Join the group
GLOBAL NEWS · SECOND-HANDUpdated 27 min ago81 stories · 10 sourcesOSINT · Cybercrime · Scams · Cold cases · Investigations

Headlines from trusted publishers worldwide, collected automatically. We have not verified these stories ourselves: every headline links to its original source. Our own reporting is on the front page.

Investigations · Europol · 3h ago

European and Ecuadorian cooperation leads to 20 arrests in major hit against drug trafficking

The operation, codenamed Operation CANTABRIA, underscores the success of strong cooperation between European and Ecuadorian law enforcement agencies, proving that joint efforts are key to tackling transnational criminal networks.Magnus BrunnerEU Commissioner f

Investigations · Europol · 3h ago

Almost 50 arrested as police target Western Balkan network linked to killings

Nearly 50 suspects have been arrested in an international operation targeting a drug trafficking network with Western Balkan members, linked to killings, kidnappings and grenade attacks across Europe.

Investigations · Europol · 3h ago

Europol urges early action to protect cryptocurrencies and sensitive data from quantum threats

The timing of these capabilities remains uncertain. However, this should not be the main concern. Adapting systems and coordinating security upgrades will take time. Therefore, regardless of the nature of the threats that may emerge, crypto-agility should be p

Investigations · Europol · 3h ago

Ordering violence from abroad: five suspects arrested in Spain, Morocco, and France

Five suspects linked to the organisation and recruitment of serious violence have been arrested in Spain, Morocco, and France, in the latest results of the Operational Taskforce (OTF) GRIMM, coordinated by Europol. The arrests in August and September target th

Investigations · Europol · 3h ago

Teenager suspected of leading KillSec ransomware group as law enforcement seizes servers and leak site

On 30 September 2026, law enforcement took control of KillSec’s leak site, securing at least 110 terabytes of data against further unauthorised access. The cybercrime group used the site to threaten organisations with the publication of stolen files unless the

Investigations · Europol · 3h ago

Cannabis smuggling from North America and Thailand into Europe: Europol highlights growing threat

Cannabis smuggling from North America and Thailand in Europe has seen a sharp rise, driven by oversupply in legal markets and the adaptability of organised crime groups. A dedicated Europol Operational Taskforce (OTF) has been established to dismantle the crim

Investigations · Europol · 3h ago

EU law enforcement chiefs gather to discuss new challenges in EU security

The Convention was opened by Jürgen Ebner, Europol’s Acting Executive Director, and Justin Kelly, Commissioner of the Irish An Garda Síochána.Jürgen EbnerEuropol Acting Executive DirectorOrganised crime itself has become digital by default. Technology is not j

Investigations · Europol · 3h ago

Spain, Denmark and the Netherlands win Europol 2026 Excellence Awards in Innovation

At the European Police Chiefs Convention on 29 September 2026, Europol announced the winners of its 2026 Excellence Awards in Innovation. Law enforcement teams from Spain, Denmark and the Netherlands took home awards for projects that put innovation to work.

Investigations · Europol · 3h ago

Protecting citizens, preserving rights

How can law enforcement make effective use of data and technology while ensuring that fundamental rights and the rule of law remain protected? This question was at the heart of the 17th Europol Data Protection Experts Network (EDEN) conference, held in Lisbon,

Scams & fraud · Europol · 3h ago

Six arrests for smuggling migrants via Schengen airports

Europol supported a migrant smuggling investigation involving law enforcement authorities from 17 countries. The criminal network was also engaged in document fraud and money laundering. The action day on 22 September 2026 in Austria, Italy, Spain, and the Uni

Investigations · ICIJ · 3h ago

Donate to ICIJ

Support our journalism.

Cybercrime · The Hacker News · 11h ago

P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands

Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword. "Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet

Cybercrime · The Hacker News · yesterday

The Third-Party Agent Problem: Why Security Built for AI You Chose Misses the Agents You Didn't

In environments studied for the 2026 State of Agent Security Report, roughly 1,280 third-party products now embed AI. About 282 of them sit behind single sign-on. The other thousand are invisible to identity infrastructure by default, not because anyone hid th

Cybercrime · The Hacker News · yesterday

Anthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection Flaws

Anthropic on Friday said it's cutting off live internet access for all its internal evaluations following the discovery of new incidents in which its artificial intelligence (AI) models exhibited misaligned behavior and targeted real websites. The AI company s

Cybercrime · KrebsOnSecurity · 2 days ago

FBI Arrests Executive at Ransomware Negotiation Firm

Agents with the Federal Bureau of Investigation (FBI) on Thursday arrested the co-founder of a Canadian cybersecurity firm in connection with an investigation into the ShinyHunters hacking group that recently relieved the FBI of sensitive data on thousands of

Cybercrime · Dark Reading · 2 days ago

ASOS Breach Reveals the Risks in Customer-Facing SaaS

The attack on the British retailer shows that compromising a single identity can lead to much deeper penetration of the corporate network.

Cybercrime · Dark Reading · 2 days ago

AI Scramble Drives Cybersecurity M&A Boom

Welcome to another gangbuster year for strategic M&A activity in cyber, with 117 deals announced in the latest quarter. What's different: Many of the buyers are not your typical cybersecurity firms.

Cybercrime · The Hacker News · 2 days ago

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories. "Using the account of Takashi Kitao, author

Cybercrime · The Record · 2 days ago

Japan confirms arrest of Russian Qilin operative, extradition to Germany

Japan’s National Police Agency confirmed the arrest and extradition to Germany of a Russian national accused of being involved in the Qilin ransomware gang.

Cybercrime · The Hacker News · 2 days ago

FBI Arrests Another ShinyHunters Suspect Reportedly Involved in Its Jobs Portal Hack

The FBI has arrested another suspected co-conspirator of ShinyHunters, FBI Director Kash Patel said on October 9 in a post on X. ShinyHunters is the extortion group that said in September it had breached the FBI's jobs portal and stolen sensitive data on almos

Cybercrime · Dark Reading · 2 days ago

What We Missed: FBI Strikes Back at ShinyHunters

In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the arrest of a suspected ShinyHunters operative to the compromise of a Pentagon-run data center.

Cybercrime · Dark Reading · 2 days ago

Security Threats Don't Stop at the Office: Why Executives' Families Need Training, Too

Those closest to executives must match their security postures because the weakest link in a family can become the entry point for attacks.

Cybercrime · The Record · 2 days ago

Hundreds of thousands impacted by data breach at biosensor firm iRhythm

A company known for wearable cardiac sensors, iRhythm, has begun notifying states of the impact of a data breach from the summer.

Cybercrime · The Record · 2 days ago

Leader of vast money mule operation that laundered cybercriminal proceeds pleads guilty

Oleg Korniev, a 42-year-old dual citizen of Ukraine and Russia, was a principal of Your Mule Cashout, or “YMCO,” which from 2007 until 2014 set up a sophisticated network of mules in the U.S. and Europe.

Cybercrime · The Record · 2 days ago

FBI touts another ShinyHunters arrest in response to data breach

“We will continue to work closely with our partners to disrupt what’s left of the ShinyHunters group and their associates, no matter where they operate," FBI Director Kash Patel said.

Cybercrime · The Record · 2 days ago

Belarusian hacktivists admit to 2023 breach of Russian state healthcare network

The Belarusian Cyber Partisans concurred with Russian research that they indeed spent months inside the network for the Moscow Department of Health.

Cybercrime · Graham Cluley · 2 days ago

$10 million bounty offered for Chinese Hafnium hacker accused of Microsoft Exchange Server mega-attack

The US State Department is offering up to US $10 million for information about the whereabouts of Zhang Yu, a 44-year-old Chinese national who is accused of being a key figure in China's state-sponsored hacking group, Hafnium. Read more in my article on the Ho

Investigations · ICIJ · 2 days ago

Tunisian court dismisses case to dissolve publisher of ICIJ partner Inkyfada

Despite the court victory, Inkyfada and its parent company Al Khatt still struggle to recover funds frozen by authorities.

Cybercrime · The Hacker News · 2 days ago

TP-Link Sued by Four More U.S. States Over Router Security and China Ties

Four more U.S. states sued router maker TP-Link Systems on October 6, bringing the total to five, with Texas filing a suit in February. Florida, Iowa, Montana and Nebraska allege the California company misled buyers about how secure its routers are and how sep

Cybercrime · Dark Reading · 2 days ago

Social Engineering AI Agents: The New BEC for 2026

As AI agents gain authority over business systems, attackers can manipulate them like business email compromise (BEC) victims.

