Bitrefill is a legitimate company that sells gift cards for popular stores like Amazon, Deliveroo, Apple, Nintendo, and thousands of others. They also sell eSIMs, and mobile top-ups. You can pay on their website for all of these with cryptocurrency. The scam is designed to catch people searching for Bitrefill or something it sells, like a gift card. Victims see a search result that appears to lead to Bitrefill but actually points to a lookalike domain. The fake site then takes them through what…
Inadequate access control in the Hiperdino REST API Mon, 09/14/2026 - 13:27 Aviso Affected Resources Hiperdino REST API v1.0. Description INCIBE has coordinated the disclosure of a critical-severity vulnerability affecting the Hiperdino REST API, which acts as a bridge for carrying out actions automatically and in real time. The vulnerability was discovered by Jorge Ramos Santana.This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability…
Wildberries told several Russian media outlets earlier this week that payments to some sellers were delayed by security measures introduced after a distributed denial-of-service (DDoS) attack targeted systems used to track and withdraw their earnings.
Researchers at German cybersecurity company Nebty have identified “DoppelCart,” a cluster of almost 119,000 domains linked to copied online stores. The researchers describe it as the largest publicly documented fake-shop network by associated domain count. They found 118,787 .shop domains in the cluster, representing 2.72% of the .shop top-level domain (TLD) population they examined. The operation copies legitimate retailers’ product catalogs, descriptions, branding, and images, sometimes even…
Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: 10.0, CVEs: CVE-2026-75650, Summary: Adobe has released a security update for Adobe Commerce and Magento Open Source. This update resolves a critical vulnerability that could result in arbitrary code execution. Adobe is aware of CVE-2026-75650 being exploited in the wild. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS:3.1 10.0
Introduction Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly UNC5669), a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers. This activity overlaps with operations publicly reported as Plump Spider and SHADOW-AETHER-064. In…
Key Takeaways Since March 31, 2025, all 51 former “best practice” requirements in PCI DSS 4.0 have been fully scored. Every 2026 assessment covers them. A large share of the new weight sits in the PCI DSS 4.0.1 application requirements, concentrated in Requirements 6 and 11: inventory of custom applications and APIs, continuous protection of public-facing apps, payment page script management, authenticated scanning, and risk-based prioritization. 6.4.3 and 11.6.1 now require a complete…
Protect your Australia- and New Zealand-based retail business from cyber threats. Learn five key decisions to secure identities, manage dependencies and ensure trading continuity against ransomware
The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned. [...]
From several independent reports, we’ve seen evidence of scammers using fake Android “interview” apps to target job seekers on the Indeed platform.Indeed is one of the world’s largest employment websites, giving scammers access to a huge pool of potential victims, especially in a competitive job market.What we foundA user in the UK posted on our forums after being instructed by a supposed employer on Indeed to install an “Interview App.”A user in Brasil submitted an anonymized report after…
Embedded credentials in Virtuagym Fri, 08/21/2026 - 11:51 Aviso Affected Resources Virtuagym / Resamania Backend API & Mobile Apps. All versions are affected at the time of reporting. Description INCIBE has coordinated the disclosure of a high-severity vulnerability affecting the backend API and mobile app of Virtuagym, a comprehensive technology platform and mobile app specialising in the fitness and health sector. The vulnerability was discovered by Pau Hinojosa.This vulnerability has been…
The agency said the latest attack came amid preparations to select a manager for seized corporate rights in IDS Ukraine, one of the country’s largest producers of bottled mineral water and beverages.
Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics. [...]
It may sound entirely bizarre but the prices you once paid for hotels, educational classes, or staplers could have all been higher because you used a Mac computer, lived in a certain zip code, or lacked an Office Depot in your neighborhood. No, really. In 2012, The Wall Street Journal reported that the travel booking site Orbitz showed Mac users pricier hotel options than PC users, because the company had determined that Mac users spend, on average, 30% more a night on hotels. That same year,…
For the latest discoveries in cyber research for the week of 10th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES North Carolina Ports, the US authority operating the ports of Wilmington, Morehead City and others, has suffered a cyberattack that forced some operations onto manual processes. The authority claims it has contained the intrusion, but degraded systems caused delays while affected services were restored. Ryde, an electric scooter operator in…
In this article What is device isolation?Case study: QNETAttack chain overviewMITRE ATT&CK techniques observedReferencesLearn more Microsoft Defender’s attack disruption now includes device isolation, a new response action that extends autonomous protection directly to compromised endpoints. At QNET, an attacker initiated a multi-stage attack using a legitimate Windows tool on a compromised endpoint to retrieve a malicious remote payload–a classic living-off-the-land (LOL) technique that often…
Microsoft Threat Intelligence identified CaptiveCrunch, an ongoing cyberespionage campaign conducted by Storm-2945, a subgroup of the Russian state-sponsored actor Midnight Blizzard. The campaign compromises hospitality-sector captive portal infrastructure to perform adversary...
A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the…
Objevila se nová forma phishingového útoku, která zneužívá legitimní aplikace pro sledování objednávek k zobrazování falešných účtenek za údajné nákupy nebo předplatná. Aktuálně jsou takové útoky hlášeny především v aplikaci Shop od společnosti Shopify, nelze však vyloučit využití této techniky i v dalších aplikacích pro sledování objednávek. Namísto tradičních phishingových e-mailů se podvodné zprávy zobrazují přímo v prostředí aplikace, kde uživatelé běžně sledují své skutečné objednávky, což…
E-commerce is the second most targeted sector for cyberattacks in 2026. Get the 10 priorities every security team must act on, with Group-IB intelligence behind each.
Merchants face $53B in card fraud losses but lack access to compromised card data. Discover the three barriers keeping merchants in the dark — and the solution.