ποΈ U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
The U.S. Department of Justice DoJ on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Center Strike Force to Madagascar to help disrupt 13 scam compounds run by Chinese organized crime.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Multiple espionagemotivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first inthewild use of BlueMoon has been attributed to the Chinaaligned statesponsored group tracked as APT31 aka Bronze Vinewood, Judgement Panda, JungleBamboo,.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π OFAC Sanctions Chinese Scam Platform Xinbi Guarantee π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
The US Treasury has placed sanctions on notorious Chinese cybercrime marketplace Xinbi Guarantee.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
OFAC Sanctions Chinese Scam Platform Xinbi Guarantee
The US Treasury has placed sanctions on notorious Chinese cybercrime marketplace Xinbi Guarantee
β€1
ποΈ Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Nearly one in ten of the internetfacing LiteLLM servers that Wiz Research scanned in February accepted sk1234, the example admin key in LiteLLM's own setup guide. LiteLLM is an opensource AI gateway, the software a company puts between its applications and the model providers it pays for. That key is the gateway's administrator credential. Anyone who holds it can read every.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6 ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence AI model broke into real thirdparty systems, marking the latest in a growing list of cases that have raised concerns about the security risks posed by autonomous AI agents. The AI company said the incident dates back to January 2026 and involved an early version of Claude Opus 4.6 that breached ".π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π Anthropic Reveals Yet Another Cybersecurity Incident π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Anthropic has found a fourth case of its model accessing thirdparty systems without authorization.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Anthropic Reveals Yet Another Cybersecurity Incident
Anthropic has found a fourth case of its model accessing third-party systems without authorization
π’ OpenAI and Anthropic admit rogue AI agents did more than first thought π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
The two companies have shared additional details on agent misbehavior.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
OpenAI and Anthropic admit rogue AI agents did more than first thought
The two companies have shared additional details on agent misbehavior
π’ Cyber researchers issue warning over 'phishing pages that exist only inside the victimβs browser' π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
A blob URL renders and delivers the phishing page inside the targets own browser, making it harder for security scanners to spot.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
Cyber researchers issue warning over 'phishing pages that exist only inside the victimβs browser'
A blob URL renders and delivers the phishing page inside the targetβs own browser, making it harder for security scanners to spot
ποΈ CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
The U.S. Cybersecurity and Infrastructure Security Agency CISA on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities KEV catalog, requiring Federal Civilian Executive Branch FCEB agencies to apply the patches by September 12, 2026. The vulnerabilities are listed below CVE202620079 CVSS score 10.0 An authentication.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π¦
From Infostealer Log to Marketplace Listing: A Technical Walkthrough of the Credential Theft Pipeline π¦
π Read more.
π Via "CYBLE"
----------
ποΈ Seen on @cibsecurity
Infostealer malware is behind a large share of today's credential compromise and it usually doesn't start with a breach at all. When a security team hears "data breach," the instinct is to look for the moment a database was exfiltrated or a network was penetrated. But more often, the real starting point is a single endpoint infection, often on a personal device, that has nothing to do with the organization's perimeter. By the time stolen credentials show up in a breach notification or a dark web alert, they've already passed through several distinct, mechanical stages. Understanding that pipeline rather than waiting for the final alert is what separates reactive security teams from ones that catch exposure early. How Infostealer Malware Powers the Credential Theft Pipeline? W...π Read more.
π Via "CYBLE"
----------
ποΈ Seen on @cibsecurity
Cyble
From Infostealer Log to Marketplace Listing: A Technical Walkthrough of the Credential Theft Pipeline
How infostealer malware fuels the credential theft pipeline β from harvesting and stealer logs to enrichment and dark web marketplace listings.
π FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
The new document appears to be part of a broader shift by the US government towards the proactive disruption of cyber threat actors.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Thre
The new document appears to be part of a broader shift by the US government towards the proactive disruption of cyber threat actors
π¦
Cyble Introduces Major Upgrade to its Executive Monitoring Module π¦
π Read more.
π Via "CYBLE"
----------
ποΈ Seen on @cibsecurity
Cyble has rolled out a significant upgrade to Executive Monitoring inside Cyble Vision, bringing unified findings, AIdriven scoring, and expanded alerting together in a single protection suite. Executive monitoring has historically meant stitching together several things at once. An impersonation tool here, a dark web exposure feed there, a reputation score from somewhere else, and alerts that show up in whatever channel each vendor happened to support. Security teams protecting their executives ended up doing the integration work themselves, correlating findings across tools, and reexplaining risk to the board every quarter using numbers that didn't quite agree with each other. That era is over. This release unifies Mentions, Impersonations, Exposures, and a new Surface Mention...π Read more.
π Via "CYBLE"
----------
ποΈ Seen on @cibsecurity
Cyble
Cyble Introduces Major Upgrade to its Executive Monitoring Module
Cyble has rolled out a significant upgrade to Executive Monitoring inside Cyble Vision, bringing unified findings, AI-driven scoring, and expanded alerting together in a single protection suite.
ποΈ Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not described. One flaw affects Check Point's Security Gateways, its firewall appliances. The other affects those gateways and the Security.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
A suspected Russianspeaking cyber actor has been attributed to the use of artificial intelligence AI to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NGMF and break into hundreds of instances. According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from "45.142.193.132," an IP address that has been linked to.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm GroupIB said in a report published on September 9. A work profile is a separate space that Android typically reserves for employer apps, and what's inside it is kept separate from everything in the personal space. That.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π MantaxOtax Android Malware Combines Ransomware With Spyware π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
MantaxOtax Android malware combines ransomware with extensive spyware capabilities.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
MantaxOtax Android Malware Combines Ransomware With Spyware
MantaxOtax Android malware combines ransomware with extensive spyware capabilities
π CISA Updates Insider Threat Guide With New Mitigation Advice π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
CISA has updated its insider threat guide with new advice on remote work, AI and risk detection.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
CISA Updates Insider Threat Guide With New Mitigation Advice
CISA has updated its insider threat guide with new advice on remote work, AI and risk detection
ποΈ Google Play Early Access Abused to Push Thousands of Deceptive Android Apps ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. Early Access apps are apps that haven't been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications or features they may be working on before their.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π΅οΈββοΈ Indonesia Hit by Android Banking App-Cloning Campaign π΅οΈββοΈ
π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Dark Reading
Indonesia Hit by Android Banking App-Cloning Campaign
The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.
π΅οΈββοΈ Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data π΅οΈββοΈ
π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Threat actors are leveraging Microsoft's Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters.π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Dark Reading
Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
Threat actors are leveraging Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters.
π΅οΈββοΈ Nightmare-Eclipse Strikes Again With 'ShieldCrash' Windows Exploit π΅οΈββοΈ
π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
The disgruntled researcher continued their vendetta against Microsoft by publishing yet another zeroday exploit for Windows Defender.π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Dark Reading
Nightmare-Eclipse Strikes Again With ShieldCrash Windows Exploit
The disgruntled researcher continued their vendetta against Microsoft by publishing yet another zero-day exploit for Windows Defender.