Cybercrime · The Hacker News · 2 days ago

Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access

Security researchers have published a full working exploit for a pre-authentication remote code execution flaw in AnyDesk Linux that gives attackers root access before anyone approves the connection. AnyDesk patched the flaw in version 8.0.3 in June, but its c

Cybercrime · The Hacker News · 2 days ago

Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects

Anthropic on Thursday unveiled OSS Scanner as an opt-in vulnerability scanner to help secure the open-source ecosystem using artificial intelligence (AI). "It's an opt-in service informed by our experience using Claude to find vulnerabilities during Project Gl

Cybercrime · The Hacker News · 2 days ago

Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge

Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners. Details of the flaws are below - CVE-2026-105133 (CVSS v4 score:

Cybercrime · The Hacker News · 2 days ago

Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their abuse by a China-linked threat actor known as Flax Typhoon. The vulnerabilities in ques

Cybercrime · The Hacker News · 2 days ago

The AI Velocity Paradox: Why Security Is Decades Behind AI Ambition

As enterprises race to deploy autonomous AI agents to accelerate business, a new report reveals they are tethered to security architectures built for a different era. The "Horizons of Identity Security" report from SailPoint highlights a critical “velocity par

Scams & fraud · Malwarebytes · 2 days ago

ASOS breach update: Hackers stole customer details and shopping searches

Stolen ASOS data includes shopping searches as well as personal details, so customers should watch out for convincing phishing messages.

Cybercrime · The Hacker News · 2 days ago

GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys

A bug in GoBalance, a tool many dark-web sites use to stay reachable during attacks, lets anyone work out the secret key that controls a site's .onion address using only public information, and then take that address over. Searchlight Cyber, which disclosed th

Cybercrime · Dark Reading · 3 days ago

'AgentCorruption' Puts AWS Environments at Risk With Single Prompt

A now-patched vulnerability in AWS Bedrock AgentCore could have allowed an attacker to use one AI chatbot to take over an organization's entire fleet.

Cybercrime · Dark Reading · 3 days ago

Venezuelan Cartel's Malware Honcho Nabbed for ATM Jackpotting

The first cybercriminal to ever make the FBI's "10 Most Wanted Fugitives" list allegedly infused Tren de Aragua's violent criminal operations with cash.

Cybercrime · Dark Reading · 3 days ago

Russian Spies Give 'MatchBoil' Malware a Stealthy Facelift

Cyber-espionage actor UAC-0099 has been steadily refining its flagship dropper in campaigns targeting Ukrainian organizations.

Scams & fraud · Malwarebytes · 3 days ago

Attackers hijack country-code domains to impersonate Google and other services

Cybercriminals compromised three country-code namespaces to get certificates that could help them impersonate trusted sites.

Investigations · ICIJ · 3 days ago

Five years after the Pandora Papers, transparency laws lose their teeth

Reforms promised swiftly after ICIJ’s investigation have fallen short in New York and beyond.

Scams & fraud · Malwarebytes · 3 days ago

Amazon has an uncomfortably personal profile on you

Amazon thinks it knows your body, your family, and your life. You didn't sign up for it, and we couldn't find a way to opt-out.

Cybercrime · Dark Reading · 3 days ago

Writing the Next Chapter

Dark Reading is about to begin a new decade in its storied history, and we have some breaking news of our own to share.

Scams & fraud · Malwarebytes · 3 days ago

Meta’s Muse AI files away your friendships, arguments, and secrets

Meta’s Muse AI builds personal dossiers that would make the FBI jealous. Even people who never signed up can get caught in its files.

Cybercrime · Graham Cluley · 4 days ago

Smashing Security podcast #487: Clippy’s crypto comeback

Microsoft's Twitter account, with its 13 million followers, was hijacked by a paperclip. There was no ransomware or data theft, just Clippy, a dodgy crypto coin, and a corporate apology that wasn't from Microsoft either. Meanwhile, UK losses from hacked email

Cybercrime · Dark Reading · 4 days ago

Australian Gov't Weighs Mandatory AI Incident Reporting

In the wake of an agentic attack against its own Medicare systems, Australia's government is feeling out what regulations might look like for frontier AI companies.

Investigations · ICIJ · 4 days ago

How Hungary’s richest man funneled millions into Orbán’s propaganda machine

Since 2022, companies belonging to Lőrinc Mészáros, who amassed a fortune from government contracts, donated more than $13 million to an online mouthpiece of the Fidesz party, a new Direkt36 investigation reveals.

Cybercrime · KrebsOnSecurity · 4 days ago

ShinyHunters Extorted Boeing Spin-off Prior to Arrests

A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group ShinyHunters has been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang. KrebsOnSecurity has learned that the suspect

Scams & fraud · Malwarebytes · 4 days ago

Google issues Android security updates: who can get them and how

Google has new Android updates, but many users will not be able to get patched immediately.

Scams & fraud · Malwarebytes · 4 days ago

AI-powered phishkit arms criminals with account-hijacking tools in 10 minutes

BlueKit puts account-hijacking tools in more criminals’ hands, making it easier to target you with convincing fake login pages and scam messages.

Scams & fraud · Malwarebytes · 4 days ago

Update Chrome and ChromeOS to fix critical security issues

Google has released a new update for the Chrome browser and ChromeOS. There are a lot of security fixes in them so don't delay.

Scams & fraud · Malwarebytes · 4 days ago

Another ShinyHunters suspect arrested

The net is tightening around the Shiny Hunters cybercrime group following the reported arrest of a second member.

Scams & fraud · FTC Consumer Alerts · 4 days ago

Did someone share an explicit image of your child online? Take these steps

Did someone share an explicit image of your child online? Possessing or sharing explicit images of children can be a serious crime — and that includes AI-generated deepfakes. Report the perpetrator immediately to criminal law enforcement and take action to get

OSINT & methods · Bellingcat · 5 days ago

Groups Associated With India’s Far-Right Receive Millions Through US Donor-Advised Funds

Sign up here to receive Bellingcat’s biggest investigations by email as soon as they are published. US non-profits whose founding leaders or organisations have been associated with India’s controversial Rashtriya Swayamsevak Sangh (RSS) – or initiatives the Hi

Scams & fraud · Malwarebytes · 5 days ago

ASOS “hackers” send push notifications to customers

ASOS customers received a push notification regarding a breach of the company. Here's what we know so far.

Scams & fraud · Malwarebytes · 5 days ago

Facebook Marketplace scam uses your name and number

Facebook users are reporting receiving a message with a fake Facebook Marketplace listing that has their name as the seller.

Scams & fraud · Malwarebytes · 5 days ago

Domino’s customers targeted in credential stuffing attacks

Domino's is warning customers by email that their accounts have been compromised in a credential stuffing attack.

Scams & fraud · Malwarebytes · 6 days ago

Google pauses open source bug bounty program after rise in AI submissions

Google has frozen its OSS VRP product vulnerability submissions to stop the flood of AI generated vulnerability reports.

Scams & fraud · Malwarebytes · 6 days ago

Proposed anti-Flock bills could spell trouble for license plate readers

Two sets of US lawmakers introduced bills in late September and early October to tackle the growing concerns about automated license plate readers.

Investigations · ICIJ · 6 days ago

New documents show how a retail chain’s sales practices helped put guns on US streets

The public release of the records is part of a legal settlement with a Wisconsin-based company accused of negligence for selling guns that were later used in crimes.

Scams & fraud · Malwarebytes · 6 days ago

A week in security (September 28 – October 4)

A list of topics we covered in the week of September 28 to October 4 of 2026

Cybercrime · Graham Cluley · 8 days ago

N0n ransomware: what you need to know

N0n is a newly-emerged cyber extortion gang. The group was first spotted in the middle of September 2026, and within days it had published on its dark web leak site details of what it claimed to be around a dozen victims. Since then, the tally has continued to

Investigations · ICIJ · 9 days ago

WATCH: Inside the China Capital investigation — a live panel

A behind-the-scenes look at ICIJ's investigation into the world's biggest bank, with insights from ICIJ’s reporter and an expert on China's lending practices.

Scams & fraud · Malwarebytes · 10 days ago

Fake xStocks, Pendle, and other sites bait crypto users with rewards votes

More than 70 fake crypto sites promise extra rewards for casting a vote, then prompt visitors to connect their wallets.

