CuraSec

tag: Insider-Threat · 4 items

2026-08-31 · The Hacker News · source ↗ #insider-threat#dprk#social-engineering
  • Engineer — Skip
  • SOC/IR — Learn: Expands the known DPRK IT-worker insider-threat profile into healthcare and sales; no IOCs or ATT&CK-mapped TTPs are provided, so there is no detection work to action today, but analysts should update their mental model of which hiring pipelines are targeted.
  • Leader — Plan: The scheme now threatens non-IT hiring pipelines, including healthcare where regulatory exposure is high; review remote-hire verification procedures and brief HR leadership on enhanced identity-vetting requirements for fully-remote roles across all business units.
2026-08-14 · BleepingComputer · source ↗ #insider-threat#data-theft#extortion
  • Engineer — Skip
  • SOC/IR — Learn: A contractor-turned-extortionist exfiltrated data and leveraged it for a $2.5M scheme; worth reviewing contractor access controls and DLP coverage as a case study for insider threat detection patterns.
  • Leader — Learn: A successful insider extortion prosecution illustrates board-level risk from contractor data access; useful for reinforcing third-party access governance and insider threat program justifications.
2026-07-11 · BleepingComputer · source ↗ #supply-chain#open-source#insider-threat
  • Engineer — Learn: A reminder that contributor-level insider threats exist in open-source projects; no specific packages or artifacts were confirmed compromised, and OpenMandriva is niche enough that most teams have no direct exposure.
  • SOC/IR — Skip
  • Leader — Skip
2026-07-11 · BleepingComputer · source ↗ #ransomware#insider-threat#blackcat
  • Engineer — Skip
  • SOC/IR — Learn: Insider-threat angle is notable: attacker was a trusted IR professional with access to victim environments, illustrating how responders can become adversaries — relevant context for vetting IR vendors and monitoring privileged access during incidents.
  • Leader — Learn: The case highlights vendor-risk and insider-threat exposure when engaging external IR firms — useful framing for board discussions on third-party access controls and contractual accountability during incident response engagements.