<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-AU"
                       href="https://www.techradar.com/au/feeds/tag/computing-security"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from TechRadar AU in Computing-security ]]></title>
                <link>https://www.techradar.com/au/computing/computing-security</link>
        <description><![CDATA[ All the latest computing-security content from the TechRadar  AU team ]]></description>
                                    <lastBuildDate>Mon, 20 Jul 2026 16:05:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ 'This one was different from anything we had handled before': Hugging Face confirms it was hit by cyberattack powered by an AI agent ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/this-one-was-different-from-anything-we-had-handled-before-hugging-face-confirms-it-was-hit-by-cyberattack-powered-by-an-ai-agent</link>
                                                                            <description>
                            <![CDATA[ There's a new twist to the old code injection attack, and this one comes with AI seasoning. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">YGS9VwWfcoup7Aym62fv9a</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Jul 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:description>                                                            <media:text><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Hugging Face discloses cyberattack where malicious code hidden in a dataset exploited flaws in its systems, enabling privilege escalation and credential theft</strong></li><li><strong>The incident was unique in being orchestrated end‑to‑end by an autonomous AI agent, which launched thousands of short‑lived sandboxes and migrated C2 infrastructure across public services</strong></li><li><strong>No customer data or public models were tampered with, but the attack highlights the emerging “agentic attacker” scenario long predicted by the industry</strong></li></ul><p>Hugging Face, one of the biggest platforms for artificial intelligence (AI) and machine learning (ML), disclosed recently suffering a cyberattack supercharged by an AI agent.</p><p>“This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system - and we detected and dissected it largely with AI of our own,” Hugging Face explained in its <a href="https://huggingface.co/blog/security-incident-july-2026" target="_blank" rel="nofollow">announcement</a>, noting that the attackers hid malicious code inside a dataset, which they then uploaded to the platform. </p><p>When Hugging Face’s automated systems processed that dataset, they exploited two software flaws which allowed the attackers’ code to run on one of the company’s servers.</p><h2 id="orchestrated-by-an-autonomous-ai-agent">Orchestrated by an autonomous AI agent</h2><p>This twist to the classic code injection attack allowed the attackers to expand their privileges and gain more control over the system, steal authentication credentials to access Hugging Face’s cloud infrastructure, and pivot to other internal systems. </p><p>But carrying the attack out mostly with an AI agent is what made this incident unique, Hugging Face explained. </p><p>Instead of a human threat actor typing commands, Hugging Face believes the attack was orchestrated by an AI-powered autonomous agent which, entirely on its own, decided which systems to probe, which vulnerabilities to exploit, which credentials to steal, and how to move laterally throughout the compromised infrastructure. </p><p>“The campaign was run by an autonomous agent framework (appearing to be built on an agentic security-research harness - used LLM still not known) executing many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services,” Hugging Face explained. “This matches the "agentic attacker" scenario the industry has been forecasting.”</p><p>In other words, the agent kept launching thousands of temporary computing environments, making it extremely hard to stop the attack (since there isn’t a single machine to block). At the same time, the infrastructure controlling the malware kept moving, likely by using legitimate public cloud or online services. Therefore, when the defenders blocked one control server, the attacks would simply come from another. </p><p>Currently there is no evidence of tampering with customer data, public user-facing models, or Spaces.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Colombian energy giant Ecopetrol says thousands of user accounts hit in cyberattack ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/colombian-energy-giant-ecopetrol-says-thousands-of-user-accounts-hit-in-cyberattack</link>
                                                                            <description>
                            <![CDATA[ The Ecopetrol attackers demanded a ransom payment but did not deploy an encryptor. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tCkHsH74JScubYSNL54dfU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Jul 2026 14:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:description>                                                            <media:text><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:text>
                                <media:title type="plain"><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Ecopetrol confirms ransomware attempt in which attackers stole data from 3,300 user accounts but failed to deploy the encryptor due to security controls</strong></li><li><strong>Stolen files were pseudonymous, with no user identities or credentials compromised; transactional systems and partner networks remained unaffected</strong></li><li><strong>The company ousted the attackers, launched an investigation, and notified Colombian authorities; no ransom demand details or data leaks have surfaced so far</strong></li></ul><p>Latin American energy producer Ecopetrol has revealed it was victim of a ransomware attack, and while the threat actors managed to get away with sensitive data from thousands of user accounts, they were unable to deploy the encryptor and thus disrupt the company’s day-to-day operations.</p><p>In a statement shared with the public, Ecopetrol explained how an unidentified threat actor accessed their IT infrastructure and pulled data from 3,300 user accounts. The attacker then proceeded to install an encryptor but was stopped by the company’s security controls. </p><p>Despite failing to deploy the encryptor, the threat actor still reached out to the company demanding payment. We don’t know how much money they asked for, in exchange for not sharing the stolen files. The database has not yet leaked, it seems, and no one claimed responsibility for the intrusion. At the same time, Ecopetrol says the stolen files are pseudonymous, suggesting that they might not be particularly useful to the attackers: </p><h2 id="notifying-the-authorities">Notifying the authorities</h2><p>“The identity of the users of the 3,300 accounts that were illegally infiltrated was not affected, nor were the respective user access credentials captured,” the machine-translated announcement reads. “Ecopetrol S.A. confirms that no compromises have been identified in the transactional technological solutions of its digital ecosystem, those of its subsidiaries, or those of its network of commercial allies, financiers, providers, and clients.”</p><p>Ecopetrol said that it managed to oust the attackers and stop further data exfiltration. It also launched an internal investigation and notified relevant authorities, including the Colombian Attorney General’s Office, the Joint Cyber Command of the Military Forces, and others. </p><p>The investigation remains ongoing.</p><p>Ecopetrol is Colombia's state-controlled oil and gas giant. It runs production, refining, transportation, and exploration operations, and is present in multiple countries, including Chile, Peru, and Bolivia. Its annual revenue is around $30 billion.</p><p><em>Via </em><a href="https://cybernews.com/news/ecopetrol-hack-colombia-ransom/" target="_blank"><em>Cybernews</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ransomware attacks hit SMBs harder than ever as cybercrime gang rivalry heats up ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/ransomware-attacks-hit-smbs-harder-than-ever-as-cybercrime-gang-rivalry-heats-up</link>
                                                                            <description>
                            <![CDATA[ Qilin and The Gentlemen are going at it, at the expense of SMBs facing more attacks than ever. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KKX2w2hiPFkYjNm9d5Yc7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/H6MfM7T3bjECJuLWR6mD5a-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Jul 2026 12:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/H6MfM7T3bjECJuLWR6mD5a-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/H6MfM7T3bjECJuLWR6mD5a-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>NordStellar reports 2,581 ransomware attacks in Q2 2026, with Qilin (299) and The Gentlemen (284) leading activity, far ahead of DragonForce (147)</strong></li><li><strong>US SMBs were hit hardest, suffering 769 incidents; Canada (97), Germany (83), and the UK (74) followed, while attacks on billion‑dollar enterprises surged 74%</strong></li><li><strong>Experts say rivalry between Qilin and The Gentlemen is driving the spike, with major corporate hits seen as reputation‑boosting trophies in the cybercriminal underground</strong></li></ul><p>Two ransomware gangs are battling for dominance, and US-based SMBs are the ones suffering most for it, experts have claimed.</p><p>Fresh data about the state of ransomware in 2026, compiled by security experts from NordStellar, shows two groups - Qilin and The Gentlemen - being by far the most active ones. </p><p>After analyzing more than 200 threat actor blogs, NordStellar concluded that there were 2,581 <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> attacks in the second quarter of the year - and of that number, 299 belong to Qilin, the most active threat actor out there. Close second are The Gentlemen, with 284 attacks. The third most active group - DragonForce - doesn’t even come close with “just” 147 attacks.</p><h2 id="smbs-and-enterprises-under-assault">SMBs and enterprises under assault</h2><p>While it seems like a close race, it’s actually The Gentlemen who have been doing the heavy lifting between April and June 2026. This group experienced a 39% increase in attacks, while Qilin’s activity actually declined somewhat, compared to Q1.</p><p>In this morbid race to the bottom, the biggest victims are US-based small and medium-sized businesses (SMB). These companies, with up to 200 employees and revenues under $25 million, experienced 769 attacks in Q2 2026, followed by Canada (97), Germany (83), and the UK (74). </p><p>NordStellar also mentioned US enterprises, who are now increasingly being targeted. Attacks against organizations with revenues north of $1 billion surged by 74%, going from 23 incidents in Q1, to 40 in Q2. </p><p>“Ransomware actors historically target SMBs because these organizations often lack comprehensive defenses, which can increase the likelihood of a successful attack,” commented Vakaris Noreika, cybersecurity expert at NordStellar. </p><p>“This recent spike in enterprise targeting is unusual and may be a temporary fluctuation. This shift likely stems from the rivalry between dominant threat actors — a successful hit on a major corporation is a badge of honor that boosts a group’s reputation within the cybercriminal underground."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ernst & Young reveals data breach following hack on support system ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/ernst-and-young-reveals-data-breach-following-hack-on-support-system</link>
                                                                            <description>
                            <![CDATA[ Someone pulled sensitive customer data from EY's servers, but the data is yet to surface anywhere. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cP6va4FhPF6yEA9zg8rxz4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GJ8T4oA8G7TYJwTEhkwJAF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Jul 2026 11:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GJ8T4oA8G7TYJwTEhkwJAF-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image Credit: Pixabay]]></media:description>                                                            <media:text><![CDATA[Representational image of a cybercriminal]]></media:text>
                                <media:title type="plain"><![CDATA[Representational image of a cybercriminal]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GJ8T4oA8G7TYJwTEhkwJAF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Ernst & Young confirms breach via a third‑party IT service management platform, exposing client tax data between March 28 and April 12, 2026</strong></li><li><strong>Attackers accessed documents tied to tax support tickets; exact scope and affected clients remain undisclosed, with no dark web leaks or group claims so far</strong></li><li><strong>EY activated incident response, secured systems, and is offering 24 months of Experian identity monitoring to impacted customers</strong></li></ul><p>Ernst & Young (EY) has confirmed suffering a cyberattack in which it lost sensitive customer information, including tax data.</p><p>In a data breach notification letter sent to affected individuals, the firm said that on April 23, 2026, it spotted “anomalous activity” within a third-party platform its IT team uses. This is an IT service management platform that helps EY staff support the teams that perform tax-related work for clients. Therefore, the tickets submitted through this platform sometimes also contain documents with client tax information which may have been exposed in the incident.</p><p>EY then activated its incident response protocols, bringing in third-party cybersecurity experts, as well as notifying relevant authorities and affected clients. </p><h2 id="free-identity-theft-protection">Free identity theft protection</h2><p>Further investigation determined that the unnamed threat actors broke in on March 28, 2026 and have, until April 12, been exfiltrating the files. EY did not say exactly which information was pulled, or how many clients were affected. We also don’t know if this only pertains to US clients, or overseas ones, as well. The attackers have, since then, been removed from EY’s virtual premises, and the systems have been secured, the company confirmed. </p><p>So far, no hacking groups claimed responsibility for this attack, and the data is yet to surface anywhere on the dark web. EY’s customers should be on the lookout for unsolicited emails, especially those claiming to be from the professional services giant. </p><p>To help them stay secure, EY is offering 24 months of <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">free identity monitoring</a> and restoration services through Experian. </p><p>Ernst & Young is one of the "Big Four" largest professional services and accounting networks in the world. It is headquartered in London, but operates as a global network of independent members spanning more than 150 countries and employing more than 400,000 people. The company’s core business includes assurance, tax, consulting, and M&A strategy.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/ernst-and-young-discloses-data-breach-after-support-system-hack/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'The bypass is still six lines of JavaScript': Security experts warn that Claude for Chrome browser extension could be hijacked, despite it alerting Anthropic several times that something was wrong ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/the-bypass-is-still-six-lines-of-javascript-security-experts-warn-that-claude-for-chrome-browser-extension-could-be-hijacked-despite-it-alerting-anthropic-several-times-that-something-was-wrong</link>
                                                                            <description>
                            <![CDATA[ Researchers found Claude’s Chrome extension still contains vulnerabilities allowing fake clicks and permission bypasses despite Anthropic releasing multiple updates. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MgcPS4oDejjXRzT9jygM9c</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hkechUkk5KHAbcMTCNVxG4-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Sun, 19 Jul 2026 18:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Claude]]></category>
                                                    <category><![CDATA[AI Platforms &amp; Assistants]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/hkechUkk5KHAbcMTCNVxG4-1280-80.png">
                                                            <media:credit><![CDATA[Anthropic]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Claude Chrome]]></media:description>                                                            <media:text><![CDATA[Claude Chrome]]></media:text>
                                <media:title type="plain"><![CDATA[Claude Chrome]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hkechUkk5KHAbcMTCNVxG4-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Anthropic’s Claude extension flaws allow fake clicks to launch sensitive AI workflows</strong></li><li><strong>Researchers found vulnerable handlers unchanged across eight extension updates</strong></li><li><strong>Synthetic clicks bypassed checks designed to confirm real user actions</strong></li></ul><p>Security researchers at Manifold Security have claimed Anthropic's Claude for <a href="https://www.techradar.com/computing/chrome/these-are-the-10-best-chrome-extensions-of-2025-according-to-google-and-theres-one-i-definitely-recommend">Chrome browser extension</a> contains two unpatched vulnerabilities in version 1.0.80, released July 7, 2026.</p><p>According to <a href="https://www.manifold.security/blog/claude-for-chrome-extension-bypass">Manifold Security</a>, it first reported both vulnerabilities to Anthropic through the company's bug bounty program on May 21, 2026, and received acknowledgment the following day.</p><p>The first flaw lets any browser extension trigger nine predefined Claude workflows by simulating a synthetic user click on claude.ai.</p><h2 id="nine-workflows-and-one-missing-check">Nine workflows and one missing check</h2><p>Researcher Ax Sharma found that the extension never verified whether a click event carried the Event.isTrusted property before acting on it.</p><p>Under default settings, the vulnerability received a CVSS score of 7.7 High, increasing to 9.6 Critical when users enabled automatic execution because Claude could perform actions without approval.</p><p>The nine hardcoded tasks include reading Gmail, opening Google Docs, checking Google Calendar, and modifying Salesforce leads without asking.</p><p>Because the <a href="https://www.techradar.com/best/browser">browser</a> marks synthetic clicks as untrusted, the extension should have rejected them but instead executed the workflow anyway.</p><p>Manifold Security confirmed on July 7 2026 that both vulnerabilities still work against version 1.0.80, months after first reporting them to Anthropic.</p><p>Anthropic released eight separate versions between 1.0.73 and 1.0.80 without altering the specific handlers’ researchers had already flagged as vulnerable.</p><p>The company closed the synthetic-click report, saying an existing internal report already tracked the broader trust-boundary issue researchers had described in detail.</p><p>However, Sharma believes the fix required only one additional line of code to verify the click event's isTrusted property before allowing the workflow to continue.</p><h2 id="a-second-structural-weakness">A second, structural weakness</h2><p>A second flaw involves a side-panel URL parameter called skipPermissions, which can activate a privileged mode without any consent prompt.</p><p>When the parameter is set to true, the panel begins skipping permission checks entirely, allowing Claude to act without asking the user first.</p><p>Manifold notes that only Anthropic's own scheduled-task feature is supposed to construct this kind of privileged URL internally right now.</p><p>The panel, however, honours that parameter regardless of which script or page actually constructed the originating URL string in practice.</p><p>One example task lets Claude read a user's Gmail inbox, identify promotional messages, and automatically click the unsubscribe links inside them.</p><p>Manifold warns that "the bypass is still six lines of JavaScript," months after researchers first flagged the underlying issue to Anthropic.</p><p>Anthropic classified this second finding as informational, arguing that the parameter is only ever constructed by its own internal systems.</p><p>Manifold said the content-script and side-panel code linked to both vulnerabilities remained byte-identical across the eight subsequent extension releases examined after the original report.</p><p>The flaws were also reproduced across Claude's Opus, Sonnet, and Fable side-panel model selections, indicating that the issue affected the extension's security design rather than the underlying artificial intelligence models.</p><p>The report also connected the findings with OWASP concerns involving LLM01: Prompt Injection and LLM06: Excessive Agency risks in AI applications.</p><p>The researchers noted that abuse involving <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> may remain difficult to detect because normal browser activity and network connections can appear unchanged while unauthorized AI actions occur.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'macOS users may face real, sophisticated threats that require neither exploits nor any elevated access to succeed': ClickLock Stealer tries to trick Apple users into revealing their passwords ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/macos-users-may-face-real-sophisticated-threats-that-require-neither-exploits-nor-any-elevated-access-to-succeed-clicklock-stealer-tries-to-trick-apple-users-into-revealing-their-passwords</link>
                                                                            <description>
                            <![CDATA[ ClickLock bores its victims into complying and then steals all sorts of data. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rTfuMcJQcWwgFKNJxEtbqi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[hacker hands at work with  interface around]]></media:description>                                                            <media:text><![CDATA[hacker hands at work with  interface around]]></media:text>
                                <media:title type="plain"><![CDATA[hacker hands at work with  interface around]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Group‑IB uncovers ClickLock, a new macOS‑focused infostealer using aggressive social engineering by spamming password prompts and terminating key apps every 210ms until victims comply</strong></li><li><strong>Once credentials are obtained, it exfiltrates browser data, crypto wallets, password manager entries, FTP configs, and device info via Telegram Bot API</strong></li><li><strong>Active since May 2026, spotted in 33 countries (mostly Europe), distributed via ClickFix campaigns, and initially undetected by security vendors until recently</strong></li></ul><p>Security researchers from Group-IB have uncovered a new infostealer targeting primarily macOS users in Europe.</p><p>Dubbed <a href="https://www.group-ib.com/blog/clicklock-stealer-macos-malware/" target="_blank">ClickLock</a>, it is more of an annoying social engineering mechanism rather than a full-blown malware variant, constantly popping up a login prompt on the victim’s device, until they finally comply and share the credentials. </p><p>Every 210 milliseconds it terminates key apps on the device (Finder, Dock, TErminal, etc.), essentially making it useless. At the same time, it keeps prompting a password dialog on the screen, making sure the victim can do nothing but provide the credentials.</p><h2 id="targeting-europeans">Targeting Europeans</h2><p>The loop is set to continue for more than three straight days, or until the victim folds. </p><p>After getting the keys to the kingdom, the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> gets to work and starts exfiltrating valuable information.</p><p>This includes data from key <a href="https://www.techradar.com/best/browser" target="_blank">browsers</a> (Chrome, Firefox, Brave, and others), saved logins, cookies, autofill data, and other browser information, data linked to cryptocurrency wallets and extensions, encrypted wallet vault material that can be cracked off-site, data from <a href="https://www.techradar.com/best/password-manager" target="_blank">password managers</a>, cached cryptocurrency addresses across EVM, Bitcoin, Solana, TRON, TON, and Stacks, shell histories, FileZilla FTP configuration and recent-server data, and basic device information.Everything is then packaged into a .ZIP archive and exfiltrated via a Telegram Bot API.</p><p>Group-IB says the campaign has been active since at least May 2026, so it’s been active for a few months now. A researcher submitted a variant to VirusTotal in early June, but it remained undetected by all security vendors until recently, Group-IB says.</p><p>So far, it has been spotted in 33 countries, more than half of which are in Europe, it was also added. The malware is most likely being distributed via a ClickFix social engineering campaign, and has not been tied to any particular threat actor. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Dangerous new GoSerpent malware is apparently on the hunt for government secrets ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/dangerous-new-goserpent-malware-is-apparently-on-the-hunt-for-government-secrets</link>
                                                                            <description>
                            <![CDATA[ The malware has been hiding in plain sight for half a decade, stealing all sorts of valuable secrets. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vjht9Nb5f4HTL3RNE3U26G</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NGKiUcJVFBC8HkMp9dTo9a-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NGKiUcJVFBC8HkMp9dTo9a-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.]]></media:description>                                                            <media:text><![CDATA[A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.]]></media:text>
                                <media:title type="plain"><![CDATA[A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NGKiUcJVFBC8HkMp9dTo9a-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Kaspersky uncovers GoSerpent, a long‑running campaign on Southeast Asian government systems using a backdoor, RAT (Stowaway), and exfiltration tool (TmcLoader)</strong></li><li><strong>Attackers showed extreme patience, waiting weeks before deploying secondary tools to evade detection and outlast log retention policies</strong></li><li><strong>Attribution remains uncertain, but overlaps with past TetrisPhantom operations; defenders are urged to review shared IoCs to detect compromise</strong></li></ul><p>Security researchers Kaspersky discovered a five-year-old piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> that’s been hiding on government computers in the Southeast Asian region, harvesting secrets and other actionable intelligence.</p><p>The company analyzed a campaign called GoSerpent, which comprises of a backdoor of the same name, a Remote Access Trojan (RAT) called Stowaway, and a two-stage data exfiltration tool called TmcLoader.</p><p>The backdoor was first used in 2021, it was said, meaning it was successfully hiding for half a decade. This was achieved, among other things, with plenty of patience and careful planning.</p><h2 id="tetrisphantom">TetrisPhantom</h2><p>“What stands out about GoSerpent is the deliberate dwell time,” Noushin Shabab, Lead Security Researcher in Kaspersky GReAT, explained. </p><p>“Usually, attackers want to move quickly once they get a foothold, but this group drops the initial backdoor and waits. They let the dust settle for weeks before deploying their secondary exfiltration tools like TmcLoader. That kind of patience is a calculated move designed to outlast standard log retention policies and automated security sweeps, making it incredibly difficult for defenders to connect the initial infection to the eventual data theft." </p><p>The researchers could not conclusively attribute this campaign to any particular threat actor but did say that it has a lot in common with older campaigns conducted by the TetrisPhantom actor, including victimology, technical capabilities, and operational methods. </p><p>Kaspersky analyzed TetrisPhantom back in 2023, when it saw the group compromising <a href="https://www.techradar.com/pro/security/dangerous-new-malware-can-crack-encrypted-usb-drives" target="_blank">secure USB drives</a> used to provide encryption for safe data storage. This campaign also targeted government entities in the Asia-Pacific region (APAC) but, at the time, it was a newly discovered threat actor with no overlap with other known groups. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US sanctions on rogue VPN accidentally break Telegram's short links worldwide ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/vpn/vpn-privacy-security/us-sanctions-on-rogue-vpn-accidentally-break-telegrams-short-links-worldwide</link>
                                                                            <description>
                            <![CDATA[ Telegram’s t.me domain was swept up in a global outage following US Treasury sanctions against First VPN services, causing millions of web links to break worldwide. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4P42CJuXVG9W8YZrgU7CEJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Zcpy2igVUaP9YqtCiCVXaE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 14:43:57 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[VPN Privacy &amp; Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Milman ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Zcpy2igVUaP9YqtCiCVXaE-1280-80.jpg">
                                                            <media:credit><![CDATA[Photo by Jaque Silva/NurPhoto via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Telegram logo appears on the screen of a smartphone that rests on top of a laptop keyboard]]></media:description>                                                            <media:text><![CDATA[The Telegram logo appears on the screen of a smartphone that rests on top of a laptop keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[The Telegram logo appears on the screen of a smartphone that rests on top of a laptop keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Zcpy2igVUaP9YqtCiCVXaE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>The US Treasury sanctioned First VPN Service for aiding ransomware gangs</strong></li><li><strong>Complying with the sanctions, the .ME registry wrongly suspended Telegram's entire t.me domain</strong></li><li><strong>The domain was restored roughly 19 hours later after Telegram CEO Pavel Durov flagged the issue online</strong></li></ul><p>If you clicked a Telegram link on Monday and stared at a blank screen, you weren't alone. Every shortlink starting with 't.me' suddenly vanished from the global internet, breaking group invites, profile shares, and channel links for roughly a billion users worldwide.</p><p>But the outage wasn't caused by a technical glitch or a targeted cyberattack. Instead, it was the unintended collateral damage of a US government crackdown on a cybercriminal proxy network.</p><p>On July 13, the US Treasury Department's Office of Foreign Assets Control (OFAC) <a href="https://www.techradar.com/vpn/vpn-privacy-security/first-vpn-administrators-sanctioned-by-us-treasury-over-ransomware-attacks">sanctioned the administrators of a rogue proxy network</a> called First VPN Service (1VPNS), aiming to cut off infrastructure used by ransomware operators. </p><p>While anyone shopping for the <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> expects privacy, First VPN actively courted cybercriminals with promises of total anonymity, leading <a href="https://www.techradar.com/vpn/vpn-privacy-security/european-law-enforcement-forces-pull-the-plug-on-this-free-vpn-in-massive-cybercrime-crackdown-heres-all-we-know">European law enforcement to pull the plug on the service</a> earlier in May.</p><p>As part of the new sanctions, the US Treasury published a list of web addresses associated with the VPN. Buried in that list was a link to First VPN's public Telegram support channel: t.me/FirstVPNService.</p><h2 id="a-sledgehammer-to-crack-a-nut">A sledgehammer to crack a nut</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qp6PFkub49CUBhgFaHwjeQ" name="First VPN" alt="This photograph shows a laptop screen displaying the website of Europol featuring the First VPN service website with a message reading, "This service has been seized"" src="https://cdn.mos.cms.futurecdn.net/qp6PFkub49CUBhgFaHwjeQ.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Photo by Fred TANNEAU / AFP via Getty Images)</span></figcaption></figure><p>Because top-level domains operate under strict international compliance rules, domain registrars must act quickly when sanctioned entities use their infrastructure.</p><p>Identity Digital, the company managing the technical backend for the .me domain, <a href="https://meduza.io/en/news/2026/07/14/u-s-treasury-sanctions-on-a-vpn-service-knocked-out-telegram-s-short-link-domain-worldwide" target="_blank" rel="nofollow">confirmed that the t.me domain had been blocked</a> at the request of OFAC. </p><p>However, because a domain registry cannot selectively disable a specific webpage or channel path — like a single Telegram group — the Montenegro-based registry Domain.Me applied a "serverHold" status to Telegram's entire t.me domain.</p><p>This sweeping action effectively erased the domain from the global <a href="https://www.techradar.com/vpn/what-is-dns">Domain Name System (DNS)</a>. The core Telegram app continued to function, and the older telegram.me domain remained active, but the shortlinks the messaging platform is built upon went entirely dark.</p><h2 id="the-swift-resolution">The swift resolution</h2><p>The sudden shutdown prompted immediate action from Telegram's leadership. </p><p>Unaware of the backend domain hold, Telegram CEO Pavel Durov <a href="https://x.com/durov/status/2076836338117046660" target="_blank" rel="nofollow">took to X</a> to publicly ask the registrar for an explanation: "Hey @domainME, t.me links stopped working. Can you look into it?"</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr">Hey @domainME, https://t.co/9z6UC2o37U links stopped working. Can you look into it? 🙏<a href="https://twitter.com/cantworkitout/status/2076836338117046660">July 14, 2026</a></p></blockquote><div class="see-more__filter"></div></div><p>Once the sanctions issue was identified, Telegram scrubbed the offending channels from its platform. The registry operator subsequently verified the compliance and brought the domain back online.</p><p>"On 13 July, 1VPNS was included as a sanctioned entity by the US Department of the Treasury. A Telegram channel using the t.me domain was among 1VPNS identified infrastructure. Accordingly, the t.me domain was suspended," domain.Me confirmed in a <a href="https://x.com/domainme/status/2077077395777994942" target="_blank" rel="nofollow">statement<u> </u></a>following the outage.</p><p>The registrar clarified that normal service resumed roughly a day later, after Telegram provided confirmation that it had removed its links and affiliations with 1VPNS. "We appreciate Telegram's prompt cooperation in resolving this matter," domain.Me added.</p><p>While the outage is now resolved, the incident highlights a glaring vulnerability in the modern web, where a single URL swept up in a government sanctions list can inadvertently silence an essential communication channel for millions.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Claude can now enter all your passwords for you - if you give it permission ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/claude-can-now-enter-all-your-passwords-for-you-if-you-give-it-permission</link>
                                                                            <description>
                            <![CDATA[ 1Password partnership will mean Claude will never see the secrets or load them into its own memory. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gESvv4V9PcQSPAyMJnfqm6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9YhV9JTvHHHB3MMDhxYpoj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 14:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9YhV9JTvHHHB3MMDhxYpoj-1280-80.jpg">
                                                            <media:credit><![CDATA[Anthropic]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Mobile phone displaying a Claude login screen.]]></media:description>                                                            <media:text><![CDATA[Mobile phone displaying a Claude login screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Mobile phone displaying a Claude login screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9YhV9JTvHHHB3MMDhxYpoj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>1Password unveils Claude partnership, letting Anthropic’s AI authenticate on users’ behalf via zero‑exposure architecture</strong></li><li><strong>Users approve each login with biometrics</strong></li><li><strong>New Agentic Mode in the browser extension locks down the interface when AI agents take over</strong></li></ul><p>Top <a href="https://www.techradar.com/best/password-manager" target="_blank">password manager</a> company 1Password has launched a new tool that allows artificial intelligence assistant Claude to authenticate on behalf of their user, and thus complete assignments that were previously impossible without major security tradeoffs.</p><p><a href="https://1password.com/blog/1password-for-claude" target="_blank" rel="nofollow">1Password for Claude</a> is built on “zero-exposure architecture” - so in practice, it means Claude can essentially ask 1Password to complete the sign-in process, but it will never see the credentials, and they will never be loaded into its memory. </p><p>In turn, 1Password will notify the user, and will request biometric approval before proceeding. Once granted, it will autofill the credentials and check to see if they were exposed on the page or not. If submission fails, it will clear the filled values and report back. </p><h2 id="agentic-mode">Agentic Mode</h2><p>"We need a new security model that is purpose-built for agents, not just humans,” said Nancy Wang, CTO of 1Password. “The answer isn't handing agents your secrets. It is to let a user give an agent permission to use a credential without letting the agent see it. Claude knows it used your login; it does not need the password or one-time code in its context. That distinction is where trust in agents starts and the foundation we're building with Anthropic."</p><p>To further strengthen its security posture, 1Password also announced Agentic Mode, a new feature in the browser extension that gives users visibility and control over browser-based <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agents</a>. When a compatible AI agent takes over, the 1Password extension automatically locks down and hides the interface. The agent can only use the logins and OTPs explicitly approved for the current task. </p><p>Even if the integration is not set up, and even if 1Password is not required for the current agentic task, Agentic Mode works, the company stressed. Other agents, besides Claude, are supported, as well. </p><p>Currently a major debate is ongoing, about how much permissions AI agents should receive, and under what rules. We’ve already seen horror stories of AI agents deleting people’s entire email inboxes, or otherwise ruining days of hard work. Whether or not this picks up or most people remain skeptical about giving AI access to certain services, remains to be seen. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Coca-Cola shuts down Fairlife dairy production lines following ransomware attack ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/coca-cola-shuts-down-fairlife-dairy-production-lines-following-ransomware-attack</link>
                                                                            <description>
                            <![CDATA[ Coca-Cola confirms ransomware attack on Fairlife in an 8-K form filed with the SEC. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">98MXZYAA7TvT8EPNELLnKY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SPwVn22r6XRNTeSZsKjoTB-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/SPwVn22r6XRNTeSZsKjoTB-1280-80.png">
                                                            <media:credit><![CDATA[Coca-Cola]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI squirrels look at Coca-Cola trucks]]></media:description>                                                            <media:text><![CDATA[AI squirrels look at Coca-Cola trucks]]></media:text>
                                <media:title type="plain"><![CDATA[AI squirrels look at Coca-Cola trucks]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SPwVn22r6XRNTeSZsKjoTB-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Coca‑Cola confirmed a ransomware attack on its dairy subsidiary Fairlife, forcing suspension of US production operations while Canada sites remain unaffected</strong></li><li><strong>Incident response protocols were activated, with third‑party experts and authorities engaged; product quality and safety were not impacted</strong></li><li><strong>Analysts warn the financial impact could be significant given Fairlife’s importance, with losses compounding the longer production remains offline</strong></li></ul><p>Coca Cola was forced to shut down parts of its operations to tackle an ongoing ransomware infection.</p><p>In an 8-K form recently filed with the US Securities and Exchange Commission (SEC), the company said the attackers struck Fairlife, its dairy company.</p><p>“On July 16, 2026, The Coca-Cola Company announced that fairlife, a dairy company owned by the company, identified unauthorized access by a third party to a portion of its systems, including its production-related systems, in connection with a <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> event,” the filing reads.</p><h2 id="compounding-impact">Compounding impact</h2><p>Coca Cola then explained that it kicked off its incident response and business continuity protocols, bringing in third-party cybersecurity experts to help investigate the attack and assess the damages. It also notified relevant authorities.</p><p>However, the production in the US has been affected, since parts of the operation had to be suspended: “Product quality and safety have not been impacted. However, as a result of the incident, production operations at fairlife in the United States are temporarily suspended. fairlife’s Canada production operations are not currently impacted,” Coca Cola explained.</p><p>It said it was now working to bring the systems back up, and that it has “not yet determined whether the incident is reasonably likely to materially affect the company.”</p><p>In a statement shared with TechRadar Pro, Cybersecurity Researcher and Advanced Services Lead at Arcova, Joseph Perry, stressed that the material impact is likely to be great. How great - depends on how fast Coca Cola moves. </p><p>“Fairlife is not a minor business buried inside Coca-Cola’s portfolio. Coca-Cola generated nearly $48 billion in net revenue last year and made a $6.1 billion contingent payment tied to its acquisition of fairlife, which provides important context for the value of the operation now sitting idle,” Perry explains. </p><p>“With production suspended across fairlife’s US facilities, every hour can compound the financial impact through lost output, delayed shipments, recovery costs, inventory exposure and potential disruption for retailers. Coca-Cola has not yet quantified the loss, but the longer production remains offline, the more quickly a cyber incident becomes a material business event.”</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/coca-cola-says-fairlife-ransomware-attack-halts-us-dairy-production/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Teenage TfL hackers sentenced to years in prison following Scattered Spider attacks ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/teenage-tfl-hackers-sentenced-to-years-in-prison-following-scattered-spider-attacks</link>
                                                                            <description>
                            <![CDATA[ Two young men pleaded guilty to hacking into Transport for London in 2024 and were given long prison sentences. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SLBSG4pbDpZE9xtCXUuJpP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7DtE9RCVmUtmH2FAfvxsvM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 11:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7DtE9RCVmUtmH2FAfvxsvM-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:description>                                                            <media:text><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:text>
                                <media:title type="plain"><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7DtE9RCVmUtmH2FAfvxsvM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Two UK men sentenced to 5 years and 6 months for the 2024 cyberattack on Transport for London, linked to the Scattered Spider group</strong></li><li><strong>Police seized devices showing evidence of the TfL breach; Flowers was also mid‑attack on US healthcare firms SSM Health and Sutter Health at the time of arrest</strong></li><li><strong>TfL reported $39M in damages; the NCA says the sentencing effectively dismantled Scattered Spider, with Microsoft confirming the arrests degraded the group’s operations</strong></li></ul><p>Two young men, one aged 20 and the other 18, have been sentenced to five years and six months in prison for their involvement in the <a href="https://www.techradar.com/pro/security/tfl-admits-2024-cyberattack-may-have-affected-over-10-million-people-personal-customer-info-stolen-heres-what-we-know-so-far">cyberattack on Transport for London (TfL)</a> in 2024.</p><p>Thalha Jubair, from East London, and Owen Flowers, from Walsall, West Midlands were arrested in 2025 under the suspicion that they were the leading members of <a href="https://www.techradar.com/pro/security/fbi-cisa-warn-of-more-scattered-spider-attacks-to-come">Scattered Spider</a> - an infamous hacking collective known for breaching dozens of companies. Initial reports from different cybersecurity organizations claimed the group consisted mostly of teenagers whose native language was English. </p><p>During the arrest, the police seized different types of electronic equipment from the suspects, including laptops, PCs, smartphones, hard drives, removable storage, and more. On one of the computers, law enforcement found screenshots and videos showing the intrusion into TfL’s systems.</p><h2 id="millions-in-damages">Millions in damages</h2><p>To make matters even worse, Flowers was in the middle of breaking into US healthcare companies SSM Health Care Corporation and Sutter Health when he was arrested: According to the National Crime Agency (NCA), these two were already “infiltrated and damaged”.</p><p>The attack on TfL was one of the more disruptive incidents that year, and one which caused a lot of financial damage, too. According to a report TfL shared with the City of London Police (CoLP), it suffered around $39 million in loss and recovery costs.</p><p>Both Jubair and Flowers initially pleaded not guilty and changed their pleas to guilty on the day they were due to stand trial, it was said. Now, they are both sentenced to more than five years in jail. The NCA says these arrests and sentencing effectively dismantled the notorious hacking collective.</p><p>“Although other cybercriminals may continue to use the damaged Scattered Spider brand, the NCA’s action against Jubair and Flowers effectively halted the group’s criminal activity,” the NCA said in its <a href="https://www.nationalcrimeagency.gov.uk/news/two-sentenced-for-hacking-transport-for-london-in-uk-s-biggest-ever-cyber-crime-case" target="_blank" rel="nofollow">report</a>. </p><p>“Independent assessment supports this, with Microsoft confirming that the arrests materially degraded the group's ability to continue conducting cybercriminal operations.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft nemesis returns with another zero-day PoC — but is 'LegacyHive' as nasty as expected? ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/microsoft-nemesis-returns-with-another-zero-day-poc-but-is-legacyhive-as-nasty-as-expected</link>
                                                                            <description>
                            <![CDATA[ Chaotic Eclipse is back with a new Windows 11 zero-day called LegacyHive. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">437WE24R6f5RrojuCvuFfS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HCMx4u3U8KVpNCqssJps2J-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jul 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HCMx4u3U8KVpNCqssJps2J-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/Ham patipak]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A laptop with the Windows 11 desktop on screen, glowing, while on a work desk ]]></media:description>                                                            <media:text><![CDATA[A laptop with the Windows 11 desktop on screen, glowing, while on a work desk ]]></media:text>
                                <media:title type="plain"><![CDATA[A laptop with the Windows 11 desktop on screen, glowing, while on a work desk ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HCMx4u3U8KVpNCqssJps2J-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researcher “Chaotic Eclipse” releases new Windows 11 zero‑day dubbed </strong><em><strong>LegacyHive</strong></em><strong>, a local privilege escalation bug targeting user registry hives</strong></li><li><strong>Exploit could let attackers elevate low‑privileged accounts, but requires prior device access; no CVE or full PoC was published</strong></li><li><strong>Experts caution that skilled actors could weaponize it quickly, urging intelligence teams to prepare mitigations despite lower perceived impact than earlier releases</strong></li></ul><p>Chaotic Eclipse, the infamous security researcher with a Microsoft grudge, did as they previously promised and released yet another zero-day vulnerability for fully patched Windows 11 devices. </p><p>However, other researchers don’t see it as dangerous as some of their previous releases.</p><p>Chaotic Eclipse disclosed a <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">zero-day</a> called LegacyHive, which is a local privilege escalation (LPE) bug targeting Windows’ user hives.</p><h2 id="escalating-privileges">Escalating privileges</h2><p>A few months ago, a hacker/researcher with the alias Chaotic Eclipse started publishing functioning exploits for fully patched Windows 11 systems, all with PoCs, claiming that Microsoft acted against them in ill faith and argued that the company does not treat researchers with the respect they deserve.</p><p>They released a total of <a href="https://www.techradar.com/pro/security/the-exact-same-issue-that-was-reported-to-microsoft-by-google-project-zero-is-actually-still-present-unpatched-chaotic-eclipse-strikes-again-with-another-worrying-windows-security-flaw" target="_blank">seven exploits</a>, some more damning than others, and promised to release a “bone-shattering” one on July 14 2026. In the meantime, Microsoft first criticized the researcher for not “responsibly” disclosing the flaws, and at one point even threatening possible legal action. However, it did not sue the researcher and later backed away from the threat entirely, partly as a result of strong public backlash.</p><p>In Windows, user hives are registry files that store configuration settings specific to an individual user account. These include desktop preferences, user-specific application settings, network drive mappings, user-specific security and privacy settings, and more. </p><p>With LegacyHive, threat actors could, in theory, gain privileged read-write access targeting other users’ hives. Or, in other words, they could turn low-privileged accounts into high-privileged ones. However, they would first need to have any access to the device, which is one of the reasons why some security researchers don’t see it as disastrous as Chaotic Eclipse’s previous work.</p><p>What also makes LegacyHive different from some other releases is that this one was not released with a CVE identifier or a fully functioning Proof of Concept (PoC). </p><p>Still, security experts are urging intelligence teams to work fast, because skilled threat actors can fill the gaps with relative ease, and turn LegacyHive into a potent weapon.</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/07/15/microsofts-serial-tormentor-drops-legacyhive-0-day/5271723" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Russian hacker turns Gemini CLI into a hacking agent, creates small-scale botnet ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/russian-hacker-turns-gemini-cli-into-a-hacking-agent-creates-small-scale-botnet</link>
                                                                            <description>
                            <![CDATA[ The hacker told the AI he was an authorized pentester - and the AI believed him. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2aLD452X3VLZeF4n8MnsB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PRCsQfoXPXi2t4jsGwWr6L-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jul 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PRCsQfoXPXi2t4jsGwWr6L-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A human shakes a robot&#039;s hand in front of blue concentric circles]]></media:description>                                                            <media:text><![CDATA[A human shakes a robot&#039;s hand in front of blue concentric circles]]></media:text>
                                <media:title type="plain"><![CDATA[A human shakes a robot&#039;s hand in front of blue concentric circles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PRCsQfoXPXi2t4jsGwWr6L-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Russian hacker “bandcampro” used Google’s Gemini CLI to control an eight‑device botnet at a dental clinic</strong></li><li><strong>The attacker tricked the AI by posing as a pen tester, directing it to migrate C2 infrastructure, troubleshoot connectivity, and prepare payload bundles</strong></li><li><strong>The AI assisted with daily operations like password guessing and WordPress access, highlighting risks of misuse when threat actors co‑opt AI tools</strong></li></ul><p>A Russian hacker and his AI companion were able to successfully control a miniature, eight-system botnet, with the hacker giving instructions in conversational language, and the AI doing his bidding, experts have found.</p><p>Analyzing 200 session logs obtained from the Russian-speaking threat actor known as “bandcampro”, cybersecurity researchers Trend Micro saw the hacker use Google’s Gemini CLI, an open source AI command-line tool that lets developers interact with Google's <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">Gemini AI</a> models directly from a terminal. </p><p>Scouring through a month’s worth of session logs (between April 21 and May 19 2026), the researchers discovered that the attacker tricked the AI by telling it they were an “authorized pen tester”. While the AI mostly complied with their nefarious overlord, they refused the orders on at least one occasion.</p><h2 id="gone-in-six-minutes">Gone in six minutes</h2><p>Trend Micro found the hacker controlled eight devices belonging to a dental clinic and sought to access their access their OpenDental database.</p><p>Using the AI, bandcampro did a number of things, starting with migrating the botnet to a new C2 infrastructure. He gave the AI a skill file with the full architecture description, standard operating procedures, infection one-liner, persistence commands, and troubleshooting steps.</p><p>He then told it to “study the C2 migration”, which had the AI process the guide and prepare all the code and necessary steps. It took the tool around six minutes to get the job done. </p><p>"The AI read the migration guide, then prepared a migration bundle, a small archive of server code, payloads, and the skill file. It then unpacked the bundle, launched the C&C server on a VPS, and brought up the Cloudflare tunnel," Trend Micro says.</p><p>Bandcampro then used the AI to troubleshoot connectivity issues, as well as for various daily operations, such as guessing passwords, generating plausible variants of existing passwords for WordPress portals, and more.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/google-gemini-cli-abused-as-a-hacking-agent-malware-botnet-operator/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Thousands of US military beneficiaries have data breached following TRICARE cyberattack — DoD Benefits Numbers and some Social Security numbers leaked ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/thousands-of-us-military-beneficiaries-have-data-breached-following-tricare-cyberattack-dod-benefits-numbers-and-some-social-security-numbers-leaked</link>
                                                                            <description>
                            <![CDATA[ TriWest suffers an attack and loses TRICARE data on some 12,000 people. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sKjC3VLGBvQgwi3mgFXgtj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nKQTr6znQKVirervbiEDkL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jul 2026 15:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nKQTr6znQKVirervbiEDkL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An office worker in front of a computer holding his hand in one hand and looking unhappy]]></media:description>                                                            <media:text><![CDATA[An office worker in front of a computer holding his hand in one hand and looking unhappy]]></media:text>
                                <media:title type="plain"><![CDATA[An office worker in front of a computer holding his hand in one hand and looking unhappy]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nKQTr6znQKVirervbiEDkL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>TriWest Healthcare confirmed an April 16 breach in which an attacker accessed and downloaded sensitive data tied to 12,000 TRICARE beneficiaries</strong></li><li><strong>Stolen information includes names, DoD Benefits numbers, ZIP codes, authorization request types, and in some cases SSNs, addresses, and dates of birth</strong></li><li><strong>TriWest says it acted immediately to contain the intrusion and notify affected individuals; no group has claimed responsibility and stolen data has not surfaced online</strong></li></ul><p>US healthcare services company TriWest Healthcare networks recently suffered a cyberattack in which it lost sensitive customer data belonging to thousands of its clients’ users.</p><p>TriWest is a private company that manages government healthcare programs, primarily on behalf of the US Department of Defense (DoD) and the Department of Veterans Affairs (VA). One of its clients is TRICARE, a DoD healthcare program for active-duty service members, National Guard and Reserve members, military retirees, and their families. </p><p>According to Cybernews, TriWest recently started notifying TRICARE customers that an “unauthorized person” accessed its network on April 16 and “downloaded some TriWest information.” Citing data provided to the California State Attorney General’s Office, the publication says 12,000 TRICARE beneficiaries were recently notified of the breach.</p><h2 id="sounding-the-alarm">Sounding the alarm</h2><p>In a statement shared with <a href="https://www.moaa.org/content/publications-and-media/news-articles/2026-news-articles/benefits/nearly-12,000-tricare-beneficiaries-warned-of-data-breach/" target="_blank"><u>Military Times</u></a>, TriWest explained what it did the moment it spotted the intrusion: “With regard to timing, as soon as the incident was discovered, TriWest took immediate action to prevent any further unauthorized activity and worked diligently with the government to notify affected individuals, consistent with applicable law and notification timelines,” TriWest officials said.</p><p>The details about the incident, the nature of the attack, or the identity of the attackers, were not disclosed. We do know that the miscreants walked away with people’s names, DoD Benefits numbers, ZIP codes, types of authorization requests and, in some cases, Social Security numbers (SSN), postal addresses, and dates of birth.</p><p>At press time, the TriWest website, as well as the company’s newsroom, were offline. It is unclear if there is any connection to the data breach. So far, no threat actors claimed responsibility for the attack, and the data is yet to surface on the dark web.</p><p>In the meantime, TRICARE beneficiaries are warned to be wary of incoming emails, especially those claiming to come from the program or the company.</p><p><em>Via </em><a href="https://cybernews.com/news/tricare-west-health-data-breach-military-beneficiaries/" target="_blank"><em>Cybernews</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Zoom patches critical security flaw which could have let hackers hijack accounts ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/zoom-patches-critical-security-flaw-which-could-have-let-hackers-hijack-accounts</link>
                                                                            <description>
                            <![CDATA[ Zoom finds improper input validation bug, but fortunately sees no evidence of abuse. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">StnEZtLDbRcvUu2DBR5ea3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/oQs6iUSDCYDEV6yP7Pj9Gh-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jul 2026 14:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/oQs6iUSDCYDEV6yP7Pj9Gh-1280-80.png">
                                                            <media:credit><![CDATA[LinkedIn]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Zoom Verified on LinkedIn Example]]></media:description>                                                            <media:text><![CDATA[Zoom Verified on LinkedIn Example]]></media:text>
                                <media:title type="plain"><![CDATA[Zoom Verified on LinkedIn Example]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/oQs6iUSDCYDEV6yP7Pj9Gh-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Zoom patches critical improper input validation flaw in multiple Windows clients and SDKs that allowed remote account takeover</strong></li><li><strong>Additional high‑severity bugs fixed include CVE‑2026‑53410 (TOCTOU race condition), CVE‑2026‑53409 (privilege management flaw), and CVE‑2026‑53411 (input validation issue)</strong></li><li><strong>All vulnerabilities were found internally, with no evidence of exploitation; users are urged to update Zoom Workplace and related products to the latest versions</strong></li></ul><p>Zoom has patched a critical-level vulnerability in multiple products that allowed threat actors to take over people’s accounts remotely.</p><p>In a security advisory, Zoom said it fixed an Improper Input Validation bug plaguing Zoom Desktop Client for Windows (before version 7.0.0), Zoom VDI Client for Windows (before versions 7.0.10, 6.6.15, and 6.5.18), and Zoom Meeting SDK for Windows (before version 7.0.0). It did not go into more details on how the flaw works.</p><p>The bug is now tracked as CVE-2026-53412, and was given a severity score of 9.8/10 (critical). To fix it, users are advised to update their software to the newest version.</p><h2 id="more-vulnerabilities">More vulnerabilities</h2><p>While certainly the most dangerous one, this is not the only bug Zoom recently addressed. The company also fixed a handful of less severe vulnerabilities, including a time-of-check to time-of-use (TOCTOU) race condition bug affecting Zoom Workplace for Windows before 7.0.5, Zoom Workplace VDI Client and VDI Plugin before 6.5.17/6.6.14, Zoom Rooms for Windows before 7.0.5, and Remote Control for Zoom Contact Center before 7.0.0. This bug is tracked as CVE-2026-53410 and was given a “high” severity score of 7/10. </p><p>Other notable mentions include CVE-2026-53409 (a high-severity improper privilege management flaw in Zoom Rooms for Windows before version 7.1.0), and </p><p>CVE-2026-53411 (a high-severity improper input validation flaw affecting the Zoom Workplace VDI Plugin for Windows before version 6.6.14).</p><p>Zoom found all of these vulnerabilities in-house and says there is no evidence that any of these were abused in real-life attacks in the past. </p><p>Zoom Workplace (the company’s <a href="https://www.techradar.com/best/best-online-collaboration-tools" target="_blank">all-in-one collaboration platform</a>) offers video meetings, team chat, phone, email, calendar, scheduling, whiteboards, and other productivity tools. It is an evolution of the original Zoom Meetings app which now competes with platforms such as Microsoft 365 and Google Workspace.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/zoom-warns-of-critical-account-takeover-vulnerability/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ KFC may be forced to shut some stores following cyberattack at key supplier ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/kfc-may-be-forced-to-shut-some-stores-following-cyberattack-at-key-supplier</link>
                                                                            <description>
                            <![CDATA[ Nichirei Co confirmed shutting parts of its infrastructure offline to contain a cyberincident which could affect KFC Japan stores. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">N2u2mC7m4y6PqqGv8ZPdLY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jul 2026 10:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:description>                                                            <media:text><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:text>
                                <media:title type="plain"><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Nichirei Co confirms cyberattack disrupting refrigerated warehouse and frozen food logistics, impacting customers including KFC Japan</strong></li><li><strong>KFC warned of delivery delays leading to possible menu restrictions, shortened hours, or temporary suspension of online orders</strong></li><li><strong>No data leaks or attacker claims have surfaced; disruptions suggest ransomware, but both companies expect operations to normalize by week’s end</strong></li></ul><p>Nichirei Co, a large Japanese company which produces frozen and processed foods, and operates cold-chain logistics to distribute them across the country, has confirmed it suffered a cyberattack which affected some of its customers, including KFC.</p><p>The company confirmed the news in a notice stating, “Today, Nichirei Co experienced a system failure caused by unauthorized access." </p><p>Nichirei said that it is currently investigating the incident, but that there is no evidence of personal or customer data leaking outside the company. However, due to the nature of the incident (which hasn’t been explained in detail), multiple operations have been affected, including refrigerated warehouse inbound/outbound operations, and frozen food shipping services.</p><h2 id="no-claims-yet">No claims yet</h2><p>These disruptions affected, among others, KFC - one of the largest fast food chains in the world. In a separate announcement, KFC said that a system failure at Nichirei Logistics Group, which happened on July 13, affected the company’s logistics and delivery sites. “From Tuesday, July 14, 2026, food delivery to KFC stores is expected to be affected,” it said.</p><p>“As a result, each store may suspend operations depending on some products going out of stock, menu restrictions, shortened business hours, or ingredient stock availability. Additionally, online orders from the official app and website have also been temporarily suspended.”</p><p>The nature of the attack, or the identity of the attackers, were not disclosed. Since Nichirei had to shut down some of its services, it could mean this was a <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> attack and that some company data was stolen after all. The Register reports that KFC Japan hasn’t posted information about store closures and continues to promote summer menu items.</p><p>At press time, no threat actors claimed responsibility for the attacks, and no Nichirei/KFC data surfaced on the dark web. The companies expect to resume normal operations by the end of the week.</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/07/16/cyberattack-threatens-utterly-critical-infrastructure-in-japan-kfc/5272220" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘A candidate who was hostile from day one never produces that baseline’: Nation states spies applying for legit jobs are hard to spot ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/a-candidate-who-was-hostile-from-day-one-never-produces-that-baseline-nation-states-spies-applying-for-legit-jobs-are-hard-to-spot</link>
                                                                            <description>
                            <![CDATA[ Nation state spies are using AI to create fake identities and realistic job applications, infiltrating organizations to steal intelligence. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4Rtu5w3gmuokG2QJknZ7AQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jul 2026 17:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ desire.athow@futurenet.com (Desire Athow) ]]></author>                    <dc:creator><![CDATA[ Desire Athow ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/oEw3XiohQwun9z7gMxKzkB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Désiré has been musing and writing about technology during a career spanning four decades. He dabbled in &lt;a href=&quot;https://www.techradar.com/news/the-best-website-builder&quot;&gt;website builders&lt;/a&gt; and &lt;a href=&quot;https://www.techradar.com/web-hosting/best-web-hosting-service-websites&quot;&gt;web hosting&lt;/a&gt; when DHTML and frames were in vogue and started narrating about the impact of technology on society just before the start of the Y2K hysteria at the turn of the last millennium.&lt;/p&gt;&lt;p&gt;Then followed a weekly tech column in a local business magazine in Mauritius, a late night tech radio programme called &lt;a href=&quot;https://web.archive.org/web/20030414214749/http://www.clicplus.com/&quot;&gt;Clicplus&lt;/a&gt; and a freelancing gig at the now-defunct, Theinquirer, with the late Mike Magee as mentor. After an eight-year stint at ITProPortal.com, where he discovered the joys of global techfests and transformed the publication into one of the biggest tech B2B independent publishers, Désiré moved to TechRadar Pro where he has been the editor for nine years.&lt;/p&gt;&lt;p&gt;He has an affinity for anything hardware and staunchly refuses to stop writing reviews of obscure products or cover niche B2B software-as-a-service providers. He is an avid deal hunter and can be found lurking around on various deals forums.&lt;/p&gt; ]]></dc:description>
                                                                                                        <dc:contributor><![CDATA[ Craig Hale ]]></dc:contributor>
                                                                    <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:description>                                                            <media:text><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:text>
                                <media:title type="plain"><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Geopolitical tensions are mounting, and nation states are employing new types of strategies to gain intelligence. A recent Five Eyes warning, for example, accused Chinese military intelligence officers of using professional networking sites and online job platforms to target individuals of interest.</p><p>In this specific case, the agents pose as recruiters advertising seemingly legitimate work to build relationships and, ultimately, get their hands on non-public information. Popular sites like LinkedIn, Indeed and Upwork have all seen this new type of attack take place.</p><p>At the same time, a parallel threat sees operatives applying for jobs within trusted organizations with access to intelligence, creating insider threats that experts warn AI might be mostly responsible for.</p><p>Generative AI, for example, can create documents, write applications and even supply live answers during real-time remote interviews, meaning that a small group of fake applicants can extend their reach much more quickly.</p><h2 id="rather-than-attacking-existing-workers-nation-states-are-creating-their-own-job-candidates">Rather than attacking existing workers, nation states are creating their own job candidates</h2><p>Once inside an organization and with access to company tools like PCs, emails and other internal systems, nation state spies can then move laterally to acquire the information they sought.</p><p>Security experts at Exabeam warn that, because this technique is still evolving, it might not always be so easy to spot. Additionally, motives can differ, with Chinese intelligence operations typically seeking military, political or economic information. North Korean agents, on the other hand, tend to be tied to stealing money, which could also come with the side effect of data and intelligence theft.</p><p>Exabeam even observed this type of attack first-hand, when a North Korean-affiliated applicant used a false identity to apply for a job at the company. After passing technical tests, a video interview and other standard checks, the suspect’s laptop was quickly flagged for unusual activity.</p><p>In the following Q&A with AI Strategy and Security Research VP Steve Povolny, I discuss these new types of attacks, who’s responsible for stamping them out and what we can do to prevent similar incidents from happening more commonly.</p><ul><li><strong>The Five Eyes alliance recently warned that foreign intelligence groups are using job platforms to recruit insiders. How significant is this threat, and what is driving its growth?</strong></li></ul><p>This is among the most serious access-driven threats facing cleared workers, and it keeps growing because the economics now favor the attacker. </p><p>Foreign intelligence services no longer need handlers and dead drops when they can post a job ad on LinkedIn or Upwork and let candidates self-select based on the access listed in their own resumes. Generative AI lets them run thousands of these conversations at once, drafting outreach and scoring which applicants sit closest to sensitive information without a trained officer. </p><p>The Five Eyes alert describes a scaled, automated funnel, and that scale is what makes it dangerous.</p><ul><li><strong>A parallel risk runs alongside that warning: adversaries who secure employment directly rather than recruiting an existing employee. Which scenario presents the greater defensive challenge, and why?</strong></li></ul><p>The infiltration model gives defenders less to work with, which makes it the harder problem. When an adversary recruits someone already on staff, most of the suspicious behavior happens outside the company on platforms the employer never sees, yet the insider remains a known person with a verified identity and a real history. </p><p>When the adversary becomes the employee, the company has onboarded a fabricated person and handed them a laptop and standing network access on day one. No behavioral baseline exists, since everything that account does counts as a first. The deception also clears the controls most organizations trust, so the failure lands before any security tool gets a vote.</p><ul><li><strong>Exabeam identified a North Korea-affiliated individual who gained employment at the company. How did the operative clear Exabeam's hiring process, and what first signaled that something was wrong?</strong></li></ul><p>He cleared it by performing well on the parts we test and forging the parts we verify. Applying under the alias Trevor Rothluebber, he aced the technical interview and take-home assessment, passed the video interview and cleared our standard pre-employment process including the background check and I-9 validation.</p><p>Our hiring team flagged a suspicion that he leaned on generative AI for live help during the video call, the first soft signal. The hard signal arrived the moment he logged into his corporate account. Our threat intelligence feed matched his username to activity previously associated with North Korean operatives and rated it high risk, and that single match reframed how the team read everything that followed.</p><p>Simultaneously, Exabeam’s platform detected a number of anomalies inconsistent with a brand new employee’s first day, and escalating in severity within hours. Incident response quietly isolated and reimaged his laptop before any real damage could be done.</p><ul><li><strong>The candidate completed applications, interviews and assigned work without raising alarm. In retrospect, what indicators were present, and why did standard screening miss them?</strong></li></ul><p>The indicators existed, but they lived in places our screening was never built to read. The driver's license he submitted was either AI-generated or very badly manually modified, and the tell was physical. The image had unique aberrations, such as the ears in the photo which had an unnatural and pixelated modification an artifact that image generators still produce, and a reviewer skims past.</p><p>The live AI assistance during the interview was another, since his answers carried a fluency that did not match the natural hesitation you expect when someone reasons through an unfamiliar problem. Standard screening missed all of it because background checks and identity validation confirm whether documents are internally consistent and whether a record exists, and they never ask whether the human attached to those documents is real.</p><p>Further fabrication of documents such as I-9 were missed by a 3rd party identity verification company, and validation of (fake) job references was not properly identified.</p><ul><li><strong>How did AI contribute to the deception? What did the fraudulent documentation involve, and what capabilities does AI introduce that traditional forgery methods lack?</strong></li></ul><p>AI showed up at nearly every stage. The fraudulent documentation centered on a forged driver's license we believe was generated rather than physically produced, paired with a stolen identity that gave the paperwork a real history to rest on.</p><p>During the interview the candidate  appeared to have run an AI copilot feeding him answers in real time, and many of these tools now stay invisible to everyone else on the call even while the candidate shares a screen. What AI adds over traditional forgery is volume and believability together. A skilled forger could always produce one convincing passport, but the craft capped how many operations could run at once.</p><p>Generative tools remove that ceiling, so a single actor can fabricate convincing documents and coach themselves through a live technical interview across dozens of applications at once, and the forgery stopped being the bottleneck it used to be.</p><ul><li><strong>The Five Eyes warning focused on China, while the Exabeam case involved North Korea. Do these actors share tactics and objectives, or do they represent distinct operational models that overlap on method?</strong></li></ul><p>They overlap heavily on method while running on different motives, which defenders should sit with. The Chinese operation the Five Eyes described aims at intelligence collection, pulling government and military insight out of people who already hold access. </p><p>The North Korean program that hit us and so many others in this industry is funded differently, since much of its purpose is revenue for a sanctioned regime, with intrusion and theft riding alongside the paycheck. The objectives diverge, yet the tradecraft has converged on one toolkit of fabricated identities, AI-assisted documents, manufactured professional histories and the patient relationship-building that lets an operative stay quiet.</p><p>When two adversaries with separate goals reach the same playbook, that tells you the playbook works and other actors are already watching.</p><ul><li><strong>Conventional insider threat programs are built to detect employees who become compromised over time. How should organizations identify a candidate who was an adversary from the point of hire?</strong></li></ul><p>Our mindset must shift toward treating the moment of hire as the start of the highest-risk window rather than the end of vetting. Traditional insider programs watch for drift, the employee who gradually turns after a financial shock or a grievance, so they depend on a baseline built over months.</p><p>A candidate who was hostile from day one never produces that baseline, which forces you to scrutinize the earliest behavior most closely. In our case, the catch came from putting new accounts under enhanced monitoring and letting an AI agent correlate scattered signals that no single alert would have justified escalating.</p><p>The working principle is to give hiring workflows and new-hire activity the same suspicion you already apply to production access.</p><ul><li><strong>Where should accountability for this threat reside within an organization? Is it a security function, an HR function, or a gap that persists because ownership is unclear?</strong></li></ul><p>Accountability most often lives in the gap right now, and that gap is exactly why the threat works. Hiring sits with HR and talent acquisition, who are measured on filling roles quickly and are not equipped to run identity verification at an intelligence-grade level.</p><p>Detection sits with security, which usually gains no visibility into a candidate until that person already holds a badge and a laptop, and the adversary exploits the seam between the two.</p><p>The workable answer is shared ownership with a clean handoff, where security sets the identity and behavioral standards hiring must meet and stays involved through the first weeks of employment rather than inheriting the problem once onboarding closes.</p><ul><li><strong>Many mid-sized companies lack dedicated threat intelligence resources. What practical measures can such organizations implement to reduce their exposure?</strong></li></ul><p>Useful defense does not require a dedicated threat intelligence team. The interview itself is the cheapest control available, and small changes make it far more revealing.</p><p>Underspecifying a problem on purpose shows whether a candidate asks clarifying questions like a real engineer or simply produces a confident answer and switching the problem partway through tests whether they adapt or whether something is feeding them responses.</p><p>Asking for an external webcam that shows the workspace instead of a shared screen removes one of the easiest hiding spots for an interview copilot. Beyond hiring, the highest-leverage move is placing every new employee on a watchlist for closer monitoring through their first weeks, which costs configuration time rather than budget.</p><p>Even a basic, low-cost threat intelligence feed would have surfaced the username match that broke our case open.</p><ul><li><strong>What is the most contested prediction on this issue, one that many security leaders would currently dispute?</strong></li></ul><p>My contested prediction is that within a couple of years the verified human interview, run live and in person for any role with meaningful access, returns as a security requirement. Many security leaders will fight that because it breaks the remote-first hiring model they spent years optimizing.</p><p>The objection I expect is that it does not scale and shrinks the talent pool, and those concerns are legitimate. My counter is that the economics have already flipped for high-access roles, since the cost of onboarding a single fabricated adversary now dwarfs the friction of one in-person verification step.</p><p>The deeper claim underneath it is that remote identity verification as we practice it today is no longer reliable for sensitive positions, and AI is what made it unreliable. Most security leaders are not ready to say that out loud yet.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts flag new scam targeting fans seeking tickets for Celine Dion concerts ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-flag-new-scam-targeting-fans-seeking-tickets-for-celine-dion-concerts</link>
                                                                            <description>
                            <![CDATA[ Multiple scams targeting Celine Dion fans have already surfaced - it looks like this scam will go on (and on). ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wubbooKqvDht9F8jtExLaa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kMQVGNaXFmvhNxH6wp5LUh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jul 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kMQVGNaXFmvhNxH6wp5LUh-1280-80.jpg">
                                                            <media:credit><![CDATA[ Say thanks! Give a shoutout to Jefferson Santos on social or copy the text below to attribute.  Photo by Jefferson Santos on Unsplash]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[shady person sitting at a computer.]]></media:description>                                                            <media:text><![CDATA[shady person sitting at a computer.]]></media:text>
                                <media:title type="plain"><![CDATA[shady person sitting at a computer.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kMQVGNaXFmvhNxH6wp5LUh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Group‑IB warns of scams exploiting Celine Dion’s concert comeback, with fraudsters selling duplicate Ticketmaster tickets and spoofing sites like AXS and Paris La Défense Arena</strong></li><li><strong>Scammers embed themselves in Facebook fan groups and marketplaces, even using voice messages to build trust and make fake offers seem legitimate</strong></li><li><strong>Fans are advised to only buy from official distributors, verify tickets in person if using resellers, and contact banks to dispute charges if scammed</strong></li></ul><p>Celine Dion is back, and hackers are already trying to exploit the fact for their own financial gain, experts have warned.</p><p>A <a href="https://www.group-ib.com/blog/fake-concert-ticket-scam-celine-dion/" target="_blank">report</a> from security researchers Group-IB has claimed there are numerous scam campaigns all across the internet and social media, looking to exploit gullible fans and steal their money.</p><p>Its aptly named “The Scam Will Go On” report said it saw scammers lurking in Facebook Groups, Facebook Marketplace, and other fan-centric spaces, offering concert tickets for sale. The tickets themselves, hosted on Ticketmaster, are valid. However, the scammers only have a few tickets which can be redeemed by the first person who reaches the venue. Everyone else will be denied entry, since their tickets will already have been used.</p><h2 id="how-to-avoid-getting-scammed">How to avoid getting scammed</h2><p>But that’s not the only scam. Some people don’t want to pay an unknown third person via wire, and would prefer to purchase the tickets directly from a service. </p><p>For those people, the scammers created entire websites, spoofing ticketing distributors such as AXS and Ticketmaster. Group-IB also saw fake websites spoofing Celine Dion and Paris La Défense Arena, the stadium where the concert will take place. </p><p>“We see that such an event generates excitement and provides scammers with another opportunity to make a fortune at the expense of unsuspecting fans,” Group-IB warned. </p><p>“Scammers are using increasingly sophisticated techniques, such as embedding themselves into social networking fan groups and speaking directly to their victims via voice messages to make the interaction more personal and gain their victims’ trust more easily. Furthermore, official ticketing platforms are being misused to make scams seem legitimate.”</p><p>The researchers recommend fans only visit official websites and those of official distributors, and if they absolutely must buy from a reseller, to make sure they’re purchasing a physical ticket, in person. Those that fell for the scam should call their bank and lodge an objection on their credit card. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New phishing campaign hits LastPass, Bitwarden users - password manager customers warned not to fall for this scam ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/new-phishing-campaign-hits-lastpass-bitwarden-users-password-manager-customers-warned-not-to-fall-for-this-scam</link>
                                                                            <description>
                            <![CDATA[ No, LastPass' security policies have not been updated, and neither have Bitwarden's - it's a scam. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sT8YuaYXwd29zBkL8LgEdf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Ramk8kAMZnG58FVJidCvuF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jul 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Ramk8kAMZnG58FVJidCvuF-1280-80.jpg">
                                                            <media:credit><![CDATA[ wk1003mike / Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image Credit: Shutterstock]]></media:description>                                                            <media:text><![CDATA[Fraude en ligne phishing]]></media:text>
                                <media:title type="plain"><![CDATA[Fraude en ligne phishing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Ramk8kAMZnG58FVJidCvuF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Attackers are spoofing LastPass and Bitwarden with phishing emails from fake newsletter domains, tricking users into signing bogus DocuSign documents</strong></li><li><strong>Victims are redirected to malicious “compliance” domains flagged by Microsoft Defender and Cloudflare, already taken offline</strong></li><li><strong>Neither password manager was breached; this is domain spoofing, and users are urged to verify sender addresses and domains before clicking links</strong></li></ul><p>Criminals have been found impersonating popular password managers LastPass and Bitwarden online in an attempt to trick users into sharing their login credentials, and thus access to a treasure trove of passwords and other secrets.</p><p>LastPass recently issued a warning to its customers, raising awareness of the ongoing phishing campaign. </p><p>However the scam also now seems to have spread to other password managers, with Bitwarden customers also apparently being targeted.</p><h2 id="passwords-are-safe">Passwords are safe</h2><p>In the campaign, LastPass users received emails from the address “hello@lastpassnewsletter.com”. </p><p>This address does not belong to LastPass, and is in no way affiliated with the <a href="https://www.techradar.com/best/password-manager" target="_blank">password manager</a>. In the message, the victims are told that the company’s security policies have been updated, and that they should navigate to a specific landing page and sign a DocuSign document.</p><p>The email comes with a ‘Review & Access Terms’ button which, if clicked, redirects the victims to lastpasscompliance[dot]com, yet another domain unaffiliated with the password management platform. </p><p><em></em><a href="https://www.bleepingcomputer.com/news/security/lastpass-bitwarden-users-targeted-with-fake-security-alerts/" target="_blank"><em>BleepingComputer</em></a> claims this domain has already been flagged as malicious by both Microsoft Defender for Office 365, and Cloudflare and is currently offline. </p><p>Digging deeper, the journalists uncovered another campaign, almost identical, but now targeting Bitwarden users. In this case, the victims were being mailed from the “hello@bitwardennewsletter.com” addresses and were being redirected to bitwardencompliance[dot]com. Identical methodology, just slightly personalized. </p><p>It is important to note that neither LastPass nor Bitwarden were compromised as part of this attack. </p><p>The companies’ infrastructure is intact, and the passwords are safe. This is a typical domain spoofing attack in which the crooks purchase a domain similar to the legitimate one, in hopes that the victims won’t spot the difference.</p><p>As usual, the best course of action is to always be skeptical of incoming emails, and to double-check the domains and email addresses from which they are sent. It is also good to cross-reference these emails with any older messages that are proven to be authentic, to see if the domains and addresses match.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hundreds of GitHub repos found posing as real software to push malware ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/hundreds-of-github-repos-found-posing-as-real-software-to-push-malware</link>
                                                                            <description>
                            <![CDATA[ Russian hackers are trying to sneak infostealers onto people's devices to grab passwords, crypto, and more. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dxoB3qPWwHz8vExitx7Zed</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jul 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phone malware]]></media:description>                                                            <media:text><![CDATA[Phone malware]]></media:text>
                                <media:title type="plain"><![CDATA[Phone malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>ArcticWolf uncovered 292 malicious GitHub repositories spoofing legitimate tools and products, delivering a new BoryptGrab infostealer variant</strong></li><li><strong>Malware steals from 19 browsers, 32 crypto wallets, messaging apps, Steam, and Windows Credential Manager, and uniquely bypasses Chrome’s App‑Bound Encryption via code injection</strong></li><li><strong>Most repos have been removed, but some remain active; GitHub’s popularity makes it a prime target, underscoring the need to vet code before use</strong></li></ul><p>Russian actors have reportedly created hundreds of malicious GitHub repositories masquerading as legitimate software but acting as a dangerous infostealer. </p><p>Cybersecurity researchers ArcticWolf discovered the campaign after finding their own products spoofed as part of the attack.</p><p>In total, the researchers found 292 fake repositories, spoofing things like security products, developer tools, macOS utilities, games, and more. Each repository contained a README file with the download URL.</p><h2 id="obviously-malicious">Obviously malicious</h2><p>Victims who download the program get a variant of the BoryptGrab infostealer family that grabs data from 19 browsers (<a href="https://www.techradar.com/best/password-manager" target="_blank">passwords</a>, cookies, payment information), 32 cryptocurrency wallets, Telegram, Discord, and Steam sessions, credentials for Meta’s Max, data from Windows Credential Manager, and more. It can also exfiltrate files from Desktop and Documents, and grab screenshots.</p><p>While most of the features can be found in other BoryptGrab variants, this one is unique in a sense that it can bypass Chrome’s App-Bound Encryption through direct code injection into the browser process.</p><p>While it hasn’t been specifically said that the threat actors are Russian, the compressed data is later sent to a Russia-based command-and-control (C2) infrastructure.</p><p>What’s also worth mentioning is that the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> is not designed to last. It has no anti-analysis layer, and doesn’t even try to hide itself in any specific manner. It does not establish persistence and simply tries to grab as much sensitive data as it can on the first attempt.</p><p>The attack, which seems to have started in the final days of June, is almost thwarted now, since most of the malicious repositories have been removed from GitHub. Citing “researchers”, <a href="https://www.bleepingcomputer.com/news/security/nearly-300-github-repos-pose-as-legit-software-to-push-malware/" target="_blank"><em>BleepingComputer</em></a> reported that several dozen still remain active, though. </p><p>Because of its importance and popularity in the open-source community, GitHub is currently one of the most targeted platforms on the internet, which is why it’s important to double-check and vet every piece of code before it’s applied to a project.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'No new vulnerability is needed to bypass UEFI Secure Boot': Experts find attackers can exploit decades-old flaws to gain access to key systems ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/no-new-vulnerability-is-needed-to-bypass-uefi-secure-boot-experts-find-attackers-can-exploit-decades-old-flaws-to-gain-access-to-key-systems</link>
                                                                            <description>
                            <![CDATA[ Almost a dozen vulnerable UEFI shim bootloaders discovered and revoked. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ojLPBeQtFiLPyCDTQAMKFB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AsscCgZRnWXMPyCxtEfpkK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jul 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/AsscCgZRnWXMPyCxtEfpkK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An email symbol inside a red square warning sign, surrounded by red triangles with exclamation marks inside them, superimposed on someone typing on a laptop]]></media:description>                                                            <media:text><![CDATA[An email symbol inside a red square warning sign, surrounded by red triangles with exclamation marks inside them, superimposed on someone typing on a laptop]]></media:text>
                                <media:title type="plain"><![CDATA[An email symbol inside a red square warning sign, surrounded by red triangles with exclamation marks inside them, superimposed on someone typing on a laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AsscCgZRnWXMPyCxtEfpkK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>ESET discovers 11 vulnerable UEFI shim bootloaders signed by Microsoft, allowing attackers to bypass Secure Boot and deploy malicious bootkits</strong></li><li><strong>Any UEFI system trusting Microsoft’s 2011 third‑party certificate could be exposed, potentially billions of devices; attackers can bring old trusted shims to new systems</strong></li><li><strong>Microsoft has revoked the vulnerable shims, and users should apply the latest UEFI revocations (Windows auto‑updates, Linux via LVFS) to block exploitation</strong></li></ul><p>Cybersecurity experts from <a href="https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/" target="_blank">ESET</a> have discovered 11 vulnerable UEFI shim bootloaders, all signed by Microsoft, which could allow threat actors to exploit ancient vulnerabilities and bypass UEFI Secure Boot, deploying all sorts of malicious bootkits.</p><p>A shim is a small, intermediary bootloader that works as a bridge between a computer's firmware (UEFI) and the operating system's bootloader. Its primary purpose is to allow operating systems to work with UEFI Secure Boot without having Microsoft sign every <a href="https://www.techradar.com/best/best-linux-distros" target="_blank">Linux</a> bootloader individually.</p><p>Any UEFI-based machine that trusts the Microsoft Corporation UEFI CA 2011 third-party UEFI certificate authority (CE) certificate, regardless of the operating system, was said to be vulnerable to the shims (versions 0.9 and older). That would put the number of potentially vulnerable devices in the billions, since almost all modern x86 PCs use UEFI firmware, and most of them trust the Microsoft Corporation UEFI CA 2011 certificate out of the box.</p><h2 id="revoking-the-shims">Revoking the shims</h2><p>However, ESET reported its findings to CERT/CC and the vulnerable UEFI applications were all revoked. </p><p>The shims come from different tools such as PC diagnostic software, Linux distribution, and other UEFI-based utilities, the researchers explained. They also added that, since the attackers can bring their own vulnerable shims to any UEFI system with the Microsoft third-party UEFI certificate enrolled, they can exploit systems that are, at first, not affected. </p><p>To block the vulnerable shims, users should apply the latest UEFI revocations from Microsoft, it was said. While Windows systems will most likely do it automatically, Linux systems users should do it through the Linux Vendor Firmware Service. </p><p>“What makes these old shims dangerous is not a novel vulnerability; it’s that no new vulnerability is needed to bypass UEFI Secure Boot,” says ESET researcher Martin Smolár, who discovered the vulnerable shims. </p><p>“An attacker needs no complicated exploitation primitives — only a copy of an old, still-trusted but unrevoked shim binary and a basic understanding of how UEFI shims work. That is enough to bypass such an essential security feature as UEFI Secure Boot."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft just released its biggest Patch Tuesday ever, with a mammoth 622 fixes including three dangerous zero-days ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/microsoft-just-released-its-biggest-patch-tuesday-ever-with-a-mammoth-622-fixes-including-three-dangerous-zero-days</link>
                                                                            <description>
                            <![CDATA[ Microsoft shipped three times more fixes than usual in its latest Patch Tuesday update. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">a4QTENza3vCL4mPwKTvD4f</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jul 2026 12:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg">
                                                            <media:credit><![CDATA[Thapana Onphalai via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:description>                                                            <media:text><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:text>
                                <media:title type="plain"><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft’s July 2026 Patch Tuesday fixed a record 622 vulnerabilities, including 58 critical, two exploited in the wild, and one publicly disclosed, plus 428 Chromium bugs</strong></li><li><strong>Actively abused flaws include CVE‑2026‑56155 (AD FS privilege escalation) and CVE‑2026‑56164 (SharePoint privilege escalation), alongside notable issues in BitLocker and Copilot</strong></li><li><strong>Surge in fixes is linked to Microsoft’s use of Anthropic’s Mythos AI, with patch volumes rising sharply since its adoption</strong></li></ul><p>Microsoft has released its July 2026 Patch Tuesday download, marking another record-breaking update, addressing hundreds of flaws across the ecosystem.</p><p>The release, which is currently rolling out to Microsoft users, fixes a staggering 622 vulnerabilities, including 58 critical-severity ones, two that were observed as being abused in the wild, and one which has already been publicly disclosed. </p><p>On top of that, Microsoft shipped fixes for another 428 Chromium bugs, as well. </p><h2 id="a-jump-in-numbers">A jump in numbers</h2><p>There are simply too many vulnerabilities to mention all of them, however two that are being exploited in the wild are CVE-2026-56155 and CVE-2026-56164. The former is described as an “Insufficient granularity of access control in Active Directory Federation Services (AD FS)” bug, which allows an authorized attacker to elevate privileges locally. It carries a severity score of 7.8/10 (high).</p><p>The latter is a “Missing authentication for critical function in Microsoft Office SharePoint” bug that allows an unauthorized attacker to elevate privileges over a network. Microsoft assigned it a medium severity score (5.3/10), but the National Vulnerability Database gave it a 9.8/10 (critical).</p><p>Other notable mentions include CVE-2026-50661, a protection mechanism failure in Windows BitLocker that allows unauthorized attackers to bypass a security feature with a physical attack, and CVE-2026-48561, an improper neutralization of special elements used in a command in Microsoft Copilot, that allows an unauthorized attacker to execute code over a network.</p><p>If you think fixing 622 vulnerabilities in a month is a lot, you’re absolutely right. It’s well above what Microsoft is used to do, and this is most likely due to the company now using the fabled Mythos - Anthropic’s cybersecurity-oriented AI. </p><p>In June 2026, roughly a month and a half after the release of Mythos, Microsoft fixed 206 flaws, which raised eyebrows because it was significantly above the company’s usual amount of bugs fixed.</p><p>In May it fixed 120 flaws, in April 167, and in March - 79.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ First VPN administrators sanctioned by US Treasury over ransomware attacks ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/vpn/vpn-privacy-security/first-vpn-administrators-sanctioned-by-us-treasury-over-ransomware-attacks</link>
                                                                            <description>
                            <![CDATA[ Following a massive Europol takedown in May, the US Treasury has officially sanctioned the administrators behind First VPN, a service favored by ransomware groups to hide their tracks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xcqXWhLyXc3yCpMeVRFUCX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qp6PFkub49CUBhgFaHwjeQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jul 2026 09:39:52 +0000</pubDate>                                                                                                                                <updated>Thu, 16 Jul 2026 11:05:33 +0000</updated>
                                                                                                                                            <category><![CDATA[VPN Privacy &amp; Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Milman ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qp6PFkub49CUBhgFaHwjeQ-1280-80.jpg">
                                                            <media:credit><![CDATA[Photo by Fred TANNEAU / AFP via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[This photograph shows a laptop screen displaying the website of Europol featuring the First VPN service website with a message reading, &quot;This service has been seized&quot;]]></media:description>                                                            <media:text><![CDATA[This photograph shows a laptop screen displaying the website of Europol featuring the First VPN service website with a message reading, &quot;This service has been seized&quot;]]></media:text>
                                <media:title type="plain"><![CDATA[This photograph shows a laptop screen displaying the website of Europol featuring the First VPN service website with a message reading, &quot;This service has been seized&quot;]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qp6PFkub49CUBhgFaHwjeQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>The US Treasury has sanctioned First VPN's administrator for aiding ransomware attacks on American infrastructure</strong></li><li><strong>Another suspect was targeted for selling "cryptors" that cloak malware from security systems</strong></li><li><strong>The move follows a May 2026 takedown by European law enforcement and the FBI that seized the VPN's infrastructure</strong></li></ul><p>The United States government has officially issued sanctions against the operators of a notorious virtual private network (VPN), escalating a global crackdown on digital infrastructure used to facilitate ransomware attacks.</p><p>On Monday (July 13), the US Department of the Treasury’s Office of Foreign Assets Control (OFAC) designated First VPN Service (also known as 1VPNS) and its Ukrainian administrator, Dmytro Rashevskyi, for abetting cybercriminals. The service, which has operated since 2014, was heavily favored by ransomware gangs targeting American hospitals, municipalities, and businesses.</p><p>While the <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> services are designed to protect everyday consumer privacy, rogue networks like First VPN provided malicious actors with the tools to "hide the origins of their attacks, deploy malware, and manage exfiltrated data," according to a <a href="https://home.treasury.gov/news/press-releases/sb0559" target="_blank" rel="nofollow">Treasury Department press release</a>.</p><p>As part of the same action, the Treasury also sanctioned Yegeniy Vladimirovich Silayev, a Belarusian national accused of selling "cryptors" to ransomware operators. </p><p>While Silayev is not directly affiliated with First VPN, his inclusion in the sanctions package highlights a broader strategy of targeting the entire cybercriminal supply chain. Cryptors are tools specifically built to disguise ransomware as harmless files, preventing security systems from detecting or deactivating the malware.</p><h2 id="a-haven-for-cybercriminals">A haven for cybercriminals</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:940px;"><p class="vanilla-image-block" style="padding-top:57.98%;"><img id="U3nMoaJ3iNrFx8Qwkwmw7d" name="Shutterstock_1050436496.jpg" alt="Code Skull" src="https://cdn.mos.cms.futurecdn.net/U3nMoaJ3iNrFx8Qwkwmw7d.jpg" mos="" align="middle" fullscreen="" width="940" height="545" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>The US Treasury's latest move is an update to an ongoing international operation against First VPN. </p><p>In a massive <a href="https://www.techradar.com/vpn/vpn-privacy-security/european-law-enforcement-forces-pull-the-plug-on-this-free-vpn-in-massive-cybercrime-crackdown-heres-all-we-know">May 2026 takedown</a>, a coordinated effort led by European law enforcement agencies and the FBI successfully seized the service's website and server infrastructure.</p><p>Prior to the takedown, Rashevskyi aggressively marketed First VPN on dark web forums. To lure cybercriminals, he promised total anonymity and boasted that the network "does not keep logs of users' identities or activities, and that it refuses to cooperate with law enforcement investigations into illegal activity originating from the servers it rents to customers".</p><p>According to the US Treasury, Rashevskyi went to great lengths to keep the operation running. He utilized false identities, such as "Maksim Sorin" and "Roman Chabanenko," to "buy infrastructure from companies that might otherwise refuse to do business with him because of complaints of abuse from internet service providers about illegal activity originating from 1VPNS servers".</p><h2 id="disrupting-the-cybercriminal-ecosystem">Disrupting the cybercriminal ecosystem</h2><p>This latest wave of sanctions was coordinated alongside the United Kingdom's Foreign, Commonwealth & Development Office (FCDO) and carries severe consequences for the designated individuals.</p><p>Under the new sanctions, all property and interests belonging to Rashevskyi and Silayev within the US are blocked, and US citizens are strictly prohibited from engaging in any transactions with them. Beyond the immediate financial freeze, OFAC sanctions serve as a massive reputational blow designed to choke off future revenue streams.</p><p>By focusing on the service providers and tool suppliers who facilitate these attacks, rather than just the ransomware operators themselves, authorities are aiming to maximize their impact and disrupt multiple gangs at once.</p><p>"Under President Trump's leadership, Treasury is using every available tool to disrupt the cybercriminal ecosystem and protect the American people," said Gene Lange, who is performing the duties of the Under Secretary for Terrorism and Financial Intelligence. "We will continue targeting the actors who enable ransomware attacks against Americans and our critical infrastructure".</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ White House launches 'Gold Eagle' cybersecurity clearinghouse to share and patch AI-discovered software flaws ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/white-house-launches-gold-eagle-cybersecurity-clearinghouse-to-share-and-patch-ai-discovered-software-flaws</link>
                                                                            <description>
                            <![CDATA[ 'Gold Eagle' scheme looks to centralize vulnerability identification and remediation for maximum efficiency. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dQ8QDDVQDMX7ftBUuZpt6A</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DFBL65zBbMWH2hNHzTrEuk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jul 2026 09:07:37 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DFBL65zBbMWH2hNHzTrEuk-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Donald Trump sings executive order]]></media:description>                                                            <media:text><![CDATA[Donald Trump sings executive order]]></media:text>
                                <media:title type="plain"><![CDATA[Donald Trump sings executive order]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DFBL65zBbMWH2hNHzTrEuk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>White House, Treasury, DHS and DoW come together to launch Gold Eagle scheme</strong></li><li><strong>The initiative will prevent duplicated work and prioritize vulnerability remediation</strong></li><li><strong>Gold Eagle will also help to identify which systems could be at risk</strong></li></ul><p>The US Government has <a href="https://www.whitehouse.gov/releases/2026/07/white-house-launches-gold-eagle-initiative-for-unprecedented-cybersecurity-vulnerability-coordination/" target="_blank">launched</a> Gold Eagle, a new clearinghouse which looks to centralize vulnerability discovery and remediation against a backdrop of evolving AI-powered security threats.</p><p>Gold Eagle will serve as a central hub between federal agencies, AI developers, open-source software developers and critical infrastructure companies, in a bid to increase the speed of vulnerability discovery and prevent major incidents from occurring in the first place.</p><p>The scheme came about under President Trump's June 2 2026 executive order 'Promoting Advanced Artificial Intelligence Innovation and Security' and represents collaboration between the Treasury, the DHS' Cybersecurity and Infrastructure Security Agency (CISA) and the Department of War.</p><h2 id="us-gold-eagle-scheme-addresses-growing-vulnerability-exploitations">US Gold Eagle scheme addresses growing vulnerability exploitations</h2><p>Under the scheme, vulnerabilities scanning will happen centrally to ensure multiple organizations aren't independently repeating the same work. Gold Eagle will also identify which software, networks and critical infrastructure could be at risk, before coordinating fixes. The White House described the scheme as a "force multiplier."</p><p>Although AI is largely to blame for the increase in attacks, Gold Eagle is set to fight fire with fire by employing AI to identify bugs too, using models like Anthropic's Mythos.</p><p>"Through this strategic partnership, we will expand existing security measures to safeguard software and networks in the 21st century and continue to promote advancements in artificial intelligence," DHS Secretary Markwayne Mullin wrote.</p><p>The concept of a dedicated clearinghouse centralizes vulnerability management to ensure the right bugs are being prioritized and to cut through the noise of lower-quality reports. Its assistance will most likely be felt by the open-source community, which has limited resources and financial backing to identify and fix issues as effectively as enterprise software vendors.</p><p>"Under the leadership of President Trump, we are bringing a wartime footing to the cyber domain to relentlessly patch vulnerabilities," Secretary of War Pete Hegseth added.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts get Google, Microsoft to pull trusted ModHeader with 1.6 million installs after finding it could harvest all kinds of data ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-get-google-microsoft-to-pull-trusted-modheader-with-1-6-million-installs-after-finding-it-could-harvest-all-kinds-of-data</link>
                                                                            <description>
                            <![CDATA[ Visited domains were being exfiltrated to a third-party server, seemingly under a Chinese actor's control. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wBogsTgqZ6B4E5RonumGgf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/97XMVxvuGbBvxfxdd8VJqH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Jul 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/97XMVxvuGbBvxfxdd8VJqH-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Chrome, Edge, Safari, and Firefox browser apps on a mobile phone]]></media:description>                                                            <media:text><![CDATA[Chrome, Edge, Safari, and Firefox browser apps on a mobile phone]]></media:text>
                                <media:title type="plain"><![CDATA[Chrome, Edge, Safari, and Firefox browser apps on a mobile phone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/97XMVxvuGbBvxfxdd8VJqH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Stripe OLT found ModHeader v7.0.18 carried a hidden spyware SDK, exfiltrating visited domains daily to a Chinese‑owned server and acting as adware</strong></li><li><strong>The extension had 1.6M downloads across Chrome and Edge before being pulled but installed endpoints remain at risk</strong></li><li><strong>Researchers urge defenders to identify and remove existing installations, as removal from stores does not automatically remediate compromised devices</strong></li></ul><p>ModHeader, a trusted Chrome and Edge browser extension with more than 1.6 million downloads, was found to be malicious, apparently sending sensitive data to a Chinese-owned server, and has since been pulled on both repositories. </p><p>Security researchers Stripe OLT revealed the news in a new <a href="https://stripeolt.com/knowledge-hub/threat-research/chrome-extension-hidden-data-exfiltration-900k-users/" target="_blank">report</a>, outlining how a ModHeader build v7.0.18 carried a hidden <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">spyware</a> SDK. </p><p>As per Stripe OLT, the spyware collects domains users visit, encrypts the data with AES-GCP, and then sends it - once a day - to a remote server. The collector was found inactive by default, but the required code, encryption key, and upload schedule were all already embedded in the extension.</p><h2 id="links-to-chinese-actors">Links to Chinese actors</h2><p>Researchers found no command-and-control functionality, which means the server only receives the stolen data and cannot communicate back. The extension also worked as an adware, displaying ads and opening advertising tabs on updates, including on enterprise-managed devices.</p><p>The researchers attributed the attack, albeit with low confidence, to a Chinese-speaking threat actor. The exfiltration domain routes emails through Lark, which is a suite common with Chinese-speaking teams, it was said. They also found Chinese strings in the code, and said that the listing ships a Simplified Chinese locale. </p><p>ModHeader is a Chrome and Edge <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> extension that allows users to modify HTTP request and response headers sent between their browser and websites. Developers and security researchers use it to test APIs, troubleshoot applications, and simulate different environments. It has around 900,000 users on Chrome, and another 700,000 on Edge. </p><p>According to <a href="https://thehackernews.com/2026/07/google-and-microsoft-pull-modheader.html" target="_blank"><em>The Hacker News</em></a>, Microsoft pulled the tool from its repository on June 3 2026, followed by Google a week later, on July 10. </p><p>“Following our disclosure, Google has removed the extension from the Chrome Web Store,” Stripe OLT concluded. “We welcome this action, but removal from the store does not automatically remediate endpoints where the extension was already installed, so defenders should continue to identify and remove existing installations.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'A single entry point can rapidly expand to greater enterprise impacts': Microsoft introduces changes to tackle ShinyHunters ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/a-single-entry-point-can-rapidly-expand-to-greater-enterprise-impacts-microsoft-introduces-changes-to-tackle-shinyhunters</link>
                                                                            <description>
                            <![CDATA[ Greater visibility, better detection, and stronger governance over OAuth-connected applications should mitigate ShinyHunters attacks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TkKBJ5zNq7m8xK9Fpcnpvg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cAewSdXkrLEUsD8muVzGX9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Jul 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cAewSdXkrLEUsD8muVzGX9-1280-80.jpg">
                                                            <media:credit><![CDATA[gguy / Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft logo outside building]]></media:description>                                                            <media:text><![CDATA[Microsoft logo outside building]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft logo outside building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cAewSdXkrLEUsD8muVzGX9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>ShinyHunters abused OAuth trust in Salesforce by tricking users and later compromising SaaS integrations, stealing tokens to access hundreds of customer environments</strong></li><li><strong>Reports suggested up to 700 victims; attackers exfiltrated data via legitimate APIs, making activity appear normal and persistent</strong></li><li><strong>Microsoft responded with Defender for Cloud Apps upgrades, adding richer telemetry, near‑real‑time detection, and stronger governance over OAuth‑connected applications</strong></li></ul><p>The ShinyHunters cybercrime group were so creative in breaking into corporate Salesforce environments that they forced Microsoft’s hand, making the company introduce new security upgrades just to address the attacks. </p><p>Microsoft has <a href="https://www.microsoft.com/en-us/security/blog/2026/07/13/defending-saas-based-applications-against-shinyhunters-oauth-abuse/" target="_blank">revealed</a> it is focusing on improving visibility into OAuth-connected applications and strengthening governance over third-party integrations in <a href="https://www.techradar.com/best/best-antivirus" target="_blank">Microsoft Defender</a> for Cloud Apps. The changes fall into two main categories: Improved detection and investigation, and new posture and governance capabilities.</p><p>It makes sense, given that some reports claimed as many as 700 victims of the year-long campaign.</p><h2 id="changes-and-improvements">Changes and improvements</h2><p>But first, a little context: In August 2025, it was reported that ShinyHunters operatives were calling their targets on the phone, claiming to be IT support, and convincing them to authorize a seemingly legitimate Salesforce Data Loader application. This app was, in fact, controlled by the attackers and requested OAuth permissions which allowed them to access Salesforce data through official APIs. </p><p>Since everything happened through legitimate authentication and API calls, the activity looked like normal user behavior.</p><p>In the following months, the campaign evolved. Instead of tricking individual employees, ShinyHunters compromised third-party SaaS providers that integrated with Salesforce, including <a href="https://www.techradar.com/pro/security/salesloft-breached-to-steal-oauth-tokens-for-salesforce-data-theft-attacks" target="_blank">Salesloft's Drift</a> integration, Gainsight, and later Klue. </p><p>By stealing OAuth tokens or integration secrets from these vendors, they accessed hundreds of downstream customer Salesforce environments without interacting with each customer individually. </p><p>At one point, Google told reporters it was aware of <a href="https://en.wikipedia.org/wiki/ShinyHunters" target="_blank">more than 700 potentially impacted organizations</a>.</p><p>“Microsoft consulted with Salesforce to improve granularity in telemetry for Defender for Cloud Apps with near-real-time detection, offering connected application attribution and expanded application permission insights,” the company said in a new report. “This activity was not the result of a vulnerability inherent to Salesforce. Rather, the threat actors abused trusted OAuth relationships for unauthorized access, data exfiltration, and persistence.”</p><p>In other words, Microsoft enabled greater visibility into OAuth-connected applications and their activity, allowed for better detection of suspicious API and OAuth behavior through richer telemetry and correlation, and now provides stronger governance of connected apps through permission analysis, risk scoring, and lifecycle management.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US and security allies warn Russian attacks on critical infrastructure are ramping up against 'poorly configured and vulnerable networking devices worldwide' ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/us-and-security-allies-warn-russian-attacks-on-critical-infrastructure-are-ramping-up-against-poorly-configured-and-vulnerable-networking-devices-worldwide</link>
                                                                            <description>
                            <![CDATA[ Russians are targeting misconfigured routers running in critical infrastructure firms. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wjQv5EkWkmzmzH5MBDmBmJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kqDd8hw4VtrskmqGDY5fKa-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Jul 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/kqDd8hw4VtrskmqGDY5fKa-1280-80.png">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person plugging an Ethernet cable into a router]]></media:description>                                                            <media:text><![CDATA[A person plugging an Ethernet cable into a router]]></media:text>
                                <media:title type="plain"><![CDATA[A person plugging an Ethernet cable into a router]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kqDd8hw4VtrskmqGDY5fKa-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>NSA, FBI, CISA, and 15 allied agencies warn Russia’s FSB Center 16 is exploiting weak/default credentials and old Cisco flaws to compromise critical infrastructure devices</strong></li><li><strong>Advisory highlights CVE‑2018‑0171 (Smart Install DoS/RCE) and CVE‑2008‑412813 (CSRF in Cisco IOS 12.4) as examples of vulnerabilities still being abused</strong></li><li><strong>TTPs overlap with Chinese groups but attribution points to Russian actors like Berserk Bear and Energetic Bear; full IoCs and mitigations were published in the joint advisory</strong></li></ul><p>Russian state-sponsored threat actors are continuously targeting broken and poorly configured networking devices belonging to critical infrastructure providers all around the world, a <a href="https://www.ic3.gov/CSA/2026/260713.pdf" target="_blank" rel="nofollow">joint security advisory</a> published by the US National Security Agency (NSA) and more than a dozen other agencies has warned.</p><p>As per the advisory, hackers working for the Russian Federal Security Service (FSB) Center 16 are constantly scanning for <a href="https://www.techradar.com/news/networking/routers-storage/best-router-9-top-wireless-routers-on-test-1090523" target="_blank">routers</a> and other internet-connected devices that can be accessed with “common or default” login credentials. </p><p>Once found, these devices are instructed to copy device configuration files and later exfiltrate them via the Trivial File Transfer Protocol to servers under their control. </p><h2 id="berserk-bear-and-salt-typhoon">Berserk Bear and Salt Typhoon</h2><p>In cases where default or weak credentials don’t work, the threat actors also try to exploit vulnerabilities. In the advisory, the agencies specifically mentioned two flaws in Cisco devices - CVE-2018-0171 and CVE-2008-412813. The former is an eight-year-old bug in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software that allows an unauthenticated, remote attacker to cause a denial of service (DoS) condition, or to execute arbitrary code.</p><p>The latter is an even older (18 years old) set of multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router that allows remote attackers to execute arbitrary commands.</p><p>Even though many of these tactics, techniques, and procedures (TTP) overlap with Chinese hackers Salt Typhoon, the agencies suggested they are primarily focusing on Russian hackers known as Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, or Static Tundra.</p><p>The joint advisory is co-authored by the NSA, FBI, and CISA, as well as 15 other agencies from Australia, the United Kingdom, Canada, New Zealand, Estonia, Finland, France, and Italy.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This new macOS infostealer poses as an Apple crash reporting tool to try and steal all your valuable data ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/this-new-macos-infostealer-poses-as-an-apple-crash-reporting-tool-to-try-and-steal-all-your-valuable-data</link>
                                                                            <description>
                            <![CDATA[ Researchers found a new piece of macOS malware grabbing passwords, crypto data, and more. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SbwjYKP7zxrLGTEJgE6gNe</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ctJuqMRzZN6mdeA4UPgdTd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Jul 2026 14:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ctJuqMRzZN6mdeA4UPgdTd-1280-80.jpg">
                                                            <media:credit><![CDATA[Herry Sucahya on Unsplash]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The menu bar running in macOS.]]></media:description>                                                            <media:text><![CDATA[The menu bar running in macOS.]]></media:text>
                                <media:title type="plain"><![CDATA[The menu bar running in macOS.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ctJuqMRzZN6mdeA4UPgdTd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Jamf researchers uncover “CrashStealer,” a notarized macOS infostealer disguised as Apple’s CrashReporter</strong></li><li><strong>Distributed via a fake site called “Werkbit Setup”, it bypasses Gatekeeper, installs a LaunchAgent</strong></li><li><strong>It then uses a fake password prompt to unlock Keychain, exfiltrating credentials, cookies, files, and data from 80 crypto wallets and 14 password managers</strong></li></ul><p>A new macOS infostealer has been spotted in the wild, masquerading as an Apple crash reporting tool, experts have warned.</p><p>Called CrashStealer, this C++ infostealer was designed to nab login credentials, keychain information, as well as data related to more than 80 cryptocurrency wallets.</p><p>Cybersecurity researchers Jamf published an in-depth <a href="https://www.jamf.com/blog/crashstealer-macos-infostealer-analysis/" target="_blank">report</a> on the malware, noting CrashStealer is most likely distributed via a fake software site that was only registered recently.</p><h2 id="unlocking-keychain">Unlocking Keychain</h2><p>Victims who land on the site (either via a social media recommendation or search engine results) need to know the PIN code before initiating the download. This was most likely done to avoid analyst scrutiny, as well as to increase perceived credibility and a sense of exclusivity.</p><p>Usually, apps downloaded from third-party sources are scanned by Gatekeeper, Apple’s built-in security system. However, Jamf says that this payload is delivered via a signed and Apple-notarized installer and distributed as a disk image named “Werkbit Setup”, which allowed it to bypass Gatekeeper without any warnings.</p><p>Those that download and run the program will get a binary named ‘CrashReporter.app’, which will create a LaunchAgent (‘com.apple.crashreporter.helper’), and will see a fake macOS password prompt.</p><p>That prompt unlocks the user’s Keychain where most of their secrets are stored (passwords, private cryptographic keys, and more) and then exfiltrates all information to a third-party server. </p><p>Besides Keychain data, the CrashReporter <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> also pulls browser credentials and cookies from most browsers, data from 80 cryptocurrency wallet extensions, 14 <a href="https://www.techradar.com/best/password-manager" target="_blank">password managers</a>, locally stored files, and more. </p><p>Jamf said CrashReporter overlaps, to some extent, with other known infostealers (AMOS, for example), but is still unique enough given its client-side encryption mechanism, as well as the native C++ implementation.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Japan's largest taxi operator Nihon Kotsu hit by cyberattack which forces systems to be shut down ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/japans-largest-taxi-operator-nihon-kotsu-hit-by-cyberattack-which-forces-systems-to-be-shut-down</link>
                                                                            <description>
                            <![CDATA[ Nihon Kotsu suffers malware attack, but there's no evidence of data exfiltration yet. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5vBZ3jEmoQgQq6pxgNJU6X</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JFKDCP2HdEKqSGJCkLNprB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Jul 2026 09:24:11 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JFKDCP2HdEKqSGJCkLNprB-1280-80.jpg">
                                                            <media:credit><![CDATA[Forcepint]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[IA y ciberseguridad]]></media:description>                                                            <media:text><![CDATA[IA y ciberseguridad]]></media:text>
                                <media:title type="plain"><![CDATA[IA y ciberseguridad]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JFKDCP2HdEKqSGJCkLNprB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Japan’s largest taxi operator confirms July 11 malware attack forcing shutdowns of its IT systems and disrupted dispatch and reservation services</strong></li><li><strong>Nihon Kotsu isolated networks, notified authorities, and brought in third‑party experts; customers were advised to use alternative taxi apps during the outage</strong></li><li><strong>No data leaks have been confirmed, but Nihon Kotsu warned it may disclose and notify affected parties if evidence of personal information exposure emerges</strong></li></ul><p>Japan’s largest taxi operator, Nihon Kotsu, hasconfirmed suffering a cyberattack which forced it to temporarily shut down parts of its IT infrastructure.</p><p>In a statement published on the company’s Japanese website, Nihon Kotsu said the attack took place in the early morning of July 11 - on a Saturday, when unnamed threat actors infected its devices with malware.</p><p>“We have recently discovered that our internal systems have been subjected to unauthorized external access (<a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware infection</a>),” the machine-translated statement reads. “We deeply apologize for the great inconvenience and concern caused to our customers, business partners, and all related parties due to this incident.”</p><h2 id="services-unavailable">Services unavailable</h2><p>As soon as it spotted the intrusion, Nihon Kotsu did what most companies do - shut down its network to prevent further damage, notified relevant law enforcement and data protection authorities, and brought in third-party experts to assess the damages and assist with the repairs.</p><p>The shutdown means some customer-facing services are unavailable: “As a result, the hire car web order and reservation management system, taxi dispatch service by phone, and some internal systems are temporarily unavailable,” the company said. </p><p>It advised its customers to use a different taxi app, which allows users to choose a taxi service to their liking. </p><p>So far, there is no evidence of any data exfiltration, or leaks to the dark web. However, the company did leave it as a possibility. </p><p>“At this time, no information leakage has been confirmed, but if any leakage or possibility of personal information of customers or related parties is newly discovered, we will promptly make official announcements and contact the affected parties individually in accordance with laws and regulations,” the company concluded.</p><p>Nihon Kotsu is Japan’s largest taxi operator, employing more than 18,000 people and running a fleet of more than 8,500 taxis and more than 2,000 chauffeur vehicles.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/japans-largest-taxi-operator-shuts-systems-after-cyberattack/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ransomware negotiator jailed for 70 months after he just helped infect victims with malware ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/ransomware-negotiator-hired-to-represent-victims-was-working-for-the-attackers</link>
                                                                            <description>
                            <![CDATA[ Ransomware negotiator served 70-month prison sentence, and will have to forfeit everything he's gained. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MUKmn9q7miZ37RfUnSqJGo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cJtFPyQYv7tobzbzvGKgSX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 13 Jul 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cJtFPyQYv7tobzbzvGKgSX-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ransomware]]></media:description>                                                            <media:text><![CDATA[Ransomware]]></media:text>
                                <media:title type="plain"><![CDATA[Ransomware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cJtFPyQYv7tobzbzvGKgSX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Ransomware negotiator Angelo Martino will serve 70 months in prison for secretly aiding BlackCat (ALPHV) attackers</strong></li><li><strong>Martino forfeits crypto proceeds, houses, cars, and boats, and must pay 10% of future salary after release</strong></li><li><strong>Martino was the third negotiator exposed; his co‑conspirators Ryan Clifford Goldberg and Kevin Tyler Martin previously received four‑year sentences for similar insider collusion</strong></li></ul><p>A ransomware negotiator who worked with the attackers behind his clients’ backs has been sentenced to almost six years in prison. </p><p>A sentencing memorandum published by the US government said 41-year-old Angelo Martino will spend the next 70 months in prison, and will also lose all of the cryptocurrency the attackers paid him for sharing insider information, as well as all of the houses, cars, and boats, he had bought with this money.</p><p>He will also have to pay 10% of any salary he earns after his release.</p><h2 id="asking-for-a-shorter-sentence">Asking for a shorter sentence</h2><p>In November 2025, it was reported that three men who worked as <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> negotiators to help victims minimize the damages of these attacks were actually <a href="https://www.techradar.com/pro/security/cybersecurity-experts-accused-of-carrying-out-their-own-attacks-using-dangerous-ransomware" target="_blank">agents for the dreaded BlackCat (ALPHV) ransomware collective</a>. </p><p>Over the next months, it was reported that the men - Ryan Clifford Goldberg of Georgia, Kevin Tyler Martin of Texas, and Angelo Martino of Land O'Lakes, Florida, not only did not help their victims, but actually infected some of them with ransomware, and later shared valuable insider information with other BlackCat affiliates, in order to maximize the payment.</p><p>Their victims included at least five companies: a medical device company from Florida (demanded $10 million in ransom, ended up paying around $1.2 million), a pharmaceutical company from Maryland, a doctor’s office and an engineering company in California, and a drone manufacturer based in Virginia.</p><p>While all three faced serious prison time (between 10 and 20 years), they received far less. Martin and Goldberg were each sentenced to four years in prison in April 2026, while Martino will spend five years and ten months behind bars. Martino pleaded guilty and asked for a 24-month sentence, stating he “provided substantial assistance that contributed to the indictment and conviction of two co-defendants.” It didn’t work. </p><p><em>Via </em><a href="https://arstechnica.com/tech-policy/2026/07/ransomware-negotiator-helped-attackers-extort-his-own-clients-gets-6-year-sentence/" target="_blank"><em>Ars Technica</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts say they were able to create a rogue agent in Google’s AI platform with just a single edit permission ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-say-they-were-able-to-create-a-rogue-agent-in-googles-ai-platform-with-just-a-single-edit-permission</link>
                                                                            <description>
                            <![CDATA[ One compromised agent could take over every other agent in that project, leading to chat logs access, and even data exfiltration. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">WK7ntVMLwUrjSriwsVPpeX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8vLsLeC4LHKgwTpJRXEWKZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 13 Jul 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8vLsLeC4LHKgwTpJRXEWKZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI]]></media:description>                                                            <media:text><![CDATA[AI]]></media:text>
                                <media:title type="plain"><![CDATA[AI]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8vLsLeC4LHKgwTpJRXEWKZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Varonis uncovered CVE‑level flaws in Google Cloud Dialogflow CX, where malicious Code Blocks in Playbooks could hijack agents, exfiltrate chat logs, and steal credentials</strong></li><li><strong>Shared Cloud Run environment with excess privileges meant one compromised agent could control all others in a project, with attacks virtually undetectable in Cloud Logging</strong></li><li><strong>Google patched the issue between April–June 2026; researchers advise reviewing audit logs, checking anomalous errors, and manually inspecting Code Blocks for unauthorized code</strong></li></ul><p>Researchers recently found a critical vulnerability in Google Cloud’s Dialogflow CX, allowing threat actors to take over different AI agents, access chat logs, and even exfiltrate sensitive data such as login credentials.</p><p>Dialogflow CX is Google Cloud’s conversational <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI platform</a> used to build many voice and text chatbots. This platform lets developers add Code Blocks, which are custom Python snippets, into conversation “Playbooks”. These blocks all execute inside a single Google-managed Cloud Run service, shared across all agents in a Google Cloud Platform project. </p><p>Security researchers Varonis <a href="https://www.varonis.com/blog/rogue-agent-dialogflow-attack" target="_blank">said</a> they discovered a critical vulnerability in which the theoretical attacker didn’t need broad admin access. With permission to edit a single chatbot’s settings, they would be able to plant malicious code relatively easily. The Cloud Run environment had no code restrictions, Varonis further explained, but had a writable filesystem, public internet egress, and ran with excess privileges. Key files could have been overwritten entirely, it was added.</p><h2 id="google-issues-a-fix">Google issues a fix</h2><p>As a result, the attacker had access to full conversation history and session state. They could call internal functions and fake LLM-generated replies which, they claim, could lead to phishing and credential theft. </p><p>Since the environment is shared per-project, one compromised agent could take over every other agent in that project, and since Cloud Logging doesn’t capture the file overwrite or injected logic, the attack would be "virtually undetectable."</p><p>Varonis reported the issue to Google in November 2025, and the latter came back with an initial fix in April 2026. However, the issue had not been fully resolved until June 2026. </p><p>In the report, the researchers said there is no evidence of in-the-wild exploitation attempts and advises customers to review DATA_WRITE audit logs for Playbooks.UpdatePlaybook calls, check for anomalous Sessions.DetectIntent errors, and manually inspect each agent's Code Blocks for leftover unauthorized code.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Vibe coded threats shift again — hackers are using AI chatbots to write malware using natural language ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/vibe-coded-threats-shift-again-hackers-are-using-ai-chatbots-to-write-malware-using-natural-language</link>
