Dutch police bust investment fraud ring stealing over €100 million

2026-07-16T01:23:27Zc344242f0d1a84dd0577c563f9ac64fc5b860bc71011e476a6aa3e31f2f011f5
AI abuseCISACVE-2026-15409CVE-2026-15410Gemini CLIGitHubSharePointSonicWallZoomaccount takeoverbotnetbulletproof hostingfraudincident responseinfostealerlaw enforcementmalwarenpmpatchingremote access trojansupply-chainvulnerabilityzero-day

What happened

The BleepingComputer feed reports multiple high-impact security events: Zoom disclosed a critical unauthenticated account-takeover vulnerability in its Windows desktop client/SDK; CISA warned of active exploitation of three on-premises SharePoint Server flaws; SonicWall confirmed two SMA1000 vulnerabilities (CVE-2026-15409, CVE-2026-15410) being used in zero-day attacks and released patches. Other notable items include malicious AsyncAPI npm packages delivering an info-stealing RAT (supply-chain attack), hundreds of fake GitHub repos distributing infostealers, abuse of Google’s open-source Gem

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
c344242f0d1a84dd0577c563f9ac64fc5b860bc71011e476a6aa3e31f2f011f5
Enrichment time
2026-07-16T01:23:27Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.