Cyber.TechVoid
Read latestCT
HomeLibraryCVEThreatsMalwareResearch

Following

Find topics and threat categories to follow

LatestBreakingVulnerabilitiesThreatsBreachesMalwareCVEResearch
See suggestions
Latest newsCVE trackerRSSllms.txt© 2026

Cyber.TechVoid

Know what happened in cybersecurity today. Source-driven cybersecurity coverage with attribution. Content may be AI-assisted from external feeds and advisories.

Sections

Latest cybersecurity newsData breach newsVulnerability updatesCVE trackerThreat intelligenceMalware watch

Feeds

RSSSitemapNews sitemapllms.txt

© 2026 Cyber.TechVoid. Accuracy over SEO.

  • Latest
  • Breaking
  • Vulnerabilities
  • Threats
  • Breaches
  • Malware
  • CVE
  • Research
TThe Hacker NewsinThreat Actors·Oct 5info

Suspected ShinyHunters Operative Detained in Jordan, Reportedly Cooperating with FBI

According to Reuters, cited by The Hacker News, a suspected member of the ShinyHunters ransomware/extortion collective identified as "Rey" — whose real name is Saif al-Din Khader — was brought into custody by Jordanian authorities on September 29, 2026. The individual is reported to be cooperating with the U.S. Federal Bureau of Investigation (FBI) to identify other group members. The detention claims remain unconfirmed by official Jordanian or U.S. government sources at the time of reporting.

11m
KKrebs on SecurityinThreat Actors·Oct 1high

Dutch Police Arrest Suspected Shiny Hunters Affiliate; Hackers Escalate Attacks on FBI and Cl0p

Dutch authorities have arrested a 23-year-old convicted cybercriminal on suspicion of aiding the Shiny Hunters hacking group. In the days following the arrest, remaining members of Shiny Hunters reportedly escalated their operations, stealing sensitive data from the FBI and issuing extortion claims targeting the Russian ransomware group Cl0p.

11m
BBleepingComputerinThreat Actors·Sep 30high

FBI Warns ShinyHunters Members Following Dutch Police Arrest of Alleged Leader

The FBI has issued warnings to members of the ShinyHunters extortion group, urging them to turn themselves in following the arrest of an alleged leader by Dutch police. The operation marks a coordinated law enforcement effort to disrupt the group's activities.

11m
BBleepingComputerinThreat Actors·Sep 29info

Dutch Police Confirm Arrest of 24-Year-Old in ShinyHunters Investigation

Dutch authorities have confirmed the arrest of a 24-year-old man from Amsterdam in connection with an investigation targeting the ShinyHunters hacking group. The operation forms part of broader law enforcement efforts to disrupt the threat actor's activities, though specific details regarding the evidence or the suspect's alleged role remain under investigation.

11m
BBleepingComputerinThreat Actors·Sep 19high

Chinese Hackers Deploy New SparroWocky Backdoor in Latin American Government Espionage Campaign

A China-linked espionage group known as FamousSparrow has been observed using a new backdoor called SparroWocky in attacks against government organizations in Latin America. The malware provides remote access and control, enabling potential data exfiltration and persistent compromise. Specific exploitation vectors and victim counts remain unconfirmed.

12m
DDark readinginThreat Actors·Sep 18high

FamousSparrow APT Conducts Espionage Campaign Targeting US Political Interests in Latin America

A cyberespionage campaign attributed to the FamousSparrow APT group, believed to be operating on behalf of the Chinese government, has been targeting US political interests across Latin America. The operation utilizes a previously undocumented stealthy backdoor to gain persistent access to sensitive systems. The campaign coincides with heightened geopolitical tensions and competition for influence in the region. While the specific initial infection vectors and full scope of compromise remain under investigation, the activity underscores the growing threat of state-sponsored espionage targeting political infrastructure.

11m
BBleepingComputerinThreat Actors·Sep 18high

US Extradites Alleged Black Axe Leaders to Face Cybercrime Charges

Five alleged leaders of the Black Axe cybercrime syndicate have been extradited to the United States to face wire fraud and money laundering charges related to global-scale cyber-enabled financial fraud. The extraditions mark a significant law enforcement action against one of the world's most prominent cybercrime organizations.

11m
BBleepingComputerinThreat Actors·Sep 16high

Malicious Admin Menu Editor Pro Plugin Backdoors WordPress Sites

A threat actor compromised the maintainer's website for the Admin Menu Editor Pro WordPress plugin and distributed malicious updates to paying customers. These updates created a hidden user account with administrative privileges, allowing unauthorized access to affected sites without the knowledge of site owners. The incident impacts an estimated 1,500 WordPress installations.

11m
TThe Hacker NewsinThreat Actors·Sep 13high

China-Linked UNC3569 Exploits Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

A China-linked threat actor tracked as UNC3569 has been observed exploiting a vulnerability in Sogou Input Method, a popular Chinese character input tool for Windows, to install the GRAYRABBIT backdoor on victims' systems. The attack chain, detailed by Gen Digital, starts with a malicious link and grants the attacker the same privileges as the logged-in user, potentially leading to data theft and further compromise. Tencent, the owner of Sogou, has not yet issued a public patch or advisory.

12m
TThe Hacker NewsinThreat Actors·Sep 10high

Slim Spider Threat Actor Targets Brazilian Financial Institutions to Steal Crypto Custody Secrets

CrowdStrike attributes a series of financially motivated attacks against Brazilian financial institutions to a previously undocumented threat actor tracked as Slim Spider. Active since at least March 2026, the group leverages deep operational knowledge of Brazil's instant payment infrastructure to steal crypto custody secrets and sensitive financial data.

11m
TThe Hacker NewsinThreat Actors·Sep 1high

North Korean Job Fraud Scheme Expands into Healthcare and Sales Sectors

Threat actors with ties to the Democratic People's Republic of Korea have been observed seeking job opportunities beyond the information technology sector. Recent investigations have identified suspected workers employed in sales, marketing, and medical professions as part of an ongoing insider threat campaign. The expansion represents an evolution of the established IT worker scheme, with operatives using falsified identities to gain employment in new target domains.

11m
KKrebs on SecurityinThreat Actors·Aug 29high

Australian Authorities Arrest Two Alleged TeamPCP Members in Major Cybercrackdown

The Australian Federal Police (AFP) have arrested two men, aged 21 and 23, from Western Australia in connection with an alleged sophisticated cybercrime syndicate known as TeamPCP. The group is accused of creating malicious open-source software to conduct supply chain attacks against thousands of global businesses, engaging in data extortion, and perpetrating the longest running spree of software supply chain attacks ever. KrebsOnSecurity identified the 21-year-old suspect's real identity in June 2026 and has been communicating with him since. The arrests mark a significant development in the investigation of one of the most persistent supply chain threat actors observed in recent years.

12m
BBleepingComputerinThreat Actors·Aug 29high

Australian Authorities Arrest Alleged TeamPCP Hackers in Supply-Chain Attack Crackdown

Australian Federal Police have arrested and charged two unnamed young men accused of belonging to TeamPCP, a hacking group implicated in supply-chain attacks targeting Python packages and developer environments. The operation marks a significant law enforcement action against the group, though the full scope of alleged attacks and victim impact remains under investigation.

11m
DDark readinginThreat Actors·Aug 27high

Researchers Identify Red Flags Exposing Fake North Korean IT Workers

A Dark Reading report highlights how North Korean state-sponsored operatives are refining their impersonation tactics to infiltrate organizations as IT workers, and outlines specific red flags researchers have identified to detect these fraudulent hires before they can cause harm.

11m
TThe Hacker NewsinThreat Actors·Aug 27info

U.S. Treasury Sanctions Iran-Linked Actors Over Critical Infrastructure Breaches

The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole-of-government, economic campaign" against the nation and its enablers. The measures target financial connections and individuals assessed to be enabling or conducting cyber operations against critical infrastructure, though specific breach details and victim entities were not disclosed in the advisory.

11m
TThe Hacker NewsinThreat Actors·Aug 23high

North Korean Remote IT Workers Infiltrate Government and Businesses via Fraudulent Job Applications

North Korean state-sponsored IT workers are infiltrating government agencies and private businesses by applying for remote positions using fake identities and stolen personally identifiable information. The FBI is actively investigating a specific case involving a North Korean remote IT worker who gained employment at an unnamed organization. These operatives use sophisticated interview techniques and fraudulent documentation to bypass hiring vetting, posing risks of data exfiltration, intellectual property theft, and compromised security postures for affected entities.

12m