<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Cybercrime</title><description>Cybersecurity articles tagged #Cybercrime on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Mexico’s Cybersecurity Plan 2025-2030: Addressing Rising Threats</title><link>https://runtimerebel.com/blog/mexicos-cybersecurity-plan-2025-2030-addressing-rising-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/mexicos-cybersecurity-plan-2025-2030-addressing-rising-threats</guid><description>Mexico&apos;s National Cybersecurity Plan 2025-2030 aims to strengthen defenses against ransomware, state-sponsored espionage, and cybercrime.</description><pubDate>Tue, 25 Aug 2026 16:30:54 GMT</pubDate><category>Mexico</category><category>Ransomware</category><category>State Sponsored Espionage</category><category>Cybercrime</category><category>LockBit</category></item><item><title>Cybercrime Policing Roadblocks: Funding &amp; Training Gaps</title><link>https://runtimerebel.com/blog/cybercrime-policing-roadblocks-funding-training-gaps</link><guid isPermaLink="true">https://runtimerebel.com/blog/cybercrime-policing-roadblocks-funding-training-gaps</guid><description>Law enforcement faces significant hurdles in combating cybercrime, primarily due to insufficient funding for training and a lack of strategic focus.</description><pubDate>Sun, 23 Aug 2026 08:20:50 GMT</pubDate><category>Cybercrime</category><category>Law Enforcement</category><category>Training</category><category>Funding</category><category>Cybersecurity Policy</category></item><item><title>UAT-10147 Leverages Agentic AI for EDR-Evasive Cybercrime</title><link>https://runtimerebel.com/blog/uat-10147-leverages-agentic-ai-for-edr-evasive-cybercrime</link><guid isPermaLink="true">https://runtimerebel.com/blog/uat-10147-leverages-agentic-ai-for-edr-evasive-cybercrime</guid><description>Talos details UAT-10147, an AI-driven cybercrime group orchestrating sophisticated post-compromise operations and evading EDR with custom rootkits.</description><pubDate>Fri, 21 Aug 2026 00:46:37 GMT</pubDate><category>Agentic AI</category><category>Cybercrime</category><category>EDR Evasion</category><category>UAT 10147</category><category>SPECTRE Implant</category></item><item><title>Kriminal AI Platform Fuels Cybercrime: OSINT &amp; Social Engineering</title><link>https://runtimerebel.com/blog/kriminal-ai-platform-fuels-cybercrime-osint-social-engineering</link><guid isPermaLink="true">https://runtimerebel.com/blog/kriminal-ai-platform-fuels-cybercrime-osint-social-engineering</guid><description>The &apos;Kriminal&apos; AI platform, offering guardrail-free social engineering and OSINT, raises significant concerns about its potential to fuel cybercrime.</description><pubDate>Thu, 20 Aug 2026 00:40:40 GMT</pubDate><category>AI</category><category>Cybercrime</category><category>Social Engineering</category><category>OSINT</category><category>Threat Intelligence</category></item><item><title>Cybercrime&apos;s Coordination Gap: Attackers Outpace Law Enforcement</title><link>https://runtimerebel.com/blog/cybercrime-s-coordination-gap-attackers-outpace-law-enforcement</link><guid isPermaLink="true">https://runtimerebel.com/blog/cybercrime-s-coordination-gap-attackers-outpace-law-enforcement</guid><description>Analysis of the widening gap between agile cybercrime organizations and fragmented global law enforcement efforts, highlighting the impact on cybersecurity.</description><pubDate>Fri, 07 Aug 2026 02:11:05 GMT</pubDate><category>Cybercrime</category><category>Law Enforcement</category><category>Threat Actors</category><category>Information Sharing</category><category>Global Cooperation</category></item><item><title>Snowflake Hacker Pleads Guilty: Analyzing the UNC5537 Data Breach</title><link>https://runtimerebel.com/blog/snowflake-hacker-pleads-guilty-analyzing-the-unc5537-data-breach</link><guid isPermaLink="true">https://runtimerebel.com/blog/snowflake-hacker-pleads-guilty-analyzing-the-unc5537-data-breach</guid><description>Hacker pleads guilty in UNC5537 Snowflake data breach, compromising 165 organizations and millions of records via stolen credentials.</description><pubDate>Fri, 07 Aug 2026 02:09:26 GMT</pubDate><category>Snowflake</category><category>Data Breach</category><category>UNC5537</category><category>Credential Theft</category><category>Cybercrime</category></item><item><title>Interpol&apos;s I-GRIP System Curtails Fraudulent Payments: A Threat Intel Brief</title><link>https://runtimerebel.com/blog/interpol-s-i-grip-system-curtails-fraudulent-payments-a-threat-intel-brief</link><guid isPermaLink="true">https://runtimerebel.com/blog/interpol-s-i-grip-system-curtails-fraudulent-payments-a-threat-intel-brief</guid><description>Explore Interpol&apos;s I-GRIP system, a global initiative enabling rapid freezing of fraudulent payments and enhancing international cooperation against cyber-enabled…</description><pubDate>Fri, 31 Jul 2026 14:11:22 GMT</pubDate><category>INTERPOL</category><category>Financial Fraud</category><category>Cybercrime</category><category>I GRIP</category><category>Payment Fraud</category><category>BEC</category><category>Phishing</category></item><item><title>ShinyHunters Breaches Brinks Home, Threatens Data Leak</title><link>https://runtimerebel.com/blog/shinyhunters-breaches-brinks-home-threatens-data-leak</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-breaches-brinks-home-threatens-data-leak</guid><description>ShinyHunters claims a breach of Brinks Home systems, threatening to leak stolen data. This analysis covers the threat actor, potential impact, and mitigation.</description><pubDate>Thu, 30 Jul 2026 17:31:04 GMT</pubDate><category>ShinyHunters</category><category>Brinks Home</category><category>Data Breach</category><category>Data Leak</category><category>Extortion</category><category>Cybercrime</category></item><item><title>TAG-195 Evolves MaaS Ecosystem with Modular Malware</title><link>https://runtimerebel.com/blog/tag-195-evolves-maas-ecosystem-with-modular-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/tag-195-evolves-maas-ecosystem-with-modular-malware</guid><description>Insikt Group identifies TAG-195&apos;s new modular malware families, signalling a significant shift in the Malware-as-a-Service ecosystem and operator-driven tooling.</description><pubDate>Thu, 23 Jul 2026 17:28:53 GMT</pubDate><category>TAG 195</category><category>MaaS</category><category>Malware as a Service</category><category>Cybercrime</category><category>Modular Malware</category></item><item><title>Evolving Carding Tactics: Residential Proxies &amp; Fraud Detection Evasion</title><link>https://runtimerebel.com/blog/evolving-carding-tactics-residential-proxies-fraud-detection-evasion</link><guid isPermaLink="true">https://runtimerebel.com/blog/evolving-carding-tactics-residential-proxies-fraud-detection-evasion</guid><description>Cybercriminals leverage &quot;clean&quot; residential proxies, browser fingerprints, and device profiles to bypass modern fraud detection systems, enhancing carding success.</description><pubDate>Fri, 17 Jul 2026 17:14:34 GMT</pubDate><category>Carding</category><category>Residential Proxies</category><category>Fraud Detection</category><category>Browser Fingerprinting</category><category>Cybercrime</category><category>Identity Spoofing</category></item><item><title>Spanish Police Dismantle €140M Cyber Fraud Ring: BEC &amp; Investment Schemes</title><link>https://runtimerebel.com/blog/spanish-police-dismantle-eur140m-cyber-fraud-ring-bec-investment-schemes</link><guid isPermaLink="true">https://runtimerebel.com/blog/spanish-police-dismantle-eur140m-cyber-fraud-ring-bec-investment-schemes</guid><description>Spanish Police dismantle a sophisticated cybercrime organization responsible for €140 million in BEC and investment fraud, arresting four key individuals.</description><pubDate>Tue, 14 Jul 2026 21:02:39 GMT</pubDate><category>Cybercrime</category><category>BEC</category><category>Investment Fraud</category><category>Money Laundering</category><category>Spain</category><category>Law Enforcement</category><category>Social Engineering</category></item><item><title>ScamBuster: AI-Driven Phishing Engagement for Threat Intel</title><link>https://runtimerebel.com/blog/scambuster-ai-driven-phishing-engagement-for-threat-intel</link><guid isPermaLink="true">https://runtimerebel.com/blog/scambuster-ai-driven-phishing-engagement-for-threat-intel</guid><description>Explore ScamBuster, an open-source, AI-driven tool that actively engages phishing attackers to gather intelligence on their TTPs, aiding threat detection and law…</description><pubDate>Mon, 13 Jul 2026 14:43:59 GMT</pubDate><category>ScamBuster</category><category>Phishing</category><category>Social Engineering</category><category>Threat Intelligence</category><category>AI</category><category>Open Source</category><category>Cybercrime</category></item><item><title>Odido Data Breach Analysis: Dutch Police Suspect Local Hacker Involvement</title><link>https://runtimerebel.com/blog/odido-data-breach-analysis-dutch-police-suspect-local-hacker-involvement</link><guid isPermaLink="true">https://runtimerebel.com/blog/odido-data-breach-analysis-dutch-police-suspect-local-hacker-involvement</guid><description>Dutch National Police identify strong indications of local hacker involvement in the February data breach at telecommunications provider Odido.</description><pubDate>Fri, 10 Jul 2026 21:07:51 GMT</pubDate><category>Odido</category><category>Data Breach</category><category>Telecommunications</category><category>Dutch Police</category><category>Cybercrime</category></item><item><title>Ryuk Ransomware Affiliate Pleads Guilty to US Hacking Charges</title><link>https://runtimerebel.com/blog/ryuk-ransomware-affiliate-pleads-guilty-to-us-hacking-charges</link><guid isPermaLink="true">https://runtimerebel.com/blog/ryuk-ransomware-affiliate-pleads-guilty-to-us-hacking-charges</guid><description>A 34-year-old Armenian national faces 15 years in prison for his role in the Ryuk ransomware operation, which targeted U.S. hospitals and businesses.</description><pubDate>Fri, 10 Jul 2026 21:07:31 GMT</pubDate><category>Ryuk</category><category>Ransomware</category><category>Cybercrime</category><category>Department of Justice</category><category>TrickBot</category></item><item><title>Insider Threat: Security Expert Sentenced for BlackCat/ALPHV Aid</title><link>https://runtimerebel.com/blog/insider-threat-security-expert-sentenced-for-blackcat-alphv-aid</link><guid isPermaLink="true">https://runtimerebel.com/blog/insider-threat-security-expert-sentenced-for-blackcat-alphv-aid</guid><description>Former ransomware negotiator Angelo Martino received a 70-month prison sentence for aiding the BlackCat/Alphv ransomware group, highlighting insider threat risks.</description><pubDate>Fri, 10 Jul 2026 14:32:15 GMT</pubDate><category>BlackCat</category><category>ALPHV</category><category>Ransomware</category><category>Insider Threat</category><category>Cybercrime</category><category>Angelo Martino</category></item><item><title>Cyber-Financial Crime Convergence: Proactive Payment Fraud Disruption</title><link>https://runtimerebel.com/blog/cyber-financial-crime-convergence-proactive-payment-fraud-disruption</link><guid isPermaLink="true">https://runtimerebel.com/blog/cyber-financial-crime-convergence-proactive-payment-fraud-disruption</guid><description>Explore how the convergence of cyber and financial crime fuels payment fraud. Learn about proactive strategies for pre-monetization disruption and intelligence-driven…</description><pubDate>Fri, 10 Jul 2026 07:48:56 GMT</pubDate><category>Payment Fraud</category><category>Financial Crime</category><category>Cybercrime</category><category>Threat Intelligence</category><category>Proactive Defense</category><category>Mastercard</category><category>Recorded Future</category></item><item><title>Global Cybercrime Crackdown: Operation HAECHI IV Disrupts Fraud</title><link>https://runtimerebel.com/blog/global-cybercrime-crackdown-operation-haechi-iv-disrupts-fraud</link><guid isPermaLink="true">https://runtimerebel.com/blog/global-cybercrime-crackdown-operation-haechi-iv-disrupts-fraud</guid><description>Operation HAECHI IV, a global anti-fraud initiative, resulted in 5,811 arrests and seized $293M, highlighting international efforts against cyber-enabled financial crime.</description><pubDate>Thu, 09 Jul 2026 11:02:50 GMT</pubDate><category>Cybercrime</category><category>Fraud</category><category>Law Enforcement</category><category>Financial Crime</category><category>HAECHI IV</category><category>Social Engineering</category></item><item><title>Google Sues Outsider Enterprise Over Gemini-Powered Phishing-as-a-Service</title><link>https://runtimerebel.com/blog/google-sues-outsider-enterprise-over-gemini-powered-phishing-as-a-service</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-sues-outsider-enterprise-over-gemini-powered-phishing-as-a-service</guid><description>Google takes legal action against Outsider Enterprise, a Chinese cybercrime network using Gemini AI to automate sophisticated phishing campaigns against global users.</description><pubDate>Tue, 07 Jul 2026 11:11:04 GMT</pubDate><category>Outsider Enterprise</category><category>Phishing as a Service</category><category>Gemini AI</category><category>Google</category><category>Scams</category><category>Cybercrime</category></item><item><title>Google Disrupts NetNut Malicious Residential Proxy Network</title><link>https://runtimerebel.com/blog/google-disrupts-netnut-malicious-residential-proxy-network</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-disrupts-netnut-malicious-residential-proxy-network</guid><description>Google, in coordination with the FBI and Lumen, has significantly disrupted the NetNut residential proxy network, impacting millions of compromised devices.</description><pubDate>Fri, 03 Jul 2026 07:31:53 GMT</pubDate><category>NetNut</category><category>Residential Proxy</category><category>Botnet</category><category>C2</category><category>Google Play Protect</category><category>Malware</category><category>IPIDEA</category><category>Cybercrime</category><category>Espionage</category></item><item><title>Cybercrime Risk Shift: Australian SMBs Under Increased Pressure</title><link>https://runtimerebel.com/blog/cybercrime-risk-shift-australian-smbs-under-increased-pressure</link><guid isPermaLink="true">https://runtimerebel.com/blog/cybercrime-risk-shift-australian-smbs-under-increased-pressure</guid><description>Analysis of shifting cybercrime landscape in Australia, detailing how institutional safeguards impact SMBs and necessitate updated defense strategies for small…</description><pubDate>Fri, 03 Jul 2026 07:30:37 GMT</pubDate><category>Australia</category><category>SMBs</category><category>Cybercrime</category><category>Threat Landscape</category><category>Regulatory Impact</category></item><item><title>FBI Seizes NetNut Proxy Platform &amp; Popa Botnet Operations</title><link>https://runtimerebel.com/blog/fbi-seizes-netnut-proxy-platform-popa-botnet-operations</link><guid isPermaLink="true">https://runtimerebel.com/blog/fbi-seizes-netnut-proxy-platform-popa-botnet-operations</guid><description>The FBI, in partnership, seized NetNut residential proxy platform and disrupted the Popa botnet, which compromised millions of devices.</description><pubDate>Fri, 03 Jul 2026 07:30:12 GMT</pubDate><category>NetNut</category><category>Popa Botnet</category><category>FBI</category><category>Alarum Technologies</category><category>Residential Proxy</category><category>Cybercrime</category><category>Law Enforcement Action</category></item><item><title>Alleged Scattered Spider Hacker Extradited: Mitigating Social Engineering</title><link>https://runtimerebel.com/blog/alleged-scattered-spider-hacker-extradited-mitigating-social-engineering</link><guid isPermaLink="true">https://runtimerebel.com/blog/alleged-scattered-spider-hacker-extradited-mitigating-social-engineering</guid><description>An alleged Scattered Spider member&apos;s extradition highlights ongoing efforts against sophisticated social engineering and identity-based attacks impacting major…</description><pubDate>Thu, 02 Jul 2026 10:45:17 GMT</pubDate><category>Scattered Spider</category><category>Social Engineering</category><category>MFA Bypass</category><category>Ransomware</category><category>Cybercrime</category><category>Extradition</category><category>UNC3944</category><category>0ktapus</category></item><item><title>DOJ Seizes 400 Illegal FIFA World Cup Streaming Domains</title><link>https://runtimerebel.com/blog/doj-seizes-400-illegal-fifa-world-cup-streaming-domains</link><guid isPermaLink="true">https://runtimerebel.com/blog/doj-seizes-400-illegal-fifa-world-cup-streaming-domains</guid><description>The U.S. Justice Department seized nearly 400 domains illegally streaming FIFA World Cup matches, disrupting copyright infringement and protecting users from associated…</description><pubDate>Mon, 29 Jun 2026 13:39:14 GMT</pubDate><category>Domain Seizure</category><category>Illegal Streaming</category><category>FIFA World Cup</category><category>Copyright Infringement</category><category>Cybercrime</category><category>DOJ</category></item><item><title>SIM-Swapping Ring Busted: Millions in Crypto Theft via Telecom Hacks</title><link>https://runtimerebel.com/blog/sim-swapping-ring-busted-millions-in-crypto-theft-via-telecom-hacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/sim-swapping-ring-busted-millions-in-crypto-theft-via-telecom-hacks</guid><description>Polish authorities dismantle a sophisticated SIM-swapping ring that hijacked telecom partners and email accounts to steal millions in cryptocurrency.</description><pubDate>Fri, 26 Jun 2026 01:02:30 GMT</pubDate><category>SIM Swapping</category><category>Cryptocurrency Theft</category><category>Telecommunications Security</category><category>Account Takeover</category><category>Cybercrime</category><category>Poland</category></item><item><title>Amadey &amp; StealC Malware Infrastructure Disrupted, 27M Credentials Stolen</title><link>https://runtimerebel.com/blog/amadey-stealc-malware-infrastructure-disrupted-27m-credentials-stolen</link><guid isPermaLink="true">https://runtimerebel.com/blog/amadey-stealc-malware-infrastructure-disrupted-27m-credentials-stolen</guid><description>Law enforcement and private sector dismantled infrastructure for Amadey and StealC malware, leading to 27M stolen credentials recovery. Learn impact &amp; defense.</description><pubDate>Wed, 24 Jun 2026 20:39:48 GMT</pubDate><category>Amadey</category><category>StealC</category><category>Malware</category><category>Takedown</category><category>Credentials</category><category>Cybercrime</category></item><item><title>Amadey &amp; StealC Malware C2 Infrastructure Disrupted</title><link>https://runtimerebel.com/blog/amadey-stealc-malware-c2-infrastructure-disrupted</link><guid isPermaLink="true">https://runtimerebel.com/blog/amadey-stealc-malware-c2-infrastructure-disrupted</guid><description>Microsoft and global allies dismantle the shared C2 infrastructure of Amadey botnet and StealC info-stealer malware, disrupting ongoing cybercrime operations.</description><pubDate>Wed, 24 Jun 2026 16:52:14 GMT</pubDate><category>Amadey</category><category>StealC</category><category>Malware</category><category>Botnet</category><category>Infostealer</category><category>Cybercrime</category><category>C2 Takedown</category><category>Microsoft</category></item><item><title>Amadey &amp; StealC Malware Operations Disrupted by Operation Endgame</title><link>https://runtimerebel.com/blog/amadey-stealc-malware-operations-disrupted-by-operation-endgame</link><guid isPermaLink="true">https://runtimerebel.com/blog/amadey-stealc-malware-operations-disrupted-by-operation-endgame</guid><description>Operation Endgame, led by Europol and Microsoft, has disrupted infrastructure supporting Amadey and StealC info-stealer malware, impacting cybercriminal services.</description><pubDate>Wed, 24 Jun 2026 16:51:44 GMT</pubDate><category>Amadey</category><category>StealC</category><category>Operation Endgame</category><category>Malware</category><category>Infostealer</category><category>Cybercrime</category><category>Law Enforcement</category></item><item><title>Scattered Spider Members Plead Guilty in TfL Infrastructure Attack</title><link>https://runtimerebel.com/blog/scattered-spider-members-plead-guilty-in-tfl-infrastructure-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/scattered-spider-members-plead-guilty-in-tfl-infrastructure-attack</guid><description>Two members of the Scattered Spider threat group plead guilty to the 2024 Transport for London hack, exposing risks of identity-based social engineering.</description><pubDate>Tue, 23 Jun 2026 16:54:58 GMT</pubDate><category>Scattered Spider</category><category>UNC3944</category><category>Transport for London</category><category>Social Engineering</category><category>Cybercrime</category></item><item><title>AudiA6 Crypto-Laundering Service Dismantled: Impact on Ransomware</title><link>https://runtimerebel.com/blog/audia6-crypto-laundering-service-dismantled-impact-on-ransomware</link><guid isPermaLink="true">https://runtimerebel.com/blog/audia6-crypto-laundering-service-dismantled-impact-on-ransomware</guid><description>Law enforcement dismantled AudiA6, a major crypto-laundering service used by ransomware groups and cybercriminals to process over $380 million.</description><pubDate>Thu, 11 Jun 2026 17:24:04 GMT</pubDate><category>AudiA6</category><category>Crypto Laundering</category><category>Ransomware</category><category>Cybercrime</category><category>Law Enforcement</category><category>Financial Crime</category></item><item><title>Identifying The Gentlemen Ransomware: Operations and Tactics</title><link>https://runtimerebel.com/blog/identifying-the-gentlemen-ransomware-operations-and-tactics</link><guid isPermaLink="true">https://runtimerebel.com/blog/identifying-the-gentlemen-ransomware-operations-and-tactics</guid><description>Analysis of The Gentlemen ransomware group, its aggressive 90% affiliate payout model, and investigations into the identity of its primary administrator.</description><pubDate>Thu, 11 Jun 2026 09:40:19 GMT</pubDate><category>The Gentlemen</category><category>Ransomware</category><category>Cybercrime</category><category>RaaS</category><category>Affiliate Marketing</category></item><item><title>Infostealers: Millions of Devices Compromised for Credential Theft</title><link>https://runtimerebel.com/blog/infostealers-millions-of-devices-compromised-for-credential-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/infostealers-millions-of-devices-compromised-for-credential-theft</guid><description>Infostealers are increasingly enabling ransomware and cybercrime operations by compromising millions of devices to harvest credentials and sensitive data.</description><pubDate>Thu, 11 Jun 2026 05:41:49 GMT</pubDate><category>Infostealers</category><category>Credential Theft</category><category>Ransomware</category><category>Cybercrime</category><category>Malware</category></item><item><title>TA4922 Expands Global Cybercrime: Analysis of Diverse TTPs</title><link>https://runtimerebel.com/blog/ta4922-expands-global-cybercrime-analysis-of-diverse-ttps</link><guid isPermaLink="true">https://runtimerebel.com/blog/ta4922-expands-global-cybercrime-analysis-of-diverse-ttps</guid><description>Runtime Rebel analyzes TA4922&apos;s expanding global cybercrime operations, detailing diverse TTPs and providing actionable mitigation strategies for security professionals.</description><pubDate>Fri, 05 Jun 2026 05:37:51 GMT</pubDate><category>TA4922</category><category>Cybercrime</category><category>China</category><category>Phishing</category><category>Malware Distribution</category></item><item><title>FBI’s 2025 Internet Crime Report: Trends and Outlook</title><link>https://runtimerebel.com/blog/fbis-2025-internet-crime-report-trends-and-outlook</link><guid isPermaLink="true">https://runtimerebel.com/blog/fbis-2025-internet-crime-report-trends-and-outlook</guid><description>The FBI&apos;s 2025 Internet Crime Report highlights evolving cybercrime trends, victim impact, and reporting significance for US security professionals.</description><pubDate>Wed, 27 May 2026 17:14:55 GMT</pubDate><category>FBI</category><category>Internet Crime Report</category><category>Cybercrime</category><category>IC3</category><category>Trends</category><category>2025</category></item><item><title>FIOD Seizes 800 Servers: Disruption of Bulletproof Hosting</title><link>https://runtimerebel.com/blog/fiod-seizes-800-servers-disruption-of-bulletproof-hosting</link><guid isPermaLink="true">https://runtimerebel.com/blog/fiod-seizes-800-servers-disruption-of-bulletproof-hosting</guid><description>Dutch authorities seize 800 servers from a bulletproof hosting provider, disrupting infrastructure for cyberattacks, disinformation, and interference campaigns.</description><pubDate>Fri, 22 May 2026 20:37:48 GMT</pubDate><category>Bulletproof Hosting</category><category>Cybercrime</category><category>FIOD</category><category>Netherlands</category><category>Server Seizure</category><category>Disinformation</category><category>Law Enforcement Action</category></item><item><title>Dismantling First VPN: Global Takedown of Ransomware Infrastructure</title><link>https://runtimerebel.com/blog/dismantling-first-vpn-global-takedown-of-ransomware-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/dismantling-first-vpn-global-takedown-of-ransomware-infrastructure</guid><description>Authorities dismantle First VPN Service, a critical infrastructure hub used by 25 ransomware groups for masking data theft and DDoS attacks.</description><pubDate>Fri, 22 May 2026 20:37:05 GMT</pubDate><category>First VPN Service</category><category>Ransomware Infrastructure</category><category>Law Enforcement Takedown</category><category>Cybercrime</category><category>Network Security</category></item><item><title>Kimwolf Botnet Operator Jacob Butler Arrested in DDoS-for-Hire Case</title><link>https://runtimerebel.com/blog/kimwolf-botnet-operator-jacob-butler-arrested-in-ddos-for-hire-case</link><guid isPermaLink="true">https://runtimerebel.com/blog/kimwolf-botnet-operator-jacob-butler-arrested-in-ddos-for-hire-case</guid><description>DOJ arrests Canadian operator of the Kimwolf botnet, a variant of the AISURU malware, used in large-scale DDoS-for-hire attacks against global targets.</description><pubDate>Fri, 22 May 2026 09:12:55 GMT</pubDate><category>Kimwolf</category><category>AISURU</category><category>DDoS for Hire</category><category>Jacob Butler</category><category>Cybercrime</category><category>DOJ</category></item><item><title>Apple&apos;s App Store Fraud Prevention: Over $11B Blocked</title><link>https://runtimerebel.com/blog/apple-s-app-store-fraud-prevention-over-11b-blocked</link><guid isPermaLink="true">https://runtimerebel.com/blog/apple-s-app-store-fraud-prevention-over-11b-blocked</guid><description>Runtime Rebel analyzes Apple&apos;s disclosure of blocking $11B in App Store fraud over six years, detailing the ongoing fight against malicious apps.</description><pubDate>Thu, 21 May 2026 20:41:16 GMT</pubDate><category>Apple</category><category>App Store</category><category>Fraud</category><category>Cybercrime</category><category>Mobile Security</category><category>Payment Fraud</category></item><item><title>Interpol Operation Ramz: Strengthening MENA Region Cyber Defense</title><link>https://runtimerebel.com/blog/interpol-operation-ramz-strengthening-mena-region-cyber-defense</link><guid isPermaLink="true">https://runtimerebel.com/blog/interpol-operation-ramz-strengthening-mena-region-cyber-defense</guid><description>Interpol&apos;s Operation Ramz highlights increased law enforcement collaboration in the Middle East to dismantle phishing and ransomware infrastructure.</description><pubDate>Wed, 20 May 2026 09:16:43 GMT</pubDate><category>INTERPOL</category><category>Operation Ramz</category><category>MENA Region</category><category>Cybercrime</category><category>Phishing</category></item><item><title>GitHub Investigates Claimed TeamPCP Breach of 4,000 Internal Repos</title><link>https://runtimerebel.com/blog/github-investigates-claimed-teampcp-breach-of-4000-internal-repos</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-investigates-claimed-teampcp-breach-of-4000-internal-repos</guid><description>GitHub is investigating a potential breach of 4,000 internal repositories claimed by TeamPCP, highlighting the risk of source code leaks for enterprises.</description><pubDate>Wed, 20 May 2026 05:27:11 GMT</pubDate><category>GitHub</category><category>TeamPCP</category><category>Source Code Leak</category><category>Data Breach</category><category>Cybercrime</category></item><item><title>AI-Developed Zero-Day 2FA Bypass: Analyzing Google&apos;s Disclosure</title><link>https://runtimerebel.com/blog/ai-developed-zero-day-2fa-bypass-analyzing-google-s-disclosure</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-developed-zero-day-2fa-bypass-analyzing-google-s-disclosure</guid><description>Google identifies the first in-the-wild zero-day exploit for 2FA bypass developed using AI, signaling a shift in cybercriminal vulnerability discovery.</description><pubDate>Mon, 11 May 2026 16:59:10 GMT</pubDate><category>AI Threats</category><category>2FA Bypass</category><category>Zero-Day</category><category>Google Security Disclosure</category><category>Cybercrime</category></item><item><title>Crimenetwork Marketplace Takedown: Impact on Underground Cybercrime</title><link>https://runtimerebel.com/blog/crimenetwork-marketplace-takedown-impact-on-underground-cybercrime</link><guid isPermaLink="true">https://runtimerebel.com/blog/crimenetwork-marketplace-takedown-impact-on-underground-cybercrime</guid><description>German authorities dismantled the Crimenetwork marketplace reboot, arresting its operator and seizing infrastructure used for global illicit digital trade.</description><pubDate>Sun, 10 May 2026 16:23:20 GMT</pubDate><category>Crimenetwork</category><category>Dark Web</category><category>Takedown</category><category>Cybercrime</category><category>Law Enforcement</category></item><item><title>Gavril Sandu Extradited to US for Historical Phishing Scheme</title><link>https://runtimerebel.com/blog/gavril-sandu-extradited-to-us-for-historical-phishing-scheme</link><guid isPermaLink="true">https://runtimerebel.com/blog/gavril-sandu-extradited-to-us-for-historical-phishing-scheme</guid><description>Gavril Sandu, a Romanian national, faces US charges for a 2007-2008 phishing operation that targeted financial institutions and thousands of victims.</description><pubDate>Wed, 06 May 2026 12:48:13 GMT</pubDate><category>Gavril Sandu</category><category>Phishing</category><category>Identity Theft</category><category>Extradition</category><category>Cybercrime</category><category>Financial Fraud</category></item><item><title>AI-Assisted Attacks: Lessons from the Kaikatsu Club Data Breach</title><link>https://runtimerebel.com/blog/ai-assisted-attacks-lessons-from-the-kaikatsu-club-data-breach</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-assisted-attacks-lessons-from-the-kaikatsu-club-data-breach</guid><description>Analyze the 2025 Kaikatsu Club breach where AI-assisted malicious code allowed a teenager to steal 7 million user records, signaling a new era of cyber threats.</description><pubDate>Mon, 04 May 2026 12:41:59 GMT</pubDate><category>AI Assisted Attacks</category><category>Kaikatsu Club</category><category>Data Breach</category><category>Japan</category><category>Cybercrime</category></item><item><title>North Korea Dominates Crypto Heists: 76% of Stolen Funds by 2026</title><link>https://runtimerebel.com/blog/north-korea-dominates-crypto-heists-76-of-stolen-funds-by-2026</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korea-dominates-crypto-heists-76-of-stolen-funds-by-2026</guid><description>North Korean threat actors are projected to be responsible for 76% of all cryptocurrency stolen by 2026, utilizing sophisticated methods for large-scale heists.</description><pubDate>Sat, 02 May 2026 00:49:12 GMT</pubDate><category>North Korea</category><category>Cryptocurrency Theft</category><category>Lazarus Group</category><category>Cybercrime</category><category>Financial Crime</category><category>Nation State APT</category></item><item><title>French ANTS Agency Data Breach: Teen Suspect Detained</title><link>https://runtimerebel.com/blog/french-ants-agency-data-breach-teen-suspect-detained</link><guid isPermaLink="true">https://runtimerebel.com/blog/french-ants-agency-data-breach-teen-suspect-detained</guid><description>French authorities detain a 15-year-old suspected of orchestrating a data breach at ANTS, the national agency for administrative documents, impacting citizen data…</description><pubDate>Fri, 01 May 2026 20:23:14 GMT</pubDate><category>ANTS</category><category>France Titres</category><category>Data Breach</category><category>Government Agency</category><category>Cybercrime</category><category>Teen Hacker</category></item><item><title>BlackCat Ransomware: Cybersecurity Pros Sentenced for 2023 Attacks</title><link>https://runtimerebel.com/blog/blackcat-ransomware-cybersecurity-pros-sentenced-for-2023-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/blackcat-ransomware-cybersecurity-pros-sentenced-for-2023-attacks</guid><description>Two cybersecurity professionals receive four-year prison sentences for their roles in facilitating BlackCat (ALPHV) ransomware attacks against U.S. victims.</description><pubDate>Fri, 01 May 2026 12:28:05 GMT</pubDate><category>BlackCat</category><category>ALPHV</category><category>Ransomware</category><category>Insider Threat</category><category>Department of Justice</category><category>Cybercrime</category></item><item><title>Global Authorities Dismantle 9 Crypto Scam Centers, 276 Arrested</title><link>https://runtimerebel.com/blog/global-authorities-dismantle-9-crypto-scam-centers-276-arrested</link><guid isPermaLink="true">https://runtimerebel.com/blog/global-authorities-dismantle-9-crypto-scam-centers-276-arrested</guid><description>International law enforcement dismantles nine crypto scam centers and arrests 276 suspects, disrupting a massive pig butchering network targeting global victims.</description><pubDate>Thu, 30 Apr 2026 12:41:31 GMT</pubDate><category>Crypto Fraud</category><category>Pig Butchering</category><category>Cybercrime</category><category>Law Enforcement</category></item><item><title>Roblox Account Hijacking: 610,000 Accounts Compromised and Sold</title><link>https://runtimerebel.com/blog/roblox-account-hijacking-610000-accounts-compromised-and-sold</link><guid isPermaLink="true">https://runtimerebel.com/blog/roblox-account-hijacking-610000-accounts-compromised-and-sold</guid><description>Ukrainian police arrested a group for hijacking 610,000 Roblox accounts and generating $225,000 in profits through illegal sales of user data.</description><pubDate>Wed, 29 Apr 2026 20:30:38 GMT</pubDate><category>Roblox</category><category>Account Takeover</category><category>Credential Stuffing</category><category>Cybercrime</category><category>Identity Theft</category></item><item><title>LofyGang Targets Minecraft Players with LofyStealer Malware</title><link>https://runtimerebel.com/blog/lofygang-targets-minecraft-players-with-lofystealer-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/lofygang-targets-minecraft-players-with-lofystealer-malware</guid><description>Brazilian cybercrime group LofyGang resurfaces after three years, deploying LofyStealer (GrabBot) disguised as a Minecraft &apos;Slinky&apos; hack to steal player credentials.</description><pubDate>Tue, 28 Apr 2026 20:34:56 GMT</pubDate><category>LofyGang</category><category>LofyStealer</category><category>GrabBot</category><category>Minecraft</category><category>Infostealer</category><category>Cybercrime</category></item><item><title>ADT Confirms Data Breach Amid ShinyHunters Extortion Threat</title><link>https://runtimerebel.com/blog/adt-confirms-data-breach-amid-shinyhunters-extortion-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/adt-confirms-data-breach-amid-shinyhunters-extortion-threat</guid><description>ADT confirms a data breach following a ShinyHunters extortion attempt. Customer data is at risk; security professionals must advise enhanced vigilance.</description><pubDate>Sat, 25 Apr 2026 00:43:18 GMT</pubDate><category>ADT</category><category>ShinyHunters</category><category>Data Breach</category><category>Extortion</category><category>Cybercrime</category><category>Threat Intelligence</category></item></channel></rss>