CyberSecurity Knuggets
Nov 18, 2025
Subject: US Issues Seizure Warrants for Starlink Terminals in Myanmar Cyberscam Compounds
Sender: info@metacurity.comD
Summary:
– US law enforcement issued seizure warrants for Starlink satellite internet terminals used by cybercriminals running scam compounds in Myanmar near the Thai border.
– Warrants authorized seizure of Starlink terminals and accounts allegedly used in money laundering and wire fraud targeting US citizens.
– FBI affidavit claims Starlink devices played a “substantial role” in the operation and recommended SpaceX disable service to these terminals.
– The compounds are linked to the Democratic Karen Benevolent Army, a US-sanctioned armed group.
– The action is part of the District of Columbia Scam Center Strike Force initiative.
– Additional related news includes US nationals pleading guilty to aiding North Korean IT worker fraud, $28B in illicit crypto funds traced in two years, Princeton University data-stealing cyberattack, critiques of Anthropic’s autonomous AI Chinese hack report, and US Cyber Command investing in AI cyberwarfare agents.
– Notable arrests and cyber incidents worldwide highlight the ongoing global cybersecurity landscape.
Subject: The CyberWire 11.17.25: The Pentagon is Spending Millions on AI-assisted Hacking
Sender: editor@thecyberwire.comD
Summary:
– The Pentagon awarded a $12.6 million contract to Arlington-based stealth startup Twenty (XX), which specializes in AI-assisted offensive cyber capabilities.
– Twenty has also secured a $240,000 US Navy research contract and venture capital backing from CIA’s In-Q-Tel, Caffeinated Capital, and General Catalyst.
– Forbes notes this is unusual as most government cyber contracts go to legacy defense contractors or small bespoke firms.
– A New York Times investigation exposed $28 billion in illicit funds laundered through major cryptocurrency exchanges—including Binance and OKX—over the past two years by hackers and scammers worldwide.
– Indian police arrested eight suspects involved in hacking and selling surveillance footage stolen from over 50,000 CCTV cameras, including a maternity hospital.
– The newsletter includes sponsored content on cybersecurity technologies and upcoming webinars focused on AI and data security, and selected reading on recent cyber threats and investigations.
Subject: DoorDash Says Personal Information Stolen in Data Breach
Sender: news@securityweek.comD
Summary:
– DoorDash disclosed a data breach compromising personal information.
– Logitech confirmed a data breach linked to the Clop extortion gang’s Oracle E-Business Suite attacks.
– Iranian hackers are targeting defense and government officials in an ongoing campaign.
– Fortinet patched a critical zero-day vulnerability actively exploited in its FortiWeb product.
– The British CPS seized about $5.39 million in crypto assets stolen via a 2020 Twitter hack involving hijacked celebrity accounts.
– A Russian man linked to the Void Blizzard hacking group was arrested in Thailand at the FBI’s request.
– Somalia confirmed a breach of its electronic visa platform exposing traveller data.
– In India, police busted a massive cybercrime ring that hacked into CCTV systems for hospitals, schools, and private homes, selling footage on Telegram.
– A South Korean man was imprisoned for illegal transactions with North Korean hackers linked to game cheating software.
– Other featured topics include cybersecurity expert insights, software development AI security, and recent hacking trends, plus information about cybersecurity virtual events and resources.
Stay Well!
