home.social

#insiderthreat — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #insiderthreat, aggregated by home.social.

fetched live
  1. Cameron Wagenius, aka Kiberphant0m, was sentenced to 70 months for hacking US telecoms and extorting victims with stolen data, including AT&T metadata for 100M+ customers. The case shows how bulk call and text metadata enables large-scale extortion and underscores insider threat risk. #TelecomSecurity #DataBreach #InsiderThreat

    cyberworldops.eu/en/army-soldi

  2. Cameron Wagenius, aka Kiberphant0m, was sentenced to 70 months for hacking US telecoms and extorting victims with stolen data, including AT&T metadata for 100M+ customers. The case shows how bulk call and text metadata enables large-scale extortion and underscores insider threat risk. #TelecomSecurity #DataBreach #InsiderThreat

    cyberworldops.eu/en/army-soldi

  3. Cameron Wagenius, aka Kiberphant0m, was sentenced to 70 months for hacking US telecoms and extorting victims with stolen data, including AT&T metadata for 100M+ customers. The case shows how bulk call and text metadata enables large-scale extortion and underscores insider threat risk. #TelecomSecurity #DataBreach #InsiderThreat

    cyberworldops.eu/en/army-soldi

  4. AI Agents Emerge as New Insider Threat Vector

    Get ready for a new frontier in cyber threats: AI agents are emerging as a prime target for hackers, with experts warning that attacks against these autonomous agents will become the next big threat vector. As AI agents gain access to sensitive data, organizations are essentially handing hackers the keys to the kingdom.

    osintsights.com/ai-agents-emer

    #AiAgents #InsiderThreat #EmergingThreats #ArtificialIntelligence #NextgenThreats

  5. CISA Revamps Insider Threat Guide with Expanded Mitigation Advice

    Stay ahead of insider threats with the latest guidance from CISA's revised Insider Threat Mitigation Guide, your go-to playbook for protecting your organization from evolving security risks. The updated guide offers practical advice on tackling emerging challenges like hybrid work, AI, and more.

    osintsights.com/cisa-revamps-i

    #InsiderThreat #InsiderThreatMitigation #Cisa #GuideRevision #HybridWork

  6. Lax Access Controls Enable Ex-Employee to Inflict Hundreds of Thousands in Damages

    A single misstep in access control can have devastating consequences: one terminated employee's lingering credentials led to hundreds of thousands of dollars in damages, including data deletion, system lockdowns, and a corrupted database. The breach not only racked up costly recovery fees but…

    osintsights.com/lax-access-con

    #AccessControlFailure #InsiderThreat #IdentityManagement #DataCorruption #ProjectManagement

  7. Un ex-dipendente Apple accusato di aver sottratto dati su un progetto segreto con OpenAI — e il MacBook aziendale avrebbe lasciato tracce nei log. Un promemoria concreto: i dispositivi corporate registrano molto più di quanto si pensi. La surface d'attacco insider passa spesso per gli strumenti più ordinari. #infosec #insiderthreat #Apple
    spider-mac.com/2026/09/01/appl

  8. Un ex-dipendente Apple accusato di aver sottratto dati su un progetto segreto con OpenAI — e il MacBook aziendale avrebbe lasciato tracce nei log. Un promemoria concreto: i dispositivi corporate registrano molto più di quanto si pensi. La surface d'attacco insider passa spesso per gli strumenti più ordinari. #infosec #insiderthreat #Apple
    spider-mac.com/2026/09/01/appl

  9. Un ex-dipendente Apple accusato di aver sottratto dati su un progetto segreto con OpenAI — e il MacBook aziendale avrebbe lasciato tracce nei log. Un promemoria concreto: i dispositivi corporate registrano molto più di quanto si pensi. La surface d'attacco insider passa spesso per gli strumenti più ordinari. #infosec #insiderthreat #Apple
    spider-mac.com/2026/09/01/appl

  10. Un ex-dipendente Apple accusato di aver sottratto dati su un progetto segreto con OpenAI — e il MacBook aziendale avrebbe lasciato tracce nei log. Un promemoria concreto: i dispositivi corporate registrano molto più di quanto si pensi. La surface d'attacco insider passa spesso per gli strumenti più ordinari. #infosec #insiderthreat #Apple
    spider-mac.com/2026/09/01/appl

