Tag: jobs
-
ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns
A vulnerability in a popular line of products from Oracle is being used in a new campaign by the prolific ShinyHunters hacking group, which recently claimed credit for an attack on the FBI’s jobs site. First seen on therecord.media Jump to article: therecord.media/shinyhunters-cyberattacks-oracle-mandiant
-
FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day
The FBI’s online portals for job applicants (at apply.fbijobs.gov) and special agent applicants (at fbijobs.gov/special-agents) are still unavailable, following what … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/28/fbi-job-portals-offline-shinyhunters-breach/
-
AI Is Changing Cybersecurity Jobs, Not Erasing Them
SANS Institute’s Rob Lee on AI Transforming Cyber Jobs. AI is reshaping entry-level cybersecurity, but SANS Institute’s Rob Lee says the data doesn’t show junior jobs disappearing. Instead, he expects the starting point to move higher as AI accelerates technical work, raises skill expectations and creates new security roles. First seen on govinfosecurity.com Jump to…
-
AI Is Changing Cybersecurity Jobs, Not Erasing Them
SANS Institute’s Rob Lee on AI Transforming Cyber Jobs. AI is reshaping entry-level cybersecurity, but SANS Institute’s Rob Lee says the data doesn’t show junior jobs disappearing. Instead, he expects the starting point to move higher as AI accelerates technical work, raises skill expectations and creates new security roles. First seen on govinfosecurity.com Jump to…
-
Breach Roundup: Thousands of AI Relays Hide China Users
Tags: ai, breach, china, cisa, cve, cybercrime, data, data-breach, flaw, google, jobs, north-korea, russia, scam, vpnAlso, CISA Ends Weekly CVE Bulletin After 22 Years, Check Point VPN Flaw Exploited. This week: AI relay servers connect to China, CISA ends weekly CVE bulletin, cybercriminal guilty pleas and sentences, drug dealers hijack Google Maps, Russian Burger King customers’ data leaked, North Korean fake job scams, SectopRAT, a Check Point VPN flaw and…
-
GitLab Email Token Lets Attackers Push Code to Main and Execute CI/CD Jobs
A long-lived GitLab incoming email token embedded in project email addresses for the >>Email work item<< feature can be exploited to push attacker-controlled code, create merge requests, and trigger CI/CD pipelines using the permissions of the token owner. This issue can also bypass GitLab's IP restrictions, as incoming email is explicitly excluded from those controls.…
-
ShinyHunters Hacks FBI Jobs Portal, Claims It Stole Agents’ Data
ShinyHunters hacks the FBI Jobs portal and claims sensitive data on nearly all FBI agents and job applicants before the site is taken offline for security work. First seen on hackread.com Jump to article: hackread.com/shinyhunters-hacks-fbi-jobs-portal-fbi-agents-data/
-
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/
-
North Korean Hackers Hide Mac Backdoors in Fake Terraform Job Tests
North Korean hackers are using fake Terraform job tests to deploy macOS backdoors and target developer access to cloud infrastructure. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-north-korean-terraform-malware/
-
Contagious Interview: 30,000 devices infected by a fake job interview
North Korea-linked WaterPlum runs the Contagious Interview campaign, infecting over 30,000 devices using a fake job interview. On September 18, Japan’s National Police Agency, the FBI, the US Department of Defense’s Cyber Crime Center, and intelligence agencies from Australia and Germany published a joint advisory about a group called WaterPlum, better known as Contagious Interview.…
-
North Korea’s job interview scam runs both ways
Attackers are targeting members of the Rust Project and maintainers of widely used crates (Rust code libraries), dangling attractive opportunities to compromise their devices … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/21/north-korean-hackers-contagious-interview-defenses/
-
Hackers Weaponize Terraform Lock Files to Infect DevOps Engineers With macOS Backdoors
North Korea-linked threat actor TraderTraitor has expanded its developer-focused intrusion activity beyond cryptocurrency targets, using weaponized Terraform lock files in fake job-interview repositories to infect DevOps engineers with macOS backdoors. SentinelOne identified an Indian IT services provider compromised with the same FLATROOF and ROOFDECK implants previously linked to the April 2026 KelpDAO-LayerZero attack. The campaign…
-
North Korean WaterPlum Hackers Target IT Professionals With Fake Job Interviews to Steal Crypto
North Korean threat actors, known as WaterPlum (also referred to as Contagious Interview), have infected at least 30,000 devices in over 100 countries by luring software developers and IT professionals into malicious job interviews. This campaign specifically targets web developers, freelancers, blockchain specialists, and cryptocurrency professionals. The attackers use persuasive recruitment messages that mimic legitimate…
-
North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign
The FBI and Defense Department partnered with Japan’s National Police Agency and law enforcement agencies in Australia and Germany on a new advisory about “WaterPlum”, a group of cyber actors allegedly stealing cryptocurrency from job applicants by posing as AI or blockchain companies. First seen on therecord.media Jump to article: therecord.media/north-korean-hackers-infect-thousands-of-devices-waterplum-scheme
-
International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data
The U.S., Japan, Germany and Australia said WaterPlum operators pose as prospective employers and have infected more than 30,000 devices worldwide. First seen on cyberscoop.com Jump to article: cyberscoop.com/north-korea-waterplum-job-seeker-crypto-attacks/
-
98% of fraudulent hires have company credentials by the time they’re caught
A 90-day period between hiring and onboarding is creating a blind spot in enterprise identity security, according to HYPR’s State of HR Identity Fraud Detection report. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/18/hypr-hiring-fraud-detection-report/
-
FBI Seizes NightmareStresser DDoSHire Domains Used in Hundreds of Thousands of Attacks
The FBI has seized internet domains linked to NightmareStresser, a long-standing distributed denial-of-service (DDoS)-for-hire platform allegedly used to launch hundreds of thousands of attacks or attempted attacks worldwide since 2022. The U.S. Attorney’s Office for the District of Alaska announced the action, which targets the infrastructure that allowed paying customers to overwhelm victims’ networks and…
-
Authorities seize popular, long-running DDoS-for-hire service domains
Cybercriminals used NightmareStresser to launch hundreds of thousands of DDoS attacks since at least 2022. Threat actors behind the operation claimed links to Russia. First seen on cyberscoop.com Jump to article: cyberscoop.com/fbi-seizes-nightmarestresser-ddos-for-hire-domains/
-
U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks
The U.S. Department of Justice (DoJ) on Tuesday announced the court-authorized seizure of internet domains associated with a distributed denial-of-service (DDoS)-for-hire service known as NightmareStresser.The domains in question are: nightmare-stresser[.]com and nightmarestresser[.]org. Visitors to the site are now greeted by a seizure banner that states -“This domain has been seized by the First seen on…
-
North Korean IT Workers Pay People to Sit Through Job Interviews While They Control the Computer
North Korean IT-worker operators are recruiting foreign nationals to sit on camera during remote job interviews. At the same time, the real candidate provides answers, completes coding tasks, or remotely controls the proxy’s computer, according to new research from Silent Push. The campaign turns ordinary job seekers into identity and payment intermediaries, creating a direct…
-
FBI takes down one of the longest-running DDoS-for-hire services
The FBI has seized the domains behind NightmareStresser, a DDoS-for-hire service officials call one of the longest running >>booter<< operations in existence. The … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/17/fbi-nightmarestresser-ddos-for-hire-service-seized/
-
US takes down NightmareStresser DDoShire platform
The U.S. Federal Bureau of Investigation (FBI) seized the domains used by NightmareStresser, one of the world’s longest-running distributed denial-of-service (DDoS) platforms. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/fbi-seizes-nightmarestresser-service-linked-to-thousands-of-ddos-attacks/
-
Israeli contractor BlackCore trained Angolan officials in online influence operations
An Israeli influence-for-hire company trained Angolan government officials to run online influence operations, including by creating fake social media personas and media outlets, researchers found. First seen on therecord.media Jump to article: therecord.media/angola-israel-influence-operations-blackcore
-
NightmareStresser Goes Offline in Global DDoSHire Crackdown
The DOJ seized domains behind NightmareStresser, a DDoS-for-hire service tied to hundreds of thousands of attacks since 2022, as part of Operation PowerOFF. Renting a DDoS attack used to be as easy as renting a movie. Pick a target, pay a few dollars, watch the site go dark. The Justice Department just made that a…
-
MSPs say nearly half their customers rely on them for CISO services
MSPs estimate that 46% of their customers, on average, look to them to act as CISOs, according to Sophos. Most of those providers do that job without the full set of … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/16/msp-ciso-services-compliance/
-
Crypto Agility: Digital Trust Is Becoming a Full-Time Job
Shrinking Certificates, ACME, mTLS and PQC Redefine Enterprise Security Posture Certificate lifespans are shrinking, making automated life cycle management essential. ACME is replacing manual renewal, mTLS is extending cryptographic identity across internal services, and post-quantum deadlines are approaching. Here’s how leaders can build crypto agility now. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/blogs/crypto-agility-digital-trust-becoming-full-time-job-p-4186
-
Most Fraudulent Hires Receive Credentials Before Detection
A new report highlights the vast growth in fraudulent candidates, presenting significant insider threat challenges to organizations First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/fraudulent-hires-credentials/
-
Most Fraudulent Hires Receive Credentials Before Detection
A new report highlights the vast growth in fraudulent candidates, presenting significant insider threat challenges to organizations First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/fraudulent-hires-credentials/
-
Most Fraudulent Hires Receive Credentials Before Detection
A new report highlights the vast growth in fraudulent candidates, presenting significant insider threat challenges to organizations First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/fraudulent-hires-credentials/
-
We Read 1,000 SOC Job Postings. Security Teams Are Hiring Three Builders for Every Analyst.
The last SOC requisition your team wrote says more about the future of security operations than analyst forecasts. It has a title, a salary range, and a duties list that a budget owner signed. Multiply that by 665 and you… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/we-read-1000-soc-job-postings-security-teams-are-hiring-three-builders-for-every-analyst/

