Pacific Security Labs
banner
pacificseclabs.bsky.social
Pacific Security Labs
@pacificseclabs.bsky.social
A cybersecurity research firm based in the Pacific North West. Featuring cybersecurity news, updates & information.
🧵1/2: BreachForums stepped into the vacuum after RaidForums’ fall, turning stolen databases and credentials into a fast, English-language retail market that sped the path from hack to identity theft.
September 18, 2025 at 10:42 PM
1/2: China uses cyberspace to gain leverage by mapping and quietly occupying the networks that carry communications and run utilities. Salt Typhoon targets telecom routers across many countries, exploiting known flaws to secure durable, large-scale visibility.
September 13, 2025 at 7:14 PM
Independent researcher Marek Tóth demonstrated a new “DOM-based extension clickjacking” attack in which a malicious site makes the UI injected by password-manager extensions invisible and, with as little as one click.
August 22, 2025 at 5:00 AM
At Black Hat USA 2025 (Aug 6–7), researchers warned that today’s AI agents and LLM-powered tools are far too easy to abuse.

Learn more from this fascinating summary from SCWorld about various AI vulnerabilities presented at the Black Hat USA 2025 event: www.scworld.com/news/sloppy-...
Sloppy AI defenses take cybersecurity back to the 1990s, researchers say
The startling lack of good security practices around AI has cybersecurity veterans wondering which decade we're living in.
www.scworld.com
August 21, 2025 at 5:04 AM
1/4: Jonathan Kamens, the former cybersecurity lead for the Department of Veterans Affairs' website, has warned that the Department of Government Efficiency (DOGE) poses a serious threat to the security of veterans' sensitive data.
February 26, 2025 at 9:49 PM
1/3: Bybit, a major cryptocurrency exchange, has suffered what is now the largest crypto heist in history, losing over $1.5 billion in ETH and stETH from one of its Ethereum cold wallets.
February 22, 2025 at 9:56 AM
1/2: The UK government has secretly ordered Apple to create a backdoor allowing access to all encrypted iCloud content worldwide, according to sources speaking to The Washington Post.
February 11, 2025 at 4:48 AM
1/4: In 2024, ransomware revenues fell by about 35%, dropping from $1.25 billion in 2023 to roughly $813 million. This decline was driven by aggressive law enforcement actions, enhanced international cooperation, and a growing reluctance among victims to pay ransoms.
February 7, 2025 at 7:31 AM
1/2: When Anthony Deyoe discovered he was a victim of identity theft, he followed all the right steps—contacting credit bureaus, freezing his credit, and securing his accounts. But instead of stopping the fraud, it made things worse.
February 5, 2025 at 10:06 PM
Elon Musk, the world's richest man is in the midst of a hostile takeover of USAID, GSA, and the Treasury, and is now calling for the prosecution of journalists and internet users who have exposed the situation and the people involved.
February 3, 2025 at 8:15 PM
1/3: Elon Musk’s growing control over federal government systems is raising major cybersecurity concerns. A group of young, mostly inexperienced engineers—some barely out of college—now have access to critical IT infrastructure, including the Treasury Department’s payment system.
February 3, 2025 at 7:37 PM
1/3: Dover Mayor Robin Christiansen has declared a state of emergency following reports of a potential cybersecurity breach that may compromise city IT systems, including emergency services, utilities, and personal data of employees and customers.
January 30, 2025 at 9:17 PM
1/3: Wiz Research recently discovered a major security lapse at DeepSeek, a Chinese AI startup known for its advanced reasoning model, DeepSeek-R1. A publicly accessible ClickHouse database, completely unprotected by authentication, was found exposing highly sensitive information.
January 30, 2025 at 7:22 AM
1/3: Researchers at the Florida Institute for Cybersecurity Research have uncovered 119 vulnerabilities in LTE and 5G core network implementations, affecting both open-source and proprietary systems used in commercial deployments.
January 29, 2025 at 2:52 AM
1/3: Russian hackers have found a new way to break into secure networks—by hopping between Wi-Fi signals like stepping stones.
January 28, 2025 at 10:48 PM