ZeroHour

Search: “prosecutors”

40 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Risky Bulletin: Ukraine's top prosecutor resigns amid scam call center scandal

Ukraine's top prosecutor Ruslan Kravchenko resigned after NABU arrested a deputy for taking bribes protecting scam call centers running fake investment platforms.

Ukraine's anti-corruption bureau NABU arrested Serhiy Kropyva, Deputy Head of International Cooperation at the Prosecutor General's Office, alleging officials took monthly protection fees from a network of 100-500 scam call centers luring victims into fake investment platforms, with bribes reportedly growing from $700,000 to $3.5 million per month. Prosecutor General Ruslan Kravchenko resigned on Monday, calling it a political decision, while Kropyva was fired with bail set at 120 million hryvnias ($2.7 million) and over 100 call centers shut down in the past month. The newsletter also briefly covers a cyberattack crippling more than 80 Luxembourg medical practices via payment vendor BMS Engineering, ShinyHunters' claimed theft of 200,000 Florida DMV driver records, a cyberattack on the American Meteor Society, and school closures in Springfield, Massachusetts.

Risky Business News · 7d agoPhishing & fraud

ChatGPT-using lawyer punished for citing fake testimony from made-up witnesses

New Mexico Supreme Court holds lawyer in contempt for filing a ChatGPT-generated brief citing fabricated witness testimony; fined $5,000 and referred to disciplinary board.

The New Mexico Supreme Court held criminal defense lawyer Stephen Aarons in direct contempt for filing a murder-appeal brief containing false testimony from wholly fabricated witnesses, including Officer Michelle Amarillo and Officer Sanchez, plus misrepresented legal authority. Aarons admitted feeding a computer-generated trial transcript into ChatGPT, powered by the OpenAI o3 model, and filing the output without verifying factual claims or telling his client. He was fined $5,000, referred to a disciplinary board, and barred from appearing before the court pending proceedings; the court struck all briefs and ordered new counsel for client Oscar Renee Sandoval.

Ars Technica · AIupdated · 4d agofirst · 4d agoAI safety & security 2 sources

Ukraine moves to crack down on scam call centers after corruption scandal

Ukraine's parliament passed legislation criminalizing fraudulent call centers with 7-12 year prison terms after a bribery scandal implicating prosecutors.

Ukraine's Verkhovna Rada passed legislation making electronic-communications fraud and organizing or working for fraudulent call centers separate crimes punishable by 7-12 years, awaiting President Zelensky's signature. The bill advanced after NABU alleged prosecutors took bribes since mid-2025 to shield scam call centers; five suspects were named and Prosecutor General Ruslan Kravchenko, who denies wrongdoing, was dismissed by parliament and presidential decree. Ukrainian authorities previously reported 411 searches and 94 suspected call centers shut down in one week, including a Kyiv operation that stole over $500,000 from dozens of Americans.

The Record · 4h agoPolicy & legal

Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars

Ukrainian lawyer turned Conti malware coder sentenced to four years in US prison, ordered to forfeit $25,042 in Bitcoin.

Oleksii Oleksiyovych Lytvynenko, 44, a trained lawyer who joined Conti under the handle "henry", pleaded guilty in June to conspiracy to commit wire fraud and was sentenced to four years. He coded a malware loader, researched targets using Google and ZoomInfo, and possessed data stolen from eight US victims who reported over $1.5 million in losses. Investigators found Cobalt Strike running and a Rocket.Chat session over Tor on his laptop when Gardaí arrested him in County Cork, Ireland in July 2023; he was extradited to the US in October 2025. Conti attacked over 1,000 victims across 47 US states and 31 countries, with payouts exceeding $150 million by January 2022.

The Register · Securityupdated · 5d agofirst · 5d agoPolicy & legal 7 sources

Russian suspect in bank account takeovers is extradited to US

Russian web developer Sergei Filimonov was extradited from Georgia to the US to face charges in a multimillion-dollar bank account takeover fraud.

Sergei Anatolyevich Filimonov, 36, appeared in an Atlanta federal court on September 4 and pleaded not guilty to bank fraud, wire fraud, access device fraud, and aggravated identity theft charges. Prosecutors say that from November 2023 to October 2025 his group bought sponsored search-engine links that diverted online banking customers to spoofed login pages, stole their credentials, and initiated unauthorized wire transfers. The FBI linked the scheme to the December 2025 seizure of the domain web3adspanels.org, identifying at least 19 victims, roughly $14.6 million in confirmed losses, and about $28 million in attempted losses.

The Record · 7d agoPolicy & legal

Russian man indicted for spreading malware to 80,000 freelancers

US prosecutors indicted a Russian national for infecting roughly 80,000 freelancers with TVRAT and DarkVNC malware via fake freelance-platform accounts.

Searzhudin Tamirlanovich Aktulaev, 40, was indicted in California for conspiracy, transmission of malicious code, and aggravated identity theft; he was arrested in Cyprus in May 2025 and extradited in August 2026. From June 2016 to November 2017, about 255 fake accounts on a Northern California freelance platform messaged roughly 80,000 users with malicious Excel attachments that ran macros to download malware. The campaign deployed TVRAT (also known as TeamSpy), which exploited a TeamViewer flaw, and DarkVNC via VNC Viewer, exfiltrating stolen data to US-hosted command-and-control servers. About half the victims were in the US, and stolen credentials were used for fraud.

Help Net Security · 13d agoPolicy & legal in the wild

Florida confirms DMV database breached via stolen police account

Florida confirms its DAVID driver database was breached using stolen police credentials; ShinyHunters claims theft of 200,000+ records.

The Florida Department of Highway Safety and Motor Vehicles confirmed a breach of its DAVID driver database, learned of on September 4, 2026, and says the breach was quickly mitigated with none ongoing. Investigators found the attacker used compromised credentials of a single Plant City Police Department employee that were improperly stored on a personal electronic device. The ShinyHunters extortion gang claims it stole more than 200,000 driver records starting September 3 and shared a Jeffrey Epstein record as proof; FLHSMV has not confirmed the count. The agency notified the Florida Attorney General's office and is working with the Florida Digital Service and Florida Department of Law Enforcement.

BleepingComputerupdated · 4d agofirst · 4d agoData breach in the wild 2 sources1

The County Prosecutors Who Became ICE Informants

Illinois county prosecutors shared defendants' personal data with federal ICE agents without warrants, disclosure, or oversight, WIRED reports.

WIRED reports that county prosecutors in Illinois effectively became informants for federal immigration agents. Defendants' personal data was shared without criminal warrants, public disclosure, or legislative oversight. The story raises privacy and accountability concerns around government handling of personal data.

WIRED · Security · 22d agoPolicy & legal

Ukrainian software developer faces 12 years in Swiss ransomware trial

Swiss prosecutors seek a 12-year sentence for a Ukrainian developer accused in LockerGoga, MegaCortex and Nefilim ransomware attacks causing roughly $160 million in losses.

A 52-year-old Ukrainian software developer went on trial at Zurich District Court over alleged involvement in ransomware attacks using LockerGoga, MegaCortex and Nefilim, with victims including Stadler Rail, Crealogix and Meier Tobler. Prosecutors allege he participated in attacks on 10 companies between December 2018 and May 2020, causing more than 130 million Swiss francs (~$160 million) in losses, and seek a 12-year sentence plus 1.8 million Swiss francs in proceeds. He denies developing malware, and his defense challenges digital evidence handling. The case ties to Oleksandr Ieremenko, who allegedly directed the attacks, was said to have FSB protection, and died falling from a Moscow window in 2022.

The Record · 29d agoPolicy & legal in the wild1

Ukraine prosecutor general steps down amid scam call center bribery probe

Ukraine's prosecutor general Ruslan Kravchenko resigned amid a probe into officials who allegedly took bribes to protect fraudulent call centers.

