• A security audit of 2,857 skills on ClawHub has found 341 malicious skills across multiple campaigns, according to new findings from Koi Security, exposing users to new supply chain risks. ClawHub is a marketplace designed to make it easy for OpenClaw users to find and install third-party skills. It’s an extension to the OpenClaw project, a self-hosted artificial intelligence (AI) assistant

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A months-long breach allowed Chinese State-sponsored hackers to hijack Notepad++ updates in 2025, exposing users to malware via a compromised hosting provider.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Shutdown begins as Congress hopes to keep duration minimal. The Senate on Friday evening approved a spending package that ensures nearly all agencies are funded through fiscal 2026, but the agreement came too late to stave off an appropriations lapse, Eric Katz of Government Executive reports

    With House lawmakers in recess until today, funding cannot be restored until the afternoon at the earliest. But that vote isn’t expected until at least Tuesday, according to The Hill and Reuters.

    Recap: Senate Democrats and the White House came to an agreement late Thursday to fund the vast majority of federal agencies, while providing a two-week stopgap continuing resolution to the Homeland Security Department. Democrats want more restrictions placed on DHS’s immigration enforcement as part of that agency’s funding bill.

    Possible DHS reforms include the removal of masks by federal law enforcement personnel, mandated use of body cameras, a requirement for third-party warrants to enter homes, the end of roving patrols in metropolitan areas by Immigration and Customs Enforcement and more uniform restrictions on use of force by federal agents. Democrats plan to negotiate over those items with the White House while the two-week DHS continuing resolution is in effect.

    “Border czar” Homan’s rhetoric of war. Top Border Patrol official Tom Homan said there are still “around 3,000” immigration agents with either ICE or CBP in Minnesota. “They've been in theater—some of these people have been in theater for eight months,” Homan said at a press conference Friday. “So there's going to be rotations of personnel. Hopefully less now that we have some agreements, maybe we can make it more efficient and safe. But they've been in theater a long time.”

    • Second opinion: CIA veteran Marc Polymeropoulos found Homan’s description of immigration enforcement unnecessary. “wtf,” Polymeropoulos wrote on social media. “This isn’t Fallujah. It’s where the f’ng Twins play,” he said, referring to the city’s Major League Baseball team. 

    Homan also said he hopes immigration agents don’t kill anymore people in Minnesota. “The President, one of the words he said to me, I came up here, he said he didn't want to see anybody die,” he told reporters. “The less interference, the less rhetoric,” he said. “I buried ICE agents throughout my career, and the saddest thing I've ever done is hand a folded flag to a wife or a child. I don't want to see anybody die. Even the people we're looking for. I don't want to see anybody die.”

    “When we go find that bad guy, when we find that bad guy, many times it's with others,” Homan said. “But we're going to enforce immigration law…We're going to do target enforcement operations and we're going to prioritize the public-safety threats and national-security threats. That is what we're here to do.” 

    Update: ProPublica has ID’d the two immigration agents who killed VA nurse Alex Pretti nine days ago. Their names are Jesus Ochoa, 43, and Raymundo Gutierrez, 35. 

    Why name these agents? “We believe there are few investigations that deserve more sunlight and public scrutiny than this one, in which two masked agents fired 10 shots at Pretti as he lay on the ground after being pepper-sprayed,” the news outlet said in an editor’s note. “The Department of Justice said it is investigating the incident, but the names of the two agents have been withheld from Congress and from state and local law enforcement.”

    “The policy of shielding officers’ identities, particularly after a public shooting, is a stark departure from standard law enforcement protocols,” ProPublica said, citing lawmakers, state attorneys general, and former federal officials in this break from precedent. “Such secrecy, in our view, deprives the public of the most fundamental tool for accountability.” Story, here

    ICE agents in Minnesota ran a woman from Ecuador off the road, causing her to crash, and “in the course of her arrest” hurt her enough that she required seven days in the hospital. Politico’s Kyle Cheney flagged that development on social media Sunday. 

    In a separate encounter some likened to actions of a drug cartel, immigration agents tracked down an observer in her car, raced ahead of it in three unmarked cars and then stopped suddenly before jumping out and surrounding her vehicle with their guns drawn just outside of St. Peter, Minn., on Thursday. The scene was recorded on the U.S. citizen’s dash camera and shared with Minnesota Public Radio, which posted it to YouTube. 

    They opened her car door, dragged her out and handcuffed her on the ground before putting her in their vehicle and driving off. They traveled about 20 minutes before one of the agents received a phone call, and they exited the freeway and dropped her at the St. Peter police station. The police chief then “spoke with her, had her get into his squad car, and took her home,” MPR reports. Homeland Security officials put out a statement two days later calling the woman an “agitator” who ran stop signs while allegedly “stalking and obstructing law enforcement.”

