Risky Bulletin: Authorities dismantle KillSec group, arrest members across Europe
In other news: Ransomware attack could have crippled South Africa's air traffic operations; US sanctions Venezuelan ATM hackers; Chinese APT targets AI experts.
This newsletter is brought to you by PortSwigger. You can subscribe to an audio version of this newsletter as a podcast by searching for "Risky Business" in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here.
European law enforcement agencies have cracked down and dismantled the KillSec ransomware group in a coordinated operation that seized servers, conducted several house searches across four countries, and detained three of the group's members.
The biggest arrest was a 16-year-old Romanian national living in Alicante, Spain, identified as the group's main administrator. The teen's name was not released, according to Spanish child privacy laws.
Two other suspects were arrested in Romania and the UK. The suspect arrested in the UK was identified as Fouad Eltibrizi, a Dutch national. The US has filed an extradition request for Eltibrizi, seeking him for a cyberattack against a Puerto Rico company in March 2025.
A fourth suspect was allegedly also identified in Spain, but not arrested. He's been described as an 18-year-old who worked as a programmer,
The group itself is what threat intel analysts would call a low-to-mid tier threat actor. KillSec was never a massive ransomware operation, but it did gather its own following because it had one of the cheapest Ransomware-as-a-Service (ransomware rental) schemes on the dark web.
It launched its platform in June 2024 and charged a $250 entry fee for access and then allowed affiliates to keep 88% of successful ransom payments.
Europol says the group's members and their affiliates launched more than 1,000 cyberattacks and hit companies all over the globe, with no particular regional or industry sector preference. Authorities say that at least 500 of those attacks were successful.
The group's main tactics involved the exploitation of known vulnerabilities in unpatched servers, gaining access to a victim's network, stealing data, and deploying their ransomware.
It engaged in double-extortion schemes, charging to delete stolen data and to provide decryption keys. According to Europol, in some cases, the group obtained "substantial ransom payments."
KillSec has also been linked to at least one zero-day—CVE-2025-31161 in CrushFTP—but has been recently going under the radar, compared to more famous groups like Qilin, DragonForce, or Akira.
KillSec's dark web leak site listed victims as recently as September 27, three days before authorities seized their servers, showing that the group was still very active.


Risky Business Podcasts
In this edition of Seriously Risky Business, Amberleigh Jack and James Wilson chat about OpenAI agents’ recent escapades into Australian government websites.
Breaches, hacks, and security incidents
ATNS ransomware attack: South Africa's air traffic control agency has stopped a ransomware attack last week against its OT network. The specific network provided weather-related services for air traffic controllers. The Air Traffic and Navigation Services says the attack could have crippled both internal and international air travel. The agency manages 6% of the world's airspace. ATNS is also investigating the possibility that one of its employees collaborated with the hackers. [Business Day]
Hackers breach Polish invoicing platform: Hacking group Fingerprint has breached and stolen data from Fakturownia, a major Polish invoicing company. This is the same group that breached the MyDr and Medyc Polish healthcare platforms. [Fakturownia // Zaufana Trzecia Strona]
Indian embassies leak: A suspected Pakistani threat actor claims to have hacked and leaked data on the Indian Ministry of Foreign Affairs and its embassy staff. [HackElite]
MetaMask security incident: Crypto-wallet service MetaMask disclosed a security incident impacting its online infrastructure. No details provided. [Metamask]
NEAR Intents hacked for $3.8m: Hackers have stolen over $3.8 million worth of crypto assets from cross-chain swap service NEAR Intents. The attackers allegedly used an exploit against one of its smart contracts. [NEAR Intents // Yahoo Finance]
Pentagon DMDC leak impacts 3.1m: More details have emerged about the breach at the Pentagon's DMDC office, which keeps track of current and former military members. According to reports, the incident exposed the data of 2.8 million living individuals and another 294,000 deceased military personnel. [FNN]
Canada says no evidence of AI hacks: AI agents that probed Canadian government sites did not breach any servers or internal systems. Canada's cybersecurity agency says it investigated reports of malicious AI agent activity after a similar incident in Australia. According to Transluce, the probes targeted the Library and Archives Canada, a Canadian federal agency. OpenAI has also notified dozens of organizations across the world that its AI agents probed their public websites and might have exploited security flaws to access wanted data. [Canadian Centre for Cyber Security // Transluce]
OpenAI blocks distillation attack: American AI company OpenAI says it detected and blocked a novel distillation attack targeting its models. The attackers reportedly copied a model's encrypted reasoning from one conversation and asked the model to transcribe it in a separate conversation. OpenAI says the attack took place through the month of July and involved more than 15,000 accounts. [OpenAI]
Morocco used telecoms to deploy spyware: The Moroccan government used the state-owned Maroc Telecom network to deploy the Pegasus spyware against human rights defenders. The spyware was deployed by Morocco's internal intelligence agency DGST between 2017 and 2021. Other deployment methods were also used. The DGST operations were exposed by a whistleblower, one of the agency's former employees. [Amnesty]
SpetsVuzAvtomatika leak: Hackers have leaked internal documents from SpetsVuzAvtomatika, a major Russian cyber research and development center. The leaked files expose multiple projects to support Russian hacking operations. This includes tools for target discovery, scanning, enrichment, active testing, internal-network access, credential theft, and data theft. The US Treasury sanctioned SpetsVuzAvtomatika in May 2021 for developing hacking tools for Russia's SVR intelligence service. [DomainTools]

General tech and privacy
Signal adds local backup support for iOS and Desktop: Signal is rolling out support for local encrypted backups for its iOS and Desktop clients. The feature allows users to back up their Signal data locally in an encrypted archive. The feature already exists on Android. f[Signal]
Cloudflare to launch its own CA: Internet infrastructure company Cloudflare is launching a Certificate Authority. The new CA will provide free certificates with automated issuance and renewal, similar to Let's Encrypt. It will also support modern certificates hardened against quantum-computing attacks. [Cloudflare]
Cloudflare is becoming a free certificate authority, and will be the first to issue post-quantum Merkle Tree Certificates
— Matt Kane (@mk.gg) September 29, 2026 at 4:04 PM
[image or embed]
Reddit deprecates RSS feeds: As part of its fight against invasive AI scrappers, Reddit will deprecate all RSS feeds on November 13, 2026. New users will also not be able to access Reddit's older and much cleaner UI. [Reddit]
Windows 11 26H2: Microsoft released a new major Windows 11 update after almost a year, 26H2, the company's normal fall release. [Windows]
Gemini 4 Argon: Google has released Gemini 4 Argon, its latest frontier model with cybersecurity capabilities. The model is rolling out to trusted cyber defenders through Google's Fairwind Program. Google claims Argon can autonomously find, validate, and patch critical software vulnerabilities on its own. [Google]
OpenAI ignored employee warnings: OpenAI ignored warnings from its own employees earlier this year that new AI models were not being properly monitored during testing. According to the New York Times, the company also ignored warnings from external security researchers about its insecure infrastructure. OpenAI reportedly prioritized speed over model security and employee concerns. [NYT]
Anthropic cries about GLM-5.3: American AI company Anthropic says Chinese AI model Zhipu GLM-5.3 is close to Mythos-like cyber capabilities but ships with weak guardrails. Anthropic warns that threat actors can bypass GLM safety protocols and abuse the model to create exploits and launch cyberattacks. The company is urging governments to take action against open-weight models like GLM-5.3 and make sure they ship proper guardrails. [Anthropic]

Anthropic is just directly fearmongering about the open weight models that are eating their lunch on price now huh
— Scoiattolo (@scarnecchia.net) September 29, 2026 at 9:51 PM
[image or embed]
I am very confused why Anthropic wrote a blog post advertising for cybersecurity teams to switch to GLM!?!?https://t.co/6Z1BTChDtj
— Andrew Case (@attrc) September 29, 2026
Government, politics, and policy
Newsom vetos pervert glasses bill: California governor Gavin Newsom has vetoed a bill that would have made it unlawful to record people using smart glasses and other wearable devices. The bill specifically targeted incidents where people are being recorded with Meta's RayBan pervert glasses. [TechCrunch]
EU law enforcement to drop Oxygen Forensics: Multiple European law enforcement agencies are dropping contracts with Oxygen Forensics. The US charged the company's CEO last month for hiding its Russian ownership when applying for government contracts. Romania's anti-corruption agency, Latvia's state police, and London's Metropolitan Police are now reviewing or have initiated the process of dropping contracts. Oxygen products are also used in Germany, Spain, Italy, Poland, and Hungary. [Politico Europe]
AIVD warns of smart car espionage risk: The Dutch internal intelligence service warned that modern smart cars pose a serious espionage risk due to the huge number of internal trackers, which can also be purchased through data brokers. The warning comes just as a Northeastern University paper looks at all the car tracking tech currently in use. [AIVD // Northeastern University]

Sponsor section
In this Risky Business sponsor interview, James Wilson chats to Kieron Hughes and Andrzej Matykiewicz from PortSwigger about the company’s latest AI pen-testing product, Burp AT.
Arrests, cybercrime, and threat intel
Dutch hacker gets prison time for stolen creds, GTA cheats: A Dutch court has sentenced a 25-year-old man to one and a half years in prison for selling combo-lists of stolen credentials. In total, the man sold more than 200 combo-lists with more than one million usernames and passwords. He also sold GTA 5 cheats and tools to crash GTA servers and evade bans. [De Rechtspraak]
US sanctions 10 TdA members over ATM hacks: The US has sanctioned 10 leaders of the Tren de Aragua Venezuelan cartel for ATM jackpotting attacks. The group stole more than $40 million across 1,500 attacks. The sanctions come after the FBI arrested and charged more than 100 suspects who participated in the hacks. Members stopped by isolated and unsupervised ATMs, connected laptops, and deployed the Ploutus malware. [US Treasury // TRM Labs // Chainalysis]
Germany suspends 9.3k scam numbers: German authorities have suspended more than 9,300 phone numbers that were used in cyber investment scams. Officials have also taken regulatory measures against the responsible telcos. Authorities say they suspended almost 14,000 phone numbers used for scams since December of last year, as part of Operation Heracles. [Bundesnetzagentur]
Scam op leak: Misconfigured servers exposed a major investment scam operation targeting South Africans with local news media-themed domains urging investments on malicious platforms. [Confiant]
Successful crypto malware operation: A cybercrime actor has stolen more than $100,000 worth of crypto by deploying an infostealer that injects right into the user's browser to steal session-related data for crypto sites. The operation also includes a clipboard clipper. [Netskope]
SleepyDuck campaign returns: Pluto Security has spotted a new cluster of malicious VSCode extensions on the OpenVSX marketplace. The company called this campaign EtherDuck, and says it's related to the SleepyDuck campaign that targeted Solidity code developers last year. [Pluto Security]

AI agents expose business secrets through images: Security researchers have found more than 13,000 images taken by AI agents and uploaded on public GitHub repositories. According to Glow Security, the agents were trying to help developers compare before and after screenshots of their apps. Agents installed in controlled or secure environments uploaded the images on GitHub as a workaround, and inadvertently exposed sensitive corporate secrets. Some of the affected companies include a Fortune 500 travel company and even a major frontier AI lab. [Glow Security]
Warlock group still active: Broadcom researchers say that Warlock, a Chinese ransomware group, is still active even after its initial attacks on Taiwanese orgs last year. The group has been hitting victims in Portuguese- and Spanish-speaking countries, spanning Europe, Africa, and Latin America. [Broadcom]
"Warlock is developed by a China-nexus threat actor Symantec calls Longlegs (aka Storm-2603). Symantec has previously tied this group to older activity clusters known as CL-CRI-1040, CamoFei, and ChamelGang."
ClickFix usage goes down: Malicious copy-paste ClickFix attacks accounted for only 12% of initial access activity over the past year, according to Microsoft's yearly Digital Defense report. The number is down from the 47% figure at the same period last year. Despite less ClickFix activity, Microsoft says that in 96% of all ClickFix detections, malware always followed after. [Microsoft]

Half a mil creds on GitHub: Truffle Security has found 543,699 unique credentials exposed in public GitHub repositories. The scan took place in July and all the creds were still valid and working at the time. Truffle says that more than 200,000 of the credentials leaked online even after GitHub rolled out protections to prevent creds and tokens to be pushed in public repositories. [Truffle Security]

Malware technical reports
Milk Dragon PhaaS: Researchers analyze Milk Dragon (NaiLong), a new AitM phishing kit. The kit has been available for sale online since October last year and was mainly used for campaigns on Facebook and TikTok marketplace advertisements. [Group-IB]
PamStealer: The Iru security team has published a breakdown of PamStealer, a new macOS infostealer that emerged on the scene in August. [Iru]
DirtyBlanket worm: A cluster of nine npm packages posing as Express modules are spreading a new Linux worm named DirtyBlanket. [SafeDep]
New DragonForce backdoors: Lab52 researchers have found two new backdoors used in recent attacks by the DragonForce ransomware. The two stand out because they use the TURN and MQTT protocols, respectively, to hide C2 traffic. Seqrite has also published a report on the group's activities. [Lab52 // Seqrite]

Sponsor section
In this sponsored interview, James Wilson talks with James Kettle and Daf Stuttard from PortSwigger about the new LLM they added to Burp Suite and the window into the future of AI-enabled hacking and security testing.
APTs, cyber-espionage, and info-ops
Ukraine says attackers use AI for phishing: In its cyber threat report for the first half of the year, Ukraine's cybersecurity agency says threat actors are now consistently using AI to craft phishing lures. [SSSCIP]
UAT-11587 targets SE Asia: A suspected Chinese APT group is targeting government and policy organizations across South and Southeast Asia. The UAT-11587 group has been active since September last year. It employs spear-phishing to infect targets with a new Rust-based backdoor named Antino. [Cisco Talos]
TA419 targets AI experts: A Chinese cyber-espionage has carried out an extensive spear-phishing operation against AI experts working for US think tanks, universities, and legal organizations. The campaign took place this year and TA419 operators impersonated economists and AI policymakers to approach their targets. Proofpoint says this is the second Chinese APT it has seen recently targeting the US AI sector. [Proofpoint]
Montenegro extradites Iranian APT member: The Montenegro government has approved the extradition of an Iranian hacker to the US. Amir Barati was arrested in June in the Adriatic resort town of Kotor. US officials claim he's a member of Silent Librarian, an Iranian APT specialized in hacking and stealing private research from universities. [Montenegro government // The Record]
Vulnerabilities, security research, and bug bounty
Security updates: Cisco, FreeBSD, Gitea, KiteWorks, OpenSSL, TanStack, TeamViewer, Tor Browser, WatchGuard.
New Cisco SD-WAN zero-day: Cisco has released firmware updates to patch an actively exploited zero-day in Catalyst SD-WAN appliances. The zero-day has allowed attackers to bypass one API authentication via maliciously crafted HTTP requests. A successful exploit grants attackers admin-level access to the device's API management component. Cisco didn't attribute the attacks. [Cisco CVE-2026-76504]
Zammad zero-days behind DIVD hack: Hackers exploited two zero-days in the Zammad helpdesk and issue tracking platform to breach Dutch cybersecurity non-profit DIVD. The two zero-days allow an attacker to hijack sessions, elevate privileges, and run remote code on Zammad servers. DIVD has reported the issues to the vendor, who is now working on patches. DIVD disclosed the hack over the weekend and said it suspects the attacker used AI tooling due to the speed at which the attack took place. [DIVD]
Zimbra bug exploited in the wild: A threat actor is hacking and stealing email inboxes from Zimbra servers. The attacker is exploiting a command injection vulnerability patched in July. They deploy a Java web shell and then steal user credentials and past emails. Microsoft documented the attacks this week but did not attribute the operation to any known group. [Microsoft // Zimbra patch]

Apple iCloud spoofing: Security researchers have found two ways—now patched—of spoofing Apple iCloud emails that took four years to get fixed. [SEC-Consult]
Linux LPE: AI security company XBOX has published a write-up on a new Linux local privilege exploitation vulnerability (CVE-2026-72018) they found over the summer. [XBOW]
Vulnerability disclosure and exploitation double: Vulnerability disclosure and vulnerability exploitation have both doubled over the past year, according to Google. The jump came from the integration of AI tools into the vulnerability discovery process. While AI has helped in finding more bugs, Google says AI is now reliably finding more consequential vulnerabilities, including ones that lead to remote code execution. [Google]

Infosec industry
Threat/trend reports: Cisco, Dr.Web, Gen Digital, Google, Microsoft, Pew Research, Point Wild, SSSCIP, Swimlane, Truffle Security, WaterISAC, and Wordfence have recently published reports and summaries covering various emerging threats and industry trends.

BSides Belfast 2026 videos: Talks from the BSides Belfast 2026 security conference, which took place last month, are available on YouTube.
Risky Business podcasts
In this edition of Between Two Nerds, Tom Uren and The Grugq talk about the rise of fully automated LLM-driven hacking campaigns among criminals and even state hacking groups. For those with the right risk appetite, a move fast and break things hacking approach using AI can pay off.