A 16-year-old is suspected of running KillSec, a ransomware group linked to almost 1,000 attacks around the world. Police arrested three people during a coordinated action day across four European countries.
The operation was coordinated by Eurojust, the European Union's agency for judicial cooperation in criminal matters. According to the agency, KillSec has been active since 2024. Investigators identified suspects in four roles within the group: administrator, developer, negotiator and affiliate.
The teenager is suspected of being both the administrator and the main operator of the group. A second suspect, who worked as a developer, has just turned 18. Eurojust noted that this person was still a minor when some of the alleged offences took place.
Fakturownia, one of Poland's major online invoicing platforms, has disclosed a data breach that may have exposed information on its users and on their customers and business partners.
The company said an unidentified attacker exploited a vulnerability in its systems and gained unauthorized access to its servers. More than 600,000 businesses use the service. Fakturownia has not yet determined how many of them were affected.
What the attacker may have accessed
According to Fakturownia, the potentially compromised data includes:
user and company account data
password hashes
bank account information
authentication and integration tokens
information on customers and business partners
The attacker may also have reached invoices issued through the platform before 2023. The company said payment card data and information stored through its integrations were not affected.
Attackers began abusing a high-severity command injection flaw in Zimbra Collaboration Suite (ZCS) in the weeks after a fix was released but before the bug was publicly disclosed, according to Microsoft.
The vulnerability, tracked as CVE-2026-73570, carries a CVSS score of 8.9. It affects ZCS versions before 10.1.20 and allows unauthenticated attackers to run code remotely on vulnerable mail servers.
How the flaw works
The problem lies in how ZCS handles SNMP notifications. SNMP (Simple Network Management Protocol) is commonly used to monitor and manage network devices and services. In affected versions, untrusted input processed during these notifications is not properly sanitized, which opens the door to OS command injection.
Microsoft has switched on Windows settings backup by default for enterprise devices that are Microsoft Entra-joined or Microsoft Entra hybrid-joined and have been upgraded to Windows 11 26H2. Microsoft Entra is the company's cloud identity and access management platform.
The change follows the release of Windows 11, version 26H2 on September 29. Microsoft had announced the plan in July.
From opt-in to default
The Windows settings backup tool was previously known as Windows Backup for Organizations. It saves enterprise users' Windows settings and restores them after a device is reset, replaced, upgraded, or reimaged.
Microsoft first presented the feature at its Ignite conference in November 2024. At that point it was opt-in and disabled by default. It went into public preview in May 2025 and became generally available in August 2025.
Star Blizzard, a Russian state-backed threat actor, has adopted a new way of installing malware on victims' machines. Microsoft researchers call the method "RedFlick" and say the group is using it to deliver its signature CosmicPulse backdoor.
The technique itself is not new to the security world. What is new is that Star Blizzard now uses it. It lets the group automate more of each attack and cut down on what the victim has to do before the infection runs.
According to Microsoft, Star Blizzard expanded its phishing operations in 2026 and made its malware delivery more efficient. The group has been active since 2017. It has a history of trying out new ways to deliver payloads, including ClickFix and WhatsApp, and it keeps building and deploying new malware families.
Guy Fawkes News is financed by advertising. You can choose how you want to use this website:
With advertising: we load an advertising script from a third-party ad network. The ad network may set cookies, use your IP address and device information, and may process data outside the EU. We also count your visits for our own visitor statistics (with a random ID stored in your browser).
Ad-free for €0.99 per month: no advertising and no advertising tracking. Cancel at any time.
You can change your decision at any time via "Cookie Settings" at the bottom of every page.