Intelligence · Updated daily

Security Intelligence

AI-analysed threats, vulnerabilities and campaigns. Not just what happened — what it means, who's affected, and what to do about it.

Page 5 of 26

101–125 of 632
highCampaignContained

First VPN dismantled in Operation Saffron: law enforcement disrupts infrastructure used by 25 ransomware groups

European and North American authorities have shut down First VPN, a criminal VPN service that facilitated ransomware attacks, data theft, and DDoS operations for approximately 25 ransomware groups. The coordinated takedown represents a significant disruption to organised cybercrime infrastructure, though similar services remain operational.

First VPN Service, 25 ransomware groups (unnamed)
highSupply ChainContained

Dutch law enforcement dismantles bulletproof hosting infrastructure supporting organised cyber operations

Dutch financial crime authorities arrested two operators and seized 800 servers from a web hosting company that provided infrastructure for coordinated cyberattacks, interference campaigns, and disinformation operations. This represents a significant disruption to a criminal supply chain enabling multiple threat actors.

Unnamed web hosting company, Multiple threat actors relying on compromised infrastructure
highMalwareContained

Kimwolf IoT Botnet Operator Arrested: International Prosecution Marks Escalation in Law Enforcement Against DDoS-for-Hire Operators

Canadian authorities arrested a 23-year-old suspected operator of Kimwolf, an IoT botnet that compromised millions of devices for large-scale DDoS attacks. The arrest and cross-border charges signal coordinated enforcement against botnet operators who target journalists and security researchers.

Internet-of-Things devices (millions), Online services targeted by DDoS attacks, Media and security research organisations
criticalVulnerabilityActive

Supply Chain Compromise: Malicious CAP.js Package Versions with Credential Harvesting

Compromised versions of @cap-js database packages (sqlite, postgres, db-service) published April 29, 2026 harvested credentials and attempted self-propagation. Any system with these versions installed must assume all local credentials (npm tokens, cloud keys, SSH keys, GitHub PATs) are compromised.

CVE-2026-46421
@cap-js/sqlite@2.2.2, @cap-js/postgres@2.2.2, @cap-js/db-service@2.10.1
mediumPolicyActive

FTC enforcement action reveals widespread non-compliance with Take It Down Act among major platforms

The FTC has issued warning letters to 12 major technology firms for allegedly failing to comply with the Take It Down Act, which requires platforms to provide accessible removal mechanisms for nonconsensual intimate imagery and process deletion requests within 48 hours. This represents the first significant enforcement action under the statute and signals regulatory intent to hold platforms accountable for abuse prevention infrastructure.

12 major technology companies (specific names not provided in source)
highMalwareContained

Ukrainian law enforcement dismantles infostealer operation run by 18-year-old, recovering 28,000 compromised accounts

Ukrainian cyberpolice and U.S. law enforcement identified and disrupted an infostealer malware operation run by an 18-year-old from Odesa who had compromised approximately 28,000 user accounts from a California-based online retailer. The case demonstrates effective international law enforcement coordination against financially-motivated cybercriminals operating from Eastern Europe.

Unnamed California-based online retail store