Leaked passwords, social engineering and spoofed social media sites are among the tools hackers are using to gather individuals' private content and sell it online, the FBI said.

The Federal Bureau of Investigation has issued a public alert regarding a surge in social engineering and cyber intrusion tactics used by threat actors to compromise social media accounts. The attackers are reportedly targeting both adults and children to steal explicit content, which is then sold on illicit marketplaces. The FBI also noted that personal information is often posted alongside the stolen content.
According to the bureau's Monday notice, these cybercriminals employ various methods to gain unauthorized access. Some incidents involve brute-force attempts, where hackers repeatedly try passwords or PINs obtained from data leak sites. When targeting individuals known to them, attackers may use variations of the victim's birthdate or name as potential passwords.
Another common tactic involves impersonation. Threat actors contact victims under the guise of social media company representatives, falsely claiming that their accounts have been breached. They then inundate victims with text messages requesting password resets or containing codes that allow the attackers to reset the victim's password themselves.
The FBI also highlighted the use of cloned social media sites. These fake platforms are designed to mimic legitimate sites, and any login credentials entered by victims are directly transmitted to the cybercriminals.
The consequences for victims extend beyond the initial breach and theft. The FBI stated that after their content is posted or sold, victims often experience "re-victimization through harassment, sextortion, stalking or other targeted attacks," including the advertising of stolen content on their own social media pages.
This alert follows recent legal actions taken by the Department of Justice against individuals involved in similar schemes. In February, an Illinois man, 27, pleaded guilty to charges related to a campaign that compromised approximately 600 women's Snapchat accounts. Last year, a former University of Michigan assistant football coach was indicted for hacking into student athlete databases across more than 100 colleges and universities, accessing medical information for about 150,000 individuals. This data was then used to breach the social media accounts of female student athletes.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.