Cybercrime

Cybercrime / Most Commented

Privacy Matters: Is It Time To Abolish The WHOIS Database?

Recently, I entered my domain name in a "WHOIS" database query to test the results of the database by using WHOIS on a number of domain name registrar websites. WHOIS is a database service that allows Internet users to look up a number of matters associated with domain names, including the full name of the owner of a domain name, the name of the domain name hosting service, the Internet Protocol or I.P. number(s) corresponding to the domain name, as well as personally identifying information on those who have registered domain names. I was astonished to find... more

Two Years After His Arrest, Pavel Durov Wants to Run His Own Registry

Telegram says it has applied for .gram, potentially giving a billion users DNS addresses while putting its governance, abuse controls, legal exposure and infrastructure under scrutiny as ICANN prepares to reveal applications. more

Cyberattackers Are Using AI Across More of the Kill Chain, Anthropic Reports

Anthropic says attackers are increasingly using AI agents to orchestrate cyber operations, automating reconnaissance, exploitation, data theft and malware adaptation while lowering the expertise and resources previously required for sophisticated attacks. more

How Domain Abuse, Social Media, and AI Fuel Brand Attacks

CISOs expect social media impersonation to become their leading cybersecurity threat as attackers increasingly combine AI-enabled deception, executive impersonation, and domain abuse across multiple channels to conduct fraud and steal sensitive information. more

The Reporting Gap: What Happens Between a DNS Abuse Complaint and a Takedown

DNS abuse enforcement can stop abusive domains and drive systemic registrar reforms, but reporting barriers, inconsistent response times, and poorly documented complaints leave many phishing sites active before actionable cases ever reach enforcement. more

International Operation Disrupts Sality Botnet After More Than Two Decades

Authorities disrupted the decades-old Sality botnet by targeting its decentralized peer-to-peer network and supporting domains, cutting infected machines off from malicious payloads while beginning the longer task of identifying and remediating compromised systems. more

Thirty-Five Years Later, Moscow Comes Looking for the Soviet Union’s Domain

Russia is imposing state identity verification on .su, the Soviet Union's surviving domain, as researchers uncover criminal infrastructure across the namespace and ICANN pursues a retirement process that could eventually remove it from the global root. more

FulcrumSec Claims 86 GB Data Theft in Manchester Airports Breach

FulcrumSec claims it stole 86 GB from Manchester Airports Group, including detailed booking and travel data, while the operator has confirmed a breach but not the group's account of its scale or method. more

ICANN’s New Data Sharpens the Picture of DNS-abuse Enforcement

ICANN's updated DNS-abuse data distinguishes allegations from actionable complaints and malicious registrations from compromised domains, offering a clearer test of whether tougher contractual requirements are strengthening enforcement or simply generating a larger volume of reports. more

Trump Enlists Private Firms for Offensive Cyber Operations

The Trump administration will allow vetted American companies to conduct surveillance and offensive cyber operations against foreign criminal groups, extending private-sector capabilities into cybercrime enforcement while keeping missions subject to federal approval, oversight and legal safeguards. more

Who Registers the Domain That Steals Your Data? The Registrar Accountability Gap in India’s DNS Abuse Crisis

India's DNS abuse crisis exposes a registrar accountability gap: malicious domains remain online while vulnerable users bear the cost. Concentrated abuse patterns suggest stronger oversight and faster mitigation could significantly reduce predictable harms nationwide today. more

The Question Isn’t Whether the Harm Is Real - It’s Who Should Act

Measuring online abuse can reveal its scale, but not who should intervene. Effective policy must distinguish harm from contractual responsibility, identify the actors best placed to act, and target remedies where they can work effectively. more

ZEGO’s Cyberattack Pushes Bavarian Textile Firm Into Insolvency

A cyberattack forced Bavarian textile specialist ZEGO into insolvency after a six-week production shutdown. The company is pursuing restructuring efforts to preserve jobs, customer relationships and its future amid growing cyber risks. more

FBI Warns of Russian Cyber Campaign Targeting Vulnerable Routers

The FBI and international partners warn that Russia's FSB Center 16 is exploiting vulnerable routers worldwide, highlighting persistent weaknesses in network security and urging organizations to adopt stronger protections to safeguard critical infrastructure against intrusion. more

The Internet, Beyond a Right: A Critical Infrastructure

As governments, economies and essential services become ever more dependent on connectivity, the internet can no longer be viewed solely as a right. It must be treated as critical infrastructure, protected, regulated and made resilient against disruption. more