    Another Border Patrol agent was found drunk in his car and covered in vomit early Tuesday morning in St. Paul. After failing a sobriety test, he was later arrested and charged with 3rd and 4th degree driving while impaired, a local outlet, the Sahan Journal, reported Thursday. 

    A judge in Texas sharply criticized federal officials and agents when ordering the release of asylum seeker Adrian Conejo Arias and his five-year-old son Liam this weekend. Both were detained earlier this month in Minnesota when agents detained Liam and used him as bait to arrest his father as well. 

    “Observing human behavior confirms that for some among us, the perfidious lust for unbridled power and the imposition of cruelty in its quest know no bounds and are bereft of human decency. And the rule of law be damned,” the judge wrote in the order


    Welcome to this Monday edition of The D Brief, a newsletter focused on developments affecting the future of U.S. national security, brought to you by Ben Watson with Bradley Peniston. It’s more important than ever to stay informed, so we’d like to take a moment to thank you for reading. Share your tips and feedback here. And if you’re not already subscribed, you can do that here. On this day in 1943, German forces surrendered at Stalingrad, ending a battle that broke the Wehrmacht’s offensive capability. Total Nazi and Soviet casualties are estimated at 2 million and up.

    Federal agents now have even broader power to arrest people without a warrant, according to an internal ICE memo the New York Times obtained late last week. The updated directive “centers on a federal law that empowers agents to make warrantless arrests of people they believe are undocumented immigrants, if they are ‘likely to escape’ before an arrest warrant can be obtained.” 

    Previously similar conditions had been applied to those allegedly posing a “flight risk,” but now they’re much wider—which would seem to make “the general premise of ever getting a warrant pointless,” one expert told the Times

    ICE agents surrounded another American in her car, broke her window, pulled her out and gave her a concussion, bruised ribs and a torn rotator cuff during a violent encounter Thursday in Salem, Oregon. Her local union said she was running errands when she was assaulted by four federal agents who demanded her “paper” while she was driving alone in Salem. 

    “The agents emptied her purse, discovered her passport, then left Maria there without seeking medical attention for her,” the union said in a statement Saturday. After the encounter, she called the police, who told her she should call the FBI since federal agents were the ones who assaulted her. The Salem Reporter has a bit more. Meanwhile to the south in Eugene, “protesters broke windows and tried to get inside the Federal Building near downtown” on Friday, the Associated Press reports. “City police declared a riot and ordered the crowd to disperse.”

    Portland’s mayor is demanding ICE leave the Oregon city after agents fired rubber bullets, pepper balls and tear gas at demonstrators, including children, at a Saturday protest the mayor described as peaceful. “Federal forces deployed heavy waves of chemical munitions, impacting a peaceful daytime protest where the vast majority of those present violated no laws, made no threat, and posed no danger to federal forces,” Mayor Keith Wilson said in a statement Saturday evening. 

    “To those who continue to work for ICE: Resign. To those who control this facility: Leave,” the mayor said. “Through your use of violence and the trampling of the Constitution, you have lost all legitimacy and replaced it with shame,” he added. He also said the city is “moving swiftly to operationalize an ordinance that went into effect this month, imposing a fee on detention facilities that use chemical agents. As we prepare to put that law into action, we are also documenting today's events and preserving evidence. The federal government must, and will, be held accountable.”

    Bigger picture: “It appears the crime rate of CBP agents and offices was higher PER CAPITA than the crime rate of undocumented immigrants,” journalist Garrett Graff testified Friday after reviewing decades of public data as part of Illinois Governor J.B. Pritzker’s Illinois Accountability Commission. Over the last decade, the arrest rate alone for CBP officers and agents (.5%) is higher than the arrest rate of undocumented immigrants in the United States (.4%), according to data from the National Institute of Justice. 

    “Criminality is so rampant inside CBP that it has seen one of its own agents or officers arrested every 24 to 36 hours since 2005,” he testified Friday. “According to CBP’s own discipline reports, over the 20 years from 2005 to 2024—the last year numbers are available—at least 4,913 CBP officers and Border Patrol agents have been arrested themselves, some multiple times.” But it doesn’t end there. “CBP’s arrest and misconduct rate is FIVE TIMES higher than other federal law enforcement agencies,” Graff reports. 

    “US federal law enforcement has never experienced a scandal as big, as far-reaching, destructive, and as far-lasting as the wave of corruption and criminality that has overtaken CBP and the Border Patrol since 2005,” Graff writes in his 50-page analysis of these historical trends. “It is a scandal that has played out the way too many Washington scandals do: With no single headline-grabbing crisis moment ever provoking action—just a steady drip-drip of allegations, misdeeds, and missed opportunities.”

    Why bring all this up? “Congress is debating right now what, if any, changes it will attempt to force on the way that ICE and CBP operate—these next two weeks are one of the biggest opportunities we have as a nation to change what we see happening in our country,” Graff says. 

    After all, before Trump took office last January, “ICE and CBP managed to go about its work in such a way that didn’t cause ordinary law-abiding US citizens to fear for their lives; ICE or CBP agents didn’t routinely operate wearing masks and deploy teargas daily against US citizens; the entire school systems of major US cities didn’t have to close in fear of CBP and ICE operaGons targeting neighborhoods, and professional sports leagues like the NBA didn’t have to cancel games because of ICE and CBP violence in major American cities. Something big has changed.” Read more, here

    Also: ICE confirmed Sunday there is a measles outbreak at its 2,400-person holding facility for immigrants in Dilley, Texas, San Antonio’s News4 reported. The facility now holds about 1,200 people, including 400 children, according to the San Antonio Current.

    Additional reading: 

    Around the Defense Department

    Pentagon taps six to lead critical technology areas. “The six CTAs are department-wide imperatives designed to maintain American military dominance — and now, each one will have accountable leaders leading the tangible ‘sprints’ under each CTA. Each sprint will be designed to deliver advanced capabilities to our warfighters rapidly and at scale,” the Pentagon said in Thursday-night social-media posts. DefenseScoop rolls them up, here

    SOUTHCOM gets a new commander. It’s Marine Lt. Gen. Francis Donovan, who had been serving as vice commander of U.S. Special Operations Command until he was approved by voice vote of the Senate on Friday evening. Donovan’s predecessor, Adm. Alvin Holsey, abruptly resigned last year in the wake of reported concerns about the Trump administration’s bombing of alleged drug boats. DefenseScoop has a bit more, here.

    Space Force stands up NORTHCOM element. It’s the latest cocom component established by the newest service branch, which stood up its SOUTHCOM component late last year. Air & Space Forces mag has a bit more, here.

    Ukraine

    Russian drone kills a dozen civilians ahead of peace talks. Associated Press: “A Russian drone strike on the Ukrainian city of Dnipro hit a bus carrying mineworkers and killed at least a dozen people, Ukrainian authorities said Sunday, hours after President Volodymyr Zelenskyy announced that the next round of peace talks between Russian and Ukrainian delegations will take place on Wednesday and Thursday.” Read on, here.

    Middle East

    Israel air strikes kill dozens in Gaza. At least 32 people were killed in air strikes in the Gaza Strip on Saturday, according to the region’s civil defense agency, which is operated by Hamas. “Palestinians have described these strikes as the heaviest since the second phase of the ceasefire, brokered by US President Trump last October, came into effect earlier this month,” the BBC reported. “The Israeli military confirmed that a number of strikes were carried out in response to what it said was a Hamas violation of the agreement on Friday.” More, here.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A high-severity security flaw has been disclosed in OpenClaw (formerly referred to as Clawdbot and Moltbot) that could allow remote code execution (RCE) through a crafted malicious link. The issue, which is tracked as CVE-2026-25253 (CVSS score: 8.8), has been addressed in version 2026.1.29 released on January 30, 2026. It has been described as a token exfiltration vulnerability that leads to

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A prolific data ransom gang that calls itself Scattered Lapsus ShinyHunters (SLSH) has a distinctive playbook when it seeks to extort payment from victim firms: Harassing, threatening and even swatting executives and their families, all while notifying journalists and regulators about the extent of the intrusion. Some victims reportedly are paying — perhaps as much to contain the stolen data as to stop the escalating personal attacks. But a top SLSH expert warns that engaging at all beyond a “We’re not paying” response only encourages further harassment, noting that the group’s fractious and unreliable history means the only winning move is not to pay.

    Image: Shutterstock.com, @Mungujakisa

    Unlike traditional, highly regimented Russia-based ransomware affiliate groups, SLSH is an unruly and somewhat fluid English-language extortion gang that appears uninterested in building a reputation of consistent behavior whereby victims might have some measure of confidence that the criminals will keep their word if paid.

    That’s according to Allison Nixon, director of research at the New York City based security consultancy Unit 221. Nixon has been closely tracking the criminal group and individual members as they bounce between various Telegram channels used to extort and harass victims, and she said SLSH differs from traditional data ransom groups in other important ways that argue against trusting them to do anything they say they’ll do — such as destroying stolen data.

    Like SLSH, many traditional Russian ransomware groups have employed high-pressure tactics to force payment in exchange for a decryption key and/or a promise to delete stolen data, such as publishing a dark web shaming blog with samples of stolen data next to a countdown clock, or notifying journalists and board members of the victim company. But Nixon said the extortion from SLSH quickly escalates way beyond that — to threats of physical violence against executives and their families, DDoS attacks on the victim’s website, and repeated email-flooding campaigns.

    SLSH is known for breaking into companies by phishing employees over the phone, and using the purloined access to steal sensitive internal data. In a January 30 blog post, Google’s security forensics firm Mandiant said SLSH’s most recent extortion attacks stem from incidents spanning early to mid-January 2026, when SLSH members pretended to be IT staff and called employees at targeted victim organizations claiming that the company was updating MFA settings.

    “The threat actor directed the employees to victim-branded credential harvesting sites to capture their SSO credentials and MFA codes, and then registered their own device for MFA,” the blog post explained.

    Victims often first learn of the breach when their brand name is uttered on whatever ephemeral new public Telegram group chat SLSH is using to threaten, extort and harass their prey. According to Nixon, the coordinated harassment on the SLSH Telegram channels is part of a well-orchestrated strategy to overwhelm the victim organization by manufacturing humiliation that pushes them over the threshold to pay.

    Nixon said multiple executives at targeted organizations have been subject to “swatting” attacks, wherein SLSH communicated a phony bomb threat or hostage situation at the target’s address in the hopes of eliciting a heavily armed police response at their home or place of work.

    “A big part of what they’re doing to victims is the psychological aspect of it, like harassing executives’ kids and threatening the board of the company,” Nixon told KrebsOnSecurity. “And while these victims are getting extortion demands, they’re simultaneously getting outreach from media outlets saying, ‘Hey, do you have any comments on the bad things we’re going to write about you.”

    Nixon argues that no one should negotiate with SLSH because the group has demonstrated a willingness to extort victims based on promises that it has no intention to keep. Nixon points out that all of SLSH’s known members hail from The Com, shorthand for a constellation of cybercrime-focused Discord and Telegram communities which serve as a kind of distributed social network that facilitates instant collaboration.

    Nixon said Com-based extortion groups tend to instigate feuds and drama between group members, leading to lying, betrayals, credibility destroying behavior, backstabbing, and sabotaging each other.

    “With this type of ongoing dysfunction, often compounding by substance abuse, these threat actors often aren’t able to act with the core goal in mind of completing a successful, strategic ransom operation,” Nixon said. “They continually lose control with outbursts that put their strategy and operational security at risk, which severely limits their ability to build a professional, scalable, and sophisticated criminal organization network for continued successful ransoms – unlike other, more tenured and professional criminal organizations focused on ransomware alone.”

    Intrusions from established ransomware groups typically center around encryption/decryption malware that mostly stays on the affected machine. In contrast, Nixon said, ransom from a Com group is often structured the same as violent sextortion schemes against minors, wherein members of The Com will steal damaging information, threaten to release it, and “promise” to delete it if the victim complies without any guarantee or technical proof point that they will keep their word. She writes:

    The SLSH group steals a significant amount of corporate data, and on the day of issuing the ransom notification, they line up a number of harassment attacks to be delivered simultaneously with the ransom. This can include swatting, DDOS, email/SMS/call floods, negative PR, complaints sent to authority figures in and above the company, and so on. Then, during the negotiation process, they lay on the pressure with more harassment- never allowing too much time to pass before a new harassment attack.

    What they negotiate for is the promise to not leak the data if you pay the ransom. This promise places a lot of trust in the extorter, because they cannot prove they deleted the data, and we believe they don’t intend to delete the data. Paying provides them vital information about the value of the stolen dataset which we believe will be useful for fraud operations after this wave is complete.

    A key component of SLSH’s efforts to convince victims to pay, Nixon said, involves manipulating the media into hyping the threat posed by this group. This approach also borrows a page from the playbook of sextortion attacks, she said, which encourages predators to keep targets continuously engaged and worrying about the consequences of non-compliance.

    “On days where SLSH had no substantial criminal ‘win’ to announce, they focused on announcing death threats and harassment to keep law enforcement, journalists, and cybercrime industry professionals focused on this group,” she said.

    An excerpt from a sextortion tutorial from a Com-based Telegram channel. Image: Unit 221B.

