California City Pulls Plug on It’s Computer System After Cyberattack

A northern California city of 30,000 people had to disconnect its entire computer network after a cyberattack, idling the municipality’s 911 emergency line for police and fire dispatch.

Officials in the city of Suisun City, located about 45 miles from San Francisco, had to find a workaround for emergency calls and did by forwarding 911 calls to a county dispatch center.

The city declared a state of emergency Saturday after malicious software invaded its computer network and system shortly before 6 p.m. Friday, according to the California Post.

“Officials shut down the entire network to stop the threat from spreading and protect evidence for a federal investigation,” the Post reported.

Despite the attack, Suisun City officials say they found a work around to prevent residents from being put in immediate danger during emergencies.

First responders remain active and dispatched, with city emergency operators routing calls through he Solano County dispatch center.

That way police and fire personnel are able to respond to calls for service,

The attack also disrupted non-emergency city services, including access to municipal records such as building permits and idled residents ability to pay bills online.

The complete shutdown came after the city council voted unanimously to pull the plug and declare a state of emergency at a special meeting Saturday morning.

Cybersecurity for municipalities and infrastructure systems have been in the news during the Iran war after U.S. authorities earlier this year issued an “urgent warning” that hackers backed by the Islamic Revolutionary Guard Corps (IRGC) in Iran were attempting to disrupt American computer networks.

Investigators are still at work in an effort to determine how the malicious software got inside the network and who was behind the attack, according to news reports.

Keep reading

More than 600,000 voter files ripped off Arizona site in 2020 by hacker, but DOJ didn’t prosecute

Arizona’s largest county suffered a significant breach of its election data in the days before the 2020 presidential election when a self-described hacker foiled security and obtained 633,000 voter registration files but the Biden Justice Department and local prosecutors declined to bring charges even after the FBI got the suspect to confess, according to declassified documents made public Thursday by the White House.

The scraping of Maricopa County’s voter registration files was the most flagged security incident in a cyberintrusion log kept by U.S. spy agencies in the days around the Nov. 3, 2020 election, and it caused an extensive FBI investigation that led agents to a home in Fountain Hills, Ariz., the memos show.

The man the FBI confronted admitted he wrote a computer script to exploit the county voter systems security and scraped the files, which included 930 with “sensitive voter information like domestic violence victims, judges and law enforcement officers,” according to the FBI case files declassified and made public by President Donald Trump’s White House Government Transparency Task Force.

FBI Director Kash Patel sent a letter to that task force this week stating the bureau spent “significant resources” but could not get the U.S. Attorney’s Office in Phoenix, the Arizona Attorney General’s Office, the Maricopa County Arizona Attorney’s Office or the Pinal County, Arizona Attorney’s Office to bring charges despite an admission from the alleged hacker.

FBI_Letter.pdf

The U.S. Attorney’s Office declined to prosecute the alleged hacker on July 12, 2021, under the Biden Administration, according to the FBI. The newly released memos do not state when the other prosecutorial agencies made similar decisions not to bring charges,  but the full case was officially closed in 2023.  

Just one day before the Nov. 3 election, the Maricopa County Recorder’s Office submitted a tip through the Arizona Counterterrorism Intelligence Center that there had been “an attempt to scrape voter registration information,” according to one FBI summary. 

FBI_Opening_Doc.pdf

According to that memo, an unidentified intruder gained access to voter registration data on the recorder’s website by using a “Powershell script” that exploited a weakness in security. More than 633,000 voter records were exfiltrated between Oct. 21, 2020, and Nov. 2, 2020, the memos state.

Keep reading

“Nothing Is 100%”: CZ Warns Bitcoin Holders After $89 Million Coldcard Wallet Exploit

A third wave of thefts against Bitcoin wallets built on flawed Coldcard firmware ran through Saturday morning, lifting observed losses to roughly 1,367 BTC – close to $89 million – drained from 4,585 addresses since Thursday.

As Cyberkendra.com reports, the size is not the interesting part. The third wave is the first one designed to be hard to follow, and that shift tells self-custody holders more about what happens next than any dollar figure does.