Scams & fraud · FTC Consumer Alerts · 10 days ago

Talking with parents and kids about deepfakes, online safety, and the Take It Down Act

Kids face a lot of challenges online: from cyberbullying and scams to digitally altered deepfakes, like nudify apps that create fake nude photos and videos of real people. Even if you’ve had conversations with your child about online safety and sensitive topic

OSINT & methods · Bellingcat · 10 days ago

Viral Google Maps Images Shared Widely This Week Show Gaza Ruins. We Obtained More Recent Satellite Imagery

Earlier this week, several viral social media posts and news articles stated that Google had updated satellite imagery over Gaza. The imagery shared in these posts and articles shows several areas, including the southern city of Rafah. Huge destruction is deta

Cybercrime · Graham Cluley · 10 days ago

FBI tells ShinyHunters members to turn themselves in, after arrest of alleged leader

The FBI has a very simple message for the ShinyHunters gang: give yourselves up. On Tuesday, FBI cyber division assistant director Brett Leatherman released a video, thanking the Dutch police for arresting a 24-year-old man they believe to be a member of the g

Cybercrime · Graham Cluley · 10 days ago

ShinyHunters suspect arrested, and is now investigated over alleged murder plots

An alleged key figure in the ShinyHunters cybercrime group has been arrested in the Netherlands, and - in a sinister twist - the 24-year-old suspect is also being investigated for attempting to arrange two murders. Read more in my article on the Hot for Securi

Investigations · ICIJ · 10 days ago

Gunvor publicly condemned Russia’s war but continued to do business with Russian energy firms, records show

Even as the trading giant publicly claimed to be winding down its Russia business, Gunvor privately acknowledged the deals to its bank, the Industrial and Commercial Bank of China, saying they complied with sanctions laws.

Cybercrime · Graham Cluley · 11 days ago

Pentagon personnel database breach exposes personal data of millions

A Pentagon personnel database was breached for nine months without anyone noticing. Over three million people are affected. Read more in my article on the Hot for Security blog.

Scams & fraud · FTC Consumer Alerts · 12 days ago

What to know ahead of Open Enrollment to avoid health insurance scams

Health insurance scams happen year-round, but they pick up during Open Enrollment for Medicare and the Marketplace. If you’re looking to find a new plan, you might search online. But before you click on a search result, remember: scammers and dishonest busines

Cybercrime · KrebsOnSecurity · 13 days ago

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest, remaining ShinyHunters me

Cybercrime · KrebsOnSecurity · 16 days ago

U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearl

Cybercrime · Graham Cluley · 17 days ago

Ukrainian ransomware developer jailed for nearly 13 years

A court in Zurich has sentenced a Ukrainian man to 12 years and nine months in prison, and banned him from Switzerland for ten years, for developing ransomware that blackmailed companies around the world. Read more in my article on the Hot for Security blog.

Cybercrime · Graham Cluley · 18 days ago

Smashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras

A store in Auckland vibe-coded itself a new website. Within hours, its inventory had somehow expanded to include a pair of crusty socks, an $850 banana, and all of New Zealand's national parks. What could possibly have gone wrong? Meanwhile, a hacker collectiv

Investigations · ICIJ · 18 days ago

China Capital stories reveal how ICBC advanced China’s political goals across four continents

ICIJ’s media partners uncovered strategic deals and moves the Chinese bank made around the world to further the political priorities of the party-state.

Scams & fraud · FTC Consumer Alerts · 18 days ago

How to report a platform that doesn't take down your intimate images

You reported an intimate photo or video shared without your consent. But 48 hours later, the platform hasn’t taken it down or responded to your request. Now what? Report the platform to the FTC at TakeItDown.ftc.gov to help keep platforms accountable for compl

Investigations · ICIJ · 19 days ago

ICIJ journalist Micah Reddy freed after 4 days in secretive Djibouti custody

Reddy and local guide Mohamed Willo Ismael (“Kooki Mahmoud”) went missing Sept. 19 in Djibouti City.

Investigations · ICIJ · 20 days ago

Trump administration gave firm with ties to ballroom donor the green light to do business with a sanctioned Russian bank

Private equity investor Konstantin Sokolov was also appointed to run a government enterprise fund.

Investigations · ICIJ · 21 days ago

Statement on missing ICIJ journalist Micah Reddy

ICIJ lost contact with our colleague Micah Reddy, ICIJ's Africa coordinator, and local journalist Mohamed Willo Ismael ("Kooki Mahmoud"), in Djibouti City on Saturday, Sept. 19.