infosecfollow

daily plain-text briefing: security, markets, business, and pittsburgh

Federal agents and Google tore down Outsider Enterprise, a China-based AI-powered phishing service running a million malicious URLs, as Washington let its Section 702 surveillance authority lapse for the first time.


Security

Ransomware and Cybercrime

1. FBI Dismantles Outsider Phishing-as-a-Service

[cybercrime, phishing, ai]

Latest developments: The FBI, working with Google and Black Lotus Labs, seized and dismantled Outsider Enterprise, escalating from Google's earlier lawsuit to a full takedown of thousands of phishing sites spanning roughly a million URLs.

read more

Outsider Enterprise ran a phishing-as-a-service kit out of China, weaponizing Google's Gemini to mass-produce scam texts and fraudulent websites that harvested credit card numbers and passwords from Americans. Operators rented the toolkit to blast smishing links across a million URLs. The coalition shut down the infrastructure and exposed the network behind it. Defenders should block known Outsider domains and warn staff about credential-stealing text lures.

Sources: BleepingComputer · The Hacker News

2. Iowa School IT Insider Jailed for Sabotage

[insider, cybercrime]

Latest developments: A federal court sentenced a former IT employee of an Iowa school district to 21 months in prison for a prolonged cyberattack on his ex-employer.

read more

The insider deleted accounts, disrupted classroom operations, and ran up tens of thousands of dollars in damage after leaving the district. The case turns on access that outlasted his employment. It underscores the danger of credentials that survive a departure. Organizations should revoke accounts the moment staff exit.

Sources: BleepingComputer

Policy and Regulation

3. Section 702 Surveillance Authority Lapses

[policy, surveillance]

Latest developments: Section 702 of the Foreign Intelligence Surveillance Act lapsed for the first time since its 2008 passage after Congress deadlocked, halting a cornerstone US foreign-intelligence collection program.

read more

Section 702 lets US agencies collect the communications of foreign targets abroad, a backbone of signals intelligence that also sweeps in Americans' data and has drawn privacy fights for years. Legislative deadlock let the authority expire outright. Intelligence agencies lose a key surveillance tool until Congress reauthorizes it. The lapse leaves ongoing collection in legal limbo.

Sources: The Record

Supply Chain Security

4. Npm 12 Disables Dependency Scripts by Default

[supply-chain, patch]

Latest developments: Npm announced that version 12 will stop running dependency lifecycle scripts on install by default, requiring developers to explicitly allow them.

read more

Supply chain attackers have long abused npm's automatic execution of install scripts to run malware the moment a developer pulls a package. Npm 12 flips the default so install no longer executes those scripts unless whitelisted. The change blunts a favorite infection vector behind recent registry compromises. Developers relying on legitimate post-install scripts must opt them back in.

Sources: SecurityWeek

Vulnerabilities and Exploits

5. Critical Zcash Orchard Flaw Found and Fixed

[vulnerability, cryptocurrency, ai]

Latest developments: Researcher Taylor Hornby disclosed a critical vulnerability in Zcash's Orchard shielded pool, found on May 29 using Claude Opus 4.8, and the Zcash team patched it.

read more

Orchard is Zcash's newest privacy system for shielded transactions, live since 2022. The Zcash team hired Hornby to hunt for exactly this class of bug, and he found a critical one fast with AI assistance. Developers fixed it before any known exploitation surfaced. Zcash holders should move to the patched software.

Sources: Schneier on Security

6. phpBB Patches Decade-Old Auth Bypass

[vulnerability, patch]

Latest developments: phpBB fixed a ten-year-old authentication bypass that let an attacker log in as any user, administrators included.

read more

phpBB is widely deployed open-source forum software running countless community sites. The flaw lurked for a decade and allowed full account takeover, including admin access. Maintainers shipped a patch. Forum operators should upgrade at once.

Sources: BleepingComputer

Data Breaches

7. Maine Pulls Breach Portal Over Fake Filings

[breach, policy]

Latest developments: Maine took its public data breach notification portal offline after fraudsters published fake breach disclosures on the state website.

read more

Maine runs a public portal where companies file data breach reports and citizens read them. Bad actors submitted bogus disclosures that the state published, undermining trust in the record. Officials pulled the portal and launched a review of submission controls. The episode exposes weak validation on government self-service intake.

Sources: BleepingComputer

Business and Politics

Pittsburgh

Weather

Today: Chance Showers And Thunderstorms, high 84F.

Tonight: Showers And Thunderstorms then Mostly Cloudy, low 56F.

Monday: Mostly Sunny, high 71F.

Business

Around Town

Events

Sports

Pirates (36-35)

Sat Jun 13 · Marlins 2 · Pirates 3 · Final

Spencer Horwitz hit by pitch with the bases loaded to lift the Pirates past the Marlins, 3-2

Up Next · Marlins @ Pirates · Sun Jun 14, 12:15 PM

Reading

Markets

weekly average, change vs prior week

S&P 500     7,377.03  ▼ -2.2%
Dow        50,725.58  ▼ -0.7%
Nasdaq     25,695.30  ▼ -3.8%
WTI crude      88.42  ▼ -5.0%
EUR/USD       1.1550  ▼ -0.4%
GBP/USD       1.3363  ▼ -0.6%
USD/JPY       160.31  ▲ +0.3%