IC3 says any account claiming to represent it is fake

The FBI's Internet Crime Complaint Center (IC3) has issued a renewed warning about scammers impersonating the agency and its personnel on social media platforms, exploiting individuals who have already fallen victim to cybercrime. The fraudsters are employing various tactics, including AI-generated content, to appear legitimate and deceive victims into providing personal or financial information.
According to the IC3, these schemes involve two primary approaches. In the first, scammers create fake social media profiles and pages that mimic FBI personnel or the IC3. They then infiltrate online groups dedicated to fraud victims or directly contact individuals, claiming to represent the FBI or the complaint center. In some instances, victims who have expressed an intent to report a scam to the FBI or file an IC3 complaint are subsequently contacted by an impersonator who directs them to a spoofed IC3 update page or continues communication through messaging applications.
The second approach involves the creation of AI-generated videos featuring senior FBI officials, which are then posted on social media. These videos direct users to a fraudulent IC3 website where they are prompted to report cybercrimes. The information collected through these fake reports is then used by the scammers to contact victims for further fraudulent activities. The IC3 noted that these AI-generated depictions of public figures are designed to enhance the perceived legitimacy of the scams.
Victims have reported being contacted through various channels, including email, phone calls, social media advertisements, and online forums. A common thread among almost all complainants is that the scammers claimed to have recovered lost funds or offered assistance in doing so.
The IC3 emphasizes that it does not maintain any social media presence and does not investigate crimes or offer to recover lost funds through social media platforms. Any social media profiles or pages claiming to represent the IC3 or offering fund recovery services are fraudulent and are actively attempting to steal personal or financial information. The IC3 also confirmed that it will never directly communicate with individuals via phone, email, social media, phone apps, online chat, or public forums.
Legitimate contact with a cybercrime victim who has reported an incident via the official IC3 website will only be made by an FBI employee from a local field office or another authorized law enforcement official. The IC3 advises individuals who have fallen victim to cybercrime or online scams to refrain from posting about their experiences on social media, as this can attract malicious actors seeking to exploit them further.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed