-->
#1 Trusted Cybersecurity News Platform
Followed by 5.70+ million
The Hacker News Logo
Get the Latest News
cybersecurity

Cybercrime | Breaking Cybersecurity News | The Hacker News

Category — Cybercrime
ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories

ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories

Oct 08, 2026 Hacking News / Cybersecurity News
The crooks have trust problems of their own. One ransomware affiliate decided to keep the profits for himself. Elsewhere, an attacker left a server exposed, complete with tools and traces of an intrusion. Apparently, keeping things secure is a problem on both sides of the fence. The rest of the week isn't much more reassuring. Malicious code turned up in developer packages and extensions that looked harmless. Familiar online services helped phishing emails appear legitimate. A basic file upload flaw gave attackers a way in, while weak session cookies made impersonation far too easy. Even AI assistants are getting their own instructions hidden inside phishing messages now. What's interesting is the gap between effort and results. Some attacks involve several stages, careful timing, and plenty of tricks. Others get surprisingly far because of a bad design choice or something nobody bothered to check. Both seem to be working well enough. Anyway, here's what else turned u...
ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms

ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms

Oct 08, 2026 Agentic AI / Web Security
Cybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence (AI) pen testing tool named ARTEX to carry out the attacks. The activity , per CrowdStrike Intelligence, was active from late September to early October 2026, and resulted in data exfiltration from various South Korea-based financial firms , including Shinhan Bank and Yegaram Savings Bank. "In this activity, the threat actor leveraged ARTEX, a recently released open-source agentic penetration testing (pentesting) tool developed in China, alongside large language models (LLMs)," the cybersecurity company said . CrowdStrike said it discovered the campaign after it identified a set of open directories hosted at a Hong Kong-based IP address, exposing Claude Code session histories, Claude memory files, and ARTEX configuration files. The campaign has not been attributed to any known threat actor or group. But evidenc...
Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia

Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia

Oct 08, 2026 Web Security / Threat Intelligence
Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials. Attackers are increasingly building filtering, session management, and traffic controls into the infrastructure that delivers the phishing page itself. ANY.RUN has identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe, and Australia. The campaign uses a multi-stage routing chain to screen visitors and automated traffic before delivering an Adobe-themed Device Code phishing page. For security teams, that makes Wazza more than another malicious URL. The campaign shows how attackers can control the path to the final lure, making the initial link less informative and potentially complicating automated detection. MSSPs face an added challenge, as they investigate alerts across multiple customer environments while keeping response times under control. That uncertainty can translate directly into longer in...
cyber security

New Priorities for Critical Infrastructure: A Nation-State Threat Roundtable

websiteSANSCritical Infrastructure / Cybersecurity
Experts from SANS Institute, FirstEnergy, MITRE and Dragos unpack what leaders should prioritize next.
cyber security

AI adoption is outpacing IT visibility

website1PasswordSaaS Security / AI Governance
Individual dashboards only show part of the story. Learn how IT can get a unified view of AI spend and usage.
U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks

U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks

Oct 08, 2026 Cybercrime / Cyber Espionage
The U.S. State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 2021 Microsoft Exchange Server attacks known as HAFNIUM. The reward is for information leading to his identification or location, the news outlet  NTD reported  this week, citing a notice from the department's Rewards for Justice program. Zhang remains at large, U.S. authorities say, meaning he has not been arrested. The charges against him have not been tested in court. Rewards for Justice  is the State Department's national security rewards program. It says it has paid more than $250 million to over 125 people since 1984. Zhang is wanted for his alleged role in "malicious cyber activities against U.S. critical infrastructure," NTD quoted the notice as saying. The amount and that wording match an offer the program was already making  in January 2025 . That of...
MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data

MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data

Oct 08, 2026 Cybercrime / Ransomware
The U.S. Department of Justice (DoJ) on Wednesday announced charges against a 50-year-old U.S. and Israeli national for allegedly defrauding ransomware victims by secretly paying the attackers to obtain decryptors while claiming to use proprietary tools to recover their data. Zohar Pinhasi (aka Zack Silver and Zack Green) has been charged with two counts of wire fraud and one count of wire fraud conspiracy. If convicted, the defendant faces up to 20 years in prison for each count. "By falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself," said U.S. Attorney Joseph Nocella, Jr. for the Eastern District of New York. Pinhasi, who owned and operated a Florida company called MonsterCloud, is alleged to have made false representations to ransomware victims, urging them not to pay a ransom and claiming to have "proprietary tools" and "advanced decryption tec...
FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

Oct 07, 2026 Cybercrime / Network Security
The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. "The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat actors to harvest and crack authentication data at scale," the agencies said . "Initial findings indicate attackers are continuing to scan internet-exposed Fortinet firewalls using previously obtained compromised credentials." FortiBleed was first documented by SOCRadar and Hudson Rock in June 2026, with the activity targeting thousands of Fortinet firewalls as part of a global campaign. In all, the Russian-speaking operation is estimated to have netted more than 86,644 working device credentials spanning 194 countries as of June 19, 2026. "The scale under discus...
FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

Oct 06, 2026
The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the theft of personal details of thousands of bureau employees. That's according to a report from Reuters, citing two sources familiar with the matter. "To date, our review has determined that the incident occurred as the result of a security failure ​of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the ​platform," Brett Leatherman, assistant director of the FBI's cyber division, was quoted as saying to Reuters. "As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce." Although the name of the third-party organization was not disclosed by the FBI, Reuters reported that it's Oracle PeopleSoft, which the ShinyHunters group said it exploited...
ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members

ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members

Oct 04, 2026 Cybercrime / Data Breach
A suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters reported , citing three people familiar with the matter. Rey, whose real name is Saif ‌al-Din Khader, is said to have been brought into custody on September 29, 2026, and cooperating with the U.S. Federal Bureau of Investigation (FBI) and law enforcement to identify other members of the group. "His cooperation is critical to ongoing efforts to arrest these hackers," a source told the news agency. Rey, who also went by the online alias ReyXBF, is not an unknown face. In a report published in November 2025, independent security journalist Brian Krebs labeled him as one of the three administrators of Scattered LAPSUS$ Hunters (SLH or SLSH), a group that's assessed to be an amalgamation of Scattered Spider, LAPSUS$, and ShinyHunters. "Previously, Rey was an administrator of the data leak w...
Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers

Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers

Oct 01, 2026 Ransomware / Cybercrime
Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid. The 16-year-old was one of 3 people arrested on September 30, when police also took control of that site. Investigators identified him as KillSec's suspected administrator and main operator,  Hamburg police said  on October 1. Police and prosecutors in Hamburg, Germany, led the operation. The Guardia Civil and the Mossos d'Esquadra, both Spanish police forces, detained him in Alicante and searched a home and an office at a hotel in the province. Their joint statement,  carried by elperiodic.com , calls him one of the group's administrators and its presumed main administrator. The other 2 people arrested are in their 20s, one in the U.K. and one in Romania, a spokesperson for Europol, the European Union's police agency,  told Reute...
ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories

ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories

Oct 01, 2026 Hacking News / Cybersecurity News
This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than people expect. A model check can run code. A cache can mix up requests. A public secret can stay useful for years. That is the lesson running through the list. Attackers do not always need a brilliant new trick. They can hide commands in public infrastructure, reuse old flaws, abuse weak defaults, or let automation stitch together a rough path that still works. Faster tools are changing the pace, but basic mistakes are still doing plenty of the work. So the interesting question this week is not “what broke?” It is “what did we assume was safe because it looked ordinary?” The full list has answers. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.
Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation

Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation

Sep 29, 2026 United States
Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. "It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters," the Politie Landelijke Opsporing en Interventies said in an X post Monday. Police said the individual is expected to appear before the Rotterdam District Court on September 29, 2026. Although law enforcement officials did not disclose any additional details, independent security journalist Brian Krebs and DataBreaches.Net identified the arrested man as Pepijn van der Stap (aka Umbreon), who was previously apprehended in 2023 for his role in a series of data thefts and extortions. Per DataBreaches.Net, van der Stap was arrested on September 15, 2026. In 2023, it emerged that the individual worked at cybersecurity company Hadrian and volunteered at the Dutch Institute for Vulnerability Disclosure (DIVD). ...
Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

Sep 28, 2026 Vulnerability / Cybercrime
The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system. Exchanges keep most customer funds in offline cold wallets and use hot and warm wallets to process withdrawals. Transfers from those wallets must still be approved before they are signed. The stolen funds came from part of Bitget's hot and warm wallets, and its cold wallets were not affected. Bitget  said last week  that a critical backend system in its wallet infrastructure had been compromised and used to spoof transaction data and trigger its approval process. It had not said how the attacker got in. Bitget CEO Gracy Chen described the attack on Monday in a livestream, in an interview with  The...
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Sep 26, 2026 Vulnerability / Web Security
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution. The vulnerability was first exploited as a zero-day in attacks against academic institutions to conduct reconnaissance, deploy remote access software like MeshCentral agent for persistence, move laterally over SSH, run a shell script to connect via SSH to other internal PeopleSoft machines using known username/password combinations, and steal data. At that time, Google-owned Mandiant said it initiated notifications to over 100 global organizations whose IP addresses matched vulnerable endpoints, most of them located in the U.S. "This new wave of activity stems from UNC6240 modifying its exploit to bypass web application firewall (WAF...
Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

Sep 25, 2026 Cryptocurrency / Cybercrime
Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.  "At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving a limited number of hot wallets," Bitget said in a post shared on X. "Bitget's cold wallets and the overwhelming majority of platform assets remain secure and unaffected." The company emphasized that customer account balances remain accurate, and deposits and trading continue to operate normally. However, withdrawals have been temporarily suspended out of an abundance of caution while a "comprehensive security review" is underway. Bitget did not disclose any details on how the attack took place, but said it has enlisted the help of Google-owned Mandiant and SlowMist for a third-party investigation. "Bitget Wallet operates as a self-custodial wallet on a completely separate and independent infrastruc...
ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories

ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories

Sep 24, 2026 Hacking News / Cybersecurity News
This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked a hundred times before. That is the thread running through the pile. Trusted paths get poisoned. Old bugs find new jobs. AI tools leak more than expected. Fake prompts look real enough. And some attacks barely need an exploit at all — just one weak setting or one person doing what the screen tells them. Nothing here looks especially dramatic. That is what makes it useful. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.
17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360

17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360

Sep 24, 2026 Social Engineering / Cybercrime
ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new global threat report traces the technique from a novelty in late 2023 to a subscription product with on-chain infrastructure and a state-sponsored user base, and explains why blocking malicious domains is no longer a useful defense. Read the full report here:   https://www.ctm360.com/reports/clickfix-beyond A particular kind of security problem no patch will close. ClickFix is one of them. The attack begins with a page that presents a problem the user believes is theirs to solve. A human verification check that will not complete. A browser that cannot render the page. A document that will not open. A Mac that is running low on storage. The page offers a remedy in the form of instructions, quietly writes the "fix" to the clipboard, and asks the user to open a system interface they already trust, paste, and press Ent...
This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move

This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move

Sep 23, 2026 Artificial Intelligence / Malware
A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is. Talos found the malware with  CAIRN , an open-source tool it released the same day to hunt for malware that uses AI services. The malware is at least three months old, because Talos's analysis of the code is dated June 17, 2026. The researchers did not describe how the malware would get onto a victim's computer. It said clues in the code tied the developer to criminal forum posts about carding, the trade in stolen card data, dating to 2025. How the AI Vote Works Malware usually takes orders from a command-and-control (C2) server that the attacker runs. CLOSEDQUORUM instead asks up t...
ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants

ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants

Sep 23, 2026 Data Breach / Cybercrime
The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency. "We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job," the group said in a statement posted on their dark web site. "Whether it be a Special Agent or any other role within your agency. The following FBI services were compromised: Criminal Justice (CJ), HR, Medlink, and more." The development was first reported by 404 Media. ShinyHunters said the FBI was targeted in response to a May 2026 public service announcement (PSA) that detailed the threat actor's targeting of Canvas , an online Learning Management System (LMS), while urging victims not to pay. The attackers, in their own counter PSA, described them as "substantial false allegations," adding, "w...
Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

Sep 22, 2026 Artificial Intelligence / Cybercrime
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs. Microsoft is tracking the threat actors behind the development and support of EvilTokens as Storm-2992 . In tandem, the Metropolitan Police Service arrested two men, aged 32 and 38, on September 11, 2026, in connection with the illicit commercial operation. The tech giant described EvilTokens as a "powerful cybercrime platform" that used AI to compromise email accounts and design roadmaps for financial fraud and scams. "While EvilTokens helped cybercriminals access email accounts, at the center of the service was an AI-style chatbot th...
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure

ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure

Sep 21, 2026 Malware / Cybercrime
Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript . "ChainScript has appeared under multiple build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66, while presenting itself as Spotify, Zoom Workplace, and Microsoft Teams software," Blackpoint Adversary Pursuit Group (APG) researchers Sam Decker, Andi Ursry, and Nevan Beal said . Like many malware families observed in recent months, ChainScript employs an EtherHiding -style command-and-control (C2) discovery technique that makes use of a Polygon smart contract to locate its active WebSocket infrastructure. ChainScript is a full-featured RAT that provides extensive remote access to the operator, including interactive CMD and PowerShell, file operations, screenshot capture, payload deployment, cryptocurrency wallet enumeration (both desktop apps and browser extensions), and remote JavaScript execution. The...
⚡ Top Stories This Week
Expert Insights Articles Videos
Cybersecurity Resources