Join the group
GLOBAL NEWS · SECOND-HANDUpdated 16 min ago81 stories · 10 sourcesOSINT · Cybercrime · Scams · Cold cases · Investigations
Global news

Cybercrime

Headlines from trusted publishers worldwide, collected automatically. We have not verified these stories ourselves: every headline links to its original source. Our own reporting is on the front page.

Cybercrime · The Hacker News · 9h ago

P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands

Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword. "Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet

Cybercrime · The Hacker News · yesterday

The Third-Party Agent Problem: Why Security Built for AI You Chose Misses the Agents You Didn't

In environments studied for the 2026 State of Agent Security Report, roughly 1,280 third-party products now embed AI. About 282 of them sit behind single sign-on. The other thousand are invisible to identity infrastructure by default, not because anyone hid th

Cybercrime · The Hacker News · yesterday

Anthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection Flaws

Anthropic on Friday said it's cutting off live internet access for all its internal evaluations following the discovery of new incidents in which its artificial intelligence (AI) models exhibited misaligned behavior and targeted real websites. The AI company s

Cybercrime · KrebsOnSecurity · 2 days ago

FBI Arrests Executive at Ransomware Negotiation Firm

Agents with the Federal Bureau of Investigation (FBI) on Thursday arrested the co-founder of a Canadian cybersecurity firm in connection with an investigation into the ShinyHunters hacking group that recently relieved the FBI of sensitive data on thousands of

Cybercrime · Dark Reading · 2 days ago

ASOS Breach Reveals the Risks in Customer-Facing SaaS

The attack on the British retailer shows that compromising a single identity can lead to much deeper penetration of the corporate network.

Cybercrime · Dark Reading · 2 days ago

AI Scramble Drives Cybersecurity M&A Boom

Welcome to another gangbuster year for strategic M&A activity in cyber, with 117 deals announced in the latest quarter. What's different: Many of the buyers are not your typical cybersecurity firms.

Cybercrime · The Hacker News · 2 days ago

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories. "Using the account of Takashi Kitao, author

Cybercrime · The Record · 2 days ago

Japan confirms arrest of Russian Qilin operative, extradition to Germany

Japan’s National Police Agency confirmed the arrest and extradition to Germany of a Russian national accused of being involved in the Qilin ransomware gang.

Cybercrime · The Hacker News · 2 days ago

FBI Arrests Another ShinyHunters Suspect Reportedly Involved in Its Jobs Portal Hack

The FBI has arrested another suspected co-conspirator of ShinyHunters, FBI Director Kash Patel said on October 9 in a post on X. ShinyHunters is the extortion group that said in September it had breached the FBI's jobs portal and stolen sensitive data on almos

Cybercrime · Dark Reading · 2 days ago

What We Missed: FBI Strikes Back at ShinyHunters

In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the arrest of a suspected ShinyHunters operative to the compromise of a Pentagon-run data center.

Cybercrime · Dark Reading · 2 days ago

Security Threats Don't Stop at the Office: Why Executives' Families Need Training, Too

Those closest to executives must match their security postures because the weakest link in a family can become the entry point for attacks.

Cybercrime · The Record · 2 days ago

Hundreds of thousands impacted by data breach at biosensor firm iRhythm

A company known for wearable cardiac sensors, iRhythm, has begun notifying states of the impact of a data breach from the summer.

Cybercrime · The Record · 2 days ago

Leader of vast money mule operation that laundered cybercriminal proceeds pleads guilty

Oleg Korniev, a 42-year-old dual citizen of Ukraine and Russia, was a principal of Your Mule Cashout, or “YMCO,” which from 2007 until 2014 set up a sophisticated network of mules in the U.S. and Europe.

Cybercrime · The Record · 2 days ago

FBI touts another ShinyHunters arrest in response to data breach

“We will continue to work closely with our partners to disrupt what’s left of the ShinyHunters group and their associates, no matter where they operate," FBI Director Kash Patel said.

Cybercrime · The Record · 2 days ago

Belarusian hacktivists admit to 2023 breach of Russian state healthcare network

The Belarusian Cyber Partisans concurred with Russian research that they indeed spent months inside the network for the Moscow Department of Health.

Cybercrime · Graham Cluley · 2 days ago

$10 million bounty offered for Chinese Hafnium hacker accused of Microsoft Exchange Server mega-attack

The US State Department is offering up to US $10 million for information about the whereabouts of Zhang Yu, a 44-year-old Chinese national who is accused of being a key figure in China's state-sponsored hacking group, Hafnium. Read more in my article on the Ho

Cybercrime · The Hacker News · 2 days ago

TP-Link Sued by Four More U.S. States Over Router Security and China Ties

Four more U.S. states sued router maker TP-Link Systems on October 6, bringing the total to five, with Texas filing a suit in February. Florida, Iowa, Montana and Nebraska allege the California company misled buyers about how secure its routers are and how sep

Cybercrime · Dark Reading · 2 days ago

Social Engineering AI Agents: The New BEC for 2026

As AI agents gain authority over business systems, attackers can manipulate them like business email compromise (BEC) victims.

Cybercrime · The Hacker News · 2 days ago

Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access

Security researchers have published a full working exploit for a pre-authentication remote code execution flaw in AnyDesk Linux that gives attackers root access before anyone approves the connection. AnyDesk patched the flaw in version 8.0.3 in June, but its c

Cybercrime · The Hacker News · 2 days ago

Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects

Anthropic on Thursday unveiled OSS Scanner as an opt-in vulnerability scanner to help secure the open-source ecosystem using artificial intelligence (AI). "It's an opt-in service informed by our experience using Claude to find vulnerabilities during Project Gl

Cybercrime · The Hacker News · 2 days ago

Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge

Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners. Details of the flaws are below - CVE-2026-105133 (CVSS v4 score:

Cybercrime · The Hacker News · 2 days ago

Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their abuse by a China-linked threat actor known as Flax Typhoon. The vulnerabilities in ques

Cybercrime · The Hacker News · 2 days ago

The AI Velocity Paradox: Why Security Is Decades Behind AI Ambition

As enterprises race to deploy autonomous AI agents to accelerate business, a new report reveals they are tethered to security architectures built for a different era. The "Horizons of Identity Security" report from SailPoint highlights a critical “velocity par

Cybercrime · The Hacker News · 2 days ago

GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys

A bug in GoBalance, a tool many dark-web sites use to stay reachable during attacks, lets anyone work out the secret key that controls a site's .onion address using only public information, and then take that address over. Searchlight Cyber, which disclosed th

Cybercrime · Dark Reading · 3 days ago

'AgentCorruption' Puts AWS Environments at Risk With Single Prompt

A now-patched vulnerability in AWS Bedrock AgentCore could have allowed an attacker to use one AI chatbot to take over an organization's entire fleet.

Cybercrime · Dark Reading · 3 days ago

Venezuelan Cartel's Malware Honcho Nabbed for ATM Jackpotting

The first cybercriminal to ever make the FBI's "10 Most Wanted Fugitives" list allegedly infused Tren de Aragua's violent criminal operations with cash.

Cybercrime · Dark Reading · 3 days ago

Russian Spies Give 'MatchBoil' Malware a Stealthy Facelift

Cyber-espionage actor UAC-0099 has been steadily refining its flagship dropper in campaigns targeting Ukrainian organizations.

Cybercrime · Dark Reading · 3 days ago

Writing the Next Chapter

Dark Reading is about to begin a new decade in its storied history, and we have some breaking news of our own to share.

Cybercrime · Graham Cluley · 4 days ago

Smashing Security podcast #487: Clippy’s crypto comeback

Microsoft's Twitter account, with its 13 million followers, was hijacked by a paperclip. There was no ransomware or data theft, just Clippy, a dodgy crypto coin, and a corporate apology that wasn't from Microsoft either. Meanwhile, UK losses from hacked email

Cybercrime · Dark Reading · 4 days ago

Australian Gov't Weighs Mandatory AI Incident Reporting

In the wake of an agentic attack against its own Medicare systems, Australia's government is feeling out what regulations might look like for frontier AI companies.