惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Fox-IT International blog
Recent Announcements
Recent Announcements
D
Docker
IT之家
IT之家
B
Blog
Jina AI
Jina AI
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 【当耐特】
Google DeepMind News
Google DeepMind News
F
Fortinet All Blogs
量子位
C
Check Point Blog
Microsoft Azure Blog
Microsoft Azure Blog
罗磊的独立博客
博客园 - 司徒正美
李成银的技术随笔
美团技术团队
Blog — PlanetScale
Blog — PlanetScale
雷峰网
雷峰网
The GitHub Blog
The GitHub Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
J
Java Code Geeks
T
The Blog of Author Tim Ferriss
酷 壳 – CoolShell
酷 壳 – CoolShell
MongoDB | Blog
MongoDB | Blog
P
Proofpoint News Feed
L
LangChain Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Y
Y Combinator Blog
大猫的无限游戏
大猫的无限游戏
有赞技术团队
有赞技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
Visual Studio Blog
T
Tailwind CSS Blog
H
Help Net Security
Engineering at Meta
Engineering at Meta
小众软件
小众软件
B
Blog RSS Feed
Stack Overflow Blog
Stack Overflow Blog
月光博客
月光博客
M
Microsoft Research Blog - Microsoft Research
宝玉的分享
宝玉的分享
人人都是产品经理
人人都是产品经理
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
GbyAI
GbyAI
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Last Week in AI
Last Week in AI
Martin Fowler
Martin Fowler
Stack Overflow Blog
Stack Overflow Blog

The Register - Security: Cyber-crime

Jailbroken Gemini helped Russian-speaking fraudster target MAGA crypto users Shai-Hulud copycat hits another npm package Grafana Labs admits all its codebase are belong to someone who popped its GitHub account Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Foxconn confirms cyberattack after Nitrogen claims Apple, Nvidia data theft Cache-poisoning caper turns TanStack npm packages toxic Attackers are cashing in on fresh 'CopyFail' Linux flaw 'CopyFail' attackers start cashing in on Linux flaw Real estate giant confirms vishing incident as ShinyHunters and Qilin both come knocking Real estate giant confirms vishing incident as ShinyHunters and Qilin both come knocking ShinyHunters claims dump puts 119K Vimeo emails in the wild ShinyHunters claims 119K Vimeo emails in the wild Romance scammers turn sweet talk into £102M payday First reports come in of victims of critical cPanel vuln as 'millions' of sites potentially exposed First reports come in of victims of critical cPanel vuln as 'millions' of sites potentially exposed Pro-Iran crew turns DDoS into shakedown as Ubuntu.com stays down Pro-Iran crew turns DDoS into shakedown as Ubuntu.com stays down French prosecutors link 15-year-old to mega-breach at state’s secure document agency French prosecutors link 15-year-old to mega-breach at state’s secure document agency Nearly half of UK businesses pwned last year as phishing keeps doing the job like it's 2005 UK business breach rate stuck at 43%... blame the phishing What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia Chinese spy group caught lurking in Poland, Asia networks Don't pay Vect a ransom - your data's likely already wiped out Don’t pay VECT a ransom - your big files are likely gone Have I Been Pwned claims Pitney Bowes hit by 8.2M email address leak Pitney Bowes the latest victim of ShinyHunters’ breach-spree Ongoing supply-chain attack 'explicitly targeting' security, dev tools Ongoing supply-chain attack 'explicitly targeting' security, dev tools Medical and utility tech companies hacked by digital intruders Medical and utility tech companies admit digital breakins Burglar alarm biz burgled: ADT confirms cyber intrusion after ShinyHunters extortion attempt Burglar alarm biz burgled: ADT confirms cyber intrusion after ShinyHunters extortion attempt Crime crew impersonates help desk, abuses Microsoft Teams to steal your data Crime crew impersonates help desk, abuses Teams chats ShinyHunters claim they have cruise giant Carnival's booty as 7.5M emails surface ShinyHunters claim they have cruise giant Carnival’s booty Governments on high alert after CISA snuffs out Firestarter backdoor on fed network CISA, NCSC issue Firestarter backdoor warning Medical data of 500k Biobank volunteers listed for sale on Alibaba, UK minister reveals Medical data of 500k Biobank volunteers listed for sale on Alibaba, UK minister reveals Pass the key, passwords have passed their sell-by date Another npm supply chain worm is tearing through dev environments Another npm supply chain worm hits dev environments France's 'Secure' ID agency probes breach as crooks claim 19M records France's 'Secure' ID agency probes claimed 19M record breach macOS ClickFix attacks deliver AppleScript stealers to snarf credentials, wallets MacOS ClickFix attacks deliver AppleScript stealers Yet another ex-ransomware negotiator admits turning rogue after payoff from crimelords Third ransomware pro pleads guilty to cybercrime U-turn AI-assisted intruders pwned Vercel via OAuth abuse and a pilfered employee account AI-pwned: Vercel breach traced to stolen employee creds Crook claims to leak 'video surveillance footage' of companies Crook claims to leak 'video surveillance footage' of companies Adaptavist Group breach spawns imposter emails as ransomware crew claims mega-haul Adaptavist Group breach: Ransomware crew claims mega-haul Scot becomes second Scattered Spider-linked crook to plead guilty in US Scot becomes second Scattered Spider-linked crook to plead guilty in US North Korea targets macOS users in latest heist North Korea targets macOS users in latest heist Textbook titan McGraw Hill on ransomware crew's reading list after 13.5M records exposed McGraw Hill linked to 13.5M-record data leak Automotive data biz Autovista blames ransomware for service disruption Automotive data biz Autovista blames ransomware for service disruption Ancient Excel bug comes out of retirement for active attacks No honor among thieves as 0APT threatens rival ransomware gang Krybit 0APT ransomware gang extorts Krybit amid doxxing threat Fake Linux leader using Slack to con devs into giving up their secrets Fake Linux Foundation leader using Slack to phish devs Booking.com warns reservation data may have checked out with intruders Booking.com warns reservation data may have checked out with intruders Gym giant Basic-Fit confirms data on a million members stolen in cyberattack Gym giant Basic-Fit confirms data on a million members stolen in cyberattack Rockstar Games gets a taste of grand theft data Rockstar Games gets a taste of grand theft data Crypto? Huh. Good gawd y'all, what is it good for? $45M in this case US, UK, Canadian cops disrupt $45M global crypto scam 'Several dozen' high-value corporations hit by new extortion crew in helpdesk phishing spree 'Several dozen' orgs targeted by a new extortion crew Months-old Adobe Reader zero-day uses PDFs to size up targets Months-old Adobe Reader zero-day uses PDFs to size up targets Zephyr Energy loses £700K in cyber hit that rerouted contractor payment Zephyr Energy loses £700K to contractor payment fraud Dutch healthcare software vendor goes dark after ransomware attack Ransomware knocks Dutch healthcare software vendor offline Hundreds of orgs compromised daily in Microsoft device code phishing attacks Hundreds of orgs compromised daily in Microsoft device code phishing attacks US cybercrime losses pass $20B for first time as AI boosts online fraud US cybercrime losses pass $20B for first time as AI boosts online fraud Russia's Fancy Bear still attacking routers to boost fake sites, NCSC warns Russia's APT28 behind latest wave of router, DNS attacks AI recruiting biz Mercor says it was 'one of thousands' hit in LiteLLM supply-chain attack Mercor says it was 'one of thousands' hit in LiteLLM attack Don't open that WhatsApp message, Microsoft warns Iran targets M365 accounts with password-spraying attacks Iran targets M365 accounts with password-spraying attacks Telnyx joins LiteLLM in latest PyPI package poisoning tied to Trivy breach Telnyx package latest hit in PyPI supply-chain compromise European Commission admits attackers broke into public web systems, but says little else
Cybercrime up 245% since the start of the Iran war
2026-03-17 · via The Register - Security: Cyber-crime

Cyber-crime

Hacktivists use proxy services from Russia, China for 'billions of designed-for-abuse connection attempts'

Cybercrime has skyrocketed since the start of the Iran war, according to Akamai, which reports a 245 percent increase in everything from credential harvesting attempts to automated reconnaissance traffic aimed at banks and other critical businesses.

Banking and fintech have been the hardest hit, accounting for 40 percent of the malicious traffic since February 28, followed by e-commerce (25 percent), video games (15 percent), technology firms (10 percent), media and streaming services (7 percent), and other industries (3 percent), the CDN provider said.

Most of the internet traffic Akamai has logged thus far has been infrastructure scanning and reconnaissance efforts, with botnet-driven discovery traffic jumping 70 percent and automated recon traffic up 65 percent. The firm also reported a notable uptick in widespread scanning of infrastructure and exposed services (up 52 percent), credential harvesting attempts (45 percent), and reconnaissance ahead of distributed denial of service (DDoS) attacks (38 percent).

REG AD

This includes an unnamed US financial services company that blocked 13 million packets originating from Iran over the last 90 days, with a network traffic flood exceeding 2 million packets on February 9 – in the lead-up to the military strikes – and then a couple of other spikes immediately after the conflict started. 

REG AD

However, not all of the malicious traffic originated from Iran. The embattled theocracy accounted for only 14 percent of the source IPs, compared to Russia (35 percent) and China (28 percent). This doesn't necessarily mean that the threat groups carrying out the cyber activities are based in these two counties. Both China and Russia have historically turned a blind eye toward digital-crime networks and services operating out of their countries – just as long as the attacks don't target Chinese and Russian government agencies or organizations.

As Akamai notes, "geopolitically motivated hacktivists are using proxy services in countries like Russia and China as a source for billions of designed-for-abuse connection attempts."

At the beginning of March, Palo Alto Networks' Unit 42 senior manager Justin Moore told The Register that the threat-intel team has tracked an uptick in pro-Russian hacktivists.

This, Moore said, is "effectively expanding the Middle East's attack surface, and potentially exposing regional infrastructure to high-disruption tactics historically used by these groups against NATO and European interests."

Some of these groups are closely tied to – or even cyber arms of – government intelligence agencies. This appears to be the case with Handala, an Iranian hacktivist crew believed to be a front for the Ministry of Intelligence and Security (MOIS), that claimed to be behind a destructive, data-wiping attack against Stryker, a global medical technology company headquartered in Kalamazoo, Michigan. 

Akamai suggests that organizations that do not "conduct business in certain geographies, or if it offers a service for which it is unlikely to have legitimate users outside specific regions of the world (e.g., financial services, public utility companies, or healthcare organizations, among others)," deny all traffic from those regions. 

Of course, being a CDN and security vendor, Akamai suggests organizations do this using its firewall – but this is sane advice during times of geopolitical conflict no matter whose networking and security gear you use. ®