<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-AU"
                       href="https://www.techradar.com/au/feeds/tag/malware"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from TechRadar AU in Malware ]]></title>
                <link>https://www.techradar.com/au/tag/malware</link>
        <description><![CDATA[ All the latest malware content from the TechRadar  AU team ]]></description>
                                    <lastBuildDate>Fri, 21 Aug 2026 15:05:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ This new malware can use Google passkeys even after a victim resets their password ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>iAuthFlow v2 sold on Russian forums lets attackers persist in email accounts  </strong></li><li><strong>Tool phishes logins, then secretly creates attacker‑controlled passkeys for lasting access  </strong></li><li><strong>Defenses include auditing passkeys, OAuth tokens, mail rules, and removing rogue methods</strong></li></ul><p>Security researchers have discovered a new <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> toolkit which allows threat actors to log back into compromised email accounts even after the password was changed and all sessions terminated.</p><p>iAuthFlow v2 is currently being sold on Russian dark web forums for north of $10,000, a new <a href="https://abnormal.ai/blog/iauthflow-v2-phishing-google-passkeys" target="_blank" rel="nofollow">report</a> from cybersecurity experts from Abnormal said, as they obtained a copy of iAuthFlow v2 for analysis.</p><p>The malware primarily works as a phishing tool, trying to trick users into logging into either Google, Microsoft, iCloud, or LinkedIn. As soon as they do that, they relay the login credentials to the attackers, who log into the accounts on their end, as well - before the tool displays a “processing” page for a few seconds while, in the background, it sets up a new passkey. </p><h2 id="how-to-defend-against-iauthflow-v2">How to defend against iAuthFlow v2</h2><p>A passkey is an alternative means of authentication that is often touted as the “<a href="https://www.techradar.com/best/password-manager" target="_blank">password</a> killer”. It uses cryptographic keys stored on a device, allowing users to sign in with a fingerprint, face scan, or device PIN. </p><p>Because the secret key never leaves the device, it is resistant to phishing. However, if the threat actor is able to generate a key of their own, on the device they own, access is basically guaranteed. </p><p>The ad for the toolkit also comes with a video demo, showing how it works. In the demo, iAuthFlow v2 created the passkey six seconds after authentication. </p><p>However, generating a passkey is not that straightforward of a process and it could encounter hiccups, Abnormal hints, saying that Google, for example, might require further identity verification before allowing the change.</p><p>Usually, when a threat actor compromises an <a href="https://www.techradar.com/news/best-email-provider" target="_blank">email account</a>, terminating all sessions and changing the password is usually enough.</p><p>In this case, however, users should do a lot more: review the account for signs of compromise, including unauthorized passkeys or security keys, malicious Gmail filters and forwarding rules, recovery and delegated access changes, and unauthorized applications, Abnormal suggests.</p><p>They should also revoke relevant OAuth tokens and grants, investigate available sign-in, mail-rule, 2-Step Verification, passkey and OAuth audit events, and finally, make sure any attacker-enrolled authentication methods are removed.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/this-new-malware-can-use-google-passkeys-even-after-a-victim-resets-their-password</link>
                                                                            <description>
                            <![CDATA[ A newly discovered toolkit can deeply compromise Gmail, Microsoft, Apple, and LinkedIn accounts ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XL5nrccyjA7YTcv5HwxC9C</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QGZS7tno9wMKaY7FVBDSNE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 21 Aug 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QGZS7tno9wMKaY7FVBDSNE-1280-80.jpg">
                                                            <media:credit><![CDATA[Ascannio / Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Gmail app listing]]></media:description>                                                            <media:text><![CDATA[Gmail app listing]]></media:text>
                                <media:title type="plain"><![CDATA[Gmail app listing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QGZS7tno9wMKaY7FVBDSNE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>iAuthFlow v2 sold on Russian forums lets attackers persist in email accounts  </strong></li><li><strong>Tool phishes logins, then secretly creates attacker‑controlled passkeys for lasting access  </strong></li><li><strong>Defenses include auditing passkeys, OAuth tokens, mail rules, and removing rogue methods</strong></li></ul><p>Security researchers have discovered a new <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> toolkit which allows threat actors to log back into compromised email accounts even after the password was changed and all sessions terminated.</p><p>iAuthFlow v2 is currently being sold on Russian dark web forums for north of $10,000, a new <a href="https://abnormal.ai/blog/iauthflow-v2-phishing-google-passkeys" target="_blank" rel="nofollow">report</a> from cybersecurity experts from Abnormal said, as they obtained a copy of iAuthFlow v2 for analysis.</p><p>The malware primarily works as a phishing tool, trying to trick users into logging into either Google, Microsoft, iCloud, or LinkedIn. As soon as they do that, they relay the login credentials to the attackers, who log into the accounts on their end, as well - before the tool displays a “processing” page for a few seconds while, in the background, it sets up a new passkey. </p><h2 id="how-to-defend-against-iauthflow-v2">How to defend against iAuthFlow v2</h2><p>A passkey is an alternative means of authentication that is often touted as the “<a href="https://www.techradar.com/best/password-manager" target="_blank">password</a> killer”. It uses cryptographic keys stored on a device, allowing users to sign in with a fingerprint, face scan, or device PIN. </p><p>Because the secret key never leaves the device, it is resistant to phishing. However, if the threat actor is able to generate a key of their own, on the device they own, access is basically guaranteed. </p><p>The ad for the toolkit also comes with a video demo, showing how it works. In the demo, iAuthFlow v2 created the passkey six seconds after authentication. </p><p>However, generating a passkey is not that straightforward of a process and it could encounter hiccups, Abnormal hints, saying that Google, for example, might require further identity verification before allowing the change.</p><p>Usually, when a threat actor compromises an <a href="https://www.techradar.com/news/best-email-provider" target="_blank">email account</a>, terminating all sessions and changing the password is usually enough.</p><p>In this case, however, users should do a lot more: review the account for signs of compromise, including unauthorized passkeys or security keys, malicious Gmail filters and forwarding rules, recovery and delegated access changes, and unauthorized applications, Abnormal suggests.</p><p>They should also revoke relevant OAuth tokens and grants, investigate available sign-in, mail-rule, 2-Step Verification, passkey and OAuth audit events, and finally, make sure any attacker-enrolled authentication methods are removed.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security experts targeted by fake crypto conference in scam to hand over details ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Huntress spotted a ClickFix campaign targeting security pros via fake conference invites  </strong></li><li><strong>Victims tricked into pasting code that installs AMOS infostealer on macOS </strong></li><li><strong>If lured, isolate systems, reset credentials, rotate secrets, and review cryptocurrency wallets</strong></li></ul><p>Cybercriminals are targeting security professionals with a highly tailored ClickFix campaign in an attempt to get their computers infected with infostealer <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, experts have warned.</p><p>An active campaign against people who have attended, or have a history of attending, various cybersecurity conferences such as Black Hat, or DEF CON has been detetced by security researchers <a href="https://www.huntress.com/blog/defcon-phishing-google-doc-malware" target="_blank">Huntress</a>, who were targets themselves. </p><p>The attack starts on X, where the threat actor uses a fake account to interact with people visiting and sharing content from these conferences. After establishing rapport, they move into DMs, claiming they’re organizing a conference of their own, and sharing a Google Docs file containing “more info” with the victim. </p><h2 id="follow-up-attack">Follow-up attack</h2><p>Here is where the attackersy go for the ClickFix attack. The document comes with a vertical sidebar, apparently as a security feature that keeps the contents of the file encrypted. The victim is given a decryption code to enter, but it returns an error and offers a solution - to bring up the Terminal and copy/paste a piece of code.</p><p>From here, it’s the usual ClickFix practice: the victim ends up downloading and running AMOS, a notorious Mac infostealer capable of grabbing browser information, cookies, keychain data, cryptocurrency wallet information, Telegram files, and more. The Windows variant did not work when Huntress tried to analyze it, but it’s safe to assume the end goal is the same.</p><p>Huntress also found that this is not where the attack ends. If the victim does not install the infostealer, the threat actor will follow up with a different document, this time pretending to be for Dropbox and working only with the desktop app. Of course, the download button leads straight back to the infostealer.</p><p>The researchers shared a full list of Indicators of Compromise (IoC) which can be found on this link. They also advised anyone who interacted with this kind of lure to isolate the system from the network, collect relevant forensic evidence, and “consider reimaging the system”. </p><p>“Assume that credentials on the system have been compromised”, they said. “Revoke active sessions, reset passwords, and rotate API keys or any other secrets that may reside on the system. Review cryptocurrency wallets as well, if present.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/security-experts-targeted-by-fake-crypto-conference-in-scam-to-hand-over-details</link>
                                                                            <description>
                            <![CDATA[ Cybersecurity pros attending conferences are being targeted with AMOS and other infostealers, experts warn. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4WM98xrduycbkQfG5f5Wdh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 21 Aug 2026 13:20:22 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:description>                                                            <media:text><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:text>
                                <media:title type="plain"><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Huntress spotted a ClickFix campaign targeting security pros via fake conference invites  </strong></li><li><strong>Victims tricked into pasting code that installs AMOS infostealer on macOS </strong></li><li><strong>If lured, isolate systems, reset credentials, rotate secrets, and review cryptocurrency wallets</strong></li></ul><p>Cybercriminals are targeting security professionals with a highly tailored ClickFix campaign in an attempt to get their computers infected with infostealer <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, experts have warned.</p><p>An active campaign against people who have attended, or have a history of attending, various cybersecurity conferences such as Black Hat, or DEF CON has been detetced by security researchers <a href="https://www.huntress.com/blog/defcon-phishing-google-doc-malware" target="_blank">Huntress</a>, who were targets themselves. </p><p>The attack starts on X, where the threat actor uses a fake account to interact with people visiting and sharing content from these conferences. After establishing rapport, they move into DMs, claiming they’re organizing a conference of their own, and sharing a Google Docs file containing “more info” with the victim. </p><h2 id="follow-up-attack">Follow-up attack</h2><p>Here is where the attackersy go for the ClickFix attack. The document comes with a vertical sidebar, apparently as a security feature that keeps the contents of the file encrypted. The victim is given a decryption code to enter, but it returns an error and offers a solution - to bring up the Terminal and copy/paste a piece of code.</p><p>From here, it’s the usual ClickFix practice: the victim ends up downloading and running AMOS, a notorious Mac infostealer capable of grabbing browser information, cookies, keychain data, cryptocurrency wallet information, Telegram files, and more. The Windows variant did not work when Huntress tried to analyze it, but it’s safe to assume the end goal is the same.</p><p>Huntress also found that this is not where the attack ends. If the victim does not install the infostealer, the threat actor will follow up with a different document, this time pretending to be for Dropbox and working only with the desktop app. Of course, the download button leads straight back to the infostealer.</p><p>The researchers shared a full list of Indicators of Compromise (IoC) which can be found on this link. They also advised anyone who interacted with this kind of lure to isolate the system from the network, collect relevant forensic evidence, and “consider reimaging the system”. </p><p>“Assume that credentials on the system have been compromised”, they said. “Revoke active sessions, reset passwords, and rotate API keys or any other secrets that may reside on the system. Review cryptocurrency wallets as well, if present.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Rethinking secure file transfer for a cross-domain world ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The UK's National Cyber Security Centre recently issued a blunt warning to government and industry alike, warning that many systems are now connected "in ways their designers never anticipated", built on protocols never intended to withstand the sophistication of today's attackers.</p><p>That warning applies to all organizations relying on cross-domain processes to move data between environments with different security levels, and especially to complex cyber-physical systems where data flows between standard IT and operational technology (OT) assets.</p><p><a href="https://www.techradar.com/best/best-ways-to-transfer-files-online">File transfer</a> is one of these fundamental processes but remains one of the most often overlooked.</p><p>Every <a href="https://www.techradar.com/best/best-billing-and-invoicing-software">invoice</a> sent to a supplier, every firmware update pushed to a factory floor, every report shared with a regulator is data crossing between systems with different levels of trust.</p><p>For years, file transfer security has been treated as a solved problem. Enterprises were happy to encrypt the channel, confirm delivery, and move on. That approach made sense when systems were simpler, and threats moved more slowly. However, it no longer reflects reality.</p><h2 id="why-perimeter-based-trust-no-longer-holds">Why perimeter-based trust no longer holds</h2><p>Most file transfer platforms were never built with security as the primary goal. They were built to move data reliably between systems, encrypt the connection, confirm that a file arrived, and log that the job was done. Whether the file itself was safe was rarely part of the equation.</p><p>That gap provides a consistent way for cyber attackers to gain a foothold in their targets' systems. A file transfer platform sits between organizations by design, trusted by both sides precisely because it's meant to be routine infrastructure.</p><p>The traditional Managed File Transfer (MFT) model is built to automate file delivery, not to defend against attack. As such, it leaves the process exposed to a familiar set of threats, from man-in-the-middle interception and credential theft to <a href="https://www.techradar.com/best/best-malware-removal">malware</a> covertly embedded in an otherwise ordinary file. Attackers don't need to break the platform itself, only to exploit the assumption that whatever moves through it can be trusted.</p><p>As we've seen with incidents like 2023's MoveIT supply chain cyberattack and last year's SharePoint breach, a single vulnerability in a widely used transfer tool can give attackers access to thousands of organizations at once, simply because every one of them assumed the platform itself could be trusted.</p><p>That assumption is exactly what attackers are counting on. Securing the channel a file travels through was never the same as securing the file.</p><h2 id="the-shrinking-window-to-respond">The shrinking window to respond</h2><p>File security has always been a blind spot, but it's become much more critical in recent years as the attack lifecycle continues to accelerate. Newly disclosed vulnerabilities are now routinely exploited within 48 hours of becoming public, leaving little room for <a href="https://www.techradar.com/best/best-patch-management-tools">patch management</a> by organizations to prepare, or even notice before they're targeted.</p><p>Detection, by contrast, still moves comparatively slowly. Breaches involving file-based attacks can go unnoticed for months, giving an intruder ample time to move laterally, extract data, or embed themselves further into connected systems before anyone realizes something is wrong.</p><p>It's not simply that attackers are fast, but that most organizations still treat file movement as something to review after the fact rather than control at the point of entry. By the time a malicious file is identified, the damage has often already been done.</p><p>This is why proactive, layered controls around every file entering or leaving the business matter more than ever. Waiting to react is not a viable strategy.</p><h2 id="establishing-continuous-file-verification">Establishing continuous file verification </h2><p>Closing this gap means shifting towards a security-first MFT process, where every file, user, and workflow is treated as a potential point of exposure rather than assumed safe by default.</p><p>Prevention is by design, rather than protection bolted on afterwards as with most traditional MFT models. And that starts with looking inside the file, not just authenticating the channel it arrives through.</p><p>Deep content inspection examines the file's actual structure, identifying hidden or malicious elements that a simple scan would miss. Alongside this, automated vulnerability detection and malware prevention should apply to every file by default, not as an optional extra reserved for high-risk transfers. Even the most innocuous file can now serve as a powerful attack vector – in fact, threat actors are counting on it.</p><p>Likewise, savvier attackers are actively designing payloads to evade detection, so standard processes need <a href="https://www.techradar.com/best/best-backup-software">backup</a>. Potentially malicious files need to be tested in a safe, isolated environment where their behavior can be observed before they ever reach a live system. This kind of sandboxing catches clues missed by reputation checks and static scanning, revealing intent rather than simply checking for known signatures.</p><p>A Content Disarm and Reconstruction (CDR) process is a valuable addition here, deconstructing files and sanitizing them by removing any active content without harming function.</p><p>However, none of this works as a single checkpoint. Each of these controls needs to feed into a continuous process, where a file is validated at every stage of its journey rather than cleared once and trusted from that point on. These capabilities should also be paired with constant monitoring and detailed audit visibility, so that if something does slip through, organizations know exactly what moved, where it went, and what it touched.</p><p>As a result, organizations can reliably build confidence in data as it crosses between environments, rather than assuming that confidence once and carrying it forward unchecked.</p><h2 id="closing-the-loop-on-trust">Closing the loop on trust</h2><p>The NCSC's warning and guidance on cross-domain systems point to the same conclusion: security built on fixed boundaries can no longer keep pace with how data actually moves.</p><p>File transfer is where that principle emerges most often in daily practice. Trust that was once given on principle must now be earned at every crossing. That shift, more than any single tool, is what will define resilient file transfer going forward.</p><p><em></em><a href="https://www.techradar.com/news/best-internet-security-suites"><em>We've reviewed, rated, and ranked the best internet security suites for PCs, Macs and mobile devices</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/rethinking-secure-file-transfer-for-a-cross-domain-world</link>
                                                                            <description>
                            <![CDATA[ Modern organizations need layered controls to secure data moving across increasingly trusted environments. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">CodgKHfXNXGc5UD3vjMc5E</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/snacLhKPDncvV3JtXYyw7M-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Aug 2026 14:23:54 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ James Neilson ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/snacLhKPDncvV3JtXYyw7M-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A portion of the globe with dotted lights criss-crossing the image connecting the countries]]></media:description>                                                            <media:text><![CDATA[A portion of the globe with dotted lights criss-crossing the image connecting the countries]]></media:text>
                                <media:title type="plain"><![CDATA[A portion of the globe with dotted lights criss-crossing the image connecting the countries]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/snacLhKPDncvV3JtXYyw7M-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK's National Cyber Security Centre recently issued a blunt warning to government and industry alike, warning that many systems are now connected "in ways their designers never anticipated", built on protocols never intended to withstand the sophistication of today's attackers.</p><p>That warning applies to all organizations relying on cross-domain processes to move data between environments with different security levels, and especially to complex cyber-physical systems where data flows between standard IT and operational technology (OT) assets.</p><p><a href="https://www.techradar.com/best/best-ways-to-transfer-files-online">File transfer</a> is one of these fundamental processes but remains one of the most often overlooked.</p><p>Every <a href="https://www.techradar.com/best/best-billing-and-invoicing-software">invoice</a> sent to a supplier, every firmware update pushed to a factory floor, every report shared with a regulator is data crossing between systems with different levels of trust.</p><p>For years, file transfer security has been treated as a solved problem. Enterprises were happy to encrypt the channel, confirm delivery, and move on. That approach made sense when systems were simpler, and threats moved more slowly. However, it no longer reflects reality.</p><h2 id="why-perimeter-based-trust-no-longer-holds">Why perimeter-based trust no longer holds</h2><p>Most file transfer platforms were never built with security as the primary goal. They were built to move data reliably between systems, encrypt the connection, confirm that a file arrived, and log that the job was done. Whether the file itself was safe was rarely part of the equation.</p><p>That gap provides a consistent way for cyber attackers to gain a foothold in their targets' systems. A file transfer platform sits between organizations by design, trusted by both sides precisely because it's meant to be routine infrastructure.</p><p>The traditional Managed File Transfer (MFT) model is built to automate file delivery, not to defend against attack. As such, it leaves the process exposed to a familiar set of threats, from man-in-the-middle interception and credential theft to <a href="https://www.techradar.com/best/best-malware-removal">malware</a> covertly embedded in an otherwise ordinary file. Attackers don't need to break the platform itself, only to exploit the assumption that whatever moves through it can be trusted.</p><p>As we've seen with incidents like 2023's MoveIT supply chain cyberattack and last year's SharePoint breach, a single vulnerability in a widely used transfer tool can give attackers access to thousands of organizations at once, simply because every one of them assumed the platform itself could be trusted.</p><p>That assumption is exactly what attackers are counting on. Securing the channel a file travels through was never the same as securing the file.</p><h2 id="the-shrinking-window-to-respond">The shrinking window to respond</h2><p>File security has always been a blind spot, but it's become much more critical in recent years as the attack lifecycle continues to accelerate. Newly disclosed vulnerabilities are now routinely exploited within 48 hours of becoming public, leaving little room for <a href="https://www.techradar.com/best/best-patch-management-tools">patch management</a> by organizations to prepare, or even notice before they're targeted.</p><p>Detection, by contrast, still moves comparatively slowly. Breaches involving file-based attacks can go unnoticed for months, giving an intruder ample time to move laterally, extract data, or embed themselves further into connected systems before anyone realizes something is wrong.</p><p>It's not simply that attackers are fast, but that most organizations still treat file movement as something to review after the fact rather than control at the point of entry. By the time a malicious file is identified, the damage has often already been done.</p><p>This is why proactive, layered controls around every file entering or leaving the business matter more than ever. Waiting to react is not a viable strategy.</p><h2 id="establishing-continuous-file-verification">Establishing continuous file verification </h2><p>Closing this gap means shifting towards a security-first MFT process, where every file, user, and workflow is treated as a potential point of exposure rather than assumed safe by default.</p><p>Prevention is by design, rather than protection bolted on afterwards as with most traditional MFT models. And that starts with looking inside the file, not just authenticating the channel it arrives through.</p><p>Deep content inspection examines the file's actual structure, identifying hidden or malicious elements that a simple scan would miss. Alongside this, automated vulnerability detection and malware prevention should apply to every file by default, not as an optional extra reserved for high-risk transfers. Even the most innocuous file can now serve as a powerful attack vector – in fact, threat actors are counting on it.</p><p>Likewise, savvier attackers are actively designing payloads to evade detection, so standard processes need <a href="https://www.techradar.com/best/best-backup-software">backup</a>. Potentially malicious files need to be tested in a safe, isolated environment where their behavior can be observed before they ever reach a live system. This kind of sandboxing catches clues missed by reputation checks and static scanning, revealing intent rather than simply checking for known signatures.</p><p>A Content Disarm and Reconstruction (CDR) process is a valuable addition here, deconstructing files and sanitizing them by removing any active content without harming function.</p><p>However, none of this works as a single checkpoint. Each of these controls needs to feed into a continuous process, where a file is validated at every stage of its journey rather than cleared once and trusted from that point on. These capabilities should also be paired with constant monitoring and detailed audit visibility, so that if something does slip through, organizations know exactly what moved, where it went, and what it touched.</p><p>As a result, organizations can reliably build confidence in data as it crosses between environments, rather than assuming that confidence once and carrying it forward unchecked.</p><h2 id="closing-the-loop-on-trust">Closing the loop on trust</h2><p>The NCSC's warning and guidance on cross-domain systems point to the same conclusion: security built on fixed boundaries can no longer keep pace with how data actually moves.</p><p>File transfer is where that principle emerges most often in daily practice. Trust that was once given on principle must now be earned at every crossing. That shift, more than any single tool, is what will define resilient file transfer going forward.</p><p><em></em><a href="https://www.techradar.com/news/best-internet-security-suites"><em>We've reviewed, rated, and ranked the best internet security suites for PCs, Macs and mobile devices</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ghosts in the machine: AI malware shows why it is time to extend Zero Trust to code ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Software security was built around human development. </p><p>People wrote, reviewed and deployed code. Now machines are taking over.  </p><p>In a recent paper, Anthropic reports that more than 80% of the code merged into its production codebase is authored by their <a href="https://www.techradar.com/best/best-ai-tools">AI</a> model, Claude. </p><p>The same capabilities that make <a href="https://www.techradar.com/best/sites-for-hiring-developers">developers</a> more productive are changing the economics of cyberattacks. </p><p>While adversaries still define the objective, machines can generate the payloads, test variants, adapt code to different environments and repeat the process at a velocity that security programs can’t match.</p><h2 id="speed-is-marginalizing-security-controls">Speed is Marginalizing Security Controls</h2><p>Most enterprise software security workflows assume there is time for review. <a href="https://www.techradar.com/pro/software-services/best-no-code-platforms">Code</a> is written, scanned, tested, approved and deployed. If something suspicious happens later, security teams investigate and respond.</p><p>That model breaks down when <a href="https://www.techradar.com/best/best-open-source-software">software</a> moves from prompt to execution in minutes.</p><p>AI-generated code can become a script, dependency, <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a> job or infrastructure change almost immediately. While development agents can modify files, resolve packages and run commands. </p><p>Human reviewers are no longer in the loop.</p><p>Attackers can use the same mechanics to generate exploits, test evasion techniques and adjust payload behavior for different targets. This creates more variation with fewer stable indicators for defenders to recognize.</p><p>While AI-assisted analysis can improve triage, it still often produces probability, not policy. At machine speed, “probably suspicious” is not good enough.</p><h2 id="machines-change-the-attack-model">Machines Change The Attack Model</h2><p>Human attackers are not disappearing. But more of the attack chain is becoming machine-executed.</p><p>AI can automate reconnaissance, accelerate vulnerability discovery, generate exploit code, rewrite payloads and adapt command sequences to the target environment. But most defensive measures are designed around human constraints: reused infrastructure, shortcuts and trackable patterns. These don’t apply to machine attacks.</p><p>A machine-generated payload may not match a known signature or have an established reputation. It may be created, used briefly and discarded. But AI <a href="https://www.techradar.com/best/best-malware-removal">malware</a> must still interact with the target environment to achieve its objective. Its behavior cannot conceal its intent, since it must access resources and change the environment in ways that advance the attack. </p><p>What malicious code is capable of doing is the more durable security signal.</p><h2 id="security-needs-to-ask-a-different-question">Security Needs to Ask A Different Question</h2><p>Software supply chain security has improved, but much of it still validates the artifact’s properties before execution rather than governing execution itself.</p><p>SBOMs, signing and provenance give security teams greater confidence in a code's composition, origin and build history. But knowing where software came from does not reveal what it will do when it runs.</p><p>Software can pass each of those checks and still create risk. Even an artifact produced through a legitimate build process may violate policy at runtime, while an AI-generated script may complete its intended task in a way that exposes data or systems. As a result, a clean dependency list is not proof of safe behavior.</p><h2 id="post-execution-detection-is-too-late">Post-Execution Detection Is Too Late</h2><p>Detection and response remain essential, but they intervene after risk has entered the environment. By the time suspicious behavior is visible, software may have accessed secrets, changed system state, opened network connections or created persistence. </p><p>AI compresses that window. Code can be generated, modified and deployed faster than humans can review it. Waiting for post-execution evidence gives attackers too much room to operate.</p><p>We need to shift the decision point left. Instead of asking, “Can we contain this software if it behaves badly?” the question should be, “Should this behavior be permitted to execute in the first place?”</p><p>That does not mean replacing existing controls, but rather changing where the decisive security gate sits.</p><h2 id="zero-trust-for-code">Zero Trust for Code</h2><p>Zero Trust changed enterprise security by rejecting implicit trust. Users, devices, sessions and access requests are not trusted simply because they appear familiar. They must be verified against policy.</p><p>Software execution needs the same level of verification.</p><p>Code should not be trusted solely because it came from a known repository, was signed by a recognized publisher, passed through a build pipeline or has not been seen exhibiting malicious behavior before. Those are useful indicators, but they are not conclusive.</p><p>Zero Trust for Code addresses this problem. Before software runs, its expected behavior should be evaluated against policy. If the behavior is acceptable, execution can proceed. If not, the artifact should be blocked, restricted, isolated or escalated for review.</p><p>Organizations can start by mapping every path through which code enters the environment or executes with meaningful privilege. This includes formal development channels such as repositories, open-source packages, containers and CI/CD pipelines, as well as email attachments, downloaded files, macros, browser extensions, endpoint installers, third-party integrations and scripts introduced through AI or automation tools. </p><p>Then identify where those paths rely on inherited trust. If execution is allowed because software came from an approved source, was signed, passed through a build process or has no malicious history, the control is incomplete. Behavior still has to be evaluated before the artifact is allowed to run.</p><p>As AI takes on more of the work of creating legitimate and malicious code, enterprises can no longer assume that code which clears existing checks should be allowed to run. Execution must become a deliberate security decision.</p><p><em></em><a href="https://www.techradar.com/news/best-internet-security-suites"><em>We've listed the best internet security suites for PCs, Macs and mobile devices</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/ghosts-in-the-machine-ai-malware-shows-why-it-is-time-to-extend-zero-trust-to-code</link>
                                                                            <description>
                            <![CDATA[ AI-generated malware is outpacing human-centered security controls, find out how enterprises can fight back. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">x7wbtdtY98HrDXmeoU79w</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Aug 2026 10:41:24 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ken Ammon ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:description>                                                            <media:text><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:text>
                                <media:title type="plain"><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Software security was built around human development. </p><p>People wrote, reviewed and deployed code. Now machines are taking over.  </p><p>In a recent paper, Anthropic reports that more than 80% of the code merged into its production codebase is authored by their <a href="https://www.techradar.com/best/best-ai-tools">AI</a> model, Claude. </p><p>The same capabilities that make <a href="https://www.techradar.com/best/sites-for-hiring-developers">developers</a> more productive are changing the economics of cyberattacks. </p><p>While adversaries still define the objective, machines can generate the payloads, test variants, adapt code to different environments and repeat the process at a velocity that security programs can’t match.</p><h2 id="speed-is-marginalizing-security-controls">Speed is Marginalizing Security Controls</h2><p>Most enterprise software security workflows assume there is time for review. <a href="https://www.techradar.com/pro/software-services/best-no-code-platforms">Code</a> is written, scanned, tested, approved and deployed. If something suspicious happens later, security teams investigate and respond.</p><p>That model breaks down when <a href="https://www.techradar.com/best/best-open-source-software">software</a> moves from prompt to execution in minutes.</p><p>AI-generated code can become a script, dependency, <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a> job or infrastructure change almost immediately. While development agents can modify files, resolve packages and run commands. </p><p>Human reviewers are no longer in the loop.</p><p>Attackers can use the same mechanics to generate exploits, test evasion techniques and adjust payload behavior for different targets. This creates more variation with fewer stable indicators for defenders to recognize.</p><p>While AI-assisted analysis can improve triage, it still often produces probability, not policy. At machine speed, “probably suspicious” is not good enough.</p><h2 id="machines-change-the-attack-model">Machines Change The Attack Model</h2><p>Human attackers are not disappearing. But more of the attack chain is becoming machine-executed.</p><p>AI can automate reconnaissance, accelerate vulnerability discovery, generate exploit code, rewrite payloads and adapt command sequences to the target environment. But most defensive measures are designed around human constraints: reused infrastructure, shortcuts and trackable patterns. These don’t apply to machine attacks.</p><p>A machine-generated payload may not match a known signature or have an established reputation. It may be created, used briefly and discarded. But AI <a href="https://www.techradar.com/best/best-malware-removal">malware</a> must still interact with the target environment to achieve its objective. Its behavior cannot conceal its intent, since it must access resources and change the environment in ways that advance the attack. </p><p>What malicious code is capable of doing is the more durable security signal.</p><h2 id="security-needs-to-ask-a-different-question">Security Needs to Ask A Different Question</h2><p>Software supply chain security has improved, but much of it still validates the artifact’s properties before execution rather than governing execution itself.</p><p>SBOMs, signing and provenance give security teams greater confidence in a code's composition, origin and build history. But knowing where software came from does not reveal what it will do when it runs.</p><p>Software can pass each of those checks and still create risk. Even an artifact produced through a legitimate build process may violate policy at runtime, while an AI-generated script may complete its intended task in a way that exposes data or systems. As a result, a clean dependency list is not proof of safe behavior.</p><h2 id="post-execution-detection-is-too-late">Post-Execution Detection Is Too Late</h2><p>Detection and response remain essential, but they intervene after risk has entered the environment. By the time suspicious behavior is visible, software may have accessed secrets, changed system state, opened network connections or created persistence. </p><p>AI compresses that window. Code can be generated, modified and deployed faster than humans can review it. Waiting for post-execution evidence gives attackers too much room to operate.</p><p>We need to shift the decision point left. Instead of asking, “Can we contain this software if it behaves badly?” the question should be, “Should this behavior be permitted to execute in the first place?”</p><p>That does not mean replacing existing controls, but rather changing where the decisive security gate sits.</p><h2 id="zero-trust-for-code">Zero Trust for Code</h2><p>Zero Trust changed enterprise security by rejecting implicit trust. Users, devices, sessions and access requests are not trusted simply because they appear familiar. They must be verified against policy.</p><p>Software execution needs the same level of verification.</p><p>Code should not be trusted solely because it came from a known repository, was signed by a recognized publisher, passed through a build pipeline or has not been seen exhibiting malicious behavior before. Those are useful indicators, but they are not conclusive.</p><p>Zero Trust for Code addresses this problem. Before software runs, its expected behavior should be evaluated against policy. If the behavior is acceptable, execution can proceed. If not, the artifact should be blocked, restricted, isolated or escalated for review.</p><p>Organizations can start by mapping every path through which code enters the environment or executes with meaningful privilege. This includes formal development channels such as repositories, open-source packages, containers and CI/CD pipelines, as well as email attachments, downloaded files, macros, browser extensions, endpoint installers, third-party integrations and scripts introduced through AI or automation tools. </p><p>Then identify where those paths rely on inherited trust. If execution is allowed because software came from an approved source, was signed, passed through a build process or has no malicious history, the control is incomplete. Behavior still has to be evaluated before the artifact is allowed to run.</p><p>As AI takes on more of the work of creating legitimate and malicious code, enterprises can no longer assume that code which clears existing checks should be allowed to run. Execution must become a deliberate security decision.</p><p><em></em><a href="https://www.techradar.com/news/best-internet-security-suites"><em>We've listed the best internet security suites for PCs, Macs and mobile devices</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hundreds of fake Chrome VPN extensions impersonating NordVPN, Proton, and more caught hijacking your traffic ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Socket's Threat Research Team found 737 fake VPN and proxy extensions on the Chrome Web Store, with more than 75,000 combined installs</strong></li><li><strong>The add-ons pose as trusted names like Proton VPN and NordVPN while routing your entire browser session through proxies run by one operator</strong></li><li><strong>Hundreds are still live, so it's worth checking your browser now and removing anything suspicious</strong></li></ul><p>A new investigation has exposed a huge cluster of counterfeit VPN extensions that promise privacy while rerouting your traffic.</p><p><a href="https://socket.dev/blog/chrome-vpn-extension-impersonation" target="_blank" rel="nofollow">Socket's Threat Research Team</a> said it identified 737 free VPN and proxy extensions published across at least 40 Chrome Web Store developer accounts. More than 27o of these impersonate 66 of the <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> services and privacy brands, including big names like <a href="https://www.techradar.com/reviews/nordvpn">NordVPN</a> and <a href="https://www.techradar.com/reviews/protonvpn">Proton VPN</a>. </p><p>Between them, the extensions racked up more than 75,000 installs, mostly among Russian-speaking users hunting for ways to reach blocked services.</p><p>If you use Chrome and rely on a browser add-on to stay private, it's worth making sure the one you installed is a genuine product from a real provider rather than one of these lookalikes.</p><h2 id="what-the-researchers-found">What the researchers found</h2><p>Socket's team traced the whole network back to a single Russian VPN subscription business trading as Myxa VPN. </p><p>The researchers linked the extensions using a shared analytics account, clustered domain registrations, common hosting, and leaked Windows build paths pointing to one project folder. The free extensions appear to act as a funnel, nudging users toward a paid subscription.</p><p>Some of the paid promises were pure fiction. Socket says the premium tiers advertised servers in countries like Japan, Singapore, and Australia, but when it tested 200 premium hostnames across 40 domains, none returned an A record, meaning those servers simply did not exist.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/2087321016624439534"><p lang="en" dir="ltr">Socket’s Threat Research Team found 737 Chrome VPN extensions in one campaign. 274 impersonated trusted brands, while 520 routed all browser traffic through shared infrastructure.The campaign’s paid plan listed 200 server hostnames. Not one resolved.https://t.co/Nwz02e3ncb<a href="https://twitter.com/cantworkitout/status/2087321016624439534">August 11, 2026</a></p></blockquote></figure><div class="see-more__filter"></div></div><p>The core trick is the same across nearly every extension. Once you press Connect, everything you browse gets pushed through a server the operator controls, with no per-site exceptions.</p><p>It adds no <a href="https://www.techradar.com/vpn/what-is-encryption">encryption</a>, so it isn't doing the protective work a real VPN would. Worse, 104 extensions resolved their proxy addresses through Cloudflare or Google DNS-over-HTTPS and handed Chrome a raw IP, a technique that makes the operator's servers harder to block or spot.</p><h2 id="why-fake-vpn-are-dangerous-and-how-to-stay-safe">Why fake VPN are dangerous, and how to stay safe</h2><p>Sitting in the middle of your traffic gives the operator a clear view. Socket says the setup lets whoever runs the proxy observe the websites you visit, TLS SNI metadata, your source <a href="https://www.techradar.com/pro/what-is-an-ip-address">IP address,</a> and any data sent over unencrypted HTTP. That means anything you type into a non-HTTPS page, including logins, could be exposed.</p><p>Socket doesn't know whether this data has actually been collected or misused, but the fact that it can be is the problem. It's the same pattern behind earlier warnings about <a href="https://www.techradar.com/vpn/vpn-privacy-security/fake-proton-vpn-extensions-slip-into-chrome-web-store-heres-how-to-stay-safe">fake VPN extensions in the Chrome Web Store</a> and <a href="https://www.techradar.com/vpn/vpn-privacy-security/google-issues-security-alert-your-vpn-app-could-be-spyware-in-disguise">Google's own alerts about spyware posing as VPN apps</a>.</p><p>Google has already acted, but not completely. By the time Socket collected its data, 221 of the 737 extensions had been removed, while 516 remained listed, so the threat hasn't fully gone away.</p><p>If you think you installed one, the advice from Socket is straightforward. Remove the extension immediately, then check that Chrome's proxy configuration has returned to normal and change any credentials you entered on non-HTTPS sites while it was active. You can review your proxy settings by heading to your browser settings and searching for "proxy."</p><div data-widget-type="multimodelreview" data-model-name="NordVPN,Surfshark,Proton VPN" data-widget-title="Today's best VPN deals" class="hawk-root"></div> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/vpn/vpn-services/hundreds-of-fake-chrome-vpn-extensions-impersonating-nordvpn-proton-and-more-caught-hijacking-your-traffic</link>
                                                                            <description>
                            <![CDATA[ Socket's Threat Research Team uncovered 737 fake Chrome VPN extensions impersonating major brands and rerouting browser traffic through their own proxies. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8MLogZ68m4QzZc2nM4Hy2o</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZfhFwGtGeLFq7LEuTgCMbD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Aug 2026 16:23:01 +0000</pubDate>                                                                                                                                <updated>Fri, 14 Aug 2026 16:27:52 +0000</updated>
                                                                                                                                            <category><![CDATA[VPN Privacy &amp; Security]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                                                                <author><![CDATA[ monicajwrites@gmail.com (Monica J. White) ]]></author>                    <dc:creator><![CDATA[ Monica J. White ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/6AQ4y5nzk8kQ47Yp69GERj.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Monica is a journalist with over a decade of experience in covering technology.&lt;/p&gt;&lt;p&gt;She writes about the latest developments in computing, which means anything from computer chips made out of paper to cutting-edge desktop processors. Her coverage includes CPUs, GPUs, and everything else that goes into a PC or a laptop, but also peripherals.&lt;/p&gt;&lt;p&gt;GPUs are Monica’s main area of interest, and nothing thrills her quite like that time every couple of years when new graphics cards hit the market. She’s always keeping tabs on the latest from Nvidia, AMD, and Intel, including both the hardware and the software that powers our PCs.&lt;/p&gt;&lt;p&gt;As an avid gamer, her focus is always on the consumer and whether something works well and provides adequate value for the money. She believes that PC building can be intimidating, so her goal is to explain complex concepts in an approachable manner while still digging into the technical nitty-gritty we all love to learn more about.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZfhFwGtGeLFq7LEuTgCMbD-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / Ink Drop]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Silhouette of a hand holding a padlock infront of the google chrome logo]]></media:description>                                                            <media:text><![CDATA[Silhouette of a hand holding a padlock infront of the google chrome logo]]></media:text>
                                <media:title type="plain"><![CDATA[Silhouette of a hand holding a padlock infront of the google chrome logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZfhFwGtGeLFq7LEuTgCMbD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Socket's Threat Research Team found 737 fake VPN and proxy extensions on the Chrome Web Store, with more than 75,000 combined installs</strong></li><li><strong>The add-ons pose as trusted names like Proton VPN and NordVPN while routing your entire browser session through proxies run by one operator</strong></li><li><strong>Hundreds are still live, so it's worth checking your browser now and removing anything suspicious</strong></li></ul><p>A new investigation has exposed a huge cluster of counterfeit VPN extensions that promise privacy while rerouting your traffic.</p><p><a href="https://socket.dev/blog/chrome-vpn-extension-impersonation" target="_blank" rel="nofollow">Socket's Threat Research Team</a> said it identified 737 free VPN and proxy extensions published across at least 40 Chrome Web Store developer accounts. More than 27o of these impersonate 66 of the <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> services and privacy brands, including big names like <a href="https://www.techradar.com/reviews/nordvpn">NordVPN</a> and <a href="https://www.techradar.com/reviews/protonvpn">Proton VPN</a>. </p><p>Between them, the extensions racked up more than 75,000 installs, mostly among Russian-speaking users hunting for ways to reach blocked services.</p><p>If you use Chrome and rely on a browser add-on to stay private, it's worth making sure the one you installed is a genuine product from a real provider rather than one of these lookalikes.</p><h2 id="what-the-researchers-found">What the researchers found</h2><p>Socket's team traced the whole network back to a single Russian VPN subscription business trading as Myxa VPN. </p><p>The researchers linked the extensions using a shared analytics account, clustered domain registrations, common hosting, and leaked Windows build paths pointing to one project folder. The free extensions appear to act as a funnel, nudging users toward a paid subscription.</p><p>Some of the paid promises were pure fiction. Socket says the premium tiers advertised servers in countries like Japan, Singapore, and Australia, but when it tested 200 premium hostnames across 40 domains, none returned an A record, meaning those servers simply did not exist.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/2087321016624439534"><p lang="en" dir="ltr">Socket’s Threat Research Team found 737 Chrome VPN extensions in one campaign. 274 impersonated trusted brands, while 520 routed all browser traffic through shared infrastructure.The campaign’s paid plan listed 200 server hostnames. Not one resolved.https://t.co/Nwz02e3ncb<a href="https://twitter.com/cantworkitout/status/2087321016624439534">August 11, 2026</a></p></blockquote></figure><div class="see-more__filter"></div></div><p>The core trick is the same across nearly every extension. Once you press Connect, everything you browse gets pushed through a server the operator controls, with no per-site exceptions.</p><p>It adds no <a href="https://www.techradar.com/vpn/what-is-encryption">encryption</a>, so it isn't doing the protective work a real VPN would. Worse, 104 extensions resolved their proxy addresses through Cloudflare or Google DNS-over-HTTPS and handed Chrome a raw IP, a technique that makes the operator's servers harder to block or spot.</p><h2 id="why-fake-vpn-are-dangerous-and-how-to-stay-safe">Why fake VPN are dangerous, and how to stay safe</h2><p>Sitting in the middle of your traffic gives the operator a clear view. Socket says the setup lets whoever runs the proxy observe the websites you visit, TLS SNI metadata, your source <a href="https://www.techradar.com/pro/what-is-an-ip-address">IP address,</a> and any data sent over unencrypted HTTP. That means anything you type into a non-HTTPS page, including logins, could be exposed.</p><p>Socket doesn't know whether this data has actually been collected or misused, but the fact that it can be is the problem. It's the same pattern behind earlier warnings about <a href="https://www.techradar.com/vpn/vpn-privacy-security/fake-proton-vpn-extensions-slip-into-chrome-web-store-heres-how-to-stay-safe">fake VPN extensions in the Chrome Web Store</a> and <a href="https://www.techradar.com/vpn/vpn-privacy-security/google-issues-security-alert-your-vpn-app-could-be-spyware-in-disguise">Google's own alerts about spyware posing as VPN apps</a>.</p><p>Google has already acted, but not completely. By the time Socket collected its data, 221 of the 737 extensions had been removed, while 516 remained listed, so the threat hasn't fully gone away.</p><p>If you think you installed one, the advice from Socket is straightforward. Remove the extension immediately, then check that Chrome's proxy configuration has returned to normal and change any credentials you entered on non-HTTPS sites while it was active. You can review your proxy settings by heading to your browser settings and searching for "proxy."</p><div data-widget-type="multimodelreview" data-model-name="NordVPN,Surfshark,Proton VPN" data-widget-title="Today's best VPN deals" class="hawk-root"></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Android users targeted by new WindRelay malware which can clone contactless cards in just 13 minutes ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>WindRelay campaign used vishing plus custom malware to turn phones into POS skimmers</strong></li><li><strong>Victims installed personalized RATs and NFC malware, enabling real‑time card theft</strong></li><li><strong>Attacks were highly targeted across Eastern Europe, with only a few individuals hit</strong></li></ul><p>Hackers are turning people’s smartphones into malicious <a href="https://www.techradar.com/news/the-best-pos-system" target="_blank">Point of Sale</a> (POS) devices and stealing their money directly from their payment cards, experts have warned. </p><p>Security researchers Group-IB spotted multiple such attacks across Eastern Europe, and named the campaign <a href="https://www.group-ib.com/blog/windrelay-nfc-spynote-rat-combo-fraud/" target="_blank">WindRelay</a>, after the custom-built malware used during the attacks.</p><p>The report notes this is a highly sophisticated, custom-tailored attack designed specifically for the victim. It starts with some form of reconnaissance, in which the attackers learn their victim’s identity, phone number, and likely other details. Although the researchers don’t discuss it, it is quite possible that the attackers obtained (or purchased) the data from unrelated data breaches and leaks.</p><h2 id="vishing-and-malware">Vishing and malware</h2><p>After learning a little bit about their target, the attackers get to work. They first prepare a remote access trojan (RAT) named SpyNote. They personalize the label with the victim’s own name (instead of it being a generic or impersonated brand), to build trust with their victim:</p><p>“Such tactics are more effective at weakening a victim’s natural defenses and suspicions,” the researchers noted in the report. “It removes the one cue people are trained to check before installing something unfamiliar — a strange or generic app name — right at the moment they’re most likely to hesitate.”</p><p>Then, they call the victim on the phone and introduce themselves as employees of their target’s bank. They claim the victim has a problem with their bank card, and instruct them to deploy SpyNote through the device’s package installer (the standard way to sideload apps outside an official app store).</p><p>SpyNote is a classic RAT that the attackers then use to deploy stage-two malware themselves. In this next step, they personally (as opposed to having the victim do it) install WindRelay, custom near-field communication (NFC) malware designed to capture contactless payment card data in real-time, when a card is tapped against the phone. </p><p>In other words, the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> turns the smartphone into a POS, and when a victim taps their card against it, the information is relayed to an attacker’s terminal. </p><h2 id="vishing-malware">Vishing + malware</h2><p>Vishing + malware combo is nothing new. We’ve seen it deployed numerous times before, and ShinyHunters are probably the shiniest example of the practice (pun definitely intended). Over the last couple of years, ShinyHunters have been calling their victims on the phone, impersonating the IT department, and getting their victims to log in via fake login portals which relay the credentials to the attackers.</p><p>They then use the credentials to access their victims’ SaaS products, exfiltrate as much sensitive data as possible, and then demand ransom in exchange for deleting the stolen files.</p><p>This new campaign, however, is a testament to the technique’s evolution. While ShinyHunters’ operatives only stay on the phone call until the victim logs in, these crooks remain on the line for as long as it takes. Group-IB says the average call lasts around 13 minutes, and by that moment, the victim will have installed both SpyNote and WindRelay, and has tapped their bank card against the phone, making unwanted payments.</p><p>In at least one case, the attackers successfully applied for a loan at the victim’s bank, stealing not only the money they had on their account, but also money they would have earned in the future.</p><p>The identity of the attackers is unknown at the time. We also don’t know exactly how many victims there were, but given the highly personalized nature of the attack, it’s safe to assume that there were only a handful.</p><p>Group-IB says it observed attacks in Czechia, Slovakia, and Slovenia, suggesting a threat actor focused primarily on Eastern European victims. The researchers also said they identified 23 samples uploaded to VirusTotal between November 2025 and July 2026, meaning the campaign was active for approximately seven months, targeting 23 individuals. </p><p>“The samples mimic various institutions from the targeted countries and contain text in the language of each targeted country,” the researchers said. “Some samples contain personalized UI elements and labels, such as the name of the victim, similar to the personalized RAT. This suggests the threat actor behind these campaigns most likely has the capability to dynamically build malicious applications tailored to individual victims.”</p><p>Group-IB says users should treat personalized app labels as a red flag and should apply extra friction to loan applications. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/android-users-targeted-by-new-windrelay-malware-which-can-clone-contactless-cards-in-just-13-minutes</link>
                                                                            <description>
                            <![CDATA[ Crooks are calling victims on the phone and installing POS malware on their smartphones. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">shwHxntyNEjscciJEjL9Li</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5kMrDAjQJGcdHytVASFjn5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 15:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5kMrDAjQJGcdHytVASFjn5-1280-80.jpg">
                                                            <media:credit><![CDATA[Rapeepong Puttakumwong via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Person pays using POS hardware card reader]]></media:description>                                                            <media:text><![CDATA[Person pays using POS hardware card reader]]></media:text>
                                <media:title type="plain"><![CDATA[Person pays using POS hardware card reader]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5kMrDAjQJGcdHytVASFjn5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>WindRelay campaign used vishing plus custom malware to turn phones into POS skimmers</strong></li><li><strong>Victims installed personalized RATs and NFC malware, enabling real‑time card theft</strong></li><li><strong>Attacks were highly targeted across Eastern Europe, with only a few individuals hit</strong></li></ul><p>Hackers are turning people’s smartphones into malicious <a href="https://www.techradar.com/news/the-best-pos-system" target="_blank">Point of Sale</a> (POS) devices and stealing their money directly from their payment cards, experts have warned. </p><p>Security researchers Group-IB spotted multiple such attacks across Eastern Europe, and named the campaign <a href="https://www.group-ib.com/blog/windrelay-nfc-spynote-rat-combo-fraud/" target="_blank">WindRelay</a>, after the custom-built malware used during the attacks.</p><p>The report notes this is a highly sophisticated, custom-tailored attack designed specifically for the victim. It starts with some form of reconnaissance, in which the attackers learn their victim’s identity, phone number, and likely other details. Although the researchers don’t discuss it, it is quite possible that the attackers obtained (or purchased) the data from unrelated data breaches and leaks.</p><h2 id="vishing-and-malware">Vishing and malware</h2><p>After learning a little bit about their target, the attackers get to work. They first prepare a remote access trojan (RAT) named SpyNote. They personalize the label with the victim’s own name (instead of it being a generic or impersonated brand), to build trust with their victim:</p><p>“Such tactics are more effective at weakening a victim’s natural defenses and suspicions,” the researchers noted in the report. “It removes the one cue people are trained to check before installing something unfamiliar — a strange or generic app name — right at the moment they’re most likely to hesitate.”</p><p>Then, they call the victim on the phone and introduce themselves as employees of their target’s bank. They claim the victim has a problem with their bank card, and instruct them to deploy SpyNote through the device’s package installer (the standard way to sideload apps outside an official app store).</p><p>SpyNote is a classic RAT that the attackers then use to deploy stage-two malware themselves. In this next step, they personally (as opposed to having the victim do it) install WindRelay, custom near-field communication (NFC) malware designed to capture contactless payment card data in real-time, when a card is tapped against the phone. </p><p>In other words, the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> turns the smartphone into a POS, and when a victim taps their card against it, the information is relayed to an attacker’s terminal. </p><h2 id="vishing-malware">Vishing + malware</h2><p>Vishing + malware combo is nothing new. We’ve seen it deployed numerous times before, and ShinyHunters are probably the shiniest example of the practice (pun definitely intended). Over the last couple of years, ShinyHunters have been calling their victims on the phone, impersonating the IT department, and getting their victims to log in via fake login portals which relay the credentials to the attackers.</p><p>They then use the credentials to access their victims’ SaaS products, exfiltrate as much sensitive data as possible, and then demand ransom in exchange for deleting the stolen files.</p><p>This new campaign, however, is a testament to the technique’s evolution. While ShinyHunters’ operatives only stay on the phone call until the victim logs in, these crooks remain on the line for as long as it takes. Group-IB says the average call lasts around 13 minutes, and by that moment, the victim will have installed both SpyNote and WindRelay, and has tapped their bank card against the phone, making unwanted payments.</p><p>In at least one case, the attackers successfully applied for a loan at the victim’s bank, stealing not only the money they had on their account, but also money they would have earned in the future.</p><p>The identity of the attackers is unknown at the time. We also don’t know exactly how many victims there were, but given the highly personalized nature of the attack, it’s safe to assume that there were only a handful.</p><p>Group-IB says it observed attacks in Czechia, Slovakia, and Slovenia, suggesting a threat actor focused primarily on Eastern European victims. The researchers also said they identified 23 samples uploaded to VirusTotal between November 2025 and July 2026, meaning the campaign was active for approximately seven months, targeting 23 individuals. </p><p>“The samples mimic various institutions from the targeted countries and contain text in the language of each targeted country,” the researchers said. “Some samples contain personalized UI elements and labels, such as the name of the victim, similar to the personalized RAT. This suggests the threat actor behind these campaigns most likely has the capability to dynamically build malicious applications tailored to individual victims.”</p><p>Group-IB says users should treat personalized app labels as a red flag and should apply extra friction to loan applications. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Windows users face six times more malware than Mac owners, Surfshark reveals — but 'Macs are safer' is only half true ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Surfshark recorded nearly 6 times as many malware detections on Windows</strong></li><li><strong>While trojans mostly target Windows devices, phishing lands harder on Mac</strong></li><li><strong>A "Macs are safe" mindset may leave users more at risk of social engineering</strong></li></ul><p>New data from <a href="https://surfshark.com/research/chart/malware-detections-windows-vs-macos">Surfshark</a> shows a stark split in how malware finds its targets: Windows users are hit at nearly six times the rate of macOS users.</p><p>The headline number is eye-catching, but the full story is more interesting. While Windows soaks up the vast majority of traditional <a href="https://www.techradar.com/news/what-is-malware-and-how-dangerous-is-it">malware</a>, Mac users face a very different kind of threat, one that a locked-down operating system does little to stop: <a href="https://www.techradar.com/news/everything-you-need-to-know-about-phishing">phishing</a>.</p><p><a href="https://www.techradar.com/best/best-antivirus">Antivirus </a>software paired with one of the <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> services remains a sensible layer of defence, whatever you run, but <a href="https://bit.ly/3SAbtut" target="_blank" rel="nofollow">Surfshark's findings</a> are a useful reminder that while risks change depending on the platform, they never disappear.</p><div class="product"><a data-dimension112="ff4c4aa2-9660-11f1-89b4-1f3684d9c300" data-action="Deal Block" data-label="Surfshark &ndash; the best cheap VPNSurfshark is a fast, easy-to-use VPN that seriously beats the competition when it comes to subscription pricing. Its two-year Starter plan works out at $2.49 a month (plus tax), but we think Surfshark One is the best value plan as it adds an antivirus, data breach monitor, and alternative ID tool starting from the equivalent of  $2.79 a month. Surfshark – the best cheap VPN" data-dimension48="Surfshark &ndash; the best cheap VPNSurfshark is a fast, easy-to-use VPN that seriously beats the competition when it comes to subscription pricing. Its two-year Starter plan works out at $2.49 a month (plus tax), but we think Surfshark One is the best value plan as it adds an antivirus, data breach monitor, and alternative ID tool starting from the equivalent of  $2.79 a month. Surfshark – the best cheap VPN" href="https://get.surfshark.net/aff_c?offer_id=1030&aff_id=1691&url_id=2561" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="pSwRio45uPDhdN5egHcYF" name="Surfshark deal image.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/pSwRio45uPDhdN5egHcYF.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong></strong><a href="http://get.surfshark.net/aff_c?offer_id=61&aff_id=1691" target="_blank" rel="nofollow" data-dimension112="ff4c4aa2-9660-11f1-89b4-1f3684d9c300" data-action="Deal Block" data-label="Surfshark &ndash; the best cheap VPNSurfshark is a fast, easy-to-use VPN that seriously beats the competition when it comes to subscription pricing. Its two-year Starter plan works out at $2.49 a month (plus tax), but we think Surfshark One is the best value plan as it adds an antivirus, data breach monitor, and alternative ID tool starting from the equivalent of  $2.79 a month. Surfshark – the best cheap VPN" data-dimension48="Surfshark &ndash; the best cheap VPNSurfshark is a fast, easy-to-use VPN that seriously beats the competition when it comes to subscription pricing. Its two-year Starter plan works out at $2.49 a month (plus tax), but we think Surfshark One is the best value plan as it adds an antivirus, data breach monitor, and alternative ID tool starting from the equivalent of  $2.79 a month. Surfshark – the best cheap VPN" data-dimension25=""><strong>Surfshark – the best cheap VPN</strong></a><strong></strong><br>Surfshark is a fast, easy-to-use VPN that seriously beats the competition when it comes to subscription pricing. Its two-year Starter plan works out at $2.49 a month<strong> </strong>(plus tax), but we think Surfshark One is the best value plan as it adds an antivirus, data breach monitor, and alternative ID tool starting from the equivalent of  $2.79 a month. <a class="view-deal button" href="https://get.surfshark.net/aff_c?offer_id=1030&aff_id=1691&url_id=2561" target="_blank" rel="nofollow" data-dimension112="ff4c4aa2-9660-11f1-89b4-1f3684d9c300" data-action="Deal Block" data-label="Surfshark &ndash; the best cheap VPNSurfshark is a fast, easy-to-use VPN that seriously beats the competition when it comes to subscription pricing. Its two-year Starter plan works out at $2.49 a month (plus tax), but we think Surfshark One is the best value plan as it adds an antivirus, data breach monitor, and alternative ID tool starting from the equivalent of  $2.79 a month. Surfshark – the best cheap VPN" data-dimension48="Surfshark &ndash; the best cheap VPNSurfshark is a fast, easy-to-use VPN that seriously beats the competition when it comes to subscription pricing. Its two-year Starter plan works out at $2.49 a month (plus tax), but we think Surfshark One is the best value plan as it adds an antivirus, data breach monitor, and alternative ID tool starting from the equivalent of  $2.79 a month. Surfshark – the best cheap VPN" data-dimension25="">View Deal</a></p></div><h2 id="the-six-times-gap-by-the-numbers">The six-times gap, by the numbers</h2><p>Surfshark analysed 391,305 malware detections logged by its antivirus between 1 January and 31 July 2026. Windows devices made up 66% of the active user base but accounted for a striking 92% of all detections, while macOS users represented 34% of the base yet just 8% of threats. </p><p>That works out to nearly six Windows detections for every one on a Mac.</p><p>"Windows' popularity has always made it the biggest target for cybercriminals," said Gabrielė Sinkevičiūtė, Head of Product at Surfshark, pointing to the scale of malware built around Windows' dominant market share, along with differences in how each platform handles third-party software and permissions.</p><p><a href="https://bit.ly/3TK4q2N" target="_blank" rel="nofollow">Surfshark's equivalent research</a> from last year yielded similar results, so the trend appears to be consistent.</p><h2 id="trojans-dominate-windows-while-phishing-surges-on-mac">Trojans dominate Windows, while phishing surges on Mac</h2><a href="https://bit.ly/3SAbtut"><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1172px;"><p class="vanilla-image-block" style="padding-top:68.17%;"><img id="xj4Tb5sFYs2sBwDTnEdTUW" name="unnamed (1)" alt="Surfshark's graph showing its Antivirus malware detection data on Windows and macOS (August 2026)" src="https://cdn.mos.cms.futurecdn.net/xj4Tb5sFYs2sBwDTnEdTUW.png" mos="" align="middle" fullscreen="" width="1172" height="799" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="caption-text">Surfshark's new Antiscam hub combines a number of its existing features into one easily navigated location </span><span class="credit" itemprop="copyrightHolder">(Image credit: Surfshark)</span></figcaption></figure></a><p>The threat mix differs sharply by platform. Trojans (malicious software hiding inside safe programs) were the top danger on Windows at 46% of detections, versus 25% on macOS, while riskware (legitimate software that can pose security threats) sat at 19% and 17% respectively. Viruses were level at 9% on both, and adware (software that puts unwanted ads on your device) trailed at 4% on Windows and 3% on Mac.</p><p><a href="https://www.techradar.com/news/everything-you-need-to-know-about-phishing">Phishing</a> is where Mac users lose ground. It ranked third on macOS at 15% of detections, but only sixth on Windows at 3%. Because phishing exploits trust rather than software flaws, a hardened operating system offers little protection, and Surfshark argues a false sense of security can make Mac owners slower to question a suspicious message.</p><p>Other research backs this up. <a href="https://www.microsoft.com/en-us/security/blog/2026/02/02/infostealers-without-borders-macos-python-stealers-and-platform-abuse/" target="_blank" rel="nofollow">Microsoft reported</a> in early 2026 that infostealer campaigns are expanding beyond Windows onto macOS using social-engineering tricks such as ClickFix prompts and fake installers, and <a href="https://www.malwarebytes.com/blog/mobile/2025/02/macs-targeted-by-info-stealers-in-new-era-of-cyberthreats" target="_blank" rel="nofollow">Malwarebytes</a> has tracked Mac infostealers becoming a mainstream threat rather than a rarity. TechRadar has likewise reported that <a href="https://www.techradar.com/pro/the-mythical-security-status-of-macos-is-no-more-report-finds-apple-devices-fare-the-worst-when-it-comes-to-full-takeover-risks">the "mythical" security status of macOS is fading</a>.</p><h2 id="how-to-stay-safe">How to stay safe</h2><p>The core advice is the same on both platforms: treat unexpected links, attachments and login prompts with suspicion, keep your operating system and apps patched, and only install software from official sources. </p><p>Never paste a command into Terminal or PowerShell because a website told you to, as that single step drives many recent Mac infections.</p><p>Running reputable antivirus software helps on either system, but the biggest fix for Mac users may be a change in attitude. Dropping the assumption that Apple hardware is inherently immune is the first real step toward not becoming the softer target.</p><div data-widget-type="review" data-model-name="Surfshark" class="hawk-root"></div> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/vpn/vpn-services/windows-users-face-six-times-more-malware-than-mac-owners-surfshark-reveals-but-macs-are-safer-is-only-half-true</link>
                                                                            <description>
                            <![CDATA[ New Surfshark data shows Windows users hit nearly six times more malware than Mac users, but Mac owners face a bigger phishing risk thanks to a false sense of security. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">EgEUaTKec78PM3a9oqtBSo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8wom7TXsEex7ExUd8LhF2n-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 09:14:22 +0000</pubDate>                                                                                                                                <updated>Thu, 13 Aug 2026 09:16:05 +0000</updated>
                                                                                                                                            <category><![CDATA[VPN Services]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                                                                <author><![CDATA[ monicajwrites@gmail.com (Monica J. White) ]]></author>                    <dc:creator><![CDATA[ Monica J. White ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/6AQ4y5nzk8kQ47Yp69GERj.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Monica is a journalist with over a decade of experience in covering technology.&lt;/p&gt;&lt;p&gt;She writes about the latest developments in computing, which means anything from computer chips made out of paper to cutting-edge desktop processors. Her coverage includes CPUs, GPUs, and everything else that goes into a PC or a laptop, but also peripherals.&lt;/p&gt;&lt;p&gt;GPUs are Monica’s main area of interest, and nothing thrills her quite like that time every couple of years when new graphics cards hit the market. She’s always keeping tabs on the latest from Nvidia, AMD, and Intel, including both the hardware and the software that powers our PCs.&lt;/p&gt;&lt;p&gt;As an avid gamer, her focus is always on the consumer and whether something works well and provides adequate value for the money. She believes that PC building can be intimidating, so her goal is to explain complex concepts in an approachable manner while still digging into the technical nitty-gritty we all love to learn more about.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8wom7TXsEex7ExUd8LhF2n-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.]]></media:description>                                                            <media:text><![CDATA[A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.]]></media:text>
                                <media:title type="plain"><![CDATA[A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8wom7TXsEex7ExUd8LhF2n-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Surfshark recorded nearly 6 times as many malware detections on Windows</strong></li><li><strong>While trojans mostly target Windows devices, phishing lands harder on Mac</strong></li><li><strong>A "Macs are safe" mindset may leave users more at risk of social engineering</strong></li></ul><p>New data from <a href="https://surfshark.com/research/chart/malware-detections-windows-vs-macos">Surfshark</a> shows a stark split in how malware finds its targets: Windows users are hit at nearly six times the rate of macOS users.</p><p>The headline number is eye-catching, but the full story is more interesting. While Windows soaks up the vast majority of traditional <a href="https://www.techradar.com/news/what-is-malware-and-how-dangerous-is-it">malware</a>, Mac users face a very different kind of threat, one that a locked-down operating system does little to stop: <a href="https://www.techradar.com/news/everything-you-need-to-know-about-phishing">phishing</a>.</p><p><a href="https://www.techradar.com/best/best-antivirus">Antivirus </a>software paired with one of the <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> services remains a sensible layer of defence, whatever you run, but <a href="https://bit.ly/3SAbtut" target="_blank" rel="nofollow">Surfshark's findings</a> are a useful reminder that while risks change depending on the platform, they never disappear.</p><div class="product"><a data-dimension112="ff4c4aa2-9660-11f1-89b4-1f3684d9c300" data-action="Deal Block" data-label="Surfshark &ndash; the best cheap VPNSurfshark is a fast, easy-to-use VPN that seriously beats the competition when it comes to subscription pricing. Its two-year Starter plan works out at $2.49 a month (plus tax), but we think Surfshark One is the best value plan as it adds an antivirus, data breach monitor, and alternative ID tool starting from the equivalent of  $2.79 a month. Surfshark – the best cheap VPN" data-dimension48="Surfshark &ndash; the best cheap VPNSurfshark is a fast, easy-to-use VPN that seriously beats the competition when it comes to subscription pricing. Its two-year Starter plan works out at $2.49 a month (plus tax), but we think Surfshark One is the best value plan as it adds an antivirus, data breach monitor, and alternative ID tool starting from the equivalent of  $2.79 a month. Surfshark – the best cheap VPN" href="https://get.surfshark.net/aff_c?offer_id=1030&aff_id=1691&url_id=2561" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="pSwRio45uPDhdN5egHcYF" name="Surfshark deal image.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/pSwRio45uPDhdN5egHcYF.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong></strong><a href="http://get.surfshark.net/aff_c?offer_id=61&aff_id=1691" target="_blank" rel="nofollow" data-dimension112="ff4c4aa2-9660-11f1-89b4-1f3684d9c300" data-action="Deal Block" data-label="Surfshark &ndash; the best cheap VPNSurfshark is a fast, easy-to-use VPN that seriously beats the competition when it comes to subscription pricing. Its two-year Starter plan works out at $2.49 a month (plus tax), but we think Surfshark One is the best value plan as it adds an antivirus, data breach monitor, and alternative ID tool starting from the equivalent of  $2.79 a month. Surfshark – the best cheap VPN" data-dimension48="Surfshark &ndash; the best cheap VPNSurfshark is a fast, easy-to-use VPN that seriously beats the competition when it comes to subscription pricing. Its two-year Starter plan works out at $2.49 a month (plus tax), but we think Surfshark One is the best value plan as it adds an antivirus, data breach monitor, and alternative ID tool starting from the equivalent of  $2.79 a month. Surfshark – the best cheap VPN" data-dimension25=""><strong>Surfshark – the best cheap VPN</strong></a><strong></strong><br>Surfshark is a fast, easy-to-use VPN that seriously beats the competition when it comes to subscription pricing. Its two-year Starter plan works out at $2.49 a month<strong> </strong>(plus tax), but we think Surfshark One is the best value plan as it adds an antivirus, data breach monitor, and alternative ID tool starting from the equivalent of  $2.79 a month. <a class="view-deal button" href="https://get.surfshark.net/aff_c?offer_id=1030&aff_id=1691&url_id=2561" target="_blank" rel="nofollow" data-dimension112="ff4c4aa2-9660-11f1-89b4-1f3684d9c300" data-action="Deal Block" data-label="Surfshark &ndash; the best cheap VPNSurfshark is a fast, easy-to-use VPN that seriously beats the competition when it comes to subscription pricing. Its two-year Starter plan works out at $2.49 a month (plus tax), but we think Surfshark One is the best value plan as it adds an antivirus, data breach monitor, and alternative ID tool starting from the equivalent of  $2.79 a month. Surfshark – the best cheap VPN" data-dimension48="Surfshark &ndash; the best cheap VPNSurfshark is a fast, easy-to-use VPN that seriously beats the competition when it comes to subscription pricing. Its two-year Starter plan works out at $2.49 a month (plus tax), but we think Surfshark One is the best value plan as it adds an antivirus, data breach monitor, and alternative ID tool starting from the equivalent of  $2.79 a month. Surfshark – the best cheap VPN" data-dimension25="">View Deal</a></p></div><h2 id="the-six-times-gap-by-the-numbers">The six-times gap, by the numbers</h2><p>Surfshark analysed 391,305 malware detections logged by its antivirus between 1 January and 31 July 2026. Windows devices made up 66% of the active user base but accounted for a striking 92% of all detections, while macOS users represented 34% of the base yet just 8% of threats. </p><p>That works out to nearly six Windows detections for every one on a Mac.</p><p>"Windows' popularity has always made it the biggest target for cybercriminals," said Gabrielė Sinkevičiūtė, Head of Product at Surfshark, pointing to the scale of malware built around Windows' dominant market share, along with differences in how each platform handles third-party software and permissions.</p><p><a href="https://bit.ly/3TK4q2N" target="_blank" rel="nofollow">Surfshark's equivalent research</a> from last year yielded similar results, so the trend appears to be consistent.</p><h2 id="trojans-dominate-windows-while-phishing-surges-on-mac">Trojans dominate Windows, while phishing surges on Mac</h2><a href="https://bit.ly/3SAbtut"><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1172px;"><p class="vanilla-image-block" style="padding-top:68.17%;"><img id="xj4Tb5sFYs2sBwDTnEdTUW" name="unnamed (1)" alt="Surfshark's graph showing its Antivirus malware detection data on Windows and macOS (August 2026)" src="https://cdn.mos.cms.futurecdn.net/xj4Tb5sFYs2sBwDTnEdTUW.png" mos="" align="middle" fullscreen="" width="1172" height="799" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="caption-text">Surfshark's new Antiscam hub combines a number of its existing features into one easily navigated location </span><span class="credit" itemprop="copyrightHolder">(Image credit: Surfshark)</span></figcaption></figure></a><p>The threat mix differs sharply by platform. Trojans (malicious software hiding inside safe programs) were the top danger on Windows at 46% of detections, versus 25% on macOS, while riskware (legitimate software that can pose security threats) sat at 19% and 17% respectively. Viruses were level at 9% on both, and adware (software that puts unwanted ads on your device) trailed at 4% on Windows and 3% on Mac.</p><p><a href="https://www.techradar.com/news/everything-you-need-to-know-about-phishing">Phishing</a> is where Mac users lose ground. It ranked third on macOS at 15% of detections, but only sixth on Windows at 3%. Because phishing exploits trust rather than software flaws, a hardened operating system offers little protection, and Surfshark argues a false sense of security can make Mac owners slower to question a suspicious message.</p><p>Other research backs this up. <a href="https://www.microsoft.com/en-us/security/blog/2026/02/02/infostealers-without-borders-macos-python-stealers-and-platform-abuse/" target="_blank" rel="nofollow">Microsoft reported</a> in early 2026 that infostealer campaigns are expanding beyond Windows onto macOS using social-engineering tricks such as ClickFix prompts and fake installers, and <a href="https://www.malwarebytes.com/blog/mobile/2025/02/macs-targeted-by-info-stealers-in-new-era-of-cyberthreats" target="_blank" rel="nofollow">Malwarebytes</a> has tracked Mac infostealers becoming a mainstream threat rather than a rarity. TechRadar has likewise reported that <a href="https://www.techradar.com/pro/the-mythical-security-status-of-macos-is-no-more-report-finds-apple-devices-fare-the-worst-when-it-comes-to-full-takeover-risks">the "mythical" security status of macOS is fading</a>.</p><h2 id="how-to-stay-safe">How to stay safe</h2><p>The core advice is the same on both platforms: treat unexpected links, attachments and login prompts with suspicion, keep your operating system and apps patched, and only install software from official sources. </p><p>Never paste a command into Terminal or PowerShell because a website told you to, as that single step drives many recent Mac infections.</p><p>Running reputable antivirus software helps on either system, but the biggest fix for Mac users may be a change in attitude. Dropping the assumption that Apple hardware is inherently immune is the first real step toward not becoming the softer target.</p><div data-widget-type="review" data-model-name="Surfshark" class="hawk-root"></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why AI is accelerating old cyber risks, not creating new ones ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The integration of <a href="https://www.techradar.com/pro/best-ai-chatbot-for-business">artificial intelligence</a> (AI) into everyday work and life has prompted businesses and regulatory bodies to take action. AI is a force introducing entirely new categories of threat, making heightened cyber resilience essential. However, amidst the panic to get in front of this, it should be noted that not all the hype is entirely accurate. </p><p>The underlying vulnerabilities organizations face today are largely the same ones they faced five or ten years ago: unpatched systems, weak <a href="https://www.techradar.com/best/best-identity-theft-protection">identity</a> controls, excessive privileges, insecure third-party integrations.</p><p>In some cases, these weaknesses have existed for some time, and most likely, will continue to exist because the first fundamental constraint of computer science is that the removal of all vulnerabilities is impossible. Therefore, no amount of tooling or budget will ever make any business 100% secure. Equally, that doesn’t mean improvements should simply be dismissed - especially in the age of AI.</p><h2 id="speed-not-novelty">Speed, not novelty</h2><p>While not introducing anything inherently new, there is still some cause for concern surrounding AI. The nature of existing weaknesses remains the same. However, AI does significantly change the speed and scale at which they can be identified and exploited. Tasks that once required time, skill, and persistence can now be automated, accelerated, and in some cases delegated.</p><p>The barrier to entry has been lowered for less sophisticated actors to operate with greater efficiency and success.</p><p>We are already seeing early signs of this shift. Elements of the attack lifecycle can be automated, be that reconnaissance or lateral movement. Nation-state actors have begun experimenting with using these systems to coordinate multi-stage operations, and we’ve recently seen a fully autonomous attack take place, without any human supervision.</p><p>At the same time, more familiar techniques are being enhanced rather than replaced. <a href="https://www.techradar.com/best/best-malware-removal">Malware</a> can be generated or iterated more quickly to evade detection. Social engineering has become more convincing through deepfakes, and phishing campaigns have become easier to scale. </p><p>None of this represents a fundamentally new playbook, simply the acceleration of an existing one. </p><h2 id="the-distraction-problem">The distraction problem</h2><p>The distinction between novelty and speed matters because it shapes how organizations respond. If AI is treated as a novel and exceptional threat, it encourages a reactive mindset. <a href="https://www.techradar.com/news/best-internet-security-suites">Security</a> teams are pushed towards finding “AI-specific” solutions, often at the expense of addressing longstanding gaps in their environment. In practice, those gaps still remain the most reliable entry points for attackers.</p><p>The risk that the current level of attention on AI creates, is a form of strategic distraction. Boards and executives are rightly asking questions about AI risk, but those conversations can become detached from the basics. Patch management programs remain inconsistent. Asset inventories are incomplete. Third-party exposure is poorly understood. Identity and access management remains fragmented across systems. </p><p>These are the same issues that security professionals were tackling before the advent of AI and the technology does not take them off the board. If anything, these become more consequential as the speed of exploitation increases. </p><h2 id="the-right-response">The right response</h2><p>It is worth being clear about the limits of control. No organization will ever be 100% secure. There will always be unknown vulnerabilities, many of which the new frontier models will be able to fish out.</p><p>However, the idea that AI introduces risk that can be entirely “solved” is misleading. Even if advanced models identify previously unknown weaknesses, the response remains the same as it has always been: prioritize, remediate and reduce exposure over time.</p><p>For defenders, matching this increased tempo requires a combination of discipline and adaptation. Established practices such as red teaming and tabletop exercises need to evolve to incorporate AI-enabled scenarios. Incident response teams need to be prepared to handle new forms of evidence, including those generated or manipulated by AI systems.</p><p>In addition, training programs need to reflect the growing sophistication of social engineering, particularly where deepfakes and voice cloning is concerned. </p><p>AI-driven detection and response capabilities can play an important role, particularly in identifying patterns at scale. But they are not a substitute for secure-by-design principles, robust access controls, or a clear understanding of where critical <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> resides. Therefore, organizations should observe caution about over-rotating towards new tools without addressing foundational weaknesses.</p><p>The expansion of the attack surface through enterprise AI adoption adds another layer of complexity. Threat actors are already targeting AI workflows directly, exploiting vulnerabilities in <a href="https://www.techradar.com/best/best-antivirus">software</a> development environments, and using techniques such as prompt injection to manipulate system behavior.</p><p>In some cases, malicious instructions can be embedded within otherwise benign content, triggering unintended actions when processed by an AI system. </p><p>Again, these developments are best understood as extensions of familiar concepts. Input validation, supply chain risk, and data integrity have always been central to security. AI introduces new contexts in which these issues manifest, but not entirely new categories of risk.</p><p>From a governance perspective, this reinforces the need for clarity rather than novelty. Boards should be focused on defining risk tolerance, ensuring accountability, and maintaining visibility over how AI is used within the organization.</p><p>This includes integrating AI considerations into existing risk frameworks rather than treating them as a separate domain. Legal, technical, and communications teams need to be aligned, particularly in scenarios involving misinformation or synthetic media, where response speed is critical. </p><h2 id="what-matters-now">What matters now</h2><p>There is value in the current focus on cyber risk. Increased attention at the board level can drive investment and accountability in ways that were previously difficult to achieve. But that attention needs to be directed towards the right problems. Treating AI as an entirely new threat risks misallocating resources and overlooking the vulnerabilities that are already present.</p><p>AI will continue to evolve and so will the ways in which it is used by both attackers and defenders. In cyber security, progress is often less about discovering new answers and more about applying existing ones with greeted consistency and speed.</p><p>The organizations that navigate this shift most effectively will be those that remain grounded in a clear understanding of what has and has not changed.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/why-ai-is-accelerating-old-cyber-risks-not-creating-new-ones</link>
                                                                            <description>
                            <![CDATA[ AI is changing cyber threats, but core security principles still determine organizational resilience. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nK4aRi3GqqpfroE4X3Ryg3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Aug 2026 10:27:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ed Williams, LevelBlue ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg">
                                                            <media:credit><![CDATA[Blue Planet Studio/Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:description>                                                            <media:text><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:text>
                                <media:title type="plain"><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The integration of <a href="https://www.techradar.com/pro/best-ai-chatbot-for-business">artificial intelligence</a> (AI) into everyday work and life has prompted businesses and regulatory bodies to take action. AI is a force introducing entirely new categories of threat, making heightened cyber resilience essential. However, amidst the panic to get in front of this, it should be noted that not all the hype is entirely accurate. </p><p>The underlying vulnerabilities organizations face today are largely the same ones they faced five or ten years ago: unpatched systems, weak <a href="https://www.techradar.com/best/best-identity-theft-protection">identity</a> controls, excessive privileges, insecure third-party integrations.</p><p>In some cases, these weaknesses have existed for some time, and most likely, will continue to exist because the first fundamental constraint of computer science is that the removal of all vulnerabilities is impossible. Therefore, no amount of tooling or budget will ever make any business 100% secure. Equally, that doesn’t mean improvements should simply be dismissed - especially in the age of AI.</p><h2 id="speed-not-novelty">Speed, not novelty</h2><p>While not introducing anything inherently new, there is still some cause for concern surrounding AI. The nature of existing weaknesses remains the same. However, AI does significantly change the speed and scale at which they can be identified and exploited. Tasks that once required time, skill, and persistence can now be automated, accelerated, and in some cases delegated.</p><p>The barrier to entry has been lowered for less sophisticated actors to operate with greater efficiency and success.</p><p>We are already seeing early signs of this shift. Elements of the attack lifecycle can be automated, be that reconnaissance or lateral movement. Nation-state actors have begun experimenting with using these systems to coordinate multi-stage operations, and we’ve recently seen a fully autonomous attack take place, without any human supervision.</p><p>At the same time, more familiar techniques are being enhanced rather than replaced. <a href="https://www.techradar.com/best/best-malware-removal">Malware</a> can be generated or iterated more quickly to evade detection. Social engineering has become more convincing through deepfakes, and phishing campaigns have become easier to scale. </p><p>None of this represents a fundamentally new playbook, simply the acceleration of an existing one. </p><h2 id="the-distraction-problem">The distraction problem</h2><p>The distinction between novelty and speed matters because it shapes how organizations respond. If AI is treated as a novel and exceptional threat, it encourages a reactive mindset. <a href="https://www.techradar.com/news/best-internet-security-suites">Security</a> teams are pushed towards finding “AI-specific” solutions, often at the expense of addressing longstanding gaps in their environment. In practice, those gaps still remain the most reliable entry points for attackers.</p><p>The risk that the current level of attention on AI creates, is a form of strategic distraction. Boards and executives are rightly asking questions about AI risk, but those conversations can become detached from the basics. Patch management programs remain inconsistent. Asset inventories are incomplete. Third-party exposure is poorly understood. Identity and access management remains fragmented across systems. </p><p>These are the same issues that security professionals were tackling before the advent of AI and the technology does not take them off the board. If anything, these become more consequential as the speed of exploitation increases. </p><h2 id="the-right-response">The right response</h2><p>It is worth being clear about the limits of control. No organization will ever be 100% secure. There will always be unknown vulnerabilities, many of which the new frontier models will be able to fish out.</p><p>However, the idea that AI introduces risk that can be entirely “solved” is misleading. Even if advanced models identify previously unknown weaknesses, the response remains the same as it has always been: prioritize, remediate and reduce exposure over time.</p><p>For defenders, matching this increased tempo requires a combination of discipline and adaptation. Established practices such as red teaming and tabletop exercises need to evolve to incorporate AI-enabled scenarios. Incident response teams need to be prepared to handle new forms of evidence, including those generated or manipulated by AI systems.</p><p>In addition, training programs need to reflect the growing sophistication of social engineering, particularly where deepfakes and voice cloning is concerned. </p><p>AI-driven detection and response capabilities can play an important role, particularly in identifying patterns at scale. But they are not a substitute for secure-by-design principles, robust access controls, or a clear understanding of where critical <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> resides. Therefore, organizations should observe caution about over-rotating towards new tools without addressing foundational weaknesses.</p><p>The expansion of the attack surface through enterprise AI adoption adds another layer of complexity. Threat actors are already targeting AI workflows directly, exploiting vulnerabilities in <a href="https://www.techradar.com/best/best-antivirus">software</a> development environments, and using techniques such as prompt injection to manipulate system behavior.</p><p>In some cases, malicious instructions can be embedded within otherwise benign content, triggering unintended actions when processed by an AI system. </p><p>Again, these developments are best understood as extensions of familiar concepts. Input validation, supply chain risk, and data integrity have always been central to security. AI introduces new contexts in which these issues manifest, but not entirely new categories of risk.</p><p>From a governance perspective, this reinforces the need for clarity rather than novelty. Boards should be focused on defining risk tolerance, ensuring accountability, and maintaining visibility over how AI is used within the organization.</p><p>This includes integrating AI considerations into existing risk frameworks rather than treating them as a separate domain. Legal, technical, and communications teams need to be aligned, particularly in scenarios involving misinformation or synthetic media, where response speed is critical. </p><h2 id="what-matters-now">What matters now</h2><p>There is value in the current focus on cyber risk. Increased attention at the board level can drive investment and accountability in ways that were previously difficult to achieve. But that attention needs to be directed towards the right problems. Treating AI as an entirely new threat risks misallocating resources and overlooking the vulnerabilities that are already present.</p><p>AI will continue to evolve and so will the ways in which it is used by both attackers and defenders. In cyber security, progress is often less about discovering new answers and more about applying existing ones with greeted consistency and speed.</p><p>The organizations that navigate this shift most effectively will be those that remain grounded in a clear understanding of what has and has not changed.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cybersecurity’s identity crisis: why trust can no longer begin and end at login ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The image most organizations still have of a cyberattack is fundamentally outdated.</p><p>We tend to picture hackers battering down digital walls by exploiting software vulnerabilities or launching convoluted <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a> campaigns. Yet some of the most damaging breaches today involve something far less dramatic. </p><p>An attacker enters through the front door using valid credentials, passes authentication checks, and proceeds through the environment as if they are a completely legitimate employee.</p><p>Recent attacks targeting public sector organizations in the UK have once again demonstrated just how easy it is to get into an environment if you have the right credentials. </p><p>Earlier this year, hackers managed to breach systems used by the UK Foreign Office and local councils using stolen login credentials. </p><p>As compromised credentials become increasingly easy to buy and sell on the dark web, organizations face a different sort of challenge: determining whether the person behind a successful login is actually who they claim to be.</p><h2 id="authentication-is-no-longer-enough">Authentication is no longer enough</h2><p>For years, organizations viewed authentication as a decisive security event. A user entered the correct <a href="https://www.techradar.com/best/password-generator">password</a>, perhaps completed a multi-factor authentication challenge, and was granted access.</p><p>The problem is that attackers have, as ever, have found a way around.</p><p>Large-scale phishing campaigns, infostealer <a href="https://www.techradar.com/best/best-malware-removal">malware</a>, session hijacking techniques and credential harvesting operations have made legitimate account access easier to acquire than ever before. The UK's Cyber Security Breaches Survey 2025 found that phishing remains the most common cyber threat facing organizations, affecting 85% of businesses that experienced a breach or attack. </p><p>For many cybercriminals, phishing is simply the first step in a wider economy built around stolen identities. Once compromised, credentials and authentication tokens are routinely traded on dark web forums, giving attackers a ready-made route into trusted environments.</p><p>So why do we continue to treat a successful authentication as proof that a user can be permanently trusted?</p><p>In reality, authentication provides only a snapshot in time. It confirms that a user presented the correct credentials at a specific moment. It does not prove that the individual behind the keyboard remains the same person throughout their activity, nor does it account for changing risk factors once access has been granted.</p><h2 id="the-rise-of-continuous-trust">The rise of continuous trust</h2><p>The concept of Zero Trust isn’t a new principle, but it reflects a broader recognition that trust must be earned repeatedly, not granted indefinitely.</p><p>Continuous trust models assume that every request, transaction, and interaction carries some degree of risk. Instead of relying solely on login events, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> controls continuously assess whether behavior remains consistent with an individual's expected identity and context.</p><p>For example, an <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employee</a> logging in from their usual location during working hours may initially present low risk. However, if that same account suddenly begins accessing systems it has never touched before, or exhibiting behavior inconsistent with historical patterns, trust levels should automatically decrease.</p><p>The critical question is no longer "Did this user authenticate correctly?" but rather "Does this activity continue to make sense?"</p><h2 id="behavior-tells-a-story-that-credentials-cannot">Behavior tells a story that credentials cannot</h2><p>One of the most promising developments in modern <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> is the growing ability to analyze behavioral signals in real time.</p><p>Every user leaves behind a digital fingerprint through their actions. They access particular applications, work within predictable timeframes, interact with specific datasets, and follow recognizable workflows. Even small deviations can provide valuable indicators of potential compromise.</p><p>Machine learning and advanced analytics increasingly allow security teams to identify these anomalies at scale. The goal is not simply to detect malicious activity but to recognize when behavior no longer aligns with an established baseline.</p><p>This is particularly important because attackers who obtain legitimate credentials often attempt to blend into normal operations. They move carefully, avoid triggering conventional alerts, and exploit the fact that many security systems are designed to detect intrusion rather than impersonation.</p><p>Behavioral intelligence offers a much-needed layer of scrutiny that credentials alone cannot provide.</p><p>Importantly, this approach also helps reduce reliance on static indicators of compromise, many of which become obsolete quickly. </p><h2 id="why-identity-security-sits-at-the-heart-of-business-resilience">Why identity security sits at the heart of business resilience</h2><p>Identity-related attacks are increasingly becoming the biggest threat to business continuity. Modern organizations depend on interconnected digital infrastructures spanning employees, contractors, partners, suppliers, and customers. The compromise of a single trusted identity can create a pathway into multiple systems and services.</p><p>Security strategies should focus on limiting unnecessary privileges, continuously validating access rights, reducing identity sprawl, and establishing clear visibility across the entire identity ecosystem.</p><p>Just as importantly, organizations must recognize that identity is dynamic. Employees join, leave, change roles, gain new permissions, and interact with new applications constantly. Security controls need to evolve at the same pace.</p><p>The organizations most resilient to future threats will be those that understand identity as a living system rather than a static credential database.</p><h2 id="the-future-of-cybersecurity-starts-with-questioning-trust">The future of cybersecurity starts with questioning trust</h2><p>The next generation of cyberattacks will be defined by attackers blending in rather than breaking in. That shift demands a fundamental rethinking of cybersecurity from first principles.</p><p>In an environment where identities are constantly targeted, trust can no longer be binary. It cannot be granted once and forgotten. Instead, trust must become dynamic, measurable, and continuously verified.</p><p>The future belongs to organizations that recognize authentication as the start of a security conversation, not its conclusion.</p><p><a href="https://www.techradar.com/best/best-antivirus"><em>We've reviewed, rated, and ranked the best antivirus</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/cybersecuritys-identity-crisis-why-trust-can-no-longer-begin-and-end-at-login</link>
