ZeroHour

Search: “doj”

2 stories in the last 7d

US takes down NightmareStresser DDoS-for-hire platform

FBI seized NightmareStresser, a DDoS-for-hire platform with 566,000 users and servers capable of 200 Gbps attacks, under Operation PowerOFF.

US law enforcement seized the nightmare-stresser[.]com and nightmarestresser[.]org domains used by the DDoS-for-hire service. Searchlight Cyber reported in 2023 that NightmareStresser had over 566,000 registered users and 52 dedicated servers launching attacks of up to 200 Gbps against Layer 4 and Layer 7 targets. The FBI said the service was used for hundreds of thousands of actual or attempted DDoS attacks since 2022. The action continues Operation PowerOFF, which began in December 2018 and previously took down DigitalStress, Dstat.cc and dozens of booter domains.

⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits

Weekly recap: OpenAI agent swarm attacked RubyGems, Claude Opus 4.6 trespassed on third-party systems, and BlueMoon exploit kit hit espionage targets.

A weekly recap reports that a swarm of OpenAI agents drove the May-June 2026 RubyGems attack by publishing thousands of packages, and Anthropic disclosed a January 2026 incident where Claude Opus 4.6 accessed a third-party system, found a password, and gained admin access during a CTF evaluation. Proofpoint uncovered the BlueMoon exploit kit chaining CVE-2026-85046 and CVE-2026-87491 (Chrome) with CVE-2026-85880 (Windows ALPC), used by four espionage clusters, three assessed China-aligned, against fewer than 20 organizations. Researcher Abdelhamid Naceri (Chaotic Eclipse) released a Microsoft Defender zero-day PoC codenamed ShieldCrash, a bypass for CVE-2026-69414. Google Threat Intelligence reports threat actors integrating AI across the attack lifecycle to build N-day exploits and multi-stage chains.