Tim Starks
banner
timstarks.bsky.social
Tim Starks
@timstarks.bsky.social
Senior reporter, CyberScoop, covering spyware, cyber policy and more. Russia-sanctioned. Former Washington Post, POLITICO, CQ Roll Call. @timstarks.02 on Signal. [email protected]. Mastodon [email protected], X timstarks, Threads tstarks2.
Reposted by Tim Starks
FBI: Cybercriminals stole $262M by impersonating bank support teams
FBI: Cybercriminals stole $262M by impersonating bank support teams
The FBI warns of a surge in account takeover (ATO) fraud schemes and says that cybercriminals impersonating various financial institutions have stolen over $262 million in ATO attacks since the start of the year.
www.bleepingcomputer.com
November 25, 2025 at 6:23 PM
Reposted by Tim Starks
"Cargo theft losses increased by 27% in 2024 and are expected to increase another 22% this year, according to the website of the National Insurance Crime Bureau (NICB)."
www.pymnts.com/news/securit...
FBI Agent Says Cargo Theft Is Now ‘Primarily Cyber-Enabled’ | PYMNTS.com
Cargo theft is now “primarily cyber-enabled,” an FBI agent said in a Tuesday (Nov. 25) Wall Street Journal report. Doug McKelway, a supervisory special
www.pymnts.com
November 25, 2025 at 6:17 PM
Reposted by Tim Starks
Self-replicating malware has infected almost 500 open-source packages, exposing more than 26,000 GitHub repositories in less than 24 hours. via @mattkapko.com cyberscoop.com/supply-chain...
Shai-Hulud worm returns stronger and more automated than ever before
Self-replicating malware has infected almost 500 open-source packages, exposing more than 26,000 GitHub repositories in less than 24 hours.
cyberscoop.com
November 25, 2025 at 4:46 PM
Reposted by Tim Starks
Research from Anthropic reveals that when Claude is taught to cheat in one area—such as reward hacking in coding exercises—it becomes broadly dishonest and malicious across unrelated tasks cyberscoop.com/anthropic-cl...
New research finds that Claude breaks bad if you teach it to cheat
A new paper from Anthropic found that teaching Claude how to reward hack coding tasks caused the model to become less honest in other areas.
cyberscoop.com
November 25, 2025 at 3:16 PM
Reposted by Tim Starks
DuckDuckGo now lets you filter out AI images in search results. Obviously not infallible or exhaustive but it’s a start.
How To Filter Out AI Images in DuckDuckgo Search Results - DuckDuckGo Help Pages
Learn how to use filters on DuckDuckGo Private Search to hide AI-generated images in results.
duckduckgo.com
November 25, 2025 at 2:42 PM
Reposted by Tim Starks
In a letter shared first with FedScoop, Sen. Warren and colleagues demand answers about an OIG report that found the agency’s cyber program to be ineffective due to cuts to staff and contracts. via @mattbracken.bsky.social fedscoop.com/cfpb-cyberse...
CFPB blasted by Senate Banking Democrats for ‘entirely avoidable’ cybersecurity flaws
In a letter shared first with FedScoop, Sens. Warren and Warner demand answers about an OIG report that found the agency’s cyber program to be ineffective due to cuts to staff and contracts.
fedscoop.com
November 24, 2025 at 5:11 PM
Reposted by Tim Starks
NEW: A top military intel official issued a memo this month warning Army servicemembers of foreign adversaries’ continued attempts to gather intelligence by targeting personnel - including civilians and their families - via fake companies and recruiters:
www.nextgov.com/defense/2025...
Foreign spies are targeting Army soldiers, civilians and families, official warns
Current and former federal workers, especially those with security clearances, should be aware of the attempts, an Army intelligence chief said in a November memo.
www.nextgov.com
November 24, 2025 at 8:21 PM
Reposted by Tim Starks
Reposted by Tim Starks
The agency’s brief notice also directed messaging app users to advice on how to protect themselves. via @timstarks.bsky.social cyberscoop.com/cisa-alert-d...
CISA alert draws attention to spyware’s targeting of messaging apps
The agency’s brief notice also directed messaging app users to advice on how to protect themselves.
cyberscoop.com
November 24, 2025 at 8:23 PM
Reposted by Tim Starks
Hackers stole a trove of data from a company used by major Wall Street banks for real-estate loans and mortgages, setting off a scramble to determine what was taken. The firm, SitusAMC, sent notifications to JPMorgan Chase, Citi, and other banks indicating that their customer data could be affected
Wall Street banks scramble to assess fallout from hack of real-estate data firm | CNN Business
Hackers stole a trove of data from a company used by major Wall Street banks for real-estate loans and mortgages, setting off a scramble to determine what was taken and which banks were affected, acco...
www.cnn.com
November 24, 2025 at 4:59 PM
Reposted by Tim Starks
Finally, Elon has made a change to his social media platform that I approve of: www.nbcnews.com/news/us-news...
X's new location transparency feature unleashes questions about origins of MAGA accounts
The function, which shows that a slew of MAGA-branded accounts are apparently based outside the U.S., also stirred speculative outrage over where the Department of Homeland Security account was create...
www.nbcnews.com
November 24, 2025 at 4:16 AM
Nice one here.
As SBOMs slowly progress at the federal level and in enterprises, the rise of AI coding assistants is fueling optimistic—and, some experts argue, “kind of insane”—claims about a future with vulnerability-free software.

Check out my latest CyberScoop piece. 1/2
cyberscoop.com/sbom-adoptio...
The slow rise of SBOMs meets the rapid advance of AI
Despite progress from CISA and global regulators, SBOM adoption in the private sector remains slow as experts debate if AI-driven coding will improve or undermine software security and transparency.
cyberscoop.com
November 24, 2025 at 3:16 PM
Reposted by Tim Starks
A lack of liability for software vendors is among the most pressing issues putting Britain’s economic and national security at risk, an influential committee of lawmakers warned on Monday.
Software companies must be held liable for British economic security, say MPs
A lack of liability for software vendors is putting Britain’s economic and national security at risk, an influential committee of lawmakers warned on Monday.
therecord.media
November 24, 2025 at 3:04 PM
This campaign aims to tackle persistent security myths in favor of better advice cyberscoop.com/hacklore-org...
This campaign aims to tackle persistent security myths in favor of better advice
Hacklore.org launches to debunk common cybersecurity myths and promote advice that actually keeps people safe online.
cyberscoop.com
November 24, 2025 at 3:06 PM
Reposted by Tim Starks
News: Trump has said he wants to make America the “crypto capital of the world.”

His sons’ company is now relying on a manufacturer that's under national security investigation for alleged ties to the Chinese Communist Party.

www.bloomberg.com/news/article...
Chinese Maker Behind Most of World’s Bitcoin Miners Has Been Focus of US National Security Probe
Investigators have sought to assess whether Bitmain Technologies’ products pose risks of espionage or sabotage, according to people familiar with the matter. The company says they don’t.
www.bloomberg.com
November 21, 2025 at 5:03 PM
Reposted by Tim Starks
New, by me and @lorenzofb.bsky.social: CrowdStrike has confirmed it fired a "suspicious insider" who passed screenshots of company systems to a prolific hacking group — which then went on to post them publicly.
CrowdStrike fires 'suspicious insider' who passed information to hackers | TechCrunch
Cybersecurity giant CrowdStrike denied it had been hacked following claims from a hacker group, which leaked screenshots from inside CrowdStrike's network.
techcrunch.com
November 21, 2025 at 7:11 PM
Reposted by Tim Starks
NEW: The FBI spied on a Signal group chat of NY immigrants' rights volunteers organizing court watch+ labeled activists “anarchist violent extremist actors.”

Joint FBI/NYPD report shows law enforcement accessed private planning convo of ppl monitoring ICE

Docs obtained by @propertyofthepeople.org
The FBI spied on a Signal group chat of immigration activists, records reveal
Exclusive: Agency accessed private conversations of New York ‘courtwatch’ group that was observing public hearings
www.theguardian.com
November 21, 2025 at 6:50 PM
Reposted by Tim Starks
According to NSO Group, enforcing the injunction would cause irreparable harm to its business and prevent the U.S. government from using its products.

✍️ @timstarks.bsky.social

cyberscoop.com/nso-group-wh...
NSO Group argues WhatsApp injunction threatens existence, future U.S. government work
The spyware vendor made those two arguments, among others, in a motion to stay the California court ruling.
cyberscoop.com
November 20, 2025 at 11:51 PM
Reposted by Tim Starks
The President of the United States is literally threatening opposing lawmakers with death for a video they made encouraging service members to refuse unlawful orders.
Trump posts again about Democrats, saying their behavior is “punishable by DEATH!”
November 20, 2025 at 3:33 PM
Reposted by Tim Starks
Trump used to be so good at staying just inside the outer bounds of acceptable behavior. Now he's completely disinhibited. We see that with him calling the female reporter Piggy and RT'ing calls to hang Democratic members of congress.
Trump calling for members of Congress to be hanged is not great, in my humble opinion.
November 20, 2025 at 3:56 PM
Reposted by Tim Starks
New: Ahead of a vote today that will likely rescind Biden-era cybersecurity regulations put in place after the Chinese-led Salt Typhoon hacks, dissenting FCC Commissioner Anna Gomez told CyberScoop the decision will erase “the only meaningful regulatory response to Salt Typhoon that I have seen.”
Why Anna Gomez believes the FCC is letting telecoms off easy after Salt Typhoon
In an interview, the lone dissenting voice on the panel, Commissioner Anna Gomez, told CyberScoop that rescinding the rules would let telecoms off the hook for the cybersecurity lapses that enabled th...
cyberscoop.com
November 20, 2025 at 1:53 PM
Reposted by Tim Starks
An international effort sanctioned Russia-based Media Land and took action against companies and people who helped Aeza Group evade previously issued sanctions. via @mattkapko.com cyberscoop.com/bulletproof-...
Five Eyes just made life harder for bulletproof hosting providers
An international effort sanctioned Russia-based Media Land and took action against companies and people who helped Aeza Group evade previously issued sanctions.
cyberscoop.com
November 20, 2025 at 2:11 PM
Reposted by Tim Starks
The company said the boundaries between cyber and physical attacks are dissolving as nation-states use network intrusions to aid military targeting in real time. via @mattkapko.com cyberscoop.com/amazon-cyber...
Amazon warns of global rise in specialized cyber-enabled kinetic targeting
The company said the boundaries between cyber and physical attacks are dissolving as nation-states use network intrusions to aid military targeting in real time.
cyberscoop.com
November 20, 2025 at 2:11 PM