Californian accused of shipping $300M worth of Nvidia chips to China without Uncle Sam’s approval.
OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling.
An Iranian national who was indicted in the United States for hacking hundreds of organizations was extradited from Montenegro this week.
Acting on an FBI-issued arrest warrant, Montenegrin authorities arrested the individual—a dual citizen of Turkey and Iran—on June 25.
The suspect is accused of taking part in numerous cyberattacks against US organizations beginning in 2013. The attacks caused more than $3.4 billion in losses.
Montenegrin authorities did not identify the individual by name, but gave his initials, A.B., and said he is 40 years old.
According to the indictment, the suspects launched attacks against 144 universities in the US and 178 abroad, 42 private companies in the US and 11 abroad, five US government agencies, and at least two NGOs.
The individuals stole over 31 terabytes of scientific resources, including academic data and intellectual property, as well as employee email accounts. The stolen information was given to the Iranian government and sold to Iranian universities.
The US government is offering rewards of up to $10 million for information on five of the Iranian hackers: Mesri, Galekuhi, Kahzadian, Fayaz, and Ballojeh.
Extraditions of Iranian hackers to face trial in the US are extremely rare, because hackers usually operate from inside Iran and avoid traveling to jurisdictions with US extradition treaties.
#TGITM @TheGhostITM
Acting on an FBI-issued arrest warrant, Montenegrin authorities arrested the individual—a dual citizen of Turkey and Iran—on June 25.
The suspect is accused of taking part in numerous cyberattacks against US organizations beginning in 2013. The attacks caused more than $3.4 billion in losses.
Montenegrin authorities did not identify the individual by name, but gave his initials, A.B., and said he is 40 years old.
According to the indictment, the suspects launched attacks against 144 universities in the US and 178 abroad, 42 private companies in the US and 11 abroad, five US government agencies, and at least two NGOs.
The individuals stole over 31 terabytes of scientific resources, including academic data and intellectual property, as well as employee email accounts. The stolen information was given to the Iranian government and sold to Iranian universities.
The US government is offering rewards of up to $10 million for information on five of the Iranian hackers: Mesri, Galekuhi, Kahzadian, Fayaz, and Ballojeh.
Extraditions of Iranian hackers to face trial in the US are extremely rare, because hackers usually operate from inside Iran and avoid traveling to jurisdictions with US extradition treaties.
#TGITM @TheGhostITM
Antino turns Outlook and OneDrive into command-and-control channels.
China-nexus UAT-11587 is using the Rust backdoor in spear-phishing attacks targeting government and policy organizations across Asia.
China-nexus UAT-11587 is using the Rust backdoor in spear-phishing attacks targeting government and policy organizations across Asia.
GitLab has patched a critical 9.9-rated flaw in its self-hosted AI Gateway that could let low-privileged Duo Agent users escape the prompt sandbox and execute commands on the underlying server.
Affected self-hosted deployments should update immediately.
Affected self-hosted deployments should update immediately.
Operation KillSwitch Dismantles KillSec Ransomware Gang; 16-Year-Old Alleged Leader Arrested
ALICANTE, Spain — An international law enforcement operation has dismantled the KillSec ransomware group and arrested a 16-year-old suspected of running it, authorities said. The teen was taken into custody in Alicante, Spain, and identified as the group’s main administrator and operator.
The operation, led by German police in Hamburg, involved authorities from Belgium, the United States, Finland, Greece, the Netherlands, Spain, Switzerland, the United Kingdom, Europol, and Eurojust. Two other suspects were arrested: one in the United Kingdom, identified as Dutch national Fouad Eltibrizi, and one in Romania.
As part of the takedown, investigators seized KillSec’s dark web leak site, replacing it with a law enforcement seizure notice. Five central servers were brought under police control, including the group’s main server and infrastructure used to store stolen data. At least 110 terabytes of stolen data were secured to prevent further unauthorized access.
The investigation covers approximately 1,000 suspected attacks worldwide, with about 500 identified as successful so far. At least 70 attacks have been linked to organizations in Germany, including 18 cases connected to Hamburg.
KillSec launched its ransomware-as-a-service platform in June 2024, charging affiliates a $250 entry fee and allowing them to keep 88% of successful ransom payments. The group exploited software vulnerabilities and poorly secured edge devices to breach corporate systems, steal sensitive data, and extort victims through its leak site. Investigators also found that members used artificial intelligence to help build and maintain their ransomware infrastructure.
Authorities said the probe remains ongoing. Victims and organizations that may have been affected are encouraged to contact law enforcement.
#TGITM @TheGhostITM
ALICANTE, Spain — An international law enforcement operation has dismantled the KillSec ransomware group and arrested a 16-year-old suspected of running it, authorities said. The teen was taken into custody in Alicante, Spain, and identified as the group’s main administrator and operator.
The operation, led by German police in Hamburg, involved authorities from Belgium, the United States, Finland, Greece, the Netherlands, Spain, Switzerland, the United Kingdom, Europol, and Eurojust. Two other suspects were arrested: one in the United Kingdom, identified as Dutch national Fouad Eltibrizi, and one in Romania.
As part of the takedown, investigators seized KillSec’s dark web leak site, replacing it with a law enforcement seizure notice. Five central servers were brought under police control, including the group’s main server and infrastructure used to store stolen data. At least 110 terabytes of stolen data were secured to prevent further unauthorized access.
The investigation covers approximately 1,000 suspected attacks worldwide, with about 500 identified as successful so far. At least 70 attacks have been linked to organizations in Germany, including 18 cases connected to Hamburg.
KillSec launched its ransomware-as-a-service platform in June 2024, charging affiliates a $250 entry fee and allowing them to keep 88% of successful ransom payments. The group exploited software vulnerabilities and poorly secured edge devices to breach corporate systems, steal sensitive data, and extort victims through its leak site. Investigators also found that members used artificial intelligence to help build and maintain their ransomware infrastructure.
Authorities said the probe remains ongoing. Victims and organizations that may have been affected are encouraged to contact law enforcement.
#TGITM @TheGhostITM
UN Security Council to Examine Emerging Technology Threats — On October 29, 2026, the council is expected to discuss how AI, cyberattacks, and autonomous technologies affect international peace and security.
Apple Strengthens Mac Security Against AI Risks — Apple plans stricter controls for Full Disk Access to prevent third-party software and AI agents from freely accessing sensitive user data.
GitLab Patches Critical AI Gateway Vulnerability — GitLab fixed a 9.9-severity flaw that could have allowed authorized users to execute arbitrary commands on self-hosted servers.
Taiwanese Foreign Minister to Visit Arizona — The visit aims to strengthen economic and semiconductor cooperation with U.S. officials and technology companies.
OpenAI Fires Three Researchers Over Confidentiality Violations — The employees were dismissed after an internal investigation found that they improperly shared sensitive company information with an independent AI-safety organization.
Google Introduces Mandatory Android Developer Identity Verification — Developers will have to verify their identities before broadly distributing apps, while unverified sideloaded apps may face a 24-hour installation delay.
U.K. Orders Universities to Halt Cooperation With Chinese Research Institute — The government acted after intelligence warnings that the institute’s projects could support Chinese intelligence and military capabilities.
India Warns Cyberattacks Could Trigger a Global Economic Crisis — India’s central bank governor cautioned that a major cyberattack, war, or technical failure could disrupt financial systems and damage the world economy.
Trump Reportedly Consulted Grok About Maduro’s Arrest — Reports claim Donald Trump asked Grok to predict Venezuelan public reaction to the possible removal and arrest of Nicolás Maduro.
Google Supports AI Education in U.S. Universities — The Google Foundation is funding pilot programs to expand AI skills, faculty training, career guidance, and AI curricula across 30 American universities.
Artificial intelligence is becoming an increasingly powerful tool in modern warfare.
In Gaza, Israel has used the technology in surveillance to identify, monitor and analyse Palestinians
In Gaza, Israel has used the technology in surveillance to identify, monitor and analyse Palestinians