Musician admits to $10M streaming royalty fraud using AI bots
2026-03-20T13:23:30Z•fed3ad5da52be4f2823938e106ae156e9d7300f3f3819766a11b92be9d893890
AI botsAdobe CommerceAisuruBitrefillBluenoroffHandala seizure','Stryker incident','Microsoft Intune','CISA','UIoT DDoSJackSkidKB5079473KimWolfLazarusMagentoMicrosoft SharePointMossadNavia data breachOneDrive sign‑inPolyShellTeams sign‑inWindows 11botnet disruptiondata breachroyalty fraudstreaming fraudunauthenticated RCEvulnerability exploitation
What happened
BleepingComputer roundup (Mar 19–20, 2026): A North Carolina musician pled guilty to using AI-driven streaming bots to fraudulently collect over $10M in royalties. International law‑enforcement disrupted C2 infrastructure for major IoT DDoS botnets (Aisuru, KimWolf, JackSkid, Mossad). Multiple high‑impact security incidents and disclosures were reported: a new unauthenticated RCE (“PolyShell”) affecting Magento/Adobe Commerce, an actively exploited critical Microsoft SharePoint flaw, Microsoft Windows 11 March update (KB5079473) causing Microsoft account sign‑in failures, and CISA warnings to
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- fed3ad5da52be4f2823938e106ae156e9d7300f3f3819766a11b92be9d893890
- Enrichment time
- 2026-03-20T13:23:30Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.