The Jewelbug webmail espionage campaign, in which a single malicious script injected into a shared government mail platform compromised accounts across 15 separate tenants, was run in parallel with what researchers describe as an industrial-scale cryptocurrency fraud operation, with both activities managed from the same control panel. Jewelbug, also tracked as Earth Alux and REF7707, has been active since at least the second quarter of 2023, according to TechTimes, making this a sustained operation rather than an opportunistic burst.Researchers at Symantec uncovered the campaign while tracing infections of the group’s Antino backdoor back to Jewelbug’s infrastructure. That access gave them…
Author: Gary Behan
Trezor’s Trezor ShipMonk data breach, disclosed this week, has exposed the personal details of nearly 14,000 customers after attackers exploited a critical zero-day vulnerability in a third-party analytics platform used by its shipping provider. The breach did not touch Trezor’s own systems or devices, but the leaked information is precisely what a phishing campaign needs.On 10 August 2026, Trezor published a blog post confirming that ShipMonk, its shipping and logistics provider, had informed the company of unauthorised access to systems containing customer order data. The affected records include full names, shipping addresses, email addresses, and phone numbers. Customers who received…
WhatsApp’s new Scam Alert feature is now in limited beta, using an on-device machine learning model to warn users when incoming messages look like scam attempts. The privacy angle is the headline within the headline: none of the message content leaves the device, and the whole thing is optional.The rollout is currently restricted to researchers in WhatsApp’s Bug Bounty community as the company tests the warning system. WhatsApp described the feature as ‘an on-device machine learning model to alert a user about potential scam messages,’ and was explicit that ‘no message content leaves the device for classification or is auto-reported…
The City-Forum data theft campaign is actively harvesting records from misconfigured Salesforce Experience Cloud and ServiceNow customer portals, and, according to Reco, the volume is climbing. The attacks do not exploit any vulnerability in either platform. Instead, they go after data that organisations have inadvertently left open to unauthenticated guest users through overly permissive sharing rules, portal configurations, or poorly scoped object permissions.Reco has traced the entire campaign to a single IP address: 158.220.87.79, hosted by German VPS provider Contabo. The attacker’s infrastructure has remained on that same address since at least March 2025, a period Reco describes as more…
The FBI, working with Google and Black Lotus Labs, has completed the Outsider Enterprise phishing takedown, dismantling a Chinese phishing-as-a-service operation that Google linked to more than 9,000 fake websites and over a million fraudulent URLs. According to authorities, the campaigns powered by the network led to the theft of more than 3.8 million credit card records and an estimated $1.9 billion in losses.The operation used AI and distributed phishing kits to impersonate trusted brands in SMS messages sent through AT&T, T-Mobile, and Verizon. According to CyberScoop, Outsider had been providing phishing kits and hosting infrastructure for cybercriminals since July…
A former IT worker has been sentenced to 21 months in prison over the Saydel School District cyberattack, a campaign of sustained disruption that stretched across nearly two years, deleted accounts, knocked out device management for a week, and left the Iowa district facing a remediation bill of nearly $60,000. Ezekiel Dean Potter, 34, had worked as a senior IT support specialist for the Saydel Community School District in Des Moines from May 2022 through April 2023. Prosecutors say he retained access credentials after leaving and began targeting his former employer’s systems almost immediately. Court documents describe what followed as…
Velvet Ant Operation Highland, a China-nexus cyberespionage campaign uncovered by Sygnia, saw the threat actor maintain persistent access to a large organisation’s isolated critical infrastructure network from 2016, going undetected for ten years by embedding itself directly into the authentication process.The campaign is attributed to the Velvet Ant activity cluster, which Sygnia identifies as a China-nexus threat actor. It is not a group that favours speed: previous Velvet Ant operations documented in 2024 included a campaign targeting F5 BIG-IP devices that ran undetected for three years. Operation Highland surpassed that considerably.How Velvet Ant Operation Highland Bridged the Air GapThe intrusion…
The Fable 5 export control ban issued by the US government has forced Anthropic to suspend its two most capable AI models, Fable 5 and Mythos 5, for all users worldwide, including customers in the UK and every other country that had been accessing them. The directive arrived at Anthropic at 5:21pm ET on 12 June, citing “national security” authorities. It bars access to both models by any foreign national, whether inside or outside the United States, and explicitly includes Anthropic’s own foreign-national employees. The company’s conclusion was swift and unambiguous: with a workforce and customer base that spans the…
Maine has taken its public breach notification database offline after Maine breach portal fake disclosures impersonating BleepingComputer-flagged companies VRChat and Discord were automatically published to the state’s website. The Maine Attorney General’s Office confirmed the filings were hoaxes submitted by an unknown entity with no connection to either company, and the database will remain inaccessible to the public while officials review how to prevent the same abuse in future.What the fake filings actually claimedThe fraudulent VRChat notification alleged that the company had suffered a breach affecting over 2.4 million people. According to Bitdefender, the filing listed compromised data as including…
The dark web supply-chain warnings that precede major software breaches rarely announce themselves clearly, according to research published by Flare. Underground forum posts advertising GitHub access, leaked vendor repositories, OAuth tokens, or CI/CD credentials may not use the phrase ‘supply-chain attack’ at all, yet they can represent precisely that risk months before any incident report surfaces. Flare’s researchers reviewed underground posts and found a consistent pattern: access that looks routine on first glance turns out to touch the trust relationships that make supply-chain attacks so damaging. A developer account sale, a leaked private repository, a listing for SaaS credentials, each…
