Information

This month in security with Tony Anscombe – August 2025 edition

From Meta shutting down millions of WhatsApp accounts linked to scam centers all the way to attacks at water facilities in Europe, August 2025 saw no shortage of impactful cybersecurity news 28 Aug 2025 As August 2025 comes to a close, ESET Chief Security Evangelist Tony Anscombe reviews a selection of the top cybersecurity stories that moved the needle, raised the alarms or offered vital lessons over the past 30 or so days, as well…

Read More

Nevada Confirms Ransomware Attack Behind Statewide Service Disruptions

Nevada on Wednesday confirmed that the days-long disruption to state systems and services was caused by a ransomware attack. The incident, disclosed on Monday morning as a network security incident, occurred on Sunday, and forced Nevada to close all state offices on Monday and Tuesday. During a press conference on Wednesday, the state’s officials publicly confirmed that a “sophisticated ransomware attack” was the cause of the disruptions. “Upon detection, we immediately activated our established cybersecurity…

Read More

Affiliates Flock to ‘Soulless’ Scam Gambling Machine

Last month, KrebsOnSecurity tracked the sudden emergence of hundreds of polished online gaming and wagering websites that lure people with free credits and eventually abscond with any cryptocurrency funds deposited by players. We’ve since learned that these scam gambling sites have proliferated thanks to a new Russian affiliate program called “Gambler Panel” that bills itself as a “soulless project that is made for profit.” A machine-translated version of Gambler Panel’s affiliate website. The scam begins…

Read More

Don’t let “back to school” become “back to (cyber)bullying”

Kids Online Cyberbullying is a fact of life in our digital-centric society, but there are ways to push back Phil Muncaster 27 Aug 2025  •  , 4 min. read For better or worse, the digital world in many ways resembles its physical counterpart. Unfortunately, that means it sometimes enables, and even exacerbates, the same bad behaviors that we often see offline. According to a 2023 Microsoft study covering 17 countries, “cyberbullying harassment and abuse” is…

Read More

First known AI-powered ransomware uncovered by ESET Research

ESET Research The discovery of PromptLock shows how malicious use of AI models could supercharge ransomware and other threats 26 Aug 2025  •  , 2 min. read ESET researchers have discovered what they called “the first known AI-powered ransomware”. The malware, which ESET has named PromptLock, has the ability to exfiltrate, encrypt and possibly even destroy data, though this last functionality appears not to have been implemented in the malware yet. While PromptLock was not…

Read More

DSLRoot, Proxies, and the Threat of ‘Legal Botnets’

The cybersecurity community on Reddit responded in disbelief this month when a self-described Air National Guard member with top secret security clearance began questioning the arrangement they’d made with company called DSLRoot, which was paying $250 a month to plug a pair of laptops into the Redditor’s high-speed Internet connection in the United States. This post examines the history and provenance of DSLRoot, one of the oldest “residential proxy” networks with origins in Russia and…

Read More

Investors beware: AI-powered financial scams swamp social media

Can you tell the difference between legitimate marketing and deepfake scam ads? It’s not always as easy as you may think. Phil Muncaster 18 Aug 2025  •  , 4 min. read As economic uncertainty and persistent inflation are eroding our pay checks and imperilling our pensions, it’s not surprising that many of us are looking to make our money go a bit further. Unfortunately, scammers are preying on this need with increasingly sophisticated schemes on…

Read More

The need for speed: Why organizations are turning to rapid, trustworthy MDR

Business Security How top-tier managed detection and response (MDR) can help organizations stay ahead of increasingly agile and determined adversaries Phil Muncaster 19 Aug 2025  •  , 5 min. read How long does it take for threat actors to move from initial access to lateral movement? Days? Hours? Unfortunately, the answer for many organizations is increasingly “minutes.” In fact, at 48 minutes, the average breakout time in 2024 was 22% shorter than the previous year,…

Read More

“What happens online stays online” and other cyberbullying myths, debunked

Kids Online Separating truth from fiction is the first step towards making better parenting decisions. Let’s puncture some of the most common misconceptions about online harassment. Phil Muncaster 21 Aug 2025  •  , 5 min. read Cyberbullying, unfortunately, is on the rise. Data from the Cyberbullying Research Center reveals that just over 58% of middle- and high-school students in the US have experienced online harassment of some sort in their lives. That’s compared to 37%…

Read More

SIM-Swapper, Scattered Spider Hacker Gets 10 Years

A 20-year-old Florida man at the center of a prolific cybercrime group known as “Scattered Spider” was sentenced to 10 years in federal prison today, and ordered to pay roughly $13 million in restitution to victims. Noah Michael Urban of Palm Coast, Fla. pleaded guilty in April 2025 to charges of wire fraud and conspiracy. Florida prosecutors alleged Urban conspired with others to steal at least $800,000 from five victims via SIM-swapping attacks that diverted…

Read More