LIVE · cybersecurity feed
Live wire
Brevo Supply-Chain Attack Infected Over 100,000 WebsitesIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawCisco alerts customers to second actively exploited zero-day in as many daysCisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce plugin
security

Early Scattered Spider member pleads guilty to cybercrime spree

Ahmed Elbadawy pocketed massive proceeds from his crimes. Prosecutors are seeking the forfeiture of about $17.6 million in virtual currency, luxury vehicles, and a vast collection of jewelry and designer bags. The post Early Scattered Spider member pleads guilty to cybercrime spree appeared first on CyberScoop.

zeroday.news ·

Ahmed Hossam Eldin Elbadawy, a 24-year-old from Texas, has pleaded guilty to federal charges of wire fraud conspiracy and aggravated identity theft. Elbadawy, identified as an early member of the cybercrime group "Scattered Spider," entered his plea a year ago, but the details were not made public until prosecutors filed an order of forfeiture this week.

Prosecutors are seeking the forfeiture of approximately $17.6 million in assets from Elbadawy, including virtual currency, luxury vehicles, jewelry, and designer bags. Specifically, the forfeiture request includes over $14.19 million in Bitcoin, more than $3.4 million in Ethereum, and nearly $63,000 in cash. Other items listed are a lifted golf cart, three luxury vehicles, a Muhammad Ali painting, luxury watches, gold jewelry, a collection of designer bags, and 150 pairs of shoes.

Elbadawy and his co-conspirators, Noah Michael Urban and Tyler Robert Buchanan, are linked to a series of extortion attacks that occurred between at least 2021 and 2023. Urban, from Florida, was sentenced to 10 years in prison last year, while Buchanan, from Scotland, pleaded guilty to multiple cybercrimes in April and awaits sentencing.

The financially motivated Scattered Spider group, a subset of the broader "The Com" network, used social engineering tactics to obtain credentials and steal sensitive company data. Their goal was to identify high-net-worth employees with virtual currency accounts containing millions of dollars.

An indictment filed against Elbadawy and his co-conspirators in late 2024 detailed at least 12 victim companies, including three in Southern California. The victims spanned various sectors, including entertainment, telecommunications, technology, business process outsourcing, IT, cloud services, and virtual currency. Authorities identified 29 victims whose systems were compromised, leading to the theft of virtual currency from many of their wallets.

Significant thefts included nearly $6.35 million in virtual currency in September 2021, $571,000 in June 2022, and almost $1.7 million in December 2022.

Federal authorities filed charges against five individuals with ties to Scattered Spider in 2024: Elbadawy, Urban, Buchanan, Evans Onyeaka Osiebo, and Joel Martin Evans.

While early leaders of Scattered Spider have faced legal action, the broader "The Com" network has continued to evolve. The FBI describes "The Com" as having thousands of members, typically aged 11 to 25, and splintered into three main subsets: Hacker Com, In Real Life Com, and Extortion Com. These interconnected networks are involved in a range of criminal activities, including swatting, extortion, sextortion of minors, production and distribution of child sexual abuse material, violent crime, and various other cybercrimes. The terms of Elbadawy's plea agreement have not been publicly released.

ShareXLinkedInWhatsAppFacebook

More News

view all →
supply chain attackhigh

Brevo Supply-Chain Attack Infected Over 100,000 Websites

A supply-chain attack on the marketing platform Brevo, formerly Sendinblue, leveraged a compromised Cloudflare API key to inject malicious code into over 100,000 websites. The attackers initially gained access through a SAML SSO vulnerability, compromising customer accounts and exporting data. After blocking the initial breach, they returned and used a stolen Cloudflare API key to deploy a malicious Worker that modified website responses at the edge, bypassing origin server security checks and distributing malware to visitors.

security

Friday Squid Blogging: On Squid Egg Sacs

Short essay about squid egg sacs. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

ai

Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks

The new program expands Vectra AI's partner strategy as increasingly complex security environments and the growing use of AI create demand for broader AI expertise, services, and security outcomes.

CVE-2026-76460

Cisco Zero-Day Highlights API Endpoint Authentication Issues

The authentication bypass flaw CVE-2026-76460 impacts Cisco's Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score.

cloud

Saving another 100TB of RAM with math (and Rust)

Cloudflare's global network is immense but not limitless. As we look for small ways to trim our resource usage, we sometimes get lucky and we can cut significantly more. Here’s how we reduced one of our Pingora-based service's RAM usage with statistics.

vulnerability

Researchers use AI to find widespread software decoder flaw

The bug, since patched, gave attackers remote code execution privileges and access to user accounts and production environments, including Meta’s core product suite and an OpenAI software repository. The post Researchers use AI to find widespread software decoder flaw appeared first on CyberScoop.