ZeroHour

Search: “reflection”

11 stories in the last 30d

UK account-hack losses surge as new reporting system exposes hidden cases

UK reported account-hack losses rose 417% to £6.3M in 2025-26, largely because the new Report Fraud system is capturing previously hidden cases.

The City of London Police's first annual assessment reported £6.3 million in losses from hacked accounts in the year ending March 31, up from £1.2 million, with victims rising from 226 to 2,325. The surge coincides with the January launch of Report Fraud, which replaced Action Fraud; 92% of account-hack reports with financial loss were recorded in the second half of the year. Cyber-dependent crime reports rose 34% to 64,608 while ransomware reports fell 25% to 323, which police warn may reflect underreporting.

The Record · 12d agoPolicy & legal

FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching

FBI officials said AI is accelerating adversary capabilities while its new cyber strategy emphasizes continuous patching, cyber hygiene, and AI-enabled defense.

At the Billington CyberSecurity Summit and ahead of a new FBI cyber strategy, deputy assistant director Jason Bilnoski said AI is boosting the speed and capability of both criminal and nation-state attackers, while stressing that basic controls like MFA would still prevent most attacks. Colleen Ferranti urged a shift from quarterly Patch Tuesday cycles to continuous, risk-based patching as AI accelerates vulnerability discovery. The strategy pledges AI-enabled triage, malware analysis, attribution support, agentic AI adoption, expanded Computer Network Operations, ICS Coordinators in every field office, and a pledge on victim relief and privacy.

CyberScoop · 8d agoPolicy & legal

Australia is replacing the Essential Eight with a new cyber framework. Here’s how exposure management can help you get ahead of it.

Australia's ASD is replacing the Essential Eight with an outcomes-based Essentials series covering IT, cloud, OT and likely agentic AI, with deprecation from mid-2027.

The Australian Signals Directorate announced in June 2026 that the Essential Eight will be replaced by an outcomes-focused Essentials series structured as chapters covering enterprise IT (including identity and SaaS), cloud, OT, and likely agentic AI. Deprecation begins around mid-2027 with full retirement around mid-2028, though timelines are targets; the Essential Eight is mandatory for roughly 98 non-corporate Commonwealth entities but voluntary for private firms. Tenable argues the shift demands continuous security posture evidence via exposure management rather than point-in-time checklist assessments.

Tenable Blog · 2d agoPolicy & legal1

Five alleged leaders of Black Axe’s operations in South Africa extradited to US

US extradited five alleged Black Axe Cape Town leaders from South Africa to face romance-scam wire fraud and money laundering charges.

The Justice Department announced five alleged leaders of Black Axe's South African wing, all Nigerian nationals, were extradited to the US over romance and advance-fee scams run from at least 2011 until their 2021 arrests in South Africa. Prosecutors say the group used fake identities and threatened to expose victims' sensitive photos, with charges including wire fraud, money laundering, and aggravated identity theft carrying up to 62 years. The extradition follows recent multi-country stings arresting dozens of Black Axe members, including 34 arrests in Spain.

CyberScoopupdated · 2d agofirst · 2d agoPolicy & legal 3 sources

Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal

A new DOT rule exempts airlines from providing meal vouchers or hotels for cyberattack-caused delays if carriers comply with applicable cybersecurity regulations.

A Department of Transportation rule published in September 2026 adds "cybersecurity attacks" to a list of 10 "not controllable" flight disruption causes, creating a new delay tracking category and relieving compliant airlines of customer service obligations like meal vouchers and hotels. The rule stems from the FAA Reauthorization Act of 2024 and applies only when carriers demonstrate compliance with applicable cybersecurity regulations. Consumer groups reacted cautiously: FlyersRights criticized the lack of public comment, while the National Consumers League saw both certainty benefits and risks from ambiguous wording. The article cites prior aviation incidents including Scattered Spider's airline attacks and the 2024 Collins Aerospace hack that disrupted European flights.

CyberScoop · 5d agoPolicy & legal

Conti ransomware crew member sentenced to four years in prison

Ukrainian national Oleksii Lytvynenko sentenced to four years in the US for his role in Conti ransomware attacks on at least 12 companies.

Oleksii Lytvynenko, 44, who pleaded guilty in June to conspiracy to commit wire fraud, was sentenced Thursday to four years in prison by the US Justice Department. He joined the Conti ransomware group in September 2021 as an intruder and malware developer, holding stolen data from 12 victims including eight US-based organizations, and prosecutors said co-conspirators extorted roughly $634,000 in Bitcoin from Tennessee victims including government entities. Conti attacked more than 1,000 organizations before disbanding in 2022, with members rebranding into Zeon, Black Basta, and Quantum/Royal/BlackSuit.

CyberScoopupdated · 5d agofirst · 6d agoPolicy & legal 7 sources1

FCC proposes public scorecard to rate telecoms on anti-robocall efforts

The FCC proposed a public scorecard rating telecoms' anti-robocall effectiveness and removed 14 providers from US networks for compliance failures.

The Federal Communications Commission issued a public notice proposing a scorecard that would assess how effectively retail voice providers, including wireless, wireline and VoIP, prevent illegal robocalls, drawing on Robocall Mitigation Database filings, consumer complaint and enforcement data. The agency stressed it is not a rulemaking imposing new requirements, and it is seeking comment on scope, such as whether to focus on larger providers. The same day, the FCC removed 14 providers from the Robocall Mitigation Database for non-compliance, effectively requiring other US providers to block their traffic within two days.

CyberScoop · 14d agoPolicy & legal

‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help

White House launches Watershed 250, a six-month Texas pilot using volunteer vendor cyber and AI tools to harden water utility defenses.

The Office of the National Cyber Director and Texas Cyber Command will oversee the six-month Project Watershed 250 pilot to improve water sector cybersecurity through industry-donated red teaming, system hardening and AI tooling. Twelve companies including Microsoft, Fortinet, Google Cloud, Palo Alto Networks, AWS, Cloudflare, Zscaler, Forescout, Abnormal AI and Dragos participated in the rollout. Officials cited recent attacks including an Iranian-backed campaign against 30 water systems in 12 states and a 2024 incident in Muleshoe, Texas. Some water-security professionals criticized the program as lacking dedicated funding.

CyberScoop · 16d agoPolicy & legal1

Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks

Australian Federal Police charges two men with 14 offences over TeamPCP supply chain backdoors in Trivy, Checkmarx KICS, and LiteLLM affecting 1,000+ organizations.

The Australian Federal Police charged two Western Australian men, aged 21 and 23, with 14 offences for their alleged principal roles in TeamPCP's March 2026 supply chain attacks; they appeared in Perth Magistrates Court on August 27, 2026. The group stole publishing credentials from trusted open-source projects and pushed poisoned releases across five ecosystems - GitHub Actions, Docker Hub, npm, PyPI, and OpenVSX - with LiteLLM's unpinned Trivy install enabling token theft and backdoored LiteLLM releases. The FBI said the malicious code potentially compromised more than 1,000 organizations, enabled theft of over 500,000 credentials, and exfiltrated at least 300 GB of data. Oligo Security linked the group's infrastructure to activity back to 2020, previously tracked as TA-NATALSTATUS and IronErn.

The Hacker News · 21d agoPolicy & legal in the wild1

Risky Bulletin: Russia starts blocking DoH and DoT

Russian users report blocks on DoH and DoT servers, including Cloudflare 1.1.1.1 and Google 8.8.8.8, in an apparent censorship crackdown.

Russian internet users began reporting failures connecting to DNS-over-HTTPS and DNS-over-TLS servers, suggesting a government crackdown on the two privacy protocols. The blocks reportedly cover Cloudflare's 1.1.1.1 and Google's 8.8.8.8 resolvers; Roskomnadzor has not officially confirmed the action. The agency tested a similar block in March on Beeline's network and had named DoH for blocking as early as 2021. The bulletin also briefly notes state-sponsored phishing of EU officials, a DDoS against Norway's Digdir, the ReliaQuest/ShinyHunters dispute, and older ransomware and breach disclosures.

Risky Business News · 22d agoPolicy & legal1

TikTok Settles U.S. Child Privacy Case for $400 Million

TikTok will pay $400 million to settle U.S. DOJ/FTC claims that it violated COPPA by collecting data from children under 13.

The U.S. Department of Justice announced a $400 million settlement with TikTok and ByteDance resolving a 2024 lawsuit over violations of the Children's Online Privacy Protection Act (COPPA). TikTok will pay $300 million immediately and $100 million upon entry of an order vacating a prior consent decree against its predecessor Musical.ly; it is one of the largest recoveries ever obtained in a COPPA case. The DOJ and FTC, filing in California, alleged TikTok knowingly allowed children under 13 to create accounts and illegally collected data via Kids Mode. TikTok was previously fined €345 million by Ireland's Data Protection Commission in 2023 for GDPR breaches involving children's data.

Security Affairs · 24d agoPolicy & legal