Scammers are leveraging AI-generated deepfakes to impersonate OnlyFans creators, tricking fans into sending money through platforms like Cash App. This scam not only defrauds fans but also harms creators, who face accusations from angry followers and even threats. While legal measures are being introduced, the global nature of hosting and enforcement challenges hinder effective control.

Scammers are employing AI-generated deepfakes to impersonate OnlyFans creators, tricking fans into sending money through peer-to-peer payment platforms before disappearing. This scheme, which leverages various social media platforms, has resulted in financial losses for fans and significant distress for the creators whose identities are being stolen.
The fraud begins on platforms like TikTok, where attackers create fake accounts using photos and videos of legitimate OnlyFans creators. These accounts often feature synthetic voices to animate still images, making them appear more convincing. Viewers are then encouraged to move to direct messaging services such as Snapchat for private conversations, often under the pretense of offering exclusive content or live chats.
Once a rapport is established, the scammers request payment via Cash App, a peer-to-peer platform designed for informal transfers. The choice of Cash App is strategic, as transfers are instant and largely irreversible, making it difficult for victims to reclaim their funds once sent. After receiving payment, the scammer blocks the victim and deletes the fake account.
This type of "catfishing" has a dual impact. Fans lose money, while the real creators suffer reputational damage and potential loss of income. Some creators, like Jessieanna Campbell, have reported receiving angry messages from fans accusing them of fraud for transactions they never initiated. In more extreme cases, one creator described fans showing up at her home, leading to concerns for her personal safety.
Identifying these deepfakes can be challenging, but experts note common artifacts. For example, a TikTok video impersonating creator Elaina St. James, which animated a still photo with a cloned voice, reportedly showed distorted teeth and frozen eyebrows. These inconsistencies are often indicators of AI-generated video, particularly when the source material is limited. Malwarebytes has published a guide to help users spot deepfakes.
The issue is compounded by the international nature of the internet. While laws like the U.S. Take It Down Act criminalize non-consensual explicit content, including AI-generated material, and the EU’s AI Act requires disclosure of AI-generated images, enforcement is difficult across national borders, especially when content is hosted overseas. Research from the University of Bristol indicates that many participants continued to trust deepfake content even after being informed of its artificial nature.
This scam mirrors patterns seen in other online frauds, such as romance scams and impersonation scams involving major brands like Amazon and Apple. The underlying manipulation remains consistent: establish familiarity, create a sense of urgency, and then request payment through an irreversible channel.
To avoid falling victim, users are advised to be wary if a creator contacts them through a third-party platform and attempts to steer the conversation toward direct payment for exclusive content. It is crucial to verify any such requests through the creator's official, verified accounts before making any payments. Any request for Cash App payment from someone claiming to be a creator, particularly before any content is delivered, should be treated as a significant red flag.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed