Fraud Alerts & Scam News

Official warnings from government agencies worldwide, updated daily.

Last updated: 2026-06-05 19:15 UTC — 80 alerts in database
πŸ‡ΊπŸ‡Έ FTC πŸ‡ΊπŸ‡Έ FBI IC3 πŸ‡¬πŸ‡§ Action Fraud πŸ‡¦πŸ‡Ί ScamWatch πŸ” Krebs
Latest Alerts
πŸ›‘οΈ SecurityWeek General
OWASP Incubator Project Helps Developers Find and Fix Vulnerable Dependencies in Seconds

CVE Lite CLI is a free, open-source command line tool that scans your projects in seconds and tells you exactly which included packages contain a vulnerability. The post OWASP Incu...

πŸ” CyberScoop General
Nightmare Eclipse incident shows the researcher-vendor fights may never fully go away

When a researcher went public with Microsoft vulnerabilities, it laid bare a conflict that has never really been solved. The post Nightmare Eclipse incident shows the researcher-ve...

πŸ›‘οΈ SecurityWeek General
In Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISA

Other noteworthy stories that might have slipped under the radar: Ultrahuman data leak, The Gentlemen ransomware analysis, Hola Browser bundles miner. The post In Other News: Anthr...

πŸ›‘οΈ SecurityWeek General
Hackers Leak DentaQuest Information Impacting 2.6 Million

The ShinyHunters extortion group leaked roughly 234 GB of data allegedly stolen from the dental benefits administrator. The post Hackers Leak DentaQuest Information Impacting 2.6 M...

πŸ›‘οΈ SecurityWeek General
Chrome 149 Patches 429 Vulnerabilities

Over 100 bugs are critical or high-severity, mainly use-after-free and insufficient validation of untrusted input flaws. The post Chrome 149 Patches 429 Vulnerabilities appeared fi...

πŸ›‘οΈ SecurityWeek General
Industry Reactions to New Trump AI Cybersecurity Executive Order: Feedback Friday

Experts commented on the EO’s voluntary nature, the balance between innovation and security, and potential implementation gaps. The post Industry Reactions to New Trump AI Cybersec...

πŸ›‘οΈ SecurityWeek General
Five Eyes: Chinese Spies Target Government, Military Staff With Fake Job Opportunities

Posing as recruiters on online platforms, Chinese intelligence officers target personnel with access to classified or privileged information. The post Five Eyes: Chinese Spies Targ...

πŸ›‘οΈ SecurityWeek General
Nightclub Giant RCI Says Data Breach Affects 40,000 Individuals

The company detected a network intrusion in March and an investigation showed that some files were stolen during the attack. The post Nightclub Giant RCI Says Data Breach Affects 4...

πŸ›‘οΈ SecurityWeek General
Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026

The vulnerability is tracked as CVE-2026-20245 and it can allow arbitrary command execution as root, but no patch yet. The post Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026...

πŸ” CyberScoop General
Hill Dems hammer GOP for $250M CISA budget cut

A House Appropriations subcommittee is set to mark up fiscal 2027 DHS funding legislation Friday. The post Hill Dems hammer GOP for $250M CISA budget cut appeared first on CyberSco...

πŸ” CyberScoop General
Your AI agent could become your biggest insider threat

New research details how the increasing integration of AI agents into businesses is making it easier than ever for insiders - malicious or otherwise - to put sensitive data at risk...

πŸ›‘οΈ SecurityWeek General
Offroad Emerges From Stealth With $7 Million to Tackle Enterprise Identity Risk

As AI agents, machine identities, and third-party applications multiply across enterprises, Offroad is betting autonomous security agents can restore control over an increasingly u...

πŸ” CyberScoop General
Inside the race to adapt to an AI-powered security world

AI is breaking things faster than anyone can fix them. Security leaders across the industry are racing to figure out what comes next. The post Inside the race to adapt to an AI-pow...

πŸ›‘οΈ SecurityWeek General
Webinar Today: Third-Party Risk in Practice – Where Programs Break Down and How to Respond

Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice. The post Web...

πŸ” CyberScoop General
European authorities crack down on illegal streaming networks

Officials said they dismantled nine organized crime groups and removed more than 27,000 URLs hosting live sports and other copyrighted media during a seven-month operation. The pos...

πŸ” CyberScoop General
DHS Secretary Markwayne Mullin pinpoints optimal CISA staffing levels

He told lawmakers that he wants approximately 600 more people than it has now, which would still be well below personnel numbers prior to Trump’s second term. The post DHS Secretar...

πŸ”’ ESET General
Lessons for life: Why children’s data is a long-term identity risk

Your child’s first data breach may happen before they’ve even opened a bank account. Here’s how to keep their digital life safe.

πŸ” CyberScoop General
DOD wants to integrate cyber in all operations, and integrate security into AI

Top Pentagon cyber policy official Katherine Sutton said recent conflicts have emphasized the importance of cyber, and that the department can’t make old mistakes with AI security....

πŸ” CyberScoop General
Trump administration releases scaled-back AI executive order

The order β€” which Trump previously refrained from signing at the last minute β€” appears to make significant concessions to industry compared to earlier drafts. The post Trump admini...

πŸ” CyberScoop General
Anthropic expanding access to Project Glasswing

Roughly 150 new organizations across critical infrastructure sectors will gain access to Claude Mythos Preview, Anthropic's most capable β€” and most restricted β€” AI model. The post ...

πŸ” CyberScoop General
Attackers are exploiting Palo Alto Networks defect that initially flew under the radar

The escalated threat posed by the defect showcases how quickly a seemingly mild vulnerability can turn into an urgent warning. The post Attackers are exploiting Palo Alto Networks ...

πŸ” Krebs General
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, a...

πŸ”’ ESET General
This month in security with Tony Anscombe – May 2026 edition

In this roundup, Tony looks at attacks against Polish water treatment facilities, how AI-directed attacks failed in Mexico, and what Google believes is the first AI-generated zero-...

πŸ”’ ESET General
ESET APT Activity Report Q4 2025–Q1 2026

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2025 and Q1 2026

πŸ”’ ESET General
What to consider before asking an AI chatbot for health advice

Using chatbots for medical advice could elicit hallucinations and even expose you to security and privacy risks. Here’s what’s at stake and how to stay safe.

πŸ”’ ESET Tech Support
BTMOB: A stealthy RAT burrowing deep into Android devices

The malware pairs remote access capabilities with ready-made campaign tools, lowering the barrier for full device compromise

πŸ” Krebs General
Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks

Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influ...

πŸ” Krebs General
Lawmakers Demand Answers as CISA Tries to Contain Data Leak

Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a ...

πŸ”’ ESET General
Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise

Watch out for bogus World Cup websites that mimic official ticket and merchandise flows to steal money and personal data

πŸ” Krebs General
Alleged Kimwolf Botmaster β€˜Dort’ Arrested, Charged in U.S. and Canada

Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved million...

πŸ”’ ESET General
Webworm: New burrowing techniques

ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal

πŸ”’ ESET General
The quest for greater tech independence

A complete decoupling from US technology is neither realistic nor necessary, but the changing environment does require nations and companies to reassess their relationships and dep...

πŸ” Krebs General
CISA Admin Leaked AWS GovCloud Keys on Github

Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several h...

πŸ”’ ESET General
Why geopolitical turmoil is a gift for scammers, and how to stay safe

Conflict is a boon for opportunistic fraudsters. Look out for their ploys.

πŸ”’ ESET General
FrostyNeighbor: Fresh mischief and digital shenanigans

ESET researchers uncovered new activities attributed to FrostyNeighbor, updating its compromise chain to support the group’s continual cyberespionage operations

πŸ” Krebs General
Patch Tuesday, May 2026 Edition

Artificial intelligence platforms may be just as susceptible to social engineering as human beings, but they are proving remarkably good at finding security vulnerabilities in huma...

πŸ”’ ESET General
Eyes wide open: How to mitigate the security and privacy risks of smart glasses

Smart glasses allow anyone to track and record the world around them. That could put your data and the privacy of those nearby at risk.

πŸ” Krebs General
Canvas Breach Disrupts Schools & Colleges Nationwide

An ongoing data extortion attack targeting the widely-used education technology platform Canvas disrupted classes and coursework at school districts and universities across the Uni...

πŸ”’ ESET General
Fake call logs, real payments: How CallPhantom tricks Android users

ESET researchers uncovered fraudulent apps on Google Play that claim to provide the call history β€œfor any number” and had been downloaded more than seven million times before being...

πŸ”’ ESET General
Fixing the password problem is as easy as 123456

How come it’s still possible to β€˜secure’ an online account with a six-digit string?

πŸ”’ ESET General
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack

ESET researchers have investigated an ongoing attack by the ScarCruft APT group that targets the Yanbian region via backdoor-laced Windows and Android games

πŸ” Krebs General
Anti-DDoS Firm Heaped Attacks on Brazilian ISPs

A Brazilian tech firm that specializes in protecting networks from distributed denial-of-service (DDoS) attacks has been enabling a botnet responsible for an extended campaign of m...

πŸ”’ ESET General
This month in security with Tony Anscombe – April 2026 edition

Warnings about helpdesk impersonation scams and Iran-linked hackers targeting critical sectors in the US, plus the most damaging scams of 2025 - here's some of what made the headli...

πŸ”’ ESET General
The calm before the ransom: What you see is not all there is

A breach claims the systems as well as the confidence that was, in retrospect, a major vulnerability

πŸ”’ ESET General
GopherWhisper: A burrow full of malware

ESET Research has discovered a new China-aligned APT group that we’ve named GopherWhisper, which targets Mongolian governmental institutions

πŸ” Krebs Crypto
β€˜Scattered Spider’ Member β€˜Tylerb’ Pleads Guilty

A 24-year-old British national and senior member of the cybercrime group "Scattered Spider" has pleaded guilty to wire fraud conspiracy and aggravated identity theft. Tyler Robert ...

πŸ”’ ESET General
New NGate variant hides in a trojanized NFC payment app

ESET researchers discover another iteration of NGate malware, this time possibly developed with the assistance of AI

πŸ”’ ESET General
What the ransom note won’t say

An attack is what you see, but a business operation is what you’re up against

πŸ”’ ESET General
That data breach alert might be a trap

Ignoring a real breach notification invites risk, but falling for a bogus one could be even worse. Stop reacting on autopilot.

πŸ” Krebs General
Patch Tuesday, April 2026 Edition

Microsoft today pushed software updates to fix a staggering 167 security vulnerabilities in its Windows operating systems and related software, including a SharePoint Server zero-d...

⚠️ Threatpost General
Student Loan Breach Exposes 2.5M Records

2.5 million people were affected, in a breach that could spell more trouble down the line.

⚠️ Threatpost General
Watering Hole Attacks Push ScanBox Keylogger

Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.

⚠️ Threatpost Phishing
Tentacles of β€˜0ktapus’ Threat Group Victimize 130 Firms

Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.

⚠️ Threatpost General
Ransomware Attacks are on the Rise

Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.

⚠️ Threatpost General
Cybercriminals Are Selling Access to Chinese Surveillance Cameras

Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.

⚠️ Threatpost General
Twitter Whistleblower Complaint: The TL;DR Version

Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk.

⚠️ Threatpost General
Firewall Bug Under Active Attack Triggers CISA Warning

CISA is warning that Palo Alto Networks’ PAN-OS is under active attack and needs to be patched ASAP.

⚠️ Threatpost General
Fake Reservation Links Prey on Weary Travelers

Fake travel reservations are exacting more pain from the travel weary, already dealing with the misery of canceled flights and overbooked hotels.

⚠️ Threatpost General
iPhone Users Urged to Update to Patch 2 Zero-Days

Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack.

⚠️ Threatpost General
Google Patches Chrome’s Fifth Zero-Day of the Year

An insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack.