Scammers are using fake V-Bucks offers and locker value sites to hijack Fortnite accounts.

Cybercriminals are actively deploying phishing scams targeting Fortnite players, using deceptive websites that promise various in-game rewards or account valuations to steal login credentials. These fraudulent pages, which appear frequently under different names and designs, aim to trick players into entering their Epic Games username and password on fake login portals.
The scams often take several forms. Some sites promise free V-Bucks or cash, sometimes under the guise of fake superhero collaborations. Another common variant offers to calculate the monetary value of a player's in-game locker, playing on the real-world value of rare skins and items in unofficial marketplaces. A more recent iteration leverages the legitimate $520 million settlement between Epic Games and the U.S. Federal Trade Commission (FTC), falsely claiming players are owed V-Bucks or other rewards through an "Epic Games Locker." However, the genuine settlement pays out actual dollars through the FTC's official process, and the claim window for that settlement closed in July 2025. References to an "EU Regulatory Mandate" or specific case numbers on these scam pages do not correspond to any authentic legal actions.
Regardless of the specific lure, all these fraudulent sites ultimately direct users to a fake Epic Games login page. Entering credentials on such a page hands the username and password directly to scammers. Stolen Fortnite accounts are valuable to criminals, who can use them to spend any saved payment methods, sell accounts with rare skins on underground markets, or attempt to scam the original owner's friends. Attackers may also try the same stolen credentials on other online platforms, hoping users have reused their passwords.
Fortnite remains a prime target for cybercriminals due to its massive player base, which includes approximately 110 million monthly active players and over 650 million registered accounts. The game's demographic, which includes a significant number of younger players, also contributes to its attractiveness as a target. Industry experts note that young gamers may be particularly susceptible to phishing because they spend more time on social media and might be less familiar with social engineering tactics. The game's emphasis on visible status through purchasable skins and emotes makes the idea of an account's "value" seem plausible, even though Epic Games does not offer an official tool for account valuation and selling accounts violates its terms of service.
Epic Games has confirmed that it does not offer an official tool to value accounts, nor does it conduct legitimate giveaways that require players to sign in through third-party websites. Players are advised to be skeptical of any offers that seem too good to be true and to only sign in to their Epic account directly at epicgames.com.
If a player suspects they have entered their login details on a fraudulent site, they should immediately change their Epic Games password by navigating directly to epicgames.com. It is also crucial to enable two-factor authentication (2FA) on their account to prevent unauthorized access, even if a password is stolen. Players should review their linked email for any suspicious password reset requests or login alerts and remove any unfamiliar connected devices or services from their account. If payment details were entered, contacting the card issuer and monitoring statements is recommended. Suspected phishing pages should be reported to Epic Games support and flagged in the browser. For any claims related to settlements or refunds, players should verify the information on the official regulator's website, such as ftc.gov for the Epic Games settlement.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed