LIVE · cybersecurity feed
Live wire
security

Scammers race to cash in on Venezuelan earthquake disaster

Scammers wasted no time exploiting Venezuela's devastating earthquake, with researchers uncovering 212 newly-registered relief-themed domains in just five days. Read more in my article on the Hot for Security blog.

zeroday.news · 32d ago

Cybercriminals are actively exploiting the recent earthquake in Venezuela, registering a significant number of new domain names in the immediate aftermath of the disaster. Threat intelligence firm WhoisXML API reported that 212 new domains referencing the earthquake were registered within five days of the event. This surge in registrations began on the same day the earthquake struck, with the highest number, 105, filed on the day following the disaster.

In contrast, the same company found no such earthquake-related domains registered in the three days prior to the event. The newly registered domain names often use language designed to appear helpful, with many referencing aid, donations, rescue efforts, or the earthquake itself. Some also mention affected people or promise services like medical help, shelter listings, or tracking.

While some of these domains may belong to legitimate aid organizations, researchers noted that a high percentage, 93%, lacked individual registrant contact information, with details obscured by privacy services or left blank. Alexandre François, a researcher, highlighted that some of these new websites are already soliciting Bitcoin donations without providing verifiable proof that the funds will reach victims.

This tactic of exploiting natural disasters for fraudulent purposes is not new. Similar patterns have been observed following events like Hurricane Harvey in 2017 and during the COVID-19 pandemic, where scammers impersonated aid organizations and facilitated money laundering through cryptocurrency. Even years after a disaster, fraudsters have been known to exploit lingering public sympathy, as seen in attempts to perpetrate "Nigerian Prince"-style scams following the 2011 Japanese tsunami.

The urgency created by natural disasters can make it easier for cybercriminals to exploit public generosity. To avoid falling victim to such scams, security experts advise individuals who wish to donate to a cause to directly type the known web address of a trusted charity into their browser, rather than clicking on links from social media or unsolicited emails.

It is also recommended to be suspicious of newly created websites, particularly those registered shortly after a disaster. Avoiding sites that exclusively request cryptocurrency donations is also advised, as legitimate charities typically offer traceable, conventional payment methods and are transparent about how funds will be used.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.