Author: Robert Timlick

  • SEC Files Charges Over $14 Million Crypto Scam Using Fake AI-Themed Investment Tips

    SEC Files Charges Over $14 Million Crypto Scam Using Fake AI-Themed Investment Tips

    The U.S. Securities and Exchange Commission (SEC) has filed charges against multiple companies for their alleged involvement in an elaborate cryptocurrency scam that swindled more than $14 million from retail investors.
    The complaint charged crypto asset trading platforms Morocoin Tech Corp., Berge Blockchain Technology Co., Ltd., and Cirkor Inc., as well as investment clubs AI Wealth Inc., Lane
  • Italy Fines Apple €98.6 Million Over ATT Rules Limiting App Store Competition

    Italy Fines Apple €98.6 Million Over ATT Rules Limiting App Store Competition

    Apple has been fined €98.6 million ($116 million) by Italy’s antitrust authority after finding that the company’s App Tracking Transparency (ATT) privacy framework restricted App Store competition.
    The Italian Competition Authority (Autorità Garante della Concorrenza e del Mercato, or AGCM) said the company’s “absolute dominant position” in app distribution allowed it to “unilaterally impose”
  • John A. Wolf appointed presiding judge

    John A. Wolf appointed presiding judge

    THE DALLES — Circuit Court Judge John A. Wolf was appointed to serve as the next presiding judge of Oregon’s Seventh Judicial District on Dec. 3, assuming the reins from Judge Karen Ostrye, who has held the position since 2022.
  • Two Chrome Extensions Caught Secretly Stealing Credentials from Over 170 Sites

    Two Chrome Extensions Caught Secretly Stealing Credentials from Over 170 Sites

    Cybersecurity researchers have discovered two malicious Google Chrome extensions with the same name and published by the same developer that come with capabilities to intercept traffic and capture user credentials.
    The extensions are advertised as a “multi-location network speed test plug-in” for developers and foreign trade personnel. Both the browser add-ons are available for download as of
  • INTERPOL Arrests 574 in Africa; Ukrainian Ransomware Affiliate Pleads Guilty

    INTERPOL Arrests 574 in Africa; Ukrainian Ransomware Affiliate Pleads Guilty

    A law enforcement operation coordinated by INTERPOL has led to the recovery of $3 million and the arrest of 574 suspects by authorities from 19 countries, amidst a continued crackdown on cybercrime networks in Africa.
    The coordinated effort, named Operation Sentinel, took place between October 27 and November 27, 2025, and mainly focused on business email compromise (BEC), digital extortion, and
  • U.S. DoJ Seizes Fraud Domain Behind $14.6 Million Bank Account Takeover Scheme

    U.S. DoJ Seizes Fraud Domain Behind $14.6 Million Bank Account Takeover Scheme

    The U.S. Justice Department (DoJ) on Monday announced the seizure of a web domain and database that it said was used to further a criminal scheme designed to target and defraud Americans by means of bank account takeover fraud.
    The domain in question, web3adspanels[.]org, was used as a backend web panel to host and manipulate illegally harvested bank login credentials. Users to the website are
  • Critical n8n Flaw (CVSS 9.9) Enables Arbitrary Code Execution Across Thousands of Instances

    Critical n8n Flaw (CVSS 9.9) Enables Arbitrary Code Execution Across Thousands of Instances

    A critical security vulnerability has been disclosed in the n8n workflow automation platform that, if successfully exploited, could result in arbitrary code execution under certain circumstances.
    The vulnerability, tracked as CVE-2025-68613, carries a CVSS score of 9.9 out of a maximum of 10.0. The package has about 57,000 weekly downloads, according to statistics on npm.
    “Under certain
  • Fake WhatsApp API Package on npm Steals Messages, Contacts, and Login Tokens

    Fake WhatsApp API Package on npm Steals Messages, Contacts, and Login Tokens

    Cybersecurity researchers have disclosed details of a new malicious package on the npm repository that works as a fully functional WhatsApp API, but also contains the ability to intercept every message and link the attacker’s device to a victim’s WhatsApp account.
    The package, named “lotusbail,” has been downloaded over 56,000 times since it was first uploaded to the registry by a user named “
  • ⚡ Weekly Recap: Firewall Exploits, AI Data Theft, Android Hacks, APT Attacks, Insider Leaks & More

    ⚡ Weekly Recap: Firewall Exploits, AI Data Theft, Android Hacks, APT Attacks, Insider Leaks & More

    Cyber threats last week showed how attackers no longer need big hacks to cause big damage. They’re going after the everyday tools we trust most — firewalls, browser add-ons, and even smart TVs — turning small cracks into serious breaches.
    The real danger now isn’t just one major attack, but hundreds of quiet ones using the software and devices already inside our networks. Each trusted system can
  • Android Malware Operations Merge Droppers, SMS Theft, and RAT Capabilities at Scale

    Android Malware Operations Merge Droppers, SMS Theft, and RAT Capabilities at Scale

    Threat actors have been observed leveraging malicious dropper apps masquerading as legitimate applications to deliver an Android SMS stealer dubbed Wonderland in mobile attacks targeting users in Uzbekistan.
    “Previously, users received ‘pure’ Trojan APKs that acted as malware immediately upon installation,” Group-IB said in an analysis published last week. “Now, adversaries increasingly deploy