                                                                            <description>
                            <![CDATA[ How do you spot an attack when signatures and behaviors can no longer be used? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7FaiGdV8mykwMcDLSkT3n9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/G8QNviZt3KrDbfWVANJrNM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 13 Jul 2026 15:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/G8QNviZt3KrDbfWVANJrNM-1280-80.jpg">
                                                            <media:credit><![CDATA[Elchinator from Pixabay ]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[malware]]></media:description>                                                            <media:text><![CDATA[malware]]></media:text>
                                <media:title type="plain"><![CDATA[malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/G8QNviZt3KrDbfWVANJrNM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Huntress analyzed AI‑generated malware “Untitled1.ps1,” a noisy custom AD enumeration tool likely built by low‑skilled attackers using generative AI</strong></li><li><strong>Attackers paired it with s5cmd for rapid data exfiltration and SharpShares.exe for share enumeration before being detected and removed</strong></li><li><strong>Report warns AI “vibe coding” lowers barriers for cybercrime, producing unique payloads that evade signature‑based defenses, requiring behavioral analytics to catch attack lifecycles</strong></li></ul><p>“Unsophisticated” cybercriminals can now easily write malicious code using Artificial Intelligence (AI) and run devastating data breach attacks with speed, forcing defenders to rethink their strategies, researchers have claimed. </p><p>Security experts Huntress thoroughly investigating a piece of AI-written <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, and <a href="https://www.huntress.com/blog/ai-coded-malware-vibe-coding-active-directory" target="_blank">explained</a> how the bespoke, AI-generated payload was a “highly aggressive, noisy, custom-built AD enumeration tool.”</p><p>Since cybercriminals are generally careful not to make too much noise and to try and do their bidding without raising any alarms, the researchers hint this was the work of a low-skilled attacker.</p><h2 id="significant-challenge">Significant challenge</h2><p>The malware, labeled Untitled1.ps1, was designed to map the Active Directory environment and apparently, it did its job well. In the next step, the crooks deployed a legitimate high-speed command-line tool for Amazon S3 operations called s5cmd which, according to Huntress, is often used for data exfiltration.</p><p>Before being spotted and kicked out, the attackers also deployed a known enumeration tool called SharpShares.exe, filtering common administrative shares while hunting for further user-accessible data repositories. </p><p>The move from off-the-shelf frameworks to custom, bespoke AI tools is a “significant challenge” for the defenders, Huntress warns. </p><p>“Historically, AVs and EDR platforms have relied heavily on file hashes and static string signatures,” they say. “Vibe-coded scripts are inherently unique. Untitled1.ps1 has never existed before and will likely never be compiled in this exact configuration again.”</p><p>As a result, defenders must focus on the “fundamental behaviors of the attack lifecycle.” AI can change the code syntax, they’re saying, but cannot change the underlying mechanics of <a href="https://www.techradar.com/pro/best-active-directory-documentation-tool-of-year" target="_blank">Active Directory</a> enumeration. </p><p>“Vibe coding lowers the barrier to entry for cybercrime, allowing unsophisticated actors to generate highly capable, evasive tooling on the fly,” the researchers concluded. “While the code itself may be messy, over-engineered, and filled with AI hallmarks like left-behind comments, the threat it poses is very real. To combat this, defenders must abandon rigid, signature-based thinking and embrace behavioral analytics to catch the underlying actions that no LLM can hide.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'Cryptomining can be a lucrative post-compromise activity in cloud environments': Experts warn AI gateways connected to Amazon Bedrock are being hijacked to steal crypto ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/cryptomining-can-be-a-lucrative-post-compromise-activity-in-cloud-environments-experts-warn-ai-gateways-connected-to-amazon-bedrock-are-being-hijacked-to-steal-crypto</link>
                                                                            <description>
                            <![CDATA[ Researchers found a new spin on an old attack, as AI gateways are used to enable cryptocurrency mining. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5yAdUAUnbCTdDiEkgv6JYN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 13 Jul 2026 14:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:description>                                                            <media:text><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:text>
                                <media:title type="plain"><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Darktrace reports cryptojacking via a compromised AI gateway (LiteLLM‑Proxy on AWS Bedrock), breached through exposed SSH and abused with XMRig mining</strong></li><li><strong>Attackers also showed suspicious IAM activity, hinting at possible cloud credential misuse, with connections traced to Vietnam</strong></li><li><strong>Experts warn AI gateways concentrate privileged access, urging strict port closures, least‑privilege roles, and control‑plane monitoring to reduce blast radius</strong></li></ul><p>If you are using AI gateways as part of your tech stack, be wary - they are being leveraged in cryptojacking attacks, experts have warned.</p><p>Cybersecurity researchers Darktrace have published a new <a href="https://www.darktrace.com/blog/when-ai-infrastructure-becomes-part-of-the-attack-surface" target="_blank" rel="nofollow">report</a> on a cloud-hosted AI gateway, connected to Amazon Bedrock, which was compromised and used for cryptocurrency mining. </p><p>An AI gateway is a piece of software that runs between users or applications and one or more AI models. It is not unlike a reverse proxy or an API gateway, but just for AI services. In this case, an Amazon EC2 instance running an AI gateway called LiteLLM-Proxy was given centralized access to large language models (LLM) hosted on Amazon Bedrock (AWS’ fully managed generative AI platform).</p><h2 id="shady-vietnamese-accounts">Shady Vietnamese accounts</h2><p>According to Darktrace, threat actors gained access most likely through a brute-force attack, since the EC2 instance was configured to accept SSH connections from anywhere on the internet. </p><p>After breaking in, they downloaded XMRig, by far the most popular cryptocurrency mining program. Within minutes, the instance started making repeated encrypted connections to a cryptocurrency mining pool, which also set off Darktrace’s alarms and spotted the attack. </p><p>Soon after, Darktrace spotted more suspicious activities, this time involving an AWS <a href="https://www.techradar.com/best/best-identity-management-software" target="_blank">Identity and Access Management </a>(IAM) user. This account started giving out unexpected and previously unused commands, such as enumerating and invoking Amazon Bedrock foundation models, or trying to set up a new IAM user account. </p><p>The final red flag was the IP address of that user - tracing back all the way to Vietnam. Darktrace said there was insufficient evidence to conclusively link the IAM activity with the earlier compromise of the AI gateway, but stressed that the behavior could indicate attempted cloud credential misuse.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Lidl customers across Europe hit in suspected data breach - here's what we know ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/lidl-customers-across-europe-hit-in-suspected-data-breach-heres-what-we-know</link>
                                                                            <description>
                            <![CDATA[ Lidl customers in three countries have had some of their data stolen - but so far, it hasn't surfaced anywhere. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KMsx6Xf64MS7G3HiiDoPWR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/k4JPVL63V4qnekffLcuCnV-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 13 Jul 2026 10:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/k4JPVL63V4qnekffLcuCnV-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Lidl store logo]]></media:description>                                                            <media:text><![CDATA[Lidl store logo]]></media:text>
                                <media:title type="plain"><![CDATA[Lidl store logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/k4JPVL63V4qnekffLcuCnV-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Lidl confirms cyberattack at third-party IT service provider that exposed customer data including names, phone numbers, emails, dates of birth, and customer numbers</strong></li><li><strong>Passwords, payment details, and addresses were not affected, but the company warns of phishing risks and urges vigilance against identity fraud attempts</strong></li><li><strong>Incident was contained quickly, reported to authorities, and investigated by forensic experts; Lidl operates ~12,900 stores across 32 countries</strong></li></ul><p>Lidl is warning its customers of a cyberattack which may have affected some of their personal information stored with the company.</p><p>In a data breach notification published on its Netherlands, Belgium, and Germany websites, the German discount supermarket chain said an IT security incident at one of its IT service providers affected some of the data stored by Lidl Online Shop customers. </p><p>“We were informed of this incident at the beginning of the week,” a machine-translated notification reads. “Despite high IT security standards, unknown persons briefly gained access to a separately stored file with customer data and part of the data was stolen from it. The system of the online shop itself is not affected.”</p><h2 id="unknown-impact">Unknown impact</h2><p>Lidl said that the unnamed miscreants walked away with people’s full names, phone numbers, email addresses, dates of birth, and customer numbers. Passwords, billing and delivery addresses, bank details, and other payment information, was allegedly not stolen. Customer accounts remained unaffected, as well.</p><p>However, the company is urging its customers to remain vigilant, since there is a high chance the crooks will use the data to send personalized <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">phishing emails</a>. </p><p>“Although we currently have no concrete evidence of misuse of data, we warn you about possible phishing attempts or identity fraud as a precaution,” Lidl said. </p><p>The company did not say which IT service provider was targeted, or how many people are affected. It merely stated that the company “responded immediately” and “took necessary steps” to restore the full security of the affected systems. The company also filed a report with the relevant authorities, and called in IT forensic experts to investigate the incident. </p><p>Local authorities, such as the Dutch Data Protection Authority, or the Belgian “competent supervisory authority for data protection” were notified, as well.</p><p>Lidl operates around 12,900 stores across 32 countries in Europe and the United States.</p><p><em>Via </em><a href="https://cybernews.com/security/lidl-bank-details-risk-security-fail/" target="_blank"><em>Cybernews</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ransomware attacks against education sector rise 16% in one year becoming the new favorite target — and reckless GenAI use could be to blame ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/ransomware-attacks-against-education-sector-rise-16-percent-in-one-year-becoming-the-new-favorite-target-and-reckless-genai-use-could-be-to-blame</link>
                                                                            <description>
                            <![CDATA[ Most of the attacks took place in Latin America, while Africa experienced a decrease. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">AnUWAn7r2cjThe5L2zRgdF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cJtFPyQYv7tobzbzvGKgSX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Jul 2026 19:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cJtFPyQYv7tobzbzvGKgSX-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ransomware]]></media:description>                                                            <media:text><![CDATA[Ransomware]]></media:text>
                                <media:title type="plain"><![CDATA[Ransomware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cJtFPyQYv7tobzbzvGKgSX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Check Point Research reports education faced 4,816 weekly ransomware attacks in June 2026, up 16% YoY, keeping it the most targeted sector</strong></li><li><strong>Risks stem from open networks, thin budgets, and reckless GenAI use, with 1 in 26 enterprise prompts leaking sensitive data and 85% of orgs affected</strong></li><li><strong>Latin America saw the sharpest rise (27%), while government and telecoms also absorbed heavy volumes, showing attackers’ focus on high‑exposure industries</strong></li></ul><p>Every week in June, organizations in the education industry around the world faced 4,816 ransomware attacks. This is up 16% compared to the same month last year, and means this sector remains the most popular target among cybercriminals.</p><p>This is according to “A New Ransomware Leader Emerges as June 2026 Attack Volumes Climb Worldwide”, a new in-depth report on the state of ransomware, published by security experts Check Point Research (CPR).</p><p>As per CPR’s new paper, education is a popular target because of “open campus networks, constant device turnover, and thin security budgets”. In other words, it’s a low-hanging fruit, especially compared to other industries like government, technology, or healthcare. But these are not the only reasons why hackers target education more than any other industry. It is also because of how employees behave which, by using GenAI recklessly, substantially increases security risk. </p><h2 id="latin-america-bearing-the-brunt">Latin America bearing the brunt</h2><p>“It is about what employees place into prompts: customer records, internal documents, infrastructure details, legal material, financial data, or HR information that may be copied into public or unmanaged GenAI tools,” CPR explains. </p><p>“1 in every 26 GenAI prompts from enterprise networks carried a high risk of sensitive data leakage, equal to a global exposure rate of 3.9%,” the paper reads. “85% of organizations that regularly use GenAI tools were affected by high-risk prompt activity,” and “a further 27% of prompts contained potentially sensitive information.</p><p>This mostly affects organizations in Latin America who reported, on average, 3,501 weekly attacks (up 27% compared to June 2025). APAC followed at 3,060 (up 5%), and Africa posted 3,008 weekly attacks (down 9%). </p><p>Besides education, <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> operators are also targeting government institutions (2,836 weekly attacks - up 5%), and telecoms (2,835 weekly attacks - up 13%). </p><p>“Together these three sectors continue to absorb a disproportionate share of global attack volume, a pattern that has held steady across recent months even as the specific numbers shift,” CPR concluded.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft discovers new multi-malware package 'GigaWiper' capable of deploying wipers and ransomware ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/microsoft-discovers-new-multi-malware-package-gigawiper-capable-of-deploying-wipers-and-ransomware</link>
                                                                            <description>
                            <![CDATA[ One wiper can destroy a computer in different ways, but it can also spy on users. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6JU6gwuxmJ5p8jKNCQnPq5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Jul 2026 16:50:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[hacker hands at work with  interface around]]></media:description>                                                            <media:text><![CDATA[hacker hands at work with  interface around]]></media:text>
                                <media:title type="plain"><![CDATA[hacker hands at work with  interface around]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft warns of “GigaWiper,” a destructive malware attributed to Iranian group CyberAv3ngers that combines multiple variants into one</strong></li><li><strong>It can wipe drives, encrypt files with a fake ransomware extension, or overwrite Windows partitions, while also spying via screenshots, VNC sessions, and system data theft</strong></li><li><strong>The malware hides under fake OneDrive tasks and registry keys, showing both espionage and sabotage capabilities with no recovery path for victims’ data</strong></li></ul><p>Microsoft is warning about a new piece of malware called GigaWiper, which can spy on people’s computers and then destroy them entirely, in different ways.</p><p>It was built by mashing different <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> variants into one, and it seems to be the work of Iranian state-sponsored threat actors called CyberAv3ngers. The hackers also took a little cheeky dig at Microsoft, through the malware’s obfuscation mechanism.</p><p>As Microsoft <a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="nofollow">explained</a>, GigaWiper can overwrite the physical drive and wipe the partition table, destroying the contents of the disk directly. It can also encrypt all files on the drive, add a .candy extension, and change the desktop wallpaper to show a warning. This ransomware approach does not share a ransom note, and does not generate a decryption key, so there is nothing to pay, and no way to decrypt the files - they are gone for good, just giving victims false hope.</p><h2 id="spying-on-the-victims">Spying on the victims</h2><p>Finally, the third method goes straight for the Windows drive, overwriting it multiple times with different data patterns. </p><p>Besides bricking the disk, GigaWiper can also spy on its victims by grabbing screenshots, recording the screen, or opening a VNC session to either stream someone else’s work, or allow the attackers to use the mouse and keyboard. The malware can also extract system data, manage programs and services, modify the registry, and more. </p><p>But the cheekiest feature is how it hides. It schedules a task called OneDrive Update and tracks itself in a registry key called OneDrive\Environment. Perhaps the attackers assumed no one really pays attention to <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">OneDrive</a>, and thus the malware could stay out of sight for longer. </p><p>Speaking of the attackers, Microsoft does not name them, but most of the components mashed together to form GigaWiper were previously attributed to CyberAv3ngers, a group linked to Iran's Islamic Revolutionary Guard Corps.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ $293 million seized and 5,811 arrests made in huge anti-scam and fraud action by Interpol and law enforcement agencies across 97 countries ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/usd293-million-seized-and-5-811-arrests-made-in-huge-anti-scam-and-fraud-action-by-interpol-and-law-enforcement-agencies-across-97-countries</link>
                                                                            <description>
                            <![CDATA[ After more than three months, Interpol says Operation First Light 2026 is now concluded. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Q9MKBftnkj8r88cPPF9GmM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kMQVGNaXFmvhNxH6wp5LUh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Jul 2026 14:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kMQVGNaXFmvhNxH6wp5LUh-1280-80.jpg">
                                                            <media:credit><![CDATA[ Say thanks! Give a shoutout to Jefferson Santos on social or copy the text below to attribute.  Photo by Jefferson Santos on Unsplash]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[shady person sitting at a computer.]]></media:description>                                                            <media:text><![CDATA[shady person sitting at a computer.]]></media:text>
                                <media:title type="plain"><![CDATA[shady person sitting at a computer.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kMQVGNaXFmvhNxH6wp5LUh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Interpol’s Operation First Light 2026 spanned 97 countries, leading to 5,811 arrests, $239M seized, and 31,014 bank accounts blocked</strong></li><li><strong>Authorities analyzed 152,808 cases, identified 15,606 suspects, and uncovered scams ranging from BEC to money laundering, with victims exceeding 142,000 globally</strong></li><li><strong>Notable busts included a fake Brazilian police station in Eswatini, crypto laundering in Thailand, and scam centers in Palau, highlighting the scale and diversity of the crackdown</strong></li></ul><p>Interpol and various national law enforcement agencies arrested more than 5,800 people and seized hundreds of millions of dollars in one of the largest crackdowns on cybercrime to date.</p><p>In an <a href="https://www.interpol.int/News-and-Events/News/2026/Over-5-800-arrests-USD-293-million-intercepted-in-global-fraud-bust" target="_blank" rel="nofollow">announcement</a>, Interpol said that it kicked off Operation First Light 2026 on January 15 and concluded it on April 30, 2026. Following an “initial period” of gathering intelligence and exchanging it among partners, police forces in 97 countries and territories started raiding premises, seizing digital equipment and cash, and arresting suspects.</p><p>In total, 5,811 individuals were arrested, and $239 million in illicit assets intercepted. During Operation First Light 2026, various police forces analyzed 152,808 cases, had 31,014 bank accounts blocked, and 99 Notices and Diffusions issued.</p><h2 id="a-replica-of-a-police-station">A replica of a police station</h2><p>Besides the arrests, the law enforcement firms also identified 15,606 suspects, which could lead to even more arrests in the coming months.</p><p>Interpol did not dismantle a single global operation here. Cases varied from money laundering, to scams and identity theft, to business email compromise, and more. </p><p>In one, particularly brazen campaign, police in Eswatini seized a “realistic replica of a Brazilian police station, complete with fake uniforms, signage and equipment”. </p><p>“Posing as Brazil’s Federal Police via video call, the scammers deceived their targets into believing they were victims of a crime, tricking them into transferring funds for “safekeeping,” which were then stolen,” Interpol explained. In this instance, police arrested 82 people and seized 240 electronic devices. </p><p>Two people were arrested in Thailand, including a 20-year-old man who allegedly processed more than $122.5 million in various cryptocurrencies in 10 months. Authorities in Palau, on the other hand, deported 22 individuals for their role in two connected scam centers being conducted from hotels. </p><p>Interpol said that during the operation it identified more than 142,000 victims globally.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Devious phishing campaign hijacks a genuine Meta business feature to send scam emails — as they really do come from Meta's own address ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/devious-phishing-campaign-hijacks-a-genuine-meta-business-feature-to-send-scam-emails-as-they-really-do-come-from-metas-own-address</link>
                                                                            <description>
                            <![CDATA[ Meta has put a stop to this attack, after adding additional safeguards. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">YMwzd7Y6gc57GRuPNGbYJm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iiobK7D8pysDnhkkAGDsgH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Jul 2026 13:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iiobK7D8pysDnhkkAGDsgH-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / mundissima ]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Silhouette of smartphone with Facebook, Messenger, WhatsApp, Instagram, Oculus apps and blurred META logo on background]]></media:description>                                                            <media:text><![CDATA[Silhouette of smartphone with Facebook, Messenger, WhatsApp, Instagram, Oculus apps and blurred META logo on background]]></media:text>
                                <media:title type="plain"><![CDATA[Silhouette of smartphone with Facebook, Messenger, WhatsApp, Instagram, Oculus apps and blurred META logo on background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iiobK7D8pysDnhkkAGDsgH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Huntress uncovers phishing campaign abusing Meta’s business account email infrastructure and impersonating the Meta Agency Partner Program</strong></li><li><strong>Victims were tricked into handing over credentials, which attackers exfiltrated to Telegram for account takeover, scam ads, and targeted phishing</strong></li><li><strong>Meta has since added guardrails that killed the campaign; Huntress published IoCs to help organizations detect related activity</strong></li></ul><p>Hackers are abusing one, and impersonating another legitimate Meta service, to try and steal login credentials for people’s business accounts with the company.</p><p>Meta, the owner of Facebook, Instagram, WhatsApp, and more, allows businesses to set up separate accounts and talk to each other. The emails sent from one to another pass through the company’s infrastructure, meaning they are shown as coming from Meta itself.</p><p>However up until recently, hackers were abusing this fact to send phishing emails that landed directly into their victims’ inboxes, security researchers Huntress <a href="https://www.huntress.com/blog/meta-business-manager-phishing" target="_blank" rel="nofollow">explained</a>. The company even tried to curb this by hardcoding a disclaimer that email senders are not part, or affiliated with, Meta, but crooks found creative ways around this, as well.</p><h2 id="spending-money">Spending money</h2><p>The phishing emails redirected victims to landing pages outside Meta’s ecosystem. These pages were designed to mimic Meta Agency Partner Program, a legitimate initiative that connects businesses with professionals in social media management work.</p><p>Those who would fail to see the ruse would end up trying to log into their accounts, instead just sharing their <a href="https://www.techradar.com/best/password-manager" target="_blank">login credentials</a> with the attackers. The secrets would get exfiltrated to a Telegram account under the threat actors’ control, which they could later use for different things, from phishing to malvertising. </p><p>“Threat actors can leverage Meta business accounts to spend the victim's money on malicious or scam advertising, or they can take over the account entirely, changing the recovery methods and password, and leverage the account to transmit more targeted attacks at the business' customers or social media followers.” the researchers explained.</p><p>Over the last couple of months, the campaign evolved and changed, using different lures and mechanics, but keeping the same end goal. However, Meta has effectively killed it by adding additional guardrails that now make it impossible to run.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This malicious Google Notes extension just wants to sneakily steal all your crypto ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/this-malicious-google-notes-extension-just-wants-to-sneakily-steal-all-your-crypto</link>
