-->
#1 Trusted Cybersecurity News Platform
Followed by 5.70+ million
The Hacker News Logo
Get the Latest News
cybersecurity

Cybercrime | Breaking Cybersecurity News | The Hacker News

Category — Cybercrime
Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware

Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware

Aug 14, 2026 Malware / Cybercrime
Threat actors are acquiring expired domains to inherit website traffic and reputation to redirect victims to scams and malware on a large scale. DNS threat intelligence firm Infoblox has given the name dropcatch domains to those that get a second chance, where an expired domain becomes available for registration and is then snapped up by another party. During the first half of 2026, 50,400 dropcatch domains were re-registered each day in the generic top-level domains (gTLDs) like ".com" alone, a figure that jumps to around 65,000 when country code top-level domains (ccTLDs) are taken into consideration. These account for nearly 20$ of all daily gTLD and ccTLD registrations, meaning one out of five newly registered domains is a dropcatch domain. "These domains can be particularly interesting, even dangerous, because they inherit reputation and sometimes connections from their previous life," Infoblox said in an exhaustive three-part report shared with The Ha...
CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps

CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps

Aug 14, 2026 United States
Cybersecurity researchers have uncovered a large-scale, global recruitment-themed phishing campaign that uses fake interview scheduling pages and Browser-in-the-Browser (BitB) windows to steal Google and Facebook credentials and, in more advanced cases, relay multi-factor authentication (MFA) prompts in real time. CTM360, which detailed the activity in a new report titled RecruitTrap , said it identified more than 3,000+ phishing URLs over two months. The campaign impersonated real recruiters and recruitment processes associated with more than 50 organizations across 14 sectors . Marketing professionals accounted for the majority of observed targets. The focus on marketing roles appears deliberate. Compromised marketing accounts can provide access to advertising platforms, corporate social media profiles, customer data, email, and other business-critical services. Read the full report here: https://www.ctm360.com/reports/recruittrap-browser-in-the-browser-bitb-recruitment-scam...
Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups

Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups

Aug 14, 2026 Cybercrime / Offensive Operation
A new White House memo signed by U.S. President Donald Trump has instructed the National Coordination Center (NCC) to establish a program that would allow private sector companies to take advantage of their "innovative capabilities" to break into foreign Transnational Criminal Organizations (TCOs) and disrupt them. "By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens," the memo reads . To that end, the NCC has been tasked with setting up a program within 60 days that allows authorized companies to conduct two types of operations against TCOs upon obtaining approval: cyber surveillance operations, which can access sensitive data without authorization from the owner or operator, and cyber effects operations, which can result in disruption, denial, degrad...
cyber security

AI Is Flooding Security with Bugs Nobody Proved

websiteSANSVulnerability / Artificial intelligence
Stephen Sims on why unproven AI findings pile up as a triage burden. Read the full SANS blog.
cyber security

Exploit Time Just Dropped From 30 Days to 30 Minutes

websiteRecoAI Security / SaaS Security
Download the 11-step checklist CISOs use to close exposure windows first.
ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories

ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories

Aug 13, 2026 Hacking News / Cybersecurity News
Some weeks have one big security story. Others bring many smaller updates that are easy to miss but still matter. This week has plenty of them, covering cloud services, AI tools, malware, data breaches, scams, and new attack methods. The latest ThreatsDay Bulletin puts all of these short updates in one place, so you can quickly catch up on what happened, what changed, and what security teams should know. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.
WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud

WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud

Aug 13, 2026 Malware / Mobile Security
A previously unseen Android near field communication ( NFC ) relay malware family dubbed WindRelay is being deployed in conjunction with a known remote access trojan (RAT) called SpyNote as part of a contactless payment fraud scheme. The purpose-built malware, according to Group-IB, is designed to capture live card data via NFC and transmit it to fraudsters in real time. It was first detected in the wild in late August 2025. "SpyNote's Accessibility Service access lets the fraudster sideload and activate the NFC app silently, with no screen sharing ever triggered," researchers Alexander Grabko, Konstantinos Angelopoulos, Pavlos Gaitanis, and Bruno Bijelić said .  These attacks typically work by luring prospective targets via phishing, smishing, or vishing scams into sideloading a malicious app. Once installed, the threat actor abuses SpyNote's remote access to install the NFC relay malware without any further user interaction. To lend credibility to the sch...
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt

DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt

Aug 11, 2026 Ransomware / Blockchain
The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience. "Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process," the Microsoft Threat Intelligence team said . The tech giant said it observed the ransomware being deployed by multiple threat actors, including an affiliate for Lynx and INC ransomware. DeadLock was first detected in July 2025, employing double extortion tactics to encrypt victim environments and apply pressure by threatening to publicly release exfiltrated data. As of this month, the group has claimed 96 victims , with most of them located in Italy, Spain, Poland, Türkiye, and the U.S. In an analysis published earlier this January, Singapore-headquartered Group-IB said the group has managed to keep a lowe...
Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks

Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks

Aug 11, 2026 Ransomware / Threat Intelligence
Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. "Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations," CISA Acting Executive Assistant Director for Cybersecurity, Chris Butera, said. Attacks deploying the ransomware have leveraged security flaws in internet-facing Fortinet FortiOS and FortiProxy ( CVE-2024-55591  and CVE-2025-24472 ) appliances to obtain initial access, and then deploy the Gunra ransomware as part of a double extortion model that combines data exfiltration and data encryption for maximum impact. Victims who refuse to pay up within five to seven days have their data published ...
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

Aug 10, 2026 Ransomware / Cybercrime
Microsoft has disclosed that Storm-1175 , a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor . The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said. "StormEncryptor is written in C++ and appends the file name extension .encrypted to files it encrypts," Microsoft noted in a series of posts on Bluesky. "It then drops a ransom note named !!!README_FIRST!!!.txt to every scanned directory." Although the exact vulnerability exploited by the threat actor as part of this campaign is unclear, the tech giant said it likely involves the exploitation of CVE-2026-18577 , a newly disclosed security flaw in N-able N‑central, to obtain initial access. The vulnerability is assessed to be a patch bypass for CVE-2026-18556, both of which allow authentication bypass and account takeover in susceptible vers...
Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials

Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials

Aug 10, 2026 Malware / Cybercrime
Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been observed delivering a browser wallet and credential stealer. The names of the extensions are below - helper-beeps.solidity-pro web3devtoolsx.solidity-pro Although neither of the extensions is now available on Open VSX, the GitHub repository for " web3devtoolsx/solidity-pro " continues to remain accessible as of writing. According to Yeeth Security , early iterations of the extensions – from 1.0.0 through v2.4.x – were found to beacon to Cloudflare Workers endpoints to retrieve an encrypted Python payload and execute it. Subsequent versions starting with v3.0.0, on the other hand, have shifted to a full-blown information stealer that can collect browser profiles, crypto wallets, source-control tokens, API keys, SSH keys, and Telegram bot tokens. The captured data is then exfiltrated via a Telegram bot u...
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

Aug 07, 2026 Malware / Social Engineering
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that's compatible with the computer's CPU architecture. "While the malware payload is capable of stealing passwords, its most interesting function is its capability to slowly deplete cryptocurrency accounts, siphoning their contents into accounts under the threat actor's control," Huntress security researcher Andrew Brandt said . The attack chain begins with pasting a ClickFix command into the Terminal app, triggering the execution of a Bash profiler/loader that collects extensive system details and then retrieves a Mach-O payload that matches the victim's processor architecture. The payload is a Go-based stealer that can ...
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

Aug 07, 2026 Phishing / SaaS Security
A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to a data extortion group known as UNC6671 . "UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via their personal mobile devices," Google Threat Intelligence Group (GTIG) and Mandiant said in a report. These calls are designed to trick victims into spoofed login portals where adversary-in-the-middle (AitM) infrastructure intercepts credentials and multi-factor authentication (MFA) tokens. The threat actors then leverage the captured data to establish session persistence and deploy automated Python and PowerShell scripts for data exfiltration from enterprise cloud environments and SaaS applications, including Microsoft 365 and Okta. According to the tech giant, UNC6671 has d...
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

Aug 07, 2026 Phishing / Email Security
Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email. "The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic," Arctic Wolf Labs said . "Automated activity maintains compromised sessions at approximately eight-hour intervals." The activity is assessed to impact organizations across healthcare, education, manufacturing, government, and professional services sectors located in the U.S., Canada, and Europe. It shares tactical overlaps with Payroll Pirate attacks tracked by Microsoft under the moniker Storm-2755 . Payroll Pirates is the designation assigned to a broader financially motivated threat cluster that involves hijacking the accounts of employees to reroute sal...
TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

Aug 07, 2026 Cybercrime / Vulnerability
A new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training their sights on the software supply chain. "The connection is supported by overlapping domains, malware deployment paths, staging techniques, backend infrastructure, and operational tradecraft," Oligo Security researchers Avi Lumelsky and Gal Elbaz said . This includes two campaigns observed in the second half of 2025: ShadowRay 2.0 (aka IronErn), which involved hijacking artificial intelligence (AI) infrastructure into a self-propagating botnet, and TA-NATALSTATUS , which targeted exposed Redis servers to deliver cryptocurrency miners. TA-NATALSTATUS is assessed to be an evolution of a prior campaign that was detailed by Trend Micro in April 2020 that involved targeting Redis servers to deploy malware. This suggests that the threat actor h...
ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories

ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories

Aug 06, 2026 Hacking News / Cybersecurity News
Apparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF can finish the job. This week runs on cheap leverage: exposed servers, recycled bugs, poisoned agent instructions, remote-access tools dressed as support software, and trusted defaults doing attackers a favor. Nothing here is especially mystical. Just ordinary systems trusting slightly too much, slightly too early. The full list follows. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.
CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

Aug 06, 2026 Vulnerability / Blockchain
Coinspect has identified CryptoJS.lib.WordArray.random() as the weak random number generator behind the Ill Bloom wallet drains . Introduced in the JavaScript cryptography library 12 years ago, the function supplied weak entropy that affected wallet apps used to generate recovery phrases. Coinspect's on-chain analysis puts the measured theft across two sweeps since late May at a lower bound of roughly $5.7 million. The blockchain security firm, which coined the Ill Bloom name in July, has now confirmed five applications that used the generator as an entropy source for recovery-phrase generation: RRWallet , which Coinspect says is discontinued. No fix. Bexo Wallet , which Coinspect says has been fixed in version 20.1.0, although the updated builds had not yet been uploaded. NanChat , which independently confirmed versions before 1.3.0 were affected. Fixed in 1.3.0. Bitcoin Libre , which Coinspect says fixed the issue in version 4, released July 2024. Milo , w...
Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service

Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service

Aug 06, 2026 Ransomware / Cybercrime
A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel , the ransomware-as-a-service operation he stood up in 2021. Between 2021 and 2023, Ransom Cartel conspirators attacked at least 18 companies, including firms in California, New York and Nebraska, and others abroad, according to the Justice Department. Silnikau, a 40-year-old Belarusian national who worked under the handles "J.P. Morgan," "lansky" and "xxx," did not carry out most of those intrusions himself. He built the business around them: the locking software, the stolen credentials he bought from initial access brokers, and a hidden panel where affiliates monitored attacks, negotiated with victims and split proceeds. He ran a ratings system that rewarded the productive ones, and pushed ransom payments through cryptocurrency mixers. Sixteen years run past the 13 years and seven months handed to Yaroslav ...
Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

Aug 06, 2026 Cybercrime / Law Enforcement
Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts . The intrusions reached at least 165 organizations and exposed records belonging to at least 100 million people. Moucka, 26, of Kitchener, Ontario, personally took at least $495,000 from ransoms and data sales. He is due to be sentenced on October 27 and faces a two-year mandatory minimum on the identity theft count and up to 30 years on the rest. What got the attackers in was old passwords. The credentials had been harvested years earlier by infostealer malware and never rotated, and the accounts had multi-factor authentication (MFA) switched off. No exploit, no flaw in the platform. The Justice Department has never named the company, in Wednesday's announcement or in the October 2024 indictment, identifying the victim only as a U.S. software-as-a-service (SaaS) pr...
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

Aug 05, 2026 Malware / Threat Intelligence
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks. The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software download. Microsoft said the wider cluster distributed MacSync and Atomic Stealer (AMOS) ; the chain it analyzed through the gate ended in AMOS. The attack still requires the user to copy and run an obfuscated command in Terminal. That command retrieves scripts and launches an infostealer targeting credentials, browser data, authentication stores, cryptocurrency wallets, and sensitive files. Microsoft has not disclosed victim numbers, targeted sectors, or the identity of the operators. Users should not follow any website, CAPTCHA, chat, or download instruction that asks them to paste text into Terminal. Micro...
OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes

OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes

Aug 05, 2026 Cybercrime / Artificial Intelligence
OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that end, it banned a coordinated network of ChatGPT accounts likely originating from Southeast Asia and operating from the city of Poipet, a region with extensive ties to scam compounds and human trafficking in the past. The cluster of accounts is said to have used OpenAI's models to create and support the operation of fake online personas, generate and translate messages sent to scam targets, create promotional content for their fraudulent schemes, and assist with day-to-day activities. The promotional content included creating social media advertisements for "chatter" jobs in Poipet specifically targeting users in Bangladesh and India that promised a base salary of $800 (and a bonus of $100 for "full attendance"), alon...
Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

Aug 05, 2026 AI Security / Threat Intelligence
Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms. One such service, Poison Claude, claims to offer access to Anthropic's large language models (LLMs), including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6. "Advertisements for Poison Claude explain how the service can offer the cheap tokens: by taking advantage of free bonus credits, such as the US$100 bonus credit on AWS for Bedrock accounts," Okta researchers Jeremy Kirk and Mathew Woodyard said in an analysis published Tuesday. "The service plainly states on its website that: 'We add those accounts to our pool, your request is routed to a specific account under the hood (you don't see this), and you get charged 5-15% of the official per-token price depending on the model.'" Poison Claude accepts payments in cryptocurrencies. Once a cus...
Expert Insights Articles Videos
Cybersecurity Resources