Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The

Two individuals identified as key members of the cybercrime group Scattered Spider have pleaded guilty to criminal charges in the United Kingdom. The pleas occurred on the first day of a trial that had been expected to last six weeks. The charges stem from a cyberattack in August 2024 that significantly disrupted Transport for London, the agency managing the public transit system for Greater London.
Thalha Jubair, aged 20, and Owen Flowers, aged 18, admitted to conspiring to commit unauthorized acts targeting Transport for London's computer systems. They also pleaded guilty to causing a risk of serious damage to human welfare. According to reports, Flowers also admitted to involvement in a conspiracy to hack U.S.-based healthcare providers SSM Health Care Corporation and Sutter Health in September 2024.
Jubair is also a person of interest to U.S. law enforcement. In September 2025, prosecutors in New Jersey unsealed an indictment alleging that Jubair and other Scattered Spider members engaged in computer fraud, wire fraud, and money laundering. These activities are linked to at least 120 network intrusions affecting 47 U.S. entities between May 2022 and September 2025, with victims reportedly paying at least $115 million in ransom.
Flowers and Jubair were previously arrested in the United Kingdom in connection with Scattered Spider ransom attacks against retailers Marks & Spencer, Harrods, and the Co-op Group. Sources familiar with those investigations indicated that Flowers was the individual who anonymously provided media interviews following the group's September 2023 ransomware attacks that impacted operations at MGM Resorts and Caesars Entertainment in Las Vegas.
Prosecutors stated that Jubair co-managed a Telegram channel known as "Star Chat," which served as a hub for a SIM-swapping operation. This group allegedly used voice and SMS-based phishing to obtain credentials from employees at major wireless providers in the U.S. and U.K. This access was then leveraged to redirect victims' phone numbers to devices controlled by the attackers, enabling the interception of calls and text messages, including multi-factor authentication codes.
U.S. prosecutors also allege that Jubair, using the hacker handle "Rocket Ace," was involved in a large-scale SMS phishing campaign during the summer of 2022. This campaign reportedly stole single sign-on credentials from employees at hundreds of companies, leading to intrusions and data theft at over 130 organizations, including LastPass, DoorDash, Mailchimp, Plex, and Signal.
Further allegations suggest that at age 15, Jubair operated under the alias "Everlynn," selling fraudulent emergency data requests. These requests, using compromised police and government email addresses, aimed to obtain subscriber data from tech companies by falsely claiming urgent life-or-death situations that precluded waiting for a court order.
In a separate but related case, Tyler Buchanan, a 24-year-old British national and Scattered Spider member, pleaded guilty in April 2026 to conspiracy to commit wire fraud and aggravated identity theft. His plea relates to participation in the same 2022 SMS phishing spree. The government claims Buchanan, Jubair, and others used credentials obtained in that campaign to steal at least $8 million in cryptocurrency from victims across the United States. Buchanan's sentencing is scheduled for October 2.
The U.S. Department of Justice indicates that three other defendants indicted alongside Buchanan in relation to the SMS phishing campaign still face charges. These individuals are Ahmed Hossam Eldin Elbadawy, Evans Onyeaka Osiebo, and Joel Martin Evans.
Flowers and Jubair are scheduled to be sentenced in a London court on July 15, 2026.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed