LIVE · cybersecurity feed
Live wire
OpenAI Announced $1B in Defensive Tools for Water UtilitiesAttackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS CredentialsCVE-2026-59346 · Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host CodeCVE-2026-32475 · Elementor Pro WordPress Plugin Vulnerability Exploited to Hack SitesBroadcom Patches Critical VMware Workstation and Fusion VM-Escape VulnerabilitiesHackers Leak Millions of Airport Passenger Records After Ransom RefusalUsing a VM to Contain an AI AgentCVE-2026-73749 · HPE Patches Critical RCE Vulnerabilities in AOS-CXCVE-2026-14894 · Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE FlawsCisco searched for IOS XR bugs and found so many it rolled them into an update release

fraud

8 stories
androidhigh

Android Malware Steals Payment Card Data via NFC

Researchers have identified a new Android malware called WindRelay that can intercept payment card information transmitted via NFC while the card is still in the user's possession. This malware operates in conjunction with the SpyNote trojan, granting attackers remote control over infected devices. The attack typically begins with a social engineering tactic where a fraudster impersonates a bank representative.

fraud

Cybercriminals Seek Clean Residential Proxies for Fraud

Fraudsters are finding that traditional residential proxies are becoming less effective for carding operations. To bypass advanced fraud detection systems, criminals are now combining these proxies with other identity information, such as browser fingerprints and device profiles.

cybersecurity

Felons, Fraudsters Flog Offensive Cybersecurity Startup

A cybersecurity startup named IRIS C2, which claims to acquire zero-day vulnerabilities for potentially millions of dollars, is reportedly run by convicted felons Jack Burkman and Jacob Wohl. The duo has a history of operating under assumed names and engaging in fraudulent activities, including spreading misinformation and securities fraud. Despite their past, IRIS C2 is actively recruiting vulnerability researchers and claims to be developing offensive cybersecurity capabilities, though their specific government contracts remain unclear.

malwarehigh

RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service

A new Malware-as-a-Service offering called RedWing packages Android bank fraud tools and is rented via Telegram. It provides ready-made malware capable of taking over phones and stealing banking credentials and one-time passcodes.

phishing

Two arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraud

Two individuals were arrested over a phishing operation that harvested credit card details. The arrests come as the Netherlands is named the worst country in Europe for payment fraud.

supply chainhigh

OpenClaw Skill Marketplace Faces AI Supply Chain Threat

Researchers have identified malicious skills within OpenClaw's ClawHub marketplace that evade automated detection. These skills are designed to deploy information-stealing malware and conduct automated financial fraud.

scam

The Purchase Scam Tactic Headed for the World Cup | Recorded Future

A sophisticated purchase scam is leveraging compromised legitimate websites to trick users searching for event tickets or merchandise. These scam domains are hidden from typical search monitoring, making them difficult to detect and disrupt. The tactic is already being used for World Cup-related fraud and is expected to expand to other large events.

smishing

Operation Road Trap: Fake toll and parking texts are spreading worldwide

Scammers are actively conducting a global smishing campaign, sending fake text messages that impersonate toll and parking authorities. These messages aim to trick drivers into clicking malicious links or providing sensitive information. The campaign has been ongoing since late 2025 and has already distributed tens of thousands of fraudulent texts across multiple countries.