Tag: marketplace
-
CISOs to Watch in Charlotte: From Theme Parks to Financial Services
Charlotte’s reputation runs on banking, but the security leaders in this piece protect a far wider slice of American consumer life: aircraft engines and building controls, a lending marketplace, packaging for half the products on a grocery shelf, payroll software,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/cisos-to-watch-in-charlotte-from-theme-parks-to-financial-services/
-
Threat Intelligence Alone Won’t Close the Exploitation Gap
Tags: advisory, ai, breach, credentials, data-breach, exploit, intelligence, marketplace, threat, vulnerabilityA leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combining that kind of intelligence with AI-assisted exploitation to accelerate the path from exposure to breach faster than most…
-
EarlyProgramm von Google-Play zur Tarnung von Online-Betrug missbraucht
Die Bitdefender Labs warnen davor, dass Cyberkriminelle verstärkt das Early-Access-Programm von Google-Play für ihre Zwecke missbrauchen. Eigentlich sollen Entwickler über Early-Access ihre noch nicht fertig entwickelten Anwendungen Interessenten vorab zur Verfügung stellen und Feedback einsammeln können. Dabei schützt der Google-Marktplatz das Programm vor öffentlichen Bewertungen und Kommentaren, die bei Early-Access anders als bei anderen Apps…
-
OFAC Sanctions Chinese Scam Platform Xinbi Guarantee
The US Treasury has placed sanctions on notorious Chinese cybercrime marketplace Xinbi Guarantee First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ofac-sanctions-chinese-scam/
-
OFAC Sanctions Chinese Scam Platform Xinbi Guarantee
The US Treasury has placed sanctions on notorious Chinese cybercrime marketplace Xinbi Guarantee First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ofac-sanctions-chinese-scam/
-
OFAC Sanctions Chinese Scam Platform Xinbi Guarantee
The US Treasury has placed sanctions on notorious Chinese cybercrime marketplace Xinbi Guarantee First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ofac-sanctions-chinese-scam/
-
US disrupts Xinbi Guarantee marketplace fueling the cyber scam economy
The U.S. government also carried out a seizure of $52.8 million from 52 wallets connected to the platform. First seen on therecord.media Jump to article: therecord.media/us-disrupts-xinbi-guarantee-marketplace-cybercrime
-
U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto
The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Center Strike Force to Madagascar to help disrupt 13 scam compounds run by Chinese…
-
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts.”Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial First seen on thehackernews.com Jump to article:…
-
Hackers Can Buy Corporate Executives’ Social Security Numbers for Just 25 Cents
Corporate executives’ Social Security numbers (SSNs) are being sold on dark web identity marketplaces for as little as $0.25 per record. This creates a low-cost entry point for fraudsters looking to commit executive impersonation, business email compromise (BEC), and identity theft. Recent threat research from Rapid7 reveals an increasingly sophisticated >>identity-as-a-service<< ecosystem. In this environment,…
-
Chinese-Speaking TA4922 Bought New RAT from Commodity Marketplaces
Proofpoint Says the Group Used the Modular RAT in at Least Three Campaigns. Chinese-speaking TA4922 is using the commercially advertised PackClient remote access trojan in phishing campaigns targeting China and India, giving the financially motivated group modular surveillance, data theft and post-compromise capabilities. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/chinese-speaking-ta4922-bought-new-rat-from-commodity-marketplaces-a-32670
-
Chinese-Speaking TA4922 Bought New RAT from Commodity Marketplaces
Proofpoint Says the Group Used the Modular RAT in at Least Three Campaigns. Chinese-speaking TA4922 is using the commercially advertised PackClient remote access trojan in phishing campaigns targeting China and India, giving the financially motivated group modular surveillance, data theft and post-compromise capabilities. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/chinese-speaking-ta4922-bought-new-rat-from-commodity-marketplaces-a-32670
-
Chinese-Speaking TA4922 Bought New RAT from Commodity Marketplaces
Proofpoint Says the Group Used the Modular RAT in at Least Three Campaigns. Chinese-speaking TA4922 is using the commercially advertised PackClient remote access trojan in phishing campaigns targeting China and India, giving the financially motivated group modular surveillance, data theft and post-compromise capabilities. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/chinese-speaking-ta4922-bought-new-rat-from-commodity-marketplaces-a-32670
-
77 Counterfeit Open VSX Extensions Collected Developer and CI/CD Data
Security researchers found 150 lookalike Open VSX extensions published under trusted names, highlighting how extension marketplaces can expose developer credentials, source code, and CI/CD systems to supply-chain risk. The post 77 Counterfeit Open VSX Extensions Collected Developer and CI/CD Data appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-open-vsx-extension-risk/
