Two individuals, Thalha Jubair and Owen Flowers, have been sentenced to 66 months in prison in the UK for their roles in a cyberattack that disrupted Transport for London's operations. The pair were identified as leading members of the Scattered Spider hacking group. Authorities linked them to significant cryptocurrency transactions and numerous cyberattacks, including extortion of US organizations and an attack on the federal court system.

Two individuals identified as leading members of the Scattered Spider cybercrime group, Thalha Jubair and Owen Flowers, have been sentenced to 66 months in jail in the United Kingdom for a 2024 cyberattack that disrupted Transport for London operations. The UK's National Crime Agency announced the sentencing on Thursday, following their arrests in September 2025 and subsequent guilty pleas.
Jubair, 20, and Flowers, 18, were described by researchers as core members of Scattered Spider, a subset of a broader collective known as "The Com." US authorities had previously accused Jubair of involvement in at least 120 cyberattacks, including the extortion of 47 US-based organizations and a January 2025 attack on the federal court system. Officials traced approximately $89.5 million in cryptocurrency, at the time of payment, to Bitcoin addresses and servers controlled by Jubair, including two payments of $25 million and $36.2 million from financial services firms between June and November 2023.
Flowers had been arrested in connection with the Transport for London attack in 2024 but was released after questioning. At the time of his initial arrest, investigators stated he was actively attempting to hack into the systems of US healthcare companies SSM Health Care Corporation and Sutter Health, which had already experienced infiltration and damage. Both Jubair and Flowers reportedly did not cooperate with authorities after their arrests.
The National Crime Agency characterized the prosecution as the largest cybercrime case brought before UK courts, representing the culmination of nearly two years of investigative work. Paul Foster, head of the National Cybercrime Unit, stated that the investigation had "severely disrupted" the threat posed by Scattered Spider, which he described as the most significant cybercrime threat to the UK in recent years.
Despite the UK authorities' positive assessment, the lasting impact of the arrests and imprisonment on Scattered Spider's activities remains unclear. While UK authorities assert the arrests effectively halted the group's criminal operations, they also acknowledged that other cybercriminals continue to use the Scattered Spider brand in more recent attacks. The FBI, in a LinkedIn post, echoed this sentiment, noting that members of Scattered Spider continue to victimize organizations globally, causing significant financial and operational harm.
Industry analysts indicated that Jubair was considered one of the four principal individuals associated with Scattered Spider, and one of its two most central figures, at the time of his arrest. These analysts also noted that Jubair and Flowers possessed substantial resources and support, with victim payments being reinvested into their criminal enterprise. Some observers expressed concern that the 66-month sentence might be lenient given the duration of the defendants' alleged reoffending, which reportedly exceeded the sentence length. There is hope that the US may seek extradition to pursue additional charges.
Scattered Spider is known for its reliance on data extortion, SIM-swap attacks, and other social engineering techniques to infiltrate networks and compromise critical services. The FBI Cyber Division's Assistant Director, Brett Leatherman, emphasized the significance of holding these two members accountable.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed