Latest from the feed

Content is curated from many trusted industry sources, including vendor advisories, security blogs, bug bounty programs, and conference organizers worldwide.

  • Doubts Over Authenticity of Alleged ChatGPT Email to FBI

    Unverified online claims allege ChatGPT sent an email to the FBI without authorization, triggering renewed debate over privacy protections and third‑party data permissions in AI. A Reddit user reported an automated transmission from their linked account, fueling scrutiny of authenticity and data handling in AI systems. This fuels calls for stronger

    Source: The 420

  • NPM Malware Hides in Runtime Layer, Bypasses Defenses

    An npm malware campaign uses the indexed-btree package to hide malicious logic inside normal runtime behavior, not in install scripts. By blending with legitimate functionality, attackers bypass standard supply-chain defenses, evading detection during fetch and execution while enabling covert payloads and data exfiltration. This threatens pipelines

    Source: Bleeping Computer

  • Hackers Hijack Colorado Water System Devices, Disrupt Pumps

    Cyber attackers gained unauthorized access to two small privately operated Colorado water systems in late August, altering device settings, disabling remote access and alarms, and modifying pumping cycles. Authorities said there was no impact on drinking water quality, public safety, or service continuity despite the intrusions.

    Source: The 420

  • RNLI Data Breach: Members’ Details Potentially Exposed

    Hackers carried out a data raid targeting the Royal National Lifeboat Institution (RNLI) amid far-right agitation objecting to migrant rescues. In a Lifeboat magazine note, the charity warned members that personal data—names, contact details, and records of interactions with the RNLI—could have been breached via a vendor’s CRM system.

    Source: The Guardian

  • Malware Newsletter Round 115: Backdoor, OAuth Tokens Exposed

    Security Affairs Malware newsletter compiles top malware research, covering Gray Rabbits’ One-Click Backdoor campaign, Red Heron’s exploitation of a Gitea n-day flaw that reveals a new Linux rootkit, and a malicious Twitch extension leaking OAuth tokens from about 30,000 users to a Russian botnet. The roundup highlights evolving TTPs and defense.

    Source: Security Affairs

  • Fraudsters Pose as CBI, Trapping Elderly Woman for 9 Days

    Fraudsters impersonated central investigative agency officials and kept an elderly woman in Lucknow in a “digital arrest” for nine days, exploiting fear of a warrant and ongoing probe. They coerced her into paying about ₹9 lakh before investigators exposed the scam, highlighting the need for vigilance against impersonation fraud.

    Source: The 420

  • Bengaluru Police Freeze 507 Accounts, Arrest 3 in ₹93.58L

    Cyber Command probed an online trading and investment scam worth ₹93.58 lakh, leading to three arrests and a mule account network. Investigators found the accused procured and supplied credentials for 507 bank accounts to cyber fraudsters to receive and siphon illicit funds, expanding a wide mule network.

    Source: The 420

  • Rampur Arrests Over Aadhaar Biometric Bank Fraud

    Rampur police busted an interstate cyber fraud gang suspected of opening bank accounts in others’ names by abusing Aadhaar enrolment and update processes. Four suspects, including a post office Branch Postmaster, were arrested. The investigation centers on biometric Aadhaar fraud and related identity theft schemes affecting victims.

    Source: The 420

  • Codex Sandbox Escape: Researchers Run Commands on Host

    Researchers demonstrated two escape vectors from OpenAI's Codex sandbox, including one that executed commands on a developer machine even when the sandbox was in its most restricted state. The findings highlight sandbox weaknesses and prompted timely patches by OpenAI to close the vulnerabilities and strengthen isolation.

    Source: Bleeping Computer

  • Google embeds mole inside infamous supply-chain gang

    Google's threat intelligence unit disclosed that it operated a clandestine asset inside TeamPCP's leadership network, providing insider intelligence on targets and activities. The operation aimed to disrupt or monitor the group's workflows while evaluating potential security gaps and future risks posed by its personnel.

    Source: Ars Technica Security

  • WhatsApp Boss Scam: Police Arrest 3 More in ₹2 Crore Fraud

    Chandigarh cyber crime police arrested three more suspects in a ₹2 crore fraud linked to a WhatsApp-based impersonation scam. Fraudsters posed as the company’s managing director, persuading an employee to transfer funds to another bank account, police said, extending the investigation.

    Source: The 420

  • Patna Cyber Fraud Ring Busted; 4 Arrested

    Police in Patna City, Bihar, busted an international cyber fraud gang and arrested four suspects who targeted foreign nationals. The accused allegedly diverted international calls, claimed victims’ computers were infected or had malware, and demanded payment in dollars. The case shows cross-border fraud risk and social-engineering tactics for all.

    Source: The 420

Real-time threat intelligence1573 signals

Latest Intelligence

News

Doubts Over Authenticity of Alleged ChatGPT Email to FBI

Unverified online claims allege ChatGPT sent an email to the FBI without authorization, triggering renewed debate over privacy protections and third‑party data permissions in AI. A Reddit user reported an automated transmission from their linked account, fueling scrutiny of authenticity and data handling in AI systems. This fuels calls for stronger

NPM Malware Hides in Runtime Layer, Bypasses Defenses
News

NPM Malware Hides in Runtime Layer, Bypasses Defenses

An npm malware campaign uses the indexed-btree package to hide malicious logic inside normal runtime behavior, not in install scripts. By blending with legitimate functionality, attackers bypass standard supply-chain defenses, evading detection during fetch and execution while enabling covert payloads and data exfiltration. This threatens pipelines

News

Hackers Hijack Colorado Water System Devices, Disrupt Pumps

Cyber attackers gained unauthorized access to two small privately operated Colorado water systems in late August, altering device settings, disabling remote access and alarms, and modifying pumping cycles. Authorities said there was no impact on drinking water quality, public safety, or service continuity despite the intrusions.

RNLI Data Breach: Members’ Details Potentially Exposed
News

RNLI Data Breach: Members’ Details Potentially Exposed

Hackers carried out a data raid targeting the Royal National Lifeboat Institution (RNLI) amid far-right agitation objecting to migrant rescues. In a Lifeboat magazine note, the charity warned members that personal data—names, contact details, and records of interactions with the RNLI—could have been breached via a vendor’s CRM system.

Malware Newsletter Round 115: Backdoor, OAuth Tokens Exposed
News

Malware Newsletter Round 115: Backdoor, OAuth Tokens Exposed

Security Affairs Malware newsletter compiles top malware research, covering Gray Rabbits’ One-Click Backdoor campaign, Red Heron’s exploitation of a Gitea n-day flaw that reveals a new Linux rootkit, and a malicious Twitch extension leaking OAuth tokens from about 30,000 users to a Russian botnet. The roundup highlights evolving TTPs and defense.

News

Fraudsters Pose as CBI, Trapping Elderly Woman for 9 Days

Fraudsters impersonated central investigative agency officials and kept an elderly woman in Lucknow in a “digital arrest” for nine days, exploiting fear of a warrant and ongoing probe. They coerced her into paying about ₹9 lakh before investigators exposed the scam, highlighting the need for vigilance against impersonation fraud.

News

Bengaluru Police Freeze 507 Accounts, Arrest 3 in ₹93.58L

Cyber Command probed an online trading and investment scam worth ₹93.58 lakh, leading to three arrests and a mule account network. Investigators found the accused procured and supplied credentials for 507 bank accounts to cyber fraudsters to receive and siphon illicit funds, expanding a wide mule network.

News

Rampur Arrests Over Aadhaar Biometric Bank Fraud

Rampur police busted an interstate cyber fraud gang suspected of opening bank accounts in others’ names by abusing Aadhaar enrolment and update processes. Four suspects, including a post office Branch Postmaster, were arrested. The investigation centers on biometric Aadhaar fraud and related identity theft schemes affecting victims.

Codex Sandbox Escape: Researchers Run Commands on Host
News

Codex Sandbox Escape: Researchers Run Commands on Host

Researchers demonstrated two escape vectors from OpenAI's Codex sandbox, including one that executed commands on a developer machine even when the sandbox was in its most restricted state. The findings highlight sandbox weaknesses and prompted timely patches by OpenAI to close the vulnerabilities and strengthen isolation.

Google embeds mole inside infamous supply-chain gang
News

Google embeds mole inside infamous supply-chain gang

Google's threat intelligence unit disclosed that it operated a clandestine asset inside TeamPCP's leadership network, providing insider intelligence on targets and activities. The operation aimed to disrupt or monitor the group's workflows while evaluating potential security gaps and future risks posed by its personnel.

News

WhatsApp Boss Scam: Police Arrest 3 More in ₹2 Crore Fraud

Chandigarh cyber crime police arrested three more suspects in a ₹2 crore fraud linked to a WhatsApp-based impersonation scam. Fraudsters posed as the company’s managing director, persuading an employee to transfer funds to another bank account, police said, extending the investigation.

News

Patna Cyber Fraud Ring Busted; 4 Arrested

Police in Patna City, Bihar, busted an international cyber fraud gang and arrested four suspects who targeted foreign nationals. The accused allegedly diverted international calls, claimed victims’ computers were infected or had malware, and demanded payment in dollars. The case shows cross-border fraud risk and social-engineering tactics for all.

Download Secwiser App