First Pass

9 stories from 6 sources

Cybercrime exploited mainstream infrastructure as defenders pushed back

Day’s Recap

Supporting Articles

11:50 PMBBC

Instagram running ads promoting child sexual abuse material in India, BBC finds

Summary

Paid ads on Instagram in India promoted child sexual abuse material using explicit keywords like “rape” and “child video” and directed users to channels on Telegram where the content was available. The ads appear to have passed platform ad review and were served to users as normal sponsored posts.

Why it matters

When CSAM promotion can be bought through mainstream ad systems, the platforms become scalable infrastructure for abuse and invite immediate legal and regulatory escalation.

3:27 PMKrebs on Security

FBI Seizes NetNut Proxy Platform, Popa Botnet

Summary

The FBI, working with industry partners, seized hundreds of domains tied to NetNut, a large residential proxy service run by Alarum Technologies. The move follows reporting and security firm findings linking NetNut infrastructure to the Popa botnet, which includes at least two million compromised devices.

Why it matters

Residential proxy platforms built on coerced or infected endpoints are a force multiplier for cybercrime, and domain seizures can temporarily blunt that scale.

8:01 PMFinextra

Visa launches threat intelligence platform; carries out agentic transactions in Europe

Summary

Visa launched a threat intelligence platform aimed at helping financial institutions detect and respond to cyber threats. It also executed agentic commerce transactions with banks across Europe, testing automated purchase flows driven by AI agents.

Why it matters

As AI-driven payments scale, the winners will be the networks and institutions that can pair automation with provable controls and shared threat intelligence.

10:23 AMPYMNTS

Visa Lets Banks Access Its In-House Cybersecurity Capabilities

Summary

Visa launched the Visa Threat Intelligence Platform to let financial institutions use the same threat detection and cyber defense capabilities Visa uses to protect its own network. The product is positioned to help banks identify cyberthreats earlier and reduce fraud by treating it as a downstream effect of cyber incidents.

Why it matters

If banks can detect intrusions earlier using Visa-grade intelligence, fraud losses and incident costs can move down, and threat intel becomes more centralized around network operators.

Other Developments

A curated list of other prominent stories from this day.

3:47 PMPYMNTS

Sen. Warner Demands DOJ Probe Into Homeland Security Network Breach

Summary

Sen. Mark Warner urged DHS and DOJ to investigate a breach of the Homeland Security Information Network, a platform used for information sharing across law enforcement and private sector partners. The request elevates the incident from an internal security issue to a potential federal investigation.

Why it matters

A breach in a core interagency sharing network can ripple across investigations, partner coordination, and the willingness to share time sensitive threat information.

3:38 PMArs Technica

Newly discovered PamStealer isn't your typical macOS malware

Summary

Researchers identified PamStealer, a macOS infostealer that departs from common Mac malware patterns and focuses on quietly collecting and exfiltrating user data. The tooling and tradecraft point to a rising level of specialization in credential and data theft on Apple endpoints.

Why it matters

As macOS theft malware professionalizes, organizations that under-secure Macs create an easy on-ramp to broader identity and cloud compromise.

7:11 AMSchneier on Security

Cybersecurity Mission Creep in the US

Summary

A paper argues that US policymakers increasingly reframe diverse problems as cybersecurity issues, from misinformation to antitrust and child safety laws. Once reframed as “cybersecuritized,” these issues can be treated as urgent, exceptional threats rather than ordinary policy disputes.

Why it matters

When everything becomes cybersecurity, extraordinary powers become easier to invoke and harder to constrain.

4:02 AMBBC

Alleged Scattered Spider hacker arrested in Finland

Summary

A 19-year-old dual US-Estonian national allegedly linked to the Scattered Spider hacking group was arrested in Finland and extradited to the United States. He now faces federal charges tied to cybercrime activity.

Why it matters

Extradition turns a dispersed hacking collective into an enforceable target and signals fewer safe jurisdictions for high-impact intrusions.

4:00 AMPYMNTS

42% of Issuers Say Fraud and Disputes Are Driving Up Costs

Summary

Card issuers report that fraud and disputes are raising operating costs, with 42% citing them as a significant cost driver. Fraud prevention is shifting from a back-office control to a core part of issuer growth strategy because false declines, failed disputes, and successful scams damage customer relationships.

Why it matters

As fraud economics worsen, issuers will redesign authorization and dispute workflows, reshaping checkout friction, chargeback dynamics, and the cost structure of card programs.

Make it yours

Build Your First Pass.

Pick your topics, set your cadence, and receive your personalized First Pass in your inbox. It’s that simple!