Sign in

jon greig

@jgreig.bsky.social
951 followers 285 following 702 posts

cybersecurity reporter for The Record. formerly: zdnet, techrepublic, blavity, haitian times, cambodia daily — send tips to jonathangreig11@protonmail.com or signal: jgreig.51

PostsRepliesMedia
jon greig @jgreig.bsky.social · 1h
Vulnerability disclosures doubled between January and August, reaching a new peak of 10,740 last month, Google’s Threat Intelligence Group said Wednesday The number of distinct vulnerabilities disclosed and exploited from Jan-Aug surpassed the totals for all of 2025 therecord.media/google-vulne...
therecord.media
Google: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation
Vulnerability disclosures continue to skyrocket, doubling over the course of the year to more than 10,000 each month, Google researchers warned.
002
jon greig @jgreig.bsky.social · 29/09/2026
The Arizona Supreme Court announced Friday that the state’s court system was attacked by hackers who stole the personal information of “many Arizonans.” therecord.media/arizona-supr...
therecord.media
Arizona Supreme Court says hackers stole residents’ personal data
A spokesperson for the court system told Recorded Future News that the incident did not involve ransomware and the hackers have not issued ransom demands for the stolen data as of Monday.
001
jon greig @jgreig.bsky.social · 25/09/2026
Kiteworks said it “received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some...systems for customers.” They urged customers to shut off the tool for six hours on Saturday therecord.media/kiteworks-ur...
therecord.media
Kiteworks urges customers to stop using platform after warning from federal intelligence agencies
Frank Balonis, CISO at Kiteworks, told Recorded Future News that the company “received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to ...
000
jon greig @jgreig.bsky.social · 25/09/2026
The CEO of Bitget said North Korean hackers were behind a $387 million theft on Thursday therecord.media/crypto-ceo-a...
therecord.media
Crypto CEO accuses North Korea of stealing $387 million from Bitget platform
The CEO said the company has a User Protection Fund that has over $464 million and those funds will be used to cover the losses.
000
jon greig @jgreig.bsky.social · 24/09/2026
One of the key figures behind the Rydox cybercriminal marketplace pleaded guilty this week to aggravated identity theft and money laundering charges therecord.media/rydox-crimin...
therecord.media
Rydox cybercriminal marketplace operator pleads guilty following co-conspirator brothers’s deportation
Ardit Kutleshi, 28, was extradited from his home country of Kosovo last year after prosecutors accused him and his older brother of running Rydox — an illicit platform used by cybercriminals to sell s...
000
jon greig @jgreig.bsky.social · 24/09/2026
Astrana became the latest healthcare tech company to report a data breach to the SEC. The company's software and tools are used across thousands of private practices across the US therecord.media/astrana-cybe...
therecord.media
Astrana latest healthcare tech firm to report data breach to SEC
The healthcare firm Astrana warned regulators that hackers accessed confidential information by impersonating company personnel.
000
jon greig @jgreig.bsky.social · 23/09/2026
An Armenian ransomware operator for Ryuk was sentenced to two years in prison after helping the gang launch hundreds of attacks therecord.media/ransomware-r...
therecord.media
Ryuk ransomware operator gets 2-year sentence after extorting victims for $1.2 million
An Armenian national and member of the Ryuk ransomware gang was sentenced to two years in federal prison for his role in launching attacks.
011
jon greig @jgreig.bsky.social · 23/09/2026
The FBI is investigating a breach perpetrated by the ShinyHunters cybercriminal group, which claimed it stole personal information on all FBI employees as retaliation for a May flash notice from the agency that they believe is innacurate therecord.media/fbi-investig...
therecord.media
FBI investigating alleged ShinyHunters breach of its jobs site
The ShinyHunters cybercriminal organization on Tuesday replaced agency images on the FBIjobs.gov site with a photo of a Pokemon that has become the group’s defacto mascot.
031
jon greig @jgreig.bsky.social · 22/09/2026
Two men were arrested in the UK for their alleged involvement in EvilTokens - an AI tool that helped cybercriminals comb through breached inboxes and provide the easiest options for how to scam people or steal their money therecord.media/two-arrested...
therecord.media
Two arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminals
Available on Telegram for a $1,500 initiation fee and a recurring monthly $500 subscription, EvilTokens provided cybercriminals with artificial intelligence tools enabling them to compromise accounts,...
000
jon greig @jgreig.bsky.social · 18/09/2026
Vietnam, Laos, Pakistan and Argentina arrested several local collaborators and seized funds tied to North Korea's IT worker campaign Chinese officials also kicked several North Koreans out of the country for espionage therecord.media/nations-take...
therecord.media
Nations take action on North Korean IT workers after UN report
A report published Wednesday said that as of July, Vietnam, Laos, Pakistan and Argentina took meaningful steps to respond to allegations involving North Korea listed in an October study.
000
jon greig @jgreig.bsky.social · 16/09/2026
The NightmareStresser platform used to disrupt hundreds of educational institutions, government agencies and other organizations was seized on Tuesday by the Justice Department therecord.media/doj-takes-do...
therecord.media
DOJ takes down NightmareStresser DDoS platform
The DOJ announced the court-authorized takedown alongside Canadian officials, but declined to say if any arrests were conducted as part of the operation.
010
jon greig @jgreig.bsky.social · 15/09/2026
Law enforcement agencies in Norway are investigating whether Norwegian telecom Telenor aided crimes against humanity through its work providing customer data to the brutal military regime currently governing Myanmar therecord.media/norway-inves...
therecord.media
Norway announces investigations into telecom Telenor’s work with Myanmar junta
Oslo-based Telenor potentially enabled crimes against humanity and violated sanctions in its dealings with the military regime that took over Myanmar in 2021, Norwegian authorities said.
0289
jon greig @jgreig.bsky.social · 15/09/2026
CenterPoint Energy warned the SEC that hackers stole customer information after a cybercriminal offered the data for sale last week therecord.media/centerpoint-...
therecord.media
Electric and gas utility CenterPoint Energy warns of data breach after dark web post
Houston-based CenterPoint Energy notified federal regulators about an incident that exposed some customer data on the dark web.
011
jon greig @jgreig.bsky.social · 10/09/2026
The firm behind the phishing email blasts, Brevo, said 138 company accounts were breached 6 were used to send mass phishing emails and the attackers exported contacts for 43 other companies therecord.media/trezor-bitbo...
therecord.media
Multiple crypto companies warn customers of phishing emails after alleged provider breach
Subscribers to newsletters from Trezor, CoinTracking and BitBox received corrupted messages through an email provider that all three companies use.
000
jon greig @jgreig.bsky.social · 03/09/2026
haitiantimes.com/2026/09/03/o...
haitiantimes.com
Where Ohio Haitians can find legal help, food and other support
Find legal help, food, bus passes and other resources available to Haitian families in Springfield and across Ohio.
000
jon greig @jgreig.bsky.social · 01/09/2026
Nutex confirmed it is being extorted after patient and employee data was stolen by The Gentlemen ransomware gang therecord.media/nutex-health...
therecord.media
Healthcare facilities operator Nutex says patient, employee data stolen in August incident
Cybercriminals breached company data and made an extortion attempt with it, Houston-based Nutex Health said in a filing with federal regulators.
000
jon greig @jgreig.bsky.social · 01/09/2026
Five men pleaded guilty to involvement in an ATM jackpotting scheme after trying to install malware on ATMs in Kansas therecord.media/kansas-atm-j...
therecord.media
Five plead guilty in latest federal ATM jackpotting case
Federal law enforcement continued to warn about ATM jackpotting gangs as it announced guilty pleas from five Venezuelan nationals.
021
jon greig @jgreig.bsky.social · 31/08/2026
McKesson said on Saturday that the hackers exfiltrated data associated with customers in their oncology and surgical business units Shinyhunters took credit for the attack late on Friday therecord.media/mckesson-cyb...
therecord.media
Pharmaceutical giant McKesson warns of 'service degradation' following cyberattack
The pharmaceutical and healthcare technology company McKesson informed regulators it is in the early stages of investigating a cybersecurity incident involving an unnamed third-party application.
020
jon greig @jgreig.bsky.social · 27/08/2026
The ATF said it recently had a “major” cyber incident. The agency appeared on the Qilin ransomware leak site on Wednesday An ATF spox told me the issue “involved a standalone computer system containing information about targets of ATF investigations.”  therecord.media/doj-atf-cybe...
therecord.media
DOJ firearms agency says hackers breached system containing investigation targets
The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed it experienced a cyberattack on a system containing investigation information, as a prolific ransomware gang claimed to have carried o...
000
jon greig @jgreig.bsky.social · 26/08/2026
The DOJ said today that Chinese hackers breached the Federal Reserve, NASA, the US Senate, DOE and more since 2018 using a tool called QScan therecord.media/qscan-qtrout...
therecord.media
US takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and Senate
The DOJ said it disrupted Chinese state-backed tools used to scan, infect and exploit IoT devices for attacks on federal agencies and multiple industries.
