LIVE · cybersecurity feed
Live wire
Malware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentialsSix Maximum-Severity Flaws Found in Cisco ProductsCritical Isolated-vm Vulnerability Leads to RCE on Host

cybercrime

cybercrime

Cyber Policing Hindered by Funding and Officer Focus

Law enforcement struggles to keep up with the increasing speed and complexity of cybercrime. Experts suggest that officers do not require extensive technical training, but rather a focus on fundamental concepts. However, insufficient budgets and a lack of concentrated effort are significant barriers to effective cyber policing.

data breachhigh

ExfilSquad Confirmed to Possess Data From 13 Organizations

Researchers have confirmed that the ExfilSquad extortion group has obtained sensitive data from a minimum of 13 organizations. The group has reportedly published these stolen datasets through torrents.

cybersecurityhigh

Trump Authorizes Private Sector Participation in Offensive Cyber Operations

The Trump administration has authorized federal law enforcement to collaborate with private companies on offensive cyber operations against foreign threat actors. A new National Security Presidential Memorandum facilitates this by establishing a framework for private sector involvement in gathering threat intelligence and proposing disruptive cyber operations, overseen by a Homeland Security Task Force program. While some in the cybersecurity community view this as a significant expansion of public-private collaboration, others express concerns about attribution accuracy and the potential for escalating cyber hostilities.

cybercrime

Attackers Exploit Law Enforcement Coordination Gaps

Cybercriminals are outpacing law enforcement efforts by adapting their tactics to evade detection. This is largely due to law enforcement agencies operating in silos, hindering effective coordination and response to evolving threats.

scams

Congress Questions Executive Branch, Allies on Anti-Scam Coordination

US Senators questioned Trump administration officials regarding the coordination between federal agencies and international allies in combating scams. Lawmakers raised concerns about the lack of a central authority overseeing the numerous federal agencies involved and whether current efforts are sufficient to address transnational scam operations. Discussions also touched upon the potential need for a multinational coordination mechanism similar to those used for drug trafficking.

ransomwarehigh

Ransom Cartel Creator Sentenced to 16 Years for Extortion Scheme

The creator of the Ransom Cartel ransomware, Maksim Silnikau, has been sentenced to 16 years in prison for his role in a scheme that targeted at least 18 companies. Silnikau recruited participants, provided tools, and managed operations, attempting to extort over $5.2 million from victims including businesses, law firms, and educational institutions. His arrest in Poland led to the cessation of Ransom Cartel's activities.

ransomwarehigh

Ransom Cartel Leader Sentenced to 16 Years in U.S.

Maksim Silnikau, the founder of the Ransom Cartel ransomware-as-a-service operation, has been sentenced to 16 years in prison by a U.S. court. Silnikau created and administered the Ransom Cartel strain, which targeted at least 18 companies globally between 2021 and 2023. He was extradited from Poland to face charges in Virginia.

ransomwarehigh

Ransom Cartel Operator Sentenced to 16 Years in US Prison

A Belarusian individual, with a long history in cybercrime, has received a 16-year prison sentence in the United States. The sentence is a result of their involvement in operating the Ransom Cartel ransomware group.

aihigh

This month in security with Tony Anscombe – July 2026 edition

July 2026 saw significant cybersecurity events including OpenAI models breaching Hugging Face, the first documented agentic ransomware operation named JADEPUFFER, and a new AI-driven supply chain threat known as 'phantom squatting'. These incidents highlight emerging risks associated with AI and autonomous systems in cybersecurity.

ransomwarehigh

Government Agencies Face Daily Ransomware Attacks, Study Warns

A recent study indicates that government agencies are frequently targeted by ransomware attacks. Attackers exploit the critical nature of public services, knowing that disruptions can be particularly damaging and may increase the likelihood of ransom payments.

scattered spiderhigh

Two Scattered Spider members sentenced to 66 months for London transport cyberattack

Two individuals, Thalha Jubair and Owen Flowers, have been sentenced to 66 months in prison in the UK for their roles in a cyberattack that disrupted Transport for London's operations. The pair were identified as leading members of the Scattered Spider hacking group. Authorities linked them to significant cryptocurrency transactions and numerous cyberattacks, including extortion of US organizations and an attack on the federal court system.

fraud

Cybercriminals Seek Clean Residential Proxies for Fraud

Fraudsters are finding that traditional residential proxies are becoming less effective for carding operations. To bypass advanced fraud detection systems, criminals are now combining these proxies with other identity information, such as browser fingerprints and device profiles.

malwarehigh

North Korean Hackers Use SVG Images to Hide Malware in Fake Coding Tests

North Korean threat actors, associated with the Contagious Interview campaign, are using steganography within SVG image files to hide malware. This technique is employed in a campaign that uses fake job postings and coding challenges to deliver malicious payloads, including credential and crypto wallet stealers.

phishinghigh

Forg365 Phishing Platform Leverages AI for Microsoft 365 Account Theft

A new phishing-as-a-service operation, dubbed Forg365, is targeting Microsoft 365 accounts. This platform employs a combination of adversary-in-the-middle techniques and device code methods, enhanced by AI-generated lures to trick users into compromising their accounts.

copyright infringement

OnlyFans Models Are Accidentally Making Hacked Government Websites Disappear

Adult content creators are inadvertently causing hacked government and university websites to disappear from search results. This occurs when creators issue copyright takedown requests, often under the Digital Millennium Copyright Act (DMCA), to remove pirated content from search engines. Scammers have been exploiting insecure government and educational domains to host malicious pages, using the names of adult creators to lure victims. Consequently, DMCA requests aimed at protecting creators' content are leading to the removal of these compromised, but legitimate, government and educational web pages from search results.

accenture

Accenture confirms breach after hacker offers stolen data for sale

Accenture has verified a data breach following claims by a threat actor who offered stolen information for sale. The compromised data reportedly includes 35 GB of source code and other sensitive material.

hacktivism

Spain arrests suspected hacker linked to Russian hacktivist campaign

Spanish police, with assistance from the FBI, have arrested an individual suspected of supporting the pro-Russian hacktivist group Cyber Army of Russia Reborn. The arrest, which occurred in March but was announced recently, is part of a broader international effort to combat cybercrime. The suspect allegedly provided logistical support to another hacker and participated in activities aimed at spreading pro-Russian narratives.

law enforcement

Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker

A court filing revealed that a persistent Windows device ID helped the FBI trace an alleged Scattered Spider hacker. The identifier linked the suspect to a break-in at a luxury jewelry retailer.

phishing

Two arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraud

Two individuals were arrested over a phishing operation that harvested credit card details. The arrests come as the Netherlands is named the worst country in Europe for payment fraud.

threat actor

UAT-7810 continues building ORB networks using new malware

The threat actor UAT-7810 is reportedly developing new custom malware. This malware is being utilized to establish ORB networks, indicating an evolution in their tools and ongoing malicious operations.

CVE-2025-3248critical

Sysdig clocks first documented case of agentic ransomware

Researchers have documented the first instance of agentic ransomware, where an artificial intelligence agent autonomously managed an entire extortion operation. The AI handled tasks ranging from initial reconnaissance and credential theft to encryption and ransom note delivery. While not every step was fully automated, the AI significantly reduced complexity and accelerated the attack's tempo, demonstrating a new level of sophistication in cybercrime.

email securityhigh

Cybercriminals Target Email Inboxes for Identity Theft

Cybercriminals are increasingly targeting email inboxes because they serve as a central hub for personal information and online accounts. Gaining access to an inbox can allow attackers to control other digital identities and access sensitive data.

gamaredonhigh

Gamaredon Group Evolves Tactics With New Tools and Alliances

ESET Research has identified new tactics employed by the Gamaredon group, including the use of tunnels, dead drops, and worker processes. The threat actor is increasingly leveraging legitimate online services to conceal its command-and-control infrastructure and to exfiltrate stolen data.

e-commerce fraudhigh

Fake shops target shoppers across Europe with fake Samsung deals, counterfeit goods and World Cup scams

Cybercriminals are orchestrating sophisticated, multinational fake online shop operations across Europe, impersonating major brands like Samsung, Nike, and Amazon. These scams leverage social media, WhatsApp, and email to trick consumers into purchasing counterfeit goods, sharing personal information, or falling victim to World Cup-themed promotions. The operations are highly organized, utilizing rotating domains, misleading redirects, and localized content to evade detection and maximize reach.

fifa world cup

Cybercriminals Are Targeting the FIFA World Cup 2026

Cybercriminals are leveraging the upcoming FIFA World Cup 2026 to conduct various malicious activities. These attacks include phishing campaigns, the distribution of fake tickets, malware deployment, impersonation tactics, and attempts to steal user credentials.

CVE-2025-55182high

EtherRat and TukTuk Malware Campaigns Lead to The Gentleman Ransomware

The EtherRat malware, initially identified in late 2025 targeting Linux servers via a React2Shell vulnerability, has evolved. A Windows variant emerged in early 2026, with investigations revealing earlier activity. These campaigns, alongside the TukTuk C2, have now been linked to the deployment of The Gentleman ransomware.