Cybercrime has become a commercialized ecosystem where criminals can buy or rent nearly every capability needed to launch sophisticated attacks. These services provide anonymity, plausible deniability, and access to short-lived infrastructure that is difficult to detect, attribute, and disrupt, enabling low-skilled actors to operate at scale, according to the Infoblox 2026 Threat Landscape Report.

Cybercrime has evolved into a sophisticated, commercialized ecosystem where nearly every component needed to launch advanced attacks is available for purchase or rent. This model provides anonymity and plausible deniability to threat actors, granting them access to ephemeral infrastructure that is challenging to detect, attribute, and disrupt. This enables even less skilled individuals to operate at scale, according to the Infoblox 2026 Threat Landscape Report.
The report highlights that cybercrime is becoming increasingly efficient, automated, and difficult to counter, driven by economic factors and the emergence of frontier AI. The distinction between financially motivated and state-sponsored actors has blurred within this complex economy, allowing criminals to evade disruption through segmentation and the adoption of commodity services. The cybercrime ecosystem continues to expand and specialize, with profits attracting more participants, enabling attackers to evolve more rapidly than defenders.
AI is playing a significant role in automating reconnaissance, generating highly convincing lures, and accelerating the speed and scale of attacks. High-profile individuals, including executives, are particularly vulnerable as threat actors exploit their identities for impersonation fraud, business email compromise (BEC), and social engineering schemes. Service providers and telecommunications companies are also at risk, as their platforms and infrastructure are frequently abused to facilitate these attacks.
Cybercrime services encompass marketplaces for various illicit activities, including "pig-butchering" scam operators, AI-generated lures, Android banking trojans, and infrastructure supporting illegal gambling operations. One observed Android banking trojan attack chain demonstrated the ability to capture one-time passwords, device fingerprints, contacts, and facial biometrics, allowing criminals to steal complete digital identities and sustain account compromise and fraud.
Scam campaigns leveraging DCloud-based infrastructure include fake cryptocurrency exchanges, pig-butchering schemes, phishing sites, wallet drainers, gambling portals, and fraudulent investment platforms. These campaigns primarily target consumers but can expose enterprise networks when employees encounter malicious links during personal browsing on corporate or personal devices.
To evade detection, attackers rely on infrastructure that appears legitimate or is concealed. They profile visitors based on device, location, and behavior, delivering scams or malware only to intended targets while showing harmless content to security researchers and automated scanners. Cloaking and traffic distribution systems further hide malicious activity behind trusted advertising domains and redirect chains, reducing visibility into campaigns. Bulletproof hosting providers support these operations by prioritizing anonymity, ignoring abuse reports, and enabling rapid infrastructure migration, allowing phishing, fraud, malware, and other illicit activities to persist.
Threat actors frequently abuse trusted infrastructure because it increases success rates, reduces costs, conceals activity, improves resilience, and can provide access to users or networks that would otherwise be difficult to reach. Fake CAPTCHA scams, for instance, trick mobile users into sending expensive international text messages through fraudulent human-verification pages. One observed instance generated approximately 60 messages, costing the victim around $30, by combining social engineering with automated infrastructure to generate revenue at scale.
Brand impersonation and fraud pose significant risks to organizations through their customers. Once customer credentials and personally identifiable information are leaked into the criminal ecosystem, attackers may reuse the data to extort organizations, develop new lures, and stage further attacks. Criminals create phishing pages that closely resemble legitimate websites, replicating branding, logos, and user experiences rather than solely relying on domains containing the impersonated company's name. Selective targeting leaves fewer traces, making campaigns more challenging for security teams, email providers, and researchers to identify.
The widespread use of smartphones for both work and personal activities is exploited by threat actors who develop personalized lures that appear relevant and trustworthy. Short-lived campaigns help attackers evade blocklists and detection by rotating domains, hosting providers, and URLs; some phishing pages remain active for less than 24 hours, significantly reducing the window for investigation.
New technologies and expanding attack surfaces create security gaps before organizations can establish adequate monitoring and protection. Security teams must identify ownership, collect data, build detections, update policies, and train staff, providing attackers with time to exploit these vulnerabilities. Residential proxy services route internet traffic through everyday devices such as phones, laptops, and smart TVs, making malicious activity appear to originate from legitimate residential IP addresses, which complicates blocking and attribution. These proxies are often embedded in mobile applications and software development kits, and organizations may not realize that employee devices have become proxy endpoints, with the resulting traffic appearing as legitimate application activity.
Browser push-notification schemes trick users into granting permissions through fake CAPTCHAs, cookie banners, and verification prompts. Once permission is granted, attackers gain a persistent communication channel to the victim's device. Some victims have reported receiving over 140 notifications per day promoting investment scams, gambling sites, fake antivirus alerts, government impersonation scams, and other fraudulent content.
Organizations also face risks from dangling CNAME records. As cloud infrastructure changes, some CNAME records may persist after cloud services or hostnames are removed. Attackers can claim abandoned cloud resources, including Azure Web Apps and GitHub Pages sites using the same hostname, and take over trusted subdomains. During the Infoblox EASM early access program, one-third of identified dangling CNAMEs were found to be easy or trivial to take over. Attackers can then use these subdomains for phishing, malware delivery, or other malicious activities.
Threat actors are also targeting software supply chains to reach a large number of victims through trusted software, libraries, and development tools. In 2026, TeamPCP reportedly compromised Trivy, KICS, LiteLLM, and the Telnyx Python SDK. Access to software used by developers and security teams creates opportunities to steal credentials and spread malicious code through downstream environments.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed