CyberCrime Blog- 2026 2025 2024 2023 2022 2021 2020 2019 2018
BigBrother blog BotNet blog Cyber blog Cryptocurrency blog Exploit blog Hacking blog ICS blog Incident blog IoT blog Malware blog OS Blog Phishing blog Ransom blog Safety blog Security blog Social blog Spam blog Vulnerebility blogDATE | NAME | Info | CATEG. | WEB |
|
12.9.26 |
Finding and Notifying a ShinyHunters Claims Impersonation Campaign Before It Activated: 61 Domains, 48 Brands | ReliaQuest Threat Research published a short public advisory about a ShinyHunters campaign on August 17, 2026. This campaign was built on domains following a company[.]claims pattern, and reported that the group had added legal team impersonation to its established help desk and IT pretexts. The advisory had no domains, and described a shape that left the reader to find the instances. | CyberCrime blog | FLARE.IO |
|
12.9.26 |
Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure | A recent Unit 42 investigation into seemingly low-priority enterprise infections demonstrates how the most effective camouflage in cybercrime is not necessarily in the use of sophisticated techniques, but in how unremarkable the threat appears. The activities that we investigated would typically not require escalation or further inquiry. But upon closer inspection, we discovered a massive cybercrime campaign largely targeting young gamers. | CyberCrime blog | Palo Alto |
|
11.9.26 |
How a Fraudulent Hire Clears Your Verification Process | The controls most companies trust to vet a candidate were built to catch mistakes and embellishments. They were not built for a well-funded adversary using a real person's identity, and sometimes a real person. | CyberCrime blog | ABNORMAL |
|
10.9.26 |
FBI Investigates Nexus Claim of 153M+ ID Records | A Dark Web service called Nexus has claimed to offer access to more than 153 million driver’s license records from the United States and Canada, along with millions of other identity documents. The FBI has reportedly opened an investigation into the exposure. | CyberCrime blog | SOCRADAR |
|
10.9.26 |
Dark Web Market: Anubis Market | Anubis Market is a multi-category Dark Web marketplace operating as a Tor hidden service, with escrow-backed trading in Bitcoin (BTC) and Monero (XMR). Its visible category strip displays more than 11,000 listings, and while narcotics account for the largest share of physical goods, its Digital section is the single biggest category on the market. | CyberCrime blog | SOCRADAR |
|
5.9.26 |
The NDA Was the Payload: Inside Phantom Deal, a Fake Acquisition Fraud Campaign | Attackers posed as executives, moved conversations to WhatsApp and personal email, and forged acquisition documents to set up international wire transfers. When they targeted Gen, researchers played along, exposing a wider M&A scam. | CyberCrime blog | GENDIGITAL |
|
31.8.26 |
Finnish Kennel Club, Shell Access, UK Iframe, Salt Mobile, and Brazil SERPRO Claims | SOCRadar Dark Web Team identified several new underground posts, including an alleged Finnish Kennel Club and Showlink dog-show database leak, and a separate initial access listing offering shell and WordPress access to websites in Indonesia and Romania. | CyberCrime blog | |
|
29.8.26 |
Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs |
Despite modern verification controls, identity theft remains one of the most pervasive threats to both individuals and enterprise organizations. U.S. Federal Trade Commission statistics show over 1 million identity theft reports annually, with related fraud and imposter scams accounting for billions in financial losses each year. |
||
|
29.8.26 |
On 26 August 2026, the Australian Federal Police charged two West Australian men over their alleged roles in a cybercrime syndicate that inserted malicious code into open-source software used by thousands of organizations worldwide. Both men appeared in Perth Magistrates Court the following day. |
|||
|
29.8.26 |
On 26 August 2026, the Australian Federal Police charged two West Australian men over their alleged roles in a cybercrime syndicate that inserted malicious code into open-source software used by thousands of organizations worldwide. Both men appeared in Perth Magistrates Court the following day. |
|||
|
29.8.26 |
Imobiliare.ro, Klark.ai, Fortinet VPN, E-Commerce Skimming, and Solimut SQLi |
SOCRadar Dark Web Team identified several new underground posts involving alleged database leaks, exposed remote access, and access-for-sale activity. The findings include an alleged Imobiliare.ro user database sale, administrative Fortinet SSL-VPN access tied to a UAE hotel reservation firm, an alleged Klark.ai data leak, a U.S. e-commerce iframe skimming operation, and alleged SQL injection access affecting Solimut Mutuelle de France. |
||
|
29.8.26 |
A ShinyHunters-associated leak site listed ReliaQuest on August 23, 2026, raising questions about a potential data extortion attempt against the cybersecurity provider. |
|||
|
29.8.26 |
A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication. |
|||
| 22.8.26 | Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor | Contents Introduction Key Targets Industries Affected Geographical focus Infection Chain Campaign Timeline Initial Findings Looking into the Decoy Document Technical Analysis Stage 1 | CyberCrime blog | Seqrite |
|
7.8.26 |
Snowflake Hacker Pleads Guilty, Faces 32 Years | Snowflake hacker Connor Riley Moucka pleaded guilty on August 5, 2026, in the U.S. District Court for the Western District of Washington, admitting to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy count tied to the 2024 breaches of Snowflake customer accounts. | CyberCrime blog | SOCRADAR |
|
6.8.26 |
Dark Web Market: Vortex Market | Vortex Market describes itself as a “classic wallet escrow market,” and that self-description is accurate. It is a general-purpose Dark Web marketplace built around anonymous trade, vendor reputation levels, and cryptocurrency payments held in market-controlled wallets. Reporting on mirror directories places the launch of the Vortex darknet market in October 2023 with full public access during 2024. | CyberCrime blog | SOCRADAR |
|
8.8.26 |
From Stolen Credentials to Full Breach: The 72-Hour Timeline | The 72-hour Timeline reveals how stolen credentials can escalate into a cyberattack, showing key attack stages and detection opportunities. | CyberCrime blog | Cyble |
|
1.8.26 |
Inside the Underground Economy: 5 Dark Web Trends Shaping the 2026 Threat Landscape | Cyble breaks down how dark web ecosystems are evolving in 2026 with ransomware, initial access brokers, AI-driven attacks, and underground threat activity. | CyberCrime blog | Cyble |