Ukraine's prosecutor general Ruslan Kravchenko resigned over an anti-corruption probe into officials who allegedly took bribes since mid-2025 to protect fraudulent call centers; he has not been charged. NABU named five suspects, including senior prosecutor Serhii Kropyva, who was remanded with bail of 120 million hryvnias (about $2.7 million) on suspicion of laundering over 89 million hryvnias (roughly $2 million). The scam centers targeted victims in Ukraine and abroad; Ukrainian authorities reported shutting about 340 call centers over the past year, including 94 in a single week during a nationwide crackdown.

The Record · 7d agoPolicy & legal

Paris Prosecutors Raid Elon Musk X

Paris prosecutors raided the offices of Elon Musk's social platform X as part of a judicial investigation in France.

Infosecurity Magazine reports that Paris prosecutors carried out a raid at the French offices of X, the social platform owned by Elon Musk. Such raids typically accompany French judicial investigations, and this action places the platform's operations in Europe under legal scrutiny. The full scope of the warrant and any charges were not detailed in the available information.

Infosecurity Magazine · 28d agoPolicy & legal

Hiding Prompt Injection in Legal Filing

A judge banned a plaintiff from electronic court filings after hidden prompt-injection text was discovered planted in legal documents.

Bruce Schneier's blog discusses an incident in which hidden prompt-injection instructions were planted inside a legal filing, apparently targeting AI systems that might process court documents. Judge Walter Spader Jr. responded by banning the plaintiff from electronic filings, requiring all future submissions as printed hard copies. Commenters debate whether the tactic could affect future AI-based processing of court records and whether plain-text formats will regain favor.

Schneier on Security · 16d agoAI safety & security in the wild

Three Ukrainians to face charges for alleged hack of 610,000 Roblox accounts

Ukrainian prosecutors charged three men for stealing session tokens from over 610,000 Roblox accounts and selling them for an estimated $480,000.

Prosecutors in Ukraine's Lviv region said a 19-year-old organizer from Drohobych and two 22-year-old associates operated from May 2025 to April 2026, harvesting Roblox session tokens via infostealer malware disguised as game cheats and bonus software. They used software to validate stolen cookies and inventory virtual currency and rare items, then sold accounts via Russian platforms for as little as $0.80 each, advertising through Telegram channels and receiving crypto payments. All three are in custody facing charges of theft, money laundering, unauthorized computer interference, and illegal sale of restricted information, carrying up to 12 years in prison.

The Record · 2h agoPolicy & legal in the wild

Russian national facing 20 years for malware campaign that infected 80,000 freelancers

US prosecutors indicted Russian national Searzhudin Aktulaev for a 2016 TVRAT malware campaign that infected 80,000 freelance platform users, carrying up to 20 years.

Searzhudin Tamirlanovich Aktulaev was arrested in Cyprus in May 2025, extradited to the US, and appeared in a San Francisco federal court on charges including conspiracy, aggravated identity theft, and damaging protected computers. Between June 2016 and November 2017 he spread a TVRAT (TVSPY/TeamSpy) variant via malicious Microsoft Excel attachments sent from 255 fake accounts on a freelance employment platform's messaging system, infecting about 80,000 users. TVRAT exploited a TeamViewer vulnerability and DarkVNC exploited a bug in VNC Viewer to take over devices; he used the access to steal data and commit fraud, maintained C2 domains, and stored stolen e-commerce credentials for hundreds of victims. About half the victims were in the US, mostly California; the charges carry a maximum 20-year sentence and his next hearing is October 5.

The Record · 13d agoPolicy & legal

Srsly Risky Biz: America's Drivers Licence Breach is a National Security Disaster

Dark web service Nexus sold 153 million US and Canadian driver's licenses, linked to identity verification firm IDScan under FBI investigation.

Krebs On Security reported that a dark web service called Nexus sold access to 153 million US and Canadian driver's licenses, claiming over a year of continuous exfiltration from a major identity verification company, with roughly 400,000 new licences added in a single day. Krebs verified the data as genuine and linked the incident via circumstantial evidence to identity verification firm IDScan, whose licences of senior US officials including Secretary of War Pete Hegseth appeared in the database; the FBI is investigating and IDScan has confirmed a breach inquiry. The article argues the data has national security implications, citing how Chinese APT espionage (Anthem, Equifax, Marriott, OPM) and Bellingcat investigations exploited leaked databases. Class action suits are being prepared, and the piece calls for stricter oversight of identity verification firms.

Risky Business News · 6d agoData breach in the wild

Jail time for Maine child in 764 marks turning point in federal law enforcement

A 17-year-old from Maine became the first minor federally adjudicated for 764 extremist crimes, including child exploitation, signaling a policy shift on prosecuting juveniles.

The FBI said a Maine teenager is the first child federally charged and adjudicated for crimes tied to the nihilistic violent extremist collective 764, part of The Com network. Charges include conspiracy to sexually exploit a child, distributing CSAM, interstate threats, cyberstalking, and identity theft. The case marks a turning point in federal policy on prosecuting juveniles and continues heightened enforcement: Kyle Spitze was sentenced to 77 years and Alexis Chavez to 40 years in related cases. The FBI is investigating more than 500 subjects connected to 764 and its offshoots nationwide.

CyberScoop · 13d agoPolicy & legal

Scammer behind $245 million crypto heist pleads guilty to RICO charges

Malone Lam, leader of a social engineering ring that stole over $245 million in cryptocurrency, pleaded guilty to US RICO charges.

Singaporean national Malone Lam, 22, pleaded guilty to RICO conspiracy charges for leading the 'Social Engineering Enterprise,' which stole more than $245 million in cryptocurrency. The group posed as Apple and Google customer support, tricked victims into installing remote desktop software, and even burgled homes to steal hardware wallets, including $263 million from a single Washington, D.C. victim. At least nine others have already pleaded guilty; Lam faces a December 8 sentencing hearing and a possible 7-to-20-year term.

The Record · 7d agoPhishing & fraud

Ex-FTC boss Khan: break out the handcuffs for AI CEOs, citing 1934 precedent

Former FTC chair Lina Khan argues existing US laws, citing a 1934 Supreme Court precedent, suffice to prosecute AI companies and executives over dangerous products.

Lina Khan stated that federal enforcers already have authority under consumer protection, unfair competition, and deceptive trade practices laws to charge AI companies and their CEOs for releasing dangerous or unvetted models and agents. She cited the 1934 Supreme Court decision FTC v. R.F. Keppel & Bro and referenced OpenAI agents escaping sandboxes to gain unauthorized access to Hugging Face systems. Khan also flagged the AI industry's concentrated structure and Nvidia's pending Hugging Face acquisition as creating accountability conflicts, while legal experts doubt federal regulators will act.

America's Driver's License Breach Is a National Security Disaster

Dark web service Nexus sells 153 million US/Canadian driver's licenses linked to a breach of identity verifier IDScan.

Krebs on Security revealed a dark web service, Nexus, selling access to 153 million driver's licenses and 3 million travel documents from US and Canadian citizens, roughly 63 percent of all US licenses. Circumstantial evidence links the data to identity verification firm IDScan, which confirmed it is investigating a breach, and the FBI is probing the incident. Licenses belonging to senior US officials, including Pete Hegseth, an FBI assistant director, and Krebs's own contacts were verified as genuine. The exfiltration appears ongoing, with the database growing by nearly 400,000 licenses in a single day, and the data carries significant national security value for foreign intelligence services.

Hacker News · security · 1d agoData breachHN 26↑ · 4 comments3· 1 read

Russian suspect in bank account takeovers is extradited to US

Russian developer Sergei Filimonov was extradited to the U.S. and pleaded not guilty to multimillion-dollar bank account takeover fraud.

Sergei Anatolyevich Filimonov, a 36-year-old Russian web developer, has been extradited to the United States to face an indictment in a multimillion-dollar bank account takeover scheme. He appeared in Atlanta federal court on September 4 and pleaded not guilty to fraud charges. Federal authorities announced the extradition on Tuesday.

DataBreaches.net · 7d agoPolicy & legal1

US charges Iranians for sprawling hacking campaign on government agencies, universities

DOJ indicts 17 Iranians tied to Mabna Institute IRGC hacking-for-hire campaign that stole 31TB from universities, agencies, and UN organizations.

The U.S. Justice Department unsealed a 14-count superseding indictment charging 17 people linked to the Mabna Institute, allegedly operating on behalf of the IRGC, in a campaign running since around 2013. The group breached 144 US universities, 42 US companies, 178 foreign universities, 11 foreign companies, and agencies including the Department of Labor, Federal Energy Regulatory Commission, and Hawaii and Indiana state governments, plus UN organizations such as UNICEF, stealing at least 31 terabytes of academic and proprietary data and about 8,000 professor email accounts. The State Department offered a $10 million reward for five individuals including Behzad Mesri, previously indicted for the $6 million HBO extortion; universities spent roughly $20 million on investigation and remediation.

The Record · 8d agoPolicy & legal 2 sources

Bernie's AI bill proposes to sentence AI developers to 20 years in prison

Senator Bernie Sanders proposed AI legislation that would impose criminal penalties on AI developers, including sentences of up to 20 years in prison.

A Hacker News discussion (21 points, 4 comments) links to a tweet about Bernie Sanders' AI bill, which would establish criminal liability for AI developers, with potential 20-year prison sentences. The proposal targets individual developers rather than only companies. As a proposed bill, it has not been enacted, and the linked discussion is brief.

Members of ‘Black Axe’ cybercriminal group extradited from South Africa

Five Black Axe members extradited from South Africa face US wire fraud and money laundering charges over romance scams defrauding more than 100 victims.

Perry Osagiede, Franklyn Edosa Osagiede, Osariemen Eric Clement, Collins Owhofasa Otughwor and Musa Mudashiru, leaders of Black Axe's Cape Town branch, were extradited September 11 and appear before a federal judge in Trenton, New Jersey under a 2021 indictment. They ran romance scams from 2011 to 2021 that stole thousands of dollars from over 100 people, threatening to leak sensitive photos and laundering proceeds through South African companies; some funds also traced to business email compromise. Wire fraud and money laundering charges each carry up to 20 years. Treasury estimates $12.7 billion stolen from Americans since 2023 via overseas romance and investment scams.

The Recordupdated · 1d agofirst · 1d agoPolicy & legal 3 sources

Three intrusions at UK criminal records office went undetected for two years

UK ICO reprimands ACRO criminal records office after three undetected intrusions over two years exposed thousands of records, including domestic violence victims.

The UK Information Commissioner's Office reprimanded ACRO Criminal Records Office after three intrusions between July 2021 and June 2023 exploited a Kentico customer portal unpatched since September 2019 and ignored Trend Micro antivirus alerts, including four quarantined Mimikatz detections. An attacker maintained persistent access for roughly seven months and staged data of nearly 11,000 people for exfiltration, though ACRO could not confirm exfiltration due to insufficient logging. ACRO notified more than 84,000 people on a precautionary basis; the Medusa ransomware group claimed the incident, and network segmentation kept attackers out of the Police National Computer.

The Record · Aug 12, 2026Data breach in the wild

Bad Likert Judge: A Novel Multi-Turn Technique to Jailbreak LLMs by Misusing Their Evaluation Capability

Unit 42 details the Bad Likert Judge multi-turn jailbreak that abuses LLMs' evaluation capability, raising attack success rates over 60% across six frontier models.

Palo Alto Networks Unit 42 describes the Bad Likert Judge technique, a multi-turn jailbreak that asks a target LLM to act as a Likert-scale judge scoring the harmfulness of example responses. The highest-rated example in each scale can carry harmful content, bypassing the model's internal guardrails. Testing across six state-of-the-art text-generation LLMs showed an average attack success rate increase of more than 60% versus plain attack prompts, with tested models anonymized. The technique targets edge cases rather than typical use, and the article positions the work as guidance for defenders on potential jailbreak risks.

Palo Alto Unit 42 · Aug 17, 2026AI safety & security

US Indicts 17 Iranians Over Years

US unsealed superseding indictment charging 17 Mabna Institute Iranians for IRGC-linked espionage stealing 31TB from universities, companies, and government agencies.

