2026-10-02 13:00 UTC
Vendor Research
Cloudflare Security · Nicole Justus · indexed 2026-10-02 13:30 UTC
Fraudsters are increasingly using AI to bypass stateless security checks. Cloudflare's new Account Abuse Protection dashboard uses stateful analysis and edge-generated Hashed User IDs to help teams investigate and block account abuse.
P0
2026-10-02 08:01 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-02 08:20 UTC
Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android applications abusing the API serving as the main conduit for malware and financial fraud, the tech giant said the move would block a major attack pathway. Advanced Protection is a
P0
2026-10-02 05:47 UTC
Other
Group-IB · indexed 2026-10-02 08:20 UTC
Group-IB descubre BraZetsu, un nuevo malware para Windows basado en Python que funciona como un toolkit maestro para Initial Access Brokers y potencia un marketplace clandestino único, mejorado con IA, para comercializar objetivos comprometidos en Iberoamérica y Latinoamérica.
P0
2026-10-01 21:37 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-10-01 21:50 UTC
Law enforcement from multiple countries collaborated to disrupt a cybercrime operation that has claimed some 500 victims worldwide in the past two years.
P15
2026-10-01 18:08 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-01 19:00 UTC
Operation KillSwitch: Europol says the KillSec ransomware group, allegedly led by a 16-year-old, was dismantled after attacks on about 1,000 victims. Law enforcement seized control of KillSec ‘s dark web leak site, the Tor website the group used to threaten victims with publishing stolen files unless they paid up. That single action locked down more […]
P15
2026-10-01 13:00 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-10-01 13:00 UTC
A year-old Chinese threat actor looks like a cybercrime gang, acts like a state-associated APT, and attacks organizations in unexpected places.
P15
2026-09-30 10:45 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 11:45 UTC
ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud
P0
2026-09-29 21:01 UTC
Security Journalism
The Record · indexed 2026-09-29 21:20 UTC
According to court documents, both men pleaded guilty to wire fraud, identity theft and access device fraud charges in June.
P0
2026-09-29 11:41 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-29 11:50 UTC
A Vietnamese national was charged with money laundering for his role in a massive "pig butchering" scam, which defrauded a victim out of $16 million worth of cryptocurrency. [...]
P0
2026-09-29 09:00 UTC
Other
ESET · indexed 2026-09-30 13:30 UTC
Con artists are targeting timeshare owners who want out – and some victims are hit twice
P0
2026-09-29 07:30 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-29 08:10 UTC
Dutch police confirm the arrest of a 24-year-old Amsterdam man as part of an investigation into the ShinyHunters hacking group. Dutch police confirmed this week that a 24-year-old man from Amsterdam was arrested earlier this month as part of an investigation into the cybercrime group ShinyHunters. The suspect appears before Rotterdam District Court today, September […]
P0
2026-09-28 17:42 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 18:40 UTC
The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system. Exchanges keep most
P0
2026-09-27 09:27 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-27 09:40 UTC
Kosovo national Ardit Kutleshi pleaded guilty to running Rydox, a cybercrime marketplace that sold stolen identities and credentials for years. Ardit Kutleshi, 28 years old and a citizen of Kosovo, pleaded guilty last week to building and running the cybercrime marketplace Rydox. The Rydox marketplace has been active since February 2016; it facilitated over 7,600 […]
P0
2026-09-26 14:34 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-26 15:40 UTC
Exploit.in data shows how a 2005 cybercrime forum helped shape today’s ransomware ecosystem, with users and practices surviving for decades. Ransomnews researcher Dancho Danchev dug up a database dump of Exploit.in covering its first three years, from February 2005 to May 2008, and the numbers inside it tell a story about Russian cybercrime that enforcement […]
P15
2026-09-25 12:16 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-25 12:20 UTC
Ardit Kutleshi created and operated Rydox, which allowed miscreants to trade PII and cybercrime tools and services. The post Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court appeared first on SecurityWeek.
P0
2026-09-25 11:35 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-25 11:50 UTC
A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools. [...]
P0
2026-09-24 18:57 UTC
Security Journalism
The Record · indexed 2026-09-24 19:15 UTC
Ardit Kutleshi, 28, was extradited from his home country of Kosovo last year after prosecutors accused him and his older brother of running Rydox — an illicit platform used by cybercriminals to sell stolen personal information, illegal access to devices and other tools for carrying out fraud.
P0
2026-09-24 13:00 UTC
Vendor Research
Rapid7 · Douglas McKee, Director, Vulnerability Intelligence · indexed 2026-09-24 13:20 UTC
Business Email Compromise (BEC) operates on a familiar playbook. Threat actors breach a mailbox, silently monitor operations, map approval chains, and ultimately exploit that access to divert funds or exfiltrate sensitive assets.This dynamic is central to our analysis as we kick off a series around Rapid7's collaborative research with Zimbra; upcoming installments will explore technical details and broader findings based within the Zimbra Collaboration Suite. Our investigation disrupted the tra…
P70
2026-09-23 13:56 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-23 14:20 UTC
ShinyHunters claims FBI breach via PeopleSoft zero-day, steals staff data; FBI investigating, no confirmation yet. The popular cybercrime group ShinyHunters is claiming that it breached the U.S. Federal Bureau of Investigation (FBI) and stole sensitive information belonging to FBI employees and job applicants. The group says the operation was not financially motivated and was instead […]
P25
2026-09-23 11:23 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-23 11:30 UTC
The cybercrime platform leveraged AI at every step of the attack chain, including writing social engineering messages and deciding targets. The post AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft appeared first on SecurityWeek.
P0
2026-09-23 07:13 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-23 07:30 UTC
The cybercrime group is unhappy with its description in an FBI report and threatens to leak stolen information. The post ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report appeared first on SecurityWeek.
P0
2026-09-22 15:51 UTC
Security Journalism
The Record · indexed 2026-09-22 16:00 UTC
Available on Telegram for a $1,500 initiation fee and a recurring monthly $500 subscription, EvilTokens provided cybercriminals with artificial intelligence tools enabling them to compromise accounts, analyze breached inboxes and find the best methods for monetizing their access through fraud.
P0
2026-09-21 20:07 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-09-21 20:30 UTC
ShinyHunters defaced Cl0p's Dark Web site and claims to have stolen victim data, potentially exposing organizations that paid ransoms to renewed extortion attempts.
P0
2026-09-21 14:00 UTC
Security Journalism
The Record · indexed 2026-09-21 14:15 UTC
The ShinyHunters extortion group hijacked the dark web leak site of the prolific Cl0p ransomware gang, according to material posted on the site over the weekend.
P15
2026-09-17 05:59 UTC
Other
Group-IB · indexed 2026-09-17 08:35 UTC
Most fraud platforms only see a threat once it becomes a transaction. This guide compares the top 5 fraud prevention platforms for banks and fintechs in 2026, including Group-IB, Feedzai, Sift, DataVisor, and Kount, and what actually separates them.
P0
2026-09-16 12:45 UTC
Security Journalism
The Record · indexed 2026-09-16 13:00 UTC
Ukraine’s parliament has approved tougher criminal penalties for involvement in fraudulent call centers and the theft of personal data, following a corruption scandal in which prosecutors were accused of taking bribes to protect scam operations.
P0
2026-09-16 07:00 UTC
Other
Group-IB · indexed 2026-09-16 08:20 UTC
Attacks now are cheap, fast, and outsourced. The recent research shows what it changes and how organizations should strategy defense.
P0
2026-09-15 14:22 UTC
Security Journalism
The Record · indexed 2026-09-15 14:40 UTC
Houston-based CenterPoint Energy notified federal regulators about an incident that exposed some customer data on the dark web.
P0
2026-09-15 09:50 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-15 10:00 UTC
Five alleged leaders of the Black Axe cybercrime syndicate, known for its involvement in global-scale cyber-enabled financial fraud, have been extradited to the United States to face wire fraud and money laundering charges. [...]
P0
2026-09-14 12:00 UTC
Security Journalism
The Record · indexed 2026-09-14 12:20 UTC
British fintech company Revolut confirmed disclosing sensitive customer data to fraudsters who submitted emergency data requests from a legitimate government email account.
P0