
Former L3Harris executive sentenced to 87 months for selling zero-day exploits
A former L3Harris executive received an 87-month sentence after admitting he stole and sold eight zero-day exploits or components to a broker.
Verified cybersecurity, fraud and digital-banking signals with decision context, affected audiences and practical actions.

A former L3Harris executive received an 87-month sentence after admitting he stole and sold eight zero-day exploits or components to a broker.

The FBI says the United States is committed to combating transnational gangs behind Southeast Asian scam compounds, following discussions with officials in three countries.

Air Côte d’Ivoire confirmed a February 8 systems breach after INC claimed it stole 208 GB of data, though the alleged theft remains unverified.

Risky Business News reports an AI-driven campaign breached more than 600 Fortinet devices, though key details about targets, methods, and impact remain unconfirmed.

Krebs reports that Starkiller relays credentials and MFA codes through live target websites, presenting a challenge for phishing detection and identity defenses.

A Risky Business News bulletin highlights reported weaknesses in RPKI infrastructure alongside a French ministry breach, UK content-removal rules, and ClickFix malware claims.

A federal sentence follows a reported scheme involving compromised tax-preparation networks, stolen client data, phishing, and more than 1,000 fraudulent refund claims.

A Palo Alto Networks report, cited by Cybersecurity Dive, says AI is helping threat groups accelerate attacks involving stolen identities and newly disclosed critical vulnerabilities.

Polish officials arrested a man accused of supporting Phobos ransomware attacks, following a multinational investigation known as “Phobos Aetor.”

An AI system is reported to have found 12 OpenSSL vulnerabilities, adding to an unusual concentration of discoveries across the project’s 2025 and 2026 releases.

Cambodia reportedly pledged to dismantle cyber scam compounds by April, but the supplied report gives no details confirming how or whether the promise will be fulfilled.

New reports cited by Cybersecurity Dive point to faster social engineering and zero-day weaponization alongside rising ransomware attacks in IT and food.

Risky Business News reports that an IcedID malware developer allegedly faked his own death to evade the FBI, with few details supplied about the case.

CISA is planning sector-specific town halls to gather feedback on the stalled CIRCIA rule governing significant cyberattack and ransomware-payment reporting.

A reported phishing chain combines a patched Office flaw, malicious Excel add-in, and fileless XWorm delivery to complicate detection.

Krebs on Security reports that the Kimwolf IoT botnet is disrupting I2P while allegedly using the network to evade takedown efforts.

Intel 471 says consulting and manufacturing firms featured prominently among ransomware victims posted to the dark web in 2025.

Microsoft’s February release addresses 60 vulnerabilities, including six the company highlighted as new and actively exploited, according to CSO Online.

Microsoft’s February release fixes more than 50 flaws, including six zero-days reportedly exploited in the wild across Windows and related software.

Researchers report a Phorpiex-linked phishing campaign using malicious LNK files to deliver Global Group ransomware through local execution.

CyberScoop reports that attacks linked to two Ivanti EPMM zero-days have affected nearly 100 victims, including two Dutch agencies and infrastructure cited by the European Commission.

Leaked documents reportedly describe a Chinese platform for practicing attacks against replicas of neighboring countries’ real critical-infrastructure networks.

BridgePay says it is working with federal investigators after warning customers about system-wide outages and a reported ransomware attack.

EU and Dutch authorities announced hacks after two Ivanti zero-days, while Ivanti said a very limited number of customers had been attacked.