  11. DIA Insider Pleads Guilty to Leaking Secrets to Foreign Spies

    A DIA insider has pleaded guilty to leaking classified information to foreign spies, admitting to betraying his oath and putting national security at risk. The shocking case began with a single email in March 2025, sparking a months-long undercover operation that ultimately led to his arrest.

    osintsights.com/dia-insider-pl

    #Espionage #InsiderThreat #NationalSecurity #Counterintelligence #Dia

  12. Wie lassen sich Insiderbedrohungen früher erkennen und proaktiver abwehren? Ne-Trust soll dafür Negative-Trust-Paradigmen und Referenzarchitekturen erforschen – technologieoffen, interdisziplinär und über Zero Trust hinaus.
    Partnering Event: 22.09.2026, 14–17 Uhr.
    Anmeldung bis 16.09.2026. Mehr: t1p.de/21fzz
    #NegativeTrust #Cybersicherheit #InsiderThreat #Forschung

  13. Wie lassen sich Insiderbedrohungen früher erkennen und proaktiver abwehren? Ne-Trust soll dafür Negative-Trust-Paradigmen und Referenzarchitekturen erforschen – technologieoffen, interdisziplinär und über Zero Trust hinaus.
    Partnering Event: 22.09.2026, 14–17 Uhr.
    Anmeldung bis 16.09.2026. Mehr: t1p.de/21fzz
    #NegativeTrust #Cybersicherheit #InsiderThreat #Forschung

  14. Wie lassen sich Insiderbedrohungen früher erkennen und proaktiver abwehren? Ne-Trust soll dafür Negative-Trust-Paradigmen und Referenzarchitekturen erforschen – technologieoffen, interdisziplinär und über Zero Trust hinaus.
    Partnering Event: 22.09.2026, 14–17 Uhr.
    Anmeldung bis 16.09.2026. Mehr: t1p.de/21fzz
    #NegativeTrust #Cybersicherheit #InsiderThreat #Forschung

  15. Wie lassen sich Insiderbedrohungen früher erkennen und proaktiver abwehren? Ne-Trust soll dafür Negative-Trust-Paradigmen und Referenzarchitekturen erforschen – technologieoffen, interdisziplinär und über Zero Trust hinaus.
    Partnering Event: 22.09.2026, 14–17 Uhr.
    Anmeldung bis 16.09.2026. Mehr: t1p.de/21fzz
    #NegativeTrust #Cybersicherheit #InsiderThreat #Forschung

  16. Wie lassen sich Insiderbedrohungen früher erkennen und proaktiver abwehren? Ne-Trust soll dafür Negative-Trust-Paradigmen und Referenzarchitekturen erforschen – technologieoffen, interdisziplinär und über Zero Trust hinaus.
    Partnering Event: 22.09.2026, 14–17 Uhr.
    Anmeldung bis 16.09.2026. Mehr: t1p.de/21fzz
    #NegativeTrust #Cybersicherheit #InsiderThreat #Forschung

  17. Rockstar Games Leak Exposes Insider Threat Risks

    The leak of Grand Theft Auto VI footage by CyberLeek has highlighted the devastating risks of insider threats, where stolen IP can destroy the hard work and livelihoods of employees and companies. This breach has exposed a gaping hole between traditional copyright enforcement and the evolving tactics of threat actors.

    osintsights.com/rockstar-games

    #InsiderThreat #IpTheft #DataExtortion #RansomwareOperations #EmergingThreats

  18. Cameron Curry, a former contract data analyst, has been sentenced to two years in prison for cyber extortion against Brightly Software. He exploited privileged access to payroll data and company documents, weaponizing the stolen information against his former employer.

    #InsiderThreat #CyberExtortion #ThreatIntelligence #DataExfiltration

    cyberworldops.eu/en/former-ana

  19. Cameron Curry, a former contract data analyst, has been sentenced to two years in prison for cyber extortion against Brightly Software. He exploited privileged access to payroll data and company documents, weaponizing the stolen information against his former employer.

    #InsiderThreat #CyberExtortion #ThreatIntelligence #DataExfiltration

    cyberworldops.eu/en/former-ana

  20. Σοκ: η «επίθεση» μπορεί να περάσει από συνέντευξη για δουλειά.

    Έρευνα που συνδέεται με τη Βόρεια Κορέα δείχνει πώς ύποπτοι προγραμματιστές απέκτησαν κανονική πρόσβαση σε εταιρικά συστήματα, χρησιμοποιώντας ψεύτικες ταυτότητες, VPN και AI.

    Αν μια εταιρεία προσλάβει το λάθος άτομο, μπορεί να το καταλάβει πολύ αργά.

    Δες ποια μικρά σημάδια τους πρόδωσαν.

    hacks.gr/proselavan-tychaia-vo

    #Cybersecurity #NorthKorea #LazarusGroup #InsiderThreat #IdentityFraud

  21. An ex-SK Hynix employee received 18 months for leaking chip manufacturing secrets to Chinese firms. Beyond the verdict: this case highlights how semiconductor IP — lithography processes, materials, tooling — has become a primary target in tech competition. Insider threat programs are rarely glamorous, but they're increasingly critical infrastructure. #infosec #InsiderThreat #semiconductors
    digitimes.com/news/a20260810VL

  22. 📰 US Data Breach Notices in H1 2026 Already Exceed All of 2025

    ITRC's H1 2026 report: US data breach notices (471M) have already surpassed all of 2025. Mega-breaches, supply chain attacks, and a 7x rise in insider threats are key drivers. #DataBreach #CyberSecurity #ITRC #InsiderThreat

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/us

  23. 📰 US Data Breach Notices in H1 2026 Already Exceed All of 2025

    ITRC's H1 2026 report: US data breach notices (471M) have already surpassed all of 2025. Mega-breaches, supply chain attacks, and a 7x rise in insider threats are key drivers. #DataBreach #CyberSecurity #ITRC #InsiderThreat

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/us

  24. American Express ordered to fix security gaps after a customer complained about improper employee access.

    It seems that a customer reported a privacy concern and fought AmEx for 4 years to get them to implement stronger access controls or monitoring of employee access to data.

    Now, the AU govt has ordered AmEx to rectify security flaws in five of its data systems to guard against “insider threats” and to restrict employee access to specific customer information to protect vulnerable and high-profile customers.

    See: oaic.gov.au/news/media-centre/

    and:

    oaic.gov.au/__data/assets/pdf_

    h/t, @TheAge (paywalled):
    theage.com.au/business/banking

    #AmEx #AmericanExpress #insiderthreat #accesscontrols #logging #enforcement #privacy #FinSec #infosec

  25. American Express ordered to fix security gaps after a customer complained about improper employee access.

    It seems that a customer reported a privacy concern and fought AmEx for 4 years to get them to implement stronger access controls or monitoring of employee access to data.

    Now, the AU govt has ordered AmEx to rectify security flaws in five of its data systems to guard against “insider threats” and to restrict employee access to specific customer information to protect vulnerable and high-profile customers.

    See: oaic.gov.au/news/media-centre/

    and:

    oaic.gov.au/__data/assets/pdf_

    h/t, @TheAge (paywalled):
    theage.com.au/business/banking

    #AmEx #AmericanExpress #insiderthreat #accesscontrols #logging #enforcement #privacy #FinSec #infosec

  26. American Express ordered to fix security gaps after a customer complained about improper employee access.

    It seems that a customer reported a privacy concern and fought AmEx for 4 years to get them to implement stronger access controls or monitoring of employee access to data.

    Now, the AU govt has ordered AmEx to rectify security flaws in five of its data systems to guard against “insider threats” and to restrict employee access to specific customer information to protect vulnerable and high-profile customers.

    See: oaic.gov.au/news/media-centre/

    and:

    oaic.gov.au/__data/assets/pdf_

    h/t, @TheAge (paywalled):
    theage.com.au/business/banking

    #AmEx #AmericanExpress #insiderthreat #accesscontrols #logging #enforcement #privacy #FinSec #infosec

  27. American Express ordered to fix security gaps after a customer complained about improper employee access.

    It seems that a customer reported a privacy concern and fought AmEx for 4 years to get them to implement stronger access controls or monitoring of employee access to data.

    Now, the AU govt has ordered AmEx to rectify security flaws in five of its data systems to guard against “insider threats” and to restrict employee access to specific customer information to protect vulnerable and high-profile customers.

    See: oaic.gov.au/news/media-centre/

    and:

    oaic.gov.au/__data/assets/pdf_

    h/t, @TheAge (paywalled):
    theage.com.au/business/banking

    #AmEx #AmericanExpress #insiderthreat #accesscontrols #logging #enforcement #privacy #FinSec #infosec

  28. American Express ordered to fix security gaps after a customer complained about improper employee access.

    It seems that a customer reported a privacy concern and fought AmEx for 4 years to get them to implement stronger access controls or monitoring of employee access to data.

    Now, the AU govt has ordered AmEx to rectify security flaws in five of its data systems to guard against “insider threats” and to restrict employee access to specific customer information to protect vulnerable and high-profile customers.

    See: oaic.gov.au/news/media-centre/

    and:

    oaic.gov.au/__data/assets/pdf_

    h/t, @TheAge (paywalled):
    theage.com.au/business/banking

    #AmEx #AmericanExpress #insiderthreat #accesscontrols #logging #enforcement #privacy #FinSec #infosec

  29. Inactive User Account Enables Hackers to Control City's Water System

    A simple mistake of leaving a former employee's user account active allowed hackers to take control of a city's water system, highlighting the importance of promptly disabling access for departed staff. This "zombie" account proved to be the vulnerable entry point that attackers exploited to wreak havoc on…

    osintsights.com/inactive-user-

    #InactiveUserAccount #ZombieAccount #MunicipalWaterSystem #InsiderThreat #AccessControl

  30. Brandon Dixon, CTO & Co-Founder of Ent AI, explains how fake remote IT workers are bypassing interviews, onboarding, and enterprise workflows using legitimate credentials and approved tools.

    👉 AI-generated interview responses
    👉 Zoom-based remote access abuse
    👉 KVM-controlled corporate laptops
    👉 Behavioral drift after hiring
    “Historically, the assumption has been that if somebody authenticated successfully, they’re probably trustworthy.”

    technadu.com/spot-fake-remote-

    #CyberSecurity #InsiderThreat #RemoteWork #IdentitySecurity #InfoSec

  31. Brandon Dixon, CTO & Co-Founder of Ent AI, explains how fake remote IT workers are bypassing interviews, onboarding, and enterprise workflows using legitimate credentials and approved tools.

    👉 AI-generated interview responses
    👉 Zoom-based remote access abuse
    👉 KVM-controlled corporate laptops
    👉 Behavioral drift after hiring
    “Historically, the assumption has been that if somebody authenticated successfully, they’re probably trustworthy.”

    technadu.com/spot-fake-remote-

    #CyberSecurity #InsiderThreat #RemoteWork #IdentitySecurity #InfoSec

  32. Brandon Dixon, CTO & Co-Founder of Ent AI, explains how fake remote IT workers are bypassing interviews, onboarding, and enterprise workflows using legitimate credentials and approved tools.

    👉 AI-generated interview responses
    👉 Zoom-based remote access abuse
    👉 KVM-controlled corporate laptops
    👉 Behavioral drift after hiring
    “Historically, the assumption has been that if somebody authenticated successfully, they’re probably trustworthy.”

    technadu.com/spot-fake-remote-

    #CyberSecurity #InsiderThreat #RemoteWork #IdentitySecurity #InfoSec

  33. Brandon Dixon, CTO & Co-Founder of Ent AI, explains how fake remote IT workers are bypassing interviews, onboarding, and enterprise workflows using legitimate credentials and approved tools.

    👉 AI-generated interview responses
    👉 Zoom-based remote access abuse
    👉 KVM-controlled corporate laptops
    👉 Behavioral drift after hiring
    “Historically, the assumption has been that if somebody authenticated successfully, they’re probably trustworthy.”

    technadu.com/spot-fake-remote-

    #CyberSecurity #InsiderThreat #RemoteWork #IdentitySecurity #InfoSec

  34. The #InsiderThreat Special Interest Group (#SIG) is building a dedicated space within the FIRST community for practitioners to come together, share real-world expertise, and develop practical approaches to detection, response, and mitigation. Early members of Insider Threat SIG will shape:

    • The direction of the SIG
    • The playbooks and frameworks we produce
    • The way this space evolves within FIRST

    We’ve just launched the #FIRST #InsiderThreatSIG and the first in-person meetup will be in Denver, Colorado in June this year! #FIRSTCON26 (Registration still available!)

    This is a practitioner-led group focused on real detection, response, and tradecraft not theory.
    If you work in IR, D&R, Threat Hunting, Insider Risk, or Security Engineering, you should be part of this!

    Join here:
    first.org/global/sigs/insider-
    Let’s build something the industry actually needs.

  35. The #InsiderThreat Special Interest Group (#SIG) is building a dedicated space within the FIRST community for practitioners to come together, share real-world expertise, and develop practical approaches to detection, response, and mitigation. Early members of Insider Threat SIG will shape:

    • The direction of the SIG
    • The playbooks and frameworks we produce
    • The way this space evolves within FIRST

    We’ve just launched the #FIRST #InsiderThreatSIG and the first in-person meetup will be in Denver, Colorado in June this year! #FIRSTCON26 (Registration still available!)

    This is a practitioner-led group focused on real detection, response, and tradecraft not theory.
    If you work in IR, D&R, Threat Hunting, Insider Risk, or Security Engineering, you should be part of this!

    Join here:
    first.org/global/sigs/insider-
    Let’s build something the industry actually needs.

  36. The #InsiderThreat Special Interest Group (#SIG) is building a dedicated space within the FIRST community for practitioners to come together, share real-world expertise, and develop practical approaches to detection, response, and mitigation. Early members of Insider Threat SIG will shape:

    • The direction of the SIG
    • The playbooks and frameworks we produce
    • The way this space evolves within FIRST

    We’ve just launched the #FIRST #InsiderThreatSIG and the first in-person meetup will be in Denver, Colorado in June this year! #FIRSTCON26 (Registration still available!)

    This is a practitioner-led group focused on real detection, response, and tradecraft not theory.
    If you work in IR, D&R, Threat Hunting, Insider Risk, or Security Engineering, you should be part of this!

    Join here:
    first.org/global/sigs/insider-
    Let’s build something the industry actually needs.

  37. The #InsiderThreat Special Interest Group (#SIG) is building a dedicated space within the FIRST community for practitioners to come together, share real-world expertise, and develop practical approaches to detection, response, and mitigation. Early members of Insider Threat SIG will shape:

    • The direction of the SIG
    • The playbooks and frameworks we produce
    • The way this space evolves within FIRST

    We’ve just launched the #FIRST #InsiderThreatSIG and the first in-person meetup will be in Denver, Colorado in June this year! #FIRSTCON26 (Registration still available!)

    This is a practitioner-led group focused on real detection, response, and tradecraft not theory.
    If you work in IR, D&R, Threat Hunting, Insider Risk, or Security Engineering, you should be part of this!

    Join here:
    first.org/global/sigs/insider-
    Let’s build something the industry actually needs.

  38. The #InsiderThreat Special Interest Group (#SIG) is building a dedicated space within the FIRST community for practitioners to come together, share real-world expertise, and develop practical approaches to detection, response, and mitigation. Early members of Insider Threat SIG will shape:

    • The direction of the SIG
    • The playbooks and frameworks we produce
    • The way this space evolves within FIRST

    We’ve just launched the #FIRST #InsiderThreatSIG and the first in-person meetup will be in Denver, Colorado in June this year! #FIRSTCON26 (Registration still available!)

    This is a practitioner-led group focused on real detection, response, and tradecraft not theory.
    If you work in IR, D&R, Threat Hunting, Insider Risk, or Security Engineering, you should be part of this!

    Join here:
    first.org/global/sigs/insider-
    Let’s build something the industry actually needs.

