Ardit Kutleshi, one of the men accused of running the Rydox cybercrime marketplace, has pleaded guilty in the United States to aggravated identity theft and money laundering.
The 28-year-old was extradited from his home country of Kosovo last year. US prosecutors say he and his older brother ran Rydox, an illicit platform where cybercriminals bought stolen personal information, unauthorized access to devices and other tools used to commit fraud.
Sentencing is set for February. The aggravated identity theft charge carries a mandatory minimum of two years in prison. The money laundering count carries a maximum of 20 years.
US healthcare technology company Astrana has told the Securities and Exchange Commission (SEC) that attackers gained access to its servers and made off with private or confidential information. The company describes the incident as material to its financial position.
The filing, submitted on Tuesday evening, makes Astrana the latest in a string of healthcare tech firms to disclose a cyberattack to the US markets regulator in recent months.
Spoofed phone number opened the door
According to the report, the intrusion did not start with a software flaw. It started with a phone call. The attackers posed as Astrana staff and spoofed the company's main corporate telephone number, so calls to employees appeared to come from a trusted internal line.
Some developers are publishing private GitLab email addresses in READMEs, contributing guides and support pages to collect bug reports. According to researchers at application security company Aikido, these addresses carry a credential that attackers can use to act on GitLab as the developer who owns them.
The addresses come from a built-in GitLab feature called "Email work item to this project." GitLab generates them automatically. When someone sends a message to one of these addresses, GitLab turns the email into an issue or task in the project.
The problem is that each address contains a long-lived token tied to the developer's account. This string works as the credential for creating work items by email.
Attackers have moved beyond scanning for WordPress sites vulnerable to CVE-2026-87902. They are now exploiting the flaw to plant files that run shell commands when they are accessed, according to WordPress security firm Patchstack.
The vulnerability was fixed in WordPress 7.1.2. Scanning began less than five hours after that release. Since then, malicious traffic has grown tenfold, and attackers are now trying to deliver payloads.
Patchstack says it saw the first malicious requests at 17:44 UTC on September 22. They came from a small group of IP addresses and targeted several sites under the company's protection.
A newly discovered botnet called Carbonato is breaking into poorly secured Docker hosts and installing the Hermes Agent AI framework, which then carries out the operators' orders on compromised machines, according to ThreatDown.
The enterprise security company found the malware in an unauthenticated Docker registry that held nearly 60 repositories and 4.3 GB of image data. The operational evidence recovered from it covers the period from October 2024 to August 2026. The archive also held details on a separate campaign that pushed counterfeit cryptocurrency wallet apps, a lure that has recently shown up in Mac-focused stealer campaigns as well.
Guy Fawkes News is financed by advertising. You can choose how you want to use this website:
With advertising: we load an advertising script from a third-party ad network. The ad network may set cookies, use your IP address and device information, and may process data outside the EU. We also count your visits for our own visitor statistics (with a random ID stored in your browser).
Ad-free for €0.99 per month: no advertising and no advertising tracking. Cancel at any time.
You can change your decision at any time via "Cookie Settings" at the bottom of every page.