Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers' bank accounts. [...]

Seven individuals have been charged in connection with a sophisticated cyber fraud operation that exploited a vulnerability at a service provider, leading to the unauthorized withdrawal of approximately €30 million ($34.6 million) from customer accounts at a major German financial institution. Four arrests were made in Brazil, while three other suspects face prosecution in Europe.
The fraudulent activity occurred over a four-day period in November 2023. While German and Brazilian federal police agencies did not initially name the affected institution, Brazilian media identified it as Commerzbank. Commerzbank subsequently confirmed that its clients were impacted by the incident, which stemmed from "technical issues at a service provider" that enabled unauthorized direct debits. The bank emphasized that customers suffered no financial losses as a result of the fraud.
German authorities indicated that the attackers exploited a software vulnerability introduced by a faulty update within the payment and transaction-processing system of a financial institution. This allowed the initiation of numerous unauthorized withdrawals from various German online banking accounts. The stolen funds were then routed to Brazil through an extensive network designed to obscure their origin.
Investigators determined that the largest portion of the funds was withdrawn in Brazil, with a smaller amount cashed out across four European countries. The proceeds were allegedly moved and concealed through a complex web of pass-through accounts, shell companies, payment institutions, virtual-asset platforms, and payment cards issued without the beneficiaries' consent.
On August 13, Brazil's Federal Police, with support from Germany's BKA, launched "Operation Klonen." This operation involved executing 21 search-and-seizure warrants across seven Brazilian cities, leading to the preventive detention of four suspects in Rio de Janeiro, Guarulhos, Goiânia, and Carapicuíba.
Brazilian authorities discovered that one of the arrested suspects had run for elected office in 2024 and allegedly used some of the illicit funds to finance their political campaign. A Brazilian federal court also ordered the seizure of financial assets, vehicles, and real estate valued at up to R$106 million ($22.4 million).
The arrested suspects in Brazil face charges including aggravated theft through electronic fraud, participation in a criminal organization, and money laundering. The three additional suspects identified in Europe will be prosecuted by law enforcement authorities in Spain and Bulgaria.

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs