
Loading summary
A
From the CISO series, it's Cybersecurity Headlines
B
these are the cybersecurity headlines for Wednesday, June 24, 2026. I'm Sarah Lane. Feds seize Alleged cyber scam Infrastructure the US Government has seized cloud infrastructure allegedly used by subsidiaries of the Cambodian conglomerate who Huion Group said to play a key role in supporting online investment scams, money laundering, human trafficking and marketplaces for stolen data. This follows last year's decision to cut Huion off from the US financial system after FinCEN said the company laundered at least $4 billion in illicit funds between 2021 and 2025, including proceeds tied to North Korean cybercrime. The FBI and international partners have been disrupting the Southeast Asian scam industry by targeting not just the scammers themselves, but the infrastructure that helps them operate. Dragos unveils AI for OT security OT security company Dragos has launched Ember AI, an assistant trained specifically on industrial systems like power grids, factories and other critical infrastructure. Dragos specializes in protecting those kinds of operational technology environments and says the tool can answer questions in plain English, pull together threat and vulnerability data, identify likely attackers, and help security teams understand what's happening faster. Cybersecurity firms are increasingly building AI tools around their own specialized data sets and expertise rather than relying solely on general purpose AI models. Scattered Spider hackers plead guilty Two alleged members of the cybercrime group Scattered Spider, a 20 year old and an 18 year old, pleaded guilty in the UK to charges tied to the 2024 hack of transport for London, which disrupted the city's transit network. Prosecutors say the pair were involved in an even broader cybercrime operation linked to separate sim swapping, SMS phishing, ransomware attacks and intrusions at more than 100 organizations, with U.S. authorities alleging Scattered Spider collected at least $115 million in ransom payments. Fake AI agent scale passes security scans Here's a reminder that AI agents can create entirely new supply chain risks. Security firm Air says it created a fake AI agent skill, got it approved by a popular marketplace, promoted it with Instagram ads, and ultimately reached about 26,000 agents, all while passing every security scanner it tested. The skill itself looked harmless, but it pointed to an external website that could be changed later, exposing a blind spot in how agent skills are vetted. And this highlights how today's AI security checks often examine the code submitted for review, but not the external instructions an agent may fetch and follow later. Huge thanks to our sponsor, Guard Square. Is your mobile app truly protected? Relying on the OS isn't enough. A Global study of 1300 security and developer leaders found that 96% of teams using layered protection reported significantly fewer security incidents. Don't wait for a breach to harden your defenses. Get the protection needed for modern security risks and learn more@guardsquare.com lookalike npm package hides multi stage windows rat jfrog Researchers found a malicious NPM package masquerading as the widely used JavaScript library post CSS Selector parser. Using a nearly identical name to slip past casual reviews, the package executed code as soon as it was imported, downloading and installing a multi stage Windows remote access Trojan that could steal Chrome passwords, provide remote shell access, transfer files, and maintain persistence on infected machines. This is yet another example of attackers moving beyond simple typo squatting with highly convinc lookalike packages that turned routine software dependencies into supply chain attack vectors. Spocks charged with running cybercrime marketplaces An Algerian man known online as Spocks Spox was extradited to the US and charged with running two cybercrime marketplaces that allegedly sold fishing kits, stolen financial credentials, compromised email access and other fraud tools. Prosecutors say Abdullah Balmilli created around 600 fishing kits that targeted major banks and payment services, collected data from roughly 5,600 victims, and funneled around $900,000 through cryptocurrency accounts between 2020 and 2023. Investors also allege he built back doors into phishing kits sold to other attackers to keep stealing data even after the kits changed hands. Mushrooming malicious pull requests threaten dev workflows Researchers at Novi say they've uncovered a widespread CICD security weakness dubbed cordyceps that could let attackers use malicious pull requests to compromise software supply chains. The issue stems from overly permissive automated workflows that can expose high privilege tokens and signing keys. And Novi found hundreds of potentially vulnerable repositories, including projects from Microsoft, Google, cloudflare, Apache and the Python Software Foundation. There's no evidence the technique has been exploited in the wild so far. Purchase scam tactic headed for the World cup recorded Future reports that scammers are increasingly hijacking legitimate websites to capture people searching for World cup tickets, merchandise and other event related deals. Instead of creating scam sites that need to rank in search results, the attackers compromise trusted websites, inject fake product pages, and quietly redirect search visitors to fraudulent stores that then take payments and then steal credit card data. The tactic is difficult to detect because the scam domains themselves don't appear in search results. One operation recorded future tracked generated roughly 17 million visits in 2026 alone. New calendar Item Alert We've got a CISO Series meetup in Vancouver on July 23rd. Head over to the events page over at cisoseries.com and register. We'll also be hosting a meetup in Seattle on July 29th at Georgetown Beer. Come join us for a few drinks. Hang out with your friendly local cyber peeps. It'll be a lot of fun. Find all the details on our events page@cisoseries.com and we hope to see you there. If you have some thoughts on the news from today, or about our show in general, be sure to reach out to us feedbackisoseries.com we'd love to hear from you. I'm Sarah Lane, reporting for the CISO series. Stay safe out there, everybody.
A
Cybersecurity headlines are available every weekday. Head to cisoseries.com for the full stories. Behind the headlines.
Host: Sarah Lane, CISO Series
Theme: Fast-breaking stories from the world of cybersecurity, covering government crackdowns on cybercrime, advances in OT security AI, notable hacker indictments, supply chain threats, and the evolving tactics of attackers.
This episode provides a snapshot of major cybersecurity news, highlighting U.S. federal action against scam infrastructure, Dragos' new AI for operational technology security, significant court developments in the Scattered Spider case, and a spate of innovative tactics targeting supply chain and consumer vulnerabilities ahead of the World Cup.
On infrastructure takedown:
“The FBI and international partners have been disrupting the Southeast Asian scam industry by targeting not just the scammers themselves, but the infrastructure that helps them operate.” (Sarah Lane, 00:42)
On AI supply chain risk:
“Today's AI security checks often examine the code submitted for review, but not the external instructions an agent may fetch and follow later.” (Sarah Lane, 03:01)
On software supply chain risk:
“Attackers moving beyond simple typo squatting with highly convincing lookalike packages that turned routine software dependencies into supply chain attack vectors.” (Sarah Lane, 04:40)
Sarah Lane delivers news in a brisk, matter-of-fact tone, balancing urgency with clarity. Quotations highlight the episode's focus on pragmatic risk assessment and technical depth without resorting to alarmism.
This episode captures escalating sophistication in both cyber threats and the countermeasures deployed by defenders, from government crackdowns to specialized AI tools. It also underscores persistent gaps in supply chain and AI agent security vetting, with the looming World Cup serving as a high-profile stage for innovation among scammers.
For more stories and in-depth analysis, visit CISOseries.com.