home.social

#cybercrime — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cybercrime, aggregated by home.social.

  1. OpenAI agents attacked software service months before Hugging Face hack

    Agents being tested by OpenAI uploaded hundreds of malicious packages to RubyGems in May, researchers have revealed.

    abc.net.au/news/2026-09-12/ope

    #AI #CyberCrime

  2. OpenAI agents attacked software service months before Hugging Face hack

    Agents being tested by OpenAI uploaded hundreds of malicious packages to RubyGems in May, researchers have revealed.

    abc.net.au/news/2026-09-12/ope

    #AI #CyberCrime

  3. OpenAI agents attacked software service months before Hugging Face hack

    Agents being tested by OpenAI uploaded hundreds of malicious packages to RubyGems in May, researchers have revealed.

    abc.net.au/news/2026-09-12/ope

    #AI #CyberCrime

  4. OpenAI agents attacked software service months before Hugging Face hack

    Agents being tested by OpenAI uploaded hundreds of malicious packages to RubyGems in May, researchers have revealed.

    abc.net.au/news/2026-09-12/ope

    #AI #CyberCrime

  5. OpenAI agents attacked software service months before Hugging Face hack

    Agents being tested by OpenAI uploaded hundreds of malicious packages to RubyGems in May, researchers have revealed.

    abc.net.au/news/2026-09-12/ope

    #AI #CyberCrime

  6. Solicitar senha. Solicitar token. Token inválido. Aguardar.

    That's the full operator menu for VX-Pack — a Brazilian-origin AiTM phishing-as-a-service kit targeting banks in Brazil and Portugal. Request password. Request token. Invalid token (ask again). Wait. One operator, one victim, one browser, in real time.

    Nearly every AiTM kit — Evilginx, Tycoon 2FA, EvilProxy — is a reverse proxy. It silently relays traffic to the real bank, grabs the session cookie, and that's your 2FA bypass. VX-Pack is a different animal: a replica site, not a relay. The operator watches the victim fill each field over a WebSocket connection, replays the credentials against the real bank themselves, and if the OTP expires mid-attempt — tokeninvalido — the kit asks the victim for another one.

    No session cookie theft. No relay fingerprint at the bank. The bank's anti-proxy controls see traffic from the operator's own machine. "It passed the bank's fraud detection" is not the assurance it sounds like.

    Active since at least January 2025, sold as PhaaS by one developer to multiple buyers running their own campaigns. Impersonates Banco Santander and more than ten other financial institutions and payment platforms across Brazil and Portugal.

    Screenshots below show one of the phishing pages impersonating Banco Santander, as well as screenshots from a walkthrough video recorded by the kit's developer. Victim flow on one side, operator panel on the other.

    Phishing domains:
    ⛔️ pactualapp[.]com
    ⛔️ pactualpj[.]com
    ⛔️ pactual[.]live
    ⛔️ ativarbia[.]net
    ⛔️ ativarbia[.]com
    ⛔️ pactualapp[.]live
    ⛔️ centraldecancelamentos[.]pt
    ⛔️ verificador-cliente[.]live
    ⛔️ ativador-login[.]click

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm

  7. Solicitar senha. Solicitar token. Token inválido. Aguardar.

    That's the full operator menu for VX-Pack — a Brazilian-origin AiTM phishing-as-a-service kit targeting banks in Brazil and Portugal. Request password. Request token. Invalid token (ask again). Wait. One operator, one victim, one browser, in real time.

    Nearly every AiTM kit — Evilginx, Tycoon 2FA, EvilProxy — is a reverse proxy. It silently relays traffic to the real bank, grabs the session cookie, and that's your 2FA bypass. VX-Pack is a different animal: a replica site, not a relay. The operator watches the victim fill each field over a WebSocket connection, replays the credentials against the real bank themselves, and if the OTP expires mid-attempt — tokeninvalido — the kit asks the victim for another one.

    No session cookie theft. No relay fingerprint at the bank. The bank's anti-proxy controls see traffic from the operator's own machine. "It passed the bank's fraud detection" is not the assurance it sounds like.

    Active since at least January 2025, sold as PhaaS by one developer to multiple buyers running their own campaigns. Impersonates Banco Santander and more than ten other financial institutions and payment platforms across Brazil and Portugal.

    Screenshots below show one of the phishing pages impersonating Banco Santander, as well as screenshots from a walkthrough video recorded by the kit's developer. Victim flow on one side, operator panel on the other.