Galaxy Research published the wave-three findings early Sunday. Between 12:23 UTC on July 31 and 06:42 UTC on August 1, across blocks 960,396 to 960,471, another 207.73 BTC left 1,912 addresses. That is roughly a tenth of a coin per victim.

Wave one, which opened at 01:10 UTC on July 30 and closed 41 minutes later, took 1,082.65 BTC from 1,195 addresses — nearly a full coin each.

Wave two, on July 31, collected just 76.16 BTC from 1,478 addresses.

Median losses tell the same story more bluntly: 0.270 BTC in wave one, 0.010 in wave two, 0.013 in wave three. The operator is now emptying wallets worth a few thousand dollars apiece and still finding enough of them to spend ten hours sweeping.

Waves one and two were easy to map because the attacker made them easy.

Both funneled coins through a handful of shared collector addresses into P2WPKH holding wallets (pay-to-witness-public-key-hash — plain single-key SegWit outputs, fully visible on chain).

Wave three abandoned that.

Each victim’s coins went to their own destination, and the proceeds now sit in 293 separate P2WSH vaults (pay-to-witness-script-hash, a format that keeps its spending conditions hidden until the first time the coins move). The sweeper also batched an average of 6.37 victims per transaction, where wave one took exactly one at a time, and scanned only the default derivation path instead of testing several branches per seed. Even the fee constant changed — 30 sat/vB in wave one, 50 and 10 in wave two, roughly 200 then exactly 10 in wave three.

That is either the same crew rebuilding after being enumerated in public, or a second crew grinding the same broken key space on its own.

The falling average haul suggests the profitable end of the vulnerable key space is picked over. That is cold comfort. Wave three’s median take of 0.013 BTC is the clearest evidence yet that no balance is now small enough to be beneath the scanner’s notice — and the sweeping had not stopped three days in.

Keep reading

Trump: Minnesota’s ‘gross incompetence’ — not Iran — behind water system hacks

President Donald Trump says Minnesota is to blame for a recent cyber-attack against the state’s water system.

While speaking on Friday at his cabinet’s historic Camp David meeting, President Trump called the North Star State’s leadership grossly incompetent after the breach reportedly affected over 30-water systems.

“We heard in ⁠Minnesota there was a cyberattack, ​and they blame it on Iran. ​I don’t think so,” Trump said. 

“I think I blame it on ​Minnesota because they’re grossly incompetent,” he continued.

“I think the governor is behind it,” he said of Minnesota Governor Tim Walz (D-Minn.). “I don’t think there was an Iranian cyberattack.”

His statements follow a New York Times report citing federal investigators who concluded that the cyber incident was likely carried out by Iranian threat actors.

“The tradecraft used, and the absence of a ransom demand, had led analysts to tentatively conclude that it was the work of Iranian hackers,” the Times reports. 

The Federal Bureau of Investigation (FBI) is continuing its investigation into the breach, which authorities say might have affected utilities across at least six other states as well.

Keep reading

MFA Was Supposed to Save Us. Hackers Found a Way Around Human Nature Instead.

For years, cybersecurity experts preached the same gospel. Use a strong password. Don’t reuse it. Turn on multi-factor authentication. The public eventually listened. Banks encouraged it. Social media platforms required it. Employers rolled it out. Even people who still struggle to find the right app on their phone learned that approving a login request was simply part of modern life.

Then the criminals adapted. One of the biggest cybersecurity stories this month revealed an uncomfortable truth about today’s online threats. Hackers are increasingly abandoning attempts to break multi-factor authentication. Instead, they’re simply waiting for people to complete it for them.

It’s a remarkably effective scam because it exploits something technology has never been very good at defending: human trust. The fake login page looks real. The text message appears legitimate. The authentication request pops up exactly as users expect. The victim enters their password, approves the prompt, and unknowingly grants attackers full access.

The security worked perfectly. The person didn’t. That’s why this latest wave of attacks should concern everyone, not just IT departments.

America is still catching up to cybersecurity basics while cybercriminals are already operating several chapters ahead. Millions of people only recently became comfortable using MFA. They don’t necessarily understand what it’s doing. They simply know they’ve been told it’s safer.

That knowledge gap has become an opportunity. Older Americans have become especially attractive targets. They bank online, manage retirement accounts digitally, schedule doctor appointments through patient portals, and increasingly rely on smartphones for everyday life. Many learned these habits out of necessity rather than curiosity, making them more vulnerable to sophisticated social engineering attacks designed to look routine.

Criminals know exactly who they’re looking for. This is no longer the stereotype of a teenager in a basement writing viruses for fun. Today’s cybercrime industry operates like a multinational business. It studies psychology, customer behavior, and user habits with the same precision legitimate companies use to improve marketing campaigns.

The objective isn’t always to outsmart the software. It’s to outsmart the person sitting behind the keyboard. Even Washington is acknowledging the stakes are getting higher. The Trump administration recently announced a new initiative to aggressively identify cybersecurity vulnerabilities tied to artificial intelligence before hostile actors can exploit them. If the federal government believes emerging technology demands an entirely new level of vigilance, it’s hard to argue that everyday consumers are somehow insulated from the same risks. If anything, they’re more exposed. 

Keep reading

CISA: Windows BlueHammer flaw now exploited by ransomware gangs

CISA confirmed on Monday that ransomware gangs have begun exploiting a high-severity Microsoft Defender privilege escalation vulnerability that has previously been abused in zero-day attacks.

Dubbed BlueHammer, the security flaw (CVE-2026-33825) was leaked by a security researcher known as “Nightmare Eclipse” in early April, together with proof-of-concept exploit code, in protest at how the Microsoft Security Response Center (MSRC) handles the disclosure process.

“Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally,” Microsoft explains in a security advisory.

Will Dormann, principal vulnerability analyst at Tharros, told BleepingComputer in April that while the issue is not easy to exploit, it gives local attackers access to the Security Account Manager (SAM) database, which contains password hashes for local accounts.

With this access, they can escalate to SYSTEM privileges and potentially take complete control of the targeted system.

“At that point, [the attackers] basically own the system, and can do things like spawn a SYSTEM-privileged shell,” Dormann said.

Keep reading

Russian Media Reports Hackers Have Receipts Ukraine Has Lost 2.4 Million Dead In War

Ukraine has lost approximately 2.4 million soldiers since the start of Russia’s operation in Ukraine in 2022

Russian hackers PalachPro and the NoName057(16) group have breached databases belonging to the Ukrainian General Staff and Ukraines territorial recruitment centers (TCCs)

They also hacked Ukrainian medical institutions and morgues.

Citing leaked data, losses stood at 1.7 million by August 2025 and crossed 2 million by December. The first six months of 2026 alone reportedly cost Kiev around 400,000 men matching total losses for all of 2023. The heaviest casualties are concentrated on the Krasnoarmeysk (Pokrovsk) Konstantinovka Lyman Zaporozhye and Kupyansk axes averaging roughly 500 AFU losses per day on each.

Mash also reports that foreign mercenary deaths have stopped being logged as combat losses instead recorded as accidents. Per the leaked data around 5,000 foreign fighters serving with the AFU have been killed a number said to be rising as TCCs continue recruiting foreign nationals many of them Argentine and Brazilian nationals aged 20 to 23.

PalachPro and NoName057(16) are the same groups Mash credits with earlier deploying AI assisted facial recognition across roughly 50000 surveillance cameras in Ukraine and the EU.

Keep reading

Crypto’s next billion-dollar hacker may move at superhuman speed

Anthropic’s new Claude Fable 5 puts powerful cyber tools behind safety filters. DeFi, already hit by more than $840 million in hacks this year, is one of the industries with the most to lose if the filters fail.

The newest AI model from Anthropic, which gives users access to stronger, faster reasoning and coding capabilities, lands in a crypto market beset by security problems and could well exacerbate them.

The company released Claude Fable 5 on Tuesday, the first public model in the Mythos class and, Anthropic says, its most powerful yet. So powerful, in fact, the company released two versions: one for widespread use and the other for more restricted distribution.

The public version sports stronger reasoning and coding ability while blocking the most dangerous uses. A less-hamstrung counterpart, Claude Mythos 5, is available only to vetted users in cybersecurity and critical infrastructure.

Experts say Mythos can find and chain zero-day vulnerabilities, or previously unknown software flaws, and help turn a bug into a working attack. Anthropic says the software tries to intercept possible attack vectors by detecting high-risk requests. Once identified, they are routed to a weaker model, Claude Opus 4.8.

The company says this specific fallback triggers in fewer than 5% of sessions. It also said in a blog post that specialized cybersecurity teams and more than 1,000 hours of external bug-bounty work found no universal way of breaking the system.

Still, Anthropic recognizes that the system is unlikely to be foolproof and says it expects determined, well-funded attackers to keep trying because the capability is valuable.

“The uplift from Mythos-level capabilities is valuable to many adversaries—for instance, those who could financially gain from cyberattacks—and we therefore expect them to be motivated to try to circumvent our safety measures,” the firm said in the post.

Keep reading

France’s Own Hack Is the Best Argument Against Its War on Encryption

Brussels and a run of European governments, France loud among them, have spent the past few years treating strong encryption as a problem to be solved.

The argument behind proposals like Chat Control is that the state needs a way to scan private messages to keep people safe and that it can be trusted to hold that kind of access without abusing it or losing control of it.

But France just handed that argument an awkward rebuttal. Tchap, the messenger the French government built for its own civil servants, got breached.

France’s National Cybersecurity Agency, ANSSI, detected the compromise on June 7, and DINUM, the digital affairs directorate that runs the platform, blocked the account involved and published an incident notice.

The intrusion broke neither the encryption nor the servers. Someone hijacked a legitimate user account, which is all an attacker needs when any one credential is a key to the same building.

That detail is the part the backdoor crowd keeps refusing to absorb. The encryption on Tchap did its job. DINUM says private conversations stay end-to-end encrypted even when an account is impersonated and that the attacker could reach only the unencrypted public chat rooms any authenticated user is able to find.

Security researchers were quick to note what that reassurance skips over. An attacker wearing a real user’s identity can see whatever that account sees in the moment, private rooms included.

A government backdoor is exactly that, an access path bolted on beside working encryption and France just demonstrated it cannot keep one of those paths shut for a single weekend.

DINUM has notified CNIL, the French data protection regulator, because personal information may have surfaced in whatever the attacker viewed. The directorate described its handling of the intrusion in a press release.

“At this stage, the account originating the malicious requests has been identified. It was immediately blocked to remove the attacker’s persistent access and allow for a thorough analysis of the data they were able to access. The investigation continues, including the study of event logs, to identify the conversations that the attacker was able to access and the nature of the exfiltrated data,” DINUM said.

The directorate also pushed responsibility back toward its own users, reminding them where the safe lines were supposed to be.

“A message has been sent to all Tchap users reminding them that a public chat room can be found and joined by any user and that its content is not encrypted. In accordance with Tchap’s terms of service, no personal, sensitive, or confidential information should be exchanged in public chat rooms: such exchanges should be reserved for private chat rooms.”

Keep reading

AI Fail: Meta’s Support Chatbot Helped Hijack High-Profile Instagram Accounts Including Obama White House

Hackers have successfully compromised numerous prominent Instagram accounts including the Barack Obama White House profile by simply asking Meta’s AI support chatbot to change the email addresses associated with target profiles, security researchers report.

404 Media reports that a newly discovered vulnerability in Meta’s AI-powered customer support system has enabled hackers to take over several high-profile Instagram accounts through a surprisingly straightforward method. The breach has affected numerous notable accounts, including the Barack Obama White House Instagram profile, the Chief Master Sergeant of Space Force’s account, and the official Sephora company account.

The exploitation technique requires minimal technical sophistication. Hackers have been sharing videos and screenshots in Telegram groups frequented by security researchers and hacking communities, demonstrating the alarming ease with which accounts can be compromised. In one documented case, an attacker initiated a conversation with Meta’s AI support bot and made a simple request to link a target account with a new email address, providing the target username and the attacker’s email address while promising to send a verification code.

Keep reading