Visualização de leitura

Liquid Network Hackers Demand Bug Fix Before Returning $320M BTC

Liquid Network security incident

The Liquid Network security incident has taken an unusual turn after the unidentified actors behind the theft of nearly 4,000 BTC offered to return “most” of the funds — but only after the vulnerability that enabled the exploit is fixed across the network.  The purported white-hat hackers communicated their condition through an ongoing exchange with Blockstream, according to Galaxy Research head Alex Thorn. The incident involved roughly $320 million worth of BTC and has raised questions over whether the attackers are genuine security researchers or simply exploiting the language and behavior associated with white-hat hacking.  The episode began on Sunday, when approximately 4,000 BTC was withdrawn from the Liquid Federation wallet. The amount represented about 95% of the Bitcoin that had been pegged into the Liquid sidechain.  Following the withdrawals, Liquid disabled its bridge nodes and paused the network. The stolen funds were subsequently consolidated into a Bitcoin address containing a message that read: “we are whitehats. contact us on chain.”  Liquid, however, has continued to describe the individuals involved as purported white-hat hackers, reflecting the uncertainty surrounding their identity and intentions. 

Liquid Network Security Incident Sparks On-Chain Conversation 

The unusual communication between the attackers and Blockstream has taken place through Bitcoin OP_RETURN messages and PGP-encrypted text.  Thorn reconstructed the exchange and reported that Blockstream attempted to contact the actors at Bitcoin block 965,822. The company sent 1,000 satoshis along with an OP_RETURN message intended to alert its security team and establish a communication channel.  A later transaction included encrypted material addressed to the holder of the relevant key, along with a PGP signature. According to Thorn, the signature could be verified against Blockstream’s published public key, providing an indication that the communication was connected to the company.  The purported white-hat hackers subsequently responded at block 965,869. They moved their own balance and sent 1,000 satoshis to the federation’s peg wallet. Alongside the transaction, they asked whether returning “most” of the withdrawn BTC to the federation address would be acceptable.  That proposal came with a significant condition: the vulnerability responsible for the Liquid Network security incident would have to be fixed first.  “Please fix the bug first,” the hackers told Blockstream. 

White-Hat Hackers Leave Questions Over Returned BTC 

The use of the word “most” has introduced another layer of uncertainty. The message does not specify how much BTC the actors would ultimately return, leaving open the possibility that they could retain a portion of the nearly 4,000 BTC taken from the federation wallet.  There is also no guarantee that the promised return will actually occur. Until the funds move back to the federation-controlled address, almost all of the Bitcoin remains under the control of the unidentified actors.  The incident initially prompted skepticism from Ledger Chief Technology Officer Charles Guillemet, who argued that conventional white-hat hackers generally do not drain hundreds of millions of dollars from a bridge.  Guillemet compared the situation with major cryptocurrency exploits such as Ronin and Euler, where attackers were responsible for substantial losses. His initial assessment suggested that the scale and method of the Liquid incident were inconsistent with the typical behavior expected from legitimate security researchers.  His position later softened after the hackers attempted to communicate with Blockstream. 

BTC Remains Under Hackers’ Control 

Guillemet noted that criminal groups do not typically make efforts to establish direct communication with their victims after carrying out an exploit. The willingness of the actors to communicate therefore created some hope that the funds could eventually be recovered.  “There’s hope,” Guillemet wrote.  He also argued that the vulnerability could potentially be researched using powerful AI systems to identify the underlying flaw without relying on proper disclosure procedures.  For now, however, the outcome of the Liquid Network security incident remains unresolved. The hackers have indicated that they are prepared to return “most” of the BTC, but only once the underlying bug has been fixed across the network.  The development leaves Blockstream and Liquid facing two immediate challenges: addressing the vulnerability that allowed the exploit and determining whether the unidentified actors will honor their commitment.  Until those steps are completed, the nearly 4,000 BTC involved in the incident remains largely outside the federation’s control. The on-chain messages provide a rare window into negotiations between an exploited crypto network and the people claiming responsibility, but they do not yet establish whether the purported white-hat hackers will ultimately return the funds. 

Mathspace Breach Impacts More Than 1 Million Users in Australia, NZ

Mathspace data breach

The Mathspace data breach has affected 1,079,819 people in Australia and New Zealand after unauthorized parties accessed an internal reporting system and downloaded user information. Mathspace confirmed the security incident on September 3, 2026, and said the affected records involve students, parents or guardians, teachers, and Mathspace staff.  The company said names, email addresses, and account details were exposed, but customer passwords, single sign-on (SSO) tokens, and other authentication credentials were not. There is currently no evidence that the information has been published, sold, distributed, or otherwise misused. The attacker’s identity remains unknown. 

How the Mathspace Data Breach Happened? 

The security incident resulted from a vulnerability in Mathspace’s self-hosted Metabase installation, which was used for internal reporting. The flaw allowed attackers to obtain administrator access without a legitimate login.  Metabase issued a critical security advisory and patched versions on August 6. Mathspace said its vulnerability-notification process failed to identify and escalate that advisory. The company later updated its Metabase instance on August 29 after seeing a subsequent notice.  An investigation found unauthorized access dating to August 10, Australian Eastern Standard Time. Information was downloaded from Mathspace’s Australian reporting database on August 27. Historical log reviews confirmed the unauthorized access on September 3, before the update had been applied. Mathspace also acknowledged that it did not complete additional compromise checks recommended for potentially affected systems at the time of the update. 

What Information was Exposed? 

The exported data included user IDs, usernames, first and last names, email addresses, country, time zone, user type, email-verification status, last-active date, last-login date and joining date. Not every field appeared for every affected person.  Mathspace said the exposure went beyond names and email addresses. User IDs are internal identifiers, including those linked to student accounts. However, no academic records, learning activities, results, assessments, password hashes, authentication tokens, SSO credentials or API credentials were exposed.  The data did not contain records directly linking accounts to schools, although Mathspace said school affiliations could potentially be inferred where identifiable email domains were used. Former or inactive users may also be affected because retained information could remain in the reporting database. 

What Users Should Know After the Security Incident? 

Names, email addresses, and account details could make phishing or impersonation attempts more convincing. Users have been advised to independently verify unexpected messages, avoid unfamiliar links and attachments, and never provide passwords or verification codes in response to unsolicited communications.  Mathspace is not requiring password resets because customer authentication credentials were not exposed. However, anyone who reused a Mathspace password elsewhere should change those reused passwords to unique ones and monitor accounts for unusual activity. 

Response to the Mathspace Data Breach 

After confirming the breach on September 3, Mathspace took Metabase offline, revoked its API keys, disabled Metabase database-access accounts in its Australian and US Snowflake environments, and changed passwords for its Metabase Cloud SQL databases. The company also copied the application database and exported access logs for investigation. Metabase remains offline while recovery and compromise checks continue.  Mathspace began notifying school contacts on September 4 and started notifying affected individuals on September 6, earlier than the date previously communicated to schools.  On September 4, the security incident was reported to Australia’s Office of the Australian Information Commissioner, the Australian Signals Directorate’s Australian Cyber Security Centre, New Zealand’s Office of the Privacy Commissioner and National Cyber Security Centre, as well as Australian state and territory education departments. 

US Puts $10 Million Bounty on Alleged Iranian Cyber Chief

$10 Million Reward for Amir Yaryab

The U.S. State Department has posted a $10 million reward for Amir Yaryab, a senior Iranian official accused of leading the Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC) Cyber Operations Command and directing multiple hacking groups targeting critical infrastructure across the United States, Europe and the Middle East. According to the Rewards for Justice program, Yaryab allegedly oversees cyber operations conducted by IRGC-CEC-affiliated groups including CyberAv3ngers, Dadeh Afzar Arman (DAA) and Mehrsam Andisheh Saz Nik (MASN). U.S. officials accuse these groups of using malware and conducting cyber and cyber-enabled information operations against civilian infrastructure worldwide.

$10 Million Reward for Amir Yaryab

The $10 million reward for Amir Yaryab seeks information leading to his identification or location. The offer applies to individuals acting at the direction or under the control of a foreign government who participate in malicious cyber activities against U.S. critical infrastructure in violation of the Computer Fraud and Abuse Act. [caption id="attachment_113961" align="aligncenter" width="600"]$10 million reward for Amir Yaryab Image Source: https://rewardsforjustice.net/[/caption] Yaryab is also accused of directing Shahid Hemmat and Shahid Shushtari, two groups linked to cyberattacks against U.S. organizations. The sectors allegedly targeted include defense, news, shipping, travel, energy, financial services and telecommunications. The six Iranian officials named in the advisory are linked to Iran's Islamic Revolutionary Guard Corps and its Cyber-Electronic Command.

Iranian Cyberattacks Target PLCs

The allegations also involve attacks against programmable logic controllers (PLCs), highlighting concerns around Iranian cyberattacks targeting industrial systems rather than focusing only on data theft. U.S. officials said Iranian-linked hackers compromised industrial control systems, specifically targeting the Vision series of PLCs manufactured by Israel-based Unitronics. These devices are used across water and wastewater, energy, food and beverage, manufacturing and healthcare sectors. The attackers exploited default credentials on the devices and left anti-Israel messages. Some of the compromises reportedly rendered the PLCs inoperative. The CyberAv3ngers group, which is linked to the IRGC-CEC, claimed responsibility for attacks against Unitronics Vision PLCs in October 2023. Beginning in November 2023, the group compromised default credentials in PLCs across the United States and left messages on the devices' digital screens.

CyberAv3ngers Attacks Critical Infrastructure

CyberAv3ngers has also claimed responsibility for attacks affecting other infrastructure. In October 2023, the group claimed it had breached ORPAK Systems, a provider of gas station solutions in Israel. The group said it had obtained the company's database and intended to publish it through its Telegram channel. The attack was reported to have disconnected 200 gasoline pumps from the system in the occupied Palestinian territories. In December 2023, CyberAv3ngers also claimed to possess and sell 1TB of data allegedly linked to Israel's electricity infrastructure. The group advertised the dataset for 5 Bitcoin, with an initial 100GB portion also offered at the same price.

U.S. Agencies Warn of PLC Cyberattacks

Concerns over critical infrastructure attacks involving PLCs continued into 2026. A joint advisory issued on April 7 by the FBI, CISA, NSA and other agencies warned that Iran-linked threat actors were actively exploiting internet-facing PLCs. The advisory said several organizations had experienced operational disruptions and financial losses after attackers interfered with industrial processes. The developments come amid broader U.S. actions against Iranian-linked cyber activity. The Justice Department accused Iran-connected hackers of breaching employee email accounts associated with the Department of Labor, the Federal Energy Regulatory Commission and multiple United Nations organizations. The Treasury Department also sanctioned Iranian nationals over cyberattacks targeting critical infrastructure. The State Department's reward offer places Amir Yaryab and the alleged activities of IRGC-CEC-linked groups at the center of the U.S. effort to identify individuals responsible for malicious cyber activity targeting critical infrastructure.

The Cyber Express Weekly Roundup: Claude Session Hijacking, PaperCut Exploits, and Enterprise Cyberattacks

Weekly Roundup September 2026

This weekly roundup highlights a range of cybersecurity developments affecting artificial intelligence platforms, enterprise software, healthcare organizations, social media accounts, and internet-facing infrastructure.  From stolen Claude sessions and bypassed PaperCut security fixes to an attempted attack targeting hundreds of thousands of X users, recent incidents demonstrate how attackers continue to exploit both software vulnerabilities and active user sessions.  The latest developments also show that organizations face growing risks across AI services, on-premises systems, enterprise edge devices, and account recovery infrastructure. Security teams are being urged to respond quickly as attackers increasingly target exposed systems and authentication mechanisms. 

The Cyber Express Weekly Roundup 

Anthropic Warns of Claude Session Hijacking 

Anthropic has warned that common infostealer malware is being used to steal active Claude sessions, potentially allowing attackers to bypass passwords and two-factor authentication. The campaign involves malware such as Vidar, LummaC2, RedLine, and Atomic Stealer, which is often distributed through pirated software and illicit downloads. Attackers may also consume victims’ paid AI usage. Read more… 

PaperCut Releases Second Emergency Patch After First Fix Is Bypassed 

PaperCut has released a second emergency patch for two actively exploited vulnerabilities affecting its NG and MF print management servers. Researchers discovered ways to bypass the initial security fix, potentially allowing attackers to chain the flaws and achieve pre-authentication remote code execution on exposed systems. Read more… 

Boston Scientific Cyberattack Limited to Certain On-Premises Systems 

Boston Scientific says its ongoing cybersecurity incident is limited to certain on-premises systems, with no impact identified on its cloud-based applications. The company has also reported no confirmed data breach or evidence of unauthorized activity since August 25, as its investigation into the incident continues. Read more… 

DOJ Investigates Attempted Cyberattack on Hundreds of Thousands of X Users 

The U.S. Department of Justice is investigating a large-scale cyberattack targeting hundreds of thousands of X accounts through the platform’s password-recovery system. Attorney General Todd Blanche said X detected and disrupted the campaign before the targeted accounts could be captured, preventing the attempted account takeover operation from succeeding. Read more… 

Two Citrix NetScaler Flaws Put Enterprise Edge Devices at Risk 

Two vulnerabilities in Citrix NetScaler ADC and Gateway have prompted an urgent patching warning from Australia’s cybersecurity agency. CVE-2026-19489, a memory overflow flaw, and CVE-2026-19490, an authentication bypass, can affect systems with specific configurations involving SIP ALG, SAML, or VPN gateway functionality. Read more… 

Weekly Cybersecurity Takeaway 

This week’s developments demonstrate that cybersecurity threats are increasingly targeting authentication systems, active user sessions, exposed enterprise infrastructure, and critical business applications. AI platforms, print management servers, healthcare environments, social media accounts, and network edge devices all remain potential targets for attackers.  Organizations should prioritize rapid security patching, protection of active sessions, strong authentication controls, careful monitoring of exposed infrastructure, and timely investigation of suspicious activity. Security teams should also review systems that rely on password-recovery mechanisms and identify enterprise devices operating with vulnerable configurations.  As businesses continue to rely on cloud services, AI platforms, remote access technologies, and internet-facing enterprise systems, attackers are finding new opportunities to exploit trusted sessions and security weaknesses. Organizations must maintain continuous monitoring and rapid response capabilities to reduce the impact of increasingly targeted cyberattacks. 

Kentucky Appellate Court Data Caught in Multi-State Cyber Data Breach

Kentucky Appellate Court Data

The Kentucky Administrative Office of the Courts (AOC) has confirmed that Kentucky Appellate Court data was compromised in a cybersecurity breach traced to a third-party vendor. West Publishing Corporation, operating as Thomson Reuters Court Management Solutions (Thomson Reuters CMS), informed the AOC that the incident originated within file systems tied to its C-Track case management platform.  C-Track is the system relied upon by the Kentucky Supreme Court and the Kentucky Court of Appeals to manage case records. Because Kentucky does not currently use third-party vendors for trial court e-filing, trial-level records that were never part of an appeal remain unaffected. The exposure is limited to Kentucky Appellate Court data that had been stored within Thomson Reuters CMS/C-Track infrastructure.  According to Thomson Reuters CMS, an unauthorized third party gained access to and obtained court data from C-Track systems across several states, not Kentucky alone. The AOC noted that Kentucky's Appellate Courts continued to function normally throughout the incident and were not operationally disrupted. 

The Kentucky Appellate Court Data Breach Incident  

The AOC said it currently has no indication that the unauthorized party shared or distributed Kentucky's data with any outside individual or entity. Thomson Reuters CMS has stated it is coordinating with third-party cybersecurity specialists and law enforcement, and has assured every affected jurisdiction, including Kentucky, that mitigation measures have been implemented to reduce the risk of future unauthorized access.  Any individuals ultimately confirmed to be affected by the data breach will be contacted directly by Thomson Reuters CMS. Those notified will receive additional details about the incident along with 12 months of complimentary credit monitoring and identity theft protection, funded by the company. 

Scope of Impact Still Under Review 

Thomson Reuters CMS is currently working through each affected court system individually, reviewing what data was exposed and determining which people or organizations warrant notification. The company has indicated this review will take time given the multi-state scope of the breach.  The AOC, however, has pressed for a faster timeline, telling Thomson Reuters CMS that it expects prompt resolution and swift notification to anyone impacted. As of now, the total number of individuals or organizations affected — if any — has not been determined. Thomson Reuters CMS has committed to covering all costs associated with the breach and will handle notification once affected parties are identified. 

AOC Response and Oversight 

The AOC emphasized that safeguarding information entrusted to Kentucky's Judicial Branch remains a core responsibility. As the investigation proceeds, the office says it is closely tracking developments, evaluating any potential consequences for the Judicial Branch, and following its established cybersecurity protocols to protect the appellate case management system tied to the Kentucky Supreme Court and Court of Appeals.  The AOC is also taking part in ongoing status briefings with the National Center for State Courts and is coordinating with officials in other states affected by the same Thomson Reuters CMS/C-Track breach, as the response to this data breach continues to unfold on a multi-jurisdictional scale. 

Two Citrix NetScaler Flaws Put Enterprise Edge Devices at Risk

Citrix NetScaler vulnerabilities

Two Citrix NetScaler vulnerabilities affecting Citrix NetScaler Application Delivery Controller (ADC) and Citrix NetScaler Gateway products have prompted a patching warning for Australian organisations. The Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) has advised organisations using the products to assess their environments and apply available security updates as a priority. Citrix has identified two vulnerabilities affecting NetScaler ADC and NetScaler Gateway, which are critical edge devices used in enterprise networking to securely deliver applications, data and remote access to users.

Citrix NetScaler Vulnerabilities Affect ADC and Gateway

The first flaw, CVE-2026-19489, is a memory overflow vulnerability. According to the alert, exploitation of this vulnerability requires SIP ALG, or Session Initiation Protocol Application Layer Gateway, to be enabled on a Large Scale NAT (LSN) group configuration. The second flaw, CVE-2026-19490, is an authentication bypass vulnerability. The vulnerability requires SAML actions to be enabled and/or the affected product to be configured as a VPN gateway. The conditions required for each vulnerability mean that organisations need to assess their specific Citrix configurations to determine whether affected systems are present in their environments.

Patches Released for Citrix NetScaler products

Citrix released patches for the affected products on August 19, 2026. ASD's ACSC is urging organisations to review the vendor's mitigation guidance, identify vulnerable versions of Citrix products and update affected systems to the latest versions. The advisory places particular emphasis on timely patching because critical edge devices are frequently targeted by threat actors as an entry point into sensitive environments. However, ASD's ACSC said it has no information indicating that a specific Australian industry or sector is currently being targeted in connection with these vulnerabilities.

Organisations Urged to Assess Vulnerable Versions

The mitigation guidance calls on organisations to assess their networks and environments for vulnerable versions of Citrix products and apply patches as soon as practicable. Organisations should also review the mitigation advice provided by Citrix and confirm that affected systems have been updated. Where NetScaler ADC and NetScaler Gateway products are managed by a third party, organisations are advised to contact the relevant managed service provider (MSP) or enterprise IT provider. They should confirm that the products have been patched and are being monitored for suspicious activity. This step is particularly relevant for organisations that do not directly manage their Citrix infrastructure and may rely on external providers for patching and monitoring.

Monitoring Remains Important After Patching

Alongside addressing the Citrix NetScaler vulnerabilities, organisations are advised to monitor affected environments for suspicious activity. The alert recommends notifying ASD's ACSC if suspicious activity is detected. The two vulnerabilities affect different configurations, with CVE-2026-19489 requiring SIP ALG to be enabled on an LSN group configuration, while CVE-2026-19490 requires SAML actions to be enabled and/or the product to be configured as a VPN gateway. For Australian organisations using Citrix NetScaler products, the immediate steps outlined by ASD's ACSC are to identify vulnerable versions, apply the available patches, confirm third-party-managed systems have been addressed and maintain monitoring for suspicious activity.