  39. AI Adoption Exposes New Vulnerabilities in APAC Cybersecurity

    As AI systems increasingly become integral to business operations, they're also emerging as a major insider threat, with 7 in 10 APAC organisations now identifying AI as their top data security risk. This new breed of threat is forcing companies to rethink their cybersecurity strategies and take a closer look at the vulnerabilities…

    osintsights.com/ai-adoption-ex

    #Apac #ArtificialIntelligence #InsiderThreat #DataSecurity #EmergingThreats

  40. Former L3Harris offensive cyber exec ordered to pay $10M after selling hacking tools to Russian exploit broker Operation Zero.

    Prosecutors say the stolen tools later surfaced in campaigns tied to Russian intel activity and Chinese cybercriminals.
    A major insider threat case with national security implications.

    Source: techcrunch.com/2026/05/08/u-s-

    Follow @technadu for more cybersecurity updates.
    #InfoSec #Cybersecurity #InsiderThreat

  41. Former L3Harris offensive cyber exec ordered to pay $10M after selling hacking tools to Russian exploit broker Operation Zero.

    Prosecutors say the stolen tools later surfaced in campaigns tied to Russian intel activity and Chinese cybercriminals.
    A major insider threat case with national security implications.

    Source: techcrunch.com/2026/05/08/u-s-

    Follow @technadu for more cybersecurity updates.
    #InfoSec #Cybersecurity #InsiderThreat

  42. Former L3Harris offensive cyber exec ordered to pay $10M after selling hacking tools to Russian exploit broker Operation Zero.

    Prosecutors say the stolen tools later surfaced in campaigns tied to Russian intel activity and Chinese cybercriminals.
    A major insider threat case with national security implications.

    Source: techcrunch.com/2026/05/08/u-s-

    Follow @technadu for more cybersecurity updates.
    #InfoSec #Cybersecurity #InsiderThreat

  43. Former L3Harris offensive cyber exec ordered to pay $10M after selling hacking tools to Russian exploit broker Operation Zero.

    Prosecutors say the stolen tools later surfaced in campaigns tied to Russian intel activity and Chinese cybercriminals.
    A major insider threat case with national security implications.

    Source: techcrunch.com/2026/05/08/u-s-

    Follow @technadu for more cybersecurity updates.
    #InfoSec #Cybersecurity #InsiderThreat

  44. Virginia man convicted in case involving deletion of 96 U.S. government databases after termination from federal contractor.
    Another major insider threat case tied to privileged access abuse.

    Source: infosec.exchange/@technadu/116

    Follow @technadu
    #Infosec #CyberSecurity #InsiderThreat

  45. Virginia man convicted in case involving deletion of 96 U.S. government databases after termination from federal contractor.
    Another major insider threat case tied to privileged access abuse.

    Source: infosec.exchange/@technadu/116

    Follow @technadu
    #Infosec #CyberSecurity #InsiderThreat

  46. Virginia man convicted in case involving deletion of 96 U.S. government databases after termination from federal contractor.
    Another major insider threat case tied to privileged access abuse.

    Source: infosec.exchange/@technadu/116

    Follow @technadu
    #Infosec #CyberSecurity #InsiderThreat

  47. Virginia man convicted in case involving deletion of 96 U.S. government databases after termination from federal contractor.
    Another major insider threat case tied to privileged access abuse.

    Source: infosec.exchange/@technadu/116

    Follow @technadu
    #Infosec #CyberSecurity #InsiderThreat

  48. Contractor Convicted for Destroying Dozens of Federal Databases

    A contractor's reckless actions led to the destruction of dozens of federal databases, showcasing a staggering disregard for the security and integrity of sensitive government information. After being terminated on February 18, 2025, the contractor and his twin brother intentionally caused chaos by accessing…

    osintsights.com/contractor-con

    #DataDestruction #FederalDatabases #InsiderThreat #GovernmentContractors #EmergingThreats

  49. UK Workers Sell Corporate Logins, Exposing Firms to Cybercrime

    One in eight UK employees at large firms have sold or know someone who has sold corporate logins in the past year, a shocking trend that puts companies at risk of cybercrime. Alarming still, many justify this risky behaviour, with senior executives being more likely to think selling credentials is acceptable.

    osintsights.com/uk-workers-sel

    #InsiderThreat #CredentialTheft #CorporateSecurity #Uk #EmployeeFraud