Category: News

Current, event-driven reporting, announcements and industry developments.

  • ‘DoppelCart’ Fraud Network Runs 119,000 Fake Online Stores to Steal Payment Card Data

    ‘DoppelCart’ Fraud Network Runs 119,000 Fake Online Stores to Steal Payment Card Data

    German cybersecurity company Nebty has identified a fraud operation dubbed DoppelCart, describing it as the largest publicly documented fake-shop network by domain count, spanning almost 119,000 domains built to mimic real retailers and harvest payment card data from bargain-hunting shoppers.

    A Cluster Built Almost Entirely on One Top-Level Domain

    Nebty’s scans identified 118,787 domains in the cluster, the large majority registered under the .shop top-level domain and accounting for roughly 2.72% of all sites on that TLD. As of the researchers’ latest scans, more than 105,000 of the fake shops remained active. The sites mimic more than 44,000 real brands, with a typical brand cloned around twice, though some brands, including SodaStream, Velasca, CurrentBody, Daniel Wellington and Dreame, were impersonated by more than 30 separate shops each. The fake storefronts typically advertise discounts of up to 65% to lure shoppers searching for deals.

    Shared Infrastructure Behind Thousands of Storefronts

    Despite the scale of the operation, the underlying infrastructure is comparatively narrow: researchers found that 96% of confirmed DoppelCart shops shared identical build files and ran on just 27 distinct e-commerce backends, suggesting a small number of template kits power the vast majority of the cluster. When testing checkout pages across the network, Nebty found code specifically built to collect payment card numbers and cardholder information at the point of sale, rather than simply taking payment through a legitimate processor and never delivering goods.

    The New Largest Fake-Shop Network on Record

    DoppelCart significantly surpasses the previously largest documented fake-shop cluster, “BogusBazaar,” a network of roughly 75,000 sites tied to an estimated 850,000 fraudulent transactions. Researchers advise shoppers to check unfamiliar retail URLs carefully for odd domain extensions, verify a business has visible customer reviews and contact information, and treat unusually steep discounts on well-known brands as a warning sign rather than an opportunity.

  • Extortion Group Claims Breach of Florida DMV Database, Threatens to Leak 200,000 Driver Records

    Extortion Group Claims Breach of Florida DMV Database, Threatens to Leak 200,000 Driver Records

    The extortion group ShinyHunters claims to have breached an online platform used by the Florida Department of Highway Safety and Motor Vehicles, stealing more than 200,000 driver records and threatening to publish the data if the state does not respond by a set deadline.

    A Password-Reset Flaw Allegedly Opened the Door

    The targeted system, known as DAVID (Driver And Vehicle Information Database), is described by the Florida Highway Safety and Motor Vehicles agency as a platform that gives law enforcement and criminal justice officials immediate access to driver and vehicle information, and serves as the state’s primary reporting mechanism for fatalities and serious injuries. ShinyHunters told BleepingComputer the intrusion exploited a password-reset weakness that let the group compromise multiple internal accounts, including ones it claims belonged to DMV employees and an FBI agent. Using that access, the group said it wrote a script to iterate through driver records by ID number, downloading the associated HTML pages and images for each one, collecting over 200,000 records since the breach allegedly began on September 3, 2026.

    Epstein Record Used as Proof, September 11 Deadline Set

    As evidence of the intrusion, the group released a screenshot of a DMV record belonging to Jeffrey Epstein, including his address and registered vehicles. ShinyHunters added the Florida agency to its dark web leak site with a listing giving officials until September 11, 2026, to make contact before the group releases the full dataset, a listing the group has labeled a “final warning.” The claimed 200,000-record figure comes directly from the attackers and has not been independently verified or confirmed by the state as of publication.

    Part of a Broader Pattern of Government Database Targeting

    ShinyHunters has claimed responsibility for a string of high-profile extortion cases against corporate and government targets over the past year, frequently relying on compromised credentials and account takeover rather than novel technical exploits to gain initial access. The alleged Florida incident underscores a recurring weak point in large government record systems: authentication and account-recovery workflows that, once compromised, can expose bulk record access far beyond what a single stolen credential would typically allow.

  • Attackers Used a Three-Year-Old Flaw to Steal Reactor Data From a Philippine Nuclear Agency

    Attackers Used a Three-Year-Old Flaw to Steal Reactor Data From a Philippine Nuclear Agency

    A threat actor exploited a long-patched vulnerability in the file-sharing platform ownCloud to steal reactor data, personnel records and stored credentials from a Philippine nuclear research organization, according to researchers who found the stolen material staged on attacker-controlled infrastructure.

    A Two-Year-Old Bug in a Default Configuration

    Threat-hunting firm Hunt.io published a blog post on August 26, 2026 identifying an ownCloud server hosted in Amsterdam that appeared to function as a staging hub for a suspected Chinese-speaking operator, containing offensive tooling alongside data taken from at least two victims: a Philippine nuclear research agency and a marine engineering and shipbuilding company serving the Philippine Navy. The intrusion exploited CVE-2023-49105, an authentication bypass in ownCloud’s pre-signed URL mechanism disclosed by the vendor in November 2023 and carrying a CVSS score of 9.8. On installations left in ownCloud’s default configuration, with no signing key configured, an attacker who knows a valid username can construct requests the system accepts as authenticated, letting them access, modify or delete files without ever supplying a password.

    Reactor Records, Personnel Files and Stored Credentials

    The material recovered from the nuclear agency’s staging folders, roughly 372 MB across 176 files, included a database of research-reactor core components, historical fuel inventories, radiation-safety documentation, incident records, and a 192 MB database dump from a biometric attendance and personnel system, alongside employee resumes, travel records and financial disclosures. Investigators also found a KeePass password database, AxCrypt-encrypted files and a PDF containing a BitLocker recovery key among the stolen material, credential artifacts that could help an attacker move further into connected systems. A separate recovered inventory suggested roughly 9 GB of data may have been taken from the agency in total, though only a fraction was directly recovered by researchers.

    CISA Adds the Flaw to Its Exploited Catalog

    The US Cybersecurity and Infrastructure Security Agency added CVE-2023-49105 to its Known Exploited Vulnerabilities catalog on August 27, 2026, one day after Hunt.io’s disclosure, formally flagging a nearly three-year-old bug as under active exploitation. The incident illustrates a recurring pattern in intrusions against sensitive government and research infrastructure: the vulnerability exploited was neither novel nor unpatched by the vendor, but a long-available fix that an internet-facing, self-hosted file-sharing system had apparently never received.

  • Nvidia-Backed Zankore Secures $3.1 Billion Loan for Southeast Asia AI/GPU Buildout

    Nvidia-Backed Zankore Secures $3.1 Billion Loan for Southeast Asia AI/GPU Buildout

    Zankore, an AI compute (“neocloud”) platform backed by Indosat Ooredoo Hutchison, Ooredoo Group, Nokia and Nvidia, signed a senior term loan facility of up to $3.1 billion to fund Nvidia GPU and cloud infrastructure deployment across Indonesia and Southeast Asia, Reuters reported. The financing supports an initial 100MW of Nvidia AI infrastructure, with Citi, ING, Natixis, Qatar National Bank and UOB arranging the debt.

    Why it matters: The deal illustrates how AI compute buildout is expanding well beyond the US, Europe and China, with large debt-financed infrastructure projects now targeting Southeast Asia specifically — a region where data center and power infrastructure security is a growing concern for operators and regulators alike.

    Source: Reuters, September 9, 2026.

  • Google to Invest $15.1 Billion in Finland AI Infrastructure, Signs First Nuclear Power Deal Outside the US

    Google to Invest $15.1 Billion in Finland AI Infrastructure, Signs First Nuclear Power Deal Outside the US

    Alphabet’s Google will invest at least €13 billion ($15.1 billion) in AI infrastructure in Finland over 2027–2028, its largest European investment to date, Reuters reported. The funding covers three new data centers plus grid and clean-energy upgrades.

    Google also signed a 22-year power purchase agreement for up to 50% of the output of Fortum’s Loviisa nuclear plant — the company’s first nuclear power deal outside the United States.

    Why it matters: The scale of AI-driven data center buildout is now large enough that hyperscalers are signing multi-decade nuclear power agreements to secure supply, a direct signal of how AI infrastructure growth is reshaping national energy planning and grid investment, including in countries not previously associated with hyperscale data center clusters.

    Source: Reuters, via DW and AFR, September 9, 2026.

