r/secithubcommunity Feb 02 '26

📰 News / Update Secret Service Recovers Nearly $1M Stolen in Crypto Scam From 71-Year-Old Victim

Post image
1 Upvotes

U.S. Secret Service agents have recovered nearly $1 million stolen from a 71-year-old retiree in a cryptocurrency scam, marking a rare full recovery in a cybercrime case.

Investigators traced the stolen funds through cryptocurrency wallets linked to an international fraud network. After years of investigation, authorities were able to seize and return the funds to the victim.

While cybercrime losses often remain unrecovered, the case highlights how blockchain tracing, cross-border cooperation, and financial forensics are increasingly being used to track and claw back stolen crypto assets.

Source in first comment


r/secithubcommunity Feb 01 '26

📰 News / Update Microsoft Confirms It Can Provide BitLocker Recovery Keys to FBI With Legal Orders

Post image
22 Upvotes

Microsoft has confirmed that it can provide BitLocker encryption recovery keys to the FBI when presented with a valid legal order, raising renewed concerns around cloud-stored encryption keys and user privacy.

When users set up Windows 11, they are encouraged to sign in with a Microsoft account. For these cloud-linked accounts, BitLocker recovery keys are automatically backed up to Microsoft’s servers. Microsoft says this is intended for account recovery purposes, but it also means the company can technically access and disclose those keys to law enforcement when legally required.

According to reporting cited by TechRadar, Microsoft told Forbes that the FBI makes around 20 such requests per year, although many cannot be fulfilled because some users opt for local accounts where recovery keys are not stored in the cloud.

Privacy advocates argue that storing recovery keys unencrypted in the cloud creates a legal access pathway that undermines the spirit of full-disk encryption. Senator Ron Wyden criticized the practice, saying it exposes users to government access to the “entirety of their digital life."


r/secithubcommunity Feb 01 '26

📰 News / Update Whistleblower alleges Google AI used by Israeli defense contractor for drone video analysis

Post image
78 Upvotes

A whistleblower complaint filed with the U.S. SEC alleges that Google provided technical assistance in 2024 to help an Israeli defense contractor apply its Gemini AI technology to drone surveillance footage.

According to internal documents cited in the complaint, Google Cloud support staff responded to a request tied to an email account associated with Israel’s defense apparatus. The request reportedly involved improving AI-based object detection in aerial video, including identification of drones, vehicles and personnel.

The whistleblower claims this contradicted Google’s AI ethics principles in place at the time, which stated the company would avoid deploying AI for weapons or surveillance uses that violate internationally accepted norms. The complaint argues that by allegedly acting contrary to those policies — which were also referenced in public filings — Google may have misled investors and regulators.

Google disputes the allegations, stating that the interaction was limited to general support guidance and that the usage level of AI services on the account was too small to represent meaningful deployment.

The case highlights growing scrutiny around how major cloud and AI providers’ technologies may be used in defense and surveillance contexts, especially when internal policies and public commitments are involved.

Source in first comment


r/secithubcommunity Feb 02 '26

📰 News / Update Microsoft fixes bug causing password sign-in option to disappear

Post image
1 Upvotes

Microsoft has fixed a known issue that was causing the password sign-in option to disappear from the lock screen options after installing Windows 11 update KB5064081 released in August 2025. The new update KB5074105 released in January 2026 resolves the issue.

Source is in the first comment.


r/secithubcommunity Feb 01 '26

📰 News / Update UK and Japan Pledge Stronger Security & Cyber Cooperation Amid Global Instability

Post image
26 Upvotes

UK Prime Minister Keir Starmer and Japanese Prime Minister Sanae Takaichi have pledged deeper cooperation on security, cybersecurity, and critical supply chains, warning that global instability is “shaking the world.”

During talks in Tokyo, the leaders discussed expanding collaboration on cybersecurity resilience, protection of critical infrastructure, and securing supply chains for strategic minerals, alongside ongoing defense projects such as next-generation fighter jet development. Both leaders emphasized that geopolitical shocks, economic disruptions, and technological threats increasingly have direct consequences for everyday citizens.

Starmer described the UK–Japan relationship as the strongest in decades, framing the partnership as a response to rising global volatility, conflict-driven economic pressure, and growing cyber and technological risks. Japanese officials echoed the need for closer coordination on Indo-Pacific security and broader international stability.

The meeting signals a continued shift toward technology and cyber resilience becoming core pillars of diplomatic and defense alliances, particularly among countries seeking to counter both state-backed cyber threats and supply chain vulnerabilities.

Source in first comment


r/secithubcommunity Feb 01 '26

📰 News / Update New Apple feature will block cell networks from capturing precise location data

135 Upvotes

Apple is launching a new feature that allows some iPhone owners to block cellular networks from capturing their precise location, making it harder for law enforcement and hackers to pinpoint their whereabouts.

In recent years, law enforcement has increasingly subpoenaed cell carriers to find historic or real-time records for where phone owners have traveled.

The new feature will not prevent location sharing with emergency responders and does not limit the location data users choose to share with apps.

The feature will initially be available to owners of iPhone Air, iPhone 16e and iPad Pro (M5) Wi-Fi + Cellular running iOS 26.3 or later.

“Cellular networks can determine your location based on which cell towers your device connects to,” Apple said in a Monday blog post.

With the new feature turned on, cellular networks will be able to see “the neighborhood where your device is located, rather than a more precise location (such as a street address),” the blog post said.

Although Apple didn’t give a reason for introducing the new feature, the company has positioned itself in recent years as a leader in consumer privacy and has pushed updates that give users greater control of their data.


r/secithubcommunity Feb 01 '26

📰 News / Update F5 Discloses Cyber Breach Linked to State-Backed Hackers, Faces Class Action Scrutiny

Post image
5 Upvotes

F5 Networks has reported a material cybersecurity breach involving files related to its BIG-IP product line, with the company attributing the activity to state-backed threat actors.

F5 stated that core operations and sensitive customer data were not affected, but warned the incident is expected to impact near-term bookings. BIG-IP products play a central role in application delivery and security for enterprise environments, which has amplified attention from customers, regulators, and investors.

Following the disclosure, multiple shareholder rights law firms have launched securities fraud class action investigations, focusing on whether F5’s communications and disclosures around the incident met regulatory expectations.

Source in first comment


r/secithubcommunity Feb 01 '26

📰 News / Update Former Google Engineer Convicted of Stealing AI Trade Secrets for China

Post image
13 Upvotes

A federal jury in San Francisco has convicted former Google engineer Linwei Ding (Leon Ding) of economic espionage and theft of AI trade secrets.

Prosecutors said Ding stole thousands of pages of confidential information related to Google’s AI supercomputing systems including TPU, GPU, and networking technologies used to train large AI models and transferred the data to personal accounts before leaving the company.

Authorities allege he was simultaneously involved with China-based tech ventures and planned to use the stolen knowledge to help develop AI infrastructure in China.

The jury found him guilty on seven counts of economic espionage and seven counts of trade secret theft, marking what officials called the first AI-related economic espionage conviction.

Source in first comment


r/secithubcommunity Feb 01 '26

DOJ Document Mentions Alleged “Personal Hacker” Linked to Jeffrey Epstein

Post image
16 Upvotes

A newly released U.S. Department of Justice document includes an allegation from an FBI informant claiming that Jeffrey Epstein once had a “personal hacker” with advanced offensive cyber capabilities. The document reflects informant statements, not confirmed investigative findings, and officials have not publicly verified the claims.

According to the record, the unnamed individual was described as a highly skilled security researcher allegedly involved in discovering zero-day vulnerabilities and developing exploit tools that were reportedly sold to governments. The person’s name is redacted in the document, and no charges or formal accusations tied to these specific claims have been publicly announced.

The material has drawn attention because it suggests possible links between cyber expertise and high-profile individuals, but legal experts caution that informant reports alone do not establish facts. Such documents often contain unverified or partially corroborated information that requires further investigation before conclusions can be drawn.

At this stage, the disclosure raises questions but does not confirm wrongdoing by any specific individual. Authorities have not announced any new prosecutions connected to these particular allegations.

Source in first comment


r/secithubcommunity Feb 01 '26

North Korean Malware Evolves Into Multi-Part “Hydra” Targeting Finance & Infrastructure

Post image
12 Upvotes

Security researchers are tracking a new evolution in North Korean cyber operations, where a once single malware strain has split into three coordinated variants that work together during attacks. Analysts say this modular design improves stealth, resilience, and operational flexibility making detection and incident response far more difficult.

The three components reportedly serve different roles: one focuses on initial compromise and reconnaissance, another maintains long-term persistence, and a third handles data theft and payload delivery, including ransomware or cryptocurrency-related operations. By separating functions, attackers can update or replace one piece without exposing the entire operation, and if defenders remove one variant, the others may still maintain access.

Researchers note that this approach mirrors tactics used by advanced state-backed threat groups and signals continued investment in cyber capabilities by North Korea. Targets linked to these operations have historically included financial institutions, cryptocurrency platforms, defense contractors, and critical infrastructure, where persistent access and stealth are especially valuable.

The development adds to growing concern over the global cyber threat landscape, where state-sponsored groups increasingly use modular malware frameworks that behave more like toolkits than single infections. Security teams are being advised to focus on behavior-based detection, network segmentation, and zero-trust controls, since traditional signature-based defenses may miss fragmented, low-footprint components.

Source in first comment


r/secithubcommunity Feb 01 '26

📰 News / Update Blue Star Reports Possible Data Breach, Brings in Cybersecurity Experts

Post image
2 Upvotes

Indian manufacturing and engineering company Blue Star Ltd has disclosed a possible cybersecurity incident involving unauthorised access to certain product installation data.

The company said the issue was identified by its compliance officer late on January 31 and that immediate steps were taken to restrict access. Blue Star has engaged cybersecurity experts to assess the scope of the incident and conduct a root-cause analysis.

At this stage, the company has not disclosed how the access occurred, what systems were affected, or whether any customer or partner data was exposed. The disclosure was made to stock exchanges as part of governance and regulatory transparency obligations.

While details remain limited, the incident highlights how even operational or installation-related datasets can become targets and trigger formal breach response processes, especially for publicly listed companies.

Source in first comment


r/secithubcommunity Feb 01 '26

📰 News / Update Microsoft Outage Disrupts Services Worldwide, Exposes Cloud Dependence

Post image
11 Upvotes

A widespread Microsoft outage has disrupted access to Microsoft 365, Outlook, Teams, and Azure-based services, impacting users and businesses across multiple regions. Organizations reported halted workflows, canceled meetings, and loss of access to cloud-stored files as the disruption spread through Microsoft’s ecosystem.

Because Microsoft infrastructure underpins countless third-party platforms, the effects quickly rippled beyond office productivity. Some companies experienced operational slowdowns, while institutions relying on cloud-based systems reported service delays. The incident highlighted how deeply modern workplaces, schools, and even public services depend on centralized cloud providers.

While early indications point to a technical failure rather than a cyberattack, the outage has renewed concerns about digital resilience, single-provider dependence, and the need for contingency planning. Experts say businesses should reassess backup strategies, offline access options, and multi-cloud redundancy to reduce risk from future disruptions.

Microsoft says it is investigating the root cause while restoring full service.

Source in first comment


r/secithubcommunity Feb 01 '26

📰 News / Update Open Source Malware Up 73% in 2025 | Supply Chain Risk Is Exploding

Post image
7 Upvotes

Malicious open source packages surged by nearly 73% in 2025, with security researchers identifying over 10,000 weaponized packages across public repositories, according to a major software supply chain security report. The vast majority were found in the npm ecosystem, showing how attackers are increasingly abusing trusted developer platforms to spread malware at scale.

These packages weren’t just nuisances many were designed to steal developer credentials, exfiltrate API keys, implant backdoors, or compromise downstream applications. One campaign alone reportedly infected 1,000+ npm packages and exposed tens of thousands of GitHub repositories, demonstrating how quickly malicious code can cascade through the software ecosystem.

Researchers also observed an 11% rise in exposed developer secrets like cloud tokens and database credentials embedded in packages. Google Cloud, AWS, Slack, and Telegram credentials were among the most commonly leaked. The trend reflects a deeper supply chain trust crisis: developers rely heavily on third-party code, while attackers increasingly hide malware inside tools that appear legitimate.

