A sophisticated banking fraud operation, dubbed REF6045, utilizes a PowerShell toolkit named SCMBANKER, delivered via fake CAPTCHA pages. Unlike automated attacks, this operation is manually controlled, allowing operators to monitor victim banking sessions, deploy fake warnings, and manipulate browser activity. The toolkit also facilitates the installation of commercial remote access tools for full system takeover. Researchers discovered the operation through exposed directories and archives, revealing the use of AI-generated scripts and operator misconfigurations.

A Mexican banking fraud campaign, identified as REF6045, is being actively managed by human operators who monitor infected systems and direct malicious activities. The initial infection vector involves deceptive CAPTCHA pages that trick users into executing a command, which then installs the SCMBANKER PowerShell toolkit. This toolkit, with components dating back to at least October 2025, provides operators with a comprehensive suite of tools for financial fraud.
Once SCMBANKER is deployed, operators can observe when a victim initiates a banking session. They can then lock the victim's screen with a fake bank warning, push the user towards live phone support, redirect their web browser, or even replace copied bank account numbers with their own. For complete control, the operation can also deploy commercial remote access tools.
Key aspects of the REF6045 operation include the adaptation of ClickFix delivery methods to facilitate operator-assisted banking fraud. Fake verification pages are used to stage the SCMBANKER toolkit, which offers a full fraud workflow. This includes monitoring banking activity, capturing screenshots, presenting vishing overlays, executing phishing redirects, manipulating clipboard data, and installing remote access tools.
The SCMBANKER toolkit specifically targets Mexico's financial ecosystem, encompassing retail and business banking portals, fintech companies, payment processors, cryptocurrency exchanges, investment platforms, tax authorities (SAT), and telecommunications services. The operation's tooling and targeting logic were exposed due to operator security oversights, such as open directories, a leaked web archive, and an unauthenticated file editor.
Analysis of the scripts revealed a significant number of AI-generated artifacts, suggesting the operator leveraged large language models (LLMs) in their development. Elastic Security Labs detected the operation on June 18, 2026, when telemetry indicated a host downloading suspicious PowerShell scripts from an exposed directory. Retrieving an archive from the same server provided a more complete view of the operation's web root.
The infection chain begins with a ClickFix fake CAPTCHA page, which presents an image challenge before instructing the victim to run a command. This command downloads a batch script disguised as a validation file. The script then initiates a series of malicious actions, including launching a fake Windows Update screen in Microsoft Edge's kiosk mode to distract the victim.
To ensure elevated privileges, the malware checks for administrator rights and, if absent, prompts the user with a social-engineered message to update their system, repeatedly relaunching itself with administrative privileges until the User Account Control (UAC) prompt is accepted. Once elevated, the mouse cursor is confined to a tiny area on the screen, preventing user interaction and further facilitating the background download of the SCMBANKER toolkit.
Malicious scripts and binaries are downloaded individually via bitsadmin from an exposed file server to a public directory. Persistence is established through the Windows Registry's Run key and the Startup folder, ensuring the toolkit launches on subsequent logons. The operation also includes a mechanism to force a reboot, which then triggers the persistence routines.
The SCMBANKER toolkit's master launcher is a VBScript that initiates various modules in parallel. These modules handle tasks such as process rotation, delayed execution of monitoring and redirect scripts, C2 communication, remote access tool installation, clipboard hijacking for account numbers, and arbitrary PowerShell command execution. An invisible cursor utility is also deployed to further hinder user interaction.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed