The FBI has successfully dismantled a phishing operation known as W3LL, which was linked to fraudulent activities totaling around $20 million. This operation utilized a specialized phishing kit that enabled attackers to trick individuals into providing sensitive information. The takedown is a significant step in combating online fraud, as phishing remains a common tactic used by cybercriminals to exploit unsuspecting users. The operation's disruption not only affects the criminals behind it but also aims to protect potential victims from falling prey to similar scams. Authorities are urging individuals and businesses to remain vigilant against phishing attempts, which can lead to financial loss and data breaches.
Hackread – Cybersecurity News, Data Breaches, AI and More
A German national, suspected of being a key figure in the DDoS-for-hire scene, was arrested in Thailand. This individual is believed to be the mastermind behind services like Fluxstress and Neldowner, which have been used to launch distributed denial-of-service (DDoS) attacks globally. His arrest marks a significant step in combating online cybercrime, particularly as DDoS attacks continue to disrupt businesses and services across various sectors. The operation he led allowed users to pay for attacks that could overwhelm targets, causing significant downtime and financial losses. His capture may deter others from engaging in similar illegal activities and could lead to further investigations into the networks supporting these services.
In a significant crackdown on identity fraud, Dutch police arrested eight men, aged 20 to 34, during an operation targeting the VerifTools platform on April 7 and 8. The suspects are linked to identity fraud, forgery, and various cybercrime offenses. Authorities seized a substantial amount of evidence, including smartphones, laptops, cash, cryptocurrency, and weapons. This investigation stems from a case that began on August 27, 2025, when police discovered that VerifTools was facilitating the creation of fake identification documents. The seizure of over 915,655 fake IDs raises concerns about the ease with which such fraudulent activities can be carried out and the potential risks to personal security and public safety.
Kaspersky's GReAT team has reported on a new campaign involving JanelaRAT, a type of remote access trojan that specifically targets financial information from users in Latin America. This malware is designed to steal sensitive data, including banking credentials, by infecting victims' devices through a series of sophisticated techniques. The infection process and the functionality of the malware have both been updated, making it more dangerous than previous versions. This campaign is particularly concerning as it highlights the ongoing risks to financial security for users in the region, especially given the rise of online banking and digital transactions. Users in Latin America need to be aware of this threat and take steps to protect their financial information.
In a recent interview, Art Manion from Tharros discussed the ongoing issues with vulnerability data across various repositories. He pointed out that many systems are not set up to effectively collect or manage this data, which leads to inconsistencies and a lack of trust. Manion introduced the concept of Minimum Viable Vulnerability Enumeration (MVVE), which aims to identify the essential assertions needed to confirm that two systems are describing the same vulnerability. However, he noted that there is no universal minimum set of assertions, as they can vary based on the specific case and change over time. This inconsistency is a significant barrier to improving the quality of vulnerability data, affecting the ability of organizations to accurately assess and respond to security risks.
MITRE has introduced a new framework called the Fight Fraud Framework (F3) to combat financial fraud, which has surged in the U.S. from $4.2 billion in losses in 2020 to $16.6 billion in 2024. Historically, fraud investigators and cybersecurity analysts have worked in silos, using different tools and approaches to tackle fraud, which has contributed to the growing issue. The F3 aims to bridge this gap by providing a common structure that allows both teams to better understand and describe fraud behaviors. This initiative is crucial as it seeks to unify efforts against financial fraud, making it easier for organizations to respond effectively. With financial fraud on the rise, the framework could help reduce losses and improve collaboration among teams tasked with preventing these crimes.
Hackread – Cybersecurity News, Data Breaches, AI and More
Actively Exploited
A hacker has reportedly used advanced AI tools, Claude Code and GPT-4.1, to steal personal records of hundreds of millions of Mexican citizens from nine different government agencies. This breach raises serious concerns about data security and the potential misuse of sensitive information. The stolen records likely include personal identifiers, which could lead to identity theft or fraud. The incident highlights vulnerabilities in governmental data protection practices and the growing capabilities of cybercriminals using AI for malicious purposes. Authorities will need to investigate the breach thoroughly and implement stronger security measures to protect citizen data in the future.
A serious vulnerability in Marimo software has come to light, allowing attackers to execute remote code without needing authentication. This flaw is currently being exploited to steal user credentials, making it a pressing issue for organizations using this software. The nature of the vulnerability means that it could potentially affect a wide range of users and systems that rely on Marimo. Companies need to act quickly to protect their data and systems from unauthorized access. Immediate action is essential to mitigate the risk posed by this vulnerability as attackers are actively targeting it.
