ZeroHour

Search: “Quick Assist”

7 stories

Conti ransomware crew member sentenced to four years in prison

Ukrainian national Oleksii Lytvynenko sentenced to four years in the US for his role in Conti ransomware attacks on at least 12 companies.

Oleksii Lytvynenko, 44, who pleaded guilty in June to conspiracy to commit wire fraud, was sentenced Thursday to four years in prison by the US Justice Department. He joined the Conti ransomware group in September 2021 as an intruder and malware developer, holding stolen data from 12 victims including eight US-based organizations, and prosecutors said co-conspirators extorted roughly $634,000 in Bitcoin from Tennessee victims including government entities. Conti attacked more than 1,000 organizations before disbanding in 2022, with members rebranding into Zeon, Black Basta, and Quantum/Royal/BlackSuit.

CyberScoopupdated · 5d agofirst · 6d agoPolicy & legal 7 sources1

NightmareStresser Goes Offline in Global DDoS-for-Hire Crackdown

The DOJ seized NightmareStresser domains, a DDoS-for-hire service behind hundreds of thousands of attacks since 2022, as part of Operation PowerOFF.

The US Department of Justice announced the court-authorized seizure of internet domains behind NightmareStresser, a booter service allegedly used to launch hundreds of thousands of actual or attempted DDoS attacks worldwide since 2022. The action, announced from the District of Alaska with FBI Anchorage and Royal Canadian Mounted Police support, is part of Operation PowerOFF, which previously took down 53 domains across 21 countries in April and 27 booter sites in December 2024. Over the past eight years, prosecutors have charged twelve defendants and seized more than 100 domains tied to DDoS-for-hire services.

US disrupts Xinbi Guarantee marketplace fueling the cyber scam economy

US Treasury sanctions and DOJ seizures take down Xinbi Guarantee, a Telegram marketplace that processed $24B+ for cyber scams, freezing $52.8M.

The Treasury Department sanctioned the Chinese-language Telegram marketplace Xinbi Guarantee and two supporting firms, Anwen Technology (XinbiPay) and SafeW Technology, while the DOJ seized its Telegram channels and $52.8 million in USDT from 52 wallets. Blockchain intelligence firm Elliptic, which assisted the Secret Service, estimates Xinbi has processed at least $24 billion in transactions since 2022, making it the second-largest illicit online marketplace and a cornerstone of Southeast Asian cybercrime. Vendors sold money laundering, stolen personal data, deepfake technology, and other services for pig-butchering scams, with payments in Tether's USDT. The DOJ's Scam Center Task Force also dismantled 13 scam centers in Madagascar, arresting dozens of alleged leaders who were repatriated to China.

The Record · 7d agoPolicy & legal

FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching

FBI officials said AI is accelerating adversary capabilities while its new cyber strategy emphasizes continuous patching, cyber hygiene, and AI-enabled defense.

At the Billington CyberSecurity Summit and ahead of a new FBI cyber strategy, deputy assistant director Jason Bilnoski said AI is boosting the speed and capability of both criminal and nation-state attackers, while stressing that basic controls like MFA would still prevent most attacks. Colleen Ferranti urged a shift from quarterly Patch Tuesday cycles to continuous, risk-based patching as AI accelerates vulnerability discovery. The strategy pledges AI-enabled triage, malware analysis, attribution support, agentic AI adoption, expanded Computer Network Operations, ICS Coordinators in every field office, and a pledge on victim relief and privacy.

CyberScoop · 8d agoPolicy & legal

FBI cyber chief worries private sector not sharing enough cyber threat information

FBI cyber chief Brett Leatherman urged companies to share breach information with the bureau as it publishes a victim-focused cyber strategy.

FBI Cyber Division assistant director Brett Leatherman said at the Billington CyberSecurity Summit that private-sector hesitancy to engage the FBI stems from misconceptions, including a belief that shared incident data is passed to regulators. He warned that organizations breached by PRC nation-state actors risk more by handling intrusions alone, since FBI involvement speeds eradication. The bureau published a new cyber strategy Wednesday emphasizing victim aid, adopting a 'share until it hurts' posture on releasing threat intelligence.

CyberScoop · 7d agoPolicy & legal

Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist

Kyle Spitze, an early 764 member, was sentenced to 77 years for producing CSAM, the longest sentence for a nihilistic violent extremist.

Kyle William Spitze, an original member of the 764 nihilistic violent extremist network and administrator of the Harm Nation offshoot, was sentenced to 77 years in federal prison. He pleaded guilty in December 2024 to producing child sexual abuse material, possession of CSAM, and distributing animal crush videos, victimizing dozens of girls through coercion, doxing and swatting threats. Investigators found roughly 25 photo albums of abuse imagery on his phone and evidence of animal torture. The Justice Department framed the sentence as a signal in a broader enforcement push against 764, which has seen multiple members arrested or sentenced since 2025.

CyberScoop · 27d agoPolicy & legal

What the 3M ChatGPT case reveals about AI governance

3M litigation shows ChatGPT prompts can become discoverable evidence, forcing enterprises to govern AI conversation records.

In the Watson Grinding explosion litigation, an engineering expert retained by 3M had used ChatGPT, and a surfaced prompt asked the system to 'show how 3M is 0% at fault'; after an off-record deposition demand, more than 350 pages of previously unproduced ChatGPT material were provided. The author argues AI interaction histories are becoming part of decision records and discovery material, a trend the American Bar Association has already examined. Enterprises are urged to manage retention, ownership, sharing, and deletion of AI conversation logs across tools like ChatGPT, Copilot, Claude, and Gemini.

CSO Online · 3d agoPolicy & legal