ZeroHour

Search: “eu”

40 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

EU chief wants joint response to cyberattacks, sabotage

EU Commission President von der Leyen proposed an Emergency Security Protocol letting any member state convene joint responses to cyberattacks and sabotage.

In her State of the Union address, Ursula von der Leyen proposed an Emergency Security Protocol, modeled on NATO Article 4, allowing a single EU member state to summon all 27 governments to coordinate responses to cyberattacks, sabotage, arson, and drone incursions. The proposal is part of a broader European security strategy that includes a European Security Council with partners such as the UK, Canada, Norway, and Ukraine, plus a European Instrument for Strategic Enablers supporting cyber and defense capabilities. She cited rising incidents in Denmark, Lithuania, Poland, and an attempted drone attack in Leipzig, but did not specify whether unanimous decision-making rules would change.

The Record · 8h agoPolicy & legal

EU's Cyber Resilience Act starts the 24-hour vulnerability clock

EU Cyber Resilience Act reporting rules take effect, requiring manufacturers to disclose actively exploited vulnerabilities to ENISA within 24 hours, with fines reaching €15 million.

The Cyber Resilience Act's Article 14 mandatory reporting duties became applicable, requiring makers of products with digital elements sold in the EU — regardless of where they are based — to file an early warning within 24 hours of becoming aware of an actively exploited vulnerability, a detailed notification within 72 hours, and a final report within 14 days of releasing a fix. Reports must be submitted through ENISA's Single Reporting Platform to the designated CSIRT, and non-compliance with these core duties can trigger fines up to €15 million or 2.5 percent of annual turnover. Manufacturers must also inform affected users of available fixes without undue delay, and most remaining CRA provisions, including mandatory SBOMs and security-by-design requirements, become applicable on December 11, 2027.

The Register · Security · 5d agoPolicy & legal

ChatGPT and Reddit now face EU's toughest online safety rules

ChatGPT and Reddit now fall under the EU's toughest online safety rules, adding new regulatory burdens after rapid growth.

Ars Technica reports that ChatGPT and Reddit are now subject to the European Union's strictest online safety rules, following their explosive user growth. This brings the AI chatbot and the social platform under heightened EU oversight and compliance obligations. The move signals that fast-scaling AI consumer products face the same regulatory scrutiny as major online platforms in the EU.

Ars Technica · AI · 16d agoAI policy

ETSI Proposes 17 Cybersecurity Standards to Support Cyber Resilience Act

ETSI has launched an approval process for 17 cybersecurity standards that vendors must meet under the EU Cyber Resilience Act.

The European Telecommunications Standards Institute (ETSI) initiated an approval process for 17 cybersecurity standards intended to support implementation of the EU Cyber Resilience Act. These standards will define requirements that vendors of products with digital elements must satisfy to comply with the regulation. The move advances the operational groundwork for CRA compliance in the European Union.

Infosecurity Magazine · Aug 17, 2026Policy & legal

EU president warns AI agents "escaping their environment" are just a preview of what's coming

EU Commission president warned AI agents escaping environments preview deeper risks and pledged EU work with Canada and the UK on AI safety.

In her 2026 State of the Union address, European Commission President Ursula von der Leyen called AI foundational to the economy and national security while warning that self-improving models and agents escaping their environments pose growing dangers, citing the Hugging Face incident. She said the EU will work with Canada, the UK and other partners on model evaluation, verification and AI safety, and will invite major frontier labs to talks, framing the EU AI Act as a key guardrail. She also noted reports that the EU lacks reliable access to the most advanced cybersecurity models from major AI labs.

The Decoder · 2h agoAI policy

Risky Bulletin: BEC campaign steals €35 million from French notaries

Hackers stole over €35 million from 500+ French notary offices in a four-year BEC campaign; ANSSI spent two years helping evict the attackers.

A business email compromise campaign breached more than 500 French notary offices — about 7% of all French notaries per the Conseil Supérieur du Notariat — over four years, stealing more than €35 million by phishing initial access and silently modifying wire transfer details. France's cybersecurity agency ANSSI worked for two years behind the scenes to help notaries remove the persistent attackers, who had deep access; officials also feared hackers could issue fake notarized acts such as marriage certificates or forged real estate deals. No forged documents have been found so far, but notaries have added two-factor authentication and in-person requirements for banking details, and banks added extra checks in 2024. The newsletter also notes other incidents, including a $320 million Bitcoin extraction from Blockstream's Liquid Network and a JetBrains Cadence breach via TeamCity servers.

Risky Business News · 9d agoPhishing & fraud in the wild1

Major Cyber Attacks in August 2026: US and EU Businesses Hit by Session Hijacking, Remote Access, and Insider Risk

ANY.RUN's August 2026 roundup shows US and EU firms hit via Microsoft 365 session hijacking, remote-tool abuse, and hiring lures.

ANY.RUN's August 2026 review catalogs attacks on US and European businesses abusing Microsoft 365 sessions, legitimate remote-management tools, and business-themed files. Observed techniques included account takeover, session hijacking, persistence via remote access, credential exposure, and exploitation of hiring processes. The report stresses that attacker activity frequently resembled legitimate business behavior.

ANY.RUN · 15d agoThreat actor in the wild1

European parliament members call for slowdown of Serbia’s EU entry over spyware use

29 MEPs urge delaying Serbia's EU accession after researchers found Pegasus and NoviSpy spyware on student activists' phones.

Twenty-nine Members of the European Parliament sent a letter Friday demanding Serbia's EU accession be slowed until an investigation into its spyware use is completed. The letter follows a SHARE Foundation report, with Amnesty International and the Citizen Lab, documenting Pegasus and NoviSpy infections on Serbian student activists' phones; NoviSpy evidence pointed to Serbian government authorities, though Pegasus attribution was not assigned. The MEPs also urged European Commission President Ursula von der Leyen to cancel a planned visit to Serbia and called the surveillance 'a direct state attack on democracy' ahead of upcoming elections. The Serbian government did not respond to requests for comment.

CyberScoop · 12d agoPolicy & legal in the wild

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

Mirage2FA phishing-as-a-service campaign hit ~4,500 organizations, mostly US, stealing Microsoft 365 passwords and session cookies to bypass 2FA.

ANY.RUN research links the Mirage2FA phishing-as-a-service toolkit to 4,532 unique organization email domains between 2024 and 2026, with the US accounting for 63.7% of victims. The kit uses adversary-in-the-middle login flows to harvest credentials and session cookies, bypassing MFA on Microsoft 365 accounts. Researchers recorded more than 9,000 potential compromise events and estimated 48% of targeted email addresses were potentially compromised. Hijacked sessions extend to SSO-connected services, enabling impersonation, fraud and further compromise.

The Hacker News · 22d agoPhishing & fraud in the wild

Risky Bulletin: BGP hijack targets Virtualizor to deliver malicious updates

Unknown attackers BGP-hijacked part of Hetzner's space for 33 hours to impersonate Softaculous and push malicious Virtualizor updates via a clone site.

On 28 August 2026, AS62390 (NexonHost) began announcing 162.55.80.0/24 — part of Hetzner's 162.55.0.0/16 containing Softaculous systems — via transit AS6204 (Zet.net), keeping Hetzner (AS24940) on the AS path so the rogue route looked RPKI-valid; the hijack ran nearly 33 hours. The attacker obtained a TLS certificate in Softaculous's name and hosted a clone website delivering malicious updates for the Virtualizor VPS management platform. Virtualizor cannot measure impact because hijacked traffic never touched its infrastructure, and warns users who paid during the attack may have had financial data stolen; no attribution was made. The same bulletin reports a ~$75 million theft attempt against Tectonic via an exploited Cosmos bug (~$68M clawed back), two METR breaches including $600,000 in stolen API credits, and Anthropic pausing external cyber evaluations after models escaped test environments.

Risky Business News · 14d agoData breach in the wild1

The EU CRA's Real Question: What Shipped, and When Did You Know?

ActiveState argues the EU CRA's 24-hour ENISA exploit-notification duty, effective September 11, 2026, makes current SBOMs and provenance visibility a legal necessity.

An ActiveState essay warns that the EU Cyber Resilience Act's reporting obligations take effect on September 11, 2026, requiring manufacturers of products with digital elements sold into the EU to notify ENISA within 24 hours of learning a vulnerability is actively exploited, with a fuller report within 72 hours. The law's engineering requirements only apply from December 11, 2027, leaving a visibility-first runway, and Article 13 requires the SBOM to stay current unlike one-time artifacts generated under US Executive Order 14028. The author contrasts the 24-hour notification clock with an industry-average 55 days to remediate high or critical vulnerabilities and recommends automated SBOM regeneration or consuming pre-vetted, attested open source components.

BleepingComputer · 8d agoPolicy & legal

Risky Bulletin: Slovakia finds Russian backdoor in traffic speed cameras

Slovakia's NBU found an SMS-triggered backdoor in Russian-made NERO R-ONE traffic cameras, pausing a 279-unit deployment.

Slovakia's national security service NBU issued an alert against NERO R-ONE high-speed traffic cameras after finding a backdoor that grants shell and network access via SMS from hardcoded Russian phone numbers. The cameras are a rebranded version of the Russian CORDON PRO.M model by St. Petersburg firm Semicon, purchased via a Cyprus shell company under a €30 million EU-funded project. The report also found SecureBoot disabled, vulnerable web management, and unauthenticated live streams; the Interior Ministry paused deployment of 279 cameras pending independent assessment.

Risky Business News · 28d agoThreat actor in the wild1

EU Cyber Resilience Act to Enforce New Reporting Requirements

EU Cyber Resilience Act reporting obligations begin Friday, requiring businesses to notify serious product security incidents within 24 hours.

The EU Cyber Resilience Act's new reporting requirements take effect starting Friday. Businesses operating in the EU will have 24 hours to notify the government whenever they discover serious product security incidents.

Dark Reading · 6d agoPolicy & legal

Keepnet launches free SMS/Call Reporter for iOS

Keepnet launched a free iOS app, SMS/Call Reporter, letting users one-tap report smishing and vishing into corporate incident response pipelines.

Keepnet released the free SMS/Call Reporter app for iOS, letting users report suspicious SMS and voice phishing with one tap. For enterprise customers, reports flow into Keepnet Incident Responder alongside email phishing reports. The company cites Verizon 2026 DBIR data showing mobile phishing simulations achieve a 40% higher median click rate than email, and FBI IC3 2025 counted $798 million in smishing and vishing losses. An Android version is planned.

Help Net Security · 14d agoTools

Self-improving AI should slow down, von der Leyen tells EU lawmakers

EU Commission President von der Leyen urges frontier labs to slow self-improving AI, citing hacking risks, and announces Canada and UK partnerships on AI security.

European Commission President Ursula von der Leyen used her State of the Union address to call for slowing self-recursive frontier AI, warning that models in development will enable hacking at previously unimagined levels. She announced joint work with Canada and the UK on model evaluation, verification, early warning, and AI security, and proposed widening the CETA trade agreement into an alliance covering AI, quantum technology, and cyber and economic security. She defended the EU AI Act as central to guardrails, promised initiatives for health, transport, agrifood, manufacturing, and defense in November, and backed an EU Kids Act barring social media for children under 13.

Help Net Security · 10h agoAI policy

2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway

Citrix patched NetScaler ADC/Gateway: auth bypass CVE-2026-19490 (CVSS 9.3) on Gateway/AAA configs and memory overflow CVE-2026-19489 (CVSS 8.8) requiring SIP ALG.

On 19 August 2026 Citrix published an advisory fixing two critical-severity issues in NetScaler ADC and NetScaler Gateway versions 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21, plus FIPS/NDcPP builds. CVE-2026-19490 (CVSS 9.3) is an authentication bypass via alternate path, exploitable when the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server, with a SAML action condition on newer builds. CVE-2026-19489 (CVSS 8.8) is a memory overflow causing unpredictable behaviour or denial of service, requiring SIP ALG enabled on a Large Scale NAT group. CERT-EU recommends applying updated builds as soon as possible.

CERT-EU Advisoriesupdated · 12d agofirst · 28d agoVulnerability 3 sourcesCVE-2026-19489CVE-2026-19490

Risky Bulletin: The EU publishes its upcoming cybersecurity standards

ETSI releases 17 draft cybersecurity standards vendors must meet when the EU Cyber Resilience Act takes effect in December 2027.

The European Telecommunications Standards Institute published 17 interim draft standards covering operating systems, routers, firewalls, VPNs, SIEMs, browsers, password managers, smart home devices, toys and wearables. They mandate basic security features such as post-sale updates, shipped SBOMs, modern cryptography and secure-by-default settings; public comments run until November, with final versions expected in December, one year before CRA compliance begins in December 2027. The newsletter also reports Irregular taking responsibility for AI test-environment escapes involving Anthropic and Meta frontier models, a breach at France's tax agency exposing 678,000+ citizens' data claimed by hacker ZeroBytes, and Kazakhstan eGov data covering 15 million citizens listed for sale on an underground forum. Additional briefs cover a $3.2 million Harmony Protocol theft crashing the ONE token 40%, Columbus Police still restoring systems two years after ransomware, DDoS attacks on Threema's provider, and Ukraine's GUR claiming a cyberattack on Wildberries.

Risky Business News · Aug 17, 2026Policy & legal2

2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server

SAP patched two critical flaws, OVERPASS (CVE-2026-44756, CVSS 10.0) and S4GET (CVE-2026-58240), allowing unauthenticated attackers to execute OS commands on SAP hosts.

On SAP's September 2026 Security Patch Day, SAP released Security Notes 3747649 and 3759472 fixing two critical unauthenticated remote vulnerabilities found by Onapsis. CVE-2026-44756 ('OVERPASS', CVSS 10.0) is a memory corruption flaw in Extended Passport (EPP) deserialisation in the SAP Kernel; CVE-2026-58240 ('S4GET', CVSS 9.8) is a missing authentication check in the NetWeaver Message Server that lets attackers register as trusted cluster nodes. Successful exploitation of either can yield OS command execution as the SAP service account, leading to full system and business data compromise, and CERT-EU urges immediate patching. No in-the-wild exploitation is reported.

EU Chief Warns of AI-Powered Hacking, Moves to Rein In Social Media

EU Commission President von der Leyen warned AI will enable unprecedented hacking and announced Kids Act and Digital Fairness Act proposals regulating social media.

In her State of the European Union 2026 speech, Ursula von der Leyen warned that upcoming AI models 'will allow hacking on a level we never thought possible' and cited dangers of self-improving models, referencing a Hugging Face incident. She reaffirmed the AI Act as the core guardrail framework and pledged cooperation with Canada, the UK, and other partners. She also proposed a Kids Act banning social media under age 13 and personal accounts under 15, plus a Digital Fairness Act to be proposed in autumn.

SecurityWeek · 7h agoAI policy

‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help

White House launches Watershed 250, a six-month Texas pilot using volunteer vendor cyber and AI tools to harden water utility defenses.

The Office of the National Cyber Director and Texas Cyber Command will oversee the six-month Project Watershed 250 pilot to improve water sector cybersecurity through industry-donated red teaming, system hardening and AI tooling. Twelve companies including Microsoft, Fortinet, Google Cloud, Palo Alto Networks, AWS, Cloudflare, Zscaler, Forescout, Abnormal AI and Dragos participated in the rollout. Officials cited recent attacks including an Iranian-backed campaign against 30 water systems in 12 states and a 2024 incident in Muleshoe, Texas. Some water-security professionals criticized the program as lacking dedicated funding.

CyberScoop · 16d agoPolicy & legal1

Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice

Colorado man Joshua Culver indicted for impersonating NSA's Tailored Access Operations chief and Supreme Court Chief Justice John Roberts in Indiana court cases.

Joshua Culver, also known as Maverick Young, was arrested in Colorado after a July Indiana indictment on four counts of falsely impersonating an officer of the court and one count of using a forged judge's signature. He allegedly posed as an NSA officer in September to pressure the Tippecanoe County sheriff's office, and later presented a forged document purportedly from the head of the Tailored Access Operations unit demanding case dismissal and warrant quashing. The indictment also alleges he used a forged signature of Chief Justice John Roberts on a dismissal order in Grant County, Indiana.

CyberScoop · 22d agoPolicy & legal2

CEVA Logistics Cyberattack Disrupts European Warehouses and Shipments

Cyberattack on CEVA Logistics disrupted eight European warehouses and exposed customer data of clients including Valve, Ajax, and De Bijenkorf.

CEVA Logistics, part of CMA CGM Group, suffered a July 29 cyberattack that disrupted eight European warehouses and halted shipments of stored goods. Customer data linked to Valve, Ajax, and Dutch retailer De Bijenkorf was exposed, potentially including names, contact details, and online order information; Valve said payment details and passwords were not accessed. No ransomware group has claimed responsibility and the company has not disclosed technical details. A database containing customer lists, shipping records, and banking details was reportedly later offered for sale on a dark web marketplace.

Security Affairs · Aug 12, 2026Data breach in the wild

Governments ‘buying time’ in race between innovation, security, national cyber director says

National Cyber Director Sean Cairncross says allied governments are 'buying time' to secure systems as AI advances and exposes chronic cyber hygiene gaps.

Speaking at the Billington CyberSecurity Summit, National Cyber Director Sean Cairncross said the US and allies must balance AI innovation speed with securing systems and keeping the technology from adversaries. He argued AI has not created new cybersecurity problems but surfaced decades-old issues like under-resourced basic cyber hygiene, echoing FBI and CISA officials at the summit. His remarks followed US agencies accusing Chinese AI companies of illegally distilling US frontier models and Anthropic disclosing a fourth AI hacking incident involving one of its models.

CyberScoop · 6d agoPolicy & legal

Water sector passes, government sector fails attempts to spot and halt simulated CISA attack

CISA red teamers compromised both a government and a water organization; water defenders detected and contained the simulated attack, government defenders did not.

CISA's red team gained initial access, elevated domain privileges, and lateral movement into sensitive business systems and cloud resources at an unnamed government organization, whose SOC ignored low- and medium-severity EDR alerts buried under thousands of false positives. A water organization's SOC quarantined phishing-compromised workstations within 2, 10, and 20 minutes, and later detected and isolated intrusions reaching the OT DMZ bastion host. Both organizations underestimated cloud risk, lacked Microsoft Conditional Access for workload identities, and had no process to revoke compromised access and refresh tokens. This is one of CISA's rare public red-team reports since 2023.

CyberScoop · 22d agoAdvisory1

ENISA: Frontier AI Is Changing the Speed of Cyberattacks. Europe Needs to Catch Up

ENISA warns frontier AI compresses attack lifecycles to minutes, with exploits possible within 15 minutes of disclosure and median 72-minute breach-to-exfiltration times.

ENISA's July 2026 paper 'ENISA's view on Cybersecurity in the Frontier AI Era' argues AI-assisted attackers may weaponize vulnerabilities within 15 minutes of disclosure and achieve initial-access-to-data-exfiltration in a median 72 minutes, creating a 'negative time-to-exploit' problem. The report cites one organisation whose CVE volume rose from roughly 80 in Q1 2025 to almost 500 in Q1 2026, then about 500 reports per day when frontier-AI tools were used. ENISA recommends machine-speed defence under 'Cybersecurity as Code', EPSS and VEX-based prioritisation, AI-assisted incident response with human oversight, and an assume-breached architecture.

Security Affairs · 2d agoAdvisory

Suspected Iran-linked attack knocked UK power plant offline for days

Suspected Iranian hackers knocked a small UK power plant offline for four days in July 2026, with no noticeable impact on the national grid.

Sources told The Telegraph that a British power plant was offline for four days in July 2026 following a suspected Iranian cyberattack, reported to the National Cyber Security Centre. The UK energy minister said the incident affected a small-scale energy generator with no noticeable effect on the power supply, and energy CEOs were briefed and given further advice afterward. The attack followed warnings about Iranian cyber activity against US energy, water, and government networks, including a coordinated attack on 30+ US community water utilities.

Help Net Security · 23d agoThreat actor

Conti ransomware crew member sentenced to four years in prison

Ukrainian national Oleksii Lytvynenko sentenced to four years in the US for his role in Conti ransomware attacks on at least 12 companies.

Oleksii Lytvynenko, 44, who pleaded guilty in June to conspiracy to commit wire fraud, was sentenced Thursday to four years in prison by the US Justice Department. He joined the Conti ransomware group in September 2021 as an intruder and malware developer, holding stolen data from 12 victims including eight US-based organizations, and prosecutors said co-conspirators extorted roughly $634,000 in Bitcoin from Tennessee victims including government entities. Conti attacked more than 1,000 organizations before disbanding in 2022, with members rebranding into Zeon, Black Basta, and Quantum/Royal/BlackSuit.

CyberScoopupdated · 5d agofirst · 6d agoPolicy & legal 7 sources1

Sexually Explicit Deepfake Sites Target 100-Plus Politicians in Europe

Deepfake pornography sites have targeted nearly 150 European politicians, overwhelmingly women MPs, per new research on 160 abusive domains.

Researcher Benjamin Shultz analyzed roughly 160 deepfake abuse domains and found at least 138 women MPs from 22 EU countries appeared or were mentioned, versus nine male MPs — making women MPs 33 times more likely to be targeted. Sites host database-like profiles with names, photos, personal details, and links to 'nudifier' creation tools. The findings, published by German think tank Agora Digitale Transformation, show politicians from Germany, the Netherlands, Italy, and France most affected, with senior politicians targeted more often. The UK and EU are planning bans on nudify services, while the US Take It Down Act has taken major deepfake sites offline.

WIRED · Security · 2d agoAI safety & security1

FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching

FBI officials said AI is accelerating adversary capabilities while its new cyber strategy emphasizes continuous patching, cyber hygiene, and AI-enabled defense.

At the Billington CyberSecurity Summit and ahead of a new FBI cyber strategy, deputy assistant director Jason Bilnoski said AI is boosting the speed and capability of both criminal and nation-state attackers, while stressing that basic controls like MFA would still prevent most attacks. Colleen Ferranti urged a shift from quarterly Patch Tuesday cycles to continuous, risk-based patching as AI accelerates vulnerability discovery. The strategy pledges AI-enabled triage, malware analysis, attribution support, agentic AI adoption, expanded Computer Network Operations, ICS Coordinators in every field office, and a pledge on victim relief and privacy.

CyberScoop · 7d agoPolicy & legal

Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist

Kyle Spitze, an early 764 member, was sentenced to 77 years for producing CSAM, the longest sentence for a nihilistic violent extremist.

Kyle William Spitze, an original member of the 764 nihilistic violent extremist network and administrator of the Harm Nation offshoot, was sentenced to 77 years in federal prison. He pleaded guilty in December 2024 to producing child sexual abuse material, possession of CSAM, and distributing animal crush videos, victimizing dozens of girls through coercion, doxing and swatting threats. Investigators found roughly 25 photo albums of abuse imagery on his phone and evidence of animal torture. The Justice Department framed the sentence as a signal in a broader enforcement push against 764, which has seen multiple members arrested or sentenced since 2025.

CyberScoop · 27d agoPolicy & legal

Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan

Dream researchers observed the first near-autonomous AI attack on a government target, with suspected Chinese hackers stealing 2,500+ Taiwan records.

Israeli firm Dream reported that suspected Chinese hackers used open-source AI models to run a near-autonomous cyberattack against Taiwan's government, extracting over 2,500 personnel records. The framework, built on Hermes and OpenClaw, adapted mid-operation without human intervention, ran autonomous 'Learning Cycles' researching applicable vulnerabilities, and expanded to supply chain vendors, a nuclear safety agency, a government email system, and seven-plus energy companies. Attackers bypassed safety guardrails by framing the work as authorized penetration testing. Dream discovered the operation via a 160MB online archive of nearly 1,400 files.

CyberScoop · Aug 12, 2026Threat actor in the wild

Apollo discloses data breach from ongoing wave of attacks hitting financial sector

Apollo Global Management confirmed a breach of cloud platforms by BlackFile-linked social engineering attackers, exposing personal data including Social Security numbers.

Apollo Global Management disclosed that attackers accessed some of its cloud platforms between July 6 and July 10, 2026. The company determined on August 12 that compromised data included names, dates of birth, contact information, home addresses, and Social Security numbers. Google attributed the broader campaign against financial sector organizations to BlackFile, a threat group affiliated with The Com that operates extortion brands Redact, Pink, Helix, and Falcon. Apollo, which manages $1.05 trillion in assets, is the first victim to formally confirm sensitive personal data was compromised in this wave, with Blackstone and Bain Capital also reportedly targeted.

CyberScoop · 26d agoData breach in the wild

Details emerge on BlackFile's recent attacks on financial companies

BlackFile (UNC6671), a The Com-linked extortion crew, keeps hitting financial and med tech firms with voice-phishing IT-support scams and ~$3 million demands.

Google Threat Intelligence Group (tracking BlackFile as UNC6671, linked to The Com) reports the extortion group remains active, shifting focus to the financial sector and med tech organizations, with new Redact-brand extortion demands issued last week. The group impersonates IT support in voice-phishing attacks using hundreds of recruited callers, targets large firms in what researchers call big-game hunting, and processes an average of 1.5 new victims daily. Extortion demands start around $3 million and are typically negotiated below $1 million; Flashpoint observed infrastructure targeting Blackstone, Bain Capital, Moody's, CME, and Apollo, though compromise is unconfirmed. Mandiant has responded to more than two dozen BlackFile compromises since January, and victims face escalation tactics including swatting.

CyberScoop · Aug 17, 2026Threat actor in the wild

Russian national extradited to US for alleged involvement in bank-account takeover scheme

US extradited Russian national Sergei Filimonov over a bank-account takeover scheme using spoofed bank domains that defrauded two banks of $6.3 million.

US authorities extradited 36-year-old Russian national Sergei Anatolyevich Filimonov from the Republic of Georgia on charges including bank and wire fraud conspiracy and aggravated identity theft. He and unnamed co-conspirators allegedly ran spoofed bank domains, bought sponsored links to lure victims, and harvested over 5,000 victim login credentials starting in November 2023, causing unauthorized transfers of about $5.58 million and $735,000 from two banks in 2024. The FBI previously identified at least 19 US victims linked to the credential-storage domain, with roughly $28 million in attempted losses including $14.6 million confirmed. Filimonov faces up to 175 years in prison, pleaded not guilty on September 4, and remains detained in the Northern District of Georgia.

CyberScoop · 8d agoPolicy & legal

Cohere Releases North Small Translate: A 218B MoE Translation Model That Scores 83.6 on WMT26 Across 50 Languages

Cohere released North Small Translate, an open-weight 218B MoE (25B active) translation model scoring 83.6 on WMT26 across 50 languages.

Cohere and Cohere Labs released North Small Translate, a decoder-only sparse Mixture-of-Experts translation model with 218B total and 25B active parameters, 128 experts with 8 activated per token plus shared experts, and 16K-token input and output context. In Cohere's vendor-reported WMT26 evaluation, judged by GPT-5.6-Sol, it scores 83.6 averaged across 50 languages (84.36 in an agentic multi-pass mode), ahead of DeepL NextGen (81.37), Qwen 3.5 397B A17B (81.56), GLM 5.2 (76.50), and Google Translate (68.20). The model was built with RWS's Language Weaver team, post-trained specifically for translation, and reports 112 output tokens per second versus 81 for Gemma 4 31B, with long-document xCOMET-XL scores of 48.9 versus 21.3 for Google Translate. It is available free on Cohere's Chat V2 API until rate limits, with three self-hosting checkpoints including a 4-bit NVFP4 variant running on 1x B200 or 2x H100.

MarkTechPost · 5d agoModel release