Fraud Alerts & Scam News

Official warnings from government agencies worldwide, updated daily.

Last updated: 2026-09-04 06:00 UTC — 3181 alerts in database
🇺🇸 FTC 🇺🇸 FBI IC3 🇬🇧 Action Fraud 🇦🇺 ScamWatch 🔐 Krebs
Latest Alerts
🔍 CyberScoop General
Attackers exploit zero-days in consistently besieged SonicWall product

SonicWall customers have confronted a barrage of attacks for years, including five actively exploited vulnerabilities in SMA 1000 appliances since late 2025. The post Attackers exp...

None General
French hospital fined €500,000 after breach exposes data of 727,000

France's data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for failing to adequately protect patients' and their relatives' data. [...]

None General
Coder's registry infrastructure compromised to push malicious modules

Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code. [......

🔍 CyberScoop General
The G7 tells industry to hurry up and prep for post-quantum encryption

The nations warn that governments and industry can no longer treat quantum codebreaking as a distant or theoretical possibility. The post The G7 tells industry to hurry up and prep...

None General
HPE patches critical ArubaOS-CX remote code execution flaw

Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. [...]

🛡️ SecurityWeek General
Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal

Hacker group published roughly 550GB of data after MAG reportedly refused to pay a ransom demand; the group says it gained access via exposed admin keys. The post Manchester Airpor...

None General
Microsoft: KB5120998 mouse reset bug affects only non-English PCs

Microsoft says a known issue that reverts mouse settings after installing the KB5120998 August 2026 preview update affects only non-English Windows 11 systems. [...]

🛡️ SecurityWeek General
Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents

New models, trained using NVIDIA Nemotron 3 Ultra, aim to catch rogue agent behavior before it executes, without the latency of large-model review. The post Capsule Security Launch...

None General
OpenAI confirms ChatGPT is down ahead of 'Astra' model launch

ChatGPT and Codex are experiencing a major outage, with users reporting errors across nearly every major ChatGPT feature. [...]

None General
Anthropic confirms Claude is down, multiple models affected

Claude is experiencing an outage, with users encountering elevated errors when sending requests to multiple Anthropic AI models. [...]

None General
Critical Elementor Pro flaw exploited to take over WordPress sites

A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbit...

None General
Your Employee’s Password Appeared in an Infostealer Log. Now What?

Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identit...

🛡️ SecurityWeek General
HiddenLayer Raises $100 Million for AI Runtime Security

The Austin-based company will invest in agentic runtime security capabilities to secure AI coding agents. The post HiddenLayer Raises $100 Million for AI Runtime Security appeared ...

None General
Microsoft says KB5120998 Windows update resets desktop settings

Microsoft has confirmed that desktop settings are lost or reset on some Windows devices after installing the KB5120998 August 2026 preview update. [...]

🛡️ SecurityWeek General
AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million

The startup’s firewall evaluates AI skills, plugins and MCP servers for malicious instructions, excessive permissions and software supply chain risks. The post AI Agent Firewall St...

None General
Plex warns users to patch security vulnerabilities immediately

Plex urged users this week to update their desktop clients and media servers immediately to patch multiple security vulnerabilities. [...]

🛡️ SecurityWeek General
153 Million Driver License Images Offered on Dark Web

Cybercriminals are offering digital scans of US and Canadian driver’s licenses, likely stolen from IDScan.net. The post 153 Million Driver License Images Offered on Dark Web appear...

🛡️ SecurityWeek General
Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability

The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution. The post Over 3 Million WordPress Sites Affected by Mi...

🛡️ SecurityWeek General
Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities

Publicly disclosed S/MIME flaws could expose encrypted email content, while critical IOS XR and Nexus bugs could enable remote code execution and authentication bypass. The post Ci...

None General
Microsoft Teams, Outlook fail to launch on ARM-based Windows PCs

Microsoft is working to fix a known issue that causes crashes and launch failures for Microsoft Teams and New Outlook users after installing updates released since the August 2026 ...

🔍 CyberScoop General
Jail time for Maine child in 764 marks turning point in federal law enforcement

Researcher tracking 764 said the first-of-its-kind case has a wider impact that will cause ripples across the landscape of violent extremist crime. The post Jail time for Maine chi...

None General
Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. [...]

🛡️ SecurityWeek General
OpenLeash Adds a Human Check to Risky AI Agent Actions

The security tool intercepts potentially dangerous agent actions, blocking clear threats and requesting human approval when intent is uncertain. The post OpenLeash Adds a Human Che...

None General
WordPress backup plugin flaw exposes millions of sites to takeover attacks

An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affec...

🔍 CyberScoop General
The FCC wants consumers to rate their telecom’s anti-robocall protections

The agency also booted 14 phone service providers from U.S. networks for violating existing robocalling regulations. The post The FCC wants consumers to rate their telecom’s anti-r...

🔍 CyberScoop General
Dogged Russia-based botnet dismantled after 23-year run

Sality’s peer-to-peer infrastructure allowed it to evade system-wide disruption efforts for an exceptionally long period. Authorities and cybersecurity experts finally brought it d...

None General
Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access. [...]

🛡️ SecurityWeek General
UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure

Late amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify. The post UK Move...

🔍 CyberScoop General
Pegasus, NoviSpy variant spyware found on devices of Serbian activists

It’s the first Pegasus infection of 2026 that Citizen Lab is forensically confirming, and the SHARE Foundation said it’s the biggest wave of spyware surveillance in Serbia yet. The...

🔍 CyberScoop General
Wyden seeks upgraded NSA security guidance on commercial VPN use

it’s the latest in a sequence of letters to feds from Sen. Ron Wyden, D-Ore., on commercial VPNs. The post Wyden seeks upgraded NSA security guidance on commercial VPN use appeared...

None General
Ransomware protection for MSPs: A 6-point checklist for faster recovery

Ransomware resilience requires more than backups or endpoint detection alone. Acronis outlines six capabilities MSPs should test across client environments, from reducing exposure ...

🛡️ SecurityWeek General
Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products

The industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products. The post Rockwell Automation Patches Over a Dozen Vu...

None General
Dropbox accounts breached through Lenovo email verification flaw

Dropbox is warning some users that an unauthorized party accessed their accounts by exploiting a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs. [......

🛡️ SecurityWeek General
Exploit Published for Fresh Cleo Harmony Vulnerability

The security defect allows remote attackers to bypass authentication through argument bearer manipulation. The post Exploit Published for Fresh Cleo Harmony Vulnerability appeared ...

🛡️ SecurityWeek General
Anthropic Details Response to Security Incidents, Unveils Enterprise Safeguards

Anthropic introduced Enterprise Frontier Safeguards (EFS), a system that combines zero data retention with automated monitoring for misuse. The post Anthropic Details Response to S...

🔒 ESET AI/Deepfake
I’ve been deepfaked: What do I do?

Don’t panic if you spot an illegally created image or video of you online – there are ways to request its removal

🛡️ SecurityWeek General
Malicious Virtualizor Update Served via BGP Hijacking

Using a technically valid TLS certificate for Softaculous’ domains, a threat actor diverted traffic to fake software updates. The post Malicious Virtualizor Update Served via BGP H...

🛡️ SecurityWeek General
OpenAI’s Astra Crosses ‘Critical’ Cyber Threshold After Finding Zero-Days

The designation applies when a model can independently find and exploit zero-day vulnerabilities across many well-defended systems. The post OpenAI’s Astra Crosses ‘Critical’ Cyber...

None General
Microsoft Defender flags legitimate Google search links as malicious

Microsoft is investigating an issue causing the Defender for Office 365 security software to mistakenly block access to legitimate Google search links. [...]

🛡️ SecurityWeek General
Chrome and Firefox Updates Patch Dozens of Vulnerabilities

The browser refreshes fix multiple use-after-free, sandbox escape, and privilege escalation bugs. The post Chrome and Firefox Updates Patch Dozens of Vulnerabilities appeared first...

None Phishing
US charges Russian for infecting 80,000 freelancers with malware

A California federal grand jury has indicted a Russian national for his role in a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware. [...]

🛡️ SecurityWeek General
23-Year-Old Sality P2P Botnet Disrupted

The shutdown operation involved peer list manipulation and Sality payload URL takedown. The post 23-Year-Old Sality P2P Botnet Disrupted appeared first on SecurityWeek.

None General
Sality botnet infrastructure dismantled in joint global takedown

International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botne...

None General
SonicWall warns of actively exploited SMA1000 zero-day flaws

SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. [...]

🛡️ SecurityWeek General
SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks

The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution. The post SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attac...

🔐 Krebs General
FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Base...

🔍 CyberScoop Phishing
FBI raises alarm over deceptive phishing campaign targeting prominent people

The ongoing social engineering threat, which dates back to late 2025, tricks victims into granting threat actors long-term access to their accounts. The post FBI raises alarm over ...

None Phishing
Hackers abuse Faronics Deploy admin tool to install ScreenConnect

Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect re...

🛡️ SecurityWeek General
Palo Alto Networks Acquires AI Agent Platform Console

The cybersecurity giant announced the acquisition alongside quarterly results showing a 34% increase in revenue and strong growth in next-generation security ARR. The post Palo Alt...

🔍 CyberScoop General
Tina Peters, through attorney, backs off formal role in Shasta County elections

Peters still left the door open to working with Shasta County on elections and doubled down on her statements that electronic voting machines should be discontinued. The post Tina ...

None General
Aesto Health says data breach affects over 9.5 million patients

Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. [...]

🛡️ SecurityWeek General
Sevii Targets AI-Speed Attacks With Preemptive Autonomous Defense

Sevii has expanded its ADR platform with AI agents designed to investigate, contain, and remediate AI-driven attacks within minutes. The post Sevii Targets AI-Speed Attacks With Pr...

🛡️ SecurityWeek General
Coast Guard Establishes Office of Maritime Cybersecurity Policy

The new office will serve as the central authority for cybersecurity policy covering US ports, vessels, and maritime facilities. The post Coast Guard Establishes Office of Maritime...

None General
Critical Langflow flaw exploited to steal OpenAI and AWS keys

Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal cre...

None General
Hackers push malicious Virtualizor update in BGP hijacking attack

Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to maliciou...

None General
Novocure data breach affects more than 1,400 cancer patients

Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack. [...]

None General
Why Even the Best Edge Security Still Misses High-Risk Sessions

Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how ...

🔍 CyberScoop General
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots

The Federal Ballot Mail Portal is described by a federal official as one of several IT systems that will be used to potentially deny thousands of mail-in ballots or more to states....

None General
Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailbo...

🛡️ SecurityWeek General
Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars

Forescout researchers used Claude AI to port a remote code execution exploit between WAGO PLC models. The post Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of...