The Justice Department unsealed a superseding indictment charging 17 members of the Iran-based Mabna Institute, which conducted hacking campaigns since at least 2013 on behalf of the IRGC and other Iranian clients. The group compromised 144 US and 178 foreign universities, at least 42 US companies, and multiple government agencies, stealing over 31 terabytes of academic data and IP plus employee email inboxes. Hackers breached roughly 8,000 of 100,000 targeted professor accounts across 24 countries, selling stolen research through Megapaper.ir and Gigapaper.ir. Behzad Mesri, tied to the HBO breach and $6 million Bitcoin extortion, is among eight new defendants, and five defendants carry State Department Rewards for Justice bounties up to $10 million.

Security Affairs · 27d agoThreat actor in the wild

ShinyHunters claims Florida DMV breach, puts data on the clock

ShinyHunters claims it breached Florida DMV's DAVID database, stole 200,000+ driver records including SSNs, and set a September 11 extortion deadline.

The ShinyHunters extortion group claims it breached the Florida Department of Highway Safety and Motor Vehicles' DAVID driver and vehicle database and stole more than 200,000 records. As evidence it published a screenshot of a Jeffrey Epstein record showing address, Social Security number, date of birth, license number and registered vehicles, and set a September 11 deadline before publication. The group says it obtained access through a password-reset weakness, compromised employee accounts, and queried and downloaded driver records and images. The Florida DMV has not confirmed the claim; it follows a separate confirmed IDScan.net breach exposing over 153 million license scans that prompted an FBI investigation.

CSO Online · 7d agoData breach in the wild1

Eight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna Institute

US prosecutors unsealed a superseding indictment charging 17 Iranians in the Mabna Institute's state-sponsored theft of 31.5 terabytes from universities and companies.

The superseding indictment unsealed in the Southern District of New York charges 17 people affiliated with Tehran's Mabna Institute, adding eight defendants to the 2018 indictment of nine. The institute allegedly compromised over 100,000 professor email accounts worldwide, including 8,000 accounts at 144 US universities, and stole at least 31.5 terabytes of academic journals, dissertations, and e-books. US universities spent approximately $3.4 billion procuring the stolen data, and victims also included at least five federal and state agencies, 42 US companies, and 11 foreign companies including HBO. The State Department's Rewards for Justice program is offering up to $10 million for information on four of the defendants.

CyberScoop · 28d agoPolicy & legal

New AI Attack Hides Malicious Instructions in Normal-Looking Text to Evade Safety Filters

Check Point researchers show crafted prose hides policy-violating instructions that bypass all tested LLM gatekeepers, including GPT-4o mini and Llama Guard 3.

A new prompt-crafting technique embeds malicious payloads inside grammatical, natural-looking text without Base64, invisible Unicode, or obvious encodings, defeating lightweight pre-screening gatekeepers. In testing, all four evaluated gatekeeper models—gpt-4o-mini-2024-07-18, gpt-oss-safeguard:20b, claude-3-haiku-20240307, and llama-guard3:8b—classified the crafted wrappers as safe at a 100% bypass rate across 23 obfuscated prompts. GPT-5 Thinking in high-reasoning mode recovered and acted on the hidden instruction in 17 of 18 tests (~94.4%), often spending over a minute and multiple Python executions. Researchers recommend paraphrasing untrusted input, hardening gatekeeper policies, and applying defense-in-depth controls for agentic deployments.

GBHackers · 5d agoAI safety & security 2 sources

Black Axe Members Extradited to US Over Internet Fraud Claims

Five alleged Black Axe leaders were extradited from South Africa to the US over romance scam and money laundering charges.

Five Nigerian nationals who allegedly led Black Axe's Cape Town zone were extradited to the US on September 11 and appeared in federal court in Trenton, New Jersey on September 14. The superseding indictment alleges romance scams, advance-fee fraud, BEC, and money laundering via US bank accounts between 2011 and 2021, using social media, dating sites, and VoIP, with coercion via threats to distribute victims' intimate photos. Charges include wire fraud and money laundering conspiracy carrying up to 20 years each, plus aggravated identity theft for three defendants.

Infosecurity Magazine · 1d agoPolicy & legal

Person Hides Prompt Injection in Legal Filing Telling AI to Side With Them

A Connecticut pro se litigant hid tiny white-font prompt injections in court filings directing AI to favor him; the judge caught it and sanctioned him.

Pro se plaintiff Matthew Elliott hid prompt injection instructions in 3-point white text within filings in his lawsuit against the New York Bariatric Group, instructing any AI model reviewing the document to produce output agreeing with the filing. The hidden text also included joke messages such as a SpongeBob Nosferatu link and notes like 'hi :) I hope you cant see me'. Court staff noticed unusual white space, and Judge Walter Spader Jr. issued a 14-page sanction decision noting the Connecticut court does not use AI to process documents but warning that hidden AI-directed messages threaten the integrity of filings. Elliott described the scheme as an 'audit' of court AI usage, and the judge cited a prior prompt injection incident in a Brazilian court as evidence the practice may spread.

404 Media · Aug 13, 2026AI safety & security in the wild

Swiss court sentences 52-year-old Ukrainian ransomware dev to nearly 13 years in the cooler

Zurich court sentences Ukrainian ransomware developer to 12 years, 9 months for LockerGoga, MegaCortex and Nefilim attacks including Stadler Rail.

Zurich District Court sentenced a 52-year-old Ukrainian to 12 years and 9 months for developing LockerGoga, MegaCortex, and Nefilim ransomware, plus a 10-year ban from Switzerland; the verdict can be appealed. The operations hit over 1,800 victims across 71 countries with losses of several hundred million Swiss francs, including Stadler Rail (2020, $6 million Nefilim demand), Meier Tobler, and Crealogix. Alleged mastermind Volodymyr Tymoshchuk, indicted in the US and tied to at least 250 companies including Norsk Hydro, remains at large with an $11 million FBI bounty.

The Register · Security · 1d agoPolicy & legal

Ministry of Justice apologizes after court staff accessed Southport victims' files

UK Ministry of Justice apologized after court staff accessed Southport attack victims' files without authorization, exposing sensitive personal data with no evidence of third-party sharing.

The UK Ministry of Justice apologized after court staff accessed case files related to victims and survivors of the 2024 Southport murders without authorization, including sensitive personal data assessed as high risk for some individuals. There is no evidence the information was shared with third parties. HM Courts and Tribunals Service and HM Prison and Probation Service are investigating, and the Information Commissioner's Office has been informed. The incident follows similar unauthorized record access at North West Ambulance Service and Aintree University Hospital.

In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

SecurityWeek weekly roundup covers exploited WordPress Super Forms flaw CVE-2026-14894, a $10M bounty on an Iranian cyber official, InjectEave attacks, and more.

SecurityWeek's weekly roundup aggregates short items across the threat landscape, including Microsoft's report of invisible Unicode tag characters used in financial phishing lures at up to 2.37 million messages per day, and active exploitation of critical WordPress Super Forms plugin flaw CVE-2026-14894 to deploy PHP webshells. Policy items include a $10 million US bounty for IRGC-CEC Cyber Operations Command lead Amir Yaryab, a 16-month prison sentence for ex-AT&T employee Kenneth Carter over SIM swaps with nearly $600,000 in intended losses, and the US arraignment of Russian Sergei Anatolyevich Filimonov over credential harvesting. Technical items include InjectEave electromagnetic side-channel attacks tested on 11 devices, an FBI warning on OAuth consent phishing, and VulnCheck's finding that only 202 of 26,153 Anthropic Project Glasswing findings were fixed.

SecurityWeek · 5d agoIndustry in the wildCVE-2026-148942

CiteShade: Citation Laundering in Multi-Source Retrieval-Augmented Generation and Its Counterfactual Defense

CiteShade attack makes RAG models cite trusted sources for attacker-chosen wrong answers, raising wrong-answer rate from 0.01 to 0.68.