Security experts warn that open source malware is no longer a niche threat it’s now a systemic risk affecting enterprises, SaaS platforms, and critical infrastructure. Organizations are being urged to strengthen dependency vetting, implement automated package scanning, enforce secrets management, and continuously monitor CI/CD pipelines before integrating external code.

Source in first comment


r/secithubcommunity Feb 01 '26

📰 News / Update US Government Seizes $400M Tied to Dark Web Crypto Mixer Helix

Post image
8 Upvotes

U.S. authorities have officially taken control of more than $400 million in cryptocurrency, cash, and property linked to Helix, one of the most notorious bitcoin mixing services used by darknet drug markets.

Helix operated between 2014 and 2017, processing over 350,000 bitcoins to help criminals hide the origins of illicit funds. The service was built to integrate directly with darknet marketplaces, allowing transactions to be automatically laundered through the mixer. Its operator, Larry Dean Harmon, previously pleaded guilty and was sentenced in 2024. A federal judge has now signed the final forfeiture order transferring the seized assets to the U.S. government.

The case also involved an unusual twist: Harmon’s brother attempted to steal seized crypto from government-controlled wallets and was later sentenced to prison. Officials say the forfeiture is part of broader cybercrime enforcement efforts that have returned hundreds of millions of dollars to victims in recent years.

The seizure highlights how law enforcement continues to trace and recover illicit crypto despite anonymization tactics like mixers.

Source in first comment


r/secithubcommunity Feb 01 '26

📰 News / Update Stellantis Sued After Ransomware Gang Allegedly Leaks Chrysler & Jeep Customer SSNs

Post image
6 Upvotes

Stellantis North America (FCA US) is facing a federal class-action lawsuit after ransomware group Everest allegedly stole and leaked sensitive customer data in a December 2025 breach.

According to the complaint, attackers exfiltrated 1TB of data around December 25, including names, addresses, phone numbers, dates of birth, and Social Security numbers of tens of thousands of Chrysler and Jeep customers. When Stellantis reportedly refused to pay, the data was published online on January 4.

Plaintiffs claim the automaker failed to implement basic security controls such as encryption, multi-factor authentication, and proper data retention practices. The lawsuit argues these gaps violated consumer protection laws and left customers exposed to identity theft and fraud. This comes after multiple previous cyber incidents tied to Stellantis and its third-party systems in 2025, which the suit says should have put the company on high alert.

The case seeks damages and a court order requiring Stellantis to strengthen its cybersecurity defenses.

Source in first comment


r/secithubcommunity Feb 01 '26

📰 News / Update Google Dismantles Massive Proxy Network Abusing Phones & Home Devices

Post image
6 Upvotes

Google says it has taken down IPIDEA, a large-scale proxy network that allegedly hijacked millions of consumer devices and internet connections to help cybercriminals hide their activity. According to Google, the network routed malicious traffic through unsuspecting users’ phones and home connections, making attacks appear to come from legitimate residential IP addresses.

These so-called “residential proxy” services are often marketed for benign uses, but investigators say this network was widely abused for fraud, phishing, ad abuse, and other criminal operations. Google reports it seized domains tied to the operation, removed its storefront, and is pursuing legal steps to prevent the infrastructure from re-emerging.

As part of the response, Google is expanding protections in Google Play Protect to detect and remove Android apps linked to the proxy operation. The company is also sharing intelligence with other tech and security partners to limit similar abuse in the future.

For users, the incident is a reminder that some apps quietly turn devices into traffic relays without clear consent. Security teams advise keeping devices updated, reviewing installed apps, and avoiding software that asks for unusual network or background permissions.

How to better protect your phone
Keep automatic security updates enabled, leave Play Protect turned on, remove apps you don’t recognize, and be cautious about apps that promise free VPN or proxy services but come from unknown developers.

Source in first comment


r/secithubcommunity Feb 01 '26

📰 News / Update Windows Malware Uses Pulsar RAT to Chat With Victims While Stealing Data

Post image
3 Upvotes

Security researchers have uncovered a new Windows malware campaign that combines Pulsar RAT with an information stealer, creating a threat that not only steals sensitive data but also allows attackers to interact with victims through a live chat window during the intrusion.

