LIVE · cybersecurity feed
Live wire
OpenAI locks down Astra over potential critical cyber capabilitiesCritical Flaws Discovered in Belgian eID Software Used by 2 Million PeopleSecurity Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITIONWebmail CSS Attacks Expose a New Risk for AI-Powered Email ToolsMetabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataCVE-2026-8037 · CISA Adds Progress LoadMaster Command Injection Flaw to KEV CatalogSensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It AllAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to AttackersNew CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
security

UK man tied to The Com sentenced for abusing 117 victims

Justin Swaddle, who was a minor when he committed the crimes, coerced children across multiple countries into self-harm and sexual abuse using threats tied to their personal information, authorities said. The post UK man tied to The Com sentenced for abusing 117 victims appeared first on CyberScoop.

zeroday.news ·

A 20-year-old man in the United Kingdom, Justin Swaddle, has been sentenced to two years in prison after admitting to an online abuse campaign that affected 117 victims across multiple countries. Swaddle, who was a minor when the offenses occurred, pleaded guilty to child sexual abuse offenses and blackmail. He will also be required to register as a sex offender.

The National Crime Agency (NCA), the UK's primary law enforcement agency, began investigating Swaddle in January 2024. This followed his arrest in October 2023 by local police on charges related to possessing, making, and distributing indecent images.

Investigators discovered Swaddle's extensive online presence on platforms such as Snapchat, Telegram, and Discord, where he used usernames including "Epstein," "Rugen," and "Moscow." A search of his electronic devices revealed hundreds of sexually explicit conversations with young females.

The NCA determined that Swaddle was a member of "The Com," a loosely organized cybercriminal network composed of minors and young adults involved in various forms of cybercrime, including violence, extortion, and sextortion.

The investigation identified 117 female victims worldwide, ranging in age from 13 to 17, with eight of them located in the United Kingdom. One 17-year-old victim recounted meeting Swaddle on Discord in November 2022 before their communications moved to Snapchat. She stated that Swaddle obtained her name, address, and school details, subsequently using this information to coerce her into various acts by threatening to expose her personal data unless she provided further images and videos.

An operations manager from the NCA noted that Swaddle specifically targeted young and vulnerable individuals globally, abusing and frightening them into self-harm and sexual activity, primarily to gain popularity among his online peers. While the number of individuals involved in Com groups may be relatively small, the impact on victims is described as significant and long-lasting.

Law enforcement agencies in both the UK and the United States have been actively prosecuting individuals affiliated with The Com. Recently, a Canadian man linked to the group pleaded guilty to widespread compromises affecting over 165 Snowflake customer environments. Additionally, two young men tied to The Com were sentenced in the UK to 66 months in jail last month for a 2024 cyberattack against Transport for London.

ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Poland uncovers second heat plant cyberattack that went hidden for months

The incident occurred on the same day as coordinated cyberattacks struck more than 30 other renewable energy installations and a larger heat plant, as Poland publicly disclosed in January.

security

Senate Democrats introduce bill to distribute $300 million annually to shore up water system cybersecurity

Two Democratic senators introduced legislation that would allocate $300 million each year to fund cybersecurity improvements for the water and wastewater sector.

vulnerability

Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant

Atlassian fixed a flaw letting one crafted link make its Rovo AI assistant exfiltrate company data

security

Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification

Cisco is proud to announce a landmark achievement: Secure Email Threat Defense has officially achieved FedRAMP Class D (High) certification!

breach

Cyberattack on Steam hardware shipper leaks names, addresses, and order data

Video game publisher Valve is alerting customers in Europe to a data breach at CEVA Logistics, its Steam hardware shipping partner. Reports from affected customers began surfacing on social media earlier today, after Valve started sending out data breach notification emails. “Between July 29 2026 and August 1, 2026, a cyberattack hit CEVA Logistics, the company that ships Steam hardware to custome

breach

Metabase zero-day exploited to access Framework customer data

Framework, the San Francisco-based company that designs repairable and upgradeable laptops, has suffered a data breach after attackers managed to exploit a zero-day vulnerability in the Metabase business intelligence service. According to the notification sent to affected Framework customers, the attackers accessed names, email addresses, phone numbers, physical addresses, and login IP addresses,