Vietnamese authorities have arrested and are prosecuting seven suspects believed to have run HiAnime, the largest anime piracy streaming service before its shutdown in June. [...]

Vietnamese authorities have arrested and are prosecuting seven individuals suspected of operating HiAnime, a prominent anime piracy service that was shut down in June. The group is accused of copyright infringement and money laundering.
HiAnime offered a vast collection of anime with English subtitles and dubs without requiring a subscription. The service gained significant popularity, attracting hundreds of millions of monthly visitors and, at times, surpassing legal streaming platforms like Disney+ and Crunchyroll in web traffic between late 2024 and 2025.
The piracy operation began under the Zoro.to domain. It was later rebranded to Aniwatch and moved to Aniwatch.to in July 2023, before undergoing another change in March 2024 to HiAnime/H!Anime, utilizing the HiAnime.to domain. Due to its widespread reach, HiAnime was recognized on the European Commission's Counterfeit and Piracy Watch List and the United States Trade Representative's Notorious Markets list.
The seven defendants face charges related to infringing copyright and related rights, as well as money laundering. Four individuals have been detained, while the remaining three are under house arrest. Authorities allege that the group created over 100 websites to host more than 26,000 pirated anime films. Between 2020 and April 2026, these sites reportedly generated approximately $12.85 million in illegal advertising revenue.
The Alliance for Creativity and Entertainment (ACE), a coalition representing over 50 major media and entertainment companies, confirmed the law enforcement action. ACE acknowledged the support of U.S. authorities, including Homeland Security Investigations and the U.S. Department of Justice, in the multi-year investigation that led to the arrests.
ACE specifically commended the efforts of Vietnam's Ministry of Public Security, particularly its Economic Crimes Investigation Department (C03) and the Department of Cybersecurity and High-Tech Crime Prevention (A05). The organization expressed its commitment to continuing collaboration with Vietnamese authorities on future actions against piracy services.
This action follows a similar operation earlier in the year when ACE announced the shutdown of AnimePlay, another significant anime streaming platform. AnimePlay hosted over 60 terabytes of anime content and had more than 5 million registered users. ACE dismantled AnimePlay by taking down its entire infrastructure, including servers and web domains.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.