    Nixon knows a thing or two about being threatened by SLSH: For the past several months, the group’s Telegram channels have been replete with threats of physical violence against her, against Yours Truly, and against other security researchers. These threats, she said, are just another way the group seeks to generate media attention and achieve a veneer of credibility, but they are useful as indicators of compromise because SLSH members tend to name drop and malign security researchers even in their communications with victims.

    “Watch for the following behaviors in their communications to you or their public statements,” Nixon said. “Repeated abusive mentions of Allison Nixon (or “A.N”), Unit 221B, or cybersecurity journalists—especially Brian Krebs—or any other cybersecurity employee, or cybersecurity company. Any threats to kill, or commit terrorism, or violence against internal employees, cybersecurity employees, investigators, and journalists.”

    Unit 221B says that while the pressure campaign during an extortion attempt may be traumatizing to employees, executives, and their family members, entering into drawn-out negotiations with SLSH incentivizes the group to increase the level of harm and risk, which could include the physical safety of employees and their families.

    “The breached data will never go back to the way it was, but we can assure you that the harassment will end,” Nixon said. “So, your decision to pay should be a separate issue from the harassment. We believe that when you separate these issues, you will objectively see that the best course of action to protect your interests, in both the short and long term, is to refuse payment.”

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft has announced a three-phase approach to phase out New Technology LAN Manager (NTLM) as part of its efforts to shift Windows environments toward stronger, Kerberos-based options. The development comes more than two years after the tech giant revealed its plans to deprecate the legacy technology, citing its susceptibility to weaknesses that could facilitate relay attacks and allow bad

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Ivanti has disclosed two critical remote code execution (RCE) flaws (CVE-2026-1281 & CVE-2026-1340) in its EPMM software.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • This week in cybersecurity from the editors at Cybercrime Magazine

    Sausalito, Calif. – Feb. 2, 2026

    Read the full story in Moneywise

    Cybercrime will cost the world more than $12 trillion annually by 2031, according to Cybersecurity Ventures, and most of that money will never be recovered. But for a 71-year-old Vermont retiree, her case is the exception.

    Jeanette Voss lost nearly $1 million, and then got it all back 4 years later. Credit goes to U.S. Secret Service agents, who recovered the victim’s funds by tracking cryptocurrency wallets tied to an international scam ring, reports New Hampshire Public Radio and Vermont media outlet Seven Days.

    While the recovery doesn’t erase years of stress and deprivation for Voss, it transformed what began as a cautionary tale into one of the rare feel-good endings in the world of cybercrime.

    Moneywise explains what happened to her, and how to protect yourself.

    Read the Full Story



    Cybercrime Magazine is Page ONE for Cybersecurity. Go to any of our sections to read the latest:

    • SCAM. The latest schemes, frauds, and social engineering attacks being launched on consumers globally.
    • NEWS. Breaking coverage on cyberattacks and data breaches, and the most recent privacy and security stories.
    • HACK. Another organization gets hacked every day. We tell you who, what, where, when, and why.
    • VC. Cybersecurity venture capital deal flow with the latest investment activity from various sources around the world.
    • M&A. Cybersecurity mergers and acquisitions including big tech, pure cyber, product vendors and professional services.
    • BLOG. What’s happening at Cybercrime Magazine. Plus the stories that don’t make headlines (but maybe they should).
    • PRESS. Cybersecurity industry news and press releases in real time from the editors at Business Wire.
    • PODCAST. New episodes daily on the Cybercrime Magazine Podcast feature victims, law enforcement, vendors, and cybersecurity experts.
    • RADIO. Tune into WCYB Digital Radio at Cybercrime.Radio, the first and only round-the-clock internet radio station devoted to cybersecurity.

    Contact us to send story tips, feedback and suggestions, and for sponsorship opportunities and custom media productions.

    The post U.S. Secret Service Agents Recovered Nearly $1M For A 71-Year-Old Retiree appeared first on Cybercrime Magazine.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Spotify and the Big Three labels have filed a record-breaking $13 trillion lawsuit against Anna’s Archive over a massive music data scrape. Find out what this means for the future of digital music.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • On December 29, 2025, Poland experienced a significant escalation in coordinated cyberattacks targeting critical energy infrastructure. More than 30 wind and photovoltaic farms, a manufacturing company, and a large combined heat and power plant supplying heating to approximately 500,000 customers were subjected to synchronized destructive operations. The attacks occurred during extreme winter weather, compounding infrastructure […]

    The post Coordinated Cyberattacks Hit 30 Wind and Solar Farms Across Poland appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