Threats Without Borders - Issue 300
A cyber investigation newsletter, for like, 300 weeks.
For those of us in the banking industry, the big story of the week is the ransomware attack on core banking services provider Fiserv by the Cl0p group. Fiserv (kind of) acknowledged the attack but attempted to minimize it, saying it was a server “not connected to client systems” and that it “finds no evidence of customer data theft”.
Stop me if you’ve heard this one before.
It seems likely the attack vector was the Windchill product lifecycle management software (PLM) software. Team Cymru published research over the weekend showing the group is observed abusing CVE-2026-12569, which allows unauthenticated remote command execution with the Windchill environment.
And for Fiserve customers, we’ll just all hold our breath and hope it isn’t MOVEit 2.0.
https://www.team-cymru.com/post/cl0p-ransomware-mft-attack-pattern-threat-intelligence
https://www.reuters.com/legal/government/philips-shell-targeted-by-hacking-group-2026-08-13/
300
Wow. This is Issue 300. Not only have I been publishing this newsletter for 300 weeks, but it’s also been 300 consecutive weeks. Every Tuesday, never a miss. Other than staying alive and remaining married, probably one of the most constant things I’ve ever consciously done. Certainly a better track record than my efforts to eat healthy or exercise.
So, I thought this would be a great time to cover some questions I’m frequently asked about the newsletter.
Why do you publish on Substack and not (insert trending platform)? Well, because Substack is easy and really gives authors considerable features for the cost to use the service… which is free. I started here and have never found a reason to leave. At this point, I believe I’m the longest-running, regularly published, cybercrime and investigations-focused newsletter on the platform.
What’s your background - why should I give you my time? Well, you probably shouldn’t give me any of your time at all, but I truly appreciate those of you who do. I was in law enforcement for 24 years. Patrol for 12, criminal investigations for 12. Early on, I was assigned to the ICAC task force, which got me into digital forensics when we were still pulling iTunes backups off the iPhone 4 and EnCase was magic. I learned the financial crime game, which transitioned me to cyber. Now, I work in cybersecurity for a bank. I’m filled with pith, snark, and caffeine. Listen to me at your own peril.
Why do you write out the entire web URL and not just hotlink a specific word like other newsletters do? Hotlinking a specific keyword or just “Link” would certainly save space, but I can’t claim to be a cybersecurity awareness and fraud prevention professional and expect people to blindly click links. So I write out every URL, and the reader can choose to click the link or copy and paste it into their browser.
Do you use AI to write the newsletter? Ah, do you actually read the shit that gets written here? Do you think AI would produce something this consistently disappointing? I use Claude and Gemini regularly to research topics and organize my ideas into coherent thoughts. My usual writing process involves free-writing all my ideas in a document, then using Grammarly to make it consumable. Early subscribers might recall what the newsletter was like before I upgraded to Grammarly's premium version. You can check the archives, especially before Issue 100, to see the difference. I remember the comment that motivated me to make a change: someone simply said, “Bro, the grammar.”
How many people read the newsletter each week? I used to be able to answer this pretty definitely, but recently, most email providers have started blocking the tracking pixels Substack uses to see if an email has been opened. So, the “opens' data in Substack's reports has become largely unreliable. Additionally, a lot of readers prefer navigating directly to the newsletter URL each week instead of subscribing and receiving it via email, as they have become more cautious with their inboxes, and email providers have a propensity to mark newsletters as spam and drop them. However, I closely monitor my subscriber engagement, which is a good indicator of my content's quality. The short answer is I don’t really know, but I like to answer the question with “a lot”.
What’s up with the attorney jokes? In the newsletter's early days, when my subscriber list was small, I spoke at a lawyer's event and gained many new subscribers. It nearly doubled the newsletter's audience. A few months later, I wrote a critique that was harsh towards attorneys, and within minutes, unsubscribe notices flooded in. I don't remember the exact numbers, but it almost wiped out my gains from the legal event. It was eye-opening to see how much people actually read what I write—a powerful moment. After that, I became more mindful of my tone, except when dealing with attorneys.
Why do prisoners in Georgia have cell phones?
A new intelligence exchange has been set up within the LEEP portal to share information about scams originating from Georgia prisons. To join the exchange:
LEEP Portal » Justice Connect » Search for “Jury duty GA Prison System Scam”
Obviously, you need to have access to the LEEP portal.
The News
McAfee claims scammers are exploiting AI technology to geolocate travel photos for targeted phishing attacks, with research showing that AI models can identify locations with over 90% accuracy using only the visual content of images. “The takeaway isn’t that AI has “seen” your photos somewhere before. It’s that a photograph inherently contains an enormous amount of locating information, in the architecture, the light, the signage, the landscape, simply by virtue of existing in the world”. https://www.mcafee.com/blogs/mcafee-news/ai-travel-photo-location-scams-geolocation-research/
VirusTotal now offers “enriched URL reports” to all users regardless of subscription level - yes, free users included. I’m a strong proponent of VT and feature the service in my Website Triage talk. The news release claims “URL Scanning 2.0 enriches reports with ‘under-the-hood’ headless browser telemetry, including the DOM, full-page screenshots, web technologies, and network request logs. Crucially, it introduces historical analysis pivoting, giving analysts the ability to track how a page has changed over time.” Awesome. https://blog.virustotal.com/2026/08/enriched-url-reports-url-scanning-20.html
You’re Invited—to be a victim. Cofense explains why invitation-themed phishing emails remain so effective. https://cofense.com/blog/you-re-invited-to-get-phished!-why-invitation-themed-emails-remain-effective
Trellix notes that the criminal use of AI has become a fully commoditized part of the cybercriminal ecosystem, lowering the barriers for sophisticated attacks. Tasks that once required advanced user skills are now simplified into single-prompt workflows, making traditional signature-based defenses less effective. The company reports that a service calling itself MessiahGPT is being actively marketed on BreachForums. The service advertises itself as “the first AI model trained with zero ethical constraints, no Reinforcement Learning from Human Feedback (RLHF), no Constitutional AI, and no concept of harm or illegality.” https://www.trellix.com/blogs/research/weaponized-ai-commoditization-of-cybercrime/
First discusses the psychological toll of incident response… over and over again. https://www.first.org/blog/20260813-Mind_Over_Malware
President Trump signed a new executive order to address transnational cybercrime https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/
And it authorizes “hacking back” which is awesome until your organization mistakenly gets caught in the crosshairs. But, I’d rather be inadvertently taken down by Microsoft than intentionally victimized by Cl0p. https://therecord.media/trump-cyber-crime-offensive
Feedback
Send Feedback to matt(at)threatswithoutborders.com
dfir
NIST has published the Digital Forensics Artifact Catalog (ArtCat). Developed by digital forensic practitioners for their peers, ArtCat provides a structured, queryable repository of digital forensic artifacts. This resource aims to facilitate efficient, automated extraction of relevant information, enhance the accessibility and reliability of artifact interpretation, and promote wider acceptance within the scientific community. https://artcat.nist.gov/all-artifacts
All of this free. For better or worse. Share it with a friend - or enemy.
Cool Jobs
Manager of E-commerce fraud and investigations, TJX Companies. https://jobs.tjx.com/global/en/job/TJCOGLOBALREQ127051EXTERNALENGLOBAL/Mgr-of-Ecommerce-Fraud-Prevention-Investigations
Cool Tools
Marco Arment (creator of the best podcast app - Overcast) releases a new app called Unforgetful - a task app for procrastinators, ADHD, and generally forgetful people. (Free but with in-app purchases for full functionality) https://unforgetful.app/
Snope has a surprisingly good guide on how to spot AI images. https://www.snopes.com/articles/471427/spot-ai-images-guide/
Irrelevant
Bar tour anyone? The oldest bar in every state. https://www.businessinsider.com/oldest-bar-every-state
Sign Off
Kudos to the organizers of the upcoming 2026 IAFCI International conference for pulling together such an amazing slate of speakers. The agenda is packed, but honestly, there are too many choices. Is that actually a thing? It’s like walking into the Candy Kitchen on the boardwalk when your parents say you can pick out one piece of candy.
Each time slot is filled with great presentations, and you can only pick one to attend. I don’t even want to attend my own sessions because of the other speakers in that time slot. Sometimes there is really too much of a good thing.
Seriously, the presenter slate is star-studded from top to bottom, and I can’t wait to take it all in.
Matt
Published every Tuesday, Threats Without Borders offers original commentary and educational pieces related to cybercrime investigations and information security topics. We also summarize and comment on news articles concerning active threat intelligence for the financial industry. The newsletter interests everyone tasked with cybersecurity or involved in preventing or investigating technology-enabled fraud, theft, or money laundering.
Legal: I am not compensated by any entity for writing this newsletter. Obviously, anything written in this space is my own nonsensical opinions and doesn’t represent the official viewpoint of my employer or any associated organization. Blame me, not them.
