FBI takedown of W3LL phishing service leads to developer arrest
2026-04-13T19:23:37Z•7ec71e6b356c924edd7df00364b734c48602f5e109ea930813f4eac065ea11a5
AdobeAxiosBooking.comCPUID','CPU-Z','HWMonitor','malware-distribution','industrial-cyCVE-2026-34621GitHub ActionsMFA-bypassMarimoMarimo-RCEOpenAIRCEStormW3LLactive-exploitationcertificatescode-signingdata-breachinfostealerlaw-enforcementphishingreservation-PINsession-hijackingsupply-chainsupply-chain-attackzero-day
What happened
BleepingComputer reports multiple high-impact incidents: the FBI and Indonesian authorities dismantled the W3LL global phishing platform and arrested its alleged developer; OpenAI is rotating potentially exposed macOS code‑signing certificates after a malicious Axios package executed in a GitHub Actions workflow; Booking.com confirmed unauthorized access forcing reservation PIN resets; Adobe issued an emergency patch for a zero‑day (CVE-2026-34621) being actively exploited. Additional notable issues include the 'Storm' infostealer that decrypts browser data server‑side enabling session hijacks
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 7ec71e6b356c924edd7df00364b734c48602f5e109ea930813f4eac065ea11a5
- Enrichment time
- 2026-04-13T19:23:37Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.