The FBI is warning that fraudsters are using fake IC3 accounts and direct messages to target people who've already been scammed.

The Federal Bureau of Investigation's Internet Crime Complaint Center (IC3) has issued a warning regarding an increase in "recovery scams" where criminals impersonate FBI agents and IC3 employees on social media and messaging applications. These scammers specifically target individuals who have previously fallen victim to cybercrime, aiming to defraud them again.
The FBI states that these schemes are becoming more sophisticated, often featuring official-looking FBI logos and branding to enhance their credibility. Scammers create fake social media accounts, sometimes with fabricated positive reviews, to lure victims. An example provided described an account named "Reliable Scam Recovery Inc" or "Ic3 Scam Recovery Inc" that promised assistance with recovering funds lost to various online frauds, including investment, crypto, and romance scams.
These fraudulent posts contain vague but reassuring claims, such as having an "experienced recovery team" and offering "professional case assessment" and "secure and confidential support." They also make high-level promises like "investigate scam activities" and "trace transactions," implying specialized legal or technical capabilities that legitimate agencies possess.
Scammers actively monitor social media for posts from individuals who have reported a scam to the FBI or intend to do so. They then contact these victims directly, posing as FBI follow-up contacts. To further convince skeptical victims, some scammers create deepfake audio and video content depicting senior FBI officials or other recognizable public figures urging victims to submit their case through a specific link to "speed up recovery." The FBI confirms that criminals are increasingly utilizing AI-generated deepfake technology to make these messages appear authentic.
The IC3 emphasizes that it does not maintain an official social media presence and does not investigate crimes or contact victims directly via social media to recover funds. The IC3's official website explicitly states that it does not collaborate with non-law enforcement entities, such as law firms or cryptocurrency services, for fund recuperation or case investigations, and will never directly solicit information or money from victims.
To avoid falling victim to these recovery scams, the FBI advises several precautions. Individuals should never pay upfront fees to recover stolen money, as legitimate government agencies do not request advance payments for such services. Unsolicited claims from anyone offering to reverse a previous scam should be viewed with extreme suspicion. Victims should never provide remote access to their devices, share passwords, recovery phrases, identification documents, or financial information with unknown third parties, as this information can be used for identity theft or further fraud.
If a message or contact from an alleged "agent" appears in direct messages shortly after a public post about being a crime victim or reporting to the FBI, it should be assumed to be a scammer unless independently verified through official channels. Suspected scams should be reported to the IC3 at ic3.gov.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed