BlueCat Horizon unifies DNS, DHCP, IPAM, and security into a cloud-first intelligent NetOps platform
Copyright scammers get Instagram accounts suspended and demand payment
Scammers file fake Instagram copyright complaints to suspend accounts, then demand ransom via Telegram; Meta restored some affected accounts.
Criminals impersonate rights holders to file fraudulent copyright complaints on Instagram, and repeated claims can trigger temporary account suspensions. They then move victims to Telegram and demand payment, often in cryptocurrency, to withdraw the complaint; one history account owner paid $50 and was targeted again immediately. Meta's automated system does not verify complainants before acting, and the Delhi High Court is examining whether platforms can legally suspend accounts over copyright claims. Meta acknowledged in court that 13 strike notices against one user were fraudulent, and after BBC review it restored affected content and added unspecified protections.
Tech support scams look different now. Here’s what to watch for
Malwarebytes warns tech support scammers now abuse sponsored search results, fake listings, calendar invites, and Apple Pay notifications, and shares red flags for impersonation scams.
Malwarebytes describes how tech support scams have expanded beyond browser locks and fake virus warnings to sponsored search results, hijacked on-site searches, fake platform listings, renewal scams, fake calendar invites, and Apple Pay notifications. Scammers impersonate trusted security companies including Malwarebytes, seeking payment, personal information, or remote access to victims' computers. Malwarebytes notes it does not outsource support, never makes unsolicited calls, and works with the FTC and the Global Anti-Scam Alliance to combat these scams.
Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
Forescout used Anthropic's Claude to port a working pre-auth RCE exploit for CVE-2021-31886 between WAGO PLCs, executing ARM shellcode on live hardware.
Forescout Vedere Labs used Claude interactively to port an RCE exploit for CVE-2021-31886, a CVSS 9.8 stack buffer overflow in the Nucleus FTP server's USER command, from a WAGO 750-852 to a WAGO 750-831 PLC, running attacker-supplied ARM shellcode. The final RCE stage cost $535.74 in API usage over 8 hours 32 minutes, and a follow-up attempt to build a C2 implant permanently bricked the device. CERT@VDE lists many Nucleus V1-based WAGO models as vulnerable with no updates available; Siemens plans no Nucleus NET remediation. The work follows a joint NSA/CISA/FBI/DOE/EPA advisory warning of AI-generated exploitation scripts targeting internet-exposed Siemens S7 PLCs.