                                                                            <description>
                            <![CDATA[ Cyber threats no longer break in; they log in. Here's why organizations must rethink trust in the age of identity-based attacks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">P4P7Uqw39itJ9WdXNiJSB8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Aug 2026 06:49:25 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Vaibhav Dutta ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:description>                                                            <media:text><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:text>
                                <media:title type="plain"><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The image most organizations still have of a cyberattack is fundamentally outdated.</p><p>We tend to picture hackers battering down digital walls by exploiting software vulnerabilities or launching convoluted <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a> campaigns. Yet some of the most damaging breaches today involve something far less dramatic. </p><p>An attacker enters through the front door using valid credentials, passes authentication checks, and proceeds through the environment as if they are a completely legitimate employee.</p><p>Recent attacks targeting public sector organizations in the UK have once again demonstrated just how easy it is to get into an environment if you have the right credentials. </p><p>Earlier this year, hackers managed to breach systems used by the UK Foreign Office and local councils using stolen login credentials. </p><p>As compromised credentials become increasingly easy to buy and sell on the dark web, organizations face a different sort of challenge: determining whether the person behind a successful login is actually who they claim to be.</p><h2 id="authentication-is-no-longer-enough">Authentication is no longer enough</h2><p>For years, organizations viewed authentication as a decisive security event. A user entered the correct <a href="https://www.techradar.com/best/password-generator">password</a>, perhaps completed a multi-factor authentication challenge, and was granted access.</p><p>The problem is that attackers have, as ever, have found a way around.</p><p>Large-scale phishing campaigns, infostealer <a href="https://www.techradar.com/best/best-malware-removal">malware</a>, session hijacking techniques and credential harvesting operations have made legitimate account access easier to acquire than ever before. The UK's Cyber Security Breaches Survey 2025 found that phishing remains the most common cyber threat facing organizations, affecting 85% of businesses that experienced a breach or attack. </p><p>For many cybercriminals, phishing is simply the first step in a wider economy built around stolen identities. Once compromised, credentials and authentication tokens are routinely traded on dark web forums, giving attackers a ready-made route into trusted environments.</p><p>So why do we continue to treat a successful authentication as proof that a user can be permanently trusted?</p><p>In reality, authentication provides only a snapshot in time. It confirms that a user presented the correct credentials at a specific moment. It does not prove that the individual behind the keyboard remains the same person throughout their activity, nor does it account for changing risk factors once access has been granted.</p><h2 id="the-rise-of-continuous-trust">The rise of continuous trust</h2><p>The concept of Zero Trust isn’t a new principle, but it reflects a broader recognition that trust must be earned repeatedly, not granted indefinitely.</p><p>Continuous trust models assume that every request, transaction, and interaction carries some degree of risk. Instead of relying solely on login events, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> controls continuously assess whether behavior remains consistent with an individual's expected identity and context.</p><p>For example, an <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employee</a> logging in from their usual location during working hours may initially present low risk. However, if that same account suddenly begins accessing systems it has never touched before, or exhibiting behavior inconsistent with historical patterns, trust levels should automatically decrease.</p><p>The critical question is no longer "Did this user authenticate correctly?" but rather "Does this activity continue to make sense?"</p><h2 id="behavior-tells-a-story-that-credentials-cannot">Behavior tells a story that credentials cannot</h2><p>One of the most promising developments in modern <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> is the growing ability to analyze behavioral signals in real time.</p><p>Every user leaves behind a digital fingerprint through their actions. They access particular applications, work within predictable timeframes, interact with specific datasets, and follow recognizable workflows. Even small deviations can provide valuable indicators of potential compromise.</p><p>Machine learning and advanced analytics increasingly allow security teams to identify these anomalies at scale. The goal is not simply to detect malicious activity but to recognize when behavior no longer aligns with an established baseline.</p><p>This is particularly important because attackers who obtain legitimate credentials often attempt to blend into normal operations. They move carefully, avoid triggering conventional alerts, and exploit the fact that many security systems are designed to detect intrusion rather than impersonation.</p><p>Behavioral intelligence offers a much-needed layer of scrutiny that credentials alone cannot provide.</p><p>Importantly, this approach also helps reduce reliance on static indicators of compromise, many of which become obsolete quickly. </p><h2 id="why-identity-security-sits-at-the-heart-of-business-resilience">Why identity security sits at the heart of business resilience</h2><p>Identity-related attacks are increasingly becoming the biggest threat to business continuity. Modern organizations depend on interconnected digital infrastructures spanning employees, contractors, partners, suppliers, and customers. The compromise of a single trusted identity can create a pathway into multiple systems and services.</p><p>Security strategies should focus on limiting unnecessary privileges, continuously validating access rights, reducing identity sprawl, and establishing clear visibility across the entire identity ecosystem.</p><p>Just as importantly, organizations must recognize that identity is dynamic. Employees join, leave, change roles, gain new permissions, and interact with new applications constantly. Security controls need to evolve at the same pace.</p><p>The organizations most resilient to future threats will be those that understand identity as a living system rather than a static credential database.</p><h2 id="the-future-of-cybersecurity-starts-with-questioning-trust">The future of cybersecurity starts with questioning trust</h2><p>The next generation of cyberattacks will be defined by attackers blending in rather than breaking in. That shift demands a fundamental rethinking of cybersecurity from first principles.</p><p>In an environment where identities are constantly targeted, trust can no longer be binary. It cannot be granted once and forgotten. Instead, trust must become dynamic, measurable, and continuously verified.</p><p>The future belongs to organizations that recognize authentication as the start of a security conversation, not its conclusion.</p><p><a href="https://www.techradar.com/best/best-antivirus"><em>We've reviewed, rated, and ranked the best antivirus</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts warn North Korean hackers are increasingly using AI to build smarter and more devious cyberattacks ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Kimsuky used local AI tools to evade monitoring and enhance operations</strong></li><li><strong>Researchers observed extensive AI-driven capability building across the group’s infrastructure</strong></li><li><strong>Defenders urged behavior-based detection to spot evolving AI-enabled threats</strong></li></ul><p>North Korean hackers have found a way to use Generative Artificial Intelligence (GenAI) to supercharge their activities without tipping off the tool’s maintainers.</p><p>When people use AI tools like ChatGPT or Claude, their activities can be (at least to some extent) tracked and curbed - with OpenAI recently identifying and <a href="https://www.techradar.com/pro/security/openai-says-it-stopped-an-asian-scam-campaign-hijacking-chatgpt-to-lure-in-victims" target="_blank">terminating multiple ChatGPT accounts</a> used in phishing and human trafficking. </p><p>That is why Kimsuky - a known state-sponsored North Korean threat actor, used Ollama, GPT4All and Msty locally, allowing them to process documents without sending any sensitive information to outside AI services. </p><h2 id="consistent-process-of-capability-development">"Consistent process of capability development"</h2><p>The attacks were spotted by security researchers <a href="https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm" target="_blank" rel="nofollow">Genians</a> who “conducted months of tracking and log analysis on the infrastructure utilized as C2 in this campaign,” to identify the tools they used.</p><p>Aside from the three LLMs, they also used retrieval augmented generation (RAG) tools for document search, as well as AI agent development frameworks, text-to-speech software, and an AI-assisted coding tool called Cursor.</p><p>Using AI to write malicious code is not as simple as it sounds, due to various guardrails set up by the developers. As a result, AI in crime has been mostly limited to drafting phishing emails and crafting authentic-looking but malicious landing pages. However, Kimsuky has shown that AI in cybercrime continues to evolve and is becoming an ever-greater threat. </p><p>“What was observed in the threat actor's infrastructure was not merely evidence of several documents being created with AI, but a consistent process of capability development: establishing local LLM runtime environments, configuring RAG based on documents in the actor's possession, collecting AI agent development frameworks, and acquiring libraries for integration with external commercial AI services,” Genians concluded.</p><p>As a result, defenders must move from content-based assessment to behavior-based detection, the researchers warned, saying this should serve “as the fundamental premise of security recommendations.”</p><p>“In addition to indicator of compromise (IoC)-based detection, organizations should contextually correlate the sequence of anomalous activities following LNK execution, including PowerShell execution, persistence establishment, and external communications, to assess the overall threat level.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/experts-warn-north-korean-hackers-are-increasingly-using-ai-to-build-smarter-and-more-devious-cyberattacks</link>
                                                                            <description>
                            <![CDATA[ In cybercrime, AI is used for more than simply drafting phishing emails and defenders need to adapt, new report states. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pMvkj5n6fSoGUjACrTKmVj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 10 Aug 2026 11:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:description>                                                            <media:text><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:text>
                                <media:title type="plain"><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Kimsuky used local AI tools to evade monitoring and enhance operations</strong></li><li><strong>Researchers observed extensive AI-driven capability building across the group’s infrastructure</strong></li><li><strong>Defenders urged behavior-based detection to spot evolving AI-enabled threats</strong></li></ul><p>North Korean hackers have found a way to use Generative Artificial Intelligence (GenAI) to supercharge their activities without tipping off the tool’s maintainers.</p><p>When people use AI tools like ChatGPT or Claude, their activities can be (at least to some extent) tracked and curbed - with OpenAI recently identifying and <a href="https://www.techradar.com/pro/security/openai-says-it-stopped-an-asian-scam-campaign-hijacking-chatgpt-to-lure-in-victims" target="_blank">terminating multiple ChatGPT accounts</a> used in phishing and human trafficking. </p><p>That is why Kimsuky - a known state-sponsored North Korean threat actor, used Ollama, GPT4All and Msty locally, allowing them to process documents without sending any sensitive information to outside AI services. </p><h2 id="consistent-process-of-capability-development">"Consistent process of capability development"</h2><p>The attacks were spotted by security researchers <a href="https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm" target="_blank" rel="nofollow">Genians</a> who “conducted months of tracking and log analysis on the infrastructure utilized as C2 in this campaign,” to identify the tools they used.</p><p>Aside from the three LLMs, they also used retrieval augmented generation (RAG) tools for document search, as well as AI agent development frameworks, text-to-speech software, and an AI-assisted coding tool called Cursor.</p><p>Using AI to write malicious code is not as simple as it sounds, due to various guardrails set up by the developers. As a result, AI in crime has been mostly limited to drafting phishing emails and crafting authentic-looking but malicious landing pages. However, Kimsuky has shown that AI in cybercrime continues to evolve and is becoming an ever-greater threat. </p><p>“What was observed in the threat actor's infrastructure was not merely evidence of several documents being created with AI, but a consistent process of capability development: establishing local LLM runtime environments, configuring RAG based on documents in the actor's possession, collecting AI agent development frameworks, and acquiring libraries for integration with external commercial AI services,” Genians concluded.</p><p>As a result, defenders must move from content-based assessment to behavior-based detection, the researchers warned, saying this should serve “as the fundamental premise of security recommendations.”</p><p>“In addition to indicator of compromise (IoC)-based detection, organizations should contextually correlate the sequence of anomalous activities following LNK execution, including PowerShell execution, persistence establishment, and external communications, to assess the overall threat level.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts warn malicious AI skills are hitting more victims than ever — with one family amassing 1.7 million downloads ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Attackers cloned AI skills, later adding malicious code to steal credentials</strong></li><li><strong>Zenity Labs found millions of installs and dozens of dangerous skill variants</strong></li><li><strong>Vercel and Microsoft removed malicious skills, but manual removal is still required</strong></li></ul><p>AI skills, instructions that teach AI agents how to do certain tasks and thus extend their capabilities, are increasingly being used in supply chain attacks, researchers have found.</p><p>Security experts at Zenity Labs uncovered a credential-stealing campaign on skills.sh, a public registry (essentially an app store) for AI agent skills. In the registry, belonging to Vercel (a cloud platform for web applications), threat actors were cloning existing skills, creating typosquatted lookalikes which, at first, did nothing malicious.</p><p>However, after a little time had past, and the skills amassed a solid download count, the attackers introduced malicious code instructing the <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agents</a> to, among other things, exfiltrate SSH keys, cloud credentials, Git and package manager tokens, Kubernetes and Docker configurations, database credentials, infrastructure-as-code credentials, environment files and service account files. The agents were then told to package the stolen information with host metadata and send it to the attackers. </p><h2 id="dozens-of-malicious-skills">Dozens of malicious skills</h2><p>While Zenity Labs could not say exactly how many people fell victim to this attack, they did stress that a single skill family amassed more than 1.7 million aggregate installs (not unique users). </p><p>And that is just one skill family, in a sea of malicious skills. The researchers also said they found “dozens” of additional skills exhibiting either malicious or dangerous behavior. Almost a third (30%) of identified dangerous skills abused Claude Code and OpenClaw to drop malware to their targets, as well. Also, Zenity found “hundreds” of reserved and empty package names that were being kept for future attacks. </p><p>These findings show how quickly cybercriminals adapt, and how creative they can get when it comes to abusing new tech. In essence, this campaign is an AI spin on a software supply-chain attack, being similar in spirit to incidents where attackers compromise an existing trusted package or repository, and later push a malicious update. </p><p>Following responsible disclosure, Vercel and Microsoft removed the identified skills, but Zenity warns that those who installed them before won’t be safe until they remove them from their systems manually.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/experts-warn-malicious-ai-skills-are-hitting-more-victims-than-ever-with-one-family-amassing-1-7-million-downloads</link>
                                                                            <description>
                            <![CDATA[ What if your AI agent suddenly turned rogue and sent all your passwords to a hacker? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ycPinqAGfEcztsGjWSXKcD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NNZdcW7Ku4FXu2CdGfdqvf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 07 Aug 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NNZdcW7Ku4FXu2CdGfdqvf-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI]]></media:description>                                                            <media:text><![CDATA[AI]]></media:text>
                                <media:title type="plain"><![CDATA[AI]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NNZdcW7Ku4FXu2CdGfdqvf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Attackers cloned AI skills, later adding malicious code to steal credentials</strong></li><li><strong>Zenity Labs found millions of installs and dozens of dangerous skill variants</strong></li><li><strong>Vercel and Microsoft removed malicious skills, but manual removal is still required</strong></li></ul><p>AI skills, instructions that teach AI agents how to do certain tasks and thus extend their capabilities, are increasingly being used in supply chain attacks, researchers have found.</p><p>Security experts at Zenity Labs uncovered a credential-stealing campaign on skills.sh, a public registry (essentially an app store) for AI agent skills. In the registry, belonging to Vercel (a cloud platform for web applications), threat actors were cloning existing skills, creating typosquatted lookalikes which, at first, did nothing malicious.</p><p>However, after a little time had past, and the skills amassed a solid download count, the attackers introduced malicious code instructing the <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agents</a> to, among other things, exfiltrate SSH keys, cloud credentials, Git and package manager tokens, Kubernetes and Docker configurations, database credentials, infrastructure-as-code credentials, environment files and service account files. The agents were then told to package the stolen information with host metadata and send it to the attackers. </p><h2 id="dozens-of-malicious-skills">Dozens of malicious skills</h2><p>While Zenity Labs could not say exactly how many people fell victim to this attack, they did stress that a single skill family amassed more than 1.7 million aggregate installs (not unique users). </p><p>And that is just one skill family, in a sea of malicious skills. The researchers also said they found “dozens” of additional skills exhibiting either malicious or dangerous behavior. Almost a third (30%) of identified dangerous skills abused Claude Code and OpenClaw to drop malware to their targets, as well. Also, Zenity found “hundreds” of reserved and empty package names that were being kept for future attacks. </p><p>These findings show how quickly cybercriminals adapt, and how creative they can get when it comes to abusing new tech. In essence, this campaign is an AI spin on a software supply-chain attack, being similar in spirit to incidents where attackers compromise an existing trusted package or repository, and later push a malicious update. </p><p>Following responsible disclosure, Vercel and Microsoft removed the identified skills, but Zenity warns that those who installed them before won’t be safe until they remove them from their systems manually.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers caught hijacking this Chinese Windows VPN's installers to spread malware ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Fortinet experts found malicious code in QuickFox VPN's Windows installer </strong></li><li><strong>The attack actively avoided personal gaming computers</strong></li><li><strong>QuickFox has since removed the malicious components from version 3.59.6</strong></li></ul><p>Cybersecurity researchers have uncovered a severe supply chain attack targeting QuickFox, a popular Chinese <a href="https://www.techradar.com/vpn/best-windows-10-vpn">Windows VPN</a> application. </p><p>According to a new <a href="https://www.fortinet.com/blog/threat-research/quickfox-supply-chain-attack-used-to-deploy-fdmtp-implant" target="_blank" rel="nofollow">report from Fortinet’s FortiGuard Labs</a>, attackers trojanized the software's installers for over a year to quietly deploy malicious backdoor implants onto users' machines.</p><p>As Fortinet's experts explain, QuickFox "is a VPN proxy and game accelerator typically employed by Chinese users to speed up access to Chinese-based resources, often to improve video game user experience<a href="https://www.fortinet.com/blog/threat-research/quickfox-supply-chain-attack-used-to-deploy-fdmtp-implant">.</a>" </p><p>However, experts found that malicious actors altered the application's underlying code to deliver a highly targeted <a href="https://www.techradar.com/news/what-is-malware-and-how-dangerous-is-it">malware</a> campaign. The threat actors modified an HTML file within the app's installer to automatically download and execute malicious JavaScript. </p><p>To avoid raising suspicion, this malicious code was pulled from a fake domain intentionally registered to mimic QuickFox’s legitimate infrastructure. Fortinet notes that the campaign had been active since at least August 2025, with QuickFox removing the malicious code with version 3.59.6. </p><p>TechRadar has not independently verified Fortinet's findings, but we have reached out to QuickFox for comment and will update this article if we receive a reply.</p><h2 id="a-highly-targeted-backdoor">A highly targeted backdoor</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1015px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="sdg89w5jqoix37UtxDByia" name="QuickFox" alt="QuickFox's app logo" src="https://cdn.mos.cms.futurecdn.net/sdg89w5jqoix37UtxDByia.png" mos="" align="middle" fullscreen="" width="1015" height="571" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: QuickFox)</span></figcaption></figure><p>The malware didn't infect everyone who downloaded the compromised VPN software. Instead, it used clever guardrails to filter out standard consumers. </p><p>If the malicious script detected Steam — the popular distribution service for online games — running on the victim's device, it immediately stopped the infection process to avoid personal gaming computers.</p><p>However, if it found tools used by developers, IT administrators, or cryptocurrency users, such as Visual Studio Code, Telegram, or various cryptocurrency wallets, it proceeded with the attack. This behavior suggests the hackers were explicitly hunting for high-value corporate environments and professionals rather than casual gamers.</p><p>When a target was deemed suitable, the script abused a legitimate Microsoft utility to secretly install the FDMTP implant and inject the malware. This persistent backdoor allowed attackers to collect sensitive system information, including <a href="https://www.techradar.com/pro/what-is-an-ip-address">IP addresses</a>, active processes, MAC addresses, and usernames. </p><p>Because FDMTP is highly modular, it also enabled the hackers to remotely download and execute additional malicious plugins, granting them long-term access to compromised machines.</p><p>While macOS builds contained the modified file, the infection process only executed on Windows endpoints. Android and iOS apps were completely unaffected.</p><h2 id="how-to-stay-safe-2">How to stay safe</h2><p>While Fortinet researchers have not confidently attributed the attack to a specific group, they noted significant technical crossovers with Twill Typhoon, a known threat actor.</p><p>The good news is that the threat now appears to be contained. According to the cybersecurity firm, "QuickFox has removed the described malicious components from their Windows installer from v3.59.6," following responsible disclosure.</p><p>If you have used QuickFox on a Windows machine over the last year, you should immediately update to the latest version directly from the vendor and run a full antivirus scan on your system. </p><p>Organizations are also advised to check their networks for any unusual activity or unrecognized file transfers originating from QuickFox installations.</p><div data-widget-type="multimodelreview" data-model-name="NordVPN,Surfshark,ExpressVPN,Proton VPN" data-widget-title="Today's best Windows VPN deals" class="hawk-root"></div> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/vpn/vpn-privacy-security/hackers-caught-hijacking-this-chinese-windows-vpns-installers-to-spread-malware</link>
                                                                            <description>
                            <![CDATA[ QuickFox VPN users might be at risk. Researchers discovered that attackers trojanized the software's Windows installer for over a year to deploy a persistent backdoor. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">EC4Uh9Tr46AmTmJdfYQ2RH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EEXAxCUDKAq3frELz3rVYY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Aug 2026 15:19:54 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[VPN Privacy &amp; Security]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DXDNjzRkphApxN8f5SooCA.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rene Millman is a seasoned technology journalist whose work has appeared in The Guardian, the Financial Times, Computer Weekly, and IT Pro. With over two decades of experience as a reporter and editor, he specializes in making complex topics like cybersecurity, VPNs, and enterprise software accessible and engaging. &lt;/p&gt;&lt;p&gt;His writing is backed by years of market analysis, allowing him to deliver news and features with an expert’s understanding of the industry.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/EEXAxCUDKAq3frELz3rVYY-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A group of hackers all wearing black with hoods pulled up over their heads with an open laptop in front of them. The background is a Chinese flag]]></media:description>                                                            <media:text><![CDATA[A group of hackers all wearing black with hoods pulled up over their heads with an open laptop in front of them. The background is a Chinese flag]]></media:text>
                                <media:title type="plain"><![CDATA[A group of hackers all wearing black with hoods pulled up over their heads with an open laptop in front of them. The background is a Chinese flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EEXAxCUDKAq3frELz3rVYY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Fortinet experts found malicious code in QuickFox VPN's Windows installer </strong></li><li><strong>The attack actively avoided personal gaming computers</strong></li><li><strong>QuickFox has since removed the malicious components from version 3.59.6</strong></li></ul><p>Cybersecurity researchers have uncovered a severe supply chain attack targeting QuickFox, a popular Chinese <a href="https://www.techradar.com/vpn/best-windows-10-vpn">Windows VPN</a> application. </p><p>According to a new <a href="https://www.fortinet.com/blog/threat-research/quickfox-supply-chain-attack-used-to-deploy-fdmtp-implant" target="_blank" rel="nofollow">report from Fortinet’s FortiGuard Labs</a>, attackers trojanized the software's installers for over a year to quietly deploy malicious backdoor implants onto users' machines.</p><p>As Fortinet's experts explain, QuickFox "is a VPN proxy and game accelerator typically employed by Chinese users to speed up access to Chinese-based resources, often to improve video game user experience<a href="https://www.fortinet.com/blog/threat-research/quickfox-supply-chain-attack-used-to-deploy-fdmtp-implant">.</a>" </p><p>However, experts found that malicious actors altered the application's underlying code to deliver a highly targeted <a href="https://www.techradar.com/news/what-is-malware-and-how-dangerous-is-it">malware</a> campaign. The threat actors modified an HTML file within the app's installer to automatically download and execute malicious JavaScript. </p><p>To avoid raising suspicion, this malicious code was pulled from a fake domain intentionally registered to mimic QuickFox’s legitimate infrastructure. Fortinet notes that the campaign had been active since at least August 2025, with QuickFox removing the malicious code with version 3.59.6. </p><p>TechRadar has not independently verified Fortinet's findings, but we have reached out to QuickFox for comment and will update this article if we receive a reply.</p><h2 id="a-highly-targeted-backdoor">A highly targeted backdoor</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1015px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="sdg89w5jqoix37UtxDByia" name="QuickFox" alt="QuickFox's app logo" src="https://cdn.mos.cms.futurecdn.net/sdg89w5jqoix37UtxDByia.png" mos="" align="middle" fullscreen="" width="1015" height="571" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: QuickFox)</span></figcaption></figure><p>The malware didn't infect everyone who downloaded the compromised VPN software. Instead, it used clever guardrails to filter out standard consumers. </p><p>If the malicious script detected Steam — the popular distribution service for online games — running on the victim's device, it immediately stopped the infection process to avoid personal gaming computers.</p><p>However, if it found tools used by developers, IT administrators, or cryptocurrency users, such as Visual Studio Code, Telegram, or various cryptocurrency wallets, it proceeded with the attack. This behavior suggests the hackers were explicitly hunting for high-value corporate environments and professionals rather than casual gamers.</p><p>When a target was deemed suitable, the script abused a legitimate Microsoft utility to secretly install the FDMTP implant and inject the malware. This persistent backdoor allowed attackers to collect sensitive system information, including <a href="https://www.techradar.com/pro/what-is-an-ip-address">IP addresses</a>, active processes, MAC addresses, and usernames. </p><p>Because FDMTP is highly modular, it also enabled the hackers to remotely download and execute additional malicious plugins, granting them long-term access to compromised machines.</p><p>While macOS builds contained the modified file, the infection process only executed on Windows endpoints. Android and iOS apps were completely unaffected.</p><h2 id="how-to-stay-safe-2">How to stay safe</h2><p>While Fortinet researchers have not confidently attributed the attack to a specific group, they noted significant technical crossovers with Twill Typhoon, a known threat actor.</p><p>The good news is that the threat now appears to be contained. According to the cybersecurity firm, "QuickFox has removed the described malicious components from their Windows installer from v3.59.6," following responsible disclosure.</p><p>If you have used QuickFox on a Windows machine over the last year, you should immediately update to the latest version directly from the vendor and run a full antivirus scan on your system. </p><p>Organizations are also advised to check their networks for any unusual activity or unrecognized file transfers originating from QuickFox installations.</p><div data-widget-type="multimodelreview" data-model-name="NordVPN,Surfshark,ExpressVPN,Proton VPN" data-widget-title="Today's best Windows VPN deals" class="hawk-root"></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google Blogger locks out thousands of users after malware false positive ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Google’s automated systems mistakenly flagged hundreds of Blogger sites as malicious</strong></li><li><strong>Company admitted a bug caused false malware labels, promising a fix</strong></li><li><strong>Users advised to request reviews, avoid migrating content</strong></li></ul><p>Hundreds of Blogger websites were locked down, and some apparently deleted as well, after Google’s automated security systems erroneously flagged them as malicious.</p><p>A user posted a new message on Google’s forum saying the huge number of reports regarding locked blogs are all for the same reason - <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">Malware</a> and Similar Malicious Content. </p><p>The nature of the lockdown “suggests misclassification by automated systems”, the post reads, adding that the team has “already been notified of this issue.”</p><h2 id="aware-of-a-bug">Aware of a bug""</h2><p>Those affected will see a red padlock in their dashboard and a warning saying the blog was locked: </p><p>"This blog was removed for violating Blogger's Community Guidelines. If you wish to request a review of the blog, click 'Request Review' below," the notice reads. </p><p>At press time, the forum post had more than 500 “I have the same question” votes, and more than 200 replies. </p><p>In a statement given to <a href="https://www.bleepingcomputer.com/news/google/google-blogger-locks-hundreds-of-blogs-in-malware-false-positive/" target="_blank"><em>BleepingComputer</em></a>, Google said it was aware of a bug that falsely labeled many sites as malicious, and that it was working on a fix.</p><p>"We are aware of a bug that incorrectly flagged some Blogger-hosted sites as malware for less than a day. We are working on a fix to resolve the issue as quickly as possible," the company said.</p><p>To make matters even worse, Google said that if users don’t file an appeal, that their blogs can be permanently deleted. </p><p>Users are advised not to create new blogs and migrate content, since that is in violation with Google’s TOS. They are also advised against deleting their Blogger profile or service from their Google account, since this will irrevocably delete the blogs. They can, however, back up their blogs if they are afraid of losing the content. </p><p>The full extent of the issue is unknown, but according to <em>BleepingComputer</em>, the number of users on the platform exceeds 200,000.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/google-blogger-locks-out-thousands-of-users-after-malware-false-positive</link>
                                                                            <description>
                            <![CDATA[ Google is aware of the situation and is working on a fix, it confirms as hundreds of bloggers report issues with their websites. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iHgkAhkcGwXMPfwoTyxCQN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Zdi4C3sHApwN8TFE2Bnhk8-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Aug 2026 14:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/Zdi4C3sHApwN8TFE2Bnhk8-1280-80.png">
                                                            <media:credit><![CDATA[WebLove.PL / Google Support]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Blogger]]></media:description>                                                            <media:text><![CDATA[Blogger]]></media:text>
                                <media:title type="plain"><![CDATA[Blogger]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Zdi4C3sHApwN8TFE2Bnhk8-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Google’s automated systems mistakenly flagged hundreds of Blogger sites as malicious</strong></li><li><strong>Company admitted a bug caused false malware labels, promising a fix</strong></li><li><strong>Users advised to request reviews, avoid migrating content</strong></li></ul><p>Hundreds of Blogger websites were locked down, and some apparently deleted as well, after Google’s automated security systems erroneously flagged them as malicious.</p><p>A user posted a new message on Google’s forum saying the huge number of reports regarding locked blogs are all for the same reason - <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">Malware</a> and Similar Malicious Content. </p><p>The nature of the lockdown “suggests misclassification by automated systems”, the post reads, adding that the team has “already been notified of this issue.”</p><h2 id="aware-of-a-bug">Aware of a bug""</h2><p>Those affected will see a red padlock in their dashboard and a warning saying the blog was locked: </p><p>"This blog was removed for violating Blogger's Community Guidelines. If you wish to request a review of the blog, click 'Request Review' below," the notice reads. </p><p>At press time, the forum post had more than 500 “I have the same question” votes, and more than 200 replies. </p><p>In a statement given to <a href="https://www.bleepingcomputer.com/news/google/google-blogger-locks-hundreds-of-blogs-in-malware-false-positive/" target="_blank"><em>BleepingComputer</em></a>, Google said it was aware of a bug that falsely labeled many sites as malicious, and that it was working on a fix.</p><p>"We are aware of a bug that incorrectly flagged some Blogger-hosted sites as malware for less than a day. We are working on a fix to resolve the issue as quickly as possible," the company said.</p><p>To make matters even worse, Google said that if users don’t file an appeal, that their blogs can be permanently deleted. </p><p>Users are advised not to create new blogs and migrate content, since that is in violation with Google’s TOS. They are also advised against deleting their Blogger profile or service from their Google account, since this will irrevocably delete the blogs. They can, however, back up their blogs if they are afraid of losing the content. </p><p>The full extent of the issue is unknown, but according to <em>BleepingComputer</em>, the number of users on the platform exceeds 200,000.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How open-source malware is re-targeting UK supply chains ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Open-source <a href="https://www.techradar.com/best/best-malware-removal">malware</a> has changed shape. </p><p>What once focused on noisy cryptomining has moved toward something far more valuable: access. </p><p>Our recent data shows attackers are increasingly targeting credentials and secrets embedded in software dependencies, with UK organizations firmly in scope.</p><p>This shift marks a move away from opportunistic abuse toward deliberate supply-chain compromise. Instead of draining compute cycles, attackers are positioning themselves inside build pipelines and developer workflows. </p><p>The goal is persistence, not disruption. </p><p>For organizations that rely heavily on <a href="https://www.techradar.com/best/best-open-source-software">open source software</a>, this fundamentally changes both the threat model and the potential impact.</p><p>This is what “shift left” actually means in 2026: controlling what enters the build, not just detecting what runs in production.</p><h2 id="why-credential-theft-has-overtaken-cryptomining">Why credential theft has overtaken cryptomining</h2><p>More than half of malicious open-source packages now focus on stealing credentials and secrets, overtaking cryptomining as the dominant threat type. The reason is straightforward. Credentials offer lasting value. They provide persistent access, broader reach across environments, and a lower risk of detection than resource abuse. A stolen token or API key can unlock entire systems, not just a single machine.</p><p>Cryptomining, by contrast, is easy to spot and quick to shut down. It consumes resources and triggers alerts. Credential theft blends in and can be executed in seconds. It exploits the trust placed on developer workflows to operate in a safe environment. </p><p>For attackers looking to maximize return while minimizing exposure, this approach maximizes returns whilst doing away with the risk of being discovered.</p><p>The implication is clear: protecting runtime infrastructure is no longer enough. The <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> boundary now starts at dependency intake and at the developer environment.</p><h2 id="multi-stage-malware-becomes-the-norm">Multi-stage malware becomes the norm</h2><p>Modern open-source malware is rarely single-purpose. Our analysis shows dropper and loader behavior increasing by nearly 2,900 percent year over year in Q1 2025, signaling a shift toward engineered, multi-stage attacks. </p><p>Around 77 percent of malicious packages distributed through open source ecosystems now combine multiple threat types. Droppers appear in nearly all observed cases, while secret exfiltration features in close to two-thirds.</p><p>These packages are designed to evolve after installation, pulling in additional payloads or changing behavior over time. This reflects industrialized campaigns rather than opportunistic experimentation. Attackers are investing in resilience, stealth, and scale.</p><p>For defenders, this means signature-based thinking is outdated. If malware is modular and adaptive, controls must focus on provenance, behavior, and prevention before execution. Again, this is what “shift left” actually means: securing the build graph itself, not just the workloads it produces.</p><h2 id="supply-chains-under-direct-pressure">Supply chains under direct pressure</h2><p>The widespread use of open source, particularly within the <a href="https://www.techradar.com/best/best-online-courses-to-learn-javascript">JavaScript</a> ecosystem, creates systemic exposure. Modern applications routinely depend on hundreds of direct and transitive npm packages. That density of reuse creates efficiency, but also amplifies upstream risk.</p><p>Recent activity linked to the Lazarus group illustrates the threat. More than 200 malicious packages were identified, almost all concentrated in npm. When a single ecosystem underpins financial services platforms, government services, and critical national <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>, concentration risk becomes a strategic issue.</p><p>A compromised dependency does not stay isolated. It propagates through shared frameworks, internal libraries, and CI pipelines. In sectors built on speed and reuse, upstream compromise quickly becomes downstream impact. This is why dependency governance is no longer just a developer hygiene issue; it is a board-level supply-chain concern.</p><h2 id="automation-turns-one-package-into-thousands-of-compromises">Automation turns one package into thousands of compromises</h2><p>Today’s malware increasingly targets CI/CD pipelines and developer workflows optimized for <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a>. When a compromised dependency enters a build, it can quietly extract API keys, certificates, and access tokens without triggering runtime alerts. Automation does the rest.</p><p>What starts as a single poisoned package can spread across hundreds or thousands of builds. The very systems designed to accelerate delivery now accelerate compromise.</p><p>The practical takeaway is uncomfortable but necessary: if build systems are automated, security controls must be automated at the same level. Manual review cannot scale against automated distribution.</p><h2 id="ai-coding-assistants-and-the-hallucination-problem">AI coding assistants and the hallucination problem</h2><p><a href="https://www.techradar.com/best/best-ai-tools">AI</a>-assisted development introduces an additional layer of risk. Studies and testing have shown that large language models can, in a meaningful percentage of cases, suggest packages or functions that do not exist. Developers under time pressure may attempt to install or rely on these hallucinated dependencies, unknowingly expanding the attack surface.</p><p>Hallucinated package names, fabricated examples, and unsafe dependency suggestions can quietly undermine supply-chain integrity. Attackers are already exploiting naming conventions and trust models to seed packages that appear legitimate to both humans and machines.</p><p>Each hallucination creates rework, friction, and lost <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a>. Much of this waste could be reduced if AI systems were grounded in authoritative, real-time package intelligence rather than pattern prediction alone.</p><p>Our recent research reinforces this point. The company found that smaller AI models augmented with live package intelligence significantly outperformed larger standalone models when handling dependency upgrades and package selection tasks. The findings suggest that real-time ecosystem context matters more than model size alone when developers are making security-sensitive decisions. It also helps smaller models are 70x cheaper compared to frontier models.</p><p>This has direct implications for software supply-chain defense. If AI coding assistants recommend dependencies without verifying package provenance, maintenance status, or ecosystem trust signals, they risk accelerating the spread of malicious or hallucinated packages into production environments.</p><p>In practice, secure AI-assisted development will depend less on increasingly large models and more on whether those models are connected to authoritative, continuously updated software intelligence.</p><p>Here too, the lesson is upstream control. Guardrails must sit at the point of dependency selection, not after the code ships.</p><h2 id="why-defenders-are-falling-behind">Why defenders are falling behind</h2><p>Many UK security controls remain focused on detecting threats after code is deployed. Attackers have moved upstream. They target the build process, the dependency graph, and the trust relationships developers rely on.</p><p>This mismatch leaves organizations well prepared for runtime incidents but exposed during development. As long as defenders assume malware announces itself loudly, supply-chain compromise will continue to slip through unnoticed.</p><p>“Shift left” is often treated as a slogan. In practice, it means enforcing policy before installation, validating provenance before execution, and blocking malicious packages before they enter the graph.</p><h2 id="stealing-the-keys-not-the-cycles">Stealing the keys, not the cycles</h2><p>Open-source malware has evolved from stealing compute to stealing access. Credentials unlock ecosystems, not just machines. For UK organisations, this makes supply-chain security a strategic concern rather than a technical afterthought.</p><p>Preventing malicious code from entering the build is now more effective than responding after deployment. The quiet shift from coins to credentials has already happened. The question is whether defenses will adapt quickly enough to match it.</p><p>If it isn’t automated, it won’t scale.</p><h2 id="what-organizations-should-prioritize-now">What organizations should prioritize now</h2><p>To respond effectively, UK organisations should focus on a small number of structural controls:</p><p>●      Gate dependency intake with automated policy enforcement before packages enter CI/CD.</p><p>●      Continuously monitor for secret exposure within build environments and revoke compromised credentials rapidly.</p><p>●      Enforce provenance and integrity verification for open-source components, including transitive dependencies.</p><p>●      Ground AI coding tools in authoritative package intelligence to prevent hallucinated or malicious dependency suggestions.</p><p>None of these measures eliminate risk. But together, they realign defenses with where attackers are actually operating: upstream, automated, and inside the supply chain.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>We've ranked and reviewed the best antivirus software available.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/how-open-source-malware-is-re-targeting-uk-supply-chains</link>
                                                                            <description>
                            <![CDATA[ Open-source malware has changed shape. What once focused on noisy cryptomining has moved toward something far more valuable: access. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">K7kRczCJ8xu5ULpbPps76b</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Aug 2026 09:13:55 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ilkka Turunen ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phone malware]]></media:description>                                                            <media:text><![CDATA[Phone malware]]></media:text>
                                <media:title type="plain"><![CDATA[Phone malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Open-source <a href="https://www.techradar.com/best/best-malware-removal">malware</a> has changed shape. </p><p>What once focused on noisy cryptomining has moved toward something far more valuable: access. </p><p>Our recent data shows attackers are increasingly targeting credentials and secrets embedded in software dependencies, with UK organizations firmly in scope.</p><p>This shift marks a move away from opportunistic abuse toward deliberate supply-chain compromise. Instead of draining compute cycles, attackers are positioning themselves inside build pipelines and developer workflows. </p><p>The goal is persistence, not disruption. </p><p>For organizations that rely heavily on <a href="https://www.techradar.com/best/best-open-source-software">open source software</a>, this fundamentally changes both the threat model and the potential impact.</p><p>This is what “shift left” actually means in 2026: controlling what enters the build, not just detecting what runs in production.</p><h2 id="why-credential-theft-has-overtaken-cryptomining">Why credential theft has overtaken cryptomining</h2><p>More than half of malicious open-source packages now focus on stealing credentials and secrets, overtaking cryptomining as the dominant threat type. The reason is straightforward. Credentials offer lasting value. They provide persistent access, broader reach across environments, and a lower risk of detection than resource abuse. A stolen token or API key can unlock entire systems, not just a single machine.</p><p>Cryptomining, by contrast, is easy to spot and quick to shut down. It consumes resources and triggers alerts. Credential theft blends in and can be executed in seconds. It exploits the trust placed on developer workflows to operate in a safe environment. </p><p>For attackers looking to maximize return while minimizing exposure, this approach maximizes returns whilst doing away with the risk of being discovered.</p><p>The implication is clear: protecting runtime infrastructure is no longer enough. The <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> boundary now starts at dependency intake and at the developer environment.</p><h2 id="multi-stage-malware-becomes-the-norm">Multi-stage malware becomes the norm</h2><p>Modern open-source malware is rarely single-purpose. Our analysis shows dropper and loader behavior increasing by nearly 2,900 percent year over year in Q1 2025, signaling a shift toward engineered, multi-stage attacks. </p><p>Around 77 percent of malicious packages distributed through open source ecosystems now combine multiple threat types. Droppers appear in nearly all observed cases, while secret exfiltration features in close to two-thirds.</p><p>These packages are designed to evolve after installation, pulling in additional payloads or changing behavior over time. This reflects industrialized campaigns rather than opportunistic experimentation. Attackers are investing in resilience, stealth, and scale.</p><p>For defenders, this means signature-based thinking is outdated. If malware is modular and adaptive, controls must focus on provenance, behavior, and prevention before execution. Again, this is what “shift left” actually means: securing the build graph itself, not just the workloads it produces.</p><h2 id="supply-chains-under-direct-pressure">Supply chains under direct pressure</h2><p>The widespread use of open source, particularly within the <a href="https://www.techradar.com/best/best-online-courses-to-learn-javascript">JavaScript</a> ecosystem, creates systemic exposure. Modern applications routinely depend on hundreds of direct and transitive npm packages. That density of reuse creates efficiency, but also amplifies upstream risk.</p><p>Recent activity linked to the Lazarus group illustrates the threat. More than 200 malicious packages were identified, almost all concentrated in npm. When a single ecosystem underpins financial services platforms, government services, and critical national <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>, concentration risk becomes a strategic issue.</p><p>A compromised dependency does not stay isolated. It propagates through shared frameworks, internal libraries, and CI pipelines. In sectors built on speed and reuse, upstream compromise quickly becomes downstream impact. This is why dependency governance is no longer just a developer hygiene issue; it is a board-level supply-chain concern.</p><h2 id="automation-turns-one-package-into-thousands-of-compromises">Automation turns one package into thousands of compromises</h2><p>Today’s malware increasingly targets CI/CD pipelines and developer workflows optimized for <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a>. When a compromised dependency enters a build, it can quietly extract API keys, certificates, and access tokens without triggering runtime alerts. Automation does the rest.</p><p>What starts as a single poisoned package can spread across hundreds or thousands of builds. The very systems designed to accelerate delivery now accelerate compromise.</p><p>The practical takeaway is uncomfortable but necessary: if build systems are automated, security controls must be automated at the same level. Manual review cannot scale against automated distribution.</p><h2 id="ai-coding-assistants-and-the-hallucination-problem">AI coding assistants and the hallucination problem</h2><p><a href="https://www.techradar.com/best/best-ai-tools">AI</a>-assisted development introduces an additional layer of risk. Studies and testing have shown that large language models can, in a meaningful percentage of cases, suggest packages or functions that do not exist. Developers under time pressure may attempt to install or rely on these hallucinated dependencies, unknowingly expanding the attack surface.</p><p>Hallucinated package names, fabricated examples, and unsafe dependency suggestions can quietly undermine supply-chain integrity. Attackers are already exploiting naming conventions and trust models to seed packages that appear legitimate to both humans and machines.</p><p>Each hallucination creates rework, friction, and lost <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a>. Much of this waste could be reduced if AI systems were grounded in authoritative, real-time package intelligence rather than pattern prediction alone.</p><p>Our recent research reinforces this point. The company found that smaller AI models augmented with live package intelligence significantly outperformed larger standalone models when handling dependency upgrades and package selection tasks. The findings suggest that real-time ecosystem context matters more than model size alone when developers are making security-sensitive decisions. It also helps smaller models are 70x cheaper compared to frontier models.</p><p>This has direct implications for software supply-chain defense. If AI coding assistants recommend dependencies without verifying package provenance, maintenance status, or ecosystem trust signals, they risk accelerating the spread of malicious or hallucinated packages into production environments.</p><p>In practice, secure AI-assisted development will depend less on increasingly large models and more on whether those models are connected to authoritative, continuously updated software intelligence.</p><p>Here too, the lesson is upstream control. Guardrails must sit at the point of dependency selection, not after the code ships.</p><h2 id="why-defenders-are-falling-behind">Why defenders are falling behind</h2><p>Many UK security controls remain focused on detecting threats after code is deployed. Attackers have moved upstream. They target the build process, the dependency graph, and the trust relationships developers rely on.</p><p>This mismatch leaves organizations well prepared for runtime incidents but exposed during development. As long as defenders assume malware announces itself loudly, supply-chain compromise will continue to slip through unnoticed.</p><p>“Shift left” is often treated as a slogan. In practice, it means enforcing policy before installation, validating provenance before execution, and blocking malicious packages before they enter the graph.</p><h2 id="stealing-the-keys-not-the-cycles">Stealing the keys, not the cycles</h2><p>Open-source malware has evolved from stealing compute to stealing access. Credentials unlock ecosystems, not just machines. For UK organisations, this makes supply-chain security a strategic concern rather than a technical afterthought.</p><p>Preventing malicious code from entering the build is now more effective than responding after deployment. The quiet shift from coins to credentials has already happened. The question is whether defenses will adapt quickly enough to match it.</p><p>If it isn’t automated, it won’t scale.</p><h2 id="what-organizations-should-prioritize-now">What organizations should prioritize now</h2><p>To respond effectively, UK organisations should focus on a small number of structural controls:</p><p>●      Gate dependency intake with automated policy enforcement before packages enter CI/CD.</p><p>●      Continuously monitor for secret exposure within build environments and revoke compromised credentials rapidly.</p><p>●      Enforce provenance and integrity verification for open-source components, including transitive dependencies.</p><p>●      Ground AI coding tools in authoritative package intelligence to prevent hallucinated or malicious dependency suggestions.</p><p>None of these measures eliminate risk. But together, they realign defenses with where attackers are actually operating: upstream, automated, and inside the supply chain.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>We've ranked and reviewed the best antivirus software available.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New ChainDrop worm poisons over 1,300 npm packages, Keyv and Cacheable among those hit ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Aikido researchers uncovers ChainDrop, a Shai‑Hulud variant infecting 1,300+ npm packages with an infostealer</strong></li><li><strong>Attackers compromised GitHub accounts tied to popular libraries (Keyv, Cacheable, flat‑cache, file‑entry‑cache) and pushed tainted releases with 2B monthly downloads</strong></li><li><strong>Malware exfiltrates developer/cloud credentials and secrets to a public GitHub repo; admins should treat affected systems as compromised even after removal</strong></li></ul><p>Another Shai-Hulud variant has been discovered in the wild, infecting more than 1,300 npm packages with an infostealer.</p><p>Security researchers Aikido <a href="https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack" target="_blank" rel="nofollow">reported</a> finding “at least 868 packages (across 1381 versions) that have been compromised by the worm.”</p><p>Shai-Hulud is a self-propagating supply chain <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> that targets software developers by compromising open-source packages and CI/CD pipelines. It steals credentials, API keys, and access tokens and then uses those stolen secrets to publish additional malicious packages.</p><h2 id="what-to-do-in-case-of-an-infection">What to do in case of an infection</h2><p>In May 2026, actors claiming to be associated with the TeamPCP group publicly released the <a href="https://www.techradar.com/pro/security/self-replicating-shai-hulud-infects-147-npm-packages-with-over-2-million-downloads-per-week" target="_blank">Shai-Hulud</a> worm's source code, saying they were “open sourcing the carnage” and inviting other threat actors to adopt and modify the code. Since then, there were multiple copycat campaigns and variants, including this one which Aikido dubbed ‘ChainDrop’.</p><p>Aikido said the attackers compromised the GitHub account of the person maintaining Keyv and Cacheable, widely used open source JavaScript libraries for caching data in Node.js applications. From there, they were able to move into other popular utilities such as flat-cache and file-entry-cache, as well as packages associated with organizations such as Deliveroo, Ornikar, OneReach, Picsart, Qlik, and ServiceTitan.</p><p>The malware was pushed directly into the projects’ main branches, and then generated additional package releases. The compromised packages have a combined 2 billion monthly downloads. </p><p>Aikido says the infostealer grabs developer and cloud credentials, encrypts them, and then sends them to a public GitHub repository called “Shai-Hulud: Here We Go Again.”</p><p>It also steals local configuration files, GitHub PATs, workflow tokens, and other ghp_, gho_, and ghs_ tokens, certain npm tokens, GitHub Actions secrets, AWS credentials, Kubernetes secrets, and more. </p><p>The researchers are saying system admins who installed a tainted package should treat their developer workstation or CI/CD runner as compromised, even if they removed the package. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/new-chaindrop-worm-poisons-over-1-300-npm-packages-keyv-and-cacheable-among-those-hit</link>
                                                                            <description>
                            <![CDATA[ Another Shai-Hulud variant hits npm packages, worming its way into hundreds of packages. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">RckCeYHbHTFv2D4CzixxRm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Aug 2026 11:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:description>                                                            <media:text><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:text>
                                <media:title type="plain"><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Aikido researchers uncovers ChainDrop, a Shai‑Hulud variant infecting 1,300+ npm packages with an infostealer</strong></li><li><strong>Attackers compromised GitHub accounts tied to popular libraries (Keyv, Cacheable, flat‑cache, file‑entry‑cache) and pushed tainted releases with 2B monthly downloads</strong></li><li><strong>Malware exfiltrates developer/cloud credentials and secrets to a public GitHub repo; admins should treat affected systems as compromised even after removal</strong></li></ul><p>Another Shai-Hulud variant has been discovered in the wild, infecting more than 1,300 npm packages with an infostealer.</p><p>Security researchers Aikido <a href="https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack" target="_blank" rel="nofollow">reported</a> finding “at least 868 packages (across 1381 versions) that have been compromised by the worm.”</p><p>Shai-Hulud is a self-propagating supply chain <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> that targets software developers by compromising open-source packages and CI/CD pipelines. It steals credentials, API keys, and access tokens and then uses those stolen secrets to publish additional malicious packages.</p><h2 id="what-to-do-in-case-of-an-infection">What to do in case of an infection</h2><p>In May 2026, actors claiming to be associated with the TeamPCP group publicly released the <a href="https://www.techradar.com/pro/security/self-replicating-shai-hulud-infects-147-npm-packages-with-over-2-million-downloads-per-week" target="_blank">Shai-Hulud</a> worm's source code, saying they were “open sourcing the carnage” and inviting other threat actors to adopt and modify the code. Since then, there were multiple copycat campaigns and variants, including this one which Aikido dubbed ‘ChainDrop’.</p><p>Aikido said the attackers compromised the GitHub account of the person maintaining Keyv and Cacheable, widely used open source JavaScript libraries for caching data in Node.js applications. From there, they were able to move into other popular utilities such as flat-cache and file-entry-cache, as well as packages associated with organizations such as Deliveroo, Ornikar, OneReach, Picsart, Qlik, and ServiceTitan.</p><p>The malware was pushed directly into the projects’ main branches, and then generated additional package releases. The compromised packages have a combined 2 billion monthly downloads. </p><p>Aikido says the infostealer grabs developer and cloud credentials, encrypts them, and then sends them to a public GitHub repository called “Shai-Hulud: Here We Go Again.”</p><p>It also steals local configuration files, GitHub PATs, workflow tokens, and other ghp_, gho_, and ghs_ tokens, certain npm tokens, GitHub Actions secrets, AWS credentials, Kubernetes secrets, and more. </p><p>The researchers are saying system admins who installed a tainted package should treat their developer workstation or CI/CD runner as compromised, even if they removed the package. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New malware disguised as popular Roblox cheat tool could give hackers full control of your PC — including the webcam ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Bitdefender reported Roblox players lured by a fake “undetected” Xeno Executor mod spreading malware</strong></li><li><strong>Infection chain delivers a Java‑based RAT and infostealer stealing browser data, online accounts, payment info, and crypto wallets</strong></li><li><strong>Malware also enables surveillance and remote control; campaign peaked in March 2026 and remains active against Roblox’s 82M players</strong></li></ul><p>Cybercriminals are targeting Roblox players with an infostealer and a Remote Access Trojan (RAT) malware that grants them full control over compromised computers, experts have warned.</p><p>Roblox is an online gaming platform, virtual universe, and game creation system where users play millions of games and user-generated mods. Among the mods is Xeno Executor, a utility that allows players to run scripts that automate certain actions or run custom code. Some players use Xeno Executor to run cheats, too.</p><p>Since it’s an unofficial script, Roblox does not allow it and blocks it whenever a new version is released. Now, security researchers Bitdefender have <a href="https://www.bitdefender.com/en-us/blog/labs/fake-xeno-roblox-discord-executor" target="_blank">reported</a> finding an “undetected” version being promoted on various gaming forums, Discord communities, and similar.</p><h2 id="cornflake-and-cocoshell">CornFlake and CocoShell</h2><p>This version is advertised as “invisible” to Roblox’s anti-cheat systems, but in reality, all it does is trigger an infection chain that ends in a Java-based RAT and information stealer. </p><p>The <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> grabs browser data such as passwords and cookies from some of the most popular browsers (Chrome, Edge, Brave, Opera, Vivaldi), as well as online accounts and payment data (Discord, Roblox, Minecraft, Microsoft Store tokens, and more). </p><p>It also steals cryptocurrency wallet data, particularly targeting the Exodus Wallet. </p><p>As for surveillance, it can log keys, track mouse movements, grab screenshots, stream whatever is on the desktop, and access the webcam. The crooks are also granted file upload and download, PowerShell command execution, and more. </p><p>The campaign was kicked off at the start of the year, reaching its peak in March, it was said. It has now stabilized and is still going relatively strong. </p><p>We don’t know exactly how many players fell victim to this campaign, but Roblox is an incredibly popular platform, so it is possible the campaign was rather successful, too.</p><p>According to <a href="https://activeplayer.io/roblox/" target="_blank" rel="nofollow"><u>Activeplayer</u></a>, Roblox currently has more than 82 million active players.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/new-malware-disguised-as-popular-roblox-cheat-tool-could-give-hackers-full-control-of-your-pc-including-the-webcam</link>
                                                                            <description>
                            <![CDATA[ A new "invisible" Xeno Executor is actually a highly capable RAT and a potent infostealer. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bdewFffvWfEHEGEL8NkXC4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/d7fHZ9ema8LcBAtrUaK7Ji-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Aug 2026 18:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/d7fHZ9ema8LcBAtrUaK7Ji-1280-80.png">
                                                            <media:credit><![CDATA[Roblox]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Screenshot of Roblox&#039;s new Kids and Select accounts]]></media:description>                                                            <media:text><![CDATA[Screenshot of Roblox&#039;s new Kids and Select accounts]]></media:text>
                                <media:title type="plain"><![CDATA[Screenshot of Roblox&#039;s new Kids and Select accounts]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/d7fHZ9ema8LcBAtrUaK7Ji-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Bitdefender reported Roblox players lured by a fake “undetected” Xeno Executor mod spreading malware</strong></li><li><strong>Infection chain delivers a Java‑based RAT and infostealer stealing browser data, online accounts, payment info, and crypto wallets</strong></li><li><strong>Malware also enables surveillance and remote control; campaign peaked in March 2026 and remains active against Roblox’s 82M players</strong></li></ul><p>Cybercriminals are targeting Roblox players with an infostealer and a Remote Access Trojan (RAT) malware that grants them full control over compromised computers, experts have warned.</p><p>Roblox is an online gaming platform, virtual universe, and game creation system where users play millions of games and user-generated mods. Among the mods is Xeno Executor, a utility that allows players to run scripts that automate certain actions or run custom code. Some players use Xeno Executor to run cheats, too.</p><p>Since it’s an unofficial script, Roblox does not allow it and blocks it whenever a new version is released. Now, security researchers Bitdefender have <a href="https://www.bitdefender.com/en-us/blog/labs/fake-xeno-roblox-discord-executor" target="_blank">reported</a> finding an “undetected” version being promoted on various gaming forums, Discord communities, and similar.</p><h2 id="cornflake-and-cocoshell">CornFlake and CocoShell</h2><p>This version is advertised as “invisible” to Roblox’s anti-cheat systems, but in reality, all it does is trigger an infection chain that ends in a Java-based RAT and information stealer. </p><p>The <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> grabs browser data such as passwords and cookies from some of the most popular browsers (Chrome, Edge, Brave, Opera, Vivaldi), as well as online accounts and payment data (Discord, Roblox, Minecraft, Microsoft Store tokens, and more). </p><p>It also steals cryptocurrency wallet data, particularly targeting the Exodus Wallet. </p><p>As for surveillance, it can log keys, track mouse movements, grab screenshots, stream whatever is on the desktop, and access the webcam. The crooks are also granted file upload and download, PowerShell command execution, and more. </p><p>The campaign was kicked off at the start of the year, reaching its peak in March, it was said. It has now stabilized and is still going relatively strong. </p><p>We don’t know exactly how many players fell victim to this campaign, but Roblox is an incredibly popular platform, so it is possible the campaign was rather successful, too.</p><p>According to <a href="https://activeplayer.io/roblox/" target="_blank" rel="nofollow"><u>Activeplayer</u></a>, Roblox currently has more than 82 million active players.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts reveal Google Password Manager can be hijacked to let hackers steal passkeys and gain access to all your secrets ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Palo Alto Networks’ Unit 42 detailed three Google passkey exploits</strong></li><li><strong>Attacks require prior malware infection; methods ranged from impersonating victims to stealing the master secret protecting synced passkeys</strong></li><li><strong>Google implemented fixes after disclosure, with some services (e.g., eBay) patching vulnerabilities directly</strong></li></ul><p>Security researchers from Palo Alto Networks’ Unit 42 have found three ways to exploit Google’s passkey system and log into people’s PIN- or biometrics-protected accounts. </p><p>They named these ways ‘Pass-ta-key’, ‘Silver Pass-ta-key’, and ‘Golden Pass-ta-key’, each being progressively more dangerous than the previous one. </p><p>While it sounds mighty dangerous, there are major caveats to the exploit, and some of the holes have been plugged already.</p><h2 id="trusting-the-wrong-device">Trusting the wrong device</h2><p>The biggest caveat is that the victim’s device needs to be infected with malware beforehand. Malware can do all sorts of things, from stealing session cookies to exfiltrating sensitive data, so if a device is tainted with malware, it’s already in trouble.</p><p>Still, Unit 42’s findings were important enough to warrant a fix from Google.</p><p>In the first technique, the attackers pretend to be the victim. By using malware, they can “ask” Google to log into a passkey-protected account as if it was the victim themselves. Usually, the service being logged into would require a PIN or a fingerprint to confirm the authenticity of the request, but in this scenario, that wasn’t the case.</p><p>The method doesn’t work everywhere, though. Unit 42 could not replicate the attack on GitHub, but they succeeded on eBay. The latter later fixed the problem. </p><p>In the second attack, Unit 42 managed to make Google “trust” the threat actor’s device, meaning the victim’s computer was no longer necessary. </p><p>In the third attack, the researchers managed to steal the “master key”. </p><p><a href="https://www.techradar.com/best/password-manager" target="_blank">Google Password Manager</a> syncs the passkeys between devices, and to do that, it uses a master secret that protects all of the synced passkeys. The researchers found that, under certain circumstances, malware can grab this master secret while Chrome is temporarily using it, unlocking all of the synced passkeys, copying them to another computer, and being able to use them at a later date. </p><p>The researchers disclosed their findings with Google before publication, and some fixes were already implemented. Google is yet to comment on the findings and confirm that all of the flaws were addressed. </p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys/" target="_blank">BleepingComputer</a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/experts-reveal-google-password-manager-can-be-hijacked-to-let-hackers-steal-passkeys-and-gain-access-to-all-your-secrets</link>
                                                                            <description>
                            <![CDATA[ Three Pass-ta-key techniques allowed security researchers to work around biometrics-protected locks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bUumiq3YYstdbhKhfwc7fL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qGbky6N99QiLtik8fjzcUL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Aug 2026 15:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qGbky6N99QiLtik8fjzcUL-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / Blue Andy]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Circuit board and shield icon, Hardware security, computer data protection and electronic technology concept,]]></media:description>                                                            <media:text><![CDATA[Circuit board and shield icon, Hardware security, computer data protection and electronic technology concept,]]></media:text>
                                <media:title type="plain"><![CDATA[Circuit board and shield icon, Hardware security, computer data protection and electronic technology concept,]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qGbky6N99QiLtik8fjzcUL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Palo Alto Networks’ Unit 42 detailed three Google passkey exploits</strong></li><li><strong>Attacks require prior malware infection; methods ranged from impersonating victims to stealing the master secret protecting synced passkeys</strong></li><li><strong>Google implemented fixes after disclosure, with some services (e.g., eBay) patching vulnerabilities directly</strong></li></ul><p>Security researchers from Palo Alto Networks’ Unit 42 have found three ways to exploit Google’s passkey system and log into people’s PIN- or biometrics-protected accounts. </p><p>They named these ways ‘Pass-ta-key’, ‘Silver Pass-ta-key’, and ‘Golden Pass-ta-key’, each being progressively more dangerous than the previous one. </p><p>While it sounds mighty dangerous, there are major caveats to the exploit, and some of the holes have been plugged already.</p><h2 id="trusting-the-wrong-device">Trusting the wrong device</h2><p>The biggest caveat is that the victim’s device needs to be infected with malware beforehand. Malware can do all sorts of things, from stealing session cookies to exfiltrating sensitive data, so if a device is tainted with malware, it’s already in trouble.</p><p>Still, Unit 42’s findings were important enough to warrant a fix from Google.</p><p>In the first technique, the attackers pretend to be the victim. By using malware, they can “ask” Google to log into a passkey-protected account as if it was the victim themselves. Usually, the service being logged into would require a PIN or a fingerprint to confirm the authenticity of the request, but in this scenario, that wasn’t the case.</p><p>The method doesn’t work everywhere, though. Unit 42 could not replicate the attack on GitHub, but they succeeded on eBay. The latter later fixed the problem. </p><p>In the second attack, Unit 42 managed to make Google “trust” the threat actor’s device, meaning the victim’s computer was no longer necessary. </p><p>In the third attack, the researchers managed to steal the “master key”. </p><p><a href="https://www.techradar.com/best/password-manager" target="_blank">Google Password Manager</a> syncs the passkeys between devices, and to do that, it uses a master secret that protects all of the synced passkeys. The researchers found that, under certain circumstances, malware can grab this master secret while Chrome is temporarily using it, unlocking all of the synced passkeys, copying them to another computer, and being able to use them at a later date. </p><p>The researchers disclosed their findings with Google before publication, and some fixes were already implemented. Google is yet to comment on the findings and confirm that all of the flaws were addressed. </p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys/" target="_blank">BleepingComputer</a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI and regulation are reshaping the future of building security ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Criminals used to rely on lock-picking tools and crowbars to break into buildings. Today’s attackers can cause just as much damage and disruption by using phishing links, <a href="https://www.techradar.com/best/best-malware-removal">malware</a> and sophisticated digital exploits to target products, systems and networks.</p><p>The truth is, today’s security challenge isn’t just physical – or cyber – but both. And keeping one step ahead of criminals is a full-time occupation. For those people tasked with researching and developing the latest products, it sometimes means using unconventional tactics, such as using professional lock pickers to test the security and resilience of new products.  </p><p>While modern locks are still based on mechanical engineering, they are more advanced than they look. Improvements in design, materials, and manufacturing mean they are stronger, more reliable, and harder to tamper with. But there’s more to locks than just <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>.</p><p>Some systems can even use the motion of turning a key to generate a small amount of electrical energy, which provides energy to power extra functions without wiring or batteries. This means they are not just standalone locks but can also be used as part of wider digital access systems.</p><p>Used extensively in buildings such as offices, hotels, hospitals and other critical infrastructure, these modern digital access solutions can also connect to cloud-based platforms to manage who can enter buildings and restricted areas. </p><h2 id="bridging-physical-and-digital-security">Bridging physical and digital security</h2><p>However, digital systems have their own security risks, which means security teams need to anticipate and defend against a wide range of risks – from attempts to breach access platforms to phishing attacks – as well as other tactics designed to exploit human behavior.</p><p>This explains why some security personnel have to adopt a ‘hacker’s mindset’ to keep systems safe. And that means continuously testing, probing, and strengthening systems to identify vulnerabilities.</p><p>But what is becoming increasingly clear is that physical and digital security systems can no longer be treated as separate entities. </p><p>Many security solutions today employ both mechanical and digital technology, which means that resilience – the kind of resilience that keeps <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> centers safe, for example – depends on understanding how risks move across systems, people and environments.</p><h2 id="embedding-resilience-into-design">Embedding resilience into design</h2><p>That means continuously designing and testing products against existing real-world threats while also anticipating what might be around the corner. That includes building security into every stage of development, especially as technology evolves.   </p><p>For instance, great strides have been made recently in terms of biometric <a href="https://www.techradar.com/best/best-authenticator-apps">authentication</a>, including facial recognition and fingerprint scanning. Similarly, <a href="https://www.techradar.com/best/best-android-phones">smartphones</a> are increasingly being used to secure credentials for mobile-based access control systems.</p><p>Work is also currently underway to use artificial intelligence (AI) to analyze data in real time to identify unusual entry times, identify multiple failed authentication attempts, or spot any other anomalies that might suggest someone is trying to gain entry illegally. </p><p>Using <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> in a positive way is important because it is also the source of some of the newest and, therefore, most unpredictable challenges. For example, there are now autonomous AI threat chains that can discover and exploit vulnerabilities unilaterally, moving from reconnaissance to exfiltration in record time without any need for human oversight.</p><p>The danger posed by cyber criminals has also become more complex due to the growing interconnectivity of digital products and services. In many ways, a world where all hardware and software are interconnected is an efficient and convenient one.</p><p>But it is also one where, if bad actors gain access to a single element, they may be able to compromise the whole network.</p><h2 id="the-importance-of-regulation-and-compliance">The importance of regulation and compliance</h2><p>This is something that the European Union (EU) is actively addressing. For instance, the European Union’s (EU) NIS2 Directive relates to cybersecurity protecting network and information systems and significantly broadens both the scope and the obligations for compliance.</p><p>It also takes an “all-hazard” approach to security, which means protecting not just digital networks and systems, but also the physical environments in which they operate.</p><p>Similarly, the EU’s Cyber Resilience Act is designed to ensure that all digital products are safe from cyber threats. </p><p>Its goal is to ensure that connected devices and software are built, updated, and maintained with security in mind, helping protect users in an increasingly connected world.</p><p>And by introducing clearer requirements and standards, the CRA will help consumers and organizations identify products with strong security features and configure them more securely from the outset.</p><p>In both cases, not only is it incumbent on vendors to meet or exceed these rules and regulations, but also to keep customers, the wider industry, and other stakeholders informed about developments. </p><p>Not only must businesses contend with the usual challenges from phishing and malware, but the rapid growth of AI has introduced a new and unpredictable dimension to keeping out online criminals. Security – both physical and cyber – has never been more critical than it is today. </p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/ai-and-regulation-are-reshaping-the-future-of-building-security</link>
                                                                            <description>
                            <![CDATA[ Physical and digital security systems can no longer be treated as separate entities. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">PhaeDPPiRasLRCpz46RbMS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UjSNcAZ5SebctebKAMQNVF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 27 Jul 2026 09:08:45 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kelly Gill ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UjSNcAZ5SebctebKAMQNVF-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity ensures data protection on internet. Data encryption, firewall, encrypted network, VPN, secure access and authentication defend against malware, hacking, cyber crime and digital threat]]></media:description>                                                            <media:text><![CDATA[Cybersecurity ensures data protection on internet. Data encryption, firewall, encrypted network, VPN, secure access and authentication defend against malware, hacking, cyber crime and digital threat]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity ensures data protection on internet. Data encryption, firewall, encrypted network, VPN, secure access and authentication defend against malware, hacking, cyber crime and digital threat]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UjSNcAZ5SebctebKAMQNVF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Criminals used to rely on lock-picking tools and crowbars to break into buildings. Today’s attackers can cause just as much damage and disruption by using phishing links, <a href="https://www.techradar.com/best/best-malware-removal">malware</a> and sophisticated digital exploits to target products, systems and networks.</p><p>The truth is, today’s security challenge isn’t just physical – or cyber – but both. And keeping one step ahead of criminals is a full-time occupation. For those people tasked with researching and developing the latest products, it sometimes means using unconventional tactics, such as using professional lock pickers to test the security and resilience of new products.  </p><p>While modern locks are still based on mechanical engineering, they are more advanced than they look. Improvements in design, materials, and manufacturing mean they are stronger, more reliable, and harder to tamper with. But there’s more to locks than just <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>.</p><p>Some systems can even use the motion of turning a key to generate a small amount of electrical energy, which provides energy to power extra functions without wiring or batteries. This means they are not just standalone locks but can also be used as part of wider digital access systems.</p><p>Used extensively in buildings such as offices, hotels, hospitals and other critical infrastructure, these modern digital access solutions can also connect to cloud-based platforms to manage who can enter buildings and restricted areas. </p><h2 id="bridging-physical-and-digital-security">Bridging physical and digital security</h2><p>However, digital systems have their own security risks, which means security teams need to anticipate and defend against a wide range of risks – from attempts to breach access platforms to phishing attacks – as well as other tactics designed to exploit human behavior.</p><p>This explains why some security personnel have to adopt a ‘hacker’s mindset’ to keep systems safe. And that means continuously testing, probing, and strengthening systems to identify vulnerabilities.</p><p>But what is becoming increasingly clear is that physical and digital security systems can no longer be treated as separate entities. </p><p>Many security solutions today employ both mechanical and digital technology, which means that resilience – the kind of resilience that keeps <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> centers safe, for example – depends on understanding how risks move across systems, people and environments.</p><h2 id="embedding-resilience-into-design">Embedding resilience into design</h2><p>That means continuously designing and testing products against existing real-world threats while also anticipating what might be around the corner. That includes building security into every stage of development, especially as technology evolves.   </p><p>For instance, great strides have been made recently in terms of biometric <a href="https://www.techradar.com/best/best-authenticator-apps">authentication</a>, including facial recognition and fingerprint scanning. Similarly, <a href="https://www.techradar.com/best/best-android-phones">smartphones</a> are increasingly being used to secure credentials for mobile-based access control systems.</p><p>Work is also currently underway to use artificial intelligence (AI) to analyze data in real time to identify unusual entry times, identify multiple failed authentication attempts, or spot any other anomalies that might suggest someone is trying to gain entry illegally. </p><p>Using <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> in a positive way is important because it is also the source of some of the newest and, therefore, most unpredictable challenges. For example, there are now autonomous AI threat chains that can discover and exploit vulnerabilities unilaterally, moving from reconnaissance to exfiltration in record time without any need for human oversight.</p><p>The danger posed by cyber criminals has also become more complex due to the growing interconnectivity of digital products and services. In many ways, a world where all hardware and software are interconnected is an efficient and convenient one.</p><p>But it is also one where, if bad actors gain access to a single element, they may be able to compromise the whole network.</p><h2 id="the-importance-of-regulation-and-compliance">The importance of regulation and compliance</h2><p>This is something that the European Union (EU) is actively addressing. For instance, the European Union’s (EU) NIS2 Directive relates to cybersecurity protecting network and information systems and significantly broadens both the scope and the obligations for compliance.</p><p>It also takes an “all-hazard” approach to security, which means protecting not just digital networks and systems, but also the physical environments in which they operate.</p><p>Similarly, the EU’s Cyber Resilience Act is designed to ensure that all digital products are safe from cyber threats. </p><p>Its goal is to ensure that connected devices and software are built, updated, and maintained with security in mind, helping protect users in an increasingly connected world.</p><p>And by introducing clearer requirements and standards, the CRA will help consumers and organizations identify products with strong security features and configure them more securely from the outset.</p><p>In both cases, not only is it incumbent on vendors to meet or exceed these rules and regulations, but also to keep customers, the wider industry, and other stakeholders informed about developments. </p><p>Not only must businesses contend with the usual challenges from phishing and malware, but the rapid growth of AI has introduced a new and unpredictable dimension to keeping out online criminals. Security – both physical and cyber – has never been more critical than it is today. </p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts claim to have found more weaknesses in Apple's Gatekeeper tool — but it doesn't seem too bothered ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Researchers show Gatekeeper can be bypassed by replacing a previously run legitimate macOS app with malware</strong></li><li><strong>Attack requires prior user‑level code execution, then swaps in a malicious app that Gatekeeper won’t re‑verify</strong></li><li><strong>Apple dismissed the issue, saying locally rebuilt bundles fall outside Gatekeeper’s scope, leaving risk to social engineering</strong></li></ul><p>A pair of researchers claims to have found a way around Gatekeeper, a built-in macOS security feature that helps protect users from running malicious or untrusted software. However Apple doesn’t really see it that way and has seemingly decided not to pursue the issue further.</p><p>Gatekeeper’s modus operandi is rather simple - when a user downloads an app from outside the App Store, it verifies the product comes from an identified developer and is notarized by Apple. If it can’t verify it - it won’t allow it to run on the machine. </p><p>Now, security researchers Talal Haj Barky and Tommy Mysk claim that, as long as a legitimate app was run at least once on a macOS device, it can be replaced with a malicious version, and Gatekeeper won’t even blink its virtual eye.</p><h2 id="locally-built">Locally built</h2><p>That also means the attack is not that straightforward to pull off. The threat actor needs to have a way to execute user-level code (for example, a malicious app, a compromised software package installed through a package manager, or a prompt injection attack that tricks an AI agent).</p><p>Once that is obtained, they can archive a legitimate app, remove the original, then replace it with <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, and Gatekeeper will not try to re-authorize it. That malicious version can then trick the victim into compromising the device even further, since a certain level of trust was already established. </p><p>After reporting the issue to Apple, the company apparently just closed it. </p><p>"Apple doesn't consider this attack to be 'modifying' the signed executable," Mysk said. "Instead, Apple says that by archiving/restoring the app bundle, the proof-of-concept code overwrites the entire app bundle, making it locally built. Locally built app bundles are not covered by macOS guards. And this is why access to Keychain or TCC protected directories require system authorization prompts. And for users to accept those is a matter of social engineering attacks that Apple considers out of scope."</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/07/24/researchers-replace-downloaded-macos-apps-with-evil-twins-apple-shrugs/5277858" target="_blank"><em>The Register</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/experts-claim-to-have-found-more-weaknesses-in-apples-gatekeeper-tool-but-it-doesnt-seem-too-bothered</link>
                                                                            <description>
                            <![CDATA[ Gatekeeper doesn't blink when you archive a legitimate app and replace it with an evil doppelganger. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cigoAwt4EPwNFgf9LCcsXa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ctUFkwkvMxVyJJwJmZLPJ5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 25 Jul 2026 14:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ctUFkwkvMxVyJJwJmZLPJ5-1280-80.jpg">
                                                            <media:credit><![CDATA[Apple]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person using iPhone Mirroring on a MacBook Pro running macOS 27 Golden Gate.]]></media:description>                                                            <media:text><![CDATA[A person using iPhone Mirroring on a MacBook Pro running macOS 27 Golden Gate.]]></media:text>
                                <media:title type="plain"><![CDATA[A person using iPhone Mirroring on a MacBook Pro running macOS 27 Golden Gate.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ctUFkwkvMxVyJJwJmZLPJ5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers show Gatekeeper can be bypassed by replacing a previously run legitimate macOS app with malware</strong></li><li><strong>Attack requires prior user‑level code execution, then swaps in a malicious app that Gatekeeper won’t re‑verify</strong></li><li><strong>Apple dismissed the issue, saying locally rebuilt bundles fall outside Gatekeeper’s scope, leaving risk to social engineering</strong></li></ul><p>A pair of researchers claims to have found a way around Gatekeeper, a built-in macOS security feature that helps protect users from running malicious or untrusted software. However Apple doesn’t really see it that way and has seemingly decided not to pursue the issue further.</p><p>Gatekeeper’s modus operandi is rather simple - when a user downloads an app from outside the App Store, it verifies the product comes from an identified developer and is notarized by Apple. If it can’t verify it - it won’t allow it to run on the machine. </p><p>Now, security researchers Talal Haj Barky and Tommy Mysk claim that, as long as a legitimate app was run at least once on a macOS device, it can be replaced with a malicious version, and Gatekeeper won’t even blink its virtual eye.</p><h2 id="locally-built">Locally built</h2><p>That also means the attack is not that straightforward to pull off. The threat actor needs to have a way to execute user-level code (for example, a malicious app, a compromised software package installed through a package manager, or a prompt injection attack that tricks an AI agent).</p><p>Once that is obtained, they can archive a legitimate app, remove the original, then replace it with <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, and Gatekeeper will not try to re-authorize it. That malicious version can then trick the victim into compromising the device even further, since a certain level of trust was already established. </p><p>After reporting the issue to Apple, the company apparently just closed it. </p><p>"Apple doesn't consider this attack to be 'modifying' the signed executable," Mysk said. "Instead, Apple says that by archiving/restoring the app bundle, the proof-of-concept code overwrites the entire app bundle, making it locally built. Locally built app bundles are not covered by macOS guards. And this is why access to Keychain or TCC protected directories require system authorization prompts. And for users to accept those is a matter of social engineering attacks that Apple considers out of scope."</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/07/24/researchers-replace-downloaded-macos-apps-with-evil-twins-apple-shrugs/5277858" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Iran-linked group caught hiding surveillance tools in fake apps ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Recorded Future found an Iran-linked group spreading spyware</strong></li><li><strong>The malware is delivered through fake VPN and media player apps</strong></li><li><strong>Researchers assess that most targets are Iranian users</strong></li></ul><p>A new report from <a href="https://www.recordedfuture.com/research/nexus-tag182-disseminates-markirat" target="_blank" rel="nofollow">Recorded Future's Insikt Group</a> describes a campaign that inverts the whole point of a privacy tool: fake VPN apps built specifically to spy on the people who install them.</p><p>Researchers have linked fresh infrastructure to an Iran-nexus threat cluster they track as TAG-182, which is using fake VPN and media player downloads to allegedly deliver a surveillance tool called MarkiRAT. The group is "highly likely" to be targeting Iranians living inside and outside the country, <a href="https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-ir-2026-0701.pdf" target="_blank" rel="nofollow">the report says</a>.</p><p>It's a blunt reminder that choosing one of the <a href="https://www.techradar.com/vpn/best-vpn" target="_blank" rel="nofollow">best VPN</a> services is a lot more secure than downloading free, unvetted tools.</p><h2 id="fake-apps-real-surveillance">Fake apps, real surveillance</h2><p>Insikt Group identified a cluster of attacker-controlled domains allegedly used to stage downloads of applications that appear nowhere on Google Play or Apple's App Store. </p><p>Two names stand out: Pis2ray VPN and a media player branded YESHICA, which was quietly renamed YESHICA YEPlayer in March 2026 after researchers publicly exposed the original.</p><p>According to researchers, if you download and run one of these files, you get MarkiRAT, a remote access Trojan. In plain terms, that is software that hands control of your device to somebody else. </p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/2072720755884695924"><p lang="en" dir="ltr">A fake VPN app. A fake media player. Both delivering Iranian government surveillance #malware to targeted dissidents. Insikt Group has new research on TAG-182 and MarkiRAT:https://t.co/G7p9JO6peT#ThreatIntelligence #Cybersecurity pic.twitter.com/GwDyvGC99r<a href="https://twitter.com/cantworkitout/status/2072720755884695924">July 2, 2026</a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Analysts have documented it capturing screenshots and uploading them to attacker-run servers, while disguising itself under believable process names.</p><p>It also abuses BITS, the background service Windows uses to fetch updates, to pull down further files. Because that activity looks like ordinary system housekeeping rather than an attack, it tends to slip past routine cleanup.</p><p>MarkiRAT is not new. It has previously been used by Ferocious Kitten, a group <a href="https://securelist.com/ferocious-kitten-6-years-of-covert-surveillance-in-iran/102806/" target="_blank" rel="nofollow">Kaspersky</a> documented conducting years of covert surveillance against activists inside Iran. </p><p>Recorded Future stops short of attributing TAG-182 to any specific Iranian agency, but places it within a broader ecosystem of state-aligned surveillance groups.</p><div data-widget-type="multimodelreview" data-model-name="NordVPN,Surfshark,Proton VPN" data-widget-title="Today's best VPN deals" class="hawk-root"></div><h2 id="why-a-fake-vpn-makes-such-an-effective-lure">Why a fake VPN makes such an effective lure</h2><p>Distribution runs largely through social media. Insikt Group found Instagram posts promoting Pis2ray VPN in the weeks following street protests in Iran in late 2025, and again around the <a href="https://www.techradar.com/vpn/vpn-privacy-security/the-internet-is-not-connected-irans-88-day-blackout-begins-to-lift-but-traffic-remains-under-50-percent">country's prolonged internet shutdown</a>, which ended with partial restoration of access on 26 May 2026.</p><p>The people most desperate for a <a href="https://www.techradar.com/vpn/virtual-private-networks">virtual private network (VPN)</a> in a censored country are exactly the people most likely to install one from a social media link, because the official stores are often the very thing they cannot reach. </p><p>Recorded Future considers it almost certain that most targets are located in Iran or tied to anti-government movements in Europe and North America. TechRadar has covered <a href="https://www.techradar.com/vpn/vpn-privacy-security/beware-iran-linked-fake-vpn-apps-found-to-spy-on-android-users" target="_blank" rel="nofollow">previous Iran-linked fake VPN campaigns</a>, and this one seems to follow the same pattern with better infrastructure.</p><h2 id="how-to-stay-safe-3">How to stay safe</h2><p>Most readers will never be targeted by a state actor, but the underlying lesson travels. </p><p>Install VPN apps only from official stores, and check that the provider has a real, verifiable presence outside the app listing. </p><p>Treat any VPN promoted through an Instagram post, a Telegram channel, or a direct message as suspect, however polished it looks. </p><p>Star ratings are a weak signal, since fake reviews are cheap.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/vpn/vpn-privacy-security/iran-linked-group-caught-hiding-surveillance-tools-in-fake-apps</link>
                                                                            <description>
                            <![CDATA[ Researchers at Recorded Future found evidence that an Iran-linked group is spreading MarkiRAT spyware through fake VPN and media player apps promoted on social media, targeting Farsi speakers worldwide. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rcr4Mct7ErHSY84Lpy5fvW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/z8Ysj7MUYeyK822yMiTepP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 25 Jul 2026 06:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[VPN Privacy &amp; Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ monicajwrites@gmail.com (Monica J. White) ]]></author>                    <dc:creator><![CDATA[ Monica J. White ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/6AQ4y5nzk8kQ47Yp69GERj.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Monica is a journalist with over a decade of experience in covering technology.&lt;/p&gt;&lt;p&gt;She writes about the latest developments in computing, which means anything from computer chips made out of paper to cutting-edge desktop processors. Her coverage includes CPUs, GPUs, and everything else that goes into a PC or a laptop, but also peripherals.&lt;/p&gt;&lt;p&gt;GPUs are Monica’s main area of interest, and nothing thrills her quite like that time every couple of years when new graphics cards hit the market. She’s always keeping tabs on the latest from Nvidia, AMD, and Intel, including both the hardware and the software that powers our PCs.&lt;/p&gt;&lt;p&gt;As an avid gamer, her focus is always on the consumer and whether something works well and provides adequate value for the money. She believes that PC building can be intimidating, so her goal is to explain complex concepts in an approachable manner while still digging into the technical nitty-gritty we all love to learn more about.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/z8Ysj7MUYeyK822yMiTepP-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Malware kan ställa till med oreda]]></media:description>                                                            <media:text><![CDATA[A hand with a mobile phone and VPN application in front of the Iran flag]]></media:text>
                                <media:title type="plain"><![CDATA[A hand with a mobile phone and VPN application in front of the Iran flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/z8Ysj7MUYeyK822yMiTepP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Recorded Future found an Iran-linked group spreading spyware</strong></li><li><strong>The malware is delivered through fake VPN and media player apps</strong></li><li><strong>Researchers assess that most targets are Iranian users</strong></li></ul><p>A new report from <a href="https://www.recordedfuture.com/research/nexus-tag182-disseminates-markirat" target="_blank" rel="nofollow">Recorded Future's Insikt Group</a> describes a campaign that inverts the whole point of a privacy tool: fake VPN apps built specifically to spy on the people who install them.</p><p>Researchers have linked fresh infrastructure to an Iran-nexus threat cluster they track as TAG-182, which is using fake VPN and media player downloads to allegedly deliver a surveillance tool called MarkiRAT. The group is "highly likely" to be targeting Iranians living inside and outside the country, <a href="https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-ir-2026-0701.pdf" target="_blank" rel="nofollow">the report says</a>.</p><p>It's a blunt reminder that choosing one of the <a href="https://www.techradar.com/vpn/best-vpn" target="_blank" rel="nofollow">best VPN</a> services is a lot more secure than downloading free, unvetted tools.</p><h2 id="fake-apps-real-surveillance">Fake apps, real surveillance</h2><p>Insikt Group identified a cluster of attacker-controlled domains allegedly used to stage downloads of applications that appear nowhere on Google Play or Apple's App Store. </p><p>Two names stand out: Pis2ray VPN and a media player branded YESHICA, which was quietly renamed YESHICA YEPlayer in March 2026 after researchers publicly exposed the original.</p><p>According to researchers, if you download and run one of these files, you get MarkiRAT, a remote access Trojan. In plain terms, that is software that hands control of your device to somebody else. </p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/2072720755884695924"><p lang="en" dir="ltr">A fake VPN app. A fake media player. Both delivering Iranian government surveillance #malware to targeted dissidents. Insikt Group has new research on TAG-182 and MarkiRAT:https://t.co/G7p9JO6peT#ThreatIntelligence #Cybersecurity pic.twitter.com/GwDyvGC99r<a href="https://twitter.com/cantworkitout/status/2072720755884695924">July 2, 2026</a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Analysts have documented it capturing screenshots and uploading them to attacker-run servers, while disguising itself under believable process names.</p><p>It also abuses BITS, the background service Windows uses to fetch updates, to pull down further files. Because that activity looks like ordinary system housekeeping rather than an attack, it tends to slip past routine cleanup.</p><p>MarkiRAT is not new. It has previously been used by Ferocious Kitten, a group <a href="https://securelist.com/ferocious-kitten-6-years-of-covert-surveillance-in-iran/102806/" target="_blank" rel="nofollow">Kaspersky</a> documented conducting years of covert surveillance against activists inside Iran. </p><p>Recorded Future stops short of attributing TAG-182 to any specific Iranian agency, but places it within a broader ecosystem of state-aligned surveillance groups.</p><div data-widget-type="multimodelreview" data-model-name="NordVPN,Surfshark,Proton VPN" data-widget-title="Today's best VPN deals" class="hawk-root"></div><h2 id="why-a-fake-vpn-makes-such-an-effective-lure">Why a fake VPN makes such an effective lure</h2><p>Distribution runs largely through social media. Insikt Group found Instagram posts promoting Pis2ray VPN in the weeks following street protests in Iran in late 2025, and again around the <a href="https://www.techradar.com/vpn/vpn-privacy-security/the-internet-is-not-connected-irans-88-day-blackout-begins-to-lift-but-traffic-remains-under-50-percent">country's prolonged internet shutdown</a>, which ended with partial restoration of access on 26 May 2026.</p><p>The people most desperate for a <a href="https://www.techradar.com/vpn/virtual-private-networks">virtual private network (VPN)</a> in a censored country are exactly the people most likely to install one from a social media link, because the official stores are often the very thing they cannot reach. </p><p>Recorded Future considers it almost certain that most targets are located in Iran or tied to anti-government movements in Europe and North America. TechRadar has covered <a href="https://www.techradar.com/vpn/vpn-privacy-security/beware-iran-linked-fake-vpn-apps-found-to-spy-on-android-users" target="_blank" rel="nofollow">previous Iran-linked fake VPN campaigns</a>, and this one seems to follow the same pattern with better infrastructure.</p><h2 id="how-to-stay-safe-3">How to stay safe</h2><p>Most readers will never be targeted by a state actor, but the underlying lesson travels. </p><p>Install VPN apps only from official stores, and check that the provider has a real, verifiable presence outside the app listing. </p><p>Treat any VPN promoted through an Instagram post, a Telegram channel, or a direct message as suspect, however polished it looks. </p><p>Star ratings are a weak signal, since fake reviews are cheap.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why you can’t buy security on the dark web ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Data leaks and corporate breaches have become routine. In many cases, stolen credentials, <a href="https://www.techradar.com/best/best-database-software">databases</a>, or attack tools eventually appear on the dark web, where they are traded and reused in future attacks.</p><p>This raises a question for <a href="https://www.techradar.com/best/best-small-business-website-builders">businesses</a>: if stolen corporate data ends up on the dark web, does it make sense to engage with this environment directly — by buying information, paying for services, or negotiating with attackers? </p><p>The short answer is no.</p><p>Not because the dark web doesn’t matter — quite the opposite: it is a core part of today’s cybercriminal <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>. The problem is that doing business with the dark web rarely reduces the immediate risks and systematically strengthens the very market that creates threats.</p><h2 id="the-nature-of-the-dark-web">The nature of the dark web</h2><p>The dark web — often used interchangeably with the term darknet — refers to parts of the internet intentionally hidden from search engines and accessible only through tools such as Tor or I2P.</p><p>It is not a single network but a collection of platforms and communities gated by encryption, nonstandard protocols, or restricted access. While some resources are relatively neutral, others are directly tied to criminal activity. From a cybersecurity perspective, the dark web matters primarily as a mature cybercrime marketplace.  </p><p>Technically, many platforms resemble early internet forums. Functionally, however, they operate much like B2B marketplaces — except the products include stolen data, compromised accounts, <a href="https://www.techradar.com/best/best-malware-removal">malware</a>, exploit kits, and attack services.</p><h2 id="the-economics-of-cybercrime">The economics of cybercrime</h2><p>A key function of the dark web is simplifying the monetization of cybercrime. More importantly, it enables specialization and the formation of complex supply chains.  </p><p>Instead of building operations end-to-end, cybercriminals now focus on specific roles: some identify vulnerabilities and gain initial access, others develop and distribute malware, while others specialize in monetization through data sales, extortion, or attacks-for-hire.</p><p>This division of labor has created a full-fledged cybercrime economy. Attackers no longer need advanced expertise or their own infrastructure — they can purchase the necessary tools and services, lowering the barrier to entry and increasing the scale of attacks.</p><p>A clear example is the Ransomware-as-a-Service (RaaS) model, where core groups develop malware and manage negotiations, while affiliates carry out attacks for a share of the ransom. This model has enabled large-scale incidents such as the 2021 Colonial Pipeline attack, which disrupted fuel supplies across the U.S. East Coast and resulted in a $4.4 million payment.</p><h2 id="dark-web-intelligence-and-false-signals">Dark web intelligence and false signals</h2><p>As the dark web evolved into a cybercrime marketplace, businesses naturally became interested in monitoring it for early warning signals.</p><p>In practice, this approach works only partially. The problem with dark web intelligence is that it comes from an environment with virtually no reliable verification mechanisms.</p><p>Like any anonymous and unregulated market, the dark web contains a significant amount of noise, manipulation, and outright fraud. Listings may be outdated, fabricated, or recycled from old leaks, while reputation signals can be artificially inflated. </p><p>The problem becomes even more pronounced when monitoring is outsourced to third-party vendors. Weak or unverifiable signals can easily be exaggerated, misinterpreted, or presented as evidence of major threats.</p><p>As a result, dark web monitoring rarely provides the level of certainty businesses expect. At best, it can highlight a potential issue that still requires verification.</p><h2 id="never-pay-cybercriminals">Never pay cybercriminals</h2><p>Direct engagement with the dark web is even more problematic — whether through ransom payments, purchasing leaked data, or hiring anonymous actors to test infrastructure.</p><p>The most obvious issue is that paying cybercriminals offers no guarantees. Attackers may simply demand another payment or leak the data anyway.</p><p>Uber learned this in 2016 after paying attackers $100,000 following a breach affecting 57 million users, only for the incident to become public later and trigger regulatory fallout.</p><p>A similar pattern appeared in the 2017 breach of HBO, when attackers stole 1.5 TB of Game of Thrones-related data, including unreleased episodes and internal <a href="https://www.techradar.com/best/best-cloud-document-storage">documents</a>. HBO reportedly transferred $250,000, but the material leaked anyway.</p><p>The broader problem, however, is structural: every payment flowing into the dark web economy directly finances its further growth. The more businesses participate in that market, the stronger the incentives for attackers to discover vulnerabilities, compromise systems, and scale operations.</p><h2 id="common-mistakes-when-dealing-with-the-dark-web">Common mistakes when dealing with the dark web</h2><p>When dealing with the dark web, organizations tend to repeat the same mistakes regardless of industry or size.</p><p>Trying to pay their way out of the problem. Companies often approach ransomware or leaks as negotiation problems. In reality, paying a ransom guarantees neither recovery nor safety. According to a 2021 study by Cybereason, 80% of organizations that paid ransoms were attacked again, often by the same groups.</p><p>Treating dark web monitoring as insurance. Monitoring services are often marketed as proactive protection. In reality, if company data appears for sale on the dark web, the compromise has already happened. Monitoring can provide signals, but it cannot replace actual <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> controls.</p><p>Hiring dark web hackers to test infrastructure. Unlike legitimate penetration testing, anonymous dark web “audits” offer no accountability, verification, or compliance guarantees. Even worse, the hired hacker may establish unauthorized access and later resell it.</p><p>Panicking after seeing the company name on the dark web. Many leaks and listings are outdated, recycled, or entirely fabricated. Without proper verification, rushed decisions can worsen the situation.</p><p>Delegating the entire issue to “dark web specialists.” Many companies delegate dark web monitoring to external vendors without the ability to independently assess the quality of the results. This creates a dangerous information asymmetry and increases dependence on unverifiable claims. </p><h2 id="what-businesses-should-do-instead">What businesses should do instead</h2><p>Dark web intelligence can be useful as one additional source of signals, but it requires cautious interpretation and independent validation. Treating it as a reliable source of truth — or outsourcing the entire function without oversight — is risky.</p><p>More importantly, businesses should avoid directly financing criminal ecosystems through payments or participation in underground markets.</p><p>Cyber resilience is built internally. Rather than attempting to “buy security” on the dark web, organizations should invest in systematic defense: resilient architecture, vulnerability <a href="https://www.techradar.com/best/it-management-tools">management</a>, monitoring, incident response, and technologies capable of mitigating attacks while maintaining continuity of critical services.</p><p><em></em><a href="https://www.techradar.com/best/secure-file-transfer-solutions"><em>We've featured the best secure file sharing.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/why-you-cant-buy-security-on-the-dark-web</link>
                                                                            <description>
                            <![CDATA[ Why buying, monitoring, or negotiating on the dark web often creates more risk than security. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wWnRmnUEZueLuNaGnKgaca</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 09:17:43 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Andrey Leskin ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:description>                                                            <media:text><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:text>
                                <media:title type="plain"><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Data leaks and corporate breaches have become routine. In many cases, stolen credentials, <a href="https://www.techradar.com/best/best-database-software">databases</a>, or attack tools eventually appear on the dark web, where they are traded and reused in future attacks.</p><p>This raises a question for <a href="https://www.techradar.com/best/best-small-business-website-builders">businesses</a>: if stolen corporate data ends up on the dark web, does it make sense to engage with this environment directly — by buying information, paying for services, or negotiating with attackers? </p><p>The short answer is no.</p><p>Not because the dark web doesn’t matter — quite the opposite: it is a core part of today’s cybercriminal <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>. The problem is that doing business with the dark web rarely reduces the immediate risks and systematically strengthens the very market that creates threats.</p><h2 id="the-nature-of-the-dark-web">The nature of the dark web</h2><p>The dark web — often used interchangeably with the term darknet — refers to parts of the internet intentionally hidden from search engines and accessible only through tools such as Tor or I2P.</p><p>It is not a single network but a collection of platforms and communities gated by encryption, nonstandard protocols, or restricted access. While some resources are relatively neutral, others are directly tied to criminal activity. From a cybersecurity perspective, the dark web matters primarily as a mature cybercrime marketplace.  </p><p>Technically, many platforms resemble early internet forums. Functionally, however, they operate much like B2B marketplaces — except the products include stolen data, compromised accounts, <a href="https://www.techradar.com/best/best-malware-removal">malware</a>, exploit kits, and attack services.</p><h2 id="the-economics-of-cybercrime">The economics of cybercrime</h2><p>A key function of the dark web is simplifying the monetization of cybercrime. More importantly, it enables specialization and the formation of complex supply chains.  </p><p>Instead of building operations end-to-end, cybercriminals now focus on specific roles: some identify vulnerabilities and gain initial access, others develop and distribute malware, while others specialize in monetization through data sales, extortion, or attacks-for-hire.</p><p>This division of labor has created a full-fledged cybercrime economy. Attackers no longer need advanced expertise or their own infrastructure — they can purchase the necessary tools and services, lowering the barrier to entry and increasing the scale of attacks.</p><p>A clear example is the Ransomware-as-a-Service (RaaS) model, where core groups develop malware and manage negotiations, while affiliates carry out attacks for a share of the ransom. This model has enabled large-scale incidents such as the 2021 Colonial Pipeline attack, which disrupted fuel supplies across the U.S. East Coast and resulted in a $4.4 million payment.</p><h2 id="dark-web-intelligence-and-false-signals">Dark web intelligence and false signals</h2><p>As the dark web evolved into a cybercrime marketplace, businesses naturally became interested in monitoring it for early warning signals.</p><p>In practice, this approach works only partially. The problem with dark web intelligence is that it comes from an environment with virtually no reliable verification mechanisms.</p><p>Like any anonymous and unregulated market, the dark web contains a significant amount of noise, manipulation, and outright fraud. Listings may be outdated, fabricated, or recycled from old leaks, while reputation signals can be artificially inflated. </p><p>The problem becomes even more pronounced when monitoring is outsourced to third-party vendors. Weak or unverifiable signals can easily be exaggerated, misinterpreted, or presented as evidence of major threats.</p><p>As a result, dark web monitoring rarely provides the level of certainty businesses expect. At best, it can highlight a potential issue that still requires verification.</p><h2 id="never-pay-cybercriminals">Never pay cybercriminals</h2><p>Direct engagement with the dark web is even more problematic — whether through ransom payments, purchasing leaked data, or hiring anonymous actors to test infrastructure.</p><p>The most obvious issue is that paying cybercriminals offers no guarantees. Attackers may simply demand another payment or leak the data anyway.</p><p>Uber learned this in 2016 after paying attackers $100,000 following a breach affecting 57 million users, only for the incident to become public later and trigger regulatory fallout.</p><p>A similar pattern appeared in the 2017 breach of HBO, when attackers stole 1.5 TB of Game of Thrones-related data, including unreleased episodes and internal <a href="https://www.techradar.com/best/best-cloud-document-storage">documents</a>. HBO reportedly transferred $250,000, but the material leaked anyway.</p><p>The broader problem, however, is structural: every payment flowing into the dark web economy directly finances its further growth. The more businesses participate in that market, the stronger the incentives for attackers to discover vulnerabilities, compromise systems, and scale operations.</p><h2 id="common-mistakes-when-dealing-with-the-dark-web">Common mistakes when dealing with the dark web</h2><p>When dealing with the dark web, organizations tend to repeat the same mistakes regardless of industry or size.</p><p>Trying to pay their way out of the problem. Companies often approach ransomware or leaks as negotiation problems. In reality, paying a ransom guarantees neither recovery nor safety. According to a 2021 study by Cybereason, 80% of organizations that paid ransoms were attacked again, often by the same groups.</p><p>Treating dark web monitoring as insurance. Monitoring services are often marketed as proactive protection. In reality, if company data appears for sale on the dark web, the compromise has already happened. Monitoring can provide signals, but it cannot replace actual <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> controls.</p><p>Hiring dark web hackers to test infrastructure. Unlike legitimate penetration testing, anonymous dark web “audits” offer no accountability, verification, or compliance guarantees. Even worse, the hired hacker may establish unauthorized access and later resell it.</p><p>Panicking after seeing the company name on the dark web. Many leaks and listings are outdated, recycled, or entirely fabricated. Without proper verification, rushed decisions can worsen the situation.</p><p>Delegating the entire issue to “dark web specialists.” Many companies delegate dark web monitoring to external vendors without the ability to independently assess the quality of the results. This creates a dangerous information asymmetry and increases dependence on unverifiable claims. </p><h2 id="what-businesses-should-do-instead">What businesses should do instead</h2><p>Dark web intelligence can be useful as one additional source of signals, but it requires cautious interpretation and independent validation. Treating it as a reliable source of truth — or outsourcing the entire function without oversight — is risky.</p><p>More importantly, businesses should avoid directly financing criminal ecosystems through payments or participation in underground markets.</p><p>Cyber resilience is built internally. Rather than attempting to “buy security” on the dark web, organizations should invest in systematic defense: resilient architecture, vulnerability <a href="https://www.techradar.com/best/it-management-tools">management</a>, monitoring, incident response, and technologies capable of mitigating attacks while maintaining continuity of critical services.</p><p><em></em><a href="https://www.techradar.com/best/secure-file-transfer-solutions"><em>We've featured the best secure file sharing.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why operational technology risk still slips past the boardroom ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Across the UK, <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> incidents have become a familiar feature of the business landscape. </p><p>Disruptions affecting manufacturing and logistics over the past year have underlined how exposed organizations can be when physical operations are connected and digitalized. </p><p>Despite this growing awareness, boardroom conversations on cyber risk still tend to center on corporate IT and not operational technology (OT).</p><p>That focus leaves a significant gap. Operational technology, the systems that run factories, manage supply chains and underpin essential services, is now a primary target for attackers. When these environments are compromised, the consequences extend far beyond lost <a href="https://www.techradar.com/pro/best-data-removal-services-of-year">data</a>, affecting safety, revenue and in some cases an organization's ability to operate at all.</p><p>For many boards, this is less a question of indifference and more one of framing. Cyber risk is still commonly understood through an IT lens, shaped by experiences  with data breaches or <a href="https://www.techradar.com/best/best-malware-removal">malware</a> attacks that take down websites or enterprise IT systems. Operational disruption behaves differently in both scale and impact, and it demands a different level of governance attention.</p><h2 id="why-ot-risk-is-routinely-underestimated">Why OT risk is routinely underestimated</h2><p>Much of today’s operational <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> was designed long before connectivity and remote access became standard. These systems were engineered for reliability and safety, not for defense against hostile actors. As they have become more connected and digitalized, exposure has increased without always being matched by equivalent <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> practices.</p><p>The result is that many of the most serious business risks now sit within operational environments that boards rarely examine in detail. This creates a structural blind spot. While IT incidents are often measured in hours or days, failures in OT environments can take longer to mitigate while halting production, disrupting critical services and generating losses that compound rapidly over time.</p><p>Boards tend to engage more effectively when risk is grounded in tangible business terms. Understanding what a facility produces in a day, or what a week-long shutdown would mean for customers and partners, brings operational risk into sharper focus. Without that context, OT security can remain abstract and under-prioritized.</p><h2 id="when-cyber-incidents-stop-operations">When cyber incidents stop operations</h2><p>Recent incidents have shown how quickly cybersecurity events can escalate into operational crises. Last year, a leading British automotive brand publicly confirmed a cyber incident that led to a precautionary shutdown of systems. Manufacturing and retail operations were halted for weeks and disruptions rippled through suppliers, logistics partners and dealerships </p><p>Similar lessons can be drawn from cyber incidents affecting the UK’s water sector, where attackers targeted environments connected to the operational systems that control treatment and distribution. Beginning in 2024, multiple incidents reached systems close enough to operational control to raise concerns about safe operation. </p><p>Taken together, these examples point to board-level issues beyond preventing down time or service outages. They are also about maintaining operational continuity, understanding how quickly localized disruptions can cascade across an organization, and factoring in safety concerns and reputational risk. </p><h2 id="a-risk-landscape-shaped-by-geopolitics">A risk landscape shaped by geopolitics</h2><p>Operational technology risk is increasingly shaped by global forces. Geopolitical tension, trade restrictions and supply chain uncertainty now influence how organizations plan and prioritize security investment. </p><p>At the same time, governments are raising expectations around resilience and incident reporting, particularly in sectors linked to national infrastructure. Boards are therefore required to consider regulatory and geopolitical pressures alongside technical risk, adding another layer of complexity to cyber governance.</p><h2 id="bringing-direction-and-discipline-to-governance">Bringing direction and discipline to governance</h2><p>Stronger oversight depends on education and structure. Boards should expect cyber leaders to explain operational risk in clear business terms and to reference recognized best practice. Focusing on a prioritized and manageable set of critical controls that deliver the greatest risk reduction provides a practical foundation without overwhelming the organization.</p><p>Governance cadence is just as important as control selection. Regular, structured engagement with senior management create space to track how security investment supports operational resilience and wider business outcomes. Treating cyber risk as a standing governance issue, rather than an occasional update, reinforces accountability and sustained attention.</p><p>Clear prioritization models can further support decision-making. Categorizing actions into those that must happen now, those that can follow next and those that should not be pursued helps align technical, operational and financial perspectives. A shared language of priority reduces ambiguity and supports more consistent execution across sites.</p><h2 id="a-leadership-obligation">A leadership obligation</h2><p>Operational technology security can no longer be treated as a technical niche. It has become a leadership responsibility shaped by operational dependence, external pressure and increasingly capable adversaries. Boards that recognize this shift are better positioned to protect continuity, revenue and trust.</p><p>Looking ahead, resilient organizations will be led by teams that engage directly with the realities of their industrial environments. Asking sharper questions, demanding clearer insight and ensuring governance structures keep pace with operational risk remain among the most effective safeguards leaders can provide.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>We've ranked and reviewed the best antivirus software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/why-operational-technology-risk-still-slips-past-the-boardroom</link>
                                                                            <description>
                            <![CDATA[ Boards need to start treating OT cyber risk as an issue of business continuity. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">EcvSXqhDCyZJkkoKy33aYY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 09:04:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Louise Bulman ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg">
                                                            <media:credit><![CDATA[sarayut Thaneerat/ via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:description>                                                            <media:text><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:text>
                                <media:title type="plain"><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Across the UK, <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> incidents have become a familiar feature of the business landscape. </p><p>Disruptions affecting manufacturing and logistics over the past year have underlined how exposed organizations can be when physical operations are connected and digitalized. </p><p>Despite this growing awareness, boardroom conversations on cyber risk still tend to center on corporate IT and not operational technology (OT).</p><p>That focus leaves a significant gap. Operational technology, the systems that run factories, manage supply chains and underpin essential services, is now a primary target for attackers. When these environments are compromised, the consequences extend far beyond lost <a href="https://www.techradar.com/pro/best-data-removal-services-of-year">data</a>, affecting safety, revenue and in some cases an organization's ability to operate at all.</p><p>For many boards, this is less a question of indifference and more one of framing. Cyber risk is still commonly understood through an IT lens, shaped by experiences  with data breaches or <a href="https://www.techradar.com/best/best-malware-removal">malware</a> attacks that take down websites or enterprise IT systems. Operational disruption behaves differently in both scale and impact, and it demands a different level of governance attention.</p><h2 id="why-ot-risk-is-routinely-underestimated">Why OT risk is routinely underestimated</h2><p>Much of today’s operational <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> was designed long before connectivity and remote access became standard. These systems were engineered for reliability and safety, not for defense against hostile actors. As they have become more connected and digitalized, exposure has increased without always being matched by equivalent <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> practices.</p><p>The result is that many of the most serious business risks now sit within operational environments that boards rarely examine in detail. This creates a structural blind spot. While IT incidents are often measured in hours or days, failures in OT environments can take longer to mitigate while halting production, disrupting critical services and generating losses that compound rapidly over time.</p><p>Boards tend to engage more effectively when risk is grounded in tangible business terms. Understanding what a facility produces in a day, or what a week-long shutdown would mean for customers and partners, brings operational risk into sharper focus. Without that context, OT security can remain abstract and under-prioritized.</p><h2 id="when-cyber-incidents-stop-operations">When cyber incidents stop operations</h2><p>Recent incidents have shown how quickly cybersecurity events can escalate into operational crises. Last year, a leading British automotive brand publicly confirmed a cyber incident that led to a precautionary shutdown of systems. Manufacturing and retail operations were halted for weeks and disruptions rippled through suppliers, logistics partners and dealerships </p><p>Similar lessons can be drawn from cyber incidents affecting the UK’s water sector, where attackers targeted environments connected to the operational systems that control treatment and distribution. Beginning in 2024, multiple incidents reached systems close enough to operational control to raise concerns about safe operation. </p><p>Taken together, these examples point to board-level issues beyond preventing down time or service outages. They are also about maintaining operational continuity, understanding how quickly localized disruptions can cascade across an organization, and factoring in safety concerns and reputational risk. </p><h2 id="a-risk-landscape-shaped-by-geopolitics">A risk landscape shaped by geopolitics</h2><p>Operational technology risk is increasingly shaped by global forces. Geopolitical tension, trade restrictions and supply chain uncertainty now influence how organizations plan and prioritize security investment. </p><p>At the same time, governments are raising expectations around resilience and incident reporting, particularly in sectors linked to national infrastructure. Boards are therefore required to consider regulatory and geopolitical pressures alongside technical risk, adding another layer of complexity to cyber governance.</p><h2 id="bringing-direction-and-discipline-to-governance">Bringing direction and discipline to governance</h2><p>Stronger oversight depends on education and structure. Boards should expect cyber leaders to explain operational risk in clear business terms and to reference recognized best practice. Focusing on a prioritized and manageable set of critical controls that deliver the greatest risk reduction provides a practical foundation without overwhelming the organization.</p><p>Governance cadence is just as important as control selection. Regular, structured engagement with senior management create space to track how security investment supports operational resilience and wider business outcomes. Treating cyber risk as a standing governance issue, rather than an occasional update, reinforces accountability and sustained attention.</p><p>Clear prioritization models can further support decision-making. Categorizing actions into those that must happen now, those that can follow next and those that should not be pursued helps align technical, operational and financial perspectives. A shared language of priority reduces ambiguity and supports more consistent execution across sites.</p><h2 id="a-leadership-obligation">A leadership obligation</h2><p>Operational technology security can no longer be treated as a technical niche. It has become a leadership responsibility shaped by operational dependence, external pressure and increasingly capable adversaries. Boards that recognize this shift are better positioned to protect continuity, revenue and trust.</p><p>Looking ahead, resilient organizations will be led by teams that engage directly with the realities of their industrial environments. Asking sharper questions, demanding clearer insight and ensuring governance structures keep pace with operational risk remain among the most effective safeguards leaders can provide.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>We've ranked and reviewed the best antivirus software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Watch out - that Microsoft Calendar invite dated 2050 could be hiding stolen files and worse ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Group‑IB discovers HollowGraph malware targeting Israeli entities, exfiltrating files via Microsoft Graph API</strong></li><li><strong>Operators hide instructions in future calendar entries, then attach encrypted stolen data to events</strong></li><li><strong>At least 12 systems were compromised; overlaps with Lyceum noted but attribution remains low‑confidence</strong></li></ul><p>Cybercriminals have found a way to communicate with the malware installed on victim devices through compromised Microsoft Calendar apps, experts have warned.</p><p>Security researchers at Group-IB have <a href="https://www.group-ib.com/blog/hollowgraph-microsoft-365/" target="_blank" rel="nofollow">detailed</a> a newly discovered piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> called HollowGraph designed to exfiltrate sensitive files from compromised devices.</p><p>What makes the malware stand out is the way it communicates with its operators. The best way to spot hidden malware is to monitor the traffic flowing in and out of a device, which is why cybercriminals try their best to hide this traffic, or blend it with another, legitimate one. In that respect, HollowGraph is unique because it abuses Microsoft Graph API and a compromised Microsoft 365 mailbox calendar.</p><h2 id="a-dozen-victims">A dozen victims</h2><p>After landing on a device and compromising the Microsoft 365 account, HollowGraph uses that account’s permissions to access Microsoft Graph. Operators create calendar entries containing instructions and place them far into the future (in the year 2050) to avoid being spotted. After acting on the instructions and harvesting valuable information, the malware exfiltrates it through the same channel.</p><p>Instead of uploading files to a suspicious server, HollowGraph attaches encrypted stolen data to calendar events and sends it through Microsoft Graph. For defenders, all of this traffic seems legitimate and usually flies under their radars. </p><p>So far, all of the victims are Israeli entities, Group-IB said. The researchers identified at least 12 compromised systems, three of which were still actively communicating with the attackers’ infrastructure during the investigation.</p><p>The researchers did not attribute the attack to any known threat actor, but hinted at a potential. They identified technical similarities in command structures and plugin mechanisms between HollowGraph’s framework, Cavern, and a .NET backdoor used by Lyceum (an Iranian-nexus threat actor associated with OilRig). However, Group-IB explicitly emphasizes that these overlaps are not distinct enough, so they assess this link with low confidence.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/watch-out-that-microsoft-calendar-invite-dated-2050-could-be-hiding-stolen-files-and-worse</link>
                                                                            <description>
                            <![CDATA[ Check your calendars for entries far into the future - especially if you're an Israeli entity. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LjgKxK7hkjXzxZoDby7Pxa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NK6WMQwJZAmbq9SfRREf2f-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jul 2026 16:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NK6WMQwJZAmbq9SfRREf2f-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images / Westend61]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Top view of woman holding smartphone and tablet with calendar on desk]]></media:description>                                                            <media:text><![CDATA[Top view of woman holding smartphone and tablet with calendar on desk]]></media:text>
                                <media:title type="plain"><![CDATA[Top view of woman holding smartphone and tablet with calendar on desk]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NK6WMQwJZAmbq9SfRREf2f-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Group‑IB discovers HollowGraph malware targeting Israeli entities, exfiltrating files via Microsoft Graph API</strong></li><li><strong>Operators hide instructions in future calendar entries, then attach encrypted stolen data to events</strong></li><li><strong>At least 12 systems were compromised; overlaps with Lyceum noted but attribution remains low‑confidence</strong></li></ul><p>Cybercriminals have found a way to communicate with the malware installed on victim devices through compromised Microsoft Calendar apps, experts have warned.</p><p>Security researchers at Group-IB have <a href="https://www.group-ib.com/blog/hollowgraph-microsoft-365/" target="_blank" rel="nofollow">detailed</a> a newly discovered piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> called HollowGraph designed to exfiltrate sensitive files from compromised devices.</p><p>What makes the malware stand out is the way it communicates with its operators. The best way to spot hidden malware is to monitor the traffic flowing in and out of a device, which is why cybercriminals try their best to hide this traffic, or blend it with another, legitimate one. In that respect, HollowGraph is unique because it abuses Microsoft Graph API and a compromised Microsoft 365 mailbox calendar.</p><h2 id="a-dozen-victims">A dozen victims</h2><p>After landing on a device and compromising the Microsoft 365 account, HollowGraph uses that account’s permissions to access Microsoft Graph. Operators create calendar entries containing instructions and place them far into the future (in the year 2050) to avoid being spotted. After acting on the instructions and harvesting valuable information, the malware exfiltrates it through the same channel.</p><p>Instead of uploading files to a suspicious server, HollowGraph attaches encrypted stolen data to calendar events and sends it through Microsoft Graph. For defenders, all of this traffic seems legitimate and usually flies under their radars. </p><p>So far, all of the victims are Israeli entities, Group-IB said. The researchers identified at least 12 compromised systems, three of which were still actively communicating with the attackers’ infrastructure during the investigation.</p><p>The researchers did not attribute the attack to any known threat actor, but hinted at a potential. They identified technical similarities in command structures and plugin mechanisms between HollowGraph’s framework, Cavern, and a .NET backdoor used by Lyceum (an Iranian-nexus threat actor associated with OilRig). However, Group-IB explicitly emphasizes that these overlaps are not distinct enough, so they assess this link with low confidence.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'macOS users may face real, sophisticated threats that require neither exploits nor any elevated access to succeed': ClickLock Stealer tries to trick Apple users into revealing their passwords ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Group‑IB uncovers ClickLock, a new macOS‑focused infostealer using aggressive social engineering by spamming password prompts and terminating key apps every 210ms until victims comply</strong></li><li><strong>Once credentials are obtained, it exfiltrates browser data, crypto wallets, password manager entries, FTP configs, and device info via Telegram Bot API</strong></li><li><strong>Active since May 2026, spotted in 33 countries (mostly Europe), distributed via ClickFix campaigns, and initially undetected by security vendors until recently</strong></li></ul><p>Security researchers from Group-IB have uncovered a new infostealer targeting primarily macOS users in Europe.</p><p>Dubbed <a href="https://www.group-ib.com/blog/clicklock-stealer-macos-malware/" target="_blank">ClickLock</a>, it is more of an annoying social engineering mechanism rather than a full-blown malware variant, constantly popping up a login prompt on the victim’s device, until they finally comply and share the credentials. </p><p>Every 210 milliseconds it terminates key apps on the device (Finder, Dock, TErminal, etc.), essentially making it useless. At the same time, it keeps prompting a password dialog on the screen, making sure the victim can do nothing but provide the credentials.</p><h2 id="targeting-europeans">Targeting Europeans</h2><p>The loop is set to continue for more than three straight days, or until the victim folds. </p><p>After getting the keys to the kingdom, the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> gets to work and starts exfiltrating valuable information.</p><p>This includes data from key <a href="https://www.techradar.com/best/browser" target="_blank">browsers</a> (Chrome, Firefox, Brave, and others), saved logins, cookies, autofill data, and other browser information, data linked to cryptocurrency wallets and extensions, encrypted wallet vault material that can be cracked off-site, data from <a href="https://www.techradar.com/best/password-manager" target="_blank">password managers</a>, cached cryptocurrency addresses across EVM, Bitcoin, Solana, TRON, TON, and Stacks, shell histories, FileZilla FTP configuration and recent-server data, and basic device information.Everything is then packaged into a .ZIP archive and exfiltrated via a Telegram Bot API.</p><p>Group-IB says the campaign has been active since at least May 2026, so it’s been active for a few months now. A researcher submitted a variant to VirusTotal in early June, but it remained undetected by all security vendors until recently, Group-IB says.</p><p>So far, it has been spotted in 33 countries, more than half of which are in Europe, it was also added. The malware is most likely being distributed via a ClickFix social engineering campaign, and has not been tied to any particular threat actor. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/macos-users-may-face-real-sophisticated-threats-that-require-neither-exploits-nor-any-elevated-access-to-succeed-clicklock-stealer-tries-to-trick-apple-users-into-revealing-their-passwords</link>
                                                                            <description>
                            <![CDATA[ ClickLock bores its victims into complying and then steals all sorts of data. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rTfuMcJQcWwgFKNJxEtbqi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[hacker hands at work with  interface around]]></media:description>                                                            <media:text><![CDATA[hacker hands at work with  interface around]]></media:text>
                                <media:title type="plain"><![CDATA[hacker hands at work with  interface around]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Group‑IB uncovers ClickLock, a new macOS‑focused infostealer using aggressive social engineering by spamming password prompts and terminating key apps every 210ms until victims comply</strong></li><li><strong>Once credentials are obtained, it exfiltrates browser data, crypto wallets, password manager entries, FTP configs, and device info via Telegram Bot API</strong></li><li><strong>Active since May 2026, spotted in 33 countries (mostly Europe), distributed via ClickFix campaigns, and initially undetected by security vendors until recently</strong></li></ul><p>Security researchers from Group-IB have uncovered a new infostealer targeting primarily macOS users in Europe.</p><p>Dubbed <a href="https://www.group-ib.com/blog/clicklock-stealer-macos-malware/" target="_blank">ClickLock</a>, it is more of an annoying social engineering mechanism rather than a full-blown malware variant, constantly popping up a login prompt on the victim’s device, until they finally comply and share the credentials. </p><p>Every 210 milliseconds it terminates key apps on the device (Finder, Dock, TErminal, etc.), essentially making it useless. At the same time, it keeps prompting a password dialog on the screen, making sure the victim can do nothing but provide the credentials.</p><h2 id="targeting-europeans">Targeting Europeans</h2><p>The loop is set to continue for more than three straight days, or until the victim folds. </p><p>After getting the keys to the kingdom, the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> gets to work and starts exfiltrating valuable information.</p><p>This includes data from key <a href="https://www.techradar.com/best/browser" target="_blank">browsers</a> (Chrome, Firefox, Brave, and others), saved logins, cookies, autofill data, and other browser information, data linked to cryptocurrency wallets and extensions, encrypted wallet vault material that can be cracked off-site, data from <a href="https://www.techradar.com/best/password-manager" target="_blank">password managers</a>, cached cryptocurrency addresses across EVM, Bitcoin, Solana, TRON, TON, and Stacks, shell histories, FileZilla FTP configuration and recent-server data, and basic device information.Everything is then packaged into a .ZIP archive and exfiltrated via a Telegram Bot API.</p><p>Group-IB says the campaign has been active since at least May 2026, so it’s been active for a few months now. A researcher submitted a variant to VirusTotal in early June, but it remained undetected by all security vendors until recently, Group-IB says.</p><p>So far, it has been spotted in 33 countries, more than half of which are in Europe, it was also added. The malware is most likely being distributed via a ClickFix social engineering campaign, and has not been tied to any particular threat actor. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Russian hacker turns Gemini CLI into a hacking agent, creates small-scale botnet ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Russian hacker “bandcampro” used Google’s Gemini CLI to control an eight‑device botnet at a dental clinic</strong></li><li><strong>The attacker tricked the AI by posing as a pen tester, directing it to migrate C2 infrastructure, troubleshoot connectivity, and prepare payload bundles</strong></li><li><strong>The AI assisted with daily operations like password guessing and WordPress access, highlighting risks of misuse when threat actors co‑opt AI tools</strong></li></ul><p>A Russian hacker and his AI companion were able to successfully control a miniature, eight-system botnet, with the hacker giving instructions in conversational language, and the AI doing his bidding, experts have found.</p><p>Analyzing 200 session logs obtained from the Russian-speaking threat actor known as “bandcampro”, cybersecurity researchers Trend Micro saw the hacker use Google’s Gemini CLI, an open source AI command-line tool that lets developers interact with Google's <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">Gemini AI</a> models directly from a terminal. </p><p>Scouring through a month’s worth of session logs (between April 21 and May 19 2026), the researchers discovered that the attacker tricked the AI by telling it they were an “authorized pen tester”. While the AI mostly complied with their nefarious overlord, they refused the orders on at least one occasion.</p><h2 id="gone-in-six-minutes">Gone in six minutes</h2><p>Trend Micro found the hacker controlled eight devices belonging to a dental clinic and sought to access their access their OpenDental database.</p><p>Using the AI, bandcampro did a number of things, starting with migrating the botnet to a new C2 infrastructure. He gave the AI a skill file with the full architecture description, standard operating procedures, infection one-liner, persistence commands, and troubleshooting steps.</p><p>He then told it to “study the C2 migration”, which had the AI process the guide and prepare all the code and necessary steps. It took the tool around six minutes to get the job done. </p><p>"The AI read the migration guide, then prepared a migration bundle, a small archive of server code, payloads, and the skill file. It then unpacked the bundle, launched the C&C server on a VPS, and brought up the Cloudflare tunnel," Trend Micro says.</p><p>Bandcampro then used the AI to troubleshoot connectivity issues, as well as for various daily operations, such as guessing passwords, generating plausible variants of existing passwords for WordPress portals, and more.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/google-gemini-cli-abused-as-a-hacking-agent-malware-botnet-operator/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/russian-hacker-turns-gemini-cli-into-a-hacking-agent-creates-small-scale-botnet</link>
                                                                            <description>
                            <![CDATA[ The hacker told the AI he was an authorized pentester - and the AI believed him. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2aLD452X3VLZeF4n8MnsB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PRCsQfoXPXi2t4jsGwWr6L-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jul 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PRCsQfoXPXi2t4jsGwWr6L-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A human shakes a robot&#039;s hand in front of blue concentric circles]]></media:description>                                                            <media:text><![CDATA[A human shakes a robot&#039;s hand in front of blue concentric circles]]></media:text>
                                <media:title type="plain"><![CDATA[A human shakes a robot&#039;s hand in front of blue concentric circles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PRCsQfoXPXi2t4jsGwWr6L-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Russian hacker “bandcampro” used Google’s Gemini CLI to control an eight‑device botnet at a dental clinic</strong></li><li><strong>The attacker tricked the AI by posing as a pen tester, directing it to migrate C2 infrastructure, troubleshoot connectivity, and prepare payload bundles</strong></li><li><strong>The AI assisted with daily operations like password guessing and WordPress access, highlighting risks of misuse when threat actors co‑opt AI tools</strong></li></ul><p>A Russian hacker and his AI companion were able to successfully control a miniature, eight-system botnet, with the hacker giving instructions in conversational language, and the AI doing his bidding, experts have found.</p><p>Analyzing 200 session logs obtained from the Russian-speaking threat actor known as “bandcampro”, cybersecurity researchers Trend Micro saw the hacker use Google’s Gemini CLI, an open source AI command-line tool that lets developers interact with Google's <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">Gemini AI</a> models directly from a terminal. </p><p>Scouring through a month’s worth of session logs (between April 21 and May 19 2026), the researchers discovered that the attacker tricked the AI by telling it they were an “authorized pen tester”. While the AI mostly complied with their nefarious overlord, they refused the orders on at least one occasion.</p><h2 id="gone-in-six-minutes">Gone in six minutes</h2><p>Trend Micro found the hacker controlled eight devices belonging to a dental clinic and sought to access their access their OpenDental database.</p><p>Using the AI, bandcampro did a number of things, starting with migrating the botnet to a new C2 infrastructure. He gave the AI a skill file with the full architecture description, standard operating procedures, infection one-liner, persistence commands, and troubleshooting steps.</p><p>He then told it to “study the C2 migration”, which had the AI process the guide and prepare all the code and necessary steps. It took the tool around six minutes to get the job done. </p><p>"The AI read the migration guide, then prepared a migration bundle, a small archive of server code, payloads, and the skill file. It then unpacked the bundle, launched the C&C server on a VPS, and brought up the Cloudflare tunnel," Trend Micro says.</p><p>Bandcampro then used the AI to troubleshoot connectivity issues, as well as for various daily operations, such as guessing passwords, generating plausible variants of existing passwords for WordPress portals, and more.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/google-gemini-cli-abused-as-a-hacking-agent-malware-botnet-operator/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hundreds of GitHub repos found posing as real software to push malware ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>ArcticWolf uncovered 292 malicious GitHub repositories spoofing legitimate tools and products, delivering a new BoryptGrab infostealer variant</strong></li><li><strong>Malware steals from 19 browsers, 32 crypto wallets, messaging apps, Steam, and Windows Credential Manager, and uniquely bypasses Chrome’s App‑Bound Encryption via code injection</strong></li><li><strong>Most repos have been removed, but some remain active; GitHub’s popularity makes it a prime target, underscoring the need to vet code before use</strong></li></ul><p>Russian actors have reportedly created hundreds of malicious GitHub repositories masquerading as legitimate software but acting as a dangerous infostealer. </p><p>Cybersecurity researchers ArcticWolf discovered the campaign after finding their own products spoofed as part of the attack.</p><p>In total, the researchers found 292 fake repositories, spoofing things like security products, developer tools, macOS utilities, games, and more. Each repository contained a README file with the download URL.</p><h2 id="obviously-malicious">Obviously malicious</h2><p>Victims who download the program get a variant of the BoryptGrab infostealer family that grabs data from 19 browsers (<a href="https://www.techradar.com/best/password-manager" target="_blank">passwords</a>, cookies, payment information), 32 cryptocurrency wallets, Telegram, Discord, and Steam sessions, credentials for Meta’s Max, data from Windows Credential Manager, and more. It can also exfiltrate files from Desktop and Documents, and grab screenshots.</p><p>While most of the features can be found in other BoryptGrab variants, this one is unique in a sense that it can bypass Chrome’s App-Bound Encryption through direct code injection into the browser process.</p><p>While it hasn’t been specifically said that the threat actors are Russian, the compressed data is later sent to a Russia-based command-and-control (C2) infrastructure.</p><p>What’s also worth mentioning is that the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> is not designed to last. It has no anti-analysis layer, and doesn’t even try to hide itself in any specific manner. It does not establish persistence and simply tries to grab as much sensitive data as it can on the first attempt.</p><p>The attack, which seems to have started in the final days of June, is almost thwarted now, since most of the malicious repositories have been removed from GitHub. Citing “researchers”, <a href="https://www.bleepingcomputer.com/news/security/nearly-300-github-repos-pose-as-legit-software-to-push-malware/" target="_blank"><em>BleepingComputer</em></a> reported that several dozen still remain active, though. </p><p>Because of its importance and popularity in the open-source community, GitHub is currently one of the most targeted platforms on the internet, which is why it’s important to double-check and vet every piece of code before it’s applied to a project.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/hundreds-of-github-repos-found-posing-as-real-software-to-push-malware</link>
                                                                            <description>
                            <![CDATA[ Russian hackers are trying to sneak infostealers onto people's devices to grab passwords, crypto, and more. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dxoB3qPWwHz8vExitx7Zed</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jul 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phone malware]]></media:description>                                                            <media:text><![CDATA[Phone malware]]></media:text>
                                <media:title type="plain"><![CDATA[Phone malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>ArcticWolf uncovered 292 malicious GitHub repositories spoofing legitimate tools and products, delivering a new BoryptGrab infostealer variant</strong></li><li><strong>Malware steals from 19 browsers, 32 crypto wallets, messaging apps, Steam, and Windows Credential Manager, and uniquely bypasses Chrome’s App‑Bound Encryption via code injection</strong></li><li><strong>Most repos have been removed, but some remain active; GitHub’s popularity makes it a prime target, underscoring the need to vet code before use</strong></li></ul><p>Russian actors have reportedly created hundreds of malicious GitHub repositories masquerading as legitimate software but acting as a dangerous infostealer. </p><p>Cybersecurity researchers ArcticWolf discovered the campaign after finding their own products spoofed as part of the attack.</p><p>In total, the researchers found 292 fake repositories, spoofing things like security products, developer tools, macOS utilities, games, and more. Each repository contained a README file with the download URL.</p><h2 id="obviously-malicious">Obviously malicious</h2><p>Victims who download the program get a variant of the BoryptGrab infostealer family that grabs data from 19 browsers (<a href="https://www.techradar.com/best/password-manager" target="_blank">passwords</a>, cookies, payment information), 32 cryptocurrency wallets, Telegram, Discord, and Steam sessions, credentials for Meta’s Max, data from Windows Credential Manager, and more. It can also exfiltrate files from Desktop and Documents, and grab screenshots.</p><p>While most of the features can be found in other BoryptGrab variants, this one is unique in a sense that it can bypass Chrome’s App-Bound Encryption through direct code injection into the browser process.</p><p>While it hasn’t been specifically said that the threat actors are Russian, the compressed data is later sent to a Russia-based command-and-control (C2) infrastructure.</p><p>What’s also worth mentioning is that the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> is not designed to last. It has no anti-analysis layer, and doesn’t even try to hide itself in any specific manner. It does not establish persistence and simply tries to grab as much sensitive data as it can on the first attempt.</p><p>The attack, which seems to have started in the final days of June, is almost thwarted now, since most of the malicious repositories have been removed from GitHub. Citing “researchers”, <a href="https://www.bleepingcomputer.com/news/security/nearly-300-github-repos-pose-as-legit-software-to-push-malware/" target="_blank"><em>BleepingComputer</em></a> reported that several dozen still remain active, though. </p><p>Because of its importance and popularity in the open-source community, GitHub is currently one of the most targeted platforms on the internet, which is why it’s important to double-check and vet every piece of code before it’s applied to a project.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How parked domains became a cybercrime goldmine ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Every day, millions of people type a web address into their browser, usually in a flurry of rapid keystrokes, and arrive exactly where they intended. </p><p>However, a small but significant number of people don’t. </p><p>They might miss a letter, type an extra letter in their haste, or get some letters mixed up. Instead of hitting linkedin[.]com, they hit linkdein[.]com. Those mistakes gave way to one of the internet’s least glamorous destinations – the parked domain.   </p><p>Most internet users have encountered them at some point, even if they didn't know what they were looking at. Typically, a parked domain would just be a sparse, messy page filled with adverts and a search bar with very little else. </p><p>They existed because someone, somewhere, recognized that in the early days of the internet a percentage of users would inevitably mistype a popular website – so they registered the most similar-looking <a href="https://www.techradar.com/news/best-domain-registrars">domain names</a> for themselves in a move known as “typosquatting” and earned advertising revenue from the resulting traffic. </p><p>If just 0.1% of the millions of people accessing amazon[.]com accidentally went to the amazn[.]com domain they’d bought, that’s still a worthwhile payday. It was a mundane corner of the digital economy, built on convenience, coincidence, and the occasional typo.</p><p>History can be a harsh teacher, but it can also sow complacency. In 2026, a lot of security teams still regard parked domains as little more than lazy digital billboards – inconvenient and annoying, but not a meaningful security concern. </p><p>However, the <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> surrounding parked domains has evolved considerably from the amateurish, pop-up-ridden advertising pages of the early internet. What was once a simple case of opportunistic domain monetization now sits inside a far more complex ecosystem of advertisers, brokers, and traffic distribution networks. </p><p>In many cases, a user's accidental visit no longer ends on a parked page at all. Instead, it triggers a journey through a chain of intermediaries operating largely out of sight. Somewhere along that journey, legitimate advertising can give way to fraud, scams, and <a href="https://www.techradar.com/best/best-malware-removal">malware</a> distribution. </p><p>In other words, one of the web's most familiar and overlooked mechanisms has become one of the most lucrative and insidious vehicles for cybercrime. </p><h2 id="from-mistype-to-malware">From Mistype to Malware </h2><p>The transformation of parked domains from digital curiosities into <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> risks has been subtle, and that’s one of the reasons it’s so dangerous. For decades, the model followed the same patterns – a user would land on a parked domain, see a collection of banners, click on something accidental or otherwise, and generate a small amount of revenue for the domain owner. </p><p>It was cynical, but at least it was transparent because users could at least see where they had ended up and decide for themselves what to do next – usually just close the tab and go where they meant to. The only real danger here came from the occasional misleading or malicious ad rather than the mechanics of the domain itself. </p><p>Today things are different. Changes within the online advertising industry, including tighter policies around traditional domain monetization, have encouraged cybercriminals and fraudsters to try new approaches to keep the train of monetization moving. </p><p>Increasingly, users who arrive at a parked domain don't encounter a parked page at all. Instead, they’re immediately redirected elsewhere through a process known as “zero-click advertising”, sometimes referred to as direct search. </p><p>What appears to be a simple typo can trigger a rapid auction in which a user's visit is bought, sold, and passed between multiple advertising partners before they ever see a destination website. Most of this activity unfolds in fractions of a second and entirely beyond the user's view, and while many of those transactions remain legitimate, the sheer complexity of the ecosystem creates opportunities for abuse. </p><p>Somewhere within that chain, traffic can be acquired by actors whose interests extend far beyond advertising revenue, opening the door to scams, malware, fraudulent software, and a host of other malicious outcomes. </p><h2 id="the-malvertising-economy">The Malvertising Economy</h2><p>One of the reasons parked domain abuse is still underestimated and difficult to pin down is that the attack path rarely follows a straight line. When most people imagine a cyberattack, they picture a malicious website waiting at the end of a link, ready to ensnare an unsuspecting user. </p><p>But in this case, by the time a user reaches the content they're ultimately shown, their traffic may have already passed through a maze of advertising exchanges, brokers, redirectors, and cloaking services. </p><p>Each participant sees only a fragment of the overall journey, making it remarkably difficult for the “good guys” to determine which “bad guys” are responsible for what. It’s a little like trying to investigate a crime scene where the evidence constantly rearranges itself.</p><p>The cowardly threat actors involved in this type of cybercrime exploit this ambiguity. They use sophisticated cloaking techniques which allow them to examine visitors before deciding which content to serve up – where are they based? What kind of browser are they using? What operating system is their device running? </p><p>A <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> researcher in California might see a harmless landing page, while a finance broker in London might be served up a credential harvesting scam. This selective delivery makes malicious activity harder to detect and even harder to reproduce. </p><p>What’s worse, parked domain abuse is rarely aimed at a specific industry or organization. The actors deploying parked domains are usually financially motivated, and their primary interest is in acquiring traffic, so they’re not going to discriminate. </p><p>Once they’ve ensnared a victim, they become a commodity moving through an invisible marketplace where every click has value and every redirection creates another opportunity for exploitation.</p><h2 id="the-blind-spot-in-traditional-security">The blind spot in traditional security</h2><p>So where does all of this leave defenders? Parked domain abuse doesn’t behave like a conventional cyber threat. While security teams are used to investigating suspicious websites, malicious files, or compromised accounts that leave a relatively obvious trail, parked domain campaigns are different because the underlying traffic distribution is constantly changing. </p><p>The same typo domain can send one user down an entirely different path than the next. By the time an analyst attempts to recreate what a victim experienced, the route may no longer exist and any “evidence” has effectively evaporated. How do they defend against something they can't see or recreate?</p><p>One thing is guaranteed – regardless of how many redirects, intermediaries, cloaking systems, or advertising platforms sit between the initial typo and the final destination, every step in the journey depends on the <a href="https://www.techradar.com/news/best-dns-server">domain name system (DNS)</a>. Often described as the internet's address book, DNS is responsible for translating domain names into the destinations users ultimately reach. </p><p>Put simply, each lookup leaves behind a breadcrumb that helps reveal relationships that would otherwise remain hidden, and that visibility has allowed researchers investigating typosquatted versions of well-known domains to follow the trail beyond the initial deception. Patterns start to emerge between seemingly unrelated cases of malware, involving the same parking providers, cloaking services, and traffic distribution infrastructure. </p><p>By examining historical DNS records and mapping the relationships between domains over time, it has become possible to connect incidents that appear to be unrelated and expose the networks operating behind them. Instead of playing “whack a mole” and chasing surface level domains, DNS mapping has allowed defenders to target the entire machine. </p><p>The greatest danger posed by parked domains isn't the typo itself, but the assumption that the infrastructure behind that typo is benign. For years, parked domains occupied a strange corner of the internet, largely ignored by security teams and rarely considered worthy of serious scrutiny. </p><p>But today, they offer cybercriminals something far more valuable than advertising revenue – access to legitimate systems, trusted business models, and vast streams of user traffic that can be manipulated and monetized at scale. </p><p>As threat actors continue to refine their use of cloaking, traffic distribution, and advertising networks, the distinction between legitimate online activity and malicious activity will become increasingly difficult to spot from the outside.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>Protect yourself against malware with the best antivirus software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/how-parked-domains-became-a-cybercrime-goldmine</link>
                                                                            <description>
                            <![CDATA[ Forgotten by security teams, parked domains have quietly become cybercrime's most lucrative hiding place. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TMRpjDCenLo2Y8LXXvpcxE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jul 2026 13:37:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dr. Renée Burton ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phone malware]]></media:description>                                                            <media:text><![CDATA[Phone malware]]></media:text>
                                <media:title type="plain"><![CDATA[Phone malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Every day, millions of people type a web address into their browser, usually in a flurry of rapid keystrokes, and arrive exactly where they intended. </p><p>However, a small but significant number of people don’t. </p><p>They might miss a letter, type an extra letter in their haste, or get some letters mixed up. Instead of hitting linkedin[.]com, they hit linkdein[.]com. Those mistakes gave way to one of the internet’s least glamorous destinations – the parked domain.   </p><p>Most internet users have encountered them at some point, even if they didn't know what they were looking at. Typically, a parked domain would just be a sparse, messy page filled with adverts and a search bar with very little else. </p><p>They existed because someone, somewhere, recognized that in the early days of the internet a percentage of users would inevitably mistype a popular website – so they registered the most similar-looking <a href="https://www.techradar.com/news/best-domain-registrars">domain names</a> for themselves in a move known as “typosquatting” and earned advertising revenue from the resulting traffic. </p><p>If just 0.1% of the millions of people accessing amazon[.]com accidentally went to the amazn[.]com domain they’d bought, that’s still a worthwhile payday. It was a mundane corner of the digital economy, built on convenience, coincidence, and the occasional typo.</p><p>History can be a harsh teacher, but it can also sow complacency. In 2026, a lot of security teams still regard parked domains as little more than lazy digital billboards – inconvenient and annoying, but not a meaningful security concern. </p><p>However, the <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> surrounding parked domains has evolved considerably from the amateurish, pop-up-ridden advertising pages of the early internet. What was once a simple case of opportunistic domain monetization now sits inside a far more complex ecosystem of advertisers, brokers, and traffic distribution networks. </p><p>In many cases, a user's accidental visit no longer ends on a parked page at all. Instead, it triggers a journey through a chain of intermediaries operating largely out of sight. Somewhere along that journey, legitimate advertising can give way to fraud, scams, and <a href="https://www.techradar.com/best/best-malware-removal">malware</a> distribution. </p><p>In other words, one of the web's most familiar and overlooked mechanisms has become one of the most lucrative and insidious vehicles for cybercrime. </p><h2 id="from-mistype-to-malware">From Mistype to Malware </h2><p>The transformation of parked domains from digital curiosities into <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> risks has been subtle, and that’s one of the reasons it’s so dangerous. For decades, the model followed the same patterns – a user would land on a parked domain, see a collection of banners, click on something accidental or otherwise, and generate a small amount of revenue for the domain owner. </p><p>It was cynical, but at least it was transparent because users could at least see where they had ended up and decide for themselves what to do next – usually just close the tab and go where they meant to. The only real danger here came from the occasional misleading or malicious ad rather than the mechanics of the domain itself. </p><p>Today things are different. Changes within the online advertising industry, including tighter policies around traditional domain monetization, have encouraged cybercriminals and fraudsters to try new approaches to keep the train of monetization moving. </p><p>Increasingly, users who arrive at a parked domain don't encounter a parked page at all. Instead, they’re immediately redirected elsewhere through a process known as “zero-click advertising”, sometimes referred to as direct search. </p><p>What appears to be a simple typo can trigger a rapid auction in which a user's visit is bought, sold, and passed between multiple advertising partners before they ever see a destination website. Most of this activity unfolds in fractions of a second and entirely beyond the user's view, and while many of those transactions remain legitimate, the sheer complexity of the ecosystem creates opportunities for abuse. </p><p>Somewhere within that chain, traffic can be acquired by actors whose interests extend far beyond advertising revenue, opening the door to scams, malware, fraudulent software, and a host of other malicious outcomes. </p><h2 id="the-malvertising-economy">The Malvertising Economy</h2><p>One of the reasons parked domain abuse is still underestimated and difficult to pin down is that the attack path rarely follows a straight line. When most people imagine a cyberattack, they picture a malicious website waiting at the end of a link, ready to ensnare an unsuspecting user. </p><p>But in this case, by the time a user reaches the content they're ultimately shown, their traffic may have already passed through a maze of advertising exchanges, brokers, redirectors, and cloaking services. </p><p>Each participant sees only a fragment of the overall journey, making it remarkably difficult for the “good guys” to determine which “bad guys” are responsible for what. It’s a little like trying to investigate a crime scene where the evidence constantly rearranges itself.</p><p>The cowardly threat actors involved in this type of cybercrime exploit this ambiguity. They use sophisticated cloaking techniques which allow them to examine visitors before deciding which content to serve up – where are they based? What kind of browser are they using? What operating system is their device running? </p><p>A <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> researcher in California might see a harmless landing page, while a finance broker in London might be served up a credential harvesting scam. This selective delivery makes malicious activity harder to detect and even harder to reproduce. </p><p>What’s worse, parked domain abuse is rarely aimed at a specific industry or organization. The actors deploying parked domains are usually financially motivated, and their primary interest is in acquiring traffic, so they’re not going to discriminate. </p><p>Once they’ve ensnared a victim, they become a commodity moving through an invisible marketplace where every click has value and every redirection creates another opportunity for exploitation.</p><h2 id="the-blind-spot-in-traditional-security">The blind spot in traditional security</h2><p>So where does all of this leave defenders? Parked domain abuse doesn’t behave like a conventional cyber threat. While security teams are used to investigating suspicious websites, malicious files, or compromised accounts that leave a relatively obvious trail, parked domain campaigns are different because the underlying traffic distribution is constantly changing. </p><p>The same typo domain can send one user down an entirely different path than the next. By the time an analyst attempts to recreate what a victim experienced, the route may no longer exist and any “evidence” has effectively evaporated. How do they defend against something they can't see or recreate?</p><p>One thing is guaranteed – regardless of how many redirects, intermediaries, cloaking systems, or advertising platforms sit between the initial typo and the final destination, every step in the journey depends on the <a href="https://www.techradar.com/news/best-dns-server">domain name system (DNS)</a>. Often described as the internet's address book, DNS is responsible for translating domain names into the destinations users ultimately reach. </p><p>Put simply, each lookup leaves behind a breadcrumb that helps reveal relationships that would otherwise remain hidden, and that visibility has allowed researchers investigating typosquatted versions of well-known domains to follow the trail beyond the initial deception. Patterns start to emerge between seemingly unrelated cases of malware, involving the same parking providers, cloaking services, and traffic distribution infrastructure. </p><p>By examining historical DNS records and mapping the relationships between domains over time, it has become possible to connect incidents that appear to be unrelated and expose the networks operating behind them. Instead of playing “whack a mole” and chasing surface level domains, DNS mapping has allowed defenders to target the entire machine. </p><p>The greatest danger posed by parked domains isn't the typo itself, but the assumption that the infrastructure behind that typo is benign. For years, parked domains occupied a strange corner of the internet, largely ignored by security teams and rarely considered worthy of serious scrutiny. </p><p>But today, they offer cybercriminals something far more valuable than advertising revenue – access to legitimate systems, trusted business models, and vast streams of user traffic that can be manipulated and monetized at scale. </p><p>As threat actors continue to refine their use of cloaking, traffic distribution, and advertising networks, the distinction between legitimate online activity and malicious activity will become increasingly difficult to spot from the outside.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>Protect yourself against malware with the best antivirus software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts get Google, Microsoft to pull trusted ModHeader with 1.6 million installs after finding it could harvest all kinds of data ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Stripe OLT found ModHeader v7.0.18 carried a hidden spyware SDK, exfiltrating visited domains daily to a Chinese‑owned server and acting as adware</strong></li><li><strong>The extension had 1.6M downloads across Chrome and Edge before being pulled but installed endpoints remain at risk</strong></li><li><strong>Researchers urge defenders to identify and remove existing installations, as removal from stores does not automatically remediate compromised devices</strong></li></ul><p>ModHeader, a trusted Chrome and Edge browser extension with more than 1.6 million downloads, was found to be malicious, apparently sending sensitive data to a Chinese-owned server, and has since been pulled on both repositories. </p><p>Security researchers Stripe OLT revealed the news in a new <a href="https://stripeolt.com/knowledge-hub/threat-research/chrome-extension-hidden-data-exfiltration-900k-users/" target="_blank">report</a>, outlining how a ModHeader build v7.0.18 carried a hidden <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">spyware</a> SDK. </p><p>As per Stripe OLT, the spyware collects domains users visit, encrypts the data with AES-GCP, and then sends it - once a day - to a remote server. The collector was found inactive by default, but the required code, encryption key, and upload schedule were all already embedded in the extension.</p><h2 id="links-to-chinese-actors">Links to Chinese actors</h2><p>Researchers found no command-and-control functionality, which means the server only receives the stolen data and cannot communicate back. The extension also worked as an adware, displaying ads and opening advertising tabs on updates, including on enterprise-managed devices.</p><p>The researchers attributed the attack, albeit with low confidence, to a Chinese-speaking threat actor. The exfiltration domain routes emails through Lark, which is a suite common with Chinese-speaking teams, it was said. They also found Chinese strings in the code, and said that the listing ships a Simplified Chinese locale. </p><p>ModHeader is a Chrome and Edge <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> extension that allows users to modify HTTP request and response headers sent between their browser and websites. Developers and security researchers use it to test APIs, troubleshoot applications, and simulate different environments. It has around 900,000 users on Chrome, and another 700,000 on Edge. </p><p>According to <a href="https://thehackernews.com/2026/07/google-and-microsoft-pull-modheader.html" target="_blank"><em>The Hacker News</em></a>, Microsoft pulled the tool from its repository on June 3 2026, followed by Google a week later, on July 10. </p><p>“Following our disclosure, Google has removed the extension from the Chrome Web Store,” Stripe OLT concluded. “We welcome this action, but removal from the store does not automatically remediate endpoints where the extension was already installed, so defenders should continue to identify and remove existing installations.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/experts-get-google-microsoft-to-pull-trusted-modheader-with-1-6-million-installs-after-finding-it-could-harvest-all-kinds-of-data</link>
                                                                            <description>
                            <![CDATA[ Visited domains were being exfiltrated to a third-party server, seemingly under a Chinese actor's control. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wBogsTgqZ6B4E5RonumGgf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/97XMVxvuGbBvxfxdd8VJqH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Jul 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/97XMVxvuGbBvxfxdd8VJqH-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Chrome, Edge, Safari, and Firefox browser apps on a mobile phone]]></media:description>                                                            <media:text><![CDATA[Chrome, Edge, Safari, and Firefox browser apps on a mobile phone]]></media:text>
                                <media:title type="plain"><![CDATA[Chrome, Edge, Safari, and Firefox browser apps on a mobile phone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/97XMVxvuGbBvxfxdd8VJqH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Stripe OLT found ModHeader v7.0.18 carried a hidden spyware SDK, exfiltrating visited domains daily to a Chinese‑owned server and acting as adware</strong></li><li><strong>The extension had 1.6M downloads across Chrome and Edge before being pulled but installed endpoints remain at risk</strong></li><li><strong>Researchers urge defenders to identify and remove existing installations, as removal from stores does not automatically remediate compromised devices</strong></li></ul><p>ModHeader, a trusted Chrome and Edge browser extension with more than 1.6 million downloads, was found to be malicious, apparently sending sensitive data to a Chinese-owned server, and has since been pulled on both repositories. </p><p>Security researchers Stripe OLT revealed the news in a new <a href="https://stripeolt.com/knowledge-hub/threat-research/chrome-extension-hidden-data-exfiltration-900k-users/" target="_blank">report</a>, outlining how a ModHeader build v7.0.18 carried a hidden <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">spyware</a> SDK. </p><p>As per Stripe OLT, the spyware collects domains users visit, encrypts the data with AES-GCP, and then sends it - once a day - to a remote server. The collector was found inactive by default, but the required code, encryption key, and upload schedule were all already embedded in the extension.</p><h2 id="links-to-chinese-actors">Links to Chinese actors</h2><p>Researchers found no command-and-control functionality, which means the server only receives the stolen data and cannot communicate back. The extension also worked as an adware, displaying ads and opening advertising tabs on updates, including on enterprise-managed devices.</p><p>The researchers attributed the attack, albeit with low confidence, to a Chinese-speaking threat actor. The exfiltration domain routes emails through Lark, which is a suite common with Chinese-speaking teams, it was said. They also found Chinese strings in the code, and said that the listing ships a Simplified Chinese locale. </p><p>ModHeader is a Chrome and Edge <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> extension that allows users to modify HTTP request and response headers sent between their browser and websites. Developers and security researchers use it to test APIs, troubleshoot applications, and simulate different environments. It has around 900,000 users on Chrome, and another 700,000 on Edge. </p><p>According to <a href="https://thehackernews.com/2026/07/google-and-microsoft-pull-modheader.html" target="_blank"><em>The Hacker News</em></a>, Microsoft pulled the tool from its repository on June 3 2026, followed by Google a week later, on July 10. </p><p>“Following our disclosure, Google has removed the extension from the Chrome Web Store,” Stripe OLT concluded. “We welcome this action, but removal from the store does not automatically remediate endpoints where the extension was already installed, so defenders should continue to identify and remove existing installations.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This new macOS infostealer poses as an Apple crash reporting tool to try and steal all your valuable data ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Jamf researchers uncover “CrashStealer,” a notarized macOS infostealer disguised as Apple’s CrashReporter</strong></li><li><strong>Distributed via a fake site called “Werkbit Setup”, it bypasses Gatekeeper, installs a LaunchAgent</strong></li><li><strong>It then uses a fake password prompt to unlock Keychain, exfiltrating credentials, cookies, files, and data from 80 crypto wallets and 14 password managers</strong></li></ul><p>A new macOS infostealer has been spotted in the wild, masquerading as an Apple crash reporting tool, experts have warned.</p><p>Called CrashStealer, this C++ infostealer was designed to nab login credentials, keychain information, as well as data related to more than 80 cryptocurrency wallets.</p><p>Cybersecurity researchers Jamf published an in-depth <a href="https://www.jamf.com/blog/crashstealer-macos-infostealer-analysis/" target="_blank">report</a> on the malware, noting CrashStealer is most likely distributed via a fake software site that was only registered recently.</p><h2 id="unlocking-keychain">Unlocking Keychain</h2><p>Victims who land on the site (either via a social media recommendation or search engine results) need to know the PIN code before initiating the download. This was most likely done to avoid analyst scrutiny, as well as to increase perceived credibility and a sense of exclusivity.</p><p>Usually, apps downloaded from third-party sources are scanned by Gatekeeper, Apple’s built-in security system. However, Jamf says that this payload is delivered via a signed and Apple-notarized installer and distributed as a disk image named “Werkbit Setup”, which allowed it to bypass Gatekeeper without any warnings.</p><p>Those that download and run the program will get a binary named ‘CrashReporter.app’, which will create a LaunchAgent (‘com.apple.crashreporter.helper’), and will see a fake macOS password prompt.</p><p>That prompt unlocks the user’s Keychain where most of their secrets are stored (passwords, private cryptographic keys, and more) and then exfiltrates all information to a third-party server. </p><p>Besides Keychain data, the CrashReporter <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> also pulls browser credentials and cookies from most browsers, data from 80 cryptocurrency wallet extensions, 14 <a href="https://www.techradar.com/best/password-manager" target="_blank">password managers</a>, locally stored files, and more. </p><p>Jamf said CrashReporter overlaps, to some extent, with other known infostealers (AMOS, for example), but is still unique enough given its client-side encryption mechanism, as well as the native C++ implementation.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/this-new-macos-infostealer-poses-as-an-apple-crash-reporting-tool-to-try-and-steal-all-your-valuable-data</link>
                                                                            <description>
                            <![CDATA[ Researchers found a new piece of macOS malware grabbing passwords, crypto data, and more. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SbwjYKP7zxrLGTEJgE6gNe</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ctJuqMRzZN6mdeA4UPgdTd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Jul 2026 14:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ctJuqMRzZN6mdeA4UPgdTd-1280-80.jpg">
                                                            <media:credit><![CDATA[Herry Sucahya on Unsplash]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The menu bar running in macOS.]]></media:description>                                                            <media:text><![CDATA[The menu bar running in macOS.]]></media:text>
                                <media:title type="plain"><![CDATA[The menu bar running in macOS.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ctJuqMRzZN6mdeA4UPgdTd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Jamf researchers uncover “CrashStealer,” a notarized macOS infostealer disguised as Apple’s CrashReporter</strong></li><li><strong>Distributed via a fake site called “Werkbit Setup”, it bypasses Gatekeeper, installs a LaunchAgent</strong></li><li><strong>It then uses a fake password prompt to unlock Keychain, exfiltrating credentials, cookies, files, and data from 80 crypto wallets and 14 password managers</strong></li></ul><p>A new macOS infostealer has been spotted in the wild, masquerading as an Apple crash reporting tool, experts have warned.</p><p>Called CrashStealer, this C++ infostealer was designed to nab login credentials, keychain information, as well as data related to more than 80 cryptocurrency wallets.</p><p>Cybersecurity researchers Jamf published an in-depth <a href="https://www.jamf.com/blog/crashstealer-macos-infostealer-analysis/" target="_blank">report</a> on the malware, noting CrashStealer is most likely distributed via a fake software site that was only registered recently.</p><h2 id="unlocking-keychain">Unlocking Keychain</h2><p>Victims who land on the site (either via a social media recommendation or search engine results) need to know the PIN code before initiating the download. This was most likely done to avoid analyst scrutiny, as well as to increase perceived credibility and a sense of exclusivity.</p><p>Usually, apps downloaded from third-party sources are scanned by Gatekeeper, Apple’s built-in security system. However, Jamf says that this payload is delivered via a signed and Apple-notarized installer and distributed as a disk image named “Werkbit Setup”, which allowed it to bypass Gatekeeper without any warnings.</p><p>Those that download and run the program will get a binary named ‘CrashReporter.app’, which will create a LaunchAgent (‘com.apple.crashreporter.helper’), and will see a fake macOS password prompt.</p><p>That prompt unlocks the user’s Keychain where most of their secrets are stored (passwords, private cryptographic keys, and more) and then exfiltrates all information to a third-party server. </p><p>Besides Keychain data, the CrashReporter <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> also pulls browser credentials and cookies from most browsers, data from 80 cryptocurrency wallet extensions, 14 <a href="https://www.techradar.com/best/password-manager" target="_blank">password managers</a>, locally stored files, and more. </p><p>Jamf said CrashReporter overlaps, to some extent, with other known infostealers (AMOS, for example), but is still unique enough given its client-side encryption mechanism, as well as the native C++ implementation.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Five reasons switching from IP VPN to SD WAN will help you build an AI-ready network ]]></title>
                                                                                                <dc:content><![CDATA[ <p>In the early 2000s, IP <a href="https://www.techradar.com/vpn/best-vpn-for-business">VPN</a> was the enterprise networking technology of choice for IT leaders. </p><p>MySpace was the go-to social network, we used Skype for video calls, we listened to music on our new MP3 players and the Nokia 1100 was the most popular mobile handset. </p><p>It feels like a different era entirely, yet many businesses are still running on legacy networks that were perfect for their needs back then but are now holding them back. </p><p>By today’s terms, networks were built for low levels of traffic. Cisco estimates global IP traffic levels were around 175 petabytes per month in 2001. Compare that to today’s figure, which is around 522,000 petabytes per month, or approximately 3000 times higher than 2001 levels, and you can understand why 87% of businesses in an Accenture study believe their legacy network is compromising their ability to advance on cloud, data and AI and digital transformation. </p><p>Untangling and replacing the complex web of enterprise networks built up over years is an unavoidable and costly necessity. It’s a bit like replacing the windows in your home - you know you’ll improve <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>, stormproof your home and cut energy costs by upgrading, but the process feels like a hassle. </p><p>Today, IT leaders aren’t just ‘replacing the windows’ by modernizing outdated networks; they’re going further and building high capacity, low latency, secure architectures designed to withstand the explosive demands of <a href="https://www.techradar.com/best/best-ai-tools">AI</a>.</p><h2 id="making-the-move-to-sd-wan">Making the move to SD WAN</h2><p>Millions of businesses are switching from IP VPN to Software-Defined Wide Area Networks, or SD WAN. Strong market growth is forecast in SD WAN, with one market forecast anticipating SD WAN CAGR of almost 40% (38.9%) from 2023 to 2030. </p><p>This growth is being driven by multiple factors including a shift to cloud-native architectures; a change in workplace practices and rise in remote working environments; and strong demand for network architectures that can manage current and future AI-related applications and services.  </p><p>SD WAN is faster, more cost effective and more secure, with built in <a href="https://www.techradar.com/best/ztna-solutions">zero trust</a> protection. It’s purpose built for distributed users and for managing cloud, AI workloads, data flows, and SaaS traffic. </p><p>But, to be truly AI ready, <a href="https://www.techradar.com/best/best-infrastructure-management-service">IT infrastructure</a> must be software driven, and this is where SD WAN excels: it gives your business the security, flexibility, and reliability needed to operate confidently in an AI driven future. Here are five ways switching to SD WAN will help you build an AI-ready network:</p><h2 id="1-built-for-ai-scale-performance">1.Built for AI-scale performance</h2><p>High-bandwidth, low latency SD WANs are critical for the delivery of AI workloads, particularly as businesses move towards AI inference. They provide fast access to <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud services</a> and dynamic bandwidth allocation as they monitor network conditions and reroute over the best available path. </p><p>For example, imagine a drive-through restaurant that uses an AI voice to take and relay orders or a supermarket that uses an AI model to scan shelves in its store, to detect gaps in stock, alert staff and predict which items will run out next. A high-performance, low latency network is essential here to guarantee a seamless <a href="https://www.techradar.com/best/cx-tools">customer experience</a>. </p><p>SD WAN’s application-aware routing levels this up even further, prioritizing AI traffic and deprioritizing the transfer of, for example, bulk file transfers or back-ups. </p><h2 id="2-security-that-matches-today-s-threat-landscape">2.Security that matches today’s threat landscape</h2><p>The global cyber attack surface has expanded dramatically. AI now plays a dual role, enabling more sophisticated attacks while also powering new, advanced defense capabilities. Traditional IP VPNs offer traffic <a href="https://www.techradar.com/best/best-encryption-software">encryption</a> but lack native security features. In contrast, SD WAN is built to protect modern networks from today’s high volume, highly sophisticated cyber threats:</p><p>- Zero trust access protects users, devices and applications</p><p>- Traffic is encrypted end to end, so that all data between sites, platforms and applications is secure</p><p>- Threat prevention at the edge protects core infrastructure from threats, with features such as intrusion detection and prevention, <a href="https://www.techradar.com/best/best-malware-removal">malware</a> scanning and <a href="https://www.techradar.com/news/best-dns-server">DNS</a> security</p><p>- Automated real-time security updates with threat intelligence pushed globally within minutes</p><h2 id="3-cloud-connectivity-without-compromise">3.Cloud connectivity without compromise</h2><p>SD WANs provide direct, optimized access to major cloud environments, such as Microsoft Azure, <a href="https://www.techradar.com/news/aws">AWS</a>, and Google Cloud, by using automated secure tunnels and intelligent path selection. </p><p>This ensures cloud and AI services run with lower latency, higher performance, and more reliable connectivity. Also important to note is that SD WANs provide high levels of autonomy and <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a>, so it’s easy to make changes quickly and easily as businesses navigate dynamic market conditions. </p><h2 id="4-data-insights-that-power-automation">4.Data insights that power automation </h2><p>SD WAN captures real-time data including latency, packet loss and application usage patterns – data which can be fed into AI-based network monitoring, automation and predictive <a href="https://www.techradar.com/best/best-maintenance-management-software">maintenance management</a> tools, so that networks become self-optimizing, self-healing and proactively secure.</p><h2 id="5-a-foundation-ready-for-sase-and-zero-trust">5.A foundation ready for SASE and Zero Trust</h2><p>When combined with Secure Access Service Edge (SASE), SD WAN creates a single, secure, high performance network foundation that’s built to drive AI opportunities while protecting against cyber risks with integrated security solutions including zero trust, secure web gateways and cloud firewalls. </p><p>SASE is a cloud based networking and security framework that combines SD WAN with integrated security services (like Zero Trust, secure web gateways, and cloud firewalls) into a single unified architecture. It’s the gold standard of AI-ready architecture.</p><p>As enterprises accelerate toward an AI driven future, the networks that once served them well are now becoming a barrier to progress. SD WAN offers a clear path forward: a software defined, secure, high performance foundation built to handle the scale, speed and complexity of modern cloud and AI workloads. </p><p>By making the shift now, businesses can replace aging infrastructure with an agile, intelligent network that not only supports today’s demands but unlocks the full potential of tomorrow’s AI innovation.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>We've ranked and reviewed the best antivirus software available</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p><h2 id=""></h2> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/five-reasons-switching-from-ip-vpn-to-sd-wan-will-help-you-build-an-ai-ready-network</link>
                                                                            <description>
                            <![CDATA[ The scale, speed and complexity of modern cloud and AI workloads demand SD WAN. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KBrWATibJQLupbVHbsHQCH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MuH6FdnCJqsnobznT3LSEM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Jul 2026 10:21:45 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Laura Farina ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MuH6FdnCJqsnobznT3LSEM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A digital representation of the globe in blue]]></media:description>                                                            <media:text><![CDATA[A digital representation of the globe in blue]]></media:text>
                                <media:title type="plain"><![CDATA[A digital representation of the globe in blue]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MuH6FdnCJqsnobznT3LSEM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In the early 2000s, IP <a href="https://www.techradar.com/vpn/best-vpn-for-business">VPN</a> was the enterprise networking technology of choice for IT leaders. </p><p>MySpace was the go-to social network, we used Skype for video calls, we listened to music on our new MP3 players and the Nokia 1100 was the most popular mobile handset. </p><p>It feels like a different era entirely, yet many businesses are still running on legacy networks that were perfect for their needs back then but are now holding them back. </p><p>By today’s terms, networks were built for low levels of traffic. Cisco estimates global IP traffic levels were around 175 petabytes per month in 2001. Compare that to today’s figure, which is around 522,000 petabytes per month, or approximately 3000 times higher than 2001 levels, and you can understand why 87% of businesses in an Accenture study believe their legacy network is compromising their ability to advance on cloud, data and AI and digital transformation. </p><p>Untangling and replacing the complex web of enterprise networks built up over years is an unavoidable and costly necessity. It’s a bit like replacing the windows in your home - you know you’ll improve <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>, stormproof your home and cut energy costs by upgrading, but the process feels like a hassle. </p><p>Today, IT leaders aren’t just ‘replacing the windows’ by modernizing outdated networks; they’re going further and building high capacity, low latency, secure architectures designed to withstand the explosive demands of <a href="https://www.techradar.com/best/best-ai-tools">AI</a>.</p><h2 id="making-the-move-to-sd-wan">Making the move to SD WAN</h2><p>Millions of businesses are switching from IP VPN to Software-Defined Wide Area Networks, or SD WAN. Strong market growth is forecast in SD WAN, with one market forecast anticipating SD WAN CAGR of almost 40% (38.9%) from 2023 to 2030. </p><p>This growth is being driven by multiple factors including a shift to cloud-native architectures; a change in workplace practices and rise in remote working environments; and strong demand for network architectures that can manage current and future AI-related applications and services.  </p><p>SD WAN is faster, more cost effective and more secure, with built in <a href="https://www.techradar.com/best/ztna-solutions">zero trust</a> protection. It’s purpose built for distributed users and for managing cloud, AI workloads, data flows, and SaaS traffic. </p><p>But, to be truly AI ready, <a href="https://www.techradar.com/best/best-infrastructure-management-service">IT infrastructure</a> must be software driven, and this is where SD WAN excels: it gives your business the security, flexibility, and reliability needed to operate confidently in an AI driven future. Here are five ways switching to SD WAN will help you build an AI-ready network:</p><h2 id="1-built-for-ai-scale-performance">1.Built for AI-scale performance</h2><p>High-bandwidth, low latency SD WANs are critical for the delivery of AI workloads, particularly as businesses move towards AI inference. They provide fast access to <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud services</a> and dynamic bandwidth allocation as they monitor network conditions and reroute over the best available path. </p><p>For example, imagine a drive-through restaurant that uses an AI voice to take and relay orders or a supermarket that uses an AI model to scan shelves in its store, to detect gaps in stock, alert staff and predict which items will run out next. A high-performance, low latency network is essential here to guarantee a seamless <a href="https://www.techradar.com/best/cx-tools">customer experience</a>. </p><p>SD WAN’s application-aware routing levels this up even further, prioritizing AI traffic and deprioritizing the transfer of, for example, bulk file transfers or back-ups. </p><h2 id="2-security-that-matches-today-s-threat-landscape">2.Security that matches today’s threat landscape</h2><p>The global cyber attack surface has expanded dramatically. AI now plays a dual role, enabling more sophisticated attacks while also powering new, advanced defense capabilities. Traditional IP VPNs offer traffic <a href="https://www.techradar.com/best/best-encryption-software">encryption</a> but lack native security features. In contrast, SD WAN is built to protect modern networks from today’s high volume, highly sophisticated cyber threats:</p><p>- Zero trust access protects users, devices and applications</p><p>- Traffic is encrypted end to end, so that all data between sites, platforms and applications is secure</p><p>- Threat prevention at the edge protects core infrastructure from threats, with features such as intrusion detection and prevention, <a href="https://www.techradar.com/best/best-malware-removal">malware</a> scanning and <a href="https://www.techradar.com/news/best-dns-server">DNS</a> security</p><p>- Automated real-time security updates with threat intelligence pushed globally within minutes</p><h2 id="3-cloud-connectivity-without-compromise">3.Cloud connectivity without compromise</h2><p>SD WANs provide direct, optimized access to major cloud environments, such as Microsoft Azure, <a href="https://www.techradar.com/news/aws">AWS</a>, and Google Cloud, by using automated secure tunnels and intelligent path selection. </p><p>This ensures cloud and AI services run with lower latency, higher performance, and more reliable connectivity. Also important to note is that SD WANs provide high levels of autonomy and <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a>, so it’s easy to make changes quickly and easily as businesses navigate dynamic market conditions. </p><h2 id="4-data-insights-that-power-automation">4.Data insights that power automation </h2><p>SD WAN captures real-time data including latency, packet loss and application usage patterns – data which can be fed into AI-based network monitoring, automation and predictive <a href="https://www.techradar.com/best/best-maintenance-management-software">maintenance management</a> tools, so that networks become self-optimizing, self-healing and proactively secure.</p><h2 id="5-a-foundation-ready-for-sase-and-zero-trust">5.A foundation ready for SASE and Zero Trust</h2><p>When combined with Secure Access Service Edge (SASE), SD WAN creates a single, secure, high performance network foundation that’s built to drive AI opportunities while protecting against cyber risks with integrated security solutions including zero trust, secure web gateways and cloud firewalls. </p><p>SASE is a cloud based networking and security framework that combines SD WAN with integrated security services (like Zero Trust, secure web gateways, and cloud firewalls) into a single unified architecture. It’s the gold standard of AI-ready architecture.</p><p>As enterprises accelerate toward an AI driven future, the networks that once served them well are now becoming a barrier to progress. SD WAN offers a clear path forward: a software defined, secure, high performance foundation built to handle the scale, speed and complexity of modern cloud and AI workloads. </p><p>By making the shift now, businesses can replace aging infrastructure with an agile, intelligent network that not only supports today’s demands but unlocks the full potential of tomorrow’s AI innovation.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>We've ranked and reviewed the best antivirus software available</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p><h2 id=""></h2>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Japan's largest taxi operator Nihon Kotsu hit by cyberattack which forces systems to be shut down ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Japan’s largest taxi operator confirms July 11 malware attack forcing shutdowns of its IT systems and disrupted dispatch and reservation services</strong></li><li><strong>Nihon Kotsu isolated networks, notified authorities, and brought in third‑party experts; customers were advised to use alternative taxi apps during the outage</strong></li><li><strong>No data leaks have been confirmed, but Nihon Kotsu warned it may disclose and notify affected parties if evidence of personal information exposure emerges</strong></li></ul><p>Japan’s largest taxi operator, Nihon Kotsu, hasconfirmed suffering a cyberattack which forced it to temporarily shut down parts of its IT infrastructure.</p><p>In a statement published on the company’s Japanese website, Nihon Kotsu said the attack took place in the early morning of July 11 - on a Saturday, when unnamed threat actors infected its devices with malware.</p><p>“We have recently discovered that our internal systems have been subjected to unauthorized external access (<a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware infection</a>),” the machine-translated statement reads. “We deeply apologize for the great inconvenience and concern caused to our customers, business partners, and all related parties due to this incident.”</p><h2 id="services-unavailable">Services unavailable</h2><p>As soon as it spotted the intrusion, Nihon Kotsu did what most companies do - shut down its network to prevent further damage, notified relevant law enforcement and data protection authorities, and brought in third-party experts to assess the damages and assist with the repairs.</p><p>The shutdown means some customer-facing services are unavailable: “As a result, the hire car web order and reservation management system, taxi dispatch service by phone, and some internal systems are temporarily unavailable,” the company said. </p><p>It advised its customers to use a different taxi app, which allows users to choose a taxi service to their liking. </p><p>So far, there is no evidence of any data exfiltration, or leaks to the dark web. However, the company did leave it as a possibility. </p><p>“At this time, no information leakage has been confirmed, but if any leakage or possibility of personal information of customers or related parties is newly discovered, we will promptly make official announcements and contact the affected parties individually in accordance with laws and regulations,” the company concluded.</p><p>Nihon Kotsu is Japan’s largest taxi operator, employing more than 18,000 people and running a fleet of more than 8,500 taxis and more than 2,000 chauffeur vehicles.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/japans-largest-taxi-operator-shuts-systems-after-cyberattack/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/japans-largest-taxi-operator-nihon-kotsu-hit-by-cyberattack-which-forces-systems-to-be-shut-down</link>
                                                                            <description>
                            <![CDATA[ Nihon Kotsu suffers malware attack, but there's no evidence of data exfiltration yet. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5vBZ3jEmoQgQq6pxgNJU6X</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JFKDCP2HdEKqSGJCkLNprB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Jul 2026 09:24:11 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JFKDCP2HdEKqSGJCkLNprB-1280-80.jpg">
                                                            <media:credit><![CDATA[Forcepint]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[IA y ciberseguridad]]></media:description>                                                            <media:text><![CDATA[IA y ciberseguridad]]></media:text>
                                <media:title type="plain"><![CDATA[IA y ciberseguridad]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JFKDCP2HdEKqSGJCkLNprB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Japan’s largest taxi operator confirms July 11 malware attack forcing shutdowns of its IT systems and disrupted dispatch and reservation services</strong></li><li><strong>Nihon Kotsu isolated networks, notified authorities, and brought in third‑party experts; customers were advised to use alternative taxi apps during the outage</strong></li><li><strong>No data leaks have been confirmed, but Nihon Kotsu warned it may disclose and notify affected parties if evidence of personal information exposure emerges</strong></li></ul><p>Japan’s largest taxi operator, Nihon Kotsu, hasconfirmed suffering a cyberattack which forced it to temporarily shut down parts of its IT infrastructure.</p><p>In a statement published on the company’s Japanese website, Nihon Kotsu said the attack took place in the early morning of July 11 - on a Saturday, when unnamed threat actors infected its devices with malware.</p><p>“We have recently discovered that our internal systems have been subjected to unauthorized external access (<a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware infection</a>),” the machine-translated statement reads. “We deeply apologize for the great inconvenience and concern caused to our customers, business partners, and all related parties due to this incident.”</p><h2 id="services-unavailable">Services unavailable</h2><p>As soon as it spotted the intrusion, Nihon Kotsu did what most companies do - shut down its network to prevent further damage, notified relevant law enforcement and data protection authorities, and brought in third-party experts to assess the damages and assist with the repairs.</p><p>The shutdown means some customer-facing services are unavailable: “As a result, the hire car web order and reservation management system, taxi dispatch service by phone, and some internal systems are temporarily unavailable,” the company said. </p><p>It advised its customers to use a different taxi app, which allows users to choose a taxi service to their liking. </p><p>So far, there is no evidence of any data exfiltration, or leaks to the dark web. However, the company did leave it as a possibility. </p><p>“At this time, no information leakage has been confirmed, but if any leakage or possibility of personal information of customers or related parties is newly discovered, we will promptly make official announcements and contact the affected parties individually in accordance with laws and regulations,” the company concluded.</p><p>Nihon Kotsu is Japan’s largest taxi operator, employing more than 18,000 people and running a fleet of more than 8,500 taxis and more than 2,000 chauffeur vehicles.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/japans-largest-taxi-operator-shuts-systems-after-cyberattack/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The new rules of software supply chain security: visibility, vigilance, validation ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The global digital economy runs on a thriving ecosystem of third-party vendors, enabling organizations to scale and innovate faster than they possibly could do on their own. </p><p>This digital ecosystem is teeming with software suppliers, not just <a href="https://www.techradar.com/best/best-small-business-software">business software</a> that you can buy but also a vast array of software libraries that are embedded in third-party products. </p><p>Speed, however, can sometimes be the enemy of risk, as many organizations have not adequately validated whether these third-party technologies are sufficiently safeguarded against cyber threats and other digital risk. </p><p>So, while software is a great enabler, it also brings risk, given that it often is built with frameworks and libraries that are not known or well supported. </p><p>Consider that companies employ an average of 106 SaaS apps within their IT environments , and the picture becomes quite clear: software supply chain security is a serious concern. </p><p>It’s no wonder that half (51%) of participants in the latest Supply Chain Risk Survey ranked software vulnerabilities in supplier products as the most disruptive <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> threat to their organization’s supply chain, behind only data breaches (64%) and <a href="https://www.techradar.com/best/best-malware-removal">malware</a> or <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a> (52%).</p><p>An ever-changing attack surface that comprises <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud services</a>, micro-services, APIs, SaaS platforms, third‑party services and now AI agents has expanded well beyond what once was an understood perimeter before widespread digital transformation took hold. </p><p>How secure is your own extended digital ecosystem? If this question makes your heart race, then take a closer look at three key considerations for addressing software supply chain security.</p><h2 id="1-visibility-determine-what-s-actually-in-your-multi-layered-supply-chain">1. Visibility: Determine what’s actually in your multi-layered supply chain</h2><p>Since the software supply chain is part of a vast, interconnected digital ecosystem, organizations likely do not have full visibility of what and who make up their third-party providers. Recent high-profile incidents have signaled just how fragile supply chains can be. </p><p>Assuring business continuity requires organizations to scrutinize partners before placing such deep trust in them. That effort starts with knowing who is in your interconnected digital ecosystem before you can start to manage the risk. </p><p>Understanding risk across a supply chain is conceptually easy, but it is practically difficult. While clearly outlining security parameters and requirements in supplier contracts is a great starting point, it is not enough, as contracting is generally a point-in-time activity and should be paired with monitoring. You must be able to see and measure <a href="https://www.techradar.com/best/best-software-asset-management-tools">software assets</a> so you can better manage them. </p><p>After all, you can’t protect what you can’t see, and many businesses still don’t have a complete, accurate asset inventory, meaning that their vulnerability exposure is incomplete. If you don’t know what systems, apps, devices and libraries are in your environment, vulnerability management is supposition, inference and guesswork. </p><p>It is crucial to understand what your suppliers are doing both upstream and who you supply downstream, because their decisions are now part of your organization’s own risk profile. Software often presents the biggest blind spots in asset management, thanks in large part to a lack transparency in software build and dependencies, shadow IT, shadow AI and unmanaged endpoints. </p><p>An organization's exposure is tied directly to the security posture of every supplier they rely on. Attackers know this, increasingly targeting upstream or downstream partners. You can secure your own environment perfectly and still be vulnerable through others’ oversight. Tools that can profile, quantify and score risk across the supply chain, therefore, are essential, as is tooling that monitors for unusual activity.</p><h2 id="2-vigilance-prioritize-the-security-of-ai-integrations-across-your-software-supply-chain">2. Vigilance: Prioritize the security of AI integrations across your software supply chain</h2><p>Threats can lurk anywhere and everywhere across your supply chain. But there’s a new kid in town: AI. The software supply chain has expanded to include the unique risks of AI ecosystem, such as reliance on external foundational models and highly connected agents. </p><p>This escalating integration of <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> makes the multi-faceted software supply chain even more of a concern. Cybersecurity professionals who participated in the latest Cybersecurity Workforce Study  revealed a troubling AI-related security event their organization experienced in that prior year: data poisoning (cited by 11%). </p><p>Data poisoning happens when bad actors intentionally insert corrupted, misleading or malicious data into the training dataset of a machine-learning model. Even a small amount of poisoned data can change the model’s behavior, in turn resulting in misclassifications, degraded accuracy or malicious outcomes. So suddenly that seemingly helpful <a href="https://www.techradar.com/pro/best-ai-chatbot-for-business">ChatBot</a> that is embedded in your <a href="https://www.techradar.com/best/the-best-crm-software">CRM</a>, <a href="https://www.techradar.com/best/cms">CMS</a> or other purpose-driven enterprise software may not be so friendly after all!</p><p>Indeed, organizations simply have little / no control over the software that suppliers are using, making it much more difficult to ensure vulnerabilities are identified before widespread rollout, as well as supported and patched once deployed, but they do have control over scrutinizing suppliers. </p><p>Therefore, the people on your <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> team and the processes they follow matter more than ever. Technology accelerates both sides of the fight, so your real advantage comes from having skilled practitioners who understand how AI changes your risk profile, attack surface and can put the right controls in place to compensate. </p><p>Cybersecurity professionals who specialize in software supply chain security can quantify the risk of model poisoning / steering, prompt injection and model inversion, and assess the inherent bias of pre-trained open-source models, protecting the integrity of software and services from upstream vulnerabilities. Such a holistic approach ensures that every component, from third-party libraries to the training data itself, meets the organization’s security and ethical standards.</p><p>In addition, reviewing and evaluating vendor agreements is an important task for cybersecurity teams and stakeholders. Think of these disciplined actions as a necessary stress-test meant to identify and address weaknesses and changing needs. A good contract with clear deliverables and expectations is part of a cybersecurity defensive strategy alongside your people and your defense technologies and ongoing monitoring of systems and services.</p><h2 id="3-validation-adopt-skills-frameworks-and-codes-of-practice-for-software-supply-chain-security">3. Validation: Adopt skills frameworks and codes of practice for software supply chain security</h2><p>No organization must stand up against the heightened threat of software supply chain security alone. Take advantage of existing guidance such as the U.K.’s Software Security Code of Practice to follow when you’re trying to batten the software hatches at your own organization. </p><p>Not only does this code support software vendors as they adopt secure software lifecycle development practices; it also supports software customers in mitigating the likelihood and impact of software supply chain attacks.</p><p>In addition to following code and other guidance frameworks, organizations can look to skills frameworks and vendor-neutral certifications to validate that their cybersecurity professionals demonstrate certain skills needed to build and strengthen supply chain security and resilience. </p><p>Skills development in the disciplines of governance, risk and compliance (GRC), secure software development and AI skills better enable cybersecurity and risk professionals to make informed decisions regarding software supply chain security and risk management. </p><h2 id="from-complexity-to-better-security">From complexity to better security</h2><p>Supply chains are complex, longer than you think and multidimensional. Organizations must place much greater focus on stress-testing the resilience of software suppliers and continuously evaluating exposure. </p><p>This approach goes well beyond being careful about what software makes it all the way to procurement. The potentially more damaging layer to address in the macro supply chain involves the embedded software and integrated AI tools that other suppliers are using.</p><p>The question is not whether your digital supply chain will face disruption. It's whether you have the visibility, vigilance and validation to operate when it does. That’s resilience: the north star of software supply chain security. Without question, transparency has to run through supply chains instead of just sitting inside organizations.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've rounded up the best endpoint protection software suites</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/the-new-rules-of-software-supply-chain-security-visibility-vigilance-validation</link>
                                                                            <description>
                            <![CDATA[ Software supply chain security is fast becoming a business-critical priority. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">c8Dxf5VhTRoXfkMpwcVx5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Jul 2026 08:56:46 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jon France ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:description>                                                            <media:text><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:text>
                                <media:title type="plain"><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The global digital economy runs on a thriving ecosystem of third-party vendors, enabling organizations to scale and innovate faster than they possibly could do on their own. </p><p>This digital ecosystem is teeming with software suppliers, not just <a href="https://www.techradar.com/best/best-small-business-software">business software</a> that you can buy but also a vast array of software libraries that are embedded in third-party products. </p><p>Speed, however, can sometimes be the enemy of risk, as many organizations have not adequately validated whether these third-party technologies are sufficiently safeguarded against cyber threats and other digital risk. </p><p>So, while software is a great enabler, it also brings risk, given that it often is built with frameworks and libraries that are not known or well supported. </p><p>Consider that companies employ an average of 106 SaaS apps within their IT environments , and the picture becomes quite clear: software supply chain security is a serious concern. </p><p>It’s no wonder that half (51%) of participants in the latest Supply Chain Risk Survey ranked software vulnerabilities in supplier products as the most disruptive <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> threat to their organization’s supply chain, behind only data breaches (64%) and <a href="https://www.techradar.com/best/best-malware-removal">malware</a> or <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a> (52%).</p><p>An ever-changing attack surface that comprises <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud services</a>, micro-services, APIs, SaaS platforms, third‑party services and now AI agents has expanded well beyond what once was an understood perimeter before widespread digital transformation took hold. </p><p>How secure is your own extended digital ecosystem? If this question makes your heart race, then take a closer look at three key considerations for addressing software supply chain security.</p><h2 id="1-visibility-determine-what-s-actually-in-your-multi-layered-supply-chain">1. Visibility: Determine what’s actually in your multi-layered supply chain</h2><p>Since the software supply chain is part of a vast, interconnected digital ecosystem, organizations likely do not have full visibility of what and who make up their third-party providers. Recent high-profile incidents have signaled just how fragile supply chains can be. </p><p>Assuring business continuity requires organizations to scrutinize partners before placing such deep trust in them. That effort starts with knowing who is in your interconnected digital ecosystem before you can start to manage the risk. </p><p>Understanding risk across a supply chain is conceptually easy, but it is practically difficult. While clearly outlining security parameters and requirements in supplier contracts is a great starting point, it is not enough, as contracting is generally a point-in-time activity and should be paired with monitoring. You must be able to see and measure <a href="https://www.techradar.com/best/best-software-asset-management-tools">software assets</a> so you can better manage them. </p><p>After all, you can’t protect what you can’t see, and many businesses still don’t have a complete, accurate asset inventory, meaning that their vulnerability exposure is incomplete. If you don’t know what systems, apps, devices and libraries are in your environment, vulnerability management is supposition, inference and guesswork. </p><p>It is crucial to understand what your suppliers are doing both upstream and who you supply downstream, because their decisions are now part of your organization’s own risk profile. Software often presents the biggest blind spots in asset management, thanks in large part to a lack transparency in software build and dependencies, shadow IT, shadow AI and unmanaged endpoints. </p><p>An organization's exposure is tied directly to the security posture of every supplier they rely on. Attackers know this, increasingly targeting upstream or downstream partners. You can secure your own environment perfectly and still be vulnerable through others’ oversight. Tools that can profile, quantify and score risk across the supply chain, therefore, are essential, as is tooling that monitors for unusual activity.</p><h2 id="2-vigilance-prioritize-the-security-of-ai-integrations-across-your-software-supply-chain">2. Vigilance: Prioritize the security of AI integrations across your software supply chain</h2><p>Threats can lurk anywhere and everywhere across your supply chain. But there’s a new kid in town: AI. The software supply chain has expanded to include the unique risks of AI ecosystem, such as reliance on external foundational models and highly connected agents. </p><p>This escalating integration of <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> makes the multi-faceted software supply chain even more of a concern. Cybersecurity professionals who participated in the latest Cybersecurity Workforce Study  revealed a troubling AI-related security event their organization experienced in that prior year: data poisoning (cited by 11%). </p><p>Data poisoning happens when bad actors intentionally insert corrupted, misleading or malicious data into the training dataset of a machine-learning model. Even a small amount of poisoned data can change the model’s behavior, in turn resulting in misclassifications, degraded accuracy or malicious outcomes. So suddenly that seemingly helpful <a href="https://www.techradar.com/pro/best-ai-chatbot-for-business">ChatBot</a> that is embedded in your <a href="https://www.techradar.com/best/the-best-crm-software">CRM</a>, <a href="https://www.techradar.com/best/cms">CMS</a> or other purpose-driven enterprise software may not be so friendly after all!</p><p>Indeed, organizations simply have little / no control over the software that suppliers are using, making it much more difficult to ensure vulnerabilities are identified before widespread rollout, as well as supported and patched once deployed, but they do have control over scrutinizing suppliers. </p><p>Therefore, the people on your <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> team and the processes they follow matter more than ever. Technology accelerates both sides of the fight, so your real advantage comes from having skilled practitioners who understand how AI changes your risk profile, attack surface and can put the right controls in place to compensate. </p><p>Cybersecurity professionals who specialize in software supply chain security can quantify the risk of model poisoning / steering, prompt injection and model inversion, and assess the inherent bias of pre-trained open-source models, protecting the integrity of software and services from upstream vulnerabilities. Such a holistic approach ensures that every component, from third-party libraries to the training data itself, meets the organization’s security and ethical standards.</p><p>In addition, reviewing and evaluating vendor agreements is an important task for cybersecurity teams and stakeholders. Think of these disciplined actions as a necessary stress-test meant to identify and address weaknesses and changing needs. A good contract with clear deliverables and expectations is part of a cybersecurity defensive strategy alongside your people and your defense technologies and ongoing monitoring of systems and services.</p><h2 id="3-validation-adopt-skills-frameworks-and-codes-of-practice-for-software-supply-chain-security">3. Validation: Adopt skills frameworks and codes of practice for software supply chain security</h2><p>No organization must stand up against the heightened threat of software supply chain security alone. Take advantage of existing guidance such as the U.K.’s Software Security Code of Practice to follow when you’re trying to batten the software hatches at your own organization. </p><p>Not only does this code support software vendors as they adopt secure software lifecycle development practices; it also supports software customers in mitigating the likelihood and impact of software supply chain attacks.</p><p>In addition to following code and other guidance frameworks, organizations can look to skills frameworks and vendor-neutral certifications to validate that their cybersecurity professionals demonstrate certain skills needed to build and strengthen supply chain security and resilience. </p><p>Skills development in the disciplines of governance, risk and compliance (GRC), secure software development and AI skills better enable cybersecurity and risk professionals to make informed decisions regarding software supply chain security and risk management. </p><h2 id="from-complexity-to-better-security">From complexity to better security</h2><p>Supply chains are complex, longer than you think and multidimensional. Organizations must place much greater focus on stress-testing the resilience of software suppliers and continuously evaluating exposure. </p><p>This approach goes well beyond being careful about what software makes it all the way to procurement. The potentially more damaging layer to address in the macro supply chain involves the embedded software and integrated AI tools that other suppliers are using.</p><p>The question is not whether your digital supply chain will face disruption. It's whether you have the visibility, vigilance and validation to operate when it does. That’s resilience: the north star of software supply chain security. Without question, transparency has to run through supply chains instead of just sitting inside organizations.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've rounded up the best endpoint protection software suites</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Vibe coded threats shift again — hackers are using AI chatbots to write malware using natural language ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Huntress analyzed AI‑generated malware “Untitled1.ps1,” a noisy custom AD enumeration tool likely built by low‑skilled attackers using generative AI</strong></li><li><strong>Attackers paired it with s5cmd for rapid data exfiltration and SharpShares.exe for share enumeration before being detected and removed</strong></li><li><strong>Report warns AI “vibe coding” lowers barriers for cybercrime, producing unique payloads that evade signature‑based defenses, requiring behavioral analytics to catch attack lifecycles</strong></li></ul><p>“Unsophisticated” cybercriminals can now easily write malicious code using Artificial Intelligence (AI) and run devastating data breach attacks with speed, forcing defenders to rethink their strategies, researchers have claimed. </p><p>Security experts Huntress thoroughly investigating a piece of AI-written <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, and <a href="https://www.huntress.com/blog/ai-coded-malware-vibe-coding-active-directory" target="_blank">explained</a> how the bespoke, AI-generated payload was a “highly aggressive, noisy, custom-built AD enumeration tool.”</p><p>Since cybercriminals are generally careful not to make too much noise and to try and do their bidding without raising any alarms, the researchers hint this was the work of a low-skilled attacker.</p><h2 id="significant-challenge">Significant challenge</h2><p>The malware, labeled Untitled1.ps1, was designed to map the Active Directory environment and apparently, it did its job well. In the next step, the crooks deployed a legitimate high-speed command-line tool for Amazon S3 operations called s5cmd which, according to Huntress, is often used for data exfiltration.</p><p>Before being spotted and kicked out, the attackers also deployed a known enumeration tool called SharpShares.exe, filtering common administrative shares while hunting for further user-accessible data repositories. </p><p>The move from off-the-shelf frameworks to custom, bespoke AI tools is a “significant challenge” for the defenders, Huntress warns. </p><p>“Historically, AVs and EDR platforms have relied heavily on file hashes and static string signatures,” they say. “Vibe-coded scripts are inherently unique. Untitled1.ps1 has never existed before and will likely never be compiled in this exact configuration again.”</p><p>As a result, defenders must focus on the “fundamental behaviors of the attack lifecycle.” AI can change the code syntax, they’re saying, but cannot change the underlying mechanics of <a href="https://www.techradar.com/pro/best-active-directory-documentation-tool-of-year" target="_blank">Active Directory</a> enumeration. </p><p>“Vibe coding lowers the barrier to entry for cybercrime, allowing unsophisticated actors to generate highly capable, evasive tooling on the fly,” the researchers concluded. “While the code itself may be messy, over-engineered, and filled with AI hallmarks like left-behind comments, the threat it poses is very real. To combat this, defenders must abandon rigid, signature-based thinking and embrace behavioral analytics to catch the underlying actions that no LLM can hide.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/vibe-coded-threats-shift-again-hackers-are-using-ai-chatbots-to-write-malware-using-natural-language</link>
                                                                            <description>
                            <![CDATA[ How do you spot an attack when signatures and behaviors can no longer be used? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7FaiGdV8mykwMcDLSkT3n9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/G8QNviZt3KrDbfWVANJrNM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 13 Jul 2026 15:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/G8QNviZt3KrDbfWVANJrNM-1280-80.jpg">
                                                            <media:credit><![CDATA[Elchinator from Pixabay ]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[malware]]></media:description>                                                            <media:text><![CDATA[malware]]></media:text>
                                <media:title type="plain"><![CDATA[malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/G8QNviZt3KrDbfWVANJrNM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Huntress analyzed AI‑generated malware “Untitled1.ps1,” a noisy custom AD enumeration tool likely built by low‑skilled attackers using generative AI</strong></li><li><strong>Attackers paired it with s5cmd for rapid data exfiltration and SharpShares.exe for share enumeration before being detected and removed</strong></li><li><strong>Report warns AI “vibe coding” lowers barriers for cybercrime, producing unique payloads that evade signature‑based defenses, requiring behavioral analytics to catch attack lifecycles</strong></li></ul><p>“Unsophisticated” cybercriminals can now easily write malicious code using Artificial Intelligence (AI) and run devastating data breach attacks with speed, forcing defenders to rethink their strategies, researchers have claimed. </p><p>Security experts Huntress thoroughly investigating a piece of AI-written <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, and <a href="https://www.huntress.com/blog/ai-coded-malware-vibe-coding-active-directory" target="_blank">explained</a> how the bespoke, AI-generated payload was a “highly aggressive, noisy, custom-built AD enumeration tool.”</p><p>Since cybercriminals are generally careful not to make too much noise and to try and do their bidding without raising any alarms, the researchers hint this was the work of a low-skilled attacker.</p><h2 id="significant-challenge">Significant challenge</h2><p>The malware, labeled Untitled1.ps1, was designed to map the Active Directory environment and apparently, it did its job well. In the next step, the crooks deployed a legitimate high-speed command-line tool for Amazon S3 operations called s5cmd which, according to Huntress, is often used for data exfiltration.</p><p>Before being spotted and kicked out, the attackers also deployed a known enumeration tool called SharpShares.exe, filtering common administrative shares while hunting for further user-accessible data repositories. </p><p>The move from off-the-shelf frameworks to custom, bespoke AI tools is a “significant challenge” for the defenders, Huntress warns. </p><p>“Historically, AVs and EDR platforms have relied heavily on file hashes and static string signatures,” they say. “Vibe-coded scripts are inherently unique. Untitled1.ps1 has never existed before and will likely never be compiled in this exact configuration again.”</p><p>As a result, defenders must focus on the “fundamental behaviors of the attack lifecycle.” AI can change the code syntax, they’re saying, but cannot change the underlying mechanics of <a href="https://www.techradar.com/pro/best-active-directory-documentation-tool-of-year" target="_blank">Active Directory</a> enumeration. </p><p>“Vibe coding lowers the barrier to entry for cybercrime, allowing unsophisticated actors to generate highly capable, evasive tooling on the fly,” the researchers concluded. “While the code itself may be messy, over-engineered, and filled with AI hallmarks like left-behind comments, the threat it poses is very real. To combat this, defenders must abandon rigid, signature-based thinking and embrace behavioral analytics to catch the underlying actions that no LLM can hide.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft discovers new multi-malware package 'GigaWiper' capable of deploying wipers and ransomware ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft warns of “GigaWiper,” a destructive malware attributed to Iranian group CyberAv3ngers that combines multiple variants into one</strong></li><li><strong>It can wipe drives, encrypt files with a fake ransomware extension, or overwrite Windows partitions, while also spying via screenshots, VNC sessions, and system data theft</strong></li><li><strong>The malware hides under fake OneDrive tasks and registry keys, showing both espionage and sabotage capabilities with no recovery path for victims’ data</strong></li></ul><p>Microsoft is warning about a new piece of malware called GigaWiper, which can spy on people’s computers and then destroy them entirely, in different ways.</p><p>It was built by mashing different <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> variants into one, and it seems to be the work of Iranian state-sponsored threat actors called CyberAv3ngers. The hackers also took a little cheeky dig at Microsoft, through the malware’s obfuscation mechanism.</p><p>As Microsoft <a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="nofollow">explained</a>, GigaWiper can overwrite the physical drive and wipe the partition table, destroying the contents of the disk directly. It can also encrypt all files on the drive, add a .candy extension, and change the desktop wallpaper to show a warning. This ransomware approach does not share a ransom note, and does not generate a decryption key, so there is nothing to pay, and no way to decrypt the files - they are gone for good, just giving victims false hope.</p><h2 id="spying-on-the-victims">Spying on the victims</h2><p>Finally, the third method goes straight for the Windows drive, overwriting it multiple times with different data patterns. </p><p>Besides bricking the disk, GigaWiper can also spy on its victims by grabbing screenshots, recording the screen, or opening a VNC session to either stream someone else’s work, or allow the attackers to use the mouse and keyboard. The malware can also extract system data, manage programs and services, modify the registry, and more. </p><p>But the cheekiest feature is how it hides. It schedules a task called OneDrive Update and tracks itself in a registry key called OneDrive\Environment. Perhaps the attackers assumed no one really pays attention to <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">OneDrive</a>, and thus the malware could stay out of sight for longer. </p><p>Speaking of the attackers, Microsoft does not name them, but most of the components mashed together to form GigaWiper were previously attributed to CyberAv3ngers, a group linked to Iran's Islamic Revolutionary Guard Corps.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/microsoft-discovers-new-multi-malware-package-gigawiper-capable-of-deploying-wipers-and-ransomware</link>
                                                                            <description>
                            <![CDATA[ One wiper can destroy a computer in different ways, but it can also spy on users. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6JU6gwuxmJ5p8jKNCQnPq5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Jul 2026 16:50:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[hacker hands at work with  interface around]]></media:description>                                                            <media:text><![CDATA[hacker hands at work with  interface around]]></media:text>
