The United States and the United Kingdom have signed a memorandum of understanding to collaborate on dismantling scam centers that steal billions through investment and romance fraud. The initiative will involve parallel investigations, information sharing, and joint disruption efforts targeting organized crime syndicates, many of which are based in Southeast Asia and run by Chinese gangs. This cooperation aims to disrupt these operations, which often exploit human trafficking victims.

The United States and the United Kingdom have formalized a joint initiative to dismantle scam centers responsible for billions of dollars in losses through investment and romance fraud schemes. A memorandum of understanding was signed on Thursday by officials from the U.S. Department of Justice and senior representatives from the U.K.'s National Crime Agency and Crown Prosecution Service.
The agreement outlines a commitment to conduct parallel investigations and share intelligence regarding the organized crime syndicates operating these scam centers, many of which are based in Southeast Asia. A key objective is to disrupt Chinese gangs that are believed to manage these scam compounds.
Under the terms of the memorandum, both nations will coordinate on jurisdictional decisions for cases of mutual interest and prioritize efforts to achieve shared outcomes against this threat. The Justice Department confirmed that both U.S. and U.K. counterparts had already identified significant overlapping cases and pledged to collaborate on an in-person disruption event with private industry partners, hosted by the National Crime Agency in London in early October.
This collaborative effort builds upon the U.S. Scam Center Strike Force, which was established in November to coordinate domestic law enforcement responses to cyber scams. The FBI has reported that cyber-enabled fraud schemes account for nearly 85% of all reported losses to the agency. Last year, Americans lost over $12 billion to cyber scams, a figure that is likely underestimated due to underreporting by victims.
The scams are frequently perpetrated by victims of human trafficking, who are housed in compounds located across countries such as Myanmar, Cambodia, and Laos. These compounds are reportedly run by Chinese gangs, often with the complicity of local officials.
The Scam Center Strike Force, led by Assistant U.S. Attorney Karen Seifert, comprises over 150 personnel, including prosecutors and agents from the FBI, IRS, and U.S. Postal Inspection Service. Its most notable success to date has been the disruption of Prince Group, a Chinese front company allegedly used to launder billions of dollars derived from these fraudulent activities.
Both U.S. and U.K. agencies have imposed sanctions on Prince Group. Additionally, the Justice Department has seized approximately $15 billion worth of Bitcoin linked to Chen Zhi, the company's CEO, as part of its ongoing efforts to combat these sophisticated criminal operations.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed