LIVE · cybersecurity feed
Live wire
CISA’s logging guidance works beyond governmentCISA orders urgent patching of actively exploited Zimbra flawZero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context InjectionMalware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply ChainHow an Emerging Industrial Protocol Family Could Put OT at Risk14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accounts
security

Venezuelan Gets Record Federal Prison Term for ATM Jackpotting

Juan Manuel Gouveia-Aguilera has been sentenced to 8 years in prison for his role in an ATM jackpotting scheme that caused millions in losses. The post Venezuelan Gets Record Federal Prison Term for ATM Jackpotting appeared first on SecurityWeek.

zeroday.news ·

Juan Manuel Gouveia-Aguilera has reportedly received an eight-year federal prison sentence for his involvement in an ATM jackpotting operation. This sentence is described as a record term for this type of crime and follows a scheme that resulted in millions of dollars in losses.

ATM jackpotting is a sophisticated form of theft where criminals manipulate an automated teller machine to dispense cash without using a legitimate bank card or account. This is typically achieved through various methods, including installing malicious software directly onto the ATM's internal computer system, exploiting network vulnerabilities, or physically tampering with the machine to gain access to its internal components. Once compromised, the malware or exploit can command the ATM to eject its entire cash contents.

The technical mechanisms often involve either direct physical access to the ATM's USB ports or network connections to install malware, or remote access gained through phishing, social engineering, or exploiting vulnerabilities in the ATM's operating system or network infrastructure. Specialized tools and software are frequently developed or acquired by criminal groups to facilitate these attacks, allowing them to bypass security measures and control the cash dispenser.

Products in the ATM category, regardless of vendor, are susceptible to such attacks if not adequately secured. Common vulnerabilities that attackers exploit include outdated operating systems, weak network segmentation, insufficient physical security, and a lack of robust anti-malware solutions. The scope of such schemes can be extensive, often targeting multiple machines across different locations or even countries, leading to significant financial losses for banks and financial institutions.

Mitigation strategies for this class of issue typically involve a multi-layered approach. This includes regularly updating ATM operating systems and software, implementing strong network segmentation to isolate ATMs from broader corporate networks, and deploying advanced endpoint protection and anti-malware solutions. Enhanced physical security measures, such as hardened casings and alarm systems, are also crucial. Furthermore, continuous monitoring for suspicious activity and prompt incident response protocols are vital for detecting and neutralizing jackpotting attempts.

This sentencing underscores the ongoing threat posed by organized cybercrime groups targeting financial infrastructure. The significant prison term reflects the severity with which authorities view these sophisticated attacks, which not only result in substantial financial losses but also erode public trust in banking systems. It highlights the global nature of these criminal enterprises and the efforts by law enforcement to combat them through international cooperation and prosecution.

ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Doubloon Dredger Abuses Notion to Harvest Authentication Tokens

Doubloon Dredger abused Notion and malicious PDFs to harvest Microsoft authentication tokens

security

Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts

Dutch Data Protection Authority said it is imposing a fine of 825 million euros because Uber violated the EU’s General Data Protection Regulation. The post Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts appeared first on SecurityWeek.

patch

Microsoft: August updates break printing, PDF export in WPF apps

Microsoft has confirmed that .NET Framework updates released as part of the August 2026 Patch Tuesday are breaking printing and PDF export in WPF applications. [...]

securitycritical

CISA’s logging guidance works beyond government

The US Cybersecurity and Infrastructure Security Agency (CISA) wants federal agencies to (re)shape their logging strategy around one question: when an attack hits, can you actually use the logs you’ve collected to catch it and reconstruct what happened afterward? The Logging Reference Architecture (LRA), released in August 2026, is meant to help US federal civilian agencies meet the logging requir

vulnerabilityhigh

CISA orders urgent patching of actively exploited Zimbra flaw

The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. [...]

nation-state

Criminal Deception in Silicon Valley

Interesting paper: Abstract: With entrepreneurial fraud cases on the rise, we investigate how entrepreneurs carry out criminal deception, employing deceptive means to defraud audiences. Analyzing court data from Silicon Valley ventures and their founders prosecuted for fraud between 2000 and 2023, our findings reveal that entrepreneurs carry out criminal deception through a process of façading: En