The reborn Kimwolf v7 botnet resolves its command servers through Ethereum Name Service across five shuffled endpoints, then falls back to a fixed Tor hidden service if every one of them fails. It is a case study in why onion services remain the most seizure-resistant C2 channel criminals have.
Connor Riley Moucka pleaded guilty to breaching 165 Snowflake customer accounts and selling the haul on hacking forums - and his own sales threads are now evidence in a case that could put him away for 32 years.
The FBI and IRS Criminal Investigation seized hundreds of NetNut domains on July 2, 2026, exposing a residential proxy network built on two million compromised smart TVs. For Tor users, it is another reminder that anonymization infrastructure keeps collapsing under law-enforcement pressure.
A single cybercrime vendor known as TheHatman listed roughly 3.64 million Azure and Entra directory records from McDonald's, TCS, Vodafone, and six other large companies between July 31 and August 16, 2026. Hudson Rock assesses the dumps as highly likely authentic, while TCS denies any credible breach.
Mandiant tracks UNC6671, a voice-phishing and extortion operation tied to The Com that has run at least four victim-facing brands on shared infrastructure since January 2026, hitting financial firms including Apollo and Moody's with demands starting near $3 million.
The Silent Ransom Group's leak site has grown from 38 listed law firms in April to 64 by August 21, 2026, with Troutman Pepper Locke client records including tens of thousands of Social Security numbers now posted after the firm reportedly stayed silent.
A race condition fixed in Tor 0.4.9.11 allowed a hostile rendezvous point to man-in-the-middle an onion service connection under rare timing conditions. We explain the bug, why the 0.4.8 sunset makes upgrading urgent, and what it means for operators.
ShinyHunters listed threat-intelligence firm ReliaQuest on its leak site on August 23 with screenshots but no verifiable evidence, days after the firm published research into the group's campaigns. The claim remains unconfirmed.
Intelligence firms and US agencies have moved past asking whether criminals use AI. Flashpoint's monthly reporting, a joint NSA and FBI advisory, and two documented intrusion cases show exactly where large language models now sit inside illicit workflows.
Initial access brokers now advertise corporate VPN, RDP and admin credentials alongside active recruitment of employees on messaging apps. Flashpoint's latest insider threat data shows a market that has professionalized faster than most defenses.
A ransomware affiliate posing as a recovery service contacted victims mid-attack, offering decryptors and data deletion for a fee. How the double-dip scam works, the red flags, and what legitimate incident response actually looks like.
Truffle Security re-verified four years of publicly leaked AWS access keys and found 88 percent of them still authenticate, including 768 that grant full control of corporate accounts. Here is what that means for self-hosters running onion infrastructure.