CyberSecurity Knuggets

Nov 18, 2025

Subject: US Issues Seizure Warrants for Starlink Terminals in Myanmar Cyberscam Compounds

Sender: info@metacurity.comD

Summary:

– US law enforcement issued seizure warrants for Starlink satellite internet terminals used by cybercriminals running scam compounds in Myanmar near the Thai border.

– Warrants authorized seizure of Starlink terminals and accounts allegedly used in money laundering and wire fraud targeting US citizens.

– FBI affidavit claims Starlink devices played a “substantial role” in the operation and recommended SpaceX disable service to these terminals.

– The compounds are linked to the Democratic Karen Benevolent Army, a US-sanctioned armed group.

– The action is part of the District of Columbia Scam Center Strike Force initiative.

– Additional related news includes US nationals pleading guilty to aiding North Korean IT worker fraud, $28B in illicit crypto funds traced in two years, Princeton University data-stealing cyberattack, critiques of Anthropic’s autonomous AI Chinese hack report, and US Cyber Command investing in AI cyberwarfare agents.

– Notable arrests and cyber incidents worldwide highlight the ongoing global cybersecurity landscape.


Subject: The CyberWire 11.17.25: The Pentagon is Spending Millions on AI-assisted Hacking

Sender: editor@thecyberwire.comD

Summary:

– The Pentagon awarded a $12.6 million contract to Arlington-based stealth startup Twenty (XX), which specializes in AI-assisted offensive cyber capabilities.

– Twenty has also secured a $240,000 US Navy research contract and venture capital backing from CIA’s In-Q-Tel, Caffeinated Capital, and General Catalyst.

– Forbes notes this is unusual as most government cyber contracts go to legacy defense contractors or small bespoke firms.

– A New York Times investigation exposed $28 billion in illicit funds laundered through major cryptocurrency exchanges—including Binance and OKX—over the past two years by hackers and scammers worldwide.

– Indian police arrested eight suspects involved in hacking and selling surveillance footage stolen from over 50,000 CCTV cameras, including a maternity hospital.

– The newsletter includes sponsored content on cybersecurity technologies and upcoming webinars focused on AI and data security, and selected reading on recent cyber threats and investigations.


Subject: DoorDash Says Personal Information Stolen in Data Breach

Sender: news@securityweek.comD

Summary:

– DoorDash disclosed a data breach compromising personal information.

– Logitech confirmed a data breach linked to the Clop extortion gang’s Oracle E-Business Suite attacks.

– Iranian hackers are targeting defense and government officials in an ongoing campaign.

– Fortinet patched a critical zero-day vulnerability actively exploited in its FortiWeb product.

– The British CPS seized about $5.39 million in crypto assets stolen via a 2020 Twitter hack involving hijacked celebrity accounts.

– A Russian man linked to the Void Blizzard hacking group was arrested in Thailand at the FBI’s request.

– Somalia confirmed a breach of its electronic visa platform exposing traveller data.

– In India, police busted a massive cybercrime ring that hacked into CCTV systems for hospitals, schools, and private homes, selling footage on Telegram.

– A South Korean man was imprisoned for illegal transactions with North Korean hackers linked to game cheating software.

– Other featured topics include cybersecurity expert insights, software development AI security, and recent hacking trends, plus information about cybersecurity virtual events and resources.

Stay Well!

summy
summy