CyberWire Daily: Lumma Takedown, GoDaddy Settlement, AI Bot Attacks, and Crypto Scams
N2K NetworksMay 22, 202527 min387 views
24 connectionsΒ·40 entities in this videoβMajor Cyber Operations and Settlements
- π‘ A joint US, EU, and Japanese operation, with Microsoft's help, has dismantled the infrastructure of Lumma, a major info-stealer malware that infected millions and stole sensitive data.
- π― The FTC has finalized a security settlement with GoDaddy, requiring them to implement stronger protections like MFA and regular security assessments after years of data breaches.
- β οΈ A breach of Telemessage, a government-used messaging service, compromised messages from over 60 US officials, raising metadata counterintelligence risks.
- π΅οΈ Twin hackers, hired as engineers despite past convictions, allegedly breached OPEXis, a software provider for nearly all US federal agencies, causing significant data loss.
Telecom and Printer Vulnerabilities
- π US telecom providers AT&T, Verizon, and T-Mobile failed to notify the Senate when law enforcement requested data from Senate-issued devices, though they have since begun complying for Senate-funded lines.
- π¨οΈ Lexmark disclosed a critical vulnerability affecting over 120 printer models, allowing remote attackers to execute arbitrary code and compromise printers.
AI in Bot Attacks and Evasion Tactics
- π€ The number of accessible AI tools has lowered the barrier for cyber attackers, making it easier to create malicious bots.
- π Malicious automation surpassed human-generated traffic for the first time, with AI being used by both simple and advanced attackers.
- π Attackers constantly retool their methods to evade detection, making it a daily grind for defenders to identify and block bot fingerprints.
- π APIs are increasingly being exploited by advanced bots, with about half of advanced malicious automation specifically targeting them due to easier machine-to-machine attacks and potentially weaker defenses.
Emerging Threats and Recommendations
- π Dragon Force, a ransomware group, is reshaping the threat landscape with aggressive tactics, rebranding as a cartel and potentially attempting hostile takeovers of rival infrastructure.
- π» A cyber attack on the UK's legal aid agency exposed sensitive data of over 2 million people, including domestic abuse survivors, raising fears of imminent leaks.
- π Recommendations for defense include implementing risk identification, understanding asset value, continuous monitoring, and using automation as a defense against automated attacks.
- π° Scammers are using increasingly creative methods, such as smuggling stolen cash in Squishmallows, as seen in a $250 million crypto fraud takedown.
Expert Insights on Bot Attacks
- π£οΈ David Holmes, CTO for Application Security at Imperva, discusses the 2025 Bad Bot Report, highlighting that malicious automation now constitutes a significant portion of internet traffic.
- π― He emphasizes that AI is lowering the barrier for attackers and refining their attacks, leading to a split between simple and advanced bot sophistication.
- π Holmes advises evolving API security and implementing risk identification and automation for defense against these persistent threats.
Knowledge graph40 entities Β· 24 connections
How they connect
An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.
Hover Β· drag to explore
40 entities
Chapters9 moments
Key Moments
Transcript97 segments
Full Transcript
Topics20 themes
Whatβs Discussed
LummaInfoStealer MalwareFTCGoDaddyTelemessageSignalOPEXisCybersecurityUS Telecom ProvidersLexmarkAIBot AttacksAPI SecurityDragon ForceRansomwareUK Legal Aid AgencyData BreachCrypto ScamsImpervaDavid Holmes
Smart Objects40 Β· 24 links
PeopleΒ· 9
CompaniesΒ· 15
ProductsΒ· 4
MediasΒ· 3
ConceptsΒ· 8
EventΒ· 1