    Phishing domains:
    ⛔️ pactualapp[.]com
    ⛔️ pactualpj[.]com
    ⛔️ pactual[.]live
    ⛔️ ativarbia[.]net
    ⛔️ ativarbia[.]com
    ⛔️ pactualapp[.]live
    ⛔️ centraldecancelamentos[.]pt
    ⛔️ verificador-cliente[.]live
    ⛔️ ativador-login[.]click

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm

  8. Solicitar senha. Solicitar token. Token inválido. Aguardar.

    That's the full operator menu for VX-Pack — a Brazilian-origin AiTM phishing-as-a-service kit targeting banks in Brazil and Portugal. Request password. Request token. Invalid token (ask again). Wait. One operator, one victim, one browser, in real time.

    Nearly every AiTM kit — Evilginx, Tycoon 2FA, EvilProxy — is a reverse proxy. It silently relays traffic to the real bank, grabs the session cookie, and that's your 2FA bypass. VX-Pack is a different animal: a replica site, not a relay. The operator watches the victim fill each field over a WebSocket connection, replays the credentials against the real bank themselves, and if the OTP expires mid-attempt — tokeninvalido — the kit asks the victim for another one.

    No session cookie theft. No relay fingerprint at the bank. The bank's anti-proxy controls see traffic from the operator's own machine. "It passed the bank's fraud detection" is not the assurance it sounds like.

    Active since at least January 2025, sold as PhaaS by one developer to multiple buyers running their own campaigns. Impersonates Banco Santander and more than ten other financial institutions and payment platforms across Brazil and Portugal.

    Screenshots below show one of the phishing pages impersonating Banco Santander, as well as screenshots from a walkthrough video recorded by the kit's developer. Victim flow on one side, operator panel on the other.

    Phishing domains:
    ⛔️ pactualapp[.]com
    ⛔️ pactualpj[.]com
    ⛔️ pactual[.]live
    ⛔️ ativarbia[.]net
    ⛔️ ativarbia[.]com
    ⛔️ pactualapp[.]live
    ⛔️ centraldecancelamentos[.]pt
    ⛔️ verificador-cliente[.]live
    ⛔️ ativador-login[.]click

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm

  9. Solicitar senha. Solicitar token. Token inválido. Aguardar.

    That's the full operator menu for VX-Pack — a Brazilian-origin AiTM phishing-as-a-service kit targeting banks in Brazil and Portugal. Request password. Request token. Invalid token (ask again). Wait. One operator, one victim, one browser, in real time.

    Nearly every AiTM kit — Evilginx, Tycoon 2FA, EvilProxy — is a reverse proxy. It silently relays traffic to the real bank, grabs the session cookie, and that's your 2FA bypass. VX-Pack is a different animal: a replica site, not a relay. The operator watches the victim fill each field over a WebSocket connection, replays the credentials against the real bank themselves, and if the OTP expires mid-attempt — tokeninvalido — the kit asks the victim for another one.

    No session cookie theft. No relay fingerprint at the bank. The bank's anti-proxy controls see traffic from the operator's own machine. "It passed the bank's fraud detection" is not the assurance it sounds like.

    Active since at least January 2025, sold as PhaaS by one developer to multiple buyers running their own campaigns. Impersonates Banco Santander and more than ten other financial institutions and payment platforms across Brazil and Portugal.

    Screenshots below show one of the phishing pages impersonating Banco Santander, as well as screenshots from a walkthrough video recorded by the kit's developer. Victim flow on one side, operator panel on the other.

    Phishing domains:
    ⛔️ pactualapp[.]com
    ⛔️ pactualpj[.]com
    ⛔️ pactual[.]live
    ⛔️ ativarbia[.]net
    ⛔️ ativarbia[.]com
    ⛔️ pactualapp[.]live
    ⛔️ centraldecancelamentos[.]pt
    ⛔️ verificador-cliente[.]live
    ⛔️ ativador-login[.]click

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm

  10. Solicitar senha. Solicitar token. Token inválido. Aguardar.

    That's the full operator menu for VX-Pack — a Brazilian-origin AiTM phishing-as-a-service kit targeting banks in Brazil and Portugal. Request password. Request token. Invalid token (ask again). Wait. One operator, one victim, one browser, in real time.

    Nearly every AiTM kit — Evilginx, Tycoon 2FA, EvilProxy — is a reverse proxy. It silently relays traffic to the real bank, grabs the session cookie, and that's your 2FA bypass. VX-Pack is a different animal: a replica site, not a relay. The operator watches the victim fill each field over a WebSocket connection, replays the credentials against the real bank themselves, and if the OTP expires mid-attempt — tokeninvalido — the kit asks the victim for another one.

    No session cookie theft. No relay fingerprint at the bank. The bank's anti-proxy controls see traffic from the operator's own machine. "It passed the bank's fraud detection" is not the assurance it sounds like.

    Active since at least January 2025, sold as PhaaS by one developer to multiple buyers running their own campaigns. Impersonates Banco Santander and more than ten other financial institutions and payment platforms across Brazil and Portugal.

    Screenshots below show one of the phishing pages impersonating Banco Santander, as well as screenshots from a walkthrough video recorded by the kit's developer. Victim flow on one side, operator panel on the other.

    Phishing domains:
    ⛔️ pactualapp[.]com
    ⛔️ pactualpj[.]com
    ⛔️ pactual[.]live
    ⛔️ ativarbia[.]net
    ⛔️ ativarbia[.]com
    ⛔️ pactualapp[.]live
    ⛔️ centraldecancelamentos[.]pt
    ⛔️ verificador-cliente[.]live
    ⛔️ ativador-login[.]click

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm

  11. 📰 Anthropic Report: AI Models Weaponized for Espionage and Cybercrime

    Anthropic report reveals its Claude AI was weaponized for espionage, automated exploit development, and mass social engineering. Highlights how AI is lowering the skill barrier for sophisticated cyberattacks. #AI #CyberCrime #ThreatIntel #Anthropic

    🔗 cyber.netsecops.io/articles/an

  12. 📰 Anthropic Report: AI Models Weaponized for Espionage and Cybercrime

    Anthropic report reveals its Claude AI was weaponized for espionage, automated exploit development, and mass social engineering. Highlights how AI is lowering the skill barrier for sophisticated cyberattacks. #AI #CyberCrime #ThreatIntel #Anthropic

    🔗 cyber.netsecops.io/articles/an

  13. 📰 Anthropic Report: AI Models Weaponized for Espionage and Cybercrime

    Anthropic report reveals its Claude AI was weaponized for espionage, automated exploit development, and mass social engineering. Highlights how AI is lowering the skill barrier for sophisticated cyberattacks. #AI #CyberCrime #ThreatIntel #Anthropic

    🔗 cyber.netsecops.io/articles/an

  14. 📰 Anthropic Report: AI Models Weaponized for Espionage and Cybercrime

    Anthropic report reveals its Claude AI was weaponized for espionage, automated exploit development, and mass social engineering. Highlights how AI is lowering the skill barrier for sophisticated cyberattacks. #AI #CyberCrime #ThreatIntel #Anthropic

    🔗 cyber.netsecops.io/articles/an

  15. 📰 Anthropic Report: AI Models Weaponized for Espionage and Cybercrime

    Anthropic report reveals its Claude AI was weaponized for espionage, automated exploit development, and mass social engineering. Highlights how AI is lowering the skill barrier for sophisticated cyberattacks. #AI #CyberCrime #ThreatIntel #Anthropic

    🔗 cyber.netsecops.io/articles/an

  16. #infosec #databreach #cybercrime

    El grupo de extorsión FulcrumSec afirma estar detrás de la brecha de seguridad de Dustin y asegura haber recibido un correo electrónico del negociador de Dustin indicando que "vieron a Novo Nordisk en las noticias" y que "no tienen intención de convertirse en noticia de portada".

    x.com/IntCyberDigest/status/20

  17. Die allerschlechteste Kombination: Chrome und Windows

    Wer sich wundert, weshalb Chromium und und daraus abgeleitete Browser (Chrome, Edge, Opera, Vivaldi) schon wieder Updates erhalten, hier ist die Erklärung. Ein Sicherheitsunternehmen hat entdeckt, dass mindestens vier Gruppen von Cybergangstern eine Kette von Sicherheitslücken nutzen, um in Institution (Firmen, Behörden) vor allem in den USA und Südostasien einzudringen. Die Angreifer verketten zwei Sicherheitslücken in Chrome (CVE-2026-85046 und ein Sandkasten-Ausbruch ohne CVE-Nummer) mit einer in Windows (CVE-2026-85880). Die Lücke in Windows wurde gerade geflickt. ... Weiterlesen:

    pc-fluesterer.info/wordpress/2

    #0day #browser #chrome #cybercrime #exploits #Microsoft #sicherheit #spionage #unplugMicrosoft #UnplugTrump #windows

  18. Die allerschlechteste Kombination: Chrome und Windows

    Wer sich wundert, weshalb Chromium und und daraus abgeleitete Browser (Chrome, Edge, Opera, Vivaldi) schon wieder Updates erhalten, hier ist die Erklärung. Ein Sicherheitsunternehmen hat entdeckt, dass mindestens vier Gruppen von Cybergangstern eine Kette von Sicherheitslücken nutzen, um in Institution (Firmen, Behörden) vor allem in den USA und Südostasien einzudringen. Die Angreifer verketten zwei Sicherheitslücken in Chrome (CVE-2026-85046 und ein Sandkasten-Ausbruch ohne CVE-Nummer) mit einer in Windows (CVE-2026-85880). Die Lücke in Windows wurde gerade geflickt. ... Weiterlesen:

    pc-fluesterer.info/wordpress/2

    #0day #browser #chrome #cybercrime #exploits #Microsoft #sicherheit #spionage #unplugMicrosoft #UnplugTrump #windows

  19. Die allerschlechteste Kombination: Chrome und Windows

    Wer sich wundert, weshalb Chromium und und daraus abgeleitete Browser (Chrome, Edge, Opera, Vivaldi) schon wieder Updates erhalten, hier ist die Erklärung. Ein Sicherheitsunternehmen hat entdeckt, dass mindestens vier Gruppen von Cybergangstern eine Kette von Sicherheitslücken nutzen, um in Institution (Firmen, Behörden) vor allem in den USA und Südostasien einzudringen. Die Angreifer verketten zwei Sicherheitslücken in Chrome (CVE-2026-85046 und ein Sandkasten-Ausbruch ohne CVE-Nummer) mit einer in Windows (CVE-2026-85880). Die Lücke in Windows wurde gerade geflickt. ... Weiterlesen:

    pc-fluesterer.info/wordpress/2

    #0day #browser #chrome #cybercrime #exploits #Microsoft #sicherheit #spionage #unplugMicrosoft #UnplugTrump #windows

  20. Die allerschlechteste Kombination: Chrome und Windows

    Wer sich wundert, weshalb Chromium und und daraus abgeleitete Browser (Chrome, Edge, Opera, Vivaldi) schon wieder Updates erhalten, hier ist die Erklärung. Ein Sicherheitsunternehmen hat entdeckt, dass mindestens vier Gruppen von Cybergangstern eine Kette von Sicherheitslücken nutzen, um in Institution (Firmen, Behörden) vor allem in den USA und Südostasien einzudringen. Die Angreifer verketten zwei Sicherheitslücken in Chrome (CVE-2026-85046 und ein Sandkasten-Ausbruch ohne CVE-Nummer) mit einer in Windows (CVE-2026-85880). Die Lücke in Windows wurde gerade geflickt. ... Weiterlesen:

    pc-fluesterer.info/wordpress/2

    #0day #browser #chrome #cybercrime #exploits #Microsoft #sicherheit #spionage #unplugMicrosoft #UnplugTrump #windows

  21. Die allerschlechteste Kombination: Chrome und Windows

    Wer sich wundert, weshalb Chromium und und daraus abgeleitete Browser (Chrome, Edge, Opera, Vivaldi) schon wieder Updates erhalten, hier ist die Erklärung. Ein Sicherheitsunternehmen hat entdeckt, dass mindestens vier Gruppen von Cybergangstern eine Kette von Sicherheitslücken nutzen, um in Institution (Firmen, Behörden) vor allem in den USA und Südostasien einzudringen. Die Angreifer verketten zwei Sicherheitslücken in Chrome (CVE-2026-85046 und ein Sandkasten-Ausbruch ohne CVE-Nummer) mit einer in Windows (CVE-2026-85880). Die Lücke in Windows wurde gerade geflickt. ... Weiterlesen:

    pc-fluesterer.info/wordpress/2

    #0day #browser #chrome #cybercrime #exploits #Microsoft #sicherheit #spionage #unplugMicrosoft #UnplugTrump #windows

  22. Anthropic claims Claude AI used for missile projects, global espionage | Cybercrime News

    AI was used to develop missile guidance software and to power state-linked cyber-espionage operations, a new report reveals.…
    #NewsBeep #News #Topstories #Armenia #AsiaPacific #China #Cybercrime #cybersecurity #Espionage #Europe #France #Headlines #investigation #Iran #MiddleEast #Russia #scienceandtechnology #Syria #Technology #TopStories #Ukraine
    newsbeep.com/727681/