  • Caterpillar and FieldAI Partner to Bring Physical AI and Autonomy to Jobsites and Factories

    Caterpillar and FieldAI Partner to Bring Physical AI and Autonomy to Jobsites and Factories

    Caterpillar Inc. has entered a collaboration with robotics startup FieldAI to bring physical AI, autonomy and robotics to construction, mining and manufacturing sites, the companies announced. The partnership pairs Caterpillar’s decades of jobsite and equipment data with FieldAI’s robot-agnostic autonomy platform, aiming to help industrial operators address labor shortages and rising productivity demands.

    Combining Operational Data With Robot-Agnostic Autonomy

    The collaboration, announced September 2, 2026, combines Caterpillar’s engineering expertise and operational data with FieldAI’s AI-enabled robot foundation models, which are designed to process large volumes of jobsite and operational data and turn real-time observations into actionable insight. FieldAI says its foundation models are already deployed across hundreds of sites worldwide and are built to operate in the kind of complex, dynamic industrial environments where conventional automation has historically struggled. The work also incorporates NVIDIA accelerated computing and Omniverse digital-twin technology, allowing the companies to build virtual representations of jobsites and manufacturing facilities for testing and validation before deployment.

    Early Applications Target Inspection and Situational Awareness

    The companies identified autonomous inspections, enhanced situational awareness, operational optimization and digital-twin modeling of jobsites and equipment as initial applications. For heavy-industry operators, autonomous inspection capabilities in particular could extend how facilities monitor equipment condition and site hazards without relying solely on scheduled manual walkthroughs. “This collaboration brings leading physical AI capabilities to a leading manufacturer of construction and mining equipment,” said Ali Agha, founder and CEO of FieldAI, adding that the companies are “shaping the next century of AI-enabled heavy industry.” The initiative builds on Caterpillar’s existing autonomous-mining programs and its broader push to extend autonomy into more complex, less structured industrial settings.

  • Microsoft Ships Record September 2026 Patch Tuesday, Fixing 964 Flaws Including Two Exploited Zero-Days

    Microsoft Ships Record September 2026 Patch Tuesday, Fixing 964 Flaws Including Two Exploited Zero-Days

    Microsoft shipped its largest Patch Tuesday on record this week, fixing 964 vulnerabilities across its product line — more than double August’s release and a new monthly high for the company. The September 2026 update includes patches for two zero-day flaws already being exploited in the wild, along with 113 vulnerabilities rated Critical.

    Two Exploited Zero-Days Among 964 Fixes

    The two actively exploited flaws include CVE-2026-81963, an elevation-of-privilege vulnerability in the Windows Update Stack that stems from improper link resolution before file access, commonly known as link following. Security researchers note the bug is most relevant to post-compromise activity, letting an attacker who already has a foothold on a system escalate to greater control. Cybersecurity companies Volexity and Proofpoint were credited with reporting one of the exploited flaws, while a researcher at Airbus Helicopters and Microsoft’s own threat intelligence team were credited with the second. The U.S. Cybersecurity and Infrastructure Security Agency has added both to its Known Exploited Vulnerabilities catalog, giving federal civilian agencies until September 22, 2026 to apply the fixes.

    A Record Critical Count Across Windows Components

    Among the 113 Critical-rated bugs, several affect core Windows security components, including CVE-2026-83939 in Windows Secure Kernel Mode and CVE-2026-83498 in Virtualization-Based Security enclave privileges. Microsoft also patched a string of remote-code-execution flaws carrying CVSS scores of 9.8, including issues in Skype for Business, the Windows Routing and Remote Access Service, the Windows HTTP Print Provider, Windows Shell and the Windows Imaging Component. None of the RCE flaws are confirmed to require no user interaction, but their severity ratings and broad footprint across widely deployed Windows components make rapid patch validation and deployment a priority for enterprise IT and security teams this month.

  • Consumer Cybersecurity Firm Guardio Reaches $1.1 Billion Valuation as Wiz Co-Founder Invests

    Consumer Cybersecurity Firm Guardio Reaches $1.1 Billion Valuation as Wiz Co-Founder Invests

    Guardio, a consumer cybersecurity company focused on protecting individuals from online scams and phishing, has raised $40 million in new funding at a valuation of $1.1 billion, with Wiz co-founder and chief executive Assaf Rappaport joining as an investor.

    Four Straight Years of Triple-Digit Growth

    The round, announced September 3, 2026, also included existing investors ION Crossover Partners, Union Tech Ventures, Vintage Investment Partners, Cerca Partners and Emerge Ventures, and brings Guardio’s total funding to date to $167 million. The Israeli company said it has grown revenue more than 100% year over year for four consecutive years, surpassing one million paying customers and $150 million in annual recurring revenue. Guardio plans to use the new capital to expand its suite of consumer-focused protection tools covering browsing, phishing and broader digital-presence risks.

    AI Cuts Both Ways for Consumer Fraud

    Gilad Shany, managing partner at ION Crossover Partners, said the company’s combination of cybersecurity expertise, consumer-product focus and distribution reach was behind the sustained growth. Rappaport, who invested personally in the round, pointed to artificial intelligence as a factor reshaping the threat landscape for ordinary consumers, making phishing, brand impersonation and deepfake voice scams more convincing and harder to distinguish from legitimate communication. Guardio’s raise adds to a run of large valuations for Israeli cybersecurity companies in 2026, as consumer-facing security products compete for a growing pool of capital alongside enterprise-focused vendors.

  • Researchers Build Zero-Click Worm That Hijacked WeChat Accounts via a Single Call

    Researchers Build Zero-Click Worm That Hijacked WeChat Accounts via a Single Call

    Security researchers at the firm Calif built a working worm capable of hijacking WeChat accounts on both iOS and Android through a single incoming call, then using the compromised account to spread automatically to the victim’s contacts, in what the company describes as the first zero-click worm demonstrated against a mainstream messaging app on both platforms.

    Attacker Calls Victim, Victim Becomes Attacker

    In a demonstration published September 8, 2026, Calif showed an Android phone calling an iPhone and taking over its WeChat account while the phone was still ringing, with no answer or user interaction required. The compromised iPhone then called a second Android phone and took control of it the same way, illustrating a self-propagating chain: attacker calls victim, victim becomes attacker, victim calls the next victim. Calif said the underlying issue is a memory-corruption bug in WeChat’s VoIP stack, and that because the caller must already be on the target’s contact list, the extra trust WeChat extends to contacts ends up working in the attacker’s favor once one account in a network is compromised. Once hijacked, an account can read and send messages, place calls, and act on the victim’s behalf.

    Patched Before Public Disclosure

    Calif reported the flaw to WeChat developer Tencent in July, and Tencent shipped version 8.0.77 for Android and 8.0.76 for iOS on August 21, 2026, mitigating the bug; Calif confirmed on August 28 that the specific exploit was also blocked on Tencent’s servers for all users regardless of app version. Tencent has not published a security advisory describing the flaw, and its release notes for the affected updates describe them only as general bug fixes. Researchers are advising WeChat users to keep the app updated, review their contact lists for unfamiliar connections, and treat unexpected incoming calls from known contacts with caution, since a compromised contact’s account could be used to continue the propagation chain.

  • Alby Discloses Critical Flaw in Internet-Exposed Bitcoin Lightning Wallets

    Alby Discloses Critical Flaw in Internet-Exposed Bitcoin Lightning Wallets

    Alby, the company behind the Bitcoin Lightning Network and Nostr tooling suite Alby Hub, has disclosed a critical vulnerability affecting older versions of its self-hosted Lightning wallet that could let an attacker take over and drain funds from any instance left reachable from the public internet.

    Unauthenticated Access to the Management API

    In a disclosure posted September 9, 2026, Alby said it had confirmed a critical flaw in Alby Hub versions 1.7.0 through 1.18.5, released before August 2025, when the Hub is publicly accessible from the internet. According to the company, an attacker who can reach the Hub’s management API over the network can access it without authorization and send funds out of the wallet, effectively draining any exposed node. Alby urged affected users to immediately take internet-exposed instances offline, update to a patched version, and change their unlock password after updating, since the credential itself could have been exposed during the window the Hub was reachable.

    Part of a Rough Stretch for Lightning-Adjacent Projects

    The disclosure follows a difficult few weeks for Lightning Network-adjacent infrastructure: Boltz, a separate non-custodial bridge that moves bitcoin between the main chain, the Lightning Network and the Liquid Network, took its swap functionality offline on August 3, 2026, after its own security issue, and Bitcoin’s Liquid Network separately suffered a $320 million theft that white-hat hackers later helped partially recover. Security researchers have pointed to the growing use of AI-assisted attack tooling as a factor putting increased pressure on smaller, self-hosted Bitcoin infrastructure projects that lack the security resources of larger custodial platforms.