Urgent.News

What's breaking now, across thousands of outlets.

Tech

Microsoft, Google took down $66 million cybercrime marketplace that sold virtual machines with free software

Effort takes down RedVDS, a criminal marketplace believed to have contributed to $66 million losses to US businesses and individuals.

Microsoft, Google took down $66 million cybercrime marketplace that sold virtual machines with free software

Microsoft and Google collaborated via the Global Signal Exchange (GSE) to dismantle a $66 million cybercrime marketplace known as RedVDS. The marketplace sold virtual machines preloaded with unlicensed software, which cybercriminals used to launch phishing, business email compromise, and other attacks. The GSE, a UK-based non-profit co-founded by Google in 2025, facilitated real-time monitoring of the cybercrime supply chain.

Microsoft's Digital Crimes Unit and Google's threat detection systems identified the RedVDS marketplace, leading to the seizure of its web domains and servers in the UK and US. Europol also took action against Europe-based RedVDS servers. The operation targeted 130,000 organizations and compromised 191,000 Microsoft email accounts during September-December 2025.

Both Microsoft and Google plan to continue sharing threat data through the GSE, highlighting the importance of collaborative efforts in combating cybercrime.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at techradar.com →

More in Tech

Custom Password Reset API Selection for Auth Systems Without Webhooks

The most important trade-off is evidence versus coupling: for password recovery and settled-order receipts, choose an email API that lets your application record a durable submission result and later…

  • Store unique message key and remote message identifier for password resets and order receipts.
  • Poll for unresolved messages and avoid storing raw reset tokens in logs.

NetScaler and the SAML Bypass: Measuring Gateway Exposure with ZoomEye

NetScaler and the SAML Bypass: Measuring Gateway Exposure with ZoomEye Authentication gateways occupy a structurally difficult position in security architecture.

  • Citrix NetScaler ADC and Gateway are critical authentication gateways.
  • CVE-2026-19490 is a SAML authentication bypass vulnerability.
  • ZoomEye measures hundreds of thousands of affected NetScaler instances.

Keep the Score Contract Out of the Agent's Write Set

A green CI job on an agent branch is not a score. It is a claim that the tree the agent left behind still exits zero. Those claims diverge as soon as the agent can delete tests, rewrite goldens, skip…

  • Contract file must bind testing process aspects
  • Include parent SHA, fixture hashes, runner config hashes
  • Contract generated from parent commit, not agent's branch

More from Monday 21 September →