Slovak intelligence dismantled an EU-funded NERO R-ONE camera and found a rebadged Russian CORDON PRO.M with two modems and a hidden SMS-triggered backdoor tied to twelve Russian phone numbers.
A single actor behind the CameraSwarm campaign compromised at least 14,530 Dahua IP cameras across Ukrainian, Russian and CIS networks in 35 days, leaning heavily on the 2021 authentication bypasses CVE-2021-33044 and CVE-2021-33045. The operation only came to light because the attacker left his own toolkit exposed online.
The FortiBleed leak exposed admin credentials for tens of thousands of internet-facing FortiGates across 194 countries. Within days of CISA's emergency advisory, an initial access broker was selling bulk US device accesses on Darkforums with forum escrow.
A seller claims a full extraction of a Korean food-delivery platform's unauthenticated Firebase backend: 47.9 million records including door codes, resident registration numbers, plaintext passwords, and live payment keys. The listing is unverified, but the pattern behind it is the most reliable supply line feeding dark-web data markets.
Connor Riley Moucka pleaded guilty to breaching 165 Snowflake customer accounts and selling the haul on hacking forums - and his own sales threads are now evidence in a case that could put him away for 32 years.
The FBI and IRS Criminal Investigation seized hundreds of NetNut domains on July 2, 2026, exposing a residential proxy network built on two million compromised smart TVs. For Tor users, it is another reminder that anonymization infrastructure keeps collapsing under law-enforcement pressure.
Intelligence firms and US agencies have moved past asking whether criminals use AI. Flashpoint's monthly reporting, a joint NSA and FBI advisory, and two documented intrusion cases show exactly where large language models now sit inside illicit workflows.
A ransomware affiliate posing as a recovery service contacted victims mid-attack, offering decryptors and data deletion for a fee. How the double-dip scam works, the red flags, and what legitimate incident response actually looks like.
Truffle Security re-verified four years of publicly leaked AWS access keys and found 88 percent of them still authenticate, including 768 that grant full control of corporate accounts. Here is what that means for self-hosters running onion infrastructure.
Compromised maintainer accounts pushed malicious crate versions whose build scripts ran malware at compile time, while trojanized npm packages delivered an AI-assisted Linux backdoor. Here is how these attacks work and why lockfiles matter.
The Android banking trojan ToxicPanda has been updated with 167 remote commands, overlay phishing for 349 financial apps, and a VPN-service trick that cuts victims off from Google Play while it works.
Researchers showed that a man-in-the-middle relay can rewrite the expiry date a POS terminal reads from an expired Visa card, reviving dead plastic for real purchases. We explain the mechanics, why the carding scene noticed, and where the attack stops.