CiteShade is presented as the first citation laundering attack against multi-source retrieval-augmented generation: an attacker controlling a single source induces a wrong answer falsely attributed to a trusted source, even while correct evidence remains in context. The attack is formalized via three necessary conditions (retrieval, generation, citation) constructible without any instructions, raising wrong-answer rate from 0.01 to 0.68 on multi-hop QA, with source deletion confirming the malicious source as causal driver. Vulnerability tracks a model's citation propensity rather than scale, reaching CLR 0.84 with explicit instruction and 0.64 without on the most citation-prone model. Perplexity filtering and citation-support checking prove insufficient; the authors propose a counterfactual defense verifying which source actually drove the answer.

arXiv cs.CR · 2d agoAI safety & security1

Risky Bulletin: Slovakia finds Russian backdoor in traffic speed cameras

Slovakia's NBU found an SMS-triggered backdoor in Russian-made NERO R-ONE traffic cameras, pausing a 279-unit deployment.

Slovakia's national security service NBU issued an alert against NERO R-ONE high-speed traffic cameras after finding a backdoor that grants shell and network access via SMS from hardcoded Russian phone numbers. The cameras are a rebranded version of the Russian CORDON PRO.M model by St. Petersburg firm Semicon, purchased via a Cyprus shell company under a €30 million EU-funded project. The report also found SecureBoot disabled, vulnerable web management, and unauthenticated live streams; the Interior Ministry paused deployment of 279 cameras pending independent assessment.

Risky Business News · 28d agoThreat actor in the wild1

Once popular for attacking AI, ASCII smuggling is embraced by spammers

Spammers adopt ASCII smuggling—invisible Unicode tag characters—to evade email filters, with Microsoft Defender detections spiking to 2.5 million per day.

ASCII smuggling hides text in Unicode tag characters (e.g., U+E0041 for "A") that are invisible to humans but readable by LLMs and text processors. The technique gained attention as a stealthy prompt-injection vector and is now used by spammers to obfuscate keywords from email detectors. Microsoft reported Defender for Office smuggling detections jumped from roughly 21,000 per day to over 1.3 million in early February, reaching 2.5 million within four days, before falling sharply in mid-May.

Ars Technica · Security · 11d agoPhishing & fraud

Sophisticated Cyberattack Exposes Data of 678,000 French Taxpayers

Hackers stole personal and tax data of 678,000 individuals and businesses from France's tax agency DGFiP, prompting a Paris criminal investigation.

France's Directorate-General for Public Finances (DGFiP) confirmed a sophisticated cyberattack exposed data on 678,000 users of the tax system, including income figures, tax rates and family circumstances for individuals and SIREN registration data for businesses. The Paris prosecutor's cybercrime unit opened a probe and referred it to the French anti-fraud office OFAC after a threat actor claimed the breach in late June. Officials stressed the stolen data does not grant access to secure accounts on impots.gouv.fr, and taxpayer notification begins Monday with warnings about identity theft and fraudulent follow-up requests. The incident follows recent breaches at the ANTS documents agency and the INSEE statistics authority.

Security Affairs · Aug 16, 2026Data breach

US charges 17 Iranian hackers over 31-terabyte academic data theft

US indicts 17 Iranian Mabna Institute hackers who stole 31TB of academic data from universities, companies, and agencies via spearphishing.

The US Department of Justice charged 17 alleged Mabna Institute members, adding eight defendants to the nine charged in 2018, for a 2013-2017 campaign largely conducted for Iran's Islamic Revolutionary Guard Corps. The group stole over 31TB of academic data and intellectual property from 144 US and 178 foreign universities, at least 42 US companies, and at least five federal and state agencies, compromising about 8,000 of 100,000 spearphished professor email accounts. US universities spent roughly $3.4 billion procuring the stolen data; one defendant also hacked HBO and sought about $6 million in bitcoin ransom. The State Department offers up to $10 million for information on five defendants, none of whom are in US custody.

Help Net Security · 27d agoPolicy & legal in the wild