
A sophisticated banking fraud operation, dubbed REF6045, utilizes a PowerShell toolkit named SCMBANKER, delivered via fake CAPTCHA pages. Unlike automated attacks, this operation is manually controlled, allowing operators to monitor victim banking sessions, deploy fake warnings, and manipulate browser activity. The toolkit also facilitates the installation of commercial remote access tools for full system takeover. Researchers discovered the operation through exposed directories and archives, revealing the use of AI-generated scripts and operator misconfigurations.

Mexico has introduced a new National Cybersecurity Plan to combat threats such as organized crime, geopolitical risks, and AI advancements. This initiative addresses recent cyber incidents affecting government and institutional bodies, aiming to mitigate data theft, ransomware, and service disruptions. The plan acknowledges Mexico's vulnerability to various cyber threats, including ransomware and state-sponsored activities, and identifies the dark web as a platform for planning attacks.