caught him.

He made millions. From commissions. Laundered through gold bars? Bought from a company in Atlanta. The original Silk Road bust happened in 2013. Same year Dream started.

Andresen might close the book. On the longest investigation ever. Maybe.

OpenAI Supply Chain Hit

Two employees got hit. At OpenAI. Supply chain attack. Target: TanStack. An open-source library. Very popular.

Hackers wanted credentials. Not user data. Yet. OpenAI saw unauthorized access in code repositories. Just internal stuff. No production systems breached.

Update your app by June 12 if you’re on macOS.

BleepingComputer details it. Git credentials gone. SSH keys. Claude Code configs. Private data stolen from developers everywhere. Not just AI folks.

The Opt-Out Hideaway

Findem. A data broker. Hated its own opt-out page.

For three years, they hid it from Google. Using a “no index” tag. A former employee did it? That’s their excuse now. Executives claimed ignorance.

Now fixed? Tell me why I should trust that.