Scammers are actively conducting a global smishing campaign, sending fake text messages that impersonate toll and parking authorities. These messages aim to trick drivers into clicking malicious links or providing sensitive information. The campaign has been ongoing since late 2025 and has already distributed tens of thousands of fraudulent texts across multiple countries.

Scammers are globally targeting drivers with fraudulent text messages impersonating toll operators, parking authorities, and transport agencies, according to a recent analysis by Bitdefender Labs. Since December 2025, researchers have tracked these "smishing" campaigns, which have sent over 79,000 deceptive messages across 12 countries. The active campaigns aim to trick recipients into paying fake fines, divulging sensitive personal and financial information, or downloading malware.
The operation, dubbed "Operation Road Trap," employs tactics such as rapid domain generation, sender-ID spoofing, and evasion techniques designed to bypass mobile security measures. Messages are delivered in multiple languages, including English, Spanish, Portuguese, French, and Hindi, and are tailored to specific regions. While the campaigns are widespread and coordinated in their methods, Bitdefender Labs has not yet attributed them to a single threat actor.
These scams commonly create a sense of urgency by claiming an unpaid toll, traffic fine, or parking ticket, often threatening consequences like additional fees, license suspension, or legal action within a short timeframe, typically 24 to 72 hours. Recipients are then directed to click a link that leads to a fraudulent website designed to mimic official payment portals. In some instances, these links are used to distribute malware.
The United States has seen the largest volume of these attacks, with campaigns impersonating state Departments of Motor Vehicles (DMVs) and toll systems like E-ZPass, SunPass, and FastTrak. Over 25,000 phishing URLs have been identified in this region, with California and Texas being particularly targeted. Some messages use spoofed sender names and are delivered via short codes, which can appear more legitimate.
In Canada, particularly in British Columbia, the scams begin with parking citation messages but can escalate to target Interac e-Transfer credentials, potentially leading to broader financial theft. Messages impersonate local parking or city collection services, with Alberta and Ontario also experiencing these attacks.
The United Kingdom is experiencing a campaign focused on road or journey payments, using minimal text and direct links to prompt quick action. Unlike other regions, these messages do not typically mention fines or legal consequences, opting for a low-friction approach.
Ireland's campaign impersonates eFlow, the electronic toll system for the M50 motorway, using the short code 7726, also seen in US campaigns. These messages claim an unpaid toll and direct users to a payment link.
Australia is targeted by scams impersonating the toll operator Linkt. These campaigns utilize shortened URLs and spoof the sender name "Linkt," potentially causing messages to appear within legitimate conversation threads on some devices.
New Zealand sees scams impersonating NZ Police and the Ministry of Justice, warning of overdue traffic fines and using government-themed domains. Messages often include mobile-specific instructions to encourage interaction.
France is experiencing ULYS toll payment scams, with messages tailored to local users and resembling legitimate notifications for small unpaid toll amounts. The Île-de-France, Rhône-Alpes, and Provence-Alpes-Côte d'Azur regions are most affected.
Luxembourg's campaign impersonates Guichet.lu, the official government services portal, with messages concerning parking violations. These scams include case reference numbers and specific dates to appear more official.
Colombia has also seen a significant volume of scam messages related to tolls and traffic fines, making it the second-largest wave of attacks tracked.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed