$351M Crypto Heist, Zombie Malware Returns & a Data Broker Loses Its Domain
Friday, September 25, 2026 · 5-minute read
Cryptocurrency exchange Bitget confirmed yesterday that suspected North Korean hackers broke into its hot and warm wallets and walked away with $351.6 million. The breach was spotted on September 24 at 18:31 UTC. Bitget says customer balances are intact, but withdrawals are paused while cybersecurity firms Mandiant and SlowMist investigate exactly how the attackers got in.
↗ The Hacker NewsThe Canadian Centre for Cyber Security issued a warning this week that attackers are actively exploiting a known hole in Roundcube Webmail. The flaw lets anyone — without even logging in — inject malicious commands into Roundcube's database and potentially steal email credentials and stored messages. A fix has been available since May 2026, but many servers haven't applied it yet.
↗ BleepingComputerA Kosovar national has pleaded guilty to running Rydox, an illegal online market that sold stolen personal data, login credentials, credit card numbers, and hacking tools. The marketplace was a go-to shop for cybercriminals looking to buy someone else's stolen identity. The defendant now faces up to 22 years in prison — a signal that international law enforcement is getting better at tracking down dark web operators.
↗ BleepingComputerBack in May 2026, attackers compromised two popular GitHub Actions — automated tools called issues-helper and maintain-one-comment — as part of a supply chain attack called Mini Shai-Hulud. GitHub disabled both repositories. But on September 16, 2026, both repos quietly came back online with the malicious code still attached to their version tags. Any software project that referenced these actions by version tag immediately started downloading and running the malware again — without the developers knowing. GitHub has since disabled them a second time.
A new version of PamStealer, a macOS-targeting information thief, has gotten a serious upgrade. Earlier versions embedded their secret decryption key right in the malware code — security researchers could find it and analyze the malware easily. The new version fetches the key from the attacker's own server, meaning the payload can't be unlocked or studied without the criminals cooperating. Victims are lured in through a fake website called "wavel[.]app" — a bogus app that looks legitimate but drops the malware on your Mac.
An attacker who isn't even logged in can slip malicious commands into Roundcube's database through a flaw in how the software handles certain email address lookups. This is called a SQL injection. If exploited, the attacker can grab stored email credentials and read private messages — all without a password. The flaw affects Roundcube versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1, and it's actively being used in real attacks right now.
Status: Patch available since May 2026 — update to Roundcube 1.6.16 or 1.7.1 immediately if you run a Roundcube server.
CISA confirmed this week that ransomware gangs are now actively exploiting a critical flaw in JetBrains TeamCity, a popular tool software teams use to automate building and testing their code. A successful attack could let hackers take full control of a TeamCity server — and from there, potentially poison the software projects built on it. This is a significant risk for any company that uses TeamCity in its development pipeline.
Status: Patch available — update your TeamCity installation to the latest version without delay. If you can't patch immediately, restrict network access to the server.
Researchers at BleepingComputer have flagged a clever and unsettling new trick used by the MacSync malware targeting Mac users. Instead of hiding instructions on a shady server that security teams can easily block, MacSync now reads from public iCloud calendar events to receive its next orders — using Apple's own trusted infrastructure as a command-and-control channel. Because iCloud traffic looks completely normal to most security filters, the malware's communications fly under the radar. This technique — hiding malicious instructions inside a legitimate, trusted platform — is a growing trend researchers are calling living-off-trusted-sites. It's a reminder that blocking unknown websites isn't enough if attackers are using Apple's own servers to run their operations.
↗ BleepingComputerImagine a company that profits from publishing your home address, phone number, and personal history online — and then, when ordered by a court to remove that information, responds by pretending to move to the Marshall Islands. That's the story of Radaris, one of the internet's most aggressive data brokers, and it just had a very bad week in a New Jersey courtroom.
Radaris has spent years publishing personal details on millions of Americans — including law enforcement officers, judges, and government workers. New Jersey's Daniels Law says those officials have the right to have their information removed. A company called Atlas Data Privacy Corp started suing Radaris in February 2024 for ignoring that law. What followed was a masterclass in legal obstruction: attorneys showed up at the last minute, claimed the wrong entity owned the site, pointed to shell companies in the Marshall Islands, British Virgin Islands, and Seychelles, and invented a fake CEO named "Gary Norden" whose name appeared in press releases seeking investor money. When one corporate entity got too close to a judgment, a fresh one would appear from a different offshore tax haven. Atlas's president described it as an "island-hopping phase."
Why does this matter to regular people? Data brokers like Radaris make money by aggregating everything publicly available about you �� your old addresses, relatives, phone numbers, estimated income — and selling it to anyone willing to pay. For most people, this is a privacy annoyance. For a police officer, a domestic abuse survivor, or a witness in a criminal case, having your home address one Google search away can be genuinely dangerous. Daniels Law exists precisely because of that risk, and Radaris spent years treating it as a minor inconvenience to be litigated away.
This time, the strategy failed. The judge ran out of patience after the defendants skipped multiple court appearances. The result: a judge ordered the radaris.com domain itself — and more than a dozen related data broker domains — transferred directly to the plaintiffs. The site now belongs to Atlas. It's a rare and striking outcome. Watch for similar Daniels Law cases to accelerate, and for other states to consider copycat legislation protecting their own public officials from data broker exposure.