2853 stories
·
0 followers

Nearly 40,000 phishing attacks hit US financial firms in H1 2026 — automated AI agents and a new Seychelles bulletproof host fuel aggressive new campaigns

1 Share
  • US financial services faced nearly 40,000 phishing URLs during H1 2026
  • Attackers used 645 hosting providers to distribute financial phishing campaigns
  • Free hosting carried 12.6% of phishing URLs targeting financial services

Phishing campaigns targeting American financial institutions are spreading across a fragmented web of hosting services, making fraudulent infrastructure difficult to contain.

New research from Netcraft has uncovered almost 40,000 unique phishing URLs connected to US financial services were discovered in the first half of 2026.

Behind those URLs were 645 hosting providers and 576 registrars, while newer services and automated AI tools helped attackers move quickly between platforms.

Cheap infrastructure is helping campaigns multiply

The scale of the activity becomes clearer when the services carrying these attacks are examined rather than the fraudulent websites alone.

Free developer and application hosting accounted for 12.6% of phishing URLs recorded against US financial services during H1 2026.

That means approximately one in eight observed attacks relied upon infrastructure that attackers could access without paying conventional hosting fees.

Netcraft observed significant changes in infrastructure use between Q1 and Q2, suggesting criminals were switching services as infrastructure became unavailable or less useful.

AI is making that movement easier by helping users create websites, reproduce legitimate pages and deploy malicious infrastructure with less technical effort.

Netcraft said generative AI website builders and cloning tools increasingly include free web hosting options, further reducing the work required to establish campaigns.

The financial brands being impersonated also show where attackers are concentrating their efforts across the sector during the reporting period.

Payment service providers accounted for 37.2% of observed phishing activity, with PayPal representing 80.6% of attacks within that subsector.

American Express accounted for 72.8% of observed activity involving card networks, showing how heavily campaigns can focus on recognizable financial brands.

Omegatech emerges as another source of attack infrastructure

The infrastructure picture changed further with the emergence of Omegatech, a paid hosting provider based in the Seychelles, which started operations in January 2026.

By June, Netcraft attributed roughly 3% of observed phishing attacks against US financial services to infrastructure hosted through Omegatech.

One cluster contained 16 .es domains that generated 585 unique attack URLs between March 25 and April 21 2026.

Those domains were used to impersonate 41 financial brands through subdomains, allowing one cluster to support campaigns against numerous institutions.

Registration data for many of those domains was unavailable, limiting visibility into the companies responsible for registering the infrastructure.

Omegatech's emergence came as another major campaign was winding down after targeting Fidelity Investments through the Darcula phishing platform.

That operation fell sevenfold from Q1 to Q2, after previously accounting for more than half of phishing infrastructure impersonating Fidelity.

Meanwhile, financially motivated North Korean groups and organized criminal operators continued pursuing banks, cryptocurrency services and compromised accounts.

The changing mix suggests that attackers are not relying on one platform, campaign or technique to reach financial customers.

Financial companies are advised to closely monitor newly registered domains, restrict suspicious links and strengthen employee verification procedures against impersonation attempts.

Google logo on a black background next to text reading 'Click to follow TechRadar'



Read the whole story
NerdsToGo
1 day ago
reply
Share this story
Delete

Dell System Update flaw allows attackers to gain root privileges (CVE-2026-86360)

1 Share

Dell is urging customers to patch a vulnerability (CVE-2026-86360) in Dell System Update (DSU) that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges. DSU is a tool used by enterprise IT administrators to apply driver, BIOS, and firmware updates to Dell PowerEdge servers. About CVE-2026-86360 CVE-2026-86360 is a path traversal vulnerability with a CVSS base score of 9.6 that affects DSU versions prior to 2.3.0.0. “An unauthenticated attacker with remote … More →

The post Dell System Update flaw allows attackers to gain root privileges (CVE-2026-86360) appeared first on Help Net Security.

Read the whole story
NerdsToGo
1 day ago
reply
Share this story
Delete

FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware

1 Share

An alleged leader of Tren de Aragua’s ATM jackpotting activities, Canelon Aguirre was on the FBI’s top 10 most wanted list since March 2026.

The post FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware appeared first on SecurityWeek.

Read the whole story
NerdsToGo
1 day ago
reply
Share this story
Delete

Dell System Update Tool Flaw Enables Code Execution Attacks

1 Share

Dell has patched a critical path traversal flaw, CVE-2026-86360, in its System Update (DSU) tool. An unauthenticated remote attacker could use it to run code with root privileges. Four other high-severity bugs were fixed in the same release.

Dell System Update flaw

According to advisory DSA-2026-324 published by Dell on October 1, 2026, the update covers five vulnerabilities in Dell System Update, and every version before 2.3.0.0 is affected. DSU is a command-line tool that enterprise IT teams use to deploy BIOS, firmware and software updates to PowerEdge servers on Linux and Windows.

The critical flaw, CVE-2026-86360, is an “Improper Limitation of a Pathname to a Restricted Directory” bug (CWE-22, path traversal).

Dell rates it CVSS 9.6, with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H. Dell says an unauthenticated attacker with remote access could gain filesystem access. It also warns the flaw could be used to execute arbitrary code with root privileges, which may fully compromise the application and the underlying operating system.

Because the tool runs privileged, a path traversal that escapes its expected directories can lead directly to root execution. One third-party write-up lists a score of 9.8, which differs from Dell’s 9.6. Dell’s figure is the vendor rating.

CVECVSSWeaknessAttacker position and impact
CVE-2026-863609.6Path traversalUnauthenticated, remote; root code execution
CVE-2026-863618.2Incorrect permission assignmentLow-privileged, local; privilege escalation
CVE-2026-863628.2Improper access controlLow-privileged, local; privilege escalation
CVE-2026-636977.6Improper certificate validationHigh-privileged, remote; remote execution
CVE-2026-711687.3Path traversalLow-privileged, local; remote execution

DSU sits on the management plane. It is the tooling trusted to patch an entire server fleet, so a compromise there can give an attacker a foothold across many PowerEdge hosts.

Teams that have wired DSU into automated patch pipelines face extra risk. A stale cached DSU binary would keep the vulnerability open.

The CVSS vector for the critical bug includes user interaction (UI:R). Defenders should not treat it as a purely wormable, zero-click issue.

Dell has reported no active exploitation. CSO Online also says Dell has no evidence of in-the-wild attacks, and reporting notes no public proof-of-concept. The disclosure came alongside fixes for Dell Container Storage Modules, which CSO counts as 18 new CVEs across the two notices.

Public details of the path traversal may let attackers reverse-engineer the patch. Treat the flaws as likely targets even though no attacks have been seen.

Dell lists no workarounds, so customers must update. The fixed release is Dell System Update 2.3.0.0 or later, which resolves all five CVEs. Administrators should inventory DSU installs on all PowerEdge hosts, including standalone systems outside central management, and upgrade anything older than 2.3.0.0.

Teams should confirm automated pipelines pull the fixed binary rather than a cached older build, restrict network access to DSU hosts until patching is complete, and review logs on DSU systems for unexpected file writes or privileged process launches. Dell recommends customers upgrade “at the earliest opportunity.”

The post Dell System Update Tool Flaw Enables Code Execution Attacks appeared first on Cyber Security News.



Read the whole story
NerdsToGo
1 day ago
reply
Share this story
Delete

Hackers stole Pentagon personnel records of over 3 million people

1 Share
The Pentagon's Defense Manpower Data Center (DMDC) is notifying millions of military service members that hackers stole their data after breaching the Pentagon's human resources management system in October 2025. [...]
Read the whole story
NerdsToGo
5 days ago
reply
Share this story
Delete

Critical TeamViewer Vulnerabilities Enable Remote Code Execution and Privilege Escalation Attacks

1 Share

TeamViewer has released security updates for five high-severity vulnerabilities in its remote-access software that could enable remote code execution, local privilege escalation, arbitrary file writes, and bypasses of user-configured session permissions.

The flaws, tracked under bulletin TV-2026-1010, affect TeamViewer Full Client and Host installations across Windows, Linux, and macOS, with the most severe issue carrying a CVSS score of 8.8.

The company said it addressed the vulnerabilities in TeamViewer version 15.82 and corresponding supported maintenance and legacy releases. TeamViewer is not aware of public disclosure or active exploitation of the flaws in the wild at the time of the September 29, 2026 advisory.

Critical TeamViewer Vulnerabilities

The highest-rated vulnerability, CVE-2026-92370, is an improper access control issue affecting TeamViewer Full Client, Host, and related modules prior to version 15.82 on Windows, Linux, and macOS. It received a CVSS score of 8.8.

An authenticated remote attacker could allegedly manipulate access-control parameters during session establishment to bypass restrictions explicitly configured by the target user.

This could allow the attacker to perform unauthorized session actions that were intended to be blocked, potentially leading to remote code execution on the affected device.

Because TeamViewer is commonly deployed for help-desk support, unattended device management, and enterprise remote administration, a permission-bypass flaw could create significant risk where attackers gain or abuse remote-session access.

Organizations should review TeamViewer permission profiles and audit recent session activity while applying the update.

CVE-2026-19743 is a path traversal vulnerability in TeamViewer’s local IPC service. It affects Full Client and Host deployments before version 15.82 across Windows, Linux, and macOS, and has a CVSS score of 7.8.

A locally authenticated, low-privileged attacker could send crafted IPC commands to the TeamViewer service daemon and abuse insufficient path validation.

Successful exploitation could permit arbitrary file writes with elevated permissions, including NT AUTHORITY\SYSTEM on Windows or root on Linux and macOS, resulting in local privilege escalation.

Two other vulnerabilities also create elevation-of-privilege risks. CVE-2026-92369 is a Windows installer rollback race condition.

A local attacker could replace rollback backup files in a user-writable temporary directory before an elevated installer restores them, potentially obtaining SYSTEM privileges. Exploitation requires a successful race condition during installation or an update rollback.

CVE-2026-92371 affects Linux Cloud Session Recording functionality. The flaw stems from improper link resolution and a race condition between path validation and file access, enabling a local authenticated attacker to redirect privileged file operations to unintended locations.

TeamViewer also patched CVE-2026-92368, a heap-based buffer overflow in the handling of .tvs session-recording files on Linux and macOS. The vulnerability arises from a size mismatch during decompression of recorded session data.

An attacker could craft a malicious recording file and persuade a victim to open it through TeamViewer’s “Play or convert recorded session” feature. If successful, the flaw could cause out-of-bounds heap writes and enable arbitrary code execution with the logged-in user’s privileges.

Administrators should treat unsolicited .tvs files as potentially malicious, particularly on endpoints that have not yet been updated.

Endpoint-monitoring teams should also investigate unusual TeamViewer recording playback activity, unexpected installer rollbacks, and suspicious file writes involving TeamViewer service processes.

Organizations should update TeamViewer Full Client and Host installations to version 15.82 or later immediately. This includes Windows, Linux, and macOS systems, as well as TeamViewer Remote, TeamViewer Tensor, and TeamViewer ONE environments using affected client components.

Supported older branches have also received fixes, including version 15.64.8 for Windows 7 and Windows 8, version 14.7.48855, and version 13.2.36230 or related platform-specific releases.

Security teams should inventory unmanaged endpoints and confirm that remote-access tooling is updated consistently, since TeamViewer deployments often span employee workstations, servers, third-party support systems, and unattended devices.

Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort. Explore for your team 

The post Critical TeamViewer Vulnerabilities Enable Remote Code Execution and Privilege Escalation Attacks appeared first on Cyber Security News.



Read the whole story
NerdsToGo
5 days ago
reply
Share this story
Delete
Next Page of Stories