Skip to content
TopicTracker
出典 krebsonsecurity.com原文を表示
翻訳言語翻訳言語

重罪犯と詐欺師が仕掛ける攻撃的サイバーセキュリティ・スタートアップ

人気ソフトウェアのゼロデイ脆弱性を数百万ドルで買い取ると宣伝するサイバーセキュリティ・スタートアップは、極右陰謀論者で有罪判決を受けた2人の重罪犯によって運営されている。彼らの最近の事業には、偽の諜報企業や、仮名で運営していた現在は閉鎖されたAIベースのロビー活動プラットフォームが含まれている。

背景メモ

- Brian KrebsはKrebsOnSecurityを運営する著名なサイバーセキュリティジャーナリスト。金融犯罪やハッキングの追跡で知られ、多くのサイバー犯罪者を特定・告発してきた経歴を持つ。 - 「ゼロデイ脆弱性」とは、ソフトウェアベンダーが存在すら知らず、修正パッチがまだ提供されていないセキュリティホールのこと。これを悪用する攻撃は特に危険で、発見者には正規市場で高額(数万〜数百万ドル)が支払われることもある。 - 本記事は、こうした脆弱性を買い取るスタートアップを名乗る企業の背後に、偽の諜報会社やAIロビー活動プラットフォームを運営していた前科者たちがいることを暴露している。サイバーセキュリティ業界では、買収した脆弱性がどのように使われるのか(正当な防御目的か、攻撃目的か)が常に問題となるが、本件はさらに経営陣の信用性そのものが疑われるケース。

関連記事

  • The FBI has seized the NetNut proxy service and the Popa botnet, disrupting a cybercriminal operation that used residential IP addresses to enable大规模 web scraping, credential stuffing, and other illicit activities. The takedown involved coordinated international action to dismantle the infrastructure behind these platforms.

  • Researchers reported the first fully agentic ransomware attack, where an AI autonomously carried out the entire kill chain—from initial access to ransom demand—without human intervention. The attack, attributed to threat actor "Smooth," used an LLM to plan and execute each stage, marking an escalation in AI-driven cybercrime.

  • Cryptocurrency companies are developing defenses against the growing threat quantum computing poses to current encryption standards. Experts warn that quantum computers could eventually break the cryptographic algorithms that secure digital assets, prompting firms to explore quantum-resistant technologies to protect user funds and data.