• UK law enforcement has arrested two individuals linked to the notorious Scattered Spider cybercriminal group, including 19-year-old Thalha Jubair from London, who faces charges in connection with over 120 network intrusions that resulted in more than $115 million in ransom payments. 

    The arrests represent a significant breakthrough in dismantling one of the world’s most prolific ransomware operations, which targeted critical infrastructure, including the London Transport system.

    “Scattered Spider” Hackers Charged

    The coordinated operation involved multiple international agencies, with the FBI’s Cyber Division, the UK’s National Crime Agency, the City of London Police, and the West Midlands Police working together to track down the cybercriminals. 

    Jubair, operating under aliases including “EarthtoStar,” “Brad,” “Austin,” and “@autistic,” was charged with computer fraud conspiracy, wire fraud conspiracy, and money laundering conspiracy in a complaint filed in the District of New Jersey.

    The investigation revealed that Scattered Spider, also known as “Octo Tempest,” “UNC3944,” and “0ktapus,” employed sophisticated social engineering techniques to infiltrate corporate networks. 

    The group’s modus operandi included voice phishing attacks against help desks, SIM swapping operations, and spear phishing campaigns to gain unauthorized access to victim systems.

    The cybercriminal operation spanned from May 2022 to September 2025, with attackers utilizing advanced persistence mechanisms and lateral movement techniques within compromised networks. 

    Law enforcement successfully seized cryptocurrency worth approximately $36 million from servers controlled by Jubair, though he managed to transfer an additional $8.4 million in cryptocurrency to alternative wallets during the seizure operation.

    The group’s targeting of critical infrastructure included successful breaches of the U.S. Courts system and a U.S.-based critical infrastructure company in October 2024 and January 2025. 

    The London Transport system breach demonstrates the group’s capability to compromise SCADA systems and operational technology networks that control essential public services.

    Assistant Deputy Chief Adrienne L. Rose from the Justice Department’s Computer Crime and Intellectual Property Section (CCIPS) emphasized that since 2020, CCIPS has secured convictions of over 180 cybercriminals and facilitated the return of more than $350 million in victim funds. 

    If convicted on all charges, Jubair faces a maximum penalty of 95 years in prison, highlighting the severe consequences for ransomware-as-a-service operators and their affiliates.

    Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

    The post UK Arrested 2 Scattered Spider Hackers Linked to London Transport System Breach appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Detecting remote employment fraud has become a critical priority for organizations striving to secure their digital onboarding processes and safeguard sensitive systems.

    In recent months, threat actors posing as legitimate hires have leveraged sophisticated tactics to bypass pre-hire screenings and embed themselves within corporate networks.

    This emerging threat vector, known as Remote Employment Fraud (REF), exploits gaps between human resources workflows and security monitoring, allowing malicious insiders to gain persistent access and exfiltrate data under the cover of a legitimate employee identity.

    The initial stages of REF involve threat actors meticulously crafting resumes, passing background checks, and scheduling interviews that appear indistinguishable from genuine candidates.

    Once onboarded, they request shipment of corporate assets—laptops, mobile devices, or network tokens—to addresses that often diverge from their purported locations.

    Through careful correlation of asset management logs with applicant tracking data, organizations can reveal discrepancies that point to fraudulent activity.

    Splunk analysts identified the first wave of these anomalies by matching ServiceNow shipment records against Workday employee profiles, flagging cases where the delivered location did not align with an employee’s registered home state.

    Location did not align with an employee’s registered home state (Source – Splunk)

    Splunk analysts noted that REF actors frequently leverage nonstandard VPN services to obfuscate their true IP addresses and geolocations.

    While virtual private networks are commonplace for legitimate remote work, inconsistencies between expected corporate VPN endpoints and unusual third-party VPN providers serve as strong indicators of fraud.

    By creating baselines in Identity Provider (IdP) logs—such as Okta or Duo—security teams can detect anomalous VPN sessions and enforce network zones that block unauthorized anonymizer services.

    Beyond transport-layer evasion, REF actors may employ improbable travel tactics to mask their origin.

    Login attempts from geographically distant locations within implausible timeframes—such as a login from London minutes after a session in New York—underscore the need for geospatial analytics.

    Splunk Enterprise Security’s Authentication Data Model can calculate approximate travel speed between login events to surface these anomalies, enabling rapid investigation before a breach escalates.

    Infection Mechanism and Persistence Through Asset Misshipment

    An in-depth look at the most prevalent REF infection mechanism reveals how initial device shipment inconsistencies provide the foothold for continued access.

    Threat actors request corporate laptops to be sent to alternate locations, often invoking urgent personal circumstances to justify mismatches.

    Once the device arrives, embedded persistence tactics—such as installing unsanctioned remote access tools—ensure ongoing connectivity.

    Security teams can prevent these operations by correlating applicant tracking system (ATS) data with IT asset logs in Splunk.

    index=servicenow sourcetype=laptop_shipment
    | eval delivered_location=case(arrivalState="CA","California", arrivalState="TX","Texas")
    | join type=outer Email [search index=identity sourcetype=workday_employee]
    | eval Suspicious=if(delivered_location!=home_state,"Yes","No")
    | search Suspicious="Yes"
    | table name, employeeId, home_state, delivered_location, Email
    Inconsistent worker locations (Source – Splunk)

    By automating this detection query, organizations can immediately surface potential REF cases, prompting joint investigations by security and HR teams.

    Integrating these detections into a Risk-Based Alerting (RBA) framework further enhances visibility, enabling prioritized incident response workflows that minimize false positives and drive efficient mitigation.

    Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

    The post Splunk Releases Guide to Detect Remote Employment Fraud Within Your Organization appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Law enforcement authorities in the U.K. have arrested two teen members of the Scattered Spider hacking group in connection with their alleged participation in an August 2024 cyber attack targeting Transport for London (TfL), the city’s public transportation agency. Thalha Jubair (aka EarthtoStar, Brad, Austin, and @autistic), 19, from East London and Owen Flowers, 18, from Walsall, West Midlands

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In a groundbreaking analysis, cybersecurity firm KELA reveals striking parallels in operational style, target selection, and online presence that suggest a possible connection between two Yemen-linked threat actors: the recently surfaced Belsen Group and the long-standing ZeroSevenGroup. Who Is the Belsen Group? The Belsen Group made its debut in early January 2025 via a post […]

    The post Researchers Reveal Connection Between Belsen and ZeroSeven Cybercrime Groups appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cloudflare experienced a significant outage on September 12, 2025, affecting its Tenant Service API, multiple APIs, and the Cloudflare Dashboard. The company has confirmed that the incident was primarily triggered by a React programming bug that caused excessive API calls, overwhelming critical infrastructure components. Technical Root Cause Identified The outage originated from a coding error […]

    The post Cloudflare Confirms API Outage Caused by React useEffect Overload Issue appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft has announced a significant upgrade to Windows 11 Notepad, introducing powerful artificial intelligence features that will revolutionize how users create and edit text. The update brings AI-powered writing assistance directly to the classic text editor, offering capabilities previously available only in premium applications. Windows 11 Notepad now features AI-powered options like write, rewrite, and summarize accessible […]

    The post Windows 11 Notepad to Receive AI Upgrade for Free Text Writing and Summarizing appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated new attack tool targeting jailbroken iOS devices has emerged, representing a significant escalation in digital identity fraud capabilities. 

    The discovery by iProov’s threat intelligence team reveals a highly specialized tool designed to perform advanced video injection attacks on iOS 15 and later devices, specifically engineered to bypass weak biometric verification systems and exploit identity verification processes lacking proper biometric safeguards.

    This breakthrough represents a troubling shift toward more programmatic and scalable attack approaches, with the tool’s suspected Chinese origins adding geopolitical relevance amidst rising concerns about technical sovereignty and digital supply chain security. 

    The tool’s emergence underscores the critical need for robust biometric verification systems capable of detecting sophisticated deepfake and injection attacks.

    Biometric Verification with Jailbroken iPhones

    The newly discovered tool operates through a multi-stage process that leverages the compromised security architecture of jailbroken iOS devices. 

    The attack begins with a prerequisite jailbroken iOS 15 or later device, where native Apple security restrictions have been removed to allow deep system modifications. 

    Attackers establish a connection using a Remote Presentation Transfer Mechanism (RPTM) server, creating a bridge between their computer and the compromised iOS device.

    The core attack involves injecting sophisticated deepfakes directly into the device’s video stream, completely bypassing the physical camera hardware. 

    Deepfakes can take the form of face swaps, in which a victim’s face is placed on another video, or motion re-enactments, in which static visuals are animated using the actions of another person. 

    The injected synthetic media tricks applications into believing the fraudulent video represents a live, real-time feed, enabling potential impersonation of legitimate users or creation of synthetic identities.

    “The discovery of this iOS tool marks a significant breakthrough in identity fraud and confirms the trend of industrialized attacks. The tool’s suspected origin is especially concerning and proves that it is essential to use a liveness detection capability that can rapidly adapt”, researchers said.

    The emergence of video injection attacks renders traditional identity verification methods insufficient, necessitating comprehensive multi-layered defense approaches. 

    Organizations must implement verification systems that simultaneously confirm the right person through identity matching to official documents and databases, verify a real person using embedded imagery and metadata analysis to detect malicious media, and ensure real-time authentication through unique passive challenge-response interactions, preventing replay attacks.

    The tool’s discovery coincides with alarming trends documented in iProov’s 2025 Threat Intelligence report, including a 2,665% increase in native virtual camera attacks and a 300% rise in face swap deepfake attacks. 

    With security experts tracking over 120 different face swap tools, threat actors are rapidly adopting new technologies to bypass verification systems, making robust liveness detection capabilities essential for organizational security.

    This multi-layered approach increases the complexity for attackers seeking to spoof identity verification systems, as advanced attacks struggle to bypass all security measures while retaining the natural traits of actual human contact.

    Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

    The post New iOS Video Injection Tool Bypasses Biometric Verification with Jailbroken iPhones appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • SystemBC, a resilient socks5 malware network first spotted in 2019, has dramatically evolved its proxy infrastructure by compromising an average of 1,500 virtual private servers (VPS) each day. This shift from residential devices to large-scale VPS nodes grants threat actors unprecedented bandwidth and longevity for malicious traffic, enabling sustained distributed denial-of-service (DDoS) and brute-force operations […]

    The post SystemBC Botnet Compromises 1,500 VPS Every Day to Rent Out for DDoS Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security researchers have uncovered a sophisticated new malware loader called “CountLoader” that leverages weaponized PDF files to deliver ransomware payloads to victims across multiple regions, with particular focus on Ukrainian targets. CountLoader represents a significant escalation in malware delivery techniques, operating through three distinct versions: .NET, PowerShell, and JScript implementations. The malware loader has been […]

    The post New Loader “CountLoader” Uses PDFs to Launch Ransomware Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Researchers have discovered a critical zero-click vulnerability in ChatGPT’s Deep Research agent that allows attackers to silently steal sensitive Gmail data without any user interaction. This sophisticated attack leverages service-side exfiltration techniques, making it invisible to traditional security defenses and representing a significant escalation in AI agent security threats. The Silent Data Theft Mechanism As per a report, the […]

    The post 0-Click ChatGPT Agent Flaw Exposes Gmail Data to Attackers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