LIVE · cybersecurity feed
Live wire
security

New York Seizes a Dozen Celebrity Deepfake Websites

In the biggest-ever legal action against harmful deepfake websites, the Manhattan District Attorney’s Office has seized 12 sites that collectively targeted around 1,200 victims.

zeroday.news ·

The Manhattan District Attorney’s Office has announced the seizure of 12 websites involved in the creation, publication, and sale of nonconsensual deepfake videos, primarily targeting women. This action, described as potentially the largest takedown of explicit deepfake sites to date, follows investigations into platforms that have depicted approximately 1,200 individuals, including celebrities, politicians, athletes, and social media influencers, in sexually explicit content.

District Attorney Alvin Bragg stated that these privacy violations have significant negative impacts on victims' careers and personal lives, urging anyone affected to contact the cybercrime bureau. The office's investigation into those responsible for operating the websites and uploading the content is ongoing.

The seizures were executed under New York’s criminal procedure laws, with takedown notices now appearing on the affected domains, indicating a seizure warrant issued by a New York State Supreme Court. While the specific names of the seized websites have not been publicly disclosed by the District Attorney’s Office, several sites displayed "THIS DOMAIN HAS BEEN SEIZED" messages late last week.

The deepfake technology, which emerged in late 2017, has advanced significantly, leading to a proliferation of websites, apps, and bots capable of generating realistic nonconsensual intimate imagery (NCII) rapidly. These sites often used names like "sex celebrity" and promised "real deepfakes," hosting videos that could be several minutes long and featured faces of public figures swapped into existing pornographic material. Some archived versions of these sites showed videos with tens of thousands of views, with one claiming to have been active since 2018.

Analysis of the seized sites indicates that many videos were reposts, with some content originating from the now-defunct MrDeepFakes platform. Researchers noted that at least two of the seized websites featured profiles for elected officials, complete with their names, positions, and grids of manipulated videos. Research has documented 56 European politicians, 16 US politicians, and two UK politicians mentioned or appearing on these sites.

Experts view these takedowns as a significant victory against synthetic NCII, demonstrating that state laws can be effectively enforced even when regulatory frameworks are fragmented across jurisdictions. The seized sites appear inaccessible even when using VPNs. However, the broader deepfake industry continues to pose challenges, with calls for interventions across the entire ecosystem, including the tools for creation, promotion, hosting infrastructure, and monetization systems.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

'Enemies of the regime' on notice

patch

Before You Patch. Why Patch Reliability Matters for Confident Deployment

Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signaling the need for additional validation before production deployment. Patch Reliability helps IT and s