CVE-2026-84115 in Cleo Harmony: JWT Refresh Token Handler Flaw Exposes Remote Attack Risk

CVE-2026-84115

A critical vulnerability identified as CVE-2026-84115 affects Cleo Harmony versions through 5.8.1.10, with the weakness tied to the platform’s JWT Refresh Token Handler and the /api/connections endpoint.   MITRE documented the issue on September 1, 2026, while VulDB classified it as a serious privilege-management vulnerability with a CVSS score of 8.3. 

CVE-2026-84115 Targets JWT Refresh Token Handler 

According to the vulnerability analysis, CVE-2026-84115 involves an unknown function within the JWT Refresh Token Handler component. The affected functionality processes requests sent to /api/connections, where manipulation of the Bearer argument in HTTP authorization headers can lead to improper privilege management.  The weakness is classified as CWE-269, which refers to Improper Privilege Management. The flaw can allow an attacker to manipulate authentication-token arguments and potentially bypass intended access controls, gaining privileges beyond those assigned to the account. 

Remote Exploitation Raises CVE-2026-84115 Risk 

The vulnerability is remotely exploitable because the attack can be conducted through network-based HTTP requests without requiring local or physical access to the targeted system. The risk is heightened because a public exploit has reportedly been made available.  An attacker exploiting CVE-2026-84115 could potentially obtain unauthorized administrative access, view sensitive information stored within Harmony, or interfere with integration workflows managed through the platform. Such activity could affect the confidentiality, integrity, and availability of systems that depend on Cleo Harmony for file transfer and API connectivity.  The VulDB analysis links the exploitation method to authentication bypass through token manipulation. Attackers could potentially intercept legitimate traffic or create forged requests using malformed or replayed bearer tokens to circumvent JWT refresh-token controls. In environments where Cleo Harmony is connected to other systems, successful exploitation could also provide opportunities for further lateral movement. 

CVE-2026-84115 Remediation Requires an Upgrade 

Organizations using affected Cleo Harmony versions should upgrade to version 5.8.1.11 or later. The release contains the necessary correction for the privilege-management problem affecting the JWT Refresh Token Handler.  Until patching is possible, organizations can strengthen input validation on API endpoints and monitor for unusual patterns involving bearer tokens. These measures may improve detection and reduce exposure, but they do not replace the recommended software upgrade, particularly given the reported public exploit.  VulDB is listed as the responsible organization, with the vulnerability recorded under VDB-397558. Disclosure took place on September 1, 2026, and the entry has an accepted moderation status, with CPE marked as ready. CWE-269 is confirmed for the vulnerability. VulDB assigns CVE-2026-84115 a CVSS score of 8.3 and an EPSS score of 0.00284. The vulnerability record also identifies an exploit as available for download.

CISA, FBI Urge Clearer Communication During Major Outages

outage communications

The CISA and FBI, along with cybersecurity agencies from Australia, Canada, New Zealand and the U.K., have released new guidance on outage communications for service providers dealing with major IT and OT outages. The guide calls for prompt, factual and audience-specific communication during disruptions caused by malicious cyber activity or non-malicious events.

Titled “Communicating Under Pressure: Best Practices for Service Providers,” the guidance says effective communication is critical to limiting operational impact when IT and OT outages affect customers, network defenders, critical infrastructure owners and operators, and the public. It recommends that organizations clearly communicate what is known, what remains unknown and what is still under investigation, while providing frequent updates as circumstances change.

Outage Communications Should Start With Facts

The agencies recommend that service providers establish an outage communications plan before an incident occurs. The plan should define incident thresholds, escalation paths, target audiences and procedures for status pages, customer and partner notices, and regulatory communications. Organizations are also advised to establish cross-functional incident teams involving engineering and operations, communications, legal, risk and compliance, and customer support.

The guidance calls for clearly defined roles, including an incident lead, communications lead and spokesperson. It also recommends parallel workstreams so technical teams can focus on diagnosing and remediating the root cause while communications teams manage external messaging and leadership handles strategy and regulatory requirements.

For organizations responding to cyber incidents, the guidance places particular emphasis on balancing transparency with operational security. If malicious activity is suspected or confirmed, external communications should not compromise investigations, containment efforts or other response activities. Organizations are also advised against making premature conclusions when the root cause remains under investigation.

Service Providers Urged to Tailor Messages

The guidance recommends segmenting communications for technical teams, executives and the public. Audiences can include enterprise IT teams and security operations centers, employees and customers, government partners and regulators, critical infrastructure owners and operators, as well as the media and general public.

During an outage, organizations should lead with a concise summary covering affected systems, user impact, scope and the known cause without speculation. The agencies also advise against vague descriptions such as “service degradation” and recommend messaging that can be understood quickly during high-pressure situations.

Transparency is another central principle. Service providers are advised to state what they know and do not know, use a single source of truth such as a status page, and focus communications on actionable guidance rather than reputation management. Customers should be told what actions they need to take or clearly informed when no action is required.

The guidance also calls for continuous, time-stamped updates that show the incident timeline, actions taken, and recovery milestones. Organizations should maintain a single status page and align external messaging with legal, contractual and sector-specific reporting obligations.

Agencies ultimately frame effective outage communications around five principles: immediate acknowledgement, technical and actionable information, transparency, accountability, and continuous updates. For service providers, the guidance positions communication as an important part of incident response, alongside technical remediation and recovery.

DOJ Investigates Cyberattack Targeting Hundreds of Thousands of X Users

cyberattack on X users

A cyberattack on X users that targeted hundreds of thousands of accounts has prompted an investigation by the US Department of Justice (DOJ), with Attorney General Todd Blanche saying sophisticated cybercriminals attempted to exploit the platform's password-recovery system. The DOJ is working with Elon Musk's X, formerly known as Twitter, to identify those responsible for the attempted attack, according to Blanche's statement on Wednesday. The incident involved hundreds of thousands of X users and was disrupted before the targeted accounts could be captured, Blanche said.

Blanche Says DOJ Is Tracking Those Behind Cyberattack on X Users 

In a statement posted on X, Blanche described the incident as a password-recovery attack carried out by "sophisticated cyber criminals." He said X managed to disrupt the effort and prevent user accounts from being taken over.  Blanche wrote: 
This week, sophisticated cyber criminals attempted a password-recovery attack on hundreds of thousands of X users. X disrupted the attack to prevent user accounts from being captured. But, as we’ve shown, the Justice Department will stop at nothing in its pursuit of cyber fraudsters and scammers. We are working closely with @X to track down the criminals behind this week’s attack. There is no refuge for those that perpetrate their criminal schemes from behind computer screens." 
The attorney general did not disclose additional technical details about the cyberattack on X users, including how the attackers attempted to exploit the recovery system, whether any individual accounts were compromised, or where the suspected criminals were operating from.  The DOJ investigation is intended to identify those responsible for the attempted intrusion, with Blanche emphasizing that authorities would pursue individuals involved in cyber fraud and scams even when those activities are conducted remotely. 

How the Password-Recovery Attack Works 

A password-recovery attack generally targets the systems users rely on when they have forgotten their login credentials. These processes can include "forgot password" features, account-recovery forms, and other mechanisms designed to help legitimate users regain access to their accounts. Attackers may attempt to exploit weaknesses in those processes to obtain access to accounts. In the incident involving X, the platform was able to disrupt the effort before the targeted accounts were captured, according to Blanche. The scale of the attempted cyberattack on X users—hundreds of thousands of accounts—makes the incident notable, although the attorney general did not provide a breakdown of how many accounts were actually affected or whether any users suffered losses. 

AI-Driven Cyberattacks Add to Growing Security Concerns 

The X incident comes against a wider backdrop of increasing cybersecurity threats facing companies and organizations around the world.  Businesses have been dealing with a rise in AI-driven cyberattacks as well as ransomware campaigns capable of stealing sensitive information, interrupting operations, and creating significant financial and operational damage.  The growing use of artificial intelligence in cyber operations has raised concerns that attackers can automate or accelerate parts of their campaigns. At the same time, organizations are exploring ways to use AI-based systems to identify vulnerabilities and strengthen their defenses.  The DOJ has also been pursuing cases involving sophisticated cyber operations. Days before news of the cyberattack on X users, the department announced an operation targeting QTFY, described by US authorities as a Chinese cyberespionage platform. 

DOJ Previously Targeted QTFY Cyberespionage Platform 

According to the Justice Department, QTFY had targeted several US institutions and organizations. Those named by the department included the US Senate, the Federal Reserve, and NASA, among others.  The action against QTFY highlights the broader range of cyber threats confronting US institutions, from espionage operations to attacks aimed at obtaining access to online accounts.  The latest investigation involving X therefore comes amid a broader push by US authorities to identify and disrupt cyber criminals and state-linked cyber operations. 

Boston Scientific Cyberattack Limited to Unauthorized Access on Certain On-Premises Systems

Boston Scientific cyberattack

As per Boston Scientific’s Aug. 30 update, “the unauthorized activity is limited to certain on-premises systems,” providing the clearest indication yet of the scope of the cybersecurity incident that has disrupted the medical device maker’s global network and business operations. Boston Scientific said the investigation into the disruption remains ongoing, with third-party cybersecurity experts. Based on its investigation to date, the company said it has found no indication of unauthorized activity in its environment related to the incident since Aug. 25. The company also clarified that its cloud-based systems and applications have not been affected. The unauthorized activity identified so far is confined to only limited on-premises systems. The clarification comes as Boston Scientific continues working to restore systems supporting manufacturing, ordering and shipping. The company has not established a timeline for a full return to normal operations.

Boston Scientific Ordering and Shipping Recovery Underway 

Boston Scientific said its confidence in restoring ordering, shipping and related system access “continues to increase” and that it is working toward a partial restoration of shipping for some products during the week following its Aug. 30 update. The company said it expects ordering and shipping to ramp up to full capacity once it can demonstrate that the restored operations are fully functional. For now, customers can continue to submit orders electronically through Electronic Data Interchange (EDI) and local applications. Those orders can be placed into a queue for future fulfillment, including orders submitted through the Global Health Exchange (GHX). The latest update indicates that the company’s ability to receive orders electronically has remained intact even while systems required to fulfill and ship those orders have been disrupted. Boston Scientific has not provided a specific date for when full ordering and shipping capacity will return.

