Security News

Cybersecurity news aggregator

CRITICAL News SC Media

Inmate charged with stealing seized cryptocurrency while serving prison sentence

The article describes a cross-site scripting vulnerability (CVE-2024-42009, CVSS 9.3 CRITICAL) in Roundcube Webmail that allows threat actors to gain initial access. Affected versions are Roundcube Webmail prior to version 1.5.8 and versions 1.6.0 through 1.6.7. The fixed versions are 1.5.8 and 1.6.8.
Read Full Article →

Threat Intelligence Inmate charged with stealing seized cryptocurrency while serving prison sentence July 10, 2026 Share By SC Staff (Adobe Stock Images) A Bulgarian national, already serving a lengthy prison sentence for laundering millions stolen from American fraud victims, has been charged with stealing $290,000 in government-seized cryptocurrency. Rossen G. Iossifov appeared in federal court this Wednesday on charges of removal of property to prevent seizure and conspiracy to commit money laundering, as reported by Bleeping Computer. While incarcerated, Iossifov allegedly conspired with others to move $290,000 in cryptocurrency from a seized account in January 2024. The funds were routed through multiple crypto exchanges and mixing services to evade government seizure. Iossifov's previous conviction stemmed from his operation of RG Coins, a cryptocurrency exchange in Sofia, Bulgaria, which facilitated money laundering for the Alexandria Online Auction Fraud Network. This network victimized at least 900 Americans by selling non-existent goods and converting payments into cryptocurrency, which Iossifov then laundered. Evidence indicated Iossifov tailored his business to criminal clients, offering favorable exchange rates and allowing transactions without identification. He previously laundered nearly $5 million for four network members, collecting over $184,000. The court ordered him to pay over $2.6 million in restitution and forfeit the cryptocurrency in the new case. If convicted of the new charges, he faces a maximum of 25 years in prison. Source: Bleeping Computer SC Staff Related Threat Intelligence Suspected Chinese spies target universities with Roundcube exploit SC Staff July 9, 2026 The threat actor, tracked by Proofpoint as UNK_MassTraction, exploits CVE-2024-42009, a cross-site scripting vulnerability in Roundcube, to gain initial access. Threat Intelligence Suspected pro-Russia hacktivist arrested in Spain with FBI support SC Staff July 7, 2026 The arrest is a component of Operation Riptide, an international initiative focused on disrupting malicious cyber activity and holding perpetrators accountable. Threat Intelligence Iranian hackers use new modular C2 framework against Israeli organizations SC Staff July 6, 2026 The threat cluster, dubbed Cavern Manticore by Check Point Research, exhibits tactical similarities with known groups like MuddyWater and Lyceum. Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Account Harvesting DNS Spoofing Deauthentication Attack Defacement Dictionary Attack Distributed Scans Domain Hijacking Fault Line Attacks Google Hacking Password Cracking You can skip this ad in 5 seconds

Share this article