US Brings Alleged Black Axe Bosses to Court Over Cybercrime
Five men that US prosecutors call senior Black Axe members now face charges over a decade of cybercrime against American victims. South African police arrested them in 2021 at the request of the United States. After a long wait, US authorities extradited all five on September 11, 2026, and each of them could now face years in prison. Who the

US Charges Russian Over TVRAT Malware Attack on Freelancers
A phishing operation that ran quietly for a year and a half has finally put its alleged operator in front of a US judge. Federal prosecutors in California have indicted a Russian national over a campaign that planted TVRAT malware on the computers of 80,000 freelancers. The attack never touched a corporate network. Instead, it arrived through a messaging system

Sality Botnet Seized After 23 Years of Crypto Theft
A piece of malware that first appeared in 2003 has finally run out of road. Law enforcement agencies across several countries seized the infrastructure behind the Sality botnet this week, and private security firms handled the technical side of the operation. The malware survived 23 years of antivirus updates, operating system rewrites, and earlier cleanup attempts. Now its command network

Claude Session Hijacking: Malware Drains Paid AI Accounts
Anthropic has started emailing Claude users with an unwelcome message. Malware sitting on their own computers stole active login sessions. Attackers then used those sessions to sign in and drain the usage that victims had paid for. This wave of Claude session hijacking did not begin with a flaw in the AI platform, because it began on the victim's own

Operation Jackal IV: 58 Arrests in Global Fraud Takedown
Police forces in 22 countries have closed one of the biggest fraud investigations of the past year. Operation Jackal IV ran from November 2025 through June 2026, and it ended with 58 arrests. Investigators also identified 263 more suspects tied to cybercrime networks run by West African organized crime groups. INTERPOL coordinated the work, and the results open a rare

Google Blogger Malware False Positive Locks 100s of Blogs
Hundreds of bloggers signed into their dashboards on August 4 and found a red padlock waiting for them. Their sites had been locked. Some were already gone. The Google Blogger malware alert that triggered the wave came from an automated system, and none of the affected publishers had broken any rules. Legitimate personal blogs, hobby sites, and small independent publications

CISA Critical Infrastructure Guidance: Plan the Cutoff Now
Water treatment plants, power grids, and telecom networks run on equipment that predates the modern internet. Most of it now connects to corporate systems, cloud platforms, and outside vendors anyway. The new CISA critical infrastructure guidance addresses that reality head on. Rather than promising to keep intruders out, it asks operators a harder question: can you disconnect fast enough to

Spanish Police Take Down €140M Cyber Fraud Ring
Investment scams and executive impersonation schemes rarely stay small for long, and a recent case out of Spain shows just how large these operations can grow. Spanish police have taken down a cyber fraud ring accused of laundering €140 million through a sprawling network of bank accounts, fake invoices, and impersonated executives. Four suspects now face charges after coordinated raids

1VPNS Hit With US Sanctions Over Ransomware Ties
The United States Treasury Department has taken direct aim at the infrastructure behind ransomware attacks. On Monday, the Office of Foreign Assets Control announced sanctions against 1VPNS, a virtual private network provider, and its administrator, in connection with ransomware attacks against U.S. organizations. The 1VPNS ransomware sanctions mark a shift toward punishing the suppliers behind attacks, not just the criminals

Inside the NetNut Botnet Takedown: 2M Devices Freed
A quiet piece of internet infrastructure just got a lot less useful for cybercriminals. The NetNut botnet takedown, carried out by Google's Threat Intelligence Group, the FBI, Lumen Technologies, and The Shadowserver Foundation, has dismantled a residential proxy network built from roughly 2 million hijacked devices. The network, also known as "Popa," gave hackers a way to disguise malicious traffic