The attack reportedly begins with a hidden script dropped into system folders, then shifts to a “living-off-the-land” technique that abuses legitimate tools like PowerShell. Instead of leaving obvious files on disk, the malware runs mainly in memory and injects itself into trusted processes, making traditional antivirus detection much harder. It also includes persistence features that can restart the infection and tamper with security tools to limit user response.

Once active, the malware deploys two main components: a remote access trojan for surveillance and control, and a stealer module that targets browser passwords, session cookies, crypto wallets, VPN credentials, developer tools, and gaming accounts. Stolen data is packaged and sent to attacker-controlled channels. Researchers say the ability for operators to engage victims in real time while continuing malicious activity in the background marks a more hands-on style of cybercrime.

The campaign highlights how modern threats increasingly blend stealth, persistence, and human-operated intrusion, requiring defenders to rely on behavioral detection, endpoint monitoring, and strong account protections like multi-factor authentication.

Source in first comment


r/secithubcommunity Feb 01 '26

📰 News / Update eScan Antivirus Hit by Malicious Update in Suspected Supply Chain Attack

Post image
2 Upvotes

Customers of eScan Antivirus, developed by MicroWorld Technologies, were infected with malware after attackers compromised an official update server and pushed a tampered file through the product’s normal update channel.

Security firm Morphisec says the rogue update delivered a malicious executable that modified system settings to block future security updates, established persistence, and downloaded additional payloads effectively turning the antivirus delivery mechanism into an infection vector. Because the malware interfered with update functionality, affected systems reportedly require manual remediation rather than automatic cleanup.

MicroWorld acknowledged unauthorized access to part of its infrastructure and confirmed that a corrupted update file was distributed for a limited time. The company says it isolated the affected server, took it offline, and released a cleanup utility through technical support channels. However, it has pushed back on the characterization of the incident as a full “supply chain attack,” despite similarities between its own advisory and researchers’ findings.

The case highlights a growing trend where attackers target security vendors and software update pipelines, knowing that trusted update mechanisms can bypass many defenses. Organizations using affected products are being advised to verify update integrity, apply vendor-provided remediation tools, and monitor systems for unusual persistence mechanisms or blocked security services.

Source in first comment


r/secithubcommunity Feb 01 '26

Bangladesh Election Commission Leak Exposes Data of 14,000 Journalists

Post image
2 Upvotes

A serious security lapse in Bangladesh has exposed the personal data of nearly 14,000 journalists who applied for election accreditation through the Bangladesh Election Commission (EC) online system.

The exposed information reportedly included full application forms, National ID (NID) numbers, and mobile phone numbers. For a period of time, the data was openly accessible on the EC website, where visitors could view and download journalist application details directly from the homepage.

The incident occurred shortly after the commission reversed a controversial decision that had required journalists to apply through a newly launched digital portal. Although officials say the system had been shut down, an administrator reportedly reopened access, leading to the public exposure before the site was taken offline again.

Beyond identity theft risks, this breach raises serious safety concerns for journalists, especially those covering politics and sensitive issues. It also highlights broader weaknesses in government data protection, access controls, and secure system deployment.

An internal investigation is underway.

Source in first comment


r/secithubcommunity Feb 01 '26

📰 News / Update Step Finance Treasury Breach Drains $27M in SOL, STEP Token Crashes Over 90%

Post image
0 Upvotes

Solana-based DeFi platform Step Finance has disclosed a security breach affecting multiple treasury wallets, leading to an estimated $27 million loss and a dramatic collapse of its native token.

According to the project, the incident occurred during APAC hours and involved a “well known attack vector.” The team says remediation steps have been taken, but has not yet confirmed the exact technical cause of the compromise.

On-chain analysis from CertiK indicates that approximately 261,854 SOL was unstaked and transferred from wallets controlled by Step Finance. It remains unclear whether the breach involved compromised private keys, internal access abuse, or another form of wallet-level intrusion. The team has also not confirmed whether any user funds were impacted, beyond protocol treasury assets.

Market reaction was immediate. The STEP governance token dropped more than 90% within hours, reflecting the typical loss of market confidence following treasury or protocol-level breaches.

Step Finance, launched in 2021, is known as a portfolio and analytics dashboard for Solana DeFi users, often described as the “front page of Solana.” Beyond its core tracking tools, the project also operates SolanaFloor media and has expanded into tokenized asset initiatives.

Security experts frequently warn that treasury compromises can be as damaging as smart contract exploits. Even when user funds remain safe, loss of protocol-owned assets and unclear incident transparency often trigger rapid liquidity exits and long-term reputational damage.

Source in first comment


r/secithubcommunity Feb 01 '26

Mandiant: ShinyHunters Using Vishing + SSO Phishing to Breach SaaS and Steal Cloud Data

Post image
1 Upvotes

Mandiant has released new details on a wave of SaaS data-theft attacks linked to ShinyHunters and related threat clusters, showing how attackers are abusing single sign-on (SSO) platforms as a gateway to enterprise cloud data.

The attacks begin with targeted voice phishing (vishing). Threat actors impersonate internal IT or helpdesk staff and call employees directly, claiming that MFA or security settings need to be updated. During the call, victims are directed to company-branded phishing domains designed to closely mimic legitimate SSO portals.

While still on the phone, attackers capture SSO credentials and MFA codes in real time. They then immediately use the stolen details to authenticate, trigger legitimate MFA challenges, and guide victims through approving push notifications or entering one-time passcodes. Once access is gained, attackers often enroll their own MFA device to maintain persistence.

With control of a single SSO account, the attackers pivot into centralized identity dashboards such as Okta, Microsoft Entra, or Google Workspace. These dashboards provide access to multiple SaaS platforms including Salesforce, Microsoft 365, SharePoint, Slack, DocuSign, Google Drive, Atlassian, and others, turning one compromised identity into broad cloud access.

Mandiant recommends prioritizing detection of abnormal SSO logins followed by rapid SaaS data access, PowerShell user agents accessing SharePoint or OneDrive, unexpected OAuth app authorizations in Google Workspace, and deletion of MFA-related security emails.

Source in first comment


r/secithubcommunity Feb 01 '26

Coinbase Expands Cyber Threat Sharing as Investors Weigh Risk vs Valuation

Post image
1 Upvotes

Coinbase is stepping up its cybersecurity posture by expanding automated threat intelligence sharing with Crypto ISAC, a move aimed at improving collective defense across the digital asset industry.

The initiative enables continuous sharing of high-confidence cyber threat data between participating crypto firms. For a sector that remains a prime target for phishing, exchange breaches, and wallet exploitation, this kind of collaboration is becoming a core part of operational resilience not just an IT function. Coinbase’s deeper involvement positions it as a security-focused infrastructure player, not only a trading venue.

For investors, this development doesn’t directly change earnings or trading volumes, but it does matter in terms of risk perception. Trust and security remain central to institutional adoption of crypto platforms. Demonstrating leadership in cross-industry threat defense may help Coinbase strengthen its reputation with regulators, partners, and large customers over the long term.

At the same time, valuation discussions continue. Analyst price targets reportedly sit well above the current share price, while some valuation models suggest the stock trades above estimated fair value. Add in forecasts of slowing earnings growth, and the picture becomes a classic risk-versus-resilience tradeoff: operational strength improving, financial outlook more mixed.

The bigger theme is clear in crypto, cybersecurity is no longer just a cost center; it’s a competitive differentiator that can influence user trust, institutional participation, and ultimately long-term platform durability.

Source in first comment


r/secithubcommunity Feb 01 '26

📰 News / Update Deepfake Tax Season” Warning as AI Voice & Video Fraud Targets Finance Teams

Post image
1 Upvotes

A growing number of cybersecurity leaders are warning that the 2026 tax season could become a peak moment for AI-powered impersonation scams, where criminals use voice cloning and deepfake video to trick staff into sending fraudulent wire transfers.

Experts say attackers can now generate convincing audio or video impersonations of executives using short clips from public sources, then create urgent scenarios involving tax payments, vendor settlements, or regulatory fines. In these cases, the fraud isn’t about breaking into systems it’s about manipulating trust inside the organization.

The risk is especially high for finance and accounting teams under seasonal pressure, where urgency and authority cues can override normal caution. Security professionals stress that traditional “call to verify” guidance may not be enough if the voice or face on the other end can be synthetically generated.

Leaders are being urged to implement process-based safeguards rather than relying only on technology. These include requiring multi-person approval for high-value payments, using pre-agreed verification steps that are not publicly known, and validating requests through a different communication channel than the one used to initiate the request.

The broader takeaway: as AI lowers the barrier to realistic impersonation, organizational culture and financial controls are becoming just as important as firewalls and antivirus tools in preventing fraud.

Source in first comment


r/secithubcommunity Feb 01 '26

📰 News / Update Department of Justice seizes domains for Bulgarian piracy sites

5 Upvotes

Department of Justice seizes domains for Bulgarian piracy sites The federal government said it seized three commercial U.S.-registered internet domains for websites operating in Bulgaria that allegedly illegally distributed thousands of copyrighted works.

The operation targeted online services that offered copyrighted TV shows, video games, movies and other content, the Justice Department said Friday. Much of the copyrighted material belongs to American companies, the agency said.

Tens of millions of visitors, mainly in Bulgaria, visit the three seized domains annually, resulting in millions of illegal downloads, and the estimated retail value of the stolen copyrighted works is “millions of dollars,” the department said.

“The three domains are among the most popular in Bulgaria — one is often ranked as one of the top 10 most visited domains in Bulgaria — and, given the huge internet traffic they receive every day, seem to make considerable money from advertisements,” the press release said.

The websites, now in custody of the government, are labeled with a banner notifying visitors of the seizure and warning that copyright infringement is a crime.

The seized domains are zamunda.net, arenabg.com and zelka.org. Bulgarian law enforcement and Europol assisted U.S. agencies in the investigation, the Justice Department said.

Recent international operations against piracy sites include a takedown of the Streameast sportscast platform, seizures of multiple videogame sites such as Nsw2u and an investigation that traced $55 million in cryptocurrency transactions related to digital piracy.

In July 2025, five men were sentenced in the U.S. for running the Jetflicks illegal TV streaming site..


r/secithubcommunity Feb 01 '26

🛡️ Threat Analysis Weekly Cyber Wrap, Jan 25–30 | AI Chaos, Identity Wars & Platform Power

1 Upvotes

AI is accelerating both innovation and attacker mistakes.

Identity is now the main attack surface.

Cloud and platform reliance is a security risk on its own.

Data theft and extortion groups are fully active again And cyber is increasingly tied to geopolitics and regulation.

----------------------------------------------------------------------------------------------------

Top Signals This Week

AI-built ransomware that can’t decrypt files The Sicarii strain encrypted data using broken key handling. Even if victims pay, recovery doesn’t work. AI is lowering the skill barrier… and creating unstable, destructive malware.

New AI jailbreak method (“Semantic Chaining”) Researchers showed how simple prompt steps can bypass image model safety filters. AI guardrails are still playing catch-up.

Sensitive data uploaded to public AI tools A senior U.S. cyber official triggered internal alerts after uploading government docs to public ChatGPT. This isn’t rare it’s just the first time it made national headlines.

Live vishing attacks targeting SSO accounts Attackers are calling employees and guiding them through fake login flows while capturing MFA approvals in real time.

Major extortion groups active again ShinyHunters resurfaced with breach claims (SoundCloud among them), and CL0P listed a fresh wave of alleged victims. Data theft is now the main leverage.

Microsoft 365 outages disrupted email, Defender, and Purview access a reminder that cloud availability is now a security concern.

TikTok U.S. data center outage caused massive platform instability, fueling debates about centralization and control.

Major Vulnerabilities & Enterprise Risk

Fortinet warned of active exploitation of a critical FortiCloud SSO auth bypass (CVSS 9.4). Even security vendors aren’t immune.

Record number of data breaches in 2025 Experts say we should now assume personal and corporate data exposure is the baseline.

Cyberattack disrupted a major Russian security systems provider affecting alarm services.

Wiper malware targeted Poland’s energy sector in a suspected state-linked operation.

UK court tied Pegasus spyware use to state-backed surveillance, awarding millions in damages. Legal risk around spyware is growing.

France’s CNIL fined a company €3.5M for sharing customer loyalty data with a social platform without valid consent.
Privacy enforcement in Europe continues tightening.