-
77 malicious extensions found on Open VSX marketplace
First seen on scworld.com Jump to article: www.scworld.com/brief/77-malicious-extensions-found-on-open-vsx-marketplace
-
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed.The “evil twin” extensions were uploaded to the repository between July 26 and August 1, 2026, according to Manifold Security. The packages have been…
-
77 Open VSX extensions found harvesting developer info
77 extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development environments where they were installed. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/77-open-vsx-extensions-found-harvesting-developer-info/
-
Salt Debuts First AWS WAF Managed Ruleset for AI Agent and API Protection
Tags: access, ai, api, attack, ceo, credentials, detection, email, endpoint, exploit, intelligence, marketplace, threat, waf, xssThe WAF gap no one is talking about Your WAF is doing its job. It’s blocking SQLi, XSS, and the usual suspects. But here’s the problem: it wasn’t built for APIs, and it definitely wasn’t built for AI agents. APIs now power nearly every digital experience. And AI agents, the automated systems that access your…
-
Mit Drogen-Marktplatz: Deutscher soll im Darknet 20 Millionen Euro erlangt haben
Der 31-Jährige soll einen riesigen Darknet-Marktplatz betrieben und am Drogenhandel mitverdient haben. Jetzt muss er sich vor Gericht verantworten. First seen on golem.de Jump to article: www.golem.de/news/mit-drogen-marktplatz-deutscher-soll-im-darknet-20-millionen-euro-erlangt-haben-2608-211565.html
-
Malicious AI agent skills can slip past the scanners built to stop them
Developers who build with AI coding agents grab capabilities off public marketplaces the same way they grab packages from npm or PyPI. The add-ons are called agent skills. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/09/malicious-ai-agent-skills-scan/
-
ClawHavoc Attack Hits ClawHub With 1,184 Malicious Skills and 247,000 Installations
The AI-agent ecosystem experienced its largest supply-chain compromise to date when ClawHavoc detonated across ClawHub, the official skill marketplace for OpenClaw. Our full AIG-powered scan of nearly 50,000 ClawHub Skills found 1,184 clearly malicious packages tied to 12 compromised publisher accounts and confirmed 247,693 installations. The campaign combined typosquatting, ranking manipulation, and multi-stage payload delivery…
-
More Malicious OpenClaw Skills Threaten AI Supply Chain
OpenClaw removed five packages from ClawHub, its skills marketplace, that bypassed security checks even though they included infostealers and other threats. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/malicious-openclaw-skills-clawhub-threaten-ai-supply-chain
-
Algerian national accused of running cybercrime marketplaces extradited to US
An Algerian national accused of running online marketplaces that sold phishing kits and fraud tools has been extradited from Spain to the United States to face bank fraud … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/24/algerian-cybercrime-marketplace-operator-extradited-to-us/
-
Justice Department seizes infrastructure used by cyber scam and criminal marketplace
lso Tuesday, the Treasury Department took action against the same Cambodian company, Huione Group, and affiliates. First seen on cyberscoop.com Jump to article: cyberscoop.com/doj-huione-group-cybercrime-seizure/
-
Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents
Security firm AIR built a fake AI agent skill, pushed it through a popular skill marketplace and an Instagram ad, and says it reached roughly 26,000 agents, including some on corporate accounts.Every skill security scanner the firm tested it against marked it safe. The payload was harmless by design: it collected the user’s email address…
-
Algerian man charged with running two cybercrime marketplaces
Abdellah Belmili allegedly ran two black-market websites selling stolen financial credentials and custom-built phishing kits targeting major American banks, federal prosecutors say. First seen on cyberscoop.com Jump to article: cyberscoop.com/algerian-man-charged-cybercrime-marketplaces/
-
Bösartige Plugins stehlen KISchlüssel von Entwicklern
Mindestens 15 Plugins im JetBrains Marketplace exfiltrieren heimlich API-Schlüssel für KI-Dienste. Rund 70.000 Installationen sind betroffen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/plugins-stehlen-ki-api-schluessel
-
Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats
Cybersecurity researchers have flagged a “coordinated malware campaign” on the JetBrains Marketplace that has published no less than 15 malicious plugins capable of exfiltrating artificial intelligence (AI) provider keys.”Every plugin poses as an AI coding assistant built on DeepSeek and other large language models, offering chat, commit messages, code review, bug finding, and unit tests,”…