Recent research has identified thirty-six malicious npm packages related to the Strapi framework that have been linked to Redis remote code execution (RCE), database theft, and persistent command and control (C2) capabilities. In addition, malicious LNK files are being used to distribute a Python-based backdoor. The Kimsuky Group has also been noted for changing their distribution techniques to enhance their attacks. These developments pose serious risks to developers and organizations using these tools, as they could lead to unauthorized access and data breaches. It is crucial for users to be vigilant and ensure they are using secure versions of these packages to avoid falling victim to these threats.
Hackread – Cybersecurity News, Data Breaches, AI and More
The FBI Atlanta office, in collaboration with the Indonesian National Police, has successfully shut down W3LLSTORE, a phishing marketplace linked to a significant $20 million fraud scheme. Authorities seized multiple domains associated with the site and detained its developer, marking a notable victory in the fight against online fraud. W3LLSTORE facilitated the distribution of phishing kits and other malicious tools, which allowed cybercriminals to target unsuspecting victims. This operation not only disrupts the marketplace but also sends a strong message to those involved in cybercrime. The crackdown is crucial as it helps protect individuals and organizations from falling victim to similar scams in the future.
Researchers at Censys have identified 5,219 devices that are vulnerable to attacks from Iranian Advanced Persistent Threat (APT) groups, with a significant number located in the United States. This exposure raises concerns about the potential for targeted cyber operations against various sectors, especially given the geopolitical tensions involving Iran. The findings suggest that organizations should assess their security postures and take proactive measures to mitigate risks associated with these vulnerabilities. The presence of such a large number of exposed devices indicates a broader issue of inadequate cybersecurity practices that could lead to severe consequences if exploited. Companies and users need to be vigilant and enhance their defenses against these potential threats.
Censys researchers have identified 5,219 Rockwell PLCs (Programmable Logic Controllers) that are exposed to potential attacks, with the majority located in the United States. This warning comes after U.S. agencies, including the FBI, CISA, and NSA, reported that Iranian-linked advanced persistent threat groups are actively exploiting these internet-connected devices. The attacks target operational technology across various critical infrastructure sectors, raising concerns about national security. Experts are urging organizations to secure these devices or disconnect them from the internet to prevent potential breaches. The situation underscores the need for better security measures in industrial control systems, especially as cyber threats continue to evolve.
The GlassWorm campaign has evolved significantly since its inception in 2025, now utilizing a Zig-based dropper embedded in a fake Integrated Development Environment (IDE) extension. This method targets developer tools, allowing attackers to compromise systems through malicious software packages. Initially starting with harmful npm packages, the campaign has escalated to large-scale supply chain attacks affecting platforms like GitHub, npm, and Visual Studio Code. Additionally, the attackers have deployed Remote Access Trojans (RATs) via counterfeit browser extensions. This evolution raises concerns for developers and organizations, as it highlights the growing sophistication of supply chain threats in the software development ecosystem.
Hackread – Cybersecurity News, Data Breaches, AI and More
Recent court proceedings have revealed that messages sent via the Signal app can still be accessed by the FBI through iPhone notification data, even after users have deleted them. This discovery raises significant concerns about privacy and the effectiveness of end-to-end encryption, as it suggests that deleted messages may not be entirely erased from device records. The implications of this finding are serious for Signal users, particularly those who rely on the app for confidential communications. The case highlights the potential vulnerabilities in how smartphones handle notifications and data retention, prompting users to reconsider the security of their communications. It also raises questions about the extent to which law enforcement can retrieve deleted digital information, which could affect how individuals perceive their privacy in the digital age.
CVE-2026-39987: Marimo RCE exploited in hours after disclosure
Security Affairs
Actively Exploited
A serious vulnerability in the open-source Python notebook tool Marimo, identified as CVE-2026-39987, has been exploited within just 10 hours of its disclosure on April 8, 2026. This flaw has a CVSS score of 9.3, indicating its severity and potential impact. Researchers from the Sysdig Threat Research Team reported that attackers began exploiting this vulnerability almost immediately, raising alarms about the security of systems using Marimo. This incident underscores the urgency for users and organizations relying on this tool to take immediate action to protect their systems from potential breaches. Quick exploitation of such vulnerabilities demonstrates the need for timely patching and awareness in the cybersecurity community.