                                                                            <description>
                            <![CDATA[ Another clipboard jacker was found in the wild, on the prowl for people's crypto. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TgqEFku9ZNa9fNUkZbYTj9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VnoVVXTmAmxSBYBe4LUwVW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Jul 2026 11:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VnoVVXTmAmxSBYBe4LUwVW-1280-80.jpg">
                                                            <media:credit><![CDATA[vjkombajn/Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image credit: Pixabay/vjkombajn]]></media:description>                                                            <media:text><![CDATA[Cryptocurrencies]]></media:text>
                                <media:title type="plain"><![CDATA[Cryptocurrencies]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VnoVVXTmAmxSBYBe4LUwVW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>McAfee flags “Silent Swap,” a malicious Chromium extension disguised as Google Notes that secretly hijacks crypto transactions</strong></li><li><strong>It works as a clipboard jacker, swapping copied wallet addresses with attacker‑controlled ones so victims unknowingly send funds to criminals</strong></li><li><strong>Researchers advise always cross‑checking full wallet strings before sending, as attackers can craft lookalike addresses differing only in a few characters</strong></li></ul><p>Researchers have found yet another extension for Chromium-based browsers that is designed solely to steal people’s hard-earned cryptocurrency.</p><p>A <a href="https://www.mcafee.com/blogs/other-blogs/mcafee-labs/crypto-clipper-wallet-swapping-browser-extension-malware/" target="_blank" rel="nofollow">report</a> from McAfee has sounded the alarm on Silent Swap, a piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> hiding inside a benign-looking Google Notes extension.</p><p>Victims who stumble upon and download it (most likely through phishing, social engineering, or shady forums and websites), will get an extension that, on the surface, works as intended. It shows a small window where the victim can type a note and save it. They can color-code the notes and search through saved ones. However, this was only made to hide the program’s true intentions, which are to steal cryptocurrency.</p><h2 id="hijacking-the-clipboard">Hijacking the clipboard</h2><p>Silent Swap works like a typical clipboard jacker. It monitors the clipboard for strings that look like a <a href="https://www.techradar.com/news/best-bitcoin-wallets" target="_blank">crypto wallet</a> - seemingly random strings of 26 to 42 alphanumeric characters. </p><p>When it spots one, it replaces it with a different one belonging to the attacker, so when the victim pastes the address into the wallet to send the funds, they are actually sending them to the address belonging to the attackers.</p><p>This works because crypto wallets are almost impossible to memorize, and too risky to type in from a piece of paper or a different document, forcing users to rely on copying and pasting. </p><p>Once the victim sends the funds, they are almost certainly irretrievably gone. Only if the funds are being sent from a centralized exchange (like Coinbase, for example), and if the victim spots the attack fast enough, can they ask the exchange’s support to freeze the transaction. In all other cases, once the money is sent, it’s gone.</p><p>The best way to defend against these attacks is to cross-reference the strings before hitting send. Some people would only check the first and last few characters, but security researchers don’t recommend it, because some clipboard jackers can generate addresses that only differ in a few characters.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ These popular Tenda routers have an unpatched security backdoor which could give hackers access ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/these-popular-tenda-routers-have-an-unpatched-security-backdoor-which-could-give-hackers-access</link>
                                                                            <description>
                            <![CDATA[ CERT/CC finds a critical flaw in multiple Tenda routers, warning users to be careful. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qgGpALH52oBx7YGEEcDg6e</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xiF2oa9QT4q5sePeRdA8Af-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 09 Jul 2026 17:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xiF2oa9QT4q5sePeRdA8Af-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[cables going into the back of a broadband router on white background]]></media:description>                                                            <media:text><![CDATA[cables going into the back of a broadband router on white background]]></media:text>
                                <media:title type="plain"><![CDATA[cables going into the back of a broadband router on white background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xiF2oa9QT4q5sePeRdA8Af-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>CERT/CC discloses CVE‑2026‑11405, a critical 9.8/10 flaw in multiple Tenda router families caused by a hardcoded backdoor credential</strong></li><li><strong>Attackers can bypass normal login checks and gain full admin access with the hidden password, regardless of configured username or password</strong></li><li><strong>Tenda has not responded; CERT/CC advises disabling remote web management and limiting local exposure, though these are only partial mitigations</strong></li></ul><p>Multiple Tenda router families carry a critical vulnerability that allows malicious actors to log in with admin privileges without knowing the credentials, experts have found.</p><p>The CERT Coordination Center disclosed a vulnerability in Tenda <a href="https://www.techradar.com/news/networking/routers-storage/best-router-9-top-wireless-routers-on-test-1090523" target="_blank">routers</a> which it described as an undocumented authentication backdoor caused by a hardcoded credential. </p><p>The flaw is tracked as CVE-2026-11405 and was assigned a severity score of 9.8/10 (critical). CERT/CC allegedly tried reaching out to the manufacturer, to no avail.</p><h2 id="how-the-vulnerability-works">How the vulnerability works</h2><p>Explaining how it works, CERT/CC says that the attacker would first try to log into the router’s web management interface normally. Even if the credentials are wrong, the firmware would not automatically reject them, but would rather check a second, hidden <a href="https://www.techradar.com/best/password-manager" target="_blank">password</a>, stored internally. If the attacker knows the hidden credential, they get full admin access, regardless of the configured admin password or username. </p><p>The username doesn’t even matter, as long as the password is supplied. Obviously, CERT/CC did not say what the password was, but with a little reverse-engineering of the firmware, it can be exposed either on the dark web, or to the general public. </p><p>Tenda is a Chinese company building budget networking gear, popular mostly in India and adjacent markets, where its products are popular in homes and among small businesses.</p><p>The flaw thus still affects multiple firmware versions, including FH1201, W15E, AC10, AC5, and AC6 router families. To make matters worse, CERT/CC added that the full list of affected models is probably even bigger. </p><p>Tenda is yet to comment on the findings. In the meantime, CERT/CC recommended users disable remote web management, if possible, to make sure the vulnerability cannot be exploited remotely, at least. The organization also suggests limiting local network exposure, but stresses that this is not an entirely bulletproof solution.</p><p><em>Via </em><a href="https://www.tomshardware.com/tech-industry/cyber-security/hidden-backdoor-found-in-tenda-routers-goes-unpatched-despite-warnings-from-cybersecurity-researchers-affected-firmware-allows-admin-access-without-a-password" target="_blank"><em>Tom's Hardware</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Accenture confirms breach after hacker steals 35GB of source code and other data ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/accenture-confirms-breach-after-hacker-steals-35gb-of-source-code-and-other-data</link>
                                                                            <description>
                            <![CDATA[ A threat actor called 888 claims to have stolen 35GB of secrets and other files from Accenture. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MLCgkfxb8VJbhs9R4xRfYZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 09 Jul 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:description>                                                            <media:text><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:text>
                                <media:title type="plain"><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Accenture confirms cyberattack after threat actor “888” advertised selling 35GB of stolen source code and keys from its Azure DevOps repos</strong></li><li><strong>Hacker claims archive includes RSA/SSH keys, Azure PATs, storage access keys, and configs, though details remain unverified</strong></li><li><strong>Accenture says the breach was remediated with no operational impact; the same actor previously tried selling Accenture employee data after a 2024 third‑party breach</strong></li></ul><p>Accenture has confirmed suffering a cyberattack, days after threat actors started selling an archive allegedly coming from the firm.</p><p>"We are aware of this isolated matter, and we have remediated its source. There is no impact to Accenture operations and service delivery," Accenture said in a statement to<em> </em><a href="https://www.bleepingcomputer.com/news/security/accenture-confirms-breach-after-hacker-offers-stolen-data-for-sale/" target="_blank"><em>BleepingComputer</em></a>.</p><p>It follows a relatively unknown threat actor called 888 posting a new thread on an underground forum, advertising the sale of an archive seemingly stolen from the global professional services company.</p><h2 id="accenture-breach">Accenture breach</h2><p>"Today I am selling the Accenture Data Breach, thanks for reading and enjoy!," the hacker said. "In July 2026, Accenture suffered a data breach which resulted in just over 35gb of source codes getting stolen from the company."</p><p>The threat actor claims to have nabbed source code, RSA keys, SSH keys, Azure Personal Access Tokens (PAT), Azure Storage access keys, and configuration files. They also shared screenshots showing how they closed an Azure DevOps repository, but at this time these claims were not independently verified. </p><p>Accenture did not say how much data it lost in the breach, or what the nature of the stolen files is. The company also did not explain how it got breached but did stress that the hole has been plugged.</p><p>According to <em>BleepingComputer</em>, this same threat actor tried to sell Accenture employee data after a third-party breach back in 2024. </p><p>Accenture is one of the world's largest <a href="https://www.techradar.com/best/best-infrastructure-management-service" target="_blank">professional services</a> and consulting firms, providing consulting, technology, managed services, and cloud engineering, to businesses and governments. It was founded in 1989 as a spin-off from Arthur Andersen's consulting business, and today operates in more than 120 countries with hundreds of thousands of employees.</p><p>In 2021, it suffered a <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> attack at the hands of the infamous LockBit, who also managed to steal data from its systems.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Japanese telco giant KDDI says 12 million emails exposed in major cyberattack ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/japanese-telco-giant-kddi-says-12-million-emails-exposed-in-major-cyberattack</link>
                                                                            <description>
                            <![CDATA[ Five KDDI clients were also affected when a threat actor exploited a vulnerability in third-party software. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">JWQ2T75gMqXJq4dhkKjb6Z</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7DtE9RCVmUtmH2FAfvxsvM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 09 Jul 2026 14:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7DtE9RCVmUtmH2FAfvxsvM-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:description>                                                            <media:text><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:text>
                                <media:title type="plain"><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7DtE9RCVmUtmH2FAfvxsvM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>KDDI confirms unauthorized access affecting six ISPs, with up to 14.22 million email addresses and passwords exposed</strong></li><li><strong>Some passwords were unencrypted; with estimates citing 12.2 million emails and 7.6 million passwords compromised</strong></li><li><strong>Company urged rapid password updates, coordinated countermeasures with ISPs, and pledged recurrence prevention</strong></li></ul><p>KDDI, one of Japan’s largest telecommunications providers, has confirmed it was recently hacked and lost millions of emails and unencrypted passwords belonging to its clients’ customers.</p><p>In a data breach notice, shared last month, the company said that it confirmed “unauthorized access” on June 17 2026.</p><p>“As a result, part of the information from email services offered by these ISPs may have leaked externally,” a machine translation of the notice reads.</p><h2 id="coordinating-countermeasures">Coordinating countermeasures</h2><p>The incident allegedly affected an <a href="https://www.techradar.com/news/best-email-provider" target="_blank">email</a> system KDDI uses to manage customer email accounts, webmail, and email storage. </p><p>KDDI says that the attack affected six ISPs: STNet, KDDI Web Communications, JCOM, Chubu Telecommunications, Nifty Corp, and BIGLOBE. Up to 14.22 million email addresses and passwords linked to these mailboxes were allegedly exposed, which includes both accounts of former customers, as well as dormant users. </p><p>“Some” passwords were hashed or encrypted, the company further said, suggesting that some - were not. It also stated that the 14.22 million number represents a “maximum estimate”, and that the investigation is still ongoing. The Record reported 12.2 million customer email addresses and 7.6 million passwords exposed. </p><p>Since spotting the intrusion on June 17, KDDI has been contacting ISPs to “coordinate countermeasures” and urged their customers to update their passwords as soon as possible. “Customers should follow instructions provided by their ISP promptly,” it said. “KDDI will continue working with ISPs to notify customers and support rapid password updates.” It also said that “many customers” have already updated their passwords. </p><p>"We are analyzing the scope of the impact and the cause, responding to customers in coordination with ISP operators, and taking measures to prevent a recurrence," the company said.</p><p>KDDI is one of Japan's largest telecommunications companies, rivaling NTT Docomo and SoftBank. It serves approximately 72 million mobile subscribers.</p><p><em>Via </em><a href="https://therecord.media/major-japanese-telco-cyberattack-12-million-emails" target="_blank"><em>The Record</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Insurance company AssuranceAmerica exposes 6.9 million drivers following major data breach — here's what we know ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/insurance-company-assuranceamerica-exposes-6-9-million-drivers-following-major-data-breach-heres-what-we-know</link>
                                                                            <description>
                            <![CDATA[ No one has claimed responsibility for AssuranceAmerica attack yet. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">RwDEXWimkCParZ4TebyqNW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 09 Jul 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:description>                                                            <media:text><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:text>
                                <media:title type="plain"><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>AssuranceAmerica reports breach affecting 6,998,886 customers, with attackers stealing credentials and exfiltrating sensitive insurance and driver data</strong></li><li><strong>Company reset passwords, isolated systems, and deployed enhanced monitoring; warns victims of phishing risks using stolen details</strong></li><li><strong>No group has claimed responsibility, and stolen data has not yet surfaced on the dark web, though ransom pressure tactics are common in such cases</strong></li></ul><p>AssuranceAmerica, an insurance company operating thousands of independent agents across the US, has confirmed suffering a cyberattack in which it lost sensitive data on almost seven million customers.</p><p>The company filed a new report with the Office of the Maine Attorney General, confirming the breach and sharing a copy of the notification letter it will soon send out to the 6,998,886 affected individuals. </p><p>In the report, the company said an unidentified threat actor stole login credentials and moved into the network, grabbing names, contact information, automobile insurance policy or insurance account information, driver or vehicle information, claims-related information, and driver's license numbers.</p><h2 id="data-can-be-used-for-phishing">Data can be used for phishing</h2><p>The attackers were spotted on March 17 2026 and were quickly locked out of the company’s network. </p><p>Affected systems were isolated, and law enforcement notified. AssuranceAmerica also reset everyone’s passwords, deployed enhanced monitoring and threat detection tools, and warned its staff to remain vigilant. </p><p>AssuranceAmerica has warned customers to be careful about incoming emails and other communications, especially those claiming to come from the company itself. </p><p>Using the information obtained in the breach, criminals can create <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">highly convincing emails</a>, tricking victims into making fraudulent payments, sharing login credentials to corporate and banking environments, or even downloading malware and ransomware.</p><p>So far, no one has claimed responsibility for this attack, and the data is yet to surface anywhere on the dark web. Usually, criminals would post snippets or samples on their websites, in an attempt to pressure the victim company into paying ransom for the files. </p><p><a href="https://www.bleepingcomputer.com/news/security/assuranceamerica-data-breach-exposes-records-of-69-million-drivers/" target="_blank"><em>BleepingComputer</em></a> notes AssuranceAmerica operates through a network of more than 9,500 independent agents, providing auto, renters, and commercial auto insurance coverage in 14 US states.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Nextcloud leaks 367K records — European cloud giant exposes staff and clients in major breach ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/nextcloud-leaks-367k-records-european-cloud-giant-exposes-staff-and-clients-in-major-breach</link>
                                                                            <description>
                            <![CDATA[ A misconfigured cloud database spills secrets, but Nextcloud was quick to remedy. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">khexrdArJQJymvBWg6wefa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/S6qqNHNiXvsDD9ymatwGjK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 09 Jul 2026 12:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/S6qqNHNiXvsDD9ymatwGjK-1280-80.jpg">
                                                            <media:credit><![CDATA[Natali _ Mis / Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cloud in Hand]]></media:description>                                                            <media:text><![CDATA[Cloud in Hand]]></media:text>
                                <media:title type="plain"><![CDATA[Cloud in Hand]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/S6qqNHNiXvsDD9ymatwGjK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Exposed ElasticSearch cluster at Nextcloud contained ~367k records (8GB), including employee data, client contracts, and scripts</strong></li><li><strong>Sensitive information such as staff emails and client company details was left unencrypted; Nextcloud secured the archive within two days after notification</strong></li><li><strong>Company attributed the incident to hosting misconfiguration, stressing customer servers were unaffected, though researchers warn attackers may have accessed the data</strong></li></ul><p>European cloud provider Nextcloud kept an unprotected database on the public internet, exposing sensitive internal and client data to anyone who knew where to look, experts have revealed.</p><p>Nextcloud is a free, open source platform that lets users create their own <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">private cloud</a>. It is often described as an alternative to Google Drive, or Microsoft 365, which allows users to control where their data sits. </p><p>In mid-May 2026, security researchers from <a href="https://cybernews.com/security/nextcloud-cloud-provider-data-leak/" target="_blank"><em>Cybernews</em></a> discovered a publicly exposed ElasticSearch cluster and, after a deeper investigation, determined it contained around 367,000 records (8GB of data in total). The archive was a mix of Nextcloud employee data, client company data, contracts, and scripts built for the company’s clients. </p><h2 id="nextcloud-reacts">Nextcloud reacts</h2><p>The majority of files were in .PDF format (71k), followed by .PNG (53k) and .MD (23k). All of the exposed records were found in a single index, with some revealing client company information, as well as data on Nextcloud staff. Some of the information was unencrypted, as well, exposing employee email addresses, client company names and addresses, and emails of individuals who sent invoices to Nextcloud. </p><p><em>Cybernews</em> reached out to Nextcloud and the company locked the archive down within two days, and notified relevant authorities. It says it found no evidence of unauthorized access, but without a deep forensic analysis, it is impossible to say if that really is the case.</p><p>“If our team managed to discover the exposed dataset, threat actors may have too,” the <em>Cybernews</em> team wrote. “Malicious attackers operate numerous bots on the web that scour the net looking for exactly that: misconfigured <a href="https://www.techradar.com/best/best-cloud-databases" target="_blank">databases</a> with data to steal.”</p><p>The company also said this was a misconfiguration issue and that its services are secure: “The issue was caused by a misconfiguration of our hosting infrastructure and is not related to the Nextcloud solution. No other Nextcloud servers belonging to our customers, partners or other users have been affected by this issue,” the company’s spokesperson told the researchers.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts warn of the 'first documented case of agentic ransomware' — dangerous JADEPUFFER attack run entirely by an LLM ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-warn-of-the-first-documented-case-of-agentic-ransomware-dangerous-jadepuffer-attack-run-entirely-by-an-llm</link>
                                                                            <description>
                            <![CDATA[ An LLM-based ransomware attack has been detected by researchers, and is notable for losing the data it encrypted... ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">NG6Ytrq4XiJMhm6rDn2ZEW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GJ8T4oA8G7TYJwTEhkwJAF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 08 Jul 2026 18:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christian Cawley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zBDYnjPnB2XPvhKbYX9Kuc.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Christian Cawley has extensive experience as a writer and editor in consumer electronics, IT and entertainment media. He has contributed to TechRadar since 2017 and has been published in Computer Weekly, Linux Format, ComputerActive, and other publications. &lt;/p&gt;&lt;p&gt;Beyond TechRadar, he heads up the team at smart home website Matter Alpha, and writes about retro gaming at Gaming Retro. &lt;/p&gt;&lt;p&gt;Formerly the editor responsible for Linux, Security, Programming, and DIY at MakeUseOf, Christian previously worked as a desktop and software support specialist in the public and private sectors.&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GJ8T4oA8G7TYJwTEhkwJAF-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image Credit: Pixabay]]></media:description>                                                            <media:text><![CDATA[Representational image of a cybercriminal]]></media:text>
                                <media:title type="plain"><![CDATA[Representational image of a cybercriminal]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GJ8T4oA8G7TYJwTEhkwJAF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>The first agentic ransomware attack has been dubbed JADEPUFFER by researchers at Sysdig</strong></li><li><strong>Threat exploited a known vulnerability, adapted to obstacles, and targeted an Alibaba Nacos</strong></li><li><strong>Unfortunately for victims, paying up means nothing, as JADEPUFFER fails to back up the data</strong></li></ul><p>Has ransomware become self-aware? Sysdig researchers have analyzed an attack on an internet-facing Langflow instance, and discovered what they believe to be the first ransomware infection driven not by a human, but by AI.</p><p>As the attack progressed via a vulnerability, it accessed a server, removed data, overcame challenges, and phoned home regularly – all controlled not by a remote operator, but by a large language model (LLM).</p><p>Dubbed “JADEPUFFER” the attack seems to point to the direction of travel for extortion-based cybercrime -- if not for the entire sector, then certainly for the cybercrime-as-a-service (CaaS) market. As highlighted in Sysdig’s conclusion: “It’s a marker of where extortion tradecraft is heading.”</p><h2 id="fully-autonomous-hack">Fully autonomous hack</h2><p>Using a code-injection attack on a Langflow deployment, <a href="https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion" target="_blank">Sysdig reported</a> that the attack was fully automated, and after exploiting the vulnerability (CVE-2025-3248) JADEPUFFER sought out credentials for LLM providers, databases cloud platforms, and cryptocurrency wallets.</p><p>It also harvested data from the Langflow instance’s Postgres database, and committed various acts of destruction before the intended Alibaba Nacos (Naming and Configuration Service) and connected MySQL database were reached. </p><p>At this point, the ransomware demand was issued, with 1,342 Nacos configuration items encrypted and crucial database tables dropped. What is interesting about this is that random encryption was applied, but no backup was made and no key or report was created – so even if the ransom was paid, the data would remain unrecovered.</p><p>(Langflow fixed the vulnerability in April 2025, so this attack could have been avoided if the instance had been patched. Ironically, Langflow is also an AI platform, providing low-code solutions to build and deploy chatbots, agents, and advanced workflows using artificial intelligence.)</p><h2 id="a-new-phase-in-cybersecurity">A new phase in cybersecurity</h2><p>Security researchers have been on the lookout for Agentic Threat Actors (ATAs) for a while now, so the arrival of JADEPUFFER is not completely unexpected. Its arrival essentially means that anyone can create and operate a ransomware (or other cyberthreat) operation, relying on intelligent prompts and low-effort, fully automated testing in the wild, from which the LLM can learn and improve.</p><p>If this does indeed represent the dawning of a new age of cybersecurity, it isn’t all bad news. This incident has demonstrated how LLM-based attacks can be detected.</p><p>It used historical vulnerabilities, for example, but the most interesting thing about it is that this attempt was pretty verbose. The Sysdig team noticed that when JADEPUFFER was presented with obstacles to its primary aim, it adapted and shared its rationale. </p><p>While this narration is common among LLMs, other threats don’t do this, which offers an advantage for detecting LLM-based threats like JADEPUFFER and the variants which will inevitably appear.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Baby Boomers beat Gen Z in password hygiene, but both generations still don’t stick to the best practices — and many people are still using decades-old passwords that they made as kids ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/baby-boomers-beat-gen-z-in-password-hygiene-but-both-generations-still-dont-stick-to-the-best-practices-and-many-people-are-still-using-decades-old-passwords-that-they-made-as-kids</link>
