Skip to main content

CyberWire Daily: Lumma Takedown, GoDaddy Settlement, AI Bot Attacks, and Crypto Scams

N2K NetworksMay 22, 202527 min387 views
24 connections·40 entities in this video→

Major Cyber Operations and Settlements

  • πŸ’‘ A joint US, EU, and Japanese operation, with Microsoft's help, has dismantled the infrastructure of Lumma, a major info-stealer malware that infected millions and stole sensitive data.
  • 🎯 The FTC has finalized a security settlement with GoDaddy, requiring them to implement stronger protections like MFA and regular security assessments after years of data breaches.
  • ⚠️ A breach of Telemessage, a government-used messaging service, compromised messages from over 60 US officials, raising metadata counterintelligence risks.
  • πŸ•΅οΈ Twin hackers, hired as engineers despite past convictions, allegedly breached OPEXis, a software provider for nearly all US federal agencies, causing significant data loss.

Telecom and Printer Vulnerabilities

  • πŸ“ž US telecom providers AT&T, Verizon, and T-Mobile failed to notify the Senate when law enforcement requested data from Senate-issued devices, though they have since begun complying for Senate-funded lines.
  • πŸ–¨οΈ Lexmark disclosed a critical vulnerability affecting over 120 printer models, allowing remote attackers to execute arbitrary code and compromise printers.

AI in Bot Attacks and Evasion Tactics

  • πŸ€– The number of accessible AI tools has lowered the barrier for cyber attackers, making it easier to create malicious bots.
  • πŸ“ˆ Malicious automation surpassed human-generated traffic for the first time, with AI being used by both simple and advanced attackers.
  • πŸ”„ Attackers constantly retool their methods to evade detection, making it a daily grind for defenders to identify and block bot fingerprints.
  • 🌐 APIs are increasingly being exploited by advanced bots, with about half of advanced malicious automation specifically targeting them due to easier machine-to-machine attacks and potentially weaker defenses.

Emerging Threats and Recommendations

  • πŸš€ Dragon Force, a ransomware group, is reshaping the threat landscape with aggressive tactics, rebranding as a cartel and potentially attempting hostile takeovers of rival infrastructure.
  • πŸ’» A cyber attack on the UK's legal aid agency exposed sensitive data of over 2 million people, including domestic abuse survivors, raising fears of imminent leaks.
  • πŸ“Š Recommendations for defense include implementing risk identification, understanding asset value, continuous monitoring, and using automation as a defense against automated attacks.
  • πŸ’° Scammers are using increasingly creative methods, such as smuggling stolen cash in Squishmallows, as seen in a $250 million crypto fraud takedown.

Expert Insights on Bot Attacks

  • πŸ—£οΈ David Holmes, CTO for Application Security at Imperva, discusses the 2025 Bad Bot Report, highlighting that malicious automation now constitutes a significant portion of internet traffic.
  • 🎯 He emphasizes that AI is lowering the barrier for attackers and refining their attacks, leading to a split between simple and advanced bot sophistication.
  • πŸ”’ Holmes advises evolving API security and implementing risk identification and automation for defense against these persistent threats.
Knowledge graph40 entities Β· 24 connections

How they connect

An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.

Hover Β· drag to explore
40 entities
Chapters9 moments

Key Moments

Transcript97 segments

Full Transcript

Topics20 themes

What’s Discussed

LummaInfoStealer MalwareFTCGoDaddyTelemessageSignalOPEXisCybersecurityUS Telecom ProvidersLexmarkAIBot AttacksAPI SecurityDragon ForceRansomwareUK Legal Aid AgencyData BreachCrypto ScamsImpervaDavid Holmes
Smart Objects40 Β· 24 links
PeopleΒ· 9
CompaniesΒ· 15
ProductsΒ· 4
MediasΒ· 3
ConceptsΒ· 8
EventΒ· 1