010
jon greig @jgreig.bsky.social · 25/08/2026
After an alleged Akira ransomware attack last year, employee benefits tech provider Paylogix said thousands of people had SSNs, financial data, healthcare info and even digital signatures stolen by cybercriminals therecord.media/paylogix-cyb...
therecord.media
Employee benefits platform Paylogix says hackers stole financial and health
The benefits management firm Paylogix told regulators that hackers stole sensitive information on tens of thousands of people from its systems.
010
Reposted by jon greig
Ron Bowes @iagox86.bsky.social · 25/08/2026
My first advisory!
071
jon greig @jgreig.bsky.social · 25/08/2026
The U.S. sanctioned several Iranian nationals on Monday for cyberattacks on critical infrastructure just days after reports emerged of a cyber intrusion on a small power plant in the United Kingdom therecord.media/iran-cyberat...
therecord.media
US sanctions Iranian cyber actors as UK discloses power plant attack
The U.S. sanctioned several Iranian nationals for cyberattacks on critical infrastructure just days after reports emerged of a cyber intrusion on a small power plant in the United Kingdom.
002
jon greig @jgreig.bsky.social · 24/08/2026
Members of Congress demanded a government watchdog examine the effect Trump staffing cuts have had on CISA's ability to protect critical infrastructure from cyberattacks therecord.media/lawmakers-ca...
therecord.media
Lawmakers call for investigation into impact of CISA staffing cuts
Lawmakers say little is known about how recent cuts have impacted CISA and how the knowledge that was lost has been replaced.
011
jon greig @jgreig.bsky.social · 21/08/2026
US Bank said a recent data theft claim from LockBit was traced back to a "fourth party" therecord.media/us-bank-says...
therecord.media
U.S. Bank says breach claims related to fourth-party incident
The bank said there is no evidence that its own systems, networks or data repositories were compromised.
000
jon greig @jgreig.bsky.social · 21/08/2026
Canada’s largest pediatric health center suffered a recent cybersecurity incident that exposed the personal information of current and former employees therecord.media/canada-hospi...
therecord.media
Canada’s Hospital for Sick Children attacked by cybercriminals again as employee data stolen
The Hospital for Sick Children — which was hit in a ransomware incident in 2022 that disabled some of its systems — released a statement on Thursday warning of a data theft incident they believe is ti...
000
jon greig @jgreig.bsky.social · 19/08/2026
Federal agencies said there is an “active threat” targeting the Siemens PLCs of critical infrastructure organizations using AI-generated exploit scripts, in what they called an “evolution” in capabilities therecord.media/nsa-fbi-warn...
therecord.media
NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology
The National Security Agency (NSA), FBI and other federal agencies said the campaign is targeting Siemens S7 Series PLCs and was being fueled by “AI-assisted development” alongside exploitation of kno...
001
jon greig @jgreig.bsky.social · 18/08/2026
The FBI and CISA updated an advisory on the #Medusa ransomware to say that more than 500 organizations have been attacked by the group The group was responsible for a devastating attack on the largest hospital system in Mississippi earlier this year therecord.media/more-than-20...
therecord.media
More than 200 victims of Medusa ransomware identified over the last year, CISA says
The Cybersecurity and Infrastructure Security Agency (CISA) and FBI updated an advisory on the group initially released in March 2025 — writing that as of April 2026, Medusa actors have hit more than ...
001
jon greig @jgreig.bsky.social · 18/08/2026
One of the largest universities in Texas is facing a wide range of disruptions following a cyberattack announced on Monday morning therecord.media/university-o...
therecord.media
University of Texas forced to take systems offline in San Antonio after cyberattack
The University of Texas at San Antonio, which serves 40,000 students across six campuses, said its IT team identified threat activity on its academic campus over the weekend and took some systems, inc...
020
jon greig @jgreig.bsky.social · 17/08/2026
Controversial debt consolidation firm Heights Finance said hackers stole SSNs, banking info and more during a May 2026 incident Nearly 750,000 people were affected therecord.media/financial-in...
therecord.media
Nearly 750k had financial info, SSNs leaked in South Carolina loan company breach
The breach affected anyone who received a loan through the company or inquired about a loan product through a third party.
000
jon greig @jgreig.bsky.social · 13/08/2026
The Trump admin wants to enlist cyber firms to surveil and hack cybercriminals with oversight by DOJ + DHS The memo says they will not sanction any operation that results in loss of life or “rise to the level of use of force or armed attack under international law.” therecord.media/trump-cyber-...
therecord.media
Trump taps cyber firms to go on offensive against criminals
The Trump administration will allow private companies to launch attacks on cybercrime organizations, the White House announced.
000
jon greig @jgreig.bsky.social · 12/08/2026
CISA gave federal agencies two weeks to patch a Microsoft bug that researchers said is being used in a North Korean campaign targeting people applying to jobs in the defense industry therecord.media/cisa-gives-f...
therecord.media
CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign
Researchers disclosed the bug to Microsoft after examining a long-running campaign by North Korean hackers to exploit the job application process.
031
jon greig @jgreig.bsky.social · 11/08/2026
Municipalities across 4 states are dealing with cyberattacks that damaged critical services Suisun City in CA declared a state of emergency after a recent cyber incident therecord.media/cyberattacks...
therecord.media
Local governments in four states dealing with cyberattacks that have shut down services
Municipalities in California, Oklahoma, Wisconsin and Texas are all recovering from disruptive cyberattacks that have affected government operations.
030
jon greig @jgreig.bsky.social · 11/08/2026
The US and South Korea partnered on an advisory about Gunra, which is built off the Conti code and has been attacking orgs since 2025 therecord.media/ransomware-s...
therecord.media
FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure
The Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned.
000
jon greig @jgreig.bsky.social · 06/08/2026
A State Department official claimed today that Trump raised the SE Asia cyber scam compound issue with Chinese President Xi directly He did not say how Xi responded therecord.media/trump-xi-sou...
therecord.media
State Department says Trump raised cyber scam compound issue with Xi
President Donald Trump has talked with Chinese President Xi Jinping about Southeast Asian scam compounds, a State Department official told senators at a hearing on the transnational issue.
001
Reposted by jon greig
Allan “Ransomware Sommelier” Liska @ransomwaresommelier.com · 05/08/2026
This seems bad…is potentially disrupting water services bad? Cyberattacks on water systems expand to 12 states as South Dakota, Georgia announce incidents Welcome back to our hell @jgreig.bsky.social!
therecord.media
Cyberattacks on water systems expand to 12 states as South Dakota, Georgia announce incidents
Water utilities in at least 12 states have reported cyberattacks on their operational technology, as the scope of a campaign allegedly linked to Iranian hackers continues to grow.
23116
jon greig @jgreig.bsky.social · 05/08/2026
Back from paternity leave! The Snowflake hacker pleaded guilty on Wednesday. He's facing 32 years in prison therecord.media/guilty-plea-...
therecord.media
Canadian man pleads guilty to Snowflake hacks that led to 165 breaches
A 26-year-old from Ontario faces as many as 32 years in prison after pleading guilty to fraud, identity theft and conspiracy charges related to the 2024 hacks of cloud platform Snowflake.
120
Reposted by jon greig
Allan “Ransomware Sommelier” Liska @ransomwaresommelier.com · 20/05/2026
$388 million???!!! Texas, Florida top list of states reporting millions of dollars lost through crypto ATMs Via @jgreig.bsky.social & @therecordmedia.bsky.social
therecord.media
Texas, Florida top list of states reporting millions of dollars lost through crypto ATMs
In most complaints, victims said they were given detailed information by fraudsters on how to take money from their bank account, where to find a cryptocurrency kiosk and how to send the funds.
311
Reposted by jon greig
Joe Warminsky @jwarminsky.bsky.social · 04/06/2026
if you’re truly a Knicks fan, you get the KNICKS IN 4 tattoo *tonight*
23810
Reposted by jon greig
Joe Warminsky @jwarminsky.bsky.social · 03/06/2026
Nas voice: “Don’t say the tarp’s off / Say the (man) titties is out” www.nytimes.com/athletic/732...
nytimes.com
MLB Tarps Off craze has awakened ‘Baseball Heaven’ with the bare truth (Gift Article)
The shirtless MLB movement feels like a miracle drug for boredom, a long time coming for even baseball’s most traditional fan base.
012
jon greig @jgreig.bsky.social · 22/05/2026
CISA made a it a bit easier for people outside the government to report exploited bugs to CISA's KEV catalog The agency announced a new portal where experts can report exploited vulnerabilities as long as they provide evidence therecord.media/cisa-to-allo...
therecord.media
CISA to allow researchers to report vulnerabilities to exploited bugs catalog
The Cybersecurity and Infrastructure Security Agency (CISA) announced the creation of a nomination form on Thursday that they said enables “researchers, vendors, and industry partners” to report bugs ...
010
Reposted by jon greig
jon greig @jgreig.bsky.social · 15/05/2026
CISA said all federal agencies have until Sunday to patch CVE-2026-20182, the latest Cisco SD-WAN bug exploited by nation-state actors. It was discovered by @rapid7.com, which said it "behaves like a master key therecord.media/cisa-orders-...
therecord.media
CISA orders all federal agencies to patch exploited bug in Cisco SD-WAN systems by Sunday
Cisco released a patch for the vulnerability on Thursday, writing in an advisory that it could “allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges ...
011
Reposted by jon greig
Allan “Ransomware Sommelier” Liska @ransomwaresommelier.com · 15/05/2026
The good news is we all have increased budget AND staff to keep up with patching all these newly discovered vulnerabilities…oh wait. Microsoft on pace to break annual vulnerability record as AI-driven patch wave takes hold Via @alexmartin.bsky.social & @therecordmedia.bsky.social
therecord.media
Microsoft on pace to break annual vulnerability record as AI-driven patch wave takes hold
Five months into 2026, Microsoft has already patched more than 500 vulnerabilities — although the exact monthly count varies depending on whether analysts include Edge, Chromium and fixes shipped earl...
062
Reposted by jon greig
Allan “Ransomware Sommelier” Liska @ransomwaresommelier.com · 07/04/2026
Massachusetts hospital turning ambulances away after cyberattack via @jgreig.bsky.social & @therecordmedia.bsky.social
therecord.media
Massachusetts hospital turning ambulances away after cyberattack
Signature Healthcare and Signature Healthcare Brockton Hospital said on Monday that the cyber incident is impacting many of their information systems.
041
Reposted by jon greig
Allan “Ransomware Sommelier” Liska @ransomwaresommelier.com · 17/04/2026
Interesting choice with the number of CVEs surging… NIST to limit work on CVE entries as submissions surge via @jgreig.bsky.social & @therecordmedia.bsky.social
therecord.media
NIST to limit work on CVE entries as submissions surge
NIST said it will only add details and information to the records of vulnerabilities that meet a certain threshold — changing a longstanding mission to categorize every CVE, which stands for cybersecu...
161
Reposted by jon greig
Allan “Ransomware Sommelier” Liska @ransomwaresommelier.com · 23/04/2026
North Korean hackers siphon more than $12 million from crypto users in sprawling campaign Via @jgreig.bsky.social & @therecordmedia.bsky.social
therecord.media
North Korean hackers siphon more than $12 million from crypto users in sprawling campaign
Researchers said the group stole up to $12 million in cryptocurrency in the first three months of 2026 through malware attacks on personal devices.
041
Reposted by jon greig
Allan “Ransomware Sommelier” Liska @ransomwaresommelier.com · 02/05/2026
Double it, at least. Cyber incident responders who carried out ransomware attacks given 4-year sentences Via @jgreig.bsky.social & @therecordmedia.bsky.social
therecord.media
Cyber incident responders who carried out ransomware attacks given 4-year sentences
Two cybersecurity incident responders who abused their positions to carry out covert ransomware attacks were sentenced to four years in prison.
055
Reposted by jon greig
Allan “Ransomware Sommelier” Liska @ransomwaresommelier.com · 05/05/2026
Conti, Akira ransomware affiliate given 8-year sentence via @jgreig.bsky.social & @therecordmedia.bsky.social
therecord.media
Conti, Akira ransomware affiliate given 8-year sentence
Deniss Zolotarjovs pleaded guilty in July 2025 to money laundering and wire fraud charges after being arrested in the country of Georgia.
163
Reposted by jon greig
Allan “Ransomware Sommelier” Liska @ransomwaresommelier.com · 05/05/2026
The list of schools impacted has already been published by ShinyHunters...not sure how many students are going to be impacted by this. via @jgreig.bsky.social & @therecordmedia.bsky.social
therecord.media
Educational company Instructure reports cyber incident
By Saturday, Infrastructure’s chief information security officer Steve Proud confirmed that the hackers gained access to information about users at some educational institutions, including names, emai...
064
jon greig @jgreig.bsky.social · 15/05/2026
CISA said all federal agencies have until Sunday to patch CVE-2026-20182, the latest Cisco SD-WAN bug exploited by nation-state actors. It was discovered by @rapid7.com, which said it "behaves like a master key therecord.media/cisa-orders-...
therecord.media
CISA orders all federal agencies to patch exploited bug in Cisco SD-WAN systems by Sunday
Cisco released a patch for the vulnerability on Thursday, writing in an advisory that it could “allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges ...
011