                                                                            <description>
                            <![CDATA[ Baby Boomers are the most likely to frequently change passwords, but often rely on unsecure methods of storage. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9x7M8jUKqaYHh5NJXopDLJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uUiBRJLfaEQ4McLrFtB7wd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Jul 2026 11:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uUiBRJLfaEQ4McLrFtB7wd-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[World Password Day]]></media:description>                                                            <media:text><![CDATA[World Password Day]]></media:text>
                                <media:title type="plain"><![CDATA[World Password Day]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uUiBRJLfaEQ4McLrFtB7wd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>NordPass study claims older generations are more likely to change passwords than younger generations</strong></li><li><strong>But younger users are more in tune with password storage services, preferring to use password managers over memory and writing them down</strong></li><li><strong>All generations are failing to adhere to the best practices when it comes to password hygiene</strong></li></ul><p>Many people may believe Gen Z are the best when it comes to adopting new tech, but a new study by <a href="https://nordpass.com/blog/password-decline-research/" target="_blank">NordPass</a> polling 7,861 respondents between the ages of 18-74 suggests that they might be the worst generation for password hygiene.</p><p>It’s not uncommon for people to pick a particular word or phrase as a password and alternate special characters, numbers, and capital letters to keep it ‘unique’, but this practice is weakened when the same central password is used for years—or even decades.</p><p>In fact, Gen Z has been found to be the generation least likely to change a password, while Baby Boomers are the most security-conscious, actively updating their passwords much more frequently.</p><h2 id="baby-boomers-value-security">Baby Boomers value security</h2><p>When breaking down the stats, NordPass found just 54% of respondents had changed their longest-standing password in the last 12 months. Those aged 18-24 were the least likely to say they had updated their password within the last year, while those in older brackets, particularly between 55-to-64, were the most likely to update their passwords.</p><p>But there is a further trend to be examined. While those in the older age brackets are more likely to update their passwords, they rely on memory or physically writing down their passwords for storage. And those in the younger, more tech-savvy age brackets were more likely to rely on browser-based password storage or third-party password managers.</p><p>Writing down passwords or relying on memory often leads to the reuse of passwords to keep them memorable and easy to type, increasing the risk that personal accounts could be breached in the event of a cyberattack. While the average number of password has dropped from 168 in 2024 to 120 in 2026, this still leaves the average person with a significant number of possibly reused passwords that could leak, potentially compromising every account they are used on.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1062px;"><p class="vanilla-image-block" style="padding-top:62.52%;"><img id="tyRwAMqY2pue95yY3VEbzR" name="infographics-password-decline" alt="A graph displaying the average password storage statistics with respondents from Australia, Canada, the UK, the US, France, Germany, Italy, and Spain, showing more people store passwords in a browser." src="https://cdn.mos.cms.futurecdn.net/tyRwAMqY2pue95yY3VEbzR.jpg" mos="" align="middle" fullscreen="" width="1062" height="664" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: NordPass)</span></figcaption></figure><p>Opting for the convenience of a browser-based password manager also introduces additional risk, as these password vaults often aren’t subjected to the same security protocols as third-party <a href="https://www.techradar.com/best/password-manager" target="_blank">password manager apps</a>. </p><p>In fact, another recent NordPass study highlighted that <a href="https://www.techradar.com/pro/security/password-reuse-only-sharpens-this-problem-browser-based-password-storage-isnt-as-safe-as-you-think-these-top-tips-from-the-experts-show-how-it-should-be-done" target="_blank">browser-based passwords are at a significantly higher chance of being leaked or stolen</a> thanks to malware, browser compromise, or physical access to the computer.</p><p>This is especially true for those using a browser-based password manager alongside a third-party app, because if the browser is compromised there is little you can do to protect your stored passwords.</p><p>“I’m fairly certain most internet users know they should immediately change a password that has been compromised,” said Karolis Arbaciauskas, head of product at cybersecurity company NordPass.</p><p>“So when people say they haven’t changed a password in years, either the password hasn’t been exposed, or they simply don’t know it has. I hate to be a bearer of bad news, but the second scenario is far more likely. Without tools to notify them when credentials appear in leaks or breaches, many users have passwords aging in the background while the risk grows.”</p><h2 id="how-to-keep-your-passwords-as-secure-as-possible">How to keep your passwords as secure as possible</h2><p>There are many ways to <a href="https://www.techradar.com/pro/security/coming-up-with-a-new-password-doesnt-have-to-be-hard-im-a-password-expert-and-these-are-my-5-top-tips-for-crafting-the-perfect-password">create a secure password</a>. These are my expert recommendations for maximizing your password security:</p><ul><li>Your password should be at least 15 characters long</li><li>Rather than relying on a memorable phrase or key date, use a string of random words such as the NIST example of ‘cassette-lava-baby’</li><li>Add in some random capitalization, numbers, and special characters, but avoid replacing certain letters with predictable special characters (such as ‘@’ for ‘a’, ‘$’ for ‘s’, and so on)</li><li>If you are forced to regularly change a password as many people are forced to do in the workplace, always use a new, unique password, rather than relying on ‘Summer12345’ followed by ‘Autumn12345’</li><li>Wherever possible, use an <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">authenticator app</a>. This can range from an app on your phone that you use to approve a login or a physical security key that you keep on your person. Many authenticators use phishing resistant passkeys that authenticate your login attempts by using your facial scan or a fingerprint</li><li>Use a password manager to store your passwords securely. They also add the benefit of being able to autofill your credentials for you</li><li>Use a credential exposure checking service such as <a href="https://haveibeenpwned.com/" target="_blank">Have I Been Pwned</a> to securely check if your email address or passwords have shown up in any dark web databases</li><li>Delete any online accounts you no longer use. If the service suffers a data breach, it could leak your username and password combination</li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 81 million login attempts hit Microsoft 365 accounts as hackers try password-spraying to force entry using stolen credentials and OAuth to bypass authentication ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/81-million-login-attempts-hit-microsoft-365-accounts-as-hackers-try-password-spraying-to-force-entry-using-stolen-credentials-and-oauth-to-bypass-authentication</link>
                                                                            <description>
                            <![CDATA[ The attack abused misconfigured conditional access policies to bypass multi-factor authentication protections. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">d8vfHgQqzay2L4VV6dTngh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9dJG7jH8XprNiB4jnuuD2M-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 02 Jul 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9dJG7jH8XprNiB4jnuuD2M-1280-80.jpg">
                                                            <media:credit><![CDATA[Microsoft]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft 365]]></media:description>                                                            <media:text><![CDATA[Microsoft 365]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft 365]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9dJG7jH8XprNiB4jnuuD2M-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>A password-spraying attack successfully breached Microsoft 365 accounts</strong></li><li><strong>The hackers abused improperly configured conditional access policies to bypass MFA</strong></li><li><strong>Many organizations targeted had no MFA implemented</strong></li></ul><p>Hackers have used previously leaked credentials to target Microsoft 365 accounts in a password-spraying attack that resulted in over 81 million login attempts during a two-week period.</p><p>The attackers then abused the improperly implemented Conditional Access policies within the Resource Owner Password Credentials (ROPC) OAuth mechanism using Azure command-line interface (CLI), allowing the hackers to bypass authentication altogether when a matching username and password was discovered.</p><p>Cybersecurity company <a href="https://www.huntress.com/blog/lshiy-password-spray-attack" target="_blank">Huntress</a> observed the attack campaign as it targeted customers and noted that 78 Microsoft accounts across 64 organizations were compromised between June 12 and 26 2026.</p><h2 id="hackers-access-365-accounts-without-authentication">Hackers access 365 accounts without authentication</h2><p>The success of the attack ultimately came down to how well organizations had implemented Conditional Access policies relating to multi-factor authentication. </p><p>“Many of the compromised businesses had implemented multi-factor authentication (MFA) via a Conditional Access Policy (CAP), but the MFA was not configured to cover this specific flow that attackers used,” Huntress explained, referring to the exploitation of ROPC.</p><p>“ROPC is considered problematic for several reasons, but one of those reasons is that it doesn't offer support for modern auth flows like MFA or SSO. That means, as we saw in this campaign, ROPC sends the password straight to the /token endpoint with no interactive MFA prompt.”</p><p>Several of the organizations that were breached did not enforce an MFA policy at all, with others only applying MFA for specific user groups such as administrators. In other cases, a login attempt only required MFA when the traffic was coming from an untrusted location, meaning that MFA was not enforced if the connection was coming from a trusted IP address. Additionally, some organizations had only enforced MFA in report-only mode, meaning that the MFA policies were never actually applied.</p><p>In order to protect against attacks of this kind of attack, Huntress recommended the following mitigations:</p><ul><li>Organizations should implement MFA for All Users, All Cloud Apps, and All Client App types</li><li>The Azure CLI application should be restricted from use by non-admin users</li><li>Response to the attack should be made on credential validity, rather than spray volume</li></ul><p>Via <a href="https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-365-accounts-with-81-million-login-attempts/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘100% of Hide My Email addresses were exploitable’: Apple’s security feature can be duped into supplying the real contact info — and the bug has remained unpatched for over a year ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/100-percent-of-hide-my-email-addresses-were-exploitable-apples-security-feature-can-be-duped-into-supplying-the-real-contact-info-and-the-bug-has-remained-unpatched-for-over-a-year</link>
                                                                            <description>
                            <![CDATA[ The bug was reported to Apple over a year ago, but still nothing has been done. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8zAuVdPwPxYpCY6BAjr9eN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NhJKejfFerSum2SW4TXEkX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 02 Jul 2026 13:57:57 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NhJKejfFerSum2SW4TXEkX-1280-80.jpg">
                                                            <media:credit><![CDATA[Apple / 9to5Mac]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A screenshot showing Hide My Email in the Mail app]]></media:description>                                                            <media:text><![CDATA[A screenshot showing Hide My Email in the Mail app]]></media:text>
                                <media:title type="plain"><![CDATA[A screenshot showing Hide My Email in the Mail app]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NhJKejfFerSum2SW4TXEkX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Apple Hide My Email can reveal a user's authentic email address</strong></li><li><strong>The bug puts users at risk of identification, experts warned</strong></li><li><strong>It has been unpatched for over a year</strong></li></ul><p>A bug in Apple’s ‘Hide My Email’ feature allows for those with knowledge of the vulnerability to identify the real email address hidden behind the anonymous email address.</p><p>The bug was discovered by EasyOptOuts co-founder, Tyler Murphy, who shared the exploit with <a href="https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses/" target="_blank"><em>404 Media</em></a> after notifying Apple multiple times that the feature could be actively exploited.</p><p>“We reported the issue and replication instructions to Apple over a year ago. We don't know why it hasn't been fixed, but we don't feel comfortable waiting any longer,” Murphy said.</p><h2 id="hide-my-email-can-be-actively-exploited">Hide My Email can be actively exploited</h2><p>As the bug still hasn’t been patched, the details of how the exploit works have not been shared. </p><p>Apple’s Hide My Email feature was designed to anonymize email addresses, helping to prevent a user’s real email address from being leaked in a data breach, or to prevent a user’s email address from being linked to them personally in a way that could reveal their identity.</p><p>There lies the crux of the issue. By being able to identify the real email address by exploiting the bug, a malicious actor could uncover the real identity of the anonymized email.</p><p>“Free, publicly accessible people-search sites make it easy to link an email address to other personal details, so people relying on Hide My Email for safety may be at risk,” Murphy said. “We don't know the full scope of the issue, but in our limited tests with volunteers, 100% of Hide My Email addresses were exploitable.”</p><p>Users concerned about being identified via people-search sites can use a <a href="https://www.techradar.com/pro/best-data-removal-services-of-year" target="_blank">data removal service</a> to have their data scrubbed from these sites, but the process can take a few days.</p><p>The issue was first reported to Apply by Murphy in June 2025, with Apple replying a month later that it was looking into the cause of the issue. Earlier this year, in March, Apple said that it had “addressed the reported issue in a recent system change,” but Murphy found that the bug could still be exploited.</p><p>Again, Murphy notified Apple, who replied in May 2026, stating, “We are still investigating this issue. To avoid placing our customers at risk, we would appreciate you not disclosing this information until our investigation is complete. We appreciate your assistance in helping us to maintain and improve the security of our products."</p><p>Later in the same month, Apply said a fix was “expected in the coming weeks."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ That free VPN Chrome and Firefox extension may be reading your clipboard every half a second, researchers warn ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/vpn/vpn-privacy-security/that-free-vpn-chrome-and-firefox-extension-may-be-reading-your-clipboard-every-half-a-second-researchers-warn</link>
                                                                            <description>
                            <![CDATA[ Researchers at Socket found two "VPN Go" browser extensions for Chrome and Firefox that posed as free VPNs while quietly stealing clipboard data through later updates. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">drttgaXd7xBrBjVNgZ6gbP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5pmsJs3KfnrtbsM98UsnG9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 01 Jul 2026 13:22:10 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[VPN Privacy &amp; Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ monicajwrites@gmail.com (Monica J. White) ]]></author>                    <dc:creator><![CDATA[ Monica J. White ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/6AQ4y5nzk8kQ47Yp69GERj.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Monica is a journalist with over a decade of experience in covering technology.&lt;/p&gt;&lt;p&gt;She writes about the latest developments in computing, which means anything from computer chips made out of paper to cutting-edge desktop processors. Her coverage includes CPUs, GPUs, and everything else that goes into a PC or a laptop, but also peripherals.&lt;/p&gt;&lt;p&gt;GPUs are Monica’s main area of interest, and nothing thrills her quite like that time every couple of years when new graphics cards hit the market. She’s always keeping tabs on the latest from Nvidia, AMD, and Intel, including both the hardware and the software that powers our PCs.&lt;/p&gt;&lt;p&gt;As an avid gamer, her focus is always on the consumer and whether something works well and provides adequate value for the money. She believes that PC building can be intimidating, so her goal is to explain complex concepts in an approachable manner while still digging into the technical nitty-gritty we all love to learn more about.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5pmsJs3KfnrtbsM98UsnG9-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Malware kan ställa till med oreda]]></media:description>                                                            <media:text><![CDATA[Android phone malware]]></media:text>
                                <media:title type="plain"><![CDATA[Android phone malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5pmsJs3KfnrtbsM98UsnG9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers found "VPN Go" extensions for Chrome and Firefox secretly harvesting copied text</strong></li><li><strong>The clipboard theft was not there at launch and arrived through a later update</strong></li><li><strong>Anything copied while the extension was active should now be treated as exposed</strong></li></ul><p>Security researchers at Socket found two browser extensions distributed under the "VPN Go: Free VPN" branding, one listed on the Chrome Web Store and one on Firefox Add-ons, to secretly harvest copied text. </p><p>Both present themselves as free VPN tools with working proxy features. Underneath, <a href="https://socket.dev/blog/chrome-and-firefox-extensions-free-vpns-add-clipboard-stealers" target="_blank" rel="nofollow">Socket says</a>, both also run a clipboard stealer that continuously watches copied text and sends it to infrastructure controlled by the attacker.</p><p>According to Socket, the clipboard theft was not present when the extensions first appeared. It was added later, through an ordinary-looking update, after the extensions had already built up a base of trusting users. That staged approach is exactly what makes this kind of threat so hard to spot, and why even a fairly cautious user can end up exposed.</p><p>For anyone weighing up a no-cost privacy tool, it is worth knowing that not every free option behaves like this, and the <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> services are tested precisely so you do not have to take this kind of gamble. But this case shows how thin the line can be between a useful free extension and a data-harvesting one.</p><h2 id="what-socket-s-research-uncovered">What Socket's research uncovered</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1213px;"><p class="vanilla-image-block" style="padding-top:56.22%;"><img id="7b3ucMmXHaTYWRvoZbT8T9" name="VPN Go" alt="VPN Go in Chrome Web Store" src="https://cdn.mos.cms.futurecdn.net/7b3ucMmXHaTYWRvoZbT8T9.png" mos="" align="middle" fullscreen="" width="1213" height="682" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Chrome)</span></figcaption></figure><p>Socket says the earliest analyzed builds behaved like ordinary proxy extensions, with no confirmed clipboard theft. </p><p>On <a href="https://www.techradar.com/reviews/google-chrome">Chrome</a>, that changed with version 1.1, when the extension added a script that reads the clipboard and ships those chunks off to a hardcoded address. The <a href="https://www.techradar.com/reviews/mozilla-firefox">Firefox</a> version followed the same path slightly later, moving the same theft loop into its background script.</p><p>Once active, the monitoring is relentless. The Chrome content script checks the clipboard roughly every half a second, according to Socket's analysis, while the Firefox build polls every 1.5 seconds. </p><p>Each newly copied value is tagged with a session identifier so it can be reassembled on the other end, then sent out over plain HTTP. All of this was happening while the two apps' privacy policies stated that the tools did not collect, store, or share user data and did not keep activity logs.</p><p>TechRadar has reached out to VPN Go for comment, but both email addresses bounced, and both extensions have since been pulled from their stores.</p><h2 id="why-clipboard-stealers-are-dangerous-for-users">Why clipboard stealers are dangerous for users</h2><p>The reason clipboard theft is so effective is that it abuses something completely routine. People copy and paste sensitive information all day, and it's not careless to do so. Password managers rely on exactly that: copying long, unique passwords into your accounts.</p><p>An extension that can silently read the clipboard has access to all of this information; it just has to wait for you to copy the right thing. If you have used either of the two extensions in question, you should treat any information you've copied during that time as exposed.</p><p>Researchers have repeatedly found free VPN extensions doing things their users never agreed to. Recent reporting has covered a <a href="https://www.techradar.com/vpn/vpn-privacy-security/this-free-chrome-vpn-extension-found-to-spy-on-its-100k-users-uninstall-it-now">free Chrome VPN extension caught taking screenshots</a> of every page its users visited, and a <a href="https://www.techradar.com/vpn/vpn-privacy-security/malicious-free-vpn-extension-makes-a-comeback">malicious free VPN extension that resurfaced</a> after being removed, returning in a more evasive form. </p><p>The pattern is consistent enough that it is worth treating any unknown free VPN extension with caution by default. That caution matters: TechRadar's own polling found that <a href="https://www.techradar.com/vpn/vpn-privacy-security/to-pay-or-not-to-pay-nearly-1-in-4-techradar-readers-say-they-use-free-vpns-despite-the-risks">nearly 1 in 4 readers use free VPNs</a> despite knowing the risks.</p><h2 id="how-to-stay-safe">How to stay safe</h2><p>If you want the protection a VPN offers without rolling the dice, stick to providers with a track record and independent testing behind them. </p><p>A reputable paid service, or one of the carefully vetted <a href="https://www.techradar.com/vpn/best-free-vpn">best free VPN</a> options, is a far safer bet than an unknown extension promising unlimited access for nothing. As the saying goes, when the product is free, there is a decent chance that you are the product.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This new tool can let you ask Claude if that 'too good to be true' online offer is actually a scam ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/this-new-tool-can-let-you-ask-claude-if-that-too-good-to-be-true-online-offer-is-actually-a-scam</link>
                                                                            <description>
                            <![CDATA[ Norton's scam detection will let you ask Claude whether an email or online deal looks suspicious without leaving the AI chatbot. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oiyS6nwHQLbUz3BVKzPJj6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QEWeUa835nVFaBLaYmYfN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 01 Jul 2026 12:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[AI Platforms &amp; Assistants]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QEWeUa835nVFaBLaYmYfN-1280-80.jpg">
                                                            <media:credit><![CDATA[Norton]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Norton Genie in Claude]]></media:description>                                                            <media:text><![CDATA[Norton Genie in Claude]]></media:text>
                                <media:title type="plain"><![CDATA[Norton Genie in Claude]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QEWeUa835nVFaBLaYmYfN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Norton's scam detection tools are now available in Claude and ChatGPT</strong></li><li><strong>Users can ask their preferred AI chatbot about the legitimacy of an email, text, website</strong></li><li><strong>Most threats consumers face now come from scams, phishing and fake ads</strong></li></ul><p>Claude is the latest AI assistant to get access to <a href="https://www.techradar.com/vpn/vpn-services/nordvpns-new-tool-helps-you-spot-online-scams-and-its-free-for-everyone">Norton's Genie scam detection tool</a> following its available for ChatGPT customers earlier this year.</p><p>Available across all Claude subscription tiers, Genie gives users access to scam detection capabilities and other cyber safety tips and advice.</p><p>Norton says its tool can analyze suspicious emails, texts, messages, images and links using its "multi-layered" detection intelligence.</p><h2 id="norton-scam-detection-now-available-in-claude-chatgpt">Norton scam detection now available in Claude, ChatGPT</h2><p>"AI assistants are becoming part of how people make decisions and evaluate information online," Head of Products and Portfolios Travis Witteveen noted, hinting that the increased prevalence of AI assistants.</p><p>"By bringing Norton Genie into even more AI platforms like Claude and ChatGPT, we’re making trusted Cyber Safety intelligence available directly in those moments to help people make more confident decisions in real time."</p><p>The company explained that Genie looks for language patterns, social engineering tactics, urgency cues, impersonation attempts, and requests for sensitive information. It also checks URLs and analyzes domains to confirm whether a user should click on the link.</p><p>When the tool launched for ChatGPT in March 2026, Norton described it as the "world's first AI-powered scam detector." Users can start conversations by tagging @Norton and asking questions like whether an email looks legit or if an online offer looks like a scam.</p><p>The company's own reporting reveals that nine in 10 threats targeting people in 2025 came from scams, phishing and fake advertisements.</p><p>So far, Norton looks to be the only security company offering direct AI chatbot integration to provide accurate insights into threat detection.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>