LIVE · cybersecurity feed
Live wire
CVE-2026-69836 · Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code ExecutionManic: The Android Malware That Exfiltrates Data Even When the Phone Is OfflineHackers poison arrayref Rust crate to push infostealer malwareNSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCsSenators press TikTok over withholding of safety features for some usersAI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical InfrastructureChatGPT for Teens tackles risky chats and homework shortcutsCritical Elementor Pro bug exposes WordPress sites to RCE attacksNew Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat DataFrequently asked questions about the active threat to Siemens S7 Series PLCs
finance

A $25 template helped scammers build hundreds of phantom bank domains

A phrase on a suspicious website turned into an investigation of phantom banks built to support scams, according to new research from Allure Security. Molly DeQuattro, the company’s VP of Operations, was reviewing a domain that resembled the brand of one of its financial services clients. The page carried none of that client’s branding. It presented an unrelated bank instead. One phrase caught her

zeroday.news ·

Cybersecurity researchers have uncovered a network of hundreds of fraudulent banking websites, many of which share common elements from a $25 commercial website template. The investigation, initiated by Allure Security, began when a researcher noticed a suspicious domain impersonating a client's brand, but displaying an unrelated bank with the phrase "one of the largest digital banking providers." A search for this specific phrase in public website source code revealed approximately 2,200 matching domains.

Further analysis by the research team revealed that nearly half of these domains, specifically 1,095, were active websites. Of those, 838 still contained the initial search phrase. A striking 97% of these 838 sites, totaling 810, retained components of "Cuex," a front-end template designed for currency exchange and digital banking, which was available for $25. Additionally, 94% of the sites utilized the Laravel PHP framework for functions like logins and session management, and 90% featured a misspelled heading from the template, "Curreny Charts."

The researchers describe this pattern as "legitimacy stacking," where various elements such as banking interfaces, dashboards, investment product details, corporate information, and support contacts are layered to create a credible appearance for an invented financial institution. Among the 838 identified sites, 770 presented login pages, 767 set session cookies, and 729 included anti-forgery tokens, indicating they were designed to collect and store user data.

This infrastructure aligns with a common fraud model where victims are introduced to a seemingly legitimate financial institution by a scammer, such as a fake broker, romantic interest, or loan agent. The fraudulent portal then provides a persistent interface to display fabricated accounts, balances, investment gains, and details about transfers, holds, or withdrawal issues, lending credibility to the scam.

One particular site, branded as "Classtands Crest," provided a crucial lead due to a sloppy copy-paste error. Its account creation page's source code still contained the title "Create an Account- Remedy bank." More significantly, the registration form on this site was configured to send submitted data to a separate domain, remedycodes[.]site. This "Remedy" address had previously been linked to two other sites flagged for suspected fraud.

Researchers recommend that individuals investigating potential phantom banks look for several tell-tale signs. These include the "Curreny Charts" typo, shared website paths and code, matching cookies, identical contact details, and registration forms that direct data to the same external destination. They also advise independently verifying any claims made by the financial institution and preserving evidence such as page content, timestamps, hashes, and source code to support their findings. The investigation highlights how a single copied sentence can expose a large network of fraudulent sites, and understanding their relationships requires tracing the underlying application and its "legitimacy stack."

finance
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

CVE-2026-69836high

Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution

Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer action is required. The vulnerability, tracked as CVE-2026-69836 (CVSS score: 10.0), is a case of remote code execution impacting the tech giant's cloud-based identity and access management service. It was previously called Azure Active Directory

vulnerability

Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5.

Secure Workload Software has five nasty flaws and even SaaS users have updates to install

patch

Nearly half of enterprises have no one leading PQC migration

Enterprises believe they are prepared for the security challenges posed by quantum computing, but gaps in ownership, testing and visibility could complicate their transition to post-quantum cryptography (PQC), according to new research from Axiad. Who owns PQC migration? (Source: Axiad) Organizations need to know where certificates, cryptographic keys and algorithms are used before they can plan a

security

Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st)

In every MFA rollout, there will come a time where you think you are closing in on "done", and some automation to list what&#;x26;#;39;s left would be handy. Something quicker than scrolling through the web interface through thousands of accounts ... This is that method. Also, remember when we discussed yesterday about the beta graph commands in the Microsoft.Graph.Beta library? We&#;x26;#;39;ll u

security

Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays, (Fri, Aug 21st)

One thing that folks never seem to do after "going to the CLOOOOUUUUD" is to look at their logs, logs that they would have checked daily when things were on premise. One log that really bears looking at is the log of successful and failed logins. the call for that is: