LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
finance

Treasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023

As the cyber scam industry expands globally, the U.S. government wants banks to share more information about what's happening to their customers.

zeroday.news ·

The U.S. Treasury Department's Financial Crimes Enforcement Network (FinCEN) has issued an alert to financial institutions, urging increased vigilance in identifying and reporting cyber fraud schemes, particularly those originating from overseas scam centers. This directive follows a comprehensive study revealing that nearly $13 billion has been stolen from Americans in cryptocurrency investment scams across all 50 states and U.S. territories between September 2023 and December 2025.

The study, based on over 33,000 cyber fraud incident reports submitted by approximately 1,300 financial institutions, highlights the escalating rate of suspected scam activity. FinCEN observed an almost 11% month-over-month increase in reports, indicating the expanding reach of these schemes beyond their initial hubs in Myanmar, Cambodia, and Laos. This alert builds upon a previous Treasury warning issued in 2023 concerning "pig butchering" scams.

Transnational criminal organizations are exploiting both emerging technologies and human vulnerabilities, leading to devastating financial losses for victims. Scammers employ various personas, from romantic partners to trusted financial advisors, to persuade individuals into transferring funds, often through traditional bank transfers or cryptocurrency. While adults over 60 accounted for about 25% of all reports, the study suggests that other age demographics are being scammed at similar rates.

Cryptocurrency firms identified approximately $5.5 billion in suspected scam activity, while traditional banks reported about $6.4 billion in potential fraud. Banks frequently detected these schemes when victims sent funds to digital asset platforms to purchase cryptocurrencies or when wire transfers were sent to scam-affiliated beneficiaries, often referencing digital asset investments.

Victims have been observed taking drastic measures, including applying for loans and second mortgages, liquidating investment accounts, and attempting wire transfers to scammer-affiliated accounts. One case involved an older adult victim who transferred nearly $640,000 from her retirement fund to a suspected scammer after meeting an individual on social media who instructed her to invest in a fictitious digital asset company. Another victim withdrew almost $150,000 from his retirement account, secured a personal loan, and utilized lines of credit on his home to send funds to a scammer, believing he was investing in a venture promoted by a digital romantic partner.

Most reports indicated the use of cryptocurrencies such as Ethereum, Tether (USDT), and USD Coin (USDC), with at least 18 other coins also appearing in the filings. FinCEN noted that scammers almost invariably converted stolen funds into USDT. Victims typically realized they were part of a scam only when they were asked to pay a fee to retrieve their supposed returns. Investigators also uncovered instances where scammers posed as "asset recovery services" to defraud victims a second time.

Days after the report's release, the U.S. government took action against Xinbi Guarantee, a Telegram-based illicit marketplace. Xinbi Guarantee was sanctioned for its role in laundering billions of dollars for scammers, becoming a primary platform for Southeast Asian scam compounds following the U.S. takedown of the Chinese platform Huione. Over $36 billion was reportedly laundered through Xinbi.

finance
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]