Breaking News – Cyber Threats – 2026-09-09 13:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-09 13:00 PDT
- U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto
The Hacker News • 2026-09-09 11:26 • thehackernews.com
The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Center Strike Force to Madagascar to help disrupt 13 scam compounds run by Chinese organized crime
https://thehackernews.com/2026/09/us-disrupts-xinbi-guarantee-scam.html - Scans for Proxmox Servers, (Wed, Sep 9th)
SANS ISC Diary (full) • 2026-09-09 10:46 • isc.sans.eduAbout a week ago, Proxmox published an advisory revealing a vulnerability in older versions of Proxmox VE, its flagship Virtual Environment product. The vulnerability only affects version 7, which has not been supported for a couple of years now.
- US says Chinese firms extracted billions of tokens from frontier AI models
BleepingComputer • 2026-09-09 09:48 • www.bleepingcomputer.com
U.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted industrial-scale distillation attacks on American frontier AI models since at least late 2024. […]
https://www.bleepingcomputer.com/news/security/us-says-chinese-firms-extracted-billions-of-tokens-from-frontier-ai-models/ - Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
The Hacker News • 2026-09-09 09:34 • thehackernews.com
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome.The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo,
https://thehackernews.com/2026/09/four-spy-groups-used-same-chrome-and.html - Driver’s License Data for Sale
Schneier on Security • 2026-09-09 09:05 • www.schneier.comA database of 153 million drivers licenses is for sale on the dark web. Brian Krebs has more detail.
https://www.schneier.com/blog/archives/2026/09/drivers-license-data-for-sale.html
- Veradigm warns of patient data breach after ransomware gang claims attack
BleepingComputer • 2026-09-09 08:31 • www.bleepingcomputer.com
Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients’ personal data. […]
https://www.bleepingcomputer.com/news/security/veradigm-discloses-patient-data-breach-after-gentlemen-gang-claims-attack/ - Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
The Hacker News • 2026-09-09 07:23 • thehackernews.com
Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create “stolen keys” that grant illicit access to tools from model providers like Google, Anthropic, and others.Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API
https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html - MFA's Weakest Link: Account Recovery Is the New Attack Path
BleepingComputer • 2026-09-09 07:01 • www.bleepingcomputer.com
MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to preventing social engineering attacks from turning account recovery into account takeover. […]
https://www.bleepingcomputer.com/news/security/mfas-weakest-link-account-recovery-is-the-new-attack-path/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.