:

TORONTO POLICE BUST SMS BLASTER CREW

INDUSTRY DESK1 MIN READ
FRI, MAY 8, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Toronto police arrested a group operating an SMS blaster that sent malicious messages to thousands of residents. The service marks the first known instance of this attack method used in Canada.

The crew used automated software to distribute text messages at scale, reaching thousands across the Greater Toronto Area. Authorities have not yet disclosed the nature of the messages or their intended targets. SMS blasters are tools that send bulk text messages, often used for phishing scams, malware distribution, or fraudulent schemes. The technology has been prevalent in other countries but remained relatively rare in Canadian criminal operations until now. The arrest follows an investigation into the unauthorized messaging campaign. Police did not release details about the suspects or the specific charges filed. The case highlights growing concerns over SMS-based attacks targeting mobile users. Security experts have warned that text messages remain a vulnerable vector for social engineering and fraud, partly because users trust SMS more than email.

■ SOURCES

TechCrunch

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Attackers are actively exploiting a critical authentication bypass vulnerability in Citrix NetScaler, according to Previdian. CVE-2026-19490 allows threat actors to circumvent security controls on the widely-deployed application delivery platform.

1H AGOIndustry Desk

A researcher known as Nightmare Eclipse has disclosed a CrowdStrike Falcon zero-day exploit called FalconFlank that enables privilege escalation on fully patched Windows systems. The vulnerability affects the widely-deployed endpoint protection software.

3H AGOSecurity Desk

The U.S. military has disabled ad tracking on service members' devices after foreign adversaries exploited location data to target troops. A senator's letter confirms the action was taken in response to security threats.

3H AGOIndustry Desk

Google has released an emergency update for Chrome to fix a high-severity zero-day vulnerability in the V8 engine currently being exploited in attacks. The update addresses this flaw plus 11 additional vulnerabilities.

5H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.