LIVE · cybersecurity feed
Live wire
Hackers target WordPress sites in miniOrange auth bypass attacksFake GTA 6 Extended Look and demo sites deliver an infostealerCVE-2026-63520 · Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)CISA’s logging guidance works beyond governmentCISA orders urgent patching of actively exploited Zimbra flawZero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context InjectionMalware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain
security

Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly

A Jersey City resident is facing charges for his alleged role as a money mule for overseas cyberscammers who stole millions from elderly New Yorkers.

zeroday.news ·

A 21-year-old Indian national, Jay Sunilbharthi Goswami, has been arrested in Canada while attempting to flee the United States, facing charges for his alleged role as a money mule in an international scam operation that defrauded elderly Americans of over $7.5 million. Goswami, a resident of Jersey City, New Jersey, was apprehended on August 17 after driving from Buffalo, New York, across the Peace Bridge into Canada and attempting to board a flight from Toronto to Doha. He is awaiting extradition back to the U.S.

Prosecutors allege that Goswami, who is in the U.S. on a student visa attending Fairleigh Dickinson University, facilitated the transfer of $7,559,185 from at least nine victims, primarily in their 70s and 80s, residing in New York and New Jersey. The scam involved overseas perpetrators, reportedly based in India, contacting victims by phone or email, impersonating law enforcement or government officials. They used various pretexts, such as linking victims to drug cases or claiming their information was stolen, to convince them to empty bank accounts and hand over funds.

Victims were instructed to provide cash, purchase gold bars, or buy gift cards. Goswami's role, as outlined in a criminal complaint by the FBI and IRS, was to collect the money or gold from victims at specified addresses using code words, and then transport it to other locations for shipment to India. He allegedly earned approximately $90,000 from his involvement in the scheme.

This is not Goswami’s first encounter with law enforcement regarding this operation. He was initially detained on December 19, 2025, but was subsequently released. Prosecutors contend that he continued his involvement with the scammers after his initial release. During his first arrest, Goswami reportedly told investigators he met one of the scammers at a funeral in India and was unaware of any illegal activity. However, the criminal complaint reportedly includes text messages, emails, and other documents suggesting his full awareness of the scam.

According to the complaint, Goswami even provided a local New Jersey lawyer's number to the individual he met at the funeral, known as "Black Tiger," after another money mule was arrested. Money mules are utilized to obscure the movement of stolen funds, complicating law enforcement efforts to trace their origins and final destinations.

Goswami faces charges of wire fraud and money laundering, which carry a potential sentence of up to 20 years in prison. The U.S. and Indian authorities have been actively targeting such scam centers. Recently, Indian authorities reportedly raided 76 locations across the country suspected of running tech support scams, following tips from companies like Amazon and Microsoft. In a separate case in May, two individuals pleaded guilty to assisting a tech-support scheme based in India that defrauded American citizens.

ShareXLinkedInWhatsAppFacebook

More News

view all →
security

TikTok reaches $400M settlement with US over COPPA violations

The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children's Online Privacy Protection Act (COPPA). [...]

phishing

ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

A ReliaQuest employee fell victim to a phishing attack and the hackers gained access to a dashboard. The post ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited appeared first on SecurityWeek.

iran

Iran-linked cyberattack shut down a UK power plant

A suspected Iran-linked cyberattack recently disrupted a small-scale UK power plant, causing it to shut down for four days. While the government confirmed the incident, it emphasized that the wider energy system remained unaffected and highly resilient. This event follows a series of similar cyber intrusions targeting water utilities in the United States, which cybersecurity analysts also suspect are linked to Iran.

gta 6high

Fake GTA 6 Extended Look and demo sites deliver an infostealer

Cybercriminals are exploiting the hype surrounding the upcoming Grand Theft Auto VI release by distributing fake demo websites that deliver an information-stealing malware. These sites impersonate Rockstar Games and trick users into downloading a malicious executable disguised as a game installer. The malware, identified as belonging to the Vidar family, is designed to steal passwords, session cookies, and other sensitive data from browsers and applications, potentially bypassing two-factor authentication through the reuse of stolen session tokens.

CVE-2026-63520critical

Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)

Rapid7 has published a technical analysis of CVE-2026-63520, a critical remote code execution vulnerability in Microsoft SharePoint. The vulnerability allows an authenticated attacker to execute arbitrary code on a vulnerable server by uploading a malicious BDC model file. When combined with another vulnerability, CVE-2026-55040, it can lead to unauthenticated RCE.

cloud

NIST Warns of Unique Security Risks in Multi-Cloud Environments

NIST has set out 23 novel challenges that arise in multi-cloud environments and has encouraged the cyber community to find solutions