Scattered Spider members behind TfL hack get five years in prison

2026-07-16T13:23:31Za3d70428d49c3388bb8b442520734b2194397ababb3df3df64da2a5e81b00c94
AI-abuseAsyncAPICISAGoogle Gemini CLIOracle E-Business SuiteScattered SpiderSharePointSonicWallSpiralsStarland RATWindows 11 EoSZoomaccount-takeoveractive-exploitationbulletproof-hostingcybersecurity-newslaw-enforcementnpmpatchingransomwarerapid-encryptionsupply-chaintrojanized-installersvulnerability-researchzero-day

What happened

A batch of high-impact security stories: CISA ordered federal agencies to urgently patch an actively exploited critical Oracle E‑Business Suite flaw; multiple vendors (SonicWall, Microsoft/SharePoint, Zoom) face actively exploited or critical vulnerabilities with SonicWall SMA1000 tracked as CVE-2026-15409 and CVE-2026-15410; attackers are using supply-chain tactics (trojanized WebEx/Zoom installers, malicious AsyncAPI npm packages) to deliver backdoors like Starland RAT and credential stealers; a new Spirals ransomware strain can complete intrusion-to-encryption in under 24 hours; law‑enforc­

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
a3d70428d49c3388bb8b442520734b2194397ababb3df3df64da2a5e81b00c94
Enrichment time
2026-07-16T13:23:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.