Another day in the wonderful world of cybersecurity where the “latest updates” read like a drinking game. Take a sip every time someone says “timely patching” like it is a weather pattern, not a managerial miracle. By the time you finish your Scotch, you will have lived through the same plot: threat actors exploit the same weaknesses, defenders promise the same improvements, and leadership celebrates the same PowerPoint.
The top story this Tuesday is the FBI arresting the alleged “most wanted” developer behind Ploutus ATM malware. According to reports, Canelon Aguirre was tied to Tren de Aragua’s ATM jackpotting operations and had been on the FBI’s top 10 list since March 2026. In other words: the criminal enterprise built a whole business model around knocking money loose from ATMs, and law enforcement eventually caught up. Small comfort, but hey, it is something.
When your security strategy is “eventually”
Let’s be honest. Real defense is not “someday we will get to it.” It is boring work: hardening endpoints, segmenting networks, monitoring for persistence, and ensuring patching and config management do not fall into the same black hole where incident postmortems go to die. Yet the security culture around us tends to treat controls like decoration.
Look at the rest of the ecosystem reflected in this newsletter: ShinyHunters is blamed on a missed patch by an Accenture contractor, and there are ongoing campaigns like fake ChatGPT/Gemini sites that steal credentials and MFA codes through browser-in-browser attacks. Meanwhile, awareness training still gets funded like it is a magic spell, despite little evidence it stops real social engineering. So yes, arresting a malware developer is important. But it does not undo the underlying system failures that made the malware profitable in the first place.
ATM jackpotting is not “special.” It is just unmanaged risk
Ploutus is just another reminder that “legacy” targets are not legacy because they are obsolete. They are legacy because organizations keep them running while treating them like untouchable sacred artifacts. The controls that would reduce risk are usually the ones people avoid because they disrupt operations, require coordination, or might expose how permissions are currently a mess.
Also, can we stop acting surprised that attackers aim at money-moving systems? ATMs are effectively high-value endpoints with operational constraints and plenty of opportunity for criminals to blend malicious activity into normal traffic. Attackers do not need creativity when defenders have predictability.
For the love of rum: do the basics before the next arrest
If you want your security program to resemble something other than a regret journal, start with control hygiene: patching you can prove, least privilege you can measure, MFA you can actually trust, and monitoring that tells you what is happening before attackers get rich. And if your organization is still relying on “awareness training” as the primary control, pour the drink you are saving for after the next breach. You are going to need it.
Read the original story here: FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware.