Fraud Alerts & Scam News

Official warnings from government agencies worldwide, updated daily.

Last updated: 2026-07-21 06:00 UTC — 1321 alerts in database
🇺🇸 FTC 🇺🇸 FBI IC3 🇬🇧 Action Fraud 🇦🇺 ScamWatch 🔐 Krebs
Latest Alerts
None General
Estée Lauder discloses data breach via Oracle E-Business flaw

Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operat...

None General
SonicWall SMA1000 flaws exploited as zero-days to push custom malware

Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances...

None Crypto
Hackers steal $23.7 million in crypto from Ostium in off-chain attack

The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed pr...

None General
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes

Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Goo...

None General
JadePuffer agentic attacks now target AI model data with ransomware

The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model che...

🔍 CyberScoop General
Director of Commerce AI standards office out after three months

The Center for AI Standards and Innovation has quietly become a key hub for the federal government to assess potential threats and harms that AI systems pose. The post Director of ...

None General
New HollowGraph malware uses Microsoft Graph for stealthy C2 comms

A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltra...

🛡️ SecurityWeek General
Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software

Neo raised money across seed and Series A funding rounds from Andreessen Horowitz, Bessemer Venture Partners, and others. The post Neo Emerges From Stealth With $100M to Control an...

🔍 CyberScoop General
Why blocking AI models won’t stop the cyber threats they create

AI companies can find vulnerabilities and write patches. But only the government can build the long-term defense strategy America needs. The post Why blocking AI models won’t...

🛡️ SecurityWeek General
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533. The post SonicWall Zero-Days Exploited to Deliver Custom Malware fo...

None General
An AI SOC Evaluation Guide for Security Leaders

Choosing an AI SOC platform requires understanding how it will perform in your own environment, not just during an evaluation. Prophet Security shares a practical framework for ass...

🛡️ SecurityWeek General
OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability

Attackers could send waves of malicious payloads to trigger buffer pre-allocations that are not freed, exhausting server memory. The post OpenSSL Silently Fixes ‘HollowByte&#...

None General
Hugging Face warns an autonomous AI agent hacked its network

The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using ...

🛡️ SecurityWeek General
New Index Tracks Material Breaches — And Refuses to Add Up the Losses

Longtime cybersecurity executive Richard Bird built the resource for security experts, journalists, policymakers, and everyday citizens. The post New Index Tracks Material Breaches...

🛡️ SecurityWeek General
Ernst & Young Data Breach Affects Personal, Financial Information

Hackers stole names, addresses, Social Security numbers, credit/debit card numbers, and other information from a third-party management platform. The post Ernst & Young Data B...

None General
Microsoft confirms Windows Server Update Services sync delays

Microsoft is working to fix a known issue affecting Windows Server Update Services (WSUS) servers, which has caused synchronization problems for more than a week. [...]

🛡️ SecurityWeek General
Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool

The agentic security tool identifies potentially exploitable code flaws, traces attack paths, and recommends targeted remediations. The post Capital One Open Sources AI-Powered ‘Vu...

None General
Windows KB5121767 OOB update fixes shutdowns on some Dell PCs

Microsoft has released emergency updates to fix a known issue causing some Dell PCs to shut down after installing the July 2026 Windows 11 security updates. [...]

🛡️ SecurityWeek General
Hugging Face Hacked in Autonomous AI Attack

Targeting production infrastructure, the attack compromised internal datasets and service credentials. The post Hugging Face Hacked in Autonomous AI Attack appeared first on Securi...

None General
Critical ServiceNow code execution flaw now exploited in attacks

Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. [...]

🛡️ SecurityWeek General
Chrome 150 Update Patches Severe Memory Safety Bugs

The fresh security update resolves six critical and high-severity use-after-free vulnerabilities. The post Chrome 150 Update Patches Severe Memory Safety Bugs appeared first on Sec...

🛡️ SecurityWeek General
WP2Shell WordPress Vulnerabilities Exploited in the Wild

Exploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure. The post WP2Shell WordPress Vulnerabilities Exploited ...

Банки Юга.ру Bank Fraud
Новая схема мошенников: «обновление счёта» в Центробанке — как не лишиться всех денег - Банки Юга.ру

Новая схема мошенников: «обновление счёта» в Центробанке — как не лишиться всех денег  Банки Юга.ру

krasnodar.bz Crypto
Полиция Краснодара предупредила о мошенничестве с криптоинвестициями — Независимое СМИ Кубани - krasnodar.bz

Полиция Краснодара предупредила о мошенничестве с криптоинвестициями — Независимое СМИ Кубани  krasnodar.bz

ad-hoc-news.de Crypto
Steam-Betrug: 8.000 Computer mit Trojaner infiziert, 220.000 Euro gestohlen - ad-hoc-news.de

Steam-Betrug: 8.000 Computer mit Trojaner infiziert, 220.000 Euro gestohlen  ad-hoc-news.de

Anwalt24 Investment
KzipPro – Betrug? Erfahrungen mit der Trading-App - Anwalt24

KzipPro – Betrug? Erfahrungen mit der Trading-App  Anwalt24

Anwalt24 Investment
CSCpro – Betrug? Erfahrungen mit der Trading-App CSCpro - Anwalt24

CSCpro – Betrug? Erfahrungen mit der Trading-App CSCpro  Anwalt24

BornCity Phishing
Phishing-Explosion: Text-Salting umgeht KI-Filter seit April - BornCity

Phishing-Explosion: Text-Salting umgeht KI-Filter seit April  BornCity

WEEX Crypto
Spreadefi: Un análisis más cercano sobre si es una estafa o no - WEEX

Spreadefi: Un análisis más cercano sobre si es una estafa o no  WEEX

None General
Hackers abuse ViPNet software to target Russian govt agencies

An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. [...]

dnepr.express Phishing
Поддельные магазины во время сезонных скидок: как не потерять деньги и данные карты — Днепр оперативный - dnepr.express

Поддельные магазины во время сезонных скидок: как не потерять деньги и данные карты — Днепр оперативный  dnepr.express

El Sol de México Job Scam
El fraude de las ofertas de empleo por WhatsApp - El Sol de México

El fraude de las ofertas de empleo por WhatsApp  El Sol de México

Börse Express Phishing
Phishing-Explosion: SMS-Betrug +162%, QR-Code-Angriffe +146% - Börse Express

Phishing-Explosion: SMS-Betrug +162%, QR-Code-Angriffe +146%  Börse Express

None General
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted com...

Вечерний Санкт-Петербург Job Scam
Петербуржцев предупредили о новой схеме мошенничества с поиском удаленной работы - Вечерний Санкт-Петербург

Петербуржцев предупредили о новой схеме мошенничества с поиском удаленной работы  Вечерний Санкт-Петербург

Портал РЕПОСТ Crypto
Мошенники спрятали вредоносное ПО в бесплатных играх Steam и украли криптовалюту на 220 тысяч долларов - Портал РЕПОСТ

Мошенники спрятали вредоносное ПО в бесплатных играх Steam и украли криптовалюту на 220 тысяч долларов  Портал РЕПОСТ

None General
WordPress Core "wp2shell" RCE flaws get public exploits, patch now

Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their ...

Xataka México Bank Fraud
Una llamada falsa puede vaciar una cuenta en México: las víctimas pierden hasta 50,000 pesos en promedio - Xataka México

Una llamada falsa puede vaciar una cuenta en México: las víctimas pierden hasta 50,000 pesos en promedio  Xataka México

None General
Microsoft warns of surge in ACR Stealer attacks on customers

Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise custom...

Milenio Phishing
¿Conoces el 'whaling'? Secretaría Anticorrupción alerta por este fraude que suplanta a tu jefe - Milenio

¿Conoces el 'whaling'? Secretaría Anticorrupción alerta por este fraude que suplanta a tu jefe  Milenio

None General
The Future of Age Verification: Your Face Never Leaves Your Device

As age verification laws expand worldwide, organizations face growing pressure to protect users' privacy while meeting regulatory requirements. Incode explains how on-device age es...

Techora.ru Phishing
Мошенники атакуют маркетплейсы: фишингом крадут пароли и оформляют кредиты - Techora.ru

Мошенники атакуют маркетплейсы: фишингом крадут пароли и оформляют кредиты  Techora.ru

Anwalt.de Investment
Donze Unlimited ein Betrug via donze-unlimited.com und user.dataflowportal.com? Erfahrungen zur Auszahlung? - Anwalt.de

Donze Unlimited ein Betrug via donze-unlimited.com und user.dataflowportal.com? Erfahrungen zur Auszahlung?  Anwalt.de

Piter.tv Job Scam
Петербуржцев предупредили о мошенничестве под видом удаленной работы - Piter.tv

Петербуржцев предупредили о мошенничестве под видом удаленной работы  Piter.tv

None General
Abbott probes two cyber incidents amid extortion claims

Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics b...

BornCity Crypto
Deepfake-Betrug: 86-Jährige verliert Million Euro an KI-Täuschung - BornCity

Deepfake-Betrug: 86-Jährige verliert Million Euro an KI-Täuschung  BornCity

None General
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload

A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes. [......

🔍 CyberScoop General
State officials, election experts pan Trump speech: ‘This is what desperation looks like’

The president’s speech re-hashed debunked conspiracies around U.S. elections. Critics say the administration’s 18-month investigation into voter fraud has been a total failure.  Th...

None General
Ernst & Young discloses data breach after support system hack

Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel. [...]

🛡️ SecurityWeek General
In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint

Noteworthy stories that might have slipped under the radar: OpenClaw AI agents exploited via WhatsApp, ransomware hits naval defense firm TKMS, Lidl discloses data breach. The post...

🔍 CyberScoop General
Leading members of Scattered Spider sentenced in UK to 66 months in jail

Thalha Jubair and Owen Flowers led and directed many attacks attributed to the hacker subset of The Com. U.S. authorities previously accused Jubair of participating in at least 120...

None General
Inside the Search for "Clean" Residential Proxies for Carding

Residential proxies are no longer the silver bullet they once were for carding. Flare explains why cybercriminals increasingly seek "clean" residential proxies and combine them wit...

Die Rheinpfalz Phishing
Phishing-​Betrug trifft 61-​Jährige: Scha­den in fünf­stel­li­ger Höhe - Die Rheinpfalz

Phishing-​Betrug trifft 61-​Jährige: Scha­den in fünf­stel­li­ger Höhe  Die Rheinpfalz

Национальная Служба Новостей Bank Fraud
Россиянам объяснили, как мошенники звонят с номеров банков - Национальная Служба Новостей

Россиянам объяснили, как мошенники звонят с номеров банков  Национальная Служба Новостей

105'5 Spreeradio Phishing
KI-Chatbots gegen Betrug - 105'5 Spreeradio

KI-Chatbots gegen Betrug  105'5 Spreeradio

DiarioBitcoin Crypto
Florida devuelve USD $710.000 a víctima de fraude cripto en recuperación sin precedentes - DiarioBitcoin

Florida devuelve USD $710.000 a víctima de fraude cripto en recuperación sin precedentes  DiarioBitcoin

🛡️ SecurityWeek General
Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive

(Video) Artificial intelligence is transforming cybersecurity, but are governance, compliance, and security practices evolving fast enough to keep up? The post Podcast: Broken Gove...

🛡️ SecurityWeek General
Beacon Security Raises $13 Million for Security Data Platform

The startup helps organizations detect, hunt, and protect their assets across environments at machine speed. The post Beacon Security Raises $13 Million for Security Data Platform ...

🛡️ SecurityWeek General
Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday

Industry professionals broadly agree that the suspension pauses third-party CMMC audits but not the underlying legal obligation to protect CUI. The post Industry Reactions to Penta...

None General
New Windows LegacyHive zero-day gives hackers admin privileges

A security researcher using the "Nightmare Eclipse" handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Wind...