
Risky Business bulletin highlights scams, cybercrime and major incidents
A Risky Business bulletin covers new US cyber priorities alongside reports involving the FBI’s wiretap network and a Romanian exporter.
Verified cybersecurity, fraud and digital-banking signals with decision context, affected audiences and practical actions.

A Risky Business bulletin covers new US cyber priorities alongside reports involving the FBI’s wiretap network and a Romanian exporter.

Autonomous AI assistants are gaining adoption while challenging familiar boundaries between software, users, insider threats and the controls organizations use to manage risk.

The FBI acknowledged suspicious activity on a network used for wiretaps and foreign-intelligence warrants, while details about access, attribution, and impact remain unavailable.

A reported federal order ended agency use of Anthropic models as OpenAI moved into the Pentagon supplier role, amid disputes over surveillance and autonomous weapons.

Risky Business News reports that Iran is attempting to hack security cameras to support missile strikes, while leaving the targets, success, and consequences unspecified.

Microsoft and Europol reportedly disrupted Tycoon 2FA, a phishing service linked in the supplied report to multifactor-authentication bypass, business email compromise, and ransomware.

A reported departure from DHS put Sean Plankey’s CISA nomination in jeopardy amid concerns about Iran-linked hackers and a weakened agency.

Europol said international agencies dismantled a phishing-as-a-service platform linked to worldwide targeting of hundreds of thousands of accounts, including hospital and school accounts.

AirSnitch is described as a cross-layer Wi-Fi attack that could enable bidirectional machine-in-the-middle activity across home, office, and enterprise networks.

Researchers said an unknown user tried to use Claude against Mexican government networks; Anthropic said it investigated, disrupted the activity, and banned involved accounts.

A widely downloaded prayer app reportedly pushed messages in Iran after explosions, but responsibility for the apparent compromise remains unclaimed and unconfirmed.

A 14-country operation seized LeakBase, a forum officials said held hundreds of millions of credentials and other stolen corporate and personal data.

The LeakBase seizure disrupted a market for stolen databases, but copied records can continue supporting identity fraud and account takeover.

Google and iVerify research links the Coruna iOS exploit kit to activity across criminal, Russian, and spyware contexts, while its possible origin remains unconfirmed.

Cloudflare says stolen passwords have overtaken infectious code as the most common tactic in major breaches, putting impersonation at the center of ransomware defenses.

Dutch NCSC guidance shows how compromised mailboxes turn routine business trust into payment loss unless finance processes verify requests independently.

A Risky Business podcast episode explores how cyber operations in Ukraine have changed, with show notes linking the discussion to espionage and missile-strike reporting.

The University of Hawaiʻi Cancer Center confirmed a leak after ransomware, with part of the incident traced to records used by a 1993 research cohort.

Moltbook’s reputation as an AI-only social network is complicated by evidence that humans created, prompted, verified, and published through many purported bots.

After a ransomware attack, University of Mississippi Medical Center clinics regained access to patient records and began resuming normal operations more than a week later.

Researchers warn that hacktivist and state-linked groups associated with Iran are using DDoS, phishing and other tactics against critical infrastructure.

An LLM deanonymization claim leads a bulletin that also covers CISA leadership, a French health ministry data theft, and Google’s ad-fraud-botnet takedown.

A Cybersecurity Dive report says China-linked hackers used malware concealed in Google Sheets during attacks affecting telecoms and government agencies.

CSO Online’s guide explains how ransomware strains differ, from rapidly locking networks to gradually leaking sensitive data, and why organizations should account for varied tactics.