The multi-country sting targeted Black Axe financial networks, seizing millions in assets and uncovering Crime-as-a-Service infrastructure across four continents. The post Interpol targets Black Axe’s illicit financial web in latest international sting appeared first on CyberScoop.

An international law enforcement operation, dubbed Operation Jackal IV, has resulted in 58 arrests and the identification of 263 suspects globally, targeting the financial networks of West African organized crime groups, including Black Axe. The operation, announced by Interpol, aimed to disrupt money laundering activities, locate high-value targets, seize assets, and support prosecutions.
Black Axe is described as a highly structured, hierarchical organization, primarily led by Nigerian nationals, that generates billions of dollars annually from numerous small-scale operations across dozens of countries. Earlier in the year, European law enforcement had already arrested several members of the group for their involvement in adversary-in-the-middle scams, business email compromise (BEC), money laundering, and vehicle trafficking.
Operation Jackal IV spanned four continents, uncovering Crime-as-a-Service infrastructure. Among the preliminary discoveries detailed by Interpol, Romanian authorities dismantled an investment scam operating from a call center. This group promised high returns on stocks or cryptocurrencies, routing victim payments to electronic wallets they controlled. Police estimate the total value of this scam at 143 million euros (approximately $166 million). Eleven individuals were arrested, and authorities seized about 330,000 euros ($379,000) in cash and cryptocurrency, six properties, and several luxury watches.
In South Africa, 39 of the 58 arrests were made during raids on seven sites in Johannesburg. These sites were linked to a syndicate that targeted retirees in English-speaking countries with romance and investment scams. Investigators seized $2.67 million and froze 257 bank accounts.
Argentine authorities identified 196 individuals connected to a Crime-as-a-Service network suspected of providing website domains and money laundering support to West African groups, leading to 17 arrests. In Italy, one individual was identified in connection with a pan-European money laundering network that utilized shell companies, remittance services, and cash withdrawals. A single account associated with this network reportedly moved 845,000 euros ($736,000) through 560 transactions.
Investigators also observed Black Axe's increasing involvement in sextortion, with victims as young as 14. Offenders are reportedly contacting teenagers on social media, coercing them into creating explicit images, and then demanding payment to prevent the material from being publicly released.
This is not Interpol's first initiative against African-based criminal groups. A similar operation in 2024 led to 300 arrests, the seizure of $3 million in assets, and the blocking of 720 bank accounts. The director of Interpol's Financial Crime and Anti-Corruption Centre emphasized that by tracing illicit financial flows across borders, law enforcement is directly attacking the financial lifeline of organized crime, making it harder for these networks to profit.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.