Investigation Has Not Confirmed a Data Breach 

Boston Scientific has not said that the cybersecurity incident resulted in a confirmed data breach. Its investigation remains focused on determining the nature, scope, and impact of the unauthorized activity. The Aug. 30 update also provides a more specific picture of the affected technology environment. While certain on-premises systems have been impacted, Boston Scientific said there has been no impact to its cloud-based systems and applications. The company previously said it had found no indication of unauthorized activity in its environment related to the incident since Aug. 25. It has not disclosed whether data was exfiltrated or whether ransomware was involved.

Impact on Medical Devices Remains Limited Based on Current Information

Boston Scientific previously said the incident had not affected devices that are not connected to a Boston Scientific network or clinicians’ ability to use those devices. For Cardiac Rhythm Management (CRM) products, the company reported no known impact on implantable device function, remote monitoring for devices that were already being remotely monitored before the disruption, or programmer interrogations. However, new remote-monitoring activations have been affected. For new CRM implants other than insertable cardiac monitors (ICMs), remote-monitoring communicators cannot currently be activated. As a result, available device data cannot reach remote patient-management systems until activation is possible. Newly implanted ICMs must be activated through the Boston Scientific Clinic Assistant app, but new ICMs cannot currently pair with patients’ remote-monitoring mobile phones. Recorded episodes can still be transmitted through an in-person interrogation using the app’s “Interrogate” function. Boston Scientific said that once its systems are restored and home-monitoring equipment is paired, recorded data will be transmitted to the remote-monitoring system. The company has also said there is no evidence that the affected network environment has increased cybersecurity risks for hospital networks through Boston Scientific devices.

Boston Scientific Continues Incident Response

Boston Scientific said it continues to work with CrowdStrike and other external cybersecurity specialists as the investigation and recovery effort proceeds. The company has been prioritizing systems with the greatest impact on customers and product delivery while working to recover its core business systems. Customers can continue communicating with sales representatives and other Boston Scientific employees through normal channels, including email, established digital platforms and existing connections. The company has acknowledged the potential challenges for customers, patients and suppliers as the disruption continues and thanked them for their patience and partnership. Boston Scientific disclosed the incident in an 8-K filing with the U.S. Securities and Exchange Commission on Aug. 26. The company said it will provide additional updates as appropriate. For now, the latest disclosure narrows the known technical scope of the incident: Boston Scientific says the unauthorized activity is limited to certain on-premises systems, while cloud-based systems and applications remain unaffected. At the same time, the continued disruption to manufacturing, order fulfillment, and shipping means the operational consequences of the attack remain significant as the investigation and recovery effort continue.

AshSqlite Vulnerability (CVE-2026-77846) Exposes Hidden JSON Fields

CVE-2026-77846

CVE-2026-77846, a newly disclosed AshSqlite vulnerability, can allow attackers to access hidden or sensitive fields stored inside JSON and map columns when applications pass untrusted input to AshSqlite's get_path/2 functionality.  The Erlang Ecosystem Foundation's CNA issued the vulnerability entry on August 30, 2026. The issue affects AshSqlite, the SQLite data layer used by the Ash Framework. Although it involves database queries, CVE-2026-77846 is not SQL injection.   Instead, the AshSqlite vulnerability results from unsafe construction of JSON paths and the way SQLite interprets special characters in those paths. 

How the CVE-2026-77846 AshSqlite Vulnerability Works 

In affected releases, AshSqlite generated JSON paths using $."-style path construction through the expression: 
path = "$." <> Enum.join(right, ".") 
The individual path segments were neither escaped nor quoted. Consequently, a key intended to represent the literal name private.secret could instead be interpreted as two JSON levels. Characters such as ., [, ], and $ could similarly alter JSONPath interpretation.  The GitHub advisory describes the flaw as “JSONPath injection in AshSqlite.SqlImplementation get_path”, stating that an attacker controlling a get_path/2 segment can traverse nested JSON and disclose private fields. The affected package is ash_sqlite, with versions 0.1.2-rc.0 through before 0.2.18 affected and 0.2.18 listed as the patched release.  The flaw remains separate from SQL injection because the generated JSON path is supplied to SQLite's json_extract as a bound expression parameter. The attacker manipulates the JSONPath grammar, rather than injecting SQL commands. 

What CVE-2026-77846 Can Expose? 

The AshSqlite vulnerability becomes relevant when an application permits untrusted input to reach get_path/2, such as through a public calculation, filter, or API that lets callers select JSON fields.  A normal endpoint might permit a caller to request a top-level title field. However, supplying private.secret can cause AshSqlite to generate $.private.secret, allowing traversal into a nested object that the API was never intended to expose. Malformed input, such as an unbalanced bracket or bare $, can also produce SQLite JSON path errors that reveal information about the underlying structure.  The published proof of concept used AshSqlite 0.2.17, Bandit, and Req. It created a JSON record containing {"title":"hello","private":{"secret":"s3cr3t-api-key-9f2c"}}. A benign key=title request returned hello, while key=private.secret returned s3cr3t-api-key-9f2c. Captured SQL showed json_extract(p0."data", ?) with the parameter $.private.secret, confirming the traversal. The PoC concluded that a single attacker-controlled path segment could leak a nested value through an endpoint designed to expose only top-level keys. 

Fixes and Administrator Actions for CVE-2026-77846 

The fix replaces the unsafe path joining with encoding that represents keys safely, escapes backslashes and quotes, and handles numeric array indexes separately. Administrators should upgrade to AshSqlite 0.2.18 or later and audit applications that accept network-controlled field-selection input.  Until upgrades are completed, applications should restrict dynamic get_path/2 calls to predefined names, reject dangerous path characters such as periods and brackets, and avoid exposing arbitrary JSON paths.  After upgrading, dependency locks and deployment images should be checked for older ash_sqlite versions. Logs should also be reviewed for unusual dots, brackets, or JSONPath symbols in field-selection requests. Such requests do not prove exploitation, but can help identify systems requiring investigation.  The practical risk of CVE-2026-77846 depends on application architecture. Internal applications without untrusted callers face lower exposure, while public search, filtering, and field-selection APIs require careful validation and access controls. 

The Cyber Express Weekly Roundup: Exploited Entra ID Flaw, AI Agent Risks, and Global Cybercrime Crackdown

The Cyber Express weekly roundup, podcast

This weekly roundup highlights a broad range of cybersecurity and technology developments affecting cloud identity infrastructure, social media platforms, businesses, digital assets, and international law enforcement.   From a critical Microsoft Entra ID vulnerability exploited before remediation to a global crackdown on West African cybercrime networks, recent developments demonstrate how attackers continue to target both technical systems and human trust.  The latest developments also show that cybersecurity risks are expanding alongside the rapid adoption of cloud services and artificial intelligence. Organizations are facing threats involving identity infrastructure, autonomous AI agents, software vulnerabilities, digital transactions, online fraud, and the misuse of emerging technologies. 

The Cyber Express Weekly Roundup 

Microsoft Confirms Exploited Entra ID Flaw 

Microsoft confirmed that a critical vulnerability in Entra ID, CVE-2026-69836, was exploited before the flaw was fixed server-side. The vulnerability carries a CVSS score of 10.0 and could allow unauthenticated attackers to achieve remote code execution, potentially affecting Microsoft’s cloud-based identity infrastructure. Read more... 

New Zealand Proposes Social Media Ban for Under-16s 

New Zealand has introduced legislation that would require high-risk social media platforms to prevent users under the age of 16 from accessing their services. Proposed age-verification methods could include digital identification, facial age estimation, or official identification documents. Read more... 

Cyble and DRONA Launch AI Cyber Defense Initiative in India 

Cyble and DRONA Cyber Solutions have launched an AI-powered cybersecurity initiative in Ahmedabad aimed at helping mid-sized businesses detect, investigate, and contain cyber threats. The initiative combines threat intelligence, AI-driven investigations, and endpoint enforcement to provide organizations with faster and more coordinated responses to security incidents. Read more... 

AI Agents Could Create New Cybersecurity Risks 

Adarsh Kant Sinha, CEO of ANVE.AI, warned that autonomous AI agents could introduce significant new cybersecurity risks as organizations increasingly allow them to interact with business-critical systems. AI agents may gain access to email, customer relationship management platforms, cloud infrastructure, and financial systems, potentially creating new avenues for misuse or compromise. Read more... 

Ledger Fixes Ethereum App Flaw Amid Disclosure Dispute 

Ledger said it fixed a clear-signing vulnerability in its Ethereum application approximately two weeks before security firm TestMachine publicly disclosed the issue. The vulnerability could potentially allow a malicious application to display one transaction to a user while preparing a different transaction for signing. Read more... 

Global Crackdown Nets 58 Arrests in West African Crime Networks 

An eight-month international law enforcement operation led by INTERPOL has resulted in 58 arrests and the identification of 263 suspects across 22 countries. Operation Jackal IV targeted West African criminal networks involved in cyber-enabled fraud, money laundering, romance scams, and investment scams. Read more... 

Weekly Cybersecurity Takeaway 

This week’s developments demonstrate that cybersecurity threats are crossing organizational, technological, and geographical boundaries, affecting cloud identity systems, artificial intelligence, digital platforms, cryptocurrency applications, and international financial crime.  Organizations should prioritize strong identity and access controls, rapid vulnerability remediation, careful management of AI-agent permissions, secure integrations, human oversight, and continuous threat monitoring.   As autonomous technologies become more deeply integrated into business operations and cybercriminal networks continue to operate across borders, security teams must adapt to a threat landscape that is becoming broader, more interconnected, and increasingly difficult to contain. 

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever.

In a statement released today, the Australian Federal Police (AFP) said two men from Western Australia, aged 21 and 23, were arrested in connection with a “sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.”

The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old suspect’s real identity in June, and has been communicating with him ever since. This story includes interviews with TeamPCP’s self-described spokesperson, and examines clues left behind by the TeamPCP leader that likely led to his undoing.

TeamPCP vaulted onto the cybercrime scene in late 2025, embedding malicious code in hundreds of open source software tools and extorting victims for profit. Members of the group made headlines by compromising corporate cloud environments using a self-propagating worm dubbed Shai-Hulud, which added malicious code to open source programs maintained by developers whose credentials at public code repositories like GitHub or NPM were phished or stolen.

Writing for Wired, journalist Andy Greenberg described TeamPCP’s core tactic as a kind of cyclical exploitation of software developers.

“The hackers gain access to a network where an open source tool commonly used by coders is being developed,” Greenberg wrote in May. “The hackers plant malware in the tool that ends up on other software developers’ machines, including some who are writing other tools intended to be used by coders. The malware allows TeamPCP’s hackers to steal credentials that let them publish malicious versions of those software development tools, too. The cycle repeats, and TeamPCP’s collection of breached networks grows.”

TeamPCP also has practiced something akin to cyclical recruitment. In May, the source code for the third iteration of Shai-Hulud was published online, and TeamPCP soon after launched a contest offering $1,000 in virtual currency to whichever participant could conduct the largest supply chain operation using the worm’s code. According to the contest rules, participants were scored based on the number of weekly and monthly downloads of packages they compromised — directly incentivizing them to target the most popular code libraries.

A screenshot of a message from TeamPCP’s Telegram account, announcing the supply chain hacking contest. Image: dataminr.com.

“TeamPCP has stated the competition is a recruiting opportunity and they intend to purchase all meaningful access harvested from participants’ campaigns,” the security firm Dataminr wrote. “The $1,000 XMR (Monero) prize is a recruitment floor and has been dismissed by the actor as ‘just like participation trophy,’ adding ‘if you find something good you will be paid way more,’ confirming the contest’s true function as talent identification and malicious access acquisition at scale.”

In March, TeamPCP executed a supply chain attack targeting AI infrastructure by compromising the code for LiteLLM, an open source AI gateway that connects users to more than 100 different large language models. A recent analysis by the security firm CloudSEK found TeamPCPs attack on LiteLLM harvested cloud service keys and other secrets from more than 2,500 organizations, including many of the world’s top technology companies.

In May, TeamPCP claimed credit for compromising at least 3,800 code repositories at the Microsoft-owned GitHub, after a GitHub developer installed a code extension that was compromised by TeamPCP’s malware.

MEET THE CYBERCATS

Security experts say TeamPCP is less of a hacker group than an amalgamation of threat actors from multiple cybercriminal gangs who sometimes work together toward similar goals.

“It is not a structured criminal crew with a single operator,” said Austin Larsen, a principal threat analyst with the Google Threat Intelligence Group. “It is a peer community of individually-skilled actors, with one clear center of gravity.”

That center of gravity is George Prepakis, an accomplished security researcher and self-described exploit developer who operates the Twitter/X profile @kernelstub. Earlier this year, @kernelstub tweeted a public invite link to a Matrix chat server he created and dubbed “Cybercats,” and TeamPCP and several other cybercrime entities have been using this server to communicate daily for the past several months.

A screenshot of the Matrix chat server “Cybercats,” whose members used hacker handles associated with multiple distinct cybercrime groups that have occasionally collaborated on a series of supply chain and data ransom attacks over the past nine months.

Kernelstub, like other administrators in the Cybercats chat, has been using his Twitter/X profile name as his handle in these Matrix communications, frequently tweeting references to other members and to conversations taking place in the Cybercats chat. In a number of cases, the corresponding X accounts for members of the Cybercats chat taunted cybercrime victims publicly before the incidents were reported in the news media.

The Cybercats administrator listed at the top of the screenshot above — “Boxturtle” — is a close associate of TeamPCP who has been tweeting about the group’s conquests under the name @xpl0itrsturtle. This handle corresponds to a data breach broker active on Breachforums and Darkforums who has been selling data stolen in a wave of recent breaches at automobile manufacturers, including BMW Group, Audi, Honda, Mercedes-Benz, Volvo and Toyota, as well as data allegedly taken from Snapchat and SportRadar.

The data leak site for the extortion group or handle “xpl0itrs.”

The Cybercats administrator “SeesawSec” in the screenshot above is the alias of whoever is behind the cybercrime group known as Fulcrumsec, which recently claimed credit for data extortion attacks against the pharmaceutical giant Novo Nordisk, the data broker LexisNexis, and Avnet, a Fortune 500 distributor of electronic components.

The data leak site of Fulcrum Security, a.k.a. Fulcrumsec.

The Cybercats administrator “@pcpcasper” also has been using a similar name on X to discuss TeamPCP’s attacks and victims. This person has an extensive message history on Telegram, where their messages and shared videos show @pcpcasper is an active and vocal member of the National Socialist Network, a neo-Nazi political organization based in Australia.

At one point in these chats, @pcpcasper shared videos and images of what they claimed was their cat, and several of those videos place this user in Western Australia. One source close to the investigation told KrebsOnSecurity that @pcpcasper was one of the two arrested, a claim supported by messages that @kernelstub posted online this morning.

The Cybercats member roster pictured above also features an administrator with the username “T,” which is short for the now-banned Twitter/X profile @pcpcats, the account operated by the self-described TeamPCP spokesperson who was arrested today. As we’ll see in a moment, @pcpcats also is from Western Australia.

By the time @kernelstub tweeted a public invite link to the Cybercats Matrix server, T/@pcpcats was posting only infrequently to the group chat, with other members often inquiring as to his whereabouts and well-being. The group’s collective concern related to @pcpcats’s tendency to blame his increasingly extended absences on the use of hallucinogens and other narcotics that kept him awake for days on end, but also caused him to crash in bed for several days after the highs wore off.

WHO IS THE TEAMPCP LEADER?

The Cybercats member @pcpcats has used multiple nicknames on the cybercrime forums, including EllisD25/LSD on Darkforums, BulkDMT on Breachstars, and Express on Breachforums. These accounts are linked because they all advertised the same Tox ID and/or Session ID as instant message contact handles in their cybercrime forum posts. BulkDMT was also known on the forums as DMT Host, which was a virtual private server (VPS) hosting service that was peddled on Darkforums and Breachstars.

DMT Host/EllisD25, posting on the English-language cybercrime community DarkForums in September 2025. Image: ke-la.com.

According to the cyber intelligence firm Intel 471, Express registered on Breachforums using the email address shitstickpp@gmail.com. Intel 471 finds Express posted on Breachforums across a two-month period in 2025 using four different Internet addresses located in South Africa. On July 30, 2025, Express announced on Breachforums they were selling access to 14 gigabytes of data stolen from South Africa’s State Information Technology Agency.

The threat intelligence platform Flashpoint recorded more than a year’s worth of messages from the TeamPCP leader’s alter ego on Telegram — Persy_PCP —  who claimed they split their life living between two countries [full disclosure: Flashpoint is an advertiser on this blog]. “I have these [files] as well, problem is these are in another country,” Persy_PCP explained to another user inquiring about a stolen data set in November 2025.

Later that month, Persy_PCP complained, “My whole country is racist and they want people like me dead.” Flashpoint records show BulkDMT shared in September 2025 that “this country is going to fucking starve when they take the farmers land,” a likely reference to white landowners in South Africa who claim to be targeted by an ongoing genocide campaign.

This tracks with public reporting on TeamPCP. Cyberscoop reported in June that Google had traced TeamPCP’s residential and mobile Internet address connections to South Africa, “indicating the primary operator was located there during at least some of its attacks.”

BulkDMT also shared on the group chat at Breachforums that they were recovering from an addiction to methamphetamine. “My life is kinda fucked rn [right now], but that’s fine and there isn’t really a point in pouring so much emotional energy into that fact, my parents had money but I unfortunately got really addicted to some things so I don’t get to benefit from that. As long as I continue to survive, stay sober, and move closer towards my goals that’s enough drive and meaning.”

The identity threat protection company SpyCloud finds shitstickpp@gmail.com shows up in the registration of an account called ChristmasSnow on the cybercrime community Raidforums in 2022. Nearly all of the Internet addresses used to access that account came from ISPs in Perth, Australia, SpyCloud found.

KrebsOnSecurity looked up all of those Perth IP addresses in passive DNS records maintained by DomainTools.com, and found one of them — 211.27.196.111 — for several years was used as a private file server by a family in Perth with the last name of Thomson. Those records show at least three hosts — ithomson.direct.quickconnect.to (a remote Synology server), kthomson0061.direct.quickconnect.to, and joshuawthomson39.myqnapcloud.com (a QNAP network storage device) — persisted at that address between 2022 and 2025.

Searching on “joshuathomson39” in the breach tracking service Constella Intelligence reveals an account at the freight forwarding company kwe.com created in the name of Joshua Thomson from Perth, Australia. The open source intelligence platform Epieos finds the phone number attached to that kwe.com account was used to register a Facebook profile for Josh Thomson, which says his family includes a brother named Ruben, his father Ian, and his mom Cindy.

That Facebook profile also says Josh and his family are originally from Pietermaritzburg, in KwaZulu-Natal, South Africa, but currently living in Cottesloe, a beach-side suburb of Perth. A search in DomainTools for Ian Thomson and Australia unearthed five domains by the same registrant, including securecomputing.au, thomson.org.au, and thomsonfamily.net.au. Ian Thomson is a dentist in Cottesloe, and a biography says he graduated from The University of the Witwatersrand in Johannesburg, South Africa.

Constella finds a joshua@thomson.org.au registered a number of accounts online, but Josh doesn’t seem to have much of a connection to dodgy cybercrime forums. His brother Ruben, on the other hand, has quite the presence on these communities, dating back to at least 2018. Constella reports ruben@thomson.org.au frequently reused the password “joshuathomson1,” and Constella further finds that password was used by just a handful of accounts, including yolosolo17@gmail.com and surfinup8@gmail.com.

According to Intel 471, surfinup8@gmail.com was used to register the user Yolosolo17 on the crime forum Altenen in 2018, and that user account was registered from the Perth address 110.141.230.15. On Altenen, Yolosolo17 advertised free web proxies, as well as the domain rubenthomson.com, which was at one point used to sell steeply discounted iPhones. DomainTools says rubenthomson.com was hosted at 110.141.230.15 and registered to surfinup8@gmail.com.

A cached copy of the domain rubenthomson.com from 2017 shows a login page underneath a banded stack of money. Image: archive.org.

SpyCloud reports 10.141.230.15 was used by the email address sheepstealing@gmail.com on Raidforums and surfinup8@gmail.com on Nulled, and that the same IP was used by the email addresses ian@thomsonfamily.net.au, jasper@yakuza.cc, and rubenthomson1@gmail.com. SpyCloud also shows that sheepstealing Gmail address is tied to the accounts Sheep420, YoloSolo117 and Yakuza.cc on Raidforums, and to the account “Sheep Stealing” on Hackforums. Intel 471 says sheepstealing@gmail.com was used to register the account DingoFlour on Breachforums in October 2023, as well Sheepx on Altenen.

Epieos reports that ruben@securecomputing.au is tied to an Airbnb account for Ruben, who described himself as a Web developer who went to school at the University of Western Australia and was living outside the country. “Hey, I’m Ruben, my friends call me Ellis. I’m a Perth creative who occasionally books rooms when visiting family and for photography.”

Epieos also finds sheepstealing@gmail.com registered an upwork.com profile under the name Ruben, who said his main skills are setting up secure server hosting solutions and PHP full-stack Web development.

“I’m familiar with Linux, working with relational databases (SQL),” the Upwork profile reads. “I also script in Python mainly for writing social media bots.”

The Upwork profile for Ruben Thomson in Cottesloe, Australia.

Epieos further discovered sheepstealing@gmail.com is connected to a Microsoft account for Ruben Thomson, and to a now-defunct GitHub account called XmasSnow/XmasSnowisBack that scammed people on the forums in 2022 by claiming to sell exclusive exploits for recently-released software patches (recall that shitstickpp@gmail.com was used to register a forum account named ChristmasSnow).

This same sheepstealing email address registered a Twitter/X account in 2026 called “Gone Fishing” that lists its location as South Africa. That Gmail account also left several reviews for businesses listed on Google Maps over the past seven years, but all of those establishments are located on the west coast of Australia.

Business reviews in Western Australia left by the Google account sheepstealing at gmail.com.

The people search service Pipl finds a 21-year-old Ruben Thomson in Western Australia who has a phone number ending in 979. A lookup on that number at Epieos reveals it is connected to a TikTok account under the name Ellis, and to a PayPal account in the name of Ruben Thomson.

Finally, a search on the name Ruben Thomson from Cottesloe at the Australian government’s record of registered businesses finds he has incorporated or served as an official in multiple companies created since 2024, including Secure Computing Solutions, Tensor Industries, and another entity ironically named OPSEC Express. Recall that Express was BulkDMT’s nickname on Breachforums.

Australian companies connected to Ruben Thomson. Image: abr.business.gov.au.

It’s ironic because OPSEC is short for the term “operational security,” which refers to techniques and behaviors used to obfuscate and compartmentalize one’s real-life identity online, and using your cybercrime handle as part of your own company name is very much the antithesis of that practice.

There is at least one other major opsec failure by Ruben that exposed a link to TeamPCP. In June 2025, someone using the name Ruben Thomson registered on HackerOne, a popular “bug bounty” program that seeks to reward and recognize researchers who agree to work with affected software vendors to help fix the flaws before publishing about their findings. What was Ruben Thomson’s chosen HackerOne username? Deadcatx3, a nickname that has been flagged by multiple security firms as an alias used by TeamPCP.

The HackerOne profile for “Ruben Thomson” uses the nickname Deadcatx3, which multiple security firms have concluded is an alias used by TeamPCP. Image credit: flare.io.

INTERVIEW WITH ELLIS

In early July 2026, not long after having discovered clues about Ellis’s real life identity, KrebsOnSecurity interviewed the TeamPCP leader via Signal, where he was remarkably open about his activities and personal struggles [for the sake of simplicity, the TeamPCP spokesperson will be referred to from here on as Ellis].

Ellis claims he stopped doing cybercrime for TeamPCP in March 2026 — just before the attacks that compromised LiteLLM — and that at least one other individual has taken over the group’s leadership since then. Ellis shared that a year earlier he had just completed the latest in a series of detox and sobriety programs, and was two months sober when he reconnected with some old friends from the malware development scene.

“One year ago I needed help monetizing some [GitHub credentials], I was two months sober and needed a distraction and something to keep busy as well as people to speak to,” Ellis said. “I had largely disconnected from my old circle, they had become very toxic and I needed to get away from the substances. Previously I had done some mass exploitation campaigns and grew up doing [malware development] and [capture the flag] contests. There were some friends who were also vending but had stopped a while, and one of them introduced me to some chats where I posted access for sale.”

Prior to that, Ellis said, he was homeless and hopping between “some very unstable places.”

“Blackhatting is fun,” he said. “There are actual rewards and incentives to learn and you grow with your team. Without qualifications, no employer will even take the time to hear you out.”

Ellis claims he’s earned a grand total of about $20,000 for his activities with TeamPCP, and that it was never about the money or fame for him. Asked whether his experiences with TeamPCP might prepare him for gainful employment in a legitimate IT job, Ellis said he doubted it.

“I am nowhere close to a skill level where I am comfortable, and this would take maybe half a decade of further experience,” he said. “I no longer have to choose between rent and food for that I’m grateful and so are the team members.”

Ellis expressed no remorse over his cybercrime activities, and said he was grateful for the friendships and relationships built throughout his engagement with TeamPCP. The young hacker also seemed resigned to his fate, and told KrebsOnSecurity that he’ll accept the consequences if he’s ever arrested.

“If I’ve already been found out then its out of my control, I’ll make peace with that,” he said. “Honestly, I think someone like me needs a lot of help that prison just can’t provide. If I had the funds to study different parts of the field and closer guidance, this would have turned out differently. But that’s a pipe dream and we both know this.”

It is clear from reading Ellis’s posts to the group’s Matrix server chats that his struggles with sobriety are ongoing. On Thursday, June 25, Ellis told @kernelstub he was about to “trip” with his “homie.”

“What kind,” @kernelstub inquired.

“Ketty and some DMT,” Ellis replied, referring to the dissociative anesthetic ketamine and dimethyltryptamine (DMT), a powerful psychedelic compound that is found naturally in some plants but is also synthetically produced in underground lab environments. “There’s a little 2cb so we might throw that in the mix,” he continued, referring to another psychedelic compound by its chemical shorthand.

Roughly two weeks before his arrest, Ellis told KrebsOnSecurity he was ready to leave his life of crime behind and was prepared to turn himself in, but that in the meantime he was making plans to tie up loose ends.

Less than 24 hours later, the TeamPCP leader posted an image on Telegram showing a yellowish powdered substance in a baggie and on a scale, possibly synthetic DMT. The image shows the powder being weighed next to a series of small vape cartridges, two of which are open on the table in front of the photographer.

An image posted by the TeamPCP leader to Telegram, advertising his acquisition of some type of psychoactive substance, most likely a synthetic version of the powerful hallucinogen known as DMT.

The two defendants were arrested Wednesday morning. The AFP said the men face a combined 14 cybercrime offenses and are scheduled to appear in Perth Magistrates Court today.

Charlie Eriksen is a security researcher at Aikido Security who has closely followed TeamPCP’s cybercrime campaigns. Eriksen said TeamPCP are a good example of a new kind of threat actor that does not fit neatly into the usual categories.

“They are not a state actor, not quite organized cybercrime, and not purely ideological,” he said. “Their motivations seem to mix money, disruption, attention, and ideology.”

Eriksen said that historically there has always been a meaningful gap between reading about an attack technique and being able to reliably turn it into an operational campaign, but that large language models (LLMs) and artificial intelligence increasingly are helping threat actors to bypass that knowledge gap.

“You had to understand the research, adapt the code, troubleshoot it, build infrastructure around it, and then repeat that process across different targets,” he said. “LLMs have compressed that gap significantly.”

According to Eriksen, this creates an environment where threat actors suddenly have the ability to operate at significant scale without having developed the operational discipline that traditionally accompanies that level of capability. Put another way, it sets the stage for cybercriminals who are capable enough to cause significant damage, but not necessarily careful enough to understand or care about the consequences.

“They can be noisy, they can make mistakes,” he said. “They can leave evidence everywhere. They can take risks that a professional criminal group or intelligence service would consider completely unacceptable. But that does not necessarily make them less dangerous. In some ways, it can make them more dangerous.”

In a recent blog post, Eriksen called TeamPCP’s Shai-Hulud worm the “best thing to happen to supply chain security,” because it forced GitHub and other public coding platforms to erect new security safeguards.

In direct response to TeamPCP’s broad success at pushing poisoned versions of popular software packages, GitHub in late July introduced a three-day “cooldown” mechanism for Dependabot, the platform’s tool for auto-fetching newly shipped updates for any package dependencies. Cooldown periods are designed to help buy time for security tools and package maintainers to identify and remove any compromised versions. Other coding ecosystems like Python and various JavaScript platforms also added support for cooldown periods this year amid growing calls from security experts about the need for more widespread adoption of the safety feature.

Eriksen said TeamPCP’s legacy is that they achieved in the span of a few months what the supply chain security community has been unable to do for years.

“They managed to wake up Microsoft to the fact that they had become negligent in terms of security,” Eriksen said. “By compromising GitHub and stealing their source code, they humiliated Microsoft into action, making them finally act on what we had been asking them to do and take seriously for a while now.”

Update, 10:08 a.m. ET: A story this morning from ABC News in Australia confirms Ruben Ian Thomson of Cottesloe was one of the two arrested. The 23-year-old suspect thought to be @pcpcasper, Michael Gaebler, also was arrested in Perth. ABC News reports that Thomson was denied bail (Mr. Gaebler’s attorney reportedly did not request bail for his client), and that both men will be held in custody until their next court appearance on September 18.

Cyble and DRONA Launch New Push to Close India’s Cybersecurity Gap

Cyber Yodha Campaign

AHMEDABAD (INDIA) — Cyble, the global AI-native cybersecurity company, and DRONA Cyber Solutions, the Ahmedabad-headquartered security operations firm, have launched an AI-powered cyber defense initiative in Ahmedabad, combining threat intelligence, investigation and endpoint enforcement through a joint managed security model.

The AI-Powered Intelligence for Cyber Defense initiative was formally launched Tuesday at DRONA Cyber Solutions' Command and Control Centre, where the companies presented a live technical demonstration showing how an intrusion attempt can be detected, investigated and contained.

The launch comes as India faces a growing cybercrime burden. India recorded 28.15 lakh cybercrime cases in 2025, a 24 percent increase over the previous year, with reported losses reaching ₹22,495 crore. The government's 1930 cybercrime helpline received 32.4 million calls during the year. Of the complaints filed, 55,484 were converted into FIRs. AI-powered cyber defense While large enterprises and banks increasingly have dedicated security teams, budgets and incident response capabilities, many manufacturers, hospital chains, schools and mid-sized businesses, particularly across Tier-2 and Tier-3 cities, continue to operate without comparable security resources.

AI-Powered Cyber Defense Takes Center Stage in Ahmedabad

Rather than focusing solely on formal remarks, Cyble and DRONA used the launch to demonstrate the initiative through a live technical exercise for the media. The demonstration began with material recovered from infostealer logs circulating on a criminal forum, alongside a lookalike domain registered to impersonate a target organisation. Analysts traced the infrastructure, established a pattern of previous activity associated with the same actor and demonstrated the detection and containment of an intrusion attempt on an endpoint.

The final containment action was authorised by a human analyst rather than executed automatically. The demonstration brought together multiple capabilities. Cyble Vision provided the initial detection through continuous monitoring of criminal marketplaces and leak sites.

Cyble Hawk supported the investigative process and attribution, while Cyble Titan handled endpoint enforcement, using hardware-level integrity checks to support its assessment. DRONA analysts remained at the centre of the process, making decisions that the system was deliberately not permitted to make independently. Cybersecurity Collaboration Mandar Patil, Executive Vice President at Cyble, said the initiative was designed to address a longstanding gap between threat detection and action for mid-sized businesses.
"India is not short of alerts. It is short of what happens next," Patil said. "We have spent a long time in this industry watching mid-sized businesses get told about a threat and then having nowhere to take that information. What we are launching today is not another alert. It is a complete chain — intelligence before the attack, investigation that would stand up to scrutiny, enforcement on the device, and a person accountable for the decision at the end of it."
Dhruv Pandit, Co-Founder and CEO of DRONA Cyber Solutions, said the initiative reflects the operational needs of organisations that require immediate action rather than another security dashboard.
"A factory owner calling us at two in the morning does not want to be shown a dashboard," Pandit said. "He wants to know what happened, he wants it contained, and he wants someone to take responsibility for what happens next."

From the Command Centre to Gujarat University, India

The Gujarat University engagement was not simply a conventional cybersecurity student session. It was a technical session titled “Kavach: Beyond the Surface — Threat Intelligence from the Dark Web Depths,” hosted by the Department of Biochemistry and Forensic Science, Gujarat University, in collaboration with Cyble.

The session brought together speakers from Cyble and DRONA Cyber Solutions to examine areas including dark web threat intelligence, government and PSU cybersecurity projects, digital forensics and incident response (DFIR), and the transition of threat intelligence from information to action.

Mandar Patil and Augustin Kurian of Cyble discussed the dark web threat intelligence landscape. Prathmesh Pawar spoke about government and PSU cybersecurity projects, while Brijesh Kapadiya addressed DFIR and Vijay Mali discussed moving threat intelligence from information to action. The keynote was delivered by Prof. Dr. Kapil Kumar, Coordinator, Department of Biochemistry and Forensic Science. AI-powered cyber defense

The session highlighted several practical aspects of cybersecurity work. The dark web was discussed not simply as a hidden part of the internet, but as a structured ecosystem requiring dedicated intelligence-gathering and threat-discovery methods. DFIR was presented as an area where speed and process are as important as technical expertise.

Another key takeaway was the importance of turning threat intelligence into action. Rather than treating intelligence as information alone, the session focused on how it can inform practical security decisions.

Patil told students that the cybersecurity industry faces a shortage of professionals with practical skills in analysing and validating threat intelligence.
"The gap this industry has is not a gap of ideas. It is a gap of people who know how to do the work," Patil said. "What separates a useful analyst from an alert-reader is the ability to ask whether a piece of intelligence is actually true before you act on it."
Augustin Kurian, Editor-in-Chief of The Cyber Express, told students that threat intelligence and journalism share an emphasis on verification.
Every story we publish about a breach, a ransomware group or a leaked database starts exactly where today's demonstration started — with intelligence somebody had to go and find, verify, and decide was worth acting on," Kurian said. The instinct we have tried to build at The Cyber Express is the same instinct a good analyst needs: do not report, and do not act on, what you have not verified.
The programme also involved technical and production teams supporting the session. Screen, sound and lighting were handled by the technical team under the guidance and supervision of Aditya More, while Misha Alagiya, Kavya Maharaja, Pathak Ami, Omi and Nandini supported stage management and photography.

A Broader Cybersecurity Collaboration

Both companies emphasised that the partnership is not intended to represent a single solution to India's cybersecurity deficit. Cyble and DRONA maintain relationships with other partners, service providers and government bodies.
"India's exposure is too large for any single partnership to take credit for solving," Patil said. "What matters is whether more of these collaborations exist a year from now, and whether the businesses we are talking about today — the ones without a security team — actually have somewhere to turn."

The AI-Powered Intelligence for Cyber Defense initiative will be delivered through DRONA's Ahmedabad command centre, with the companies indicating an intent to extend the service model to customers elsewhere in India over time.

The initiative also folds into DRONA's existing Cyber Yodha Campaign, a national programme aimed at building 50 integrated cybersecurity command centre labs and training more than 100,000 defenders.

Global Crackdown on West African Crime Networks Leads to 58 Arrests

West African Organized Crime Groups

An eight-month international operation targeting West African organized crime groups has resulted in 58 arrests and the identification of 263 suspects across 22 countries, according to INTERPOL. Operation Jackal IV, conducted from November 2025 to June 2026, focused on disrupting criminal networks, tracing illicit funds, identifying high-value targets and supporting arrests and prosecutions. The operation brought together countries across six continents to tackle the growing global threat posed by West African criminal networks, including Black Axe and similar groups. These networks have been linked to a significant share of global cyber-enabled financial fraud, including romance scams, cryptocurrency and investment scams, and business email compromise fraud.

Operation Jackal IV Targets West African Organized Crime Groups

Operation Jackal IV also targeted money laundering activities used to move and conceal criminal proceeds across borders. INTERPOL coordinated cross-border intelligence sharing, analysis and operational support during the operation. It also provided specialized training to strengthen international investigations into financial crime. Tomonobu Kaya, Director of the INTERPOL Financial Crime and Anti-Corruption Centre, said the operation showed the importance of international cooperation in following illicit financial flows and disrupting criminal networks. [caption id="attachment_113806" align="aligncenter" width="600"]West African Organized Crime Groups Image Source: INTERPOL[/caption]

Major Arrests and Financial Crime Investigations

In Argentina, authorities identified 196 individuals linked to a major Crime-as-a-Service network suspected of providing website domains and money laundering support to West African organized crime groups. The investigation resulted in 17 arrests, with an INTERPOL Operational Support Team assisting with analysis of seized data and identification of suspects and criminal networks. South African authorities raided seven locations in Johannesburg linked to a syndicate involved in romance and investment scams targeting retirees in English-speaking countries. Investigators arrested 39 people, seized USD 2.67 million and blocked 257 bank accounts. In Italy, investigators identified an individual connected to a pan-European money laundering network that used shell companies, remittance services and cash withdrawals. One account processed EUR 845,000, or about USD 736,000, through 560 transactions involving 20 financial instruments. Romanian authorities dismantled a criminal group operating an investment scam through a call centre. The group promoted high returns from stocks and cryptocurrencies, with victims' money transferred to electronic wallets controlled by perpetrators. Authorities estimated that EUR 143 million had been stolen and laundered globally. Eleven people were arrested, while cash, cryptocurrency, six real estate properties and luxury watches were seized.

Sextortion and Crime-as-a-Service Emerge

Beyond individual investigations, the operation highlighted emerging threats involving sextortion and Crime-as-a-Service. INTERPOL identified an increase in West African organized crime groups using sextortion to target minors, including victims as young as 14. In these cases, offenders typically contacted minors through social media, established trust and persuaded them to share explicit images or videos. They then threatened to distribute the material to the victim's contacts unless a ransom was paid. Investigators also found that some criminal syndicates were procuring Crime-as-a-Service from external providers, including through the dark web. These services were used to outsource activities such as money laundering and other operational functions. While several cases from Operation Jackal IV remain under investigation, the preliminary results demonstrate the scale and international reach of the networks targeted during the eight-month operation. The participating countries were Austria, Argentina, Australia, Canada, Côte d'Ivoire, France, Germany, Indonesia, Ireland, Italy, Japan, Malaysia, the Netherlands, Nigeria, Portugal, South Africa, Spain, Sweden, Switzerland, the United Arab Emirates, the United Kingdom and the United States.

Britain Gains Access to Ukraine’s ‘Goldmine’ of Battlefield AI Data

UK Ukraine AI partnership

The UK Ukraine AI partnership will give Britain access to Ukraine’s Avengers AI Labs, bringing together Ukrainian battlefield experience, operational data and engineering expertise with the UK’s AI ecosystem. The agreement, signed by President Volodymyr Zelenskyy and Prime Minister Andy Burnham in Ukraine, will focus initially on defence and national security. Under the partnership, British innovators and researchers will gain access to data and insights collected across the battlefield. The UK government described Avengers AI Labs as a “goldmine of battlefield data,” offering researchers access to real-world operational information used to train AI models.

How Avengers AI Labs Uses Battlefield Data

The data is collected through thousands of daylight cameras and infrared sensors deployed across the battlefield. The systems capture images and information involving tanks, artillery, air defence systems, infantry and aerial targets, including Shahed drones and reconnaissance UAVs. The data is used to train AI models to recognize and classify battlefield objects. Ukraine’s Defense Ministry has previously said that systems trained using the Avengers Labs platform analyze more than 100,000 drone video feeds each month and help identify about 70% of enemy targets in real time. The UK’s access to the platform is intended to allow British startups, researchers and engineers to work with operational insights and develop technologies based on real-world datasets. The partnership will initially bring together engineers, academics, businesses and military operational expertise from both countries to address national security challenges. The two countries will also explore additional platforms for future collaboration.

UK Ukraine AI Partnership Test New Defence Technology

Several pilot projects involving British startups have already been rolled out as part of the agreement. The companies named are Bristol-based Sintela, Oxford’s Mind Foundry and London’s Skyral. The first technology is due to be deployed at a UK defence site to help protect bases from protestors and hostile actors seeking intelligence. The project combines Ukrainian data with UK technology and turns buried fibre-optic cables into an AI-enabled sensor. The technology could also be used in other critical locations, including airports, prisons, railways and energy plants, according to the information released about the partnership. A second project will examine the development of next-generation low-power AI chips designed for future drones, robotics and autonomous systems. If successful, the technology could support machines designed to operate for longer, respond faster and function in environments where conventional systems face limitations.

AI Sovereignty and Defence Innovation

The agreement forms part of the UK and Ukraine’s 100 Year Partnership and expands cooperation between the two countries in AI and defence technology. The UK will provide access to its universities, researchers, technology companies and AI ecosystem, while Ukraine will provide access to operational experience and datasets generated during the war. Minister for AI Kanishka Narayan described the arrangement as AI sovereignty in practice, focused on developing national capabilities and turning frontline experience into technologies for military and critical infrastructure protection. The partnership also follows the UK government’s announcement that defence firm MBDA can release classified information on UK components for the long-range SCALP missile to establish local assembly lines in Ukraine. The broader agreement is intended to combine Ukrainian battlefield data with British scientific, engineering and technology expertise, with the initial focus remaining on defence, national security and the development of future defence technology.

Ledger Fixes Ethereum App Flaw as Disclosure Timeline Is Disputed

Ethereum app

Ledger CTO Charles Guillemet said on Aug. 23, 2026, that the company had fixed a clear-signing flaw in its Ethereum app two weeks before security firm TestMachine publicly disclosed the issue. As of Aug. 24, there were no independently verified reports of funds stolen through the specific vulnerability.  The issue involved clear signing, a security feature that displays transaction amounts, addresses, and smart-contract actions directly on a Ledger device before approval. TestMachine said a malicious application could send a competing command while a user was reviewing the legitimate transaction. Under that scenario, the device screen could display one transaction while another was prepared for signing. Researchers cited a potential example in which a limited transaction could be replaced with a broader token approval.  TestMachine said its AI vulnerability scanner, Azimuth, discovered and validated the flaw during an autonomous scan on a Ledger Flex. Because of shared code, the company said Nano X, Nano S Plus, Stax and Apex devices could also potentially be affected. However, no complete public proof of concept showing fund theft across every named device was available at publication.  Guillemet said Ledger Donjon, the company's internal security research team, had independently identified the problem using an AI-powered vulnerability research system. He said the fix “was deployed two weeks ago” and argued that claims the vulnerability remained open amounted to “manufacturing fear for attention.”  TestMachine disputed that account, saying it had shared and verified the finding with Ledger but declined a bounty. Guillemet said the company contacted Ledger's bounty program only after the fix had shipped and did not discuss the vulnerability with the bounty team before publication. Neither side's account of the disclosure sequence has been independently confirmed. 

TestMachine, Ledger and the Missing Release Record 

Ledger's public Ethereum app repository creates another unresolved question. As of Aug. 24, its newest tagged release was version 1.22.1, dated May 27, 2026. Its only listed change was “Instability in APDU communication handling.” No August 2026 tagged release identifies the clear-signing substitution issue described by TestMachine.  That does not establish that Ledger failed to patch the flaw. Ledger can distribute application updates through its device app store without creating a corresponding tagged GitHub release. Still, the public record does not allow users to verify Guillemet's “two weeks ago” timeline or determine which Ethereum app version contains the fix, as CoinLaw reports. Ledger has also not published a detailed technical advisory, affected-version list, or patched release identifier. Its guidance, echoed by Guillemet, is to keep firmware and apps updated. 

What Users Need to Check for the Ethereum App Vulnerability? 

The patched Ethereum app has been described as available through Ledger Live, but updating the desktop or mobile interface alone may not replace an outdated application installed on the hardware wallet. Users therefore need to check the device's own app store and reinstall or update the Ethereum app separately.  The incident also highlights why clear signing matters. Verifying transaction details on the hardware device itself, rather than relying solely on the paired software, is intended to protect users from transaction manipulation.  The Ledger discussion should not be treated as evidence of confirmed losses from this flaw. At this stage, the facts establish a disputed disclosure timeline, an asserted fix, and a lack of independently verified theft—not confirmation that funds were lost or that the patch was never shipped.  For TestMachine, Ledger and users alike, the unresolved issue is documentation. A dated, versioned security advisory identifying the affected versions and patch would allow users to verify their protection without relying on competing public statements. 

AliExpress caught using silent audio to fingerprint visitors’ browsers

AliExpress, the online marketplace owned by Alibaba Group, has come under scrutiny after researchers and browser maker Brave reported finding silent Web Audio processing on the site that could help fingerprint visitors’ devices.

The audio processing did not record people through their microphones. Instead, it generated and processed an inaudible signal, then measured small, repeatable differences in the way a browser and device handled it.

Browser fingerprinting is a way for websites to identify devices and recognize returning visitors without relying on conventional cookies. It works by using information about a device and browser to create a unique signature.

The AliExpress website was found processing a fixed audio waveform and examining the resulting numerical values. Tiny differences can arise from the browser, operating system, CPU behavior, audio hardware, and drivers. When combined with other signals, they become another input that can contribute to a browser or device identifier.

Investigation of the page’s code reportedly found audio-processing graphs that were set to zero volume but remained connected to the system audio output. That explains why a user could hear nothing, and why muting a browser tab would not necessarily prevent the processing. All the relevant work was occurring within the Web Audio graph rather than through a conventional media player.

And audio measurements were only one part of the reported data collection. The scripts also gathered information tied to canvas rendering, WebGL, display settings, hardware configuration, WebRTC behavior and user interactions. Together, those signals can create a more detailed profile of a device than any one signal would provide on its own.

Fingerprinting can be used for legitimate purposes such as fraud prevention, bot detection, and risk assessment. It can help companies spot suspicious transactions or automated activity even when cookies have been deleted or accounts have changed. But it also raises privacy concerns because users may not know the tracking is happening and have limited control over it.


Safer. Cleaner. Ad-free browsing.


Earlier studies have shown that visitors’ choices about allowing cookies were ignored in more than half the cases studied. Fingerprinting adds another privacy concern because it can allow websites to recognize visitors without relying on cookies at all.

How to protect yourself

The alleged AliExpress implementation is a useful example of how modern tracking can be both silent and technically legitimate at the API level while still raising privacy concerns.

Brave says its browser blocks the AliExpress scripts responsible for the audio-based tracking. Other steps you can take include:

  • Use content blockers and anti-tracking extensions to limit the information websites can collect about your browser and device.
  • Keep your browser up to date since browser vendors continually change privacy defenses as fingerprinting methods evolve.
  • Use a separate browser or browser profile for shopping, ideally without signing in to other services in the same profile.

Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

The Cyber Express Weekly Roundup: Tax Data Breach, AI Security Risks, and Critical GitLab Flaw

The Cyber Express August 21 Weekly Roundup

This weekly roundup highlights a broad range of cybersecurity threats affecting government agencies, businesses, enterprise AI systems, and software platforms. From a major French tax authority breach to a critical GitLab vulnerability, recent incidents demonstrate how attackers continue to exploit sensitive data, digital systems, and emerging technologies. The latest developments also show that cybersecurity risks are expanding beyond traditional attacks. Organizations are increasingly facing threats involving sensitive customer information, AI-powered systems, supply-chain risks, software vulnerabilities, and potential interference with critical operations.

The Cyber Express Weekly Roundup

French Tax Authority Data Breach Hits 678,000 People 

France’s tax authority, DGFiP, confirmed a cyberattack that exposed tax and cadastral information belonging to 678,000 individuals and professionals. The accessed information includes tax income, withholding rates, business details, addresses, and property information. DGFiP said online accounts and passwords were not compromised and is continuing to investigate the incident. Read more... 

Cyberattack Targets Ukraine Agency Ahead of Major Asset Tender 

Ukraine’s Asset Recovery and Management Agency (ARMA) suffered a suspected cyberattack shortly before a major deadline to select a manager for assets linked to sanctioned Russian oligarch Mikhail Fridman. ARMA said the incident, combined with earlier cyber activity and increased information pressure, could indicate a coordinated attempt to disrupt its operations or influence the tender. Read more... 

Oz Hair and Beauty Data Breach Exposes Customer Information 

Oz Hair and Beauty confirmed that an unauthorized party accessed customer information, including names, email addresses, phone numbers, and purchase history. The company said credit card, banking, and home-address information were not compromised. The number of affected customers remains undisclosed, while an investigation into the breach continues. Read more... 

Enterprise AI Is Expanding the Cybersecurity Risk 

Guild Group’s Mohammad Arif warned that the rapid adoption of enterprise AI is creating new cybersecurity challenges as AI systems gain access to sensitive data, applications, and business workflows. Key concerns include shadow AI, data leakage, insecure integrations, AI supply-chain attacks, prompt injection, and AI-powered phishingRead more... 

Critical GitLab Flaw Could Let Attackers Delete Public Projects 

GitLab patched a critical vulnerability, CVE-2026-19478, that could allow unauthenticated attackers to remotely modify or delete public projects and user data. The flaw carries a CVSS score of 9.4. GitLab also addressed a high-severity GraphQL CSRF vulnerability, CVE-2026-19650. Read more... 

Weekly Cybersecurity Takeaway 

This week’s incidents demonstrate that cybersecurity threats are increasingly crossing organizational and technological boundaries, affecting government systems, customer data, enterprise AI, and software development platforms. Organizations should prioritize strong access controls, rapid vulnerability patching, data protection, AI governance, employee awareness, and continuous monitoring. As attackers continue exploiting both human trust and technical weaknesses, security teams must adapt to a threat landscape that is becoming broader, faster, and increasingly interconnected.
❌