                                <media:title type="plain"><![CDATA[hacker hands at work with  interface around]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft warns of “GigaWiper,” a destructive malware attributed to Iranian group CyberAv3ngers that combines multiple variants into one</strong></li><li><strong>It can wipe drives, encrypt files with a fake ransomware extension, or overwrite Windows partitions, while also spying via screenshots, VNC sessions, and system data theft</strong></li><li><strong>The malware hides under fake OneDrive tasks and registry keys, showing both espionage and sabotage capabilities with no recovery path for victims’ data</strong></li></ul><p>Microsoft is warning about a new piece of malware called GigaWiper, which can spy on people’s computers and then destroy them entirely, in different ways.</p><p>It was built by mashing different <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> variants into one, and it seems to be the work of Iranian state-sponsored threat actors called CyberAv3ngers. The hackers also took a little cheeky dig at Microsoft, through the malware’s obfuscation mechanism.</p><p>As Microsoft <a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="nofollow">explained</a>, GigaWiper can overwrite the physical drive and wipe the partition table, destroying the contents of the disk directly. It can also encrypt all files on the drive, add a .candy extension, and change the desktop wallpaper to show a warning. This ransomware approach does not share a ransom note, and does not generate a decryption key, so there is nothing to pay, and no way to decrypt the files - they are gone for good, just giving victims false hope.</p><h2 id="spying-on-the-victims">Spying on the victims</h2><p>Finally, the third method goes straight for the Windows drive, overwriting it multiple times with different data patterns. </p><p>Besides bricking the disk, GigaWiper can also spy on its victims by grabbing screenshots, recording the screen, or opening a VNC session to either stream someone else’s work, or allow the attackers to use the mouse and keyboard. The malware can also extract system data, manage programs and services, modify the registry, and more. </p><p>But the cheekiest feature is how it hides. It schedules a task called OneDrive Update and tracks itself in a registry key called OneDrive\Environment. Perhaps the attackers assumed no one really pays attention to <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">OneDrive</a>, and thus the malware could stay out of sight for longer. </p><p>Speaking of the attackers, Microsoft does not name them, but most of the components mashed together to form GigaWiper were previously attributed to CyberAv3ngers, a group linked to Iran's Islamic Revolutionary Guard Corps.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This malicious Google Notes extension just wants to sneakily steal all your crypto ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>McAfee flags “Silent Swap,” a malicious Chromium extension disguised as Google Notes that secretly hijacks crypto transactions</strong></li><li><strong>It works as a clipboard jacker, swapping copied wallet addresses with attacker‑controlled ones so victims unknowingly send funds to criminals</strong></li><li><strong>Researchers advise always cross‑checking full wallet strings before sending, as attackers can craft lookalike addresses differing only in a few characters</strong></li></ul><p>Researchers have found yet another extension for Chromium-based browsers that is designed solely to steal people’s hard-earned cryptocurrency.</p><p>A <a href="https://www.mcafee.com/blogs/other-blogs/mcafee-labs/crypto-clipper-wallet-swapping-browser-extension-malware/" target="_blank" rel="nofollow">report</a> from McAfee has sounded the alarm on Silent Swap, a piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> hiding inside a benign-looking Google Notes extension.</p><p>Victims who stumble upon and download it (most likely through phishing, social engineering, or shady forums and websites), will get an extension that, on the surface, works as intended. It shows a small window where the victim can type a note and save it. They can color-code the notes and search through saved ones. However, this was only made to hide the program’s true intentions, which are to steal cryptocurrency.</p><h2 id="hijacking-the-clipboard">Hijacking the clipboard</h2><p>Silent Swap works like a typical clipboard jacker. It monitors the clipboard for strings that look like a <a href="https://www.techradar.com/news/best-bitcoin-wallets" target="_blank">crypto wallet</a> - seemingly random strings of 26 to 42 alphanumeric characters. </p><p>When it spots one, it replaces it with a different one belonging to the attacker, so when the victim pastes the address into the wallet to send the funds, they are actually sending them to the address belonging to the attackers.</p><p>This works because crypto wallets are almost impossible to memorize, and too risky to type in from a piece of paper or a different document, forcing users to rely on copying and pasting. </p><p>Once the victim sends the funds, they are almost certainly irretrievably gone. Only if the funds are being sent from a centralized exchange (like Coinbase, for example), and if the victim spots the attack fast enough, can they ask the exchange’s support to freeze the transaction. In all other cases, once the money is sent, it’s gone.</p><p>The best way to defend against these attacks is to cross-reference the strings before hitting send. Some people would only check the first and last few characters, but security researchers don’t recommend it, because some clipboard jackers can generate addresses that only differ in a few characters.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/this-malicious-google-notes-extension-just-wants-to-sneakily-steal-all-your-crypto</link>
                                                                            <description>
                            <![CDATA[ Another clipboard jacker was found in the wild, on the prowl for people's crypto. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TgqEFku9ZNa9fNUkZbYTj9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VnoVVXTmAmxSBYBe4LUwVW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Jul 2026 11:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VnoVVXTmAmxSBYBe4LUwVW-1280-80.jpg">
                                                            <media:credit><![CDATA[vjkombajn/Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image credit: Pixabay/vjkombajn]]></media:description>                                                            <media:text><![CDATA[Cryptocurrencies]]></media:text>
                                <media:title type="plain"><![CDATA[Cryptocurrencies]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VnoVVXTmAmxSBYBe4LUwVW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>McAfee flags “Silent Swap,” a malicious Chromium extension disguised as Google Notes that secretly hijacks crypto transactions</strong></li><li><strong>It works as a clipboard jacker, swapping copied wallet addresses with attacker‑controlled ones so victims unknowingly send funds to criminals</strong></li><li><strong>Researchers advise always cross‑checking full wallet strings before sending, as attackers can craft lookalike addresses differing only in a few characters</strong></li></ul><p>Researchers have found yet another extension for Chromium-based browsers that is designed solely to steal people’s hard-earned cryptocurrency.</p><p>A <a href="https://www.mcafee.com/blogs/other-blogs/mcafee-labs/crypto-clipper-wallet-swapping-browser-extension-malware/" target="_blank" rel="nofollow">report</a> from McAfee has sounded the alarm on Silent Swap, a piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> hiding inside a benign-looking Google Notes extension.</p><p>Victims who stumble upon and download it (most likely through phishing, social engineering, or shady forums and websites), will get an extension that, on the surface, works as intended. It shows a small window where the victim can type a note and save it. They can color-code the notes and search through saved ones. However, this was only made to hide the program’s true intentions, which are to steal cryptocurrency.</p><h2 id="hijacking-the-clipboard">Hijacking the clipboard</h2><p>Silent Swap works like a typical clipboard jacker. It monitors the clipboard for strings that look like a <a href="https://www.techradar.com/news/best-bitcoin-wallets" target="_blank">crypto wallet</a> - seemingly random strings of 26 to 42 alphanumeric characters. </p><p>When it spots one, it replaces it with a different one belonging to the attacker, so when the victim pastes the address into the wallet to send the funds, they are actually sending them to the address belonging to the attackers.</p><p>This works because crypto wallets are almost impossible to memorize, and too risky to type in from a piece of paper or a different document, forcing users to rely on copying and pasting. </p><p>Once the victim sends the funds, they are almost certainly irretrievably gone. Only if the funds are being sent from a centralized exchange (like Coinbase, for example), and if the victim spots the attack fast enough, can they ask the exchange’s support to freeze the transaction. In all other cases, once the money is sent, it’s gone.</p><p>The best way to defend against these attacks is to cross-reference the strings before hitting send. Some people would only check the first and last few characters, but security researchers don’t recommend it, because some clipboard jackers can generate addresses that only differ in a few characters.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How AI is taking IoT security to the next level ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The IoT and <a href="https://www.techradar.com/best/best-ai-tools">AI</a> are a likely partnership: IoT generates and captures data, often in large volume, AI is ideally placed to analyze it. </p><p>Combined, AIoT presents new opportunities, so much so that Transforma Insights forecasts no fewer than 9.1 billion AIoT connections at the end of 2033, a more than six-fold increase in 10 years. </p><p></p><p>The potential for AI in the IoT is far-reaching, and one standout application is enhanced security.</p><h2 id="the-security-risk-to-the-iot">The security risk to the IoT </h2><p>All connected devices are under growing levels of threat, but the IoT is particularly targeted. According to Beaming’s cyberthreat report into UK businesses, IoT devices were most frequently attacked in 2024. They are attractive targets for the data they exchange and their potential to be compromised. </p><p>The devices are often unmanned and generally sit outside corporate <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> perimeters. They may be in remote spots, where they could be subject to unauthorized physical access attempts, and often remain in place for long periods of time. Many, such as the IoT devices used in energy, transport, utilities and retail, transfer sensitive data of high value. </p><p>Businesses need confidence that data collected through the IoT—both real-time and historical—comes from secure and trusted sources, not least when it comes to developing and training AI models. In this, the IoT works with digital twins, which are digital representations of physical objects or systems. </p><p>The IoT enables the seamless flow of real-world data between the physical and the digital, while the digital twin’s attributes provide the features for AI modelling. Historical data collected through IoT is then used to train and refine the AI model. </p><h2 id="how-ai-is-helping-secure-the-iot">How AI is helping secure the IoT</h2><p>AI applies its <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a> and analytical capabilities to many tasks and priorities. It is making inroads into cybersecurity, something that has not gone unnoticed. Last year, the IEEE revealed almost half of the global technology leaders it surveyed (47%) expect vulnerability identification and attack prevention to be a top use of AI in 2026. </p><p>That may be some comfort to enterprises and connectivity and solutions providers grappling with the problem of protecting IoT devices and applications. This challenge is compounded by the fact that attackers are increasingly using AI themselves to automate phishing, accelerate reconnaissance and develop adaptive <a href="https://www.techradar.com/best/best-malware-removal">malware</a> that evades traditional detection. However, it is more comforting still, that AI is already making a difference in the IoT, redefining how organizations protect their devices. </p><p>AI-powered anomaly and threat detection (ATD) is helping security teams identify threats like suspicious network traffic and botnet activity faster and improving resilience across large-scale IoT environments, something enterprises must strive for. </p><p>In the recent past, the focus on the IoT was arguably getting devices online. That is no longer the challenge; the test now is keeping them operational: compliance readiness and the flexibility to adapt to ever-evolving commercial and technological changes. It also means maintaining resilience. </p><p>IoT security must follow a clear defend against, detect and react approach to swiftly counter attacks. No one or two of these three measures are enough without the others. </p><h2 id="how-ai-improves-iot-visibility-and-incident-response">How AI improves IoT visibility and incident response</h2><p>AI-powered ATD detects anomalous behavior, such as remote code execution, abnormal port connection or a suspicious IP. These could indicate the beginnings of a cyberattack on an IoT device. It analyses the anomaly and can identify the attack type, be it distributed denial of service (<a href="https://www.techradar.com/news/best-ddos-protection">DDoS</a>), man-in-the-middle (MiTM) or an attempted device takeover. </p><p>ATD can then trigger direct action, if business rules dictate an automated response. This could take the form of threat isolation or referring the incident for full review. </p><h2 id="anomaly-and-threat-detection-protects-over-one-million-devices">Anomaly and threat detection protects over one million devices</h2><p>ATD runs entirely in the mobile core network infrastructure, rather than through software agents on a device, so it can be retrofitted to existing systems.</p><p>Enterprises that have identified IP backdoors and Mirai botnet infections within hours. </p><p>With IP backdoors, ATD detects unusual outbound connections, or traffic, to suspicious IPs. Such backdoors may allow remote control or data exfiltration, both of which leave identifiable behavioral traces.</p><p>In the case of Mirai, anomalous behavior typically exhibits as spikes in outbound traffic, uncommon ports use, or repetitive scanning of external IPs. ATD can flag these irregularities in real time and trigger corrective actions, such as blocking or quarantining the device, blocking or throttling traffic or patching firmware.</p><h2 id="automation-and-analytics-can-shape-the-next-phase-of-iot-security">Automation and analytics can shape the next phase of IoT security</h2><p>There is a clear shift in IoT implementation and management. It is insufficient to plan for device deployment, sit back and gather the data. Without a strategy that accounts for the stresses, threats and changes that beset IoT estates, enterprises risk costly surprises like unplanned site visits and service disruptions. </p><p>AI, through automation and analytics, can shape the next phase of IoT security. Enterprises that detect, analyze and even automatically address, anomalous activity reduce the risk of cyberattack-related outages and inconvenient site visits to access devices. </p><p>Sending field technicians to maintain or repair devices can add significantly to total cost of ownership. Each truck roll, which incurs expenses for labor, fuel, vehicle wear and often missed <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a> opportunities, can add up to over $1000 per site visit. </p><p>IoT downtime, meanwhile disrupts operations and can have a catastrophic reputational, as well as financial, cost. </p><h2 id="how-to-balance-innovation-data-privacy-and-operational-control">How to balance innovation, data privacy and operational control</h2><p>Enterprises are, for the most part, keen to innovate through AI but have understandable questions about data privacy and operational control. </p><p>It is important to know what AI does, in all process integrations, to understand why it does it and to have control that prevents AI deviating from its purpose.</p><p>On data privacy, ATD isn’t installed on IoT devices. Only packet headers from device <a href="https://www.techradar.com/best/best-cloud-storage">cloud</a> communications are mirrored from the mobile core to the ATD engine, with threat levels and AI-driven insights relayed through a customer portal. </p><p>Operational control is maintained through the business rules that dictate how the ATD engine reacts. The option to refer an anomaly for review, for example, gives enterprises the flexibility to incorporate human oversight, under predetermined circumstances. </p><p>This is especially useful when you consider there can be genuine reasons why a SIM may increase or cease communication, that an incident reviewer will understand.</p><h2 id="ai-powered-iot-security">AI-powered IoT security </h2><p>AI is making a difference to the speed, efficiency and depth of response to cyberthreats. Automation and advanced analytics within IoT solutions’ security measures also help enterprises manage costs, by minimizing labor-intensive manual tasks and site visits, and reducing the risk of expensive cyberattack reparations. </p><p>For CISOs, CIOs, product and operations managers seeking to maximize IoT value and protect their enterprise IT domains from external threats, AI-powered ATD offers visibility and actionable insights to take IoT security to the next level.</p><p><a href="https://www.techradar.com/best/best-antivirus"><em>We've reviewed and ranked the best antivirus software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/how-ai-is-taking-iot-security-to-the-next-level</link>
                                                                            <description>
                            <![CDATA[ AI is redefining how organizations protect and manage connected devices. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BwU5d5Knz43h6RHYPL7LC3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/euoWA3SymQA2cKKjmF37W4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Jul 2026 10:28:27 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Iain Davidson ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/euoWA3SymQA2cKKjmF37W4-1280-80.jpg">
                                                            <media:credit><![CDATA[The Register]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wi-Fi]]></media:description>                                                            <media:text><![CDATA[Wi-Fi]]></media:text>
                                <media:title type="plain"><![CDATA[Wi-Fi]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/euoWA3SymQA2cKKjmF37W4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The IoT and <a href="https://www.techradar.com/best/best-ai-tools">AI</a> are a likely partnership: IoT generates and captures data, often in large volume, AI is ideally placed to analyze it. </p><p>Combined, AIoT presents new opportunities, so much so that Transforma Insights forecasts no fewer than 9.1 billion AIoT connections at the end of 2033, a more than six-fold increase in 10 years. </p><p></p><p>The potential for AI in the IoT is far-reaching, and one standout application is enhanced security.</p><h2 id="the-security-risk-to-the-iot">The security risk to the IoT </h2><p>All connected devices are under growing levels of threat, but the IoT is particularly targeted. According to Beaming’s cyberthreat report into UK businesses, IoT devices were most frequently attacked in 2024. They are attractive targets for the data they exchange and their potential to be compromised. </p><p>The devices are often unmanned and generally sit outside corporate <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> perimeters. They may be in remote spots, where they could be subject to unauthorized physical access attempts, and often remain in place for long periods of time. Many, such as the IoT devices used in energy, transport, utilities and retail, transfer sensitive data of high value. </p><p>Businesses need confidence that data collected through the IoT—both real-time and historical—comes from secure and trusted sources, not least when it comes to developing and training AI models. In this, the IoT works with digital twins, which are digital representations of physical objects or systems. </p><p>The IoT enables the seamless flow of real-world data between the physical and the digital, while the digital twin’s attributes provide the features for AI modelling. Historical data collected through IoT is then used to train and refine the AI model. </p><h2 id="how-ai-is-helping-secure-the-iot">How AI is helping secure the IoT</h2><p>AI applies its <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a> and analytical capabilities to many tasks and priorities. It is making inroads into cybersecurity, something that has not gone unnoticed. Last year, the IEEE revealed almost half of the global technology leaders it surveyed (47%) expect vulnerability identification and attack prevention to be a top use of AI in 2026. </p><p>That may be some comfort to enterprises and connectivity and solutions providers grappling with the problem of protecting IoT devices and applications. This challenge is compounded by the fact that attackers are increasingly using AI themselves to automate phishing, accelerate reconnaissance and develop adaptive <a href="https://www.techradar.com/best/best-malware-removal">malware</a> that evades traditional detection. However, it is more comforting still, that AI is already making a difference in the IoT, redefining how organizations protect their devices. </p><p>AI-powered anomaly and threat detection (ATD) is helping security teams identify threats like suspicious network traffic and botnet activity faster and improving resilience across large-scale IoT environments, something enterprises must strive for. </p><p>In the recent past, the focus on the IoT was arguably getting devices online. That is no longer the challenge; the test now is keeping them operational: compliance readiness and the flexibility to adapt to ever-evolving commercial and technological changes. It also means maintaining resilience. </p><p>IoT security must follow a clear defend against, detect and react approach to swiftly counter attacks. No one or two of these three measures are enough without the others. </p><h2 id="how-ai-improves-iot-visibility-and-incident-response">How AI improves IoT visibility and incident response</h2><p>AI-powered ATD detects anomalous behavior, such as remote code execution, abnormal port connection or a suspicious IP. These could indicate the beginnings of a cyberattack on an IoT device. It analyses the anomaly and can identify the attack type, be it distributed denial of service (<a href="https://www.techradar.com/news/best-ddos-protection">DDoS</a>), man-in-the-middle (MiTM) or an attempted device takeover. </p><p>ATD can then trigger direct action, if business rules dictate an automated response. This could take the form of threat isolation or referring the incident for full review. </p><h2 id="anomaly-and-threat-detection-protects-over-one-million-devices">Anomaly and threat detection protects over one million devices</h2><p>ATD runs entirely in the mobile core network infrastructure, rather than through software agents on a device, so it can be retrofitted to existing systems.</p><p>Enterprises that have identified IP backdoors and Mirai botnet infections within hours. </p><p>With IP backdoors, ATD detects unusual outbound connections, or traffic, to suspicious IPs. Such backdoors may allow remote control or data exfiltration, both of which leave identifiable behavioral traces.</p><p>In the case of Mirai, anomalous behavior typically exhibits as spikes in outbound traffic, uncommon ports use, or repetitive scanning of external IPs. ATD can flag these irregularities in real time and trigger corrective actions, such as blocking or quarantining the device, blocking or throttling traffic or patching firmware.</p><h2 id="automation-and-analytics-can-shape-the-next-phase-of-iot-security">Automation and analytics can shape the next phase of IoT security</h2><p>There is a clear shift in IoT implementation and management. It is insufficient to plan for device deployment, sit back and gather the data. Without a strategy that accounts for the stresses, threats and changes that beset IoT estates, enterprises risk costly surprises like unplanned site visits and service disruptions. </p><p>AI, through automation and analytics, can shape the next phase of IoT security. Enterprises that detect, analyze and even automatically address, anomalous activity reduce the risk of cyberattack-related outages and inconvenient site visits to access devices. </p><p>Sending field technicians to maintain or repair devices can add significantly to total cost of ownership. Each truck roll, which incurs expenses for labor, fuel, vehicle wear and often missed <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a> opportunities, can add up to over $1000 per site visit. </p><p>IoT downtime, meanwhile disrupts operations and can have a catastrophic reputational, as well as financial, cost. </p><h2 id="how-to-balance-innovation-data-privacy-and-operational-control">How to balance innovation, data privacy and operational control</h2><p>Enterprises are, for the most part, keen to innovate through AI but have understandable questions about data privacy and operational control. </p><p>It is important to know what AI does, in all process integrations, to understand why it does it and to have control that prevents AI deviating from its purpose.</p><p>On data privacy, ATD isn’t installed on IoT devices. Only packet headers from device <a href="https://www.techradar.com/best/best-cloud-storage">cloud</a> communications are mirrored from the mobile core to the ATD engine, with threat levels and AI-driven insights relayed through a customer portal. </p><p>Operational control is maintained through the business rules that dictate how the ATD engine reacts. The option to refer an anomaly for review, for example, gives enterprises the flexibility to incorporate human oversight, under predetermined circumstances. </p><p>This is especially useful when you consider there can be genuine reasons why a SIM may increase or cease communication, that an incident reviewer will understand.</p><h2 id="ai-powered-iot-security">AI-powered IoT security </h2><p>AI is making a difference to the speed, efficiency and depth of response to cyberthreats. Automation and advanced analytics within IoT solutions’ security measures also help enterprises manage costs, by minimizing labor-intensive manual tasks and site visits, and reducing the risk of expensive cyberattack reparations. </p><p>For CISOs, CIOs, product and operations managers seeking to maximize IoT value and protect their enterprise IT domains from external threats, AI-powered ATD offers visibility and actionable insights to take IoT security to the next level.</p><p><a href="https://www.techradar.com/best/best-antivirus"><em>We've reviewed and ranked the best antivirus software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ MacPaw Moonlock antivirus review ]]></title>
                                                                                                <dc:content><![CDATA[ <p>MacPaw has spent years building a reputation as one of the most design-conscious developers in the Mac ecosystem. Its flagship product, <a href="https://www.techradar.com/reviews/cleanmymac-x-for-mac-review" target="_blank">CleanMyMac</a>, has long included a malware removal module powered by Moonlock's engine. In October 2025, the Kyiv-based company spun that security technology into a standalone product: Moonlock, a full-featured antivirus app that goes well beyond a simple scanner.</p><p>Rather than leading with threat counts and detection percentages, Moonlock frames itself as security software that treats users like adults, explaining what malware is, why it matters, and what to do next, instead of firing off opaque alerts. The marketing centers on a 'care, not scare' approach, essentially promising to educate you rather than just bombarding you with red-text alerts.</p><p>While many live in the mythical belief that Macs are immune to viruses, <a href="https://moonlock.com/2025-macos-threat-report" target="_blank">MacPaw's own research</a> reports that 66 percent of Mac users encountered at least one cyber threat last year, with a 67% increase in registered macOS backdoor variants in 2025. The research shows a key message: macOS is not immune, are users are being targeted more frequently than ever.</p><h3 class="article-body__section" id="section-plans-and-pricing"><span>Plans and pricing</span></h3><p>Moonlock starts at $54 per year for a single Mac, with licenses available for 2, 5, or more than 10 devices per subscription. Monthly billing and one-time lifetime license options are also available for those who prefer not to commit to an annual cycle.</p><p>Discounts of up to 67 percent are advertised on multi-year plans, which is worth exploring if you intend to stick with the product long term.</p><p>New users get a seven-day free trial, though a credit card is required to start. That is a common enough practice, but it does mean you will need to remember to cancel if the product does not suit you. To soften the blow of that annual fee, Moonlock offers a 30-day money-back guarantee, which is a considerably more generous safety net than the case-by-case refund process offered by some competitors.</p><p>Current Setapp subscribers get access to Moonlock at no additional charge, which may be the most compelling value proposition for those already in MacPaw's subscription ecosystem. At $54 per year for a single device, standalone pricing lands considerably higher than ClamXAV's three-Mac Home plan at $29.95, a gap worth weighing if budget is a primary concern.</p><h3 class="article-body__section" id="section-features"><span>Features</span></h3><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2624px;"><p class="vanilla-image-block" style="padding-top:63.41%;"><img id="5KepRLD9rYrfaLqHs4edTZ" name="moonlock-scan" alt="A screenshot of a MacPaw Moonlock scan" src="https://cdn.mos.cms.futurecdn.net/5KepRLD9rYrfaLqHs4edTZ.jpg" mos="" align="middle" fullscreen="" width="2624" height="1664" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Moonlock)</span></figcaption></figure><p>Moonlock is organized into six sections: Home, Malware Scanner, VPN, Network Inspector, System Protection, and Security Advisor. That framework reflects a deliberate decision to bundle a security suite rather than deliver a focused antivirus, giving the product a notably broader footprint than Mac-only rivals like ClamXAV.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2624px;"><p class="vanilla-image-block" style="padding-top:66.31%;"><img id="Z7hkDirscjtHPz8KP3X67Q" name="moonlock-malware-scanner" alt="A screenshot of the MacPaw Moonlock malware scanner in action" src="https://cdn.mos.cms.futurecdn.net/Z7hkDirscjtHPz8KP3X67Q.jpg" mos="" align="middle" fullscreen="" width="2624" height="1740" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Moonlock)</span></figcaption></figure><p>Real-time protection runs continuously in the background, monitoring file activity, app behavior, and Mail attachments even when the main application window is closed. The Malware Scanner supports on-demand and scheduled scans, with built-in quarantine and removal tools. Detected threats are accompanied by plain-language explanations rather than raw file paths and specialized terms.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2624px;"><p class="vanilla-image-block" style="padding-top:66.31%;"><img id="ZTwnWuF8rVzcFgSx7DrkdU" name="moonlock-vpn" alt="A screenshot of the MacPaw Moonlock VPN in action" src="https://cdn.mos.cms.futurecdn.net/ZTwnWuF8rVzcFgSx7DrkdU.jpg" mos="" align="middle" fullscreen="" width="2624" height="1740" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Moonlock)</span></figcaption></figure><p>The bundled VPN is a simplified version of MacPaw's ClearVPN, covering around 60 server locations across more than 45 countries. Independent testing found no DNS or WebRTC leaks, and MacPaw maintains a no-logging policy. Speed retention is strong, holding around 82 percent of baseline download speeds on transatlantic connections and up to 96 percent on closer servers.</p><p>Network Inspector adds a country-level connection blocker, permitting users to block outbound traffic to specific regions. System Protection audits macOS's own built-in security settings and walks you through any gaps. Finally, Security Advisor provides a checklist for basic digital hygiene, including practical guidance on habits such as two-factor authentication and app permissions. AI assists with malware classification on the backend, helping the team update threat databases before new strains reach your device.</p><h3 class="article-body__section" id="section-privacy-and-security"><span>Privacy and Security</span></h3><p>From a top level perspective, Moonlock was tested by the third-party laboratory AV-Test in September 2025 and earned it's AV-Test certification. It scored a 5.5/6 in Protection, 4.5/6 in Performance, and a full 6/6 for Usability (which I'll dive into in the next section).</p><p>As for the credibility of the underlying research arm, Moonlock Lab has made several notable contributions to the antivirus landscape, being the first to identify PyStealer on VirusTotal, and the lab has also been cited by the SANS Institute for discovering new variants of the Atomic macOS infostealer.</p><p>Regarding privacy, the VPN operates under a strict zero-logs policy, and all data is processed locally. MacPaw publishes a Trust Center at security.macpaw.com describing its data-handling practices, certifications, and security standards, which is a nice change in transparency from many other antivirus providers.</p><p>The one caveat worth noting is that Moonlock is a recent standalone launch. While the underlying engine has been in use in CleanMyMac for some time, the app itself has a limited history as an independently tested product. But it is worth noting that in the time since the last time AV-Test handled Moonlock, MacPaw have likely taken steps to improve protection and performance.</p><h3 class="article-body__section" id="section-interface-and-in-use"><span>Interface and in use</span></h3><p>The interface is highly polished, modern, and immediately legible, with a two-panel home dashboard that separates tasks on the left from status information on the right. Everything is where you would expect it to be, and the visual hierarchy makes it easy to tell at a glance whether your Mac is protected. </p><p>Instead of a generic 'Threat Resolved' notification, Moonlock tells you what was found, why it poses a risk, and what your options are. I found I was the one to make the final call on whether to remove a flagged item, which sidesteps the infuriating experience of automated deletion that occasionally catches legitimate software.</p><p>The system requirements make it suitable for older devices too, requiring macOS 13 or later and 515MB of disk space. The app runs quickly and, in day-to-day use, does not noticeably drag on performance. Installation requires a MacPaw account, which adds a step that competitors like ClamXAV skip entirely for home users, but the tradeoff is a unified login for managing licenses and accessing support.</p><p>Ultimately, Moonlock is a great option for those looking for an accessible and easily navigable Mac antivirus that doesn't bombard you with any overly-technical language, and performs as though you are the one in control.</p><h3 class="article-body__section" id="section-support"><span>Support</span></h3><p>Moonlock support runs on MacPaw's established infrastructure, with a dedicated knowledge base that covers installation, configuration, and troubleshooting, and those with questions can submit immediate inquiries through the support portal. In-app feedback is also available via the Help menu.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2624px;"><p class="vanilla-image-block" style="padding-top:63.41%;"><img id="Poe8caHraKyHPdShHYkJug" name="moonlock-security-advisor" alt="A screenshot of the Moonlock security advisor in action" src="https://cdn.mos.cms.futurecdn.net/Poe8caHraKyHPdShHYkJug.jpg" mos="" align="middle" fullscreen="" width="2624" height="1664" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Moonlock)</span></figcaption></figure><p>As with many Mac-focused security products, live chat or phone support does not appear to be offered as a standard option. For most home users, the knowledge base and email channel will be sufficient. Teams with more complicated environments should verify support response times before committing, particularly given that Moonlock is a relatively new standalone product and the support documentation is still maturing.</p><h3 class="article-body__section" id="section-the-competition"><span>The competition</span></h3><p>ClamXAV is the most direct rival in the Mac-exclusive antivirus space. At $29.95 per year for three devices, it is considerably cheaper than Moonlock's $54 single-device starting price, and it also holds a perfect AV-Test score compared to Moonlock's test results. It does not include a VPN, network inspection, or the polished onboarding experience Moonlock offers, but for those who want focused antivirus protection at a lower cost, it is a strong option.</p><p><a href="https://www.techradar.com/pro/intego-mac-internet-security-x9-review" target="_blank">Intego Mac Internet Security X9</a> sits at a comparable price point and includes a network monitor, with a longer track record in independent third-party testing. Bitdefender Total Security and Norton AntiVirus Plus both offer wider platform coverage and larger feature sets, making them better fits for households with mixed Windows and Mac devices.</p><p>Those who are already subscribed to CleanMyMac should also note that its built-in malware-scanning module, powered by the same Moonlock engine, continues to function independently. Therefore the question is whether the full Moonlock standalone app adds enough to justify an additional subscription or an upgrade in spending.</p><h2 id="final-verdict">Final verdict</h2><p>Moonlock is one of the most carefully designed security apps I've encountered in the Mac ecosystem. Its interface is excellent, its feature set is broader than most Mac-specific alternatives, and the research team behind it is doing genuinely credible original work. The 30-day money-back guarantee is also a nice addition, despite the need to enter your payment details first.</p><p>At $54 per year for a single Mac, it costs nearly twice as much as ClamXAV's three-device plan. The added value of the bundled VPN and Network Inspector goes some way toward justifying that gap, but those who already have a VPN solution elsewhere may not find the extras compelling enough. Setapp subscribers, on the other hand, get all of this for free as part of a subscription they likely already value.</p><p>For long-standing CleanMyMac users who already benefit from the embedded Moonlock engine, the standalone app offers greater depth, visibility, and control, but it's not a replacement for anything missing. It is a fuller version of the protection they have already been relying on, now with a VPN, richer reporting, and a proper home for the security features that were previously contained within a Mac cleaning utility.</p><p>For Mac users who want a single subscription that covers antivirus, VPN, network monitoring, and system security guidance, Moonlock makes a strong argument. Just go in aware of what you are paying for relative to the alternatives.</p><p><em>You might also be interested in our report on </em><a href="https://www.techradar.com/news/software/applications/30-best-mac-apps-for-just-about-everything-712511"><em>the best Mac apps of the year</em></a><em>.</em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/computing/macs/macpaw-moonlock-antivirus-review</link>
                                                                            <description>
                            <![CDATA[ Moonlock is a relatively new arrival to the Mac antivirus scene, but offers excellent usability and won't hinder the performance of older Macs. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VeqiGPVbAQdSwFCBLk4FdC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QM9hJkWMMHyFDBLSPEBhmG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 06 Jul 2026 13:32:19 +0000</pubDate>                                                                                                                                <updated>Mon, 06 Jul 2026 13:34:33 +0000</updated>
                                                                                                                                            <category><![CDATA[Macs]]></category>
                                                    <category><![CDATA[macOS]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Desktop PCs]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ bryan.wolfe@futurenet.com (Bryan M Wolfe) ]]></author>                    <dc:creator><![CDATA[ Bryan M Wolfe ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsbij4rP7NWfEAnN3HdV87.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                        <dc:contributor><![CDATA[ Benedict Collins ]]></dc:contributor>
                                                                    <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QM9hJkWMMHyFDBLSPEBhmG-1280-80.jpg">
                                                            <media:credit><![CDATA[Moonlock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A screenshot of the MacPaw Moonlock dashboard]]></media:description>                                                            <media:text><![CDATA[A screenshot of the MacPaw Moonlock dashboard]]></media:text>
                                <media:title type="plain"><![CDATA[A screenshot of the MacPaw Moonlock dashboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QM9hJkWMMHyFDBLSPEBhmG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>MacPaw has spent years building a reputation as one of the most design-conscious developers in the Mac ecosystem. Its flagship product, <a href="https://www.techradar.com/reviews/cleanmymac-x-for-mac-review" target="_blank">CleanMyMac</a>, has long included a malware removal module powered by Moonlock's engine. In October 2025, the Kyiv-based company spun that security technology into a standalone product: Moonlock, a full-featured antivirus app that goes well beyond a simple scanner.</p><p>Rather than leading with threat counts and detection percentages, Moonlock frames itself as security software that treats users like adults, explaining what malware is, why it matters, and what to do next, instead of firing off opaque alerts. The marketing centers on a 'care, not scare' approach, essentially promising to educate you rather than just bombarding you with red-text alerts.</p><p>While many live in the mythical belief that Macs are immune to viruses, <a href="https://moonlock.com/2025-macos-threat-report" target="_blank">MacPaw's own research</a> reports that 66 percent of Mac users encountered at least one cyber threat last year, with a 67% increase in registered macOS backdoor variants in 2025. The research shows a key message: macOS is not immune, are users are being targeted more frequently than ever.</p><h3 class="article-body__section" id="section-plans-and-pricing"><span>Plans and pricing</span></h3><p>Moonlock starts at $54 per year for a single Mac, with licenses available for 2, 5, or more than 10 devices per subscription. Monthly billing and one-time lifetime license options are also available for those who prefer not to commit to an annual cycle.</p><p>Discounts of up to 67 percent are advertised on multi-year plans, which is worth exploring if you intend to stick with the product long term.</p><p>New users get a seven-day free trial, though a credit card is required to start. That is a common enough practice, but it does mean you will need to remember to cancel if the product does not suit you. To soften the blow of that annual fee, Moonlock offers a 30-day money-back guarantee, which is a considerably more generous safety net than the case-by-case refund process offered by some competitors.</p><p>Current Setapp subscribers get access to Moonlock at no additional charge, which may be the most compelling value proposition for those already in MacPaw's subscription ecosystem. At $54 per year for a single device, standalone pricing lands considerably higher than ClamXAV's three-Mac Home plan at $29.95, a gap worth weighing if budget is a primary concern.</p><h3 class="article-body__section" id="section-features"><span>Features</span></h3><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2624px;"><p class="vanilla-image-block" style="padding-top:63.41%;"><img id="5KepRLD9rYrfaLqHs4edTZ" name="moonlock-scan" alt="A screenshot of a MacPaw Moonlock scan" src="https://cdn.mos.cms.futurecdn.net/5KepRLD9rYrfaLqHs4edTZ.jpg" mos="" align="middle" fullscreen="" width="2624" height="1664" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Moonlock)</span></figcaption></figure><p>Moonlock is organized into six sections: Home, Malware Scanner, VPN, Network Inspector, System Protection, and Security Advisor. That framework reflects a deliberate decision to bundle a security suite rather than deliver a focused antivirus, giving the product a notably broader footprint than Mac-only rivals like ClamXAV.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2624px;"><p class="vanilla-image-block" style="padding-top:66.31%;"><img id="Z7hkDirscjtHPz8KP3X67Q" name="moonlock-malware-scanner" alt="A screenshot of the MacPaw Moonlock malware scanner in action" src="https://cdn.mos.cms.futurecdn.net/Z7hkDirscjtHPz8KP3X67Q.jpg" mos="" align="middle" fullscreen="" width="2624" height="1740" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Moonlock)</span></figcaption></figure><p>Real-time protection runs continuously in the background, monitoring file activity, app behavior, and Mail attachments even when the main application window is closed. The Malware Scanner supports on-demand and scheduled scans, with built-in quarantine and removal tools. Detected threats are accompanied by plain-language explanations rather than raw file paths and specialized terms.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2624px;"><p class="vanilla-image-block" style="padding-top:66.31%;"><img id="ZTwnWuF8rVzcFgSx7DrkdU" name="moonlock-vpn" alt="A screenshot of the MacPaw Moonlock VPN in action" src="https://cdn.mos.cms.futurecdn.net/ZTwnWuF8rVzcFgSx7DrkdU.jpg" mos="" align="middle" fullscreen="" width="2624" height="1740" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Moonlock)</span></figcaption></figure><p>The bundled VPN is a simplified version of MacPaw's ClearVPN, covering around 60 server locations across more than 45 countries. Independent testing found no DNS or WebRTC leaks, and MacPaw maintains a no-logging policy. Speed retention is strong, holding around 82 percent of baseline download speeds on transatlantic connections and up to 96 percent on closer servers.</p><p>Network Inspector adds a country-level connection blocker, permitting users to block outbound traffic to specific regions. System Protection audits macOS's own built-in security settings and walks you through any gaps. Finally, Security Advisor provides a checklist for basic digital hygiene, including practical guidance on habits such as two-factor authentication and app permissions. AI assists with malware classification on the backend, helping the team update threat databases before new strains reach your device.</p><h3 class="article-body__section" id="section-privacy-and-security"><span>Privacy and Security</span></h3><p>From a top level perspective, Moonlock was tested by the third-party laboratory AV-Test in September 2025 and earned it's AV-Test certification. It scored a 5.5/6 in Protection, 4.5/6 in Performance, and a full 6/6 for Usability (which I'll dive into in the next section).</p><p>As for the credibility of the underlying research arm, Moonlock Lab has made several notable contributions to the antivirus landscape, being the first to identify PyStealer on VirusTotal, and the lab has also been cited by the SANS Institute for discovering new variants of the Atomic macOS infostealer.</p><p>Regarding privacy, the VPN operates under a strict zero-logs policy, and all data is processed locally. MacPaw publishes a Trust Center at security.macpaw.com describing its data-handling practices, certifications, and security standards, which is a nice change in transparency from many other antivirus providers.</p><p>The one caveat worth noting is that Moonlock is a recent standalone launch. While the underlying engine has been in use in CleanMyMac for some time, the app itself has a limited history as an independently tested product. But it is worth noting that in the time since the last time AV-Test handled Moonlock, MacPaw have likely taken steps to improve protection and performance.</p><h3 class="article-body__section" id="section-interface-and-in-use"><span>Interface and in use</span></h3><p>The interface is highly polished, modern, and immediately legible, with a two-panel home dashboard that separates tasks on the left from status information on the right. Everything is where you would expect it to be, and the visual hierarchy makes it easy to tell at a glance whether your Mac is protected. </p><p>Instead of a generic 'Threat Resolved' notification, Moonlock tells you what was found, why it poses a risk, and what your options are. I found I was the one to make the final call on whether to remove a flagged item, which sidesteps the infuriating experience of automated deletion that occasionally catches legitimate software.</p><p>The system requirements make it suitable for older devices too, requiring macOS 13 or later and 515MB of disk space. The app runs quickly and, in day-to-day use, does not noticeably drag on performance. Installation requires a MacPaw account, which adds a step that competitors like ClamXAV skip entirely for home users, but the tradeoff is a unified login for managing licenses and accessing support.</p><p>Ultimately, Moonlock is a great option for those looking for an accessible and easily navigable Mac antivirus that doesn't bombard you with any overly-technical language, and performs as though you are the one in control.</p><h3 class="article-body__section" id="section-support"><span>Support</span></h3><p>Moonlock support runs on MacPaw's established infrastructure, with a dedicated knowledge base that covers installation, configuration, and troubleshooting, and those with questions can submit immediate inquiries through the support portal. In-app feedback is also available via the Help menu.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2624px;"><p class="vanilla-image-block" style="padding-top:63.41%;"><img id="Poe8caHraKyHPdShHYkJug" name="moonlock-security-advisor" alt="A screenshot of the Moonlock security advisor in action" src="https://cdn.mos.cms.futurecdn.net/Poe8caHraKyHPdShHYkJug.jpg" mos="" align="middle" fullscreen="" width="2624" height="1664" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Moonlock)</span></figcaption></figure><p>As with many Mac-focused security products, live chat or phone support does not appear to be offered as a standard option. For most home users, the knowledge base and email channel will be sufficient. Teams with more complicated environments should verify support response times before committing, particularly given that Moonlock is a relatively new standalone product and the support documentation is still maturing.</p><h3 class="article-body__section" id="section-the-competition"><span>The competition</span></h3><p>ClamXAV is the most direct rival in the Mac-exclusive antivirus space. At $29.95 per year for three devices, it is considerably cheaper than Moonlock's $54 single-device starting price, and it also holds a perfect AV-Test score compared to Moonlock's test results. It does not include a VPN, network inspection, or the polished onboarding experience Moonlock offers, but for those who want focused antivirus protection at a lower cost, it is a strong option.</p><p><a href="https://www.techradar.com/pro/intego-mac-internet-security-x9-review" target="_blank">Intego Mac Internet Security X9</a> sits at a comparable price point and includes a network monitor, with a longer track record in independent third-party testing. Bitdefender Total Security and Norton AntiVirus Plus both offer wider platform coverage and larger feature sets, making them better fits for households with mixed Windows and Mac devices.</p><p>Those who are already subscribed to CleanMyMac should also note that its built-in malware-scanning module, powered by the same Moonlock engine, continues to function independently. Therefore the question is whether the full Moonlock standalone app adds enough to justify an additional subscription or an upgrade in spending.</p><h2 id="final-verdict">Final verdict</h2><p>Moonlock is one of the most carefully designed security apps I've encountered in the Mac ecosystem. Its interface is excellent, its feature set is broader than most Mac-specific alternatives, and the research team behind it is doing genuinely credible original work. The 30-day money-back guarantee is also a nice addition, despite the need to enter your payment details first.</p><p>At $54 per year for a single Mac, it costs nearly twice as much as ClamXAV's three-device plan. The added value of the bundled VPN and Network Inspector goes some way toward justifying that gap, but those who already have a VPN solution elsewhere may not find the extras compelling enough. Setapp subscribers, on the other hand, get all of this for free as part of a subscription they likely already value.</p><p>For long-standing CleanMyMac users who already benefit from the embedded Moonlock engine, the standalone app offers greater depth, visibility, and control, but it's not a replacement for anything missing. It is a fuller version of the protection they have already been relying on, now with a VPN, richer reporting, and a proper home for the security features that were previously contained within a Mac cleaning utility.</p><p>For Mac users who want a single subscription that covers antivirus, VPN, network monitoring, and system security guidance, Moonlock makes a strong argument. Just go in aware of what you are paying for relative to the alternatives.</p><p><em>You might also be interested in our report on </em><a href="https://www.techradar.com/news/software/applications/30-best-mac-apps-for-just-about-everything-712511"><em>the best Mac apps of the year</em></a><em>.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ We built a trillion-dollar security industry on top of an unprotected layer ]]></title>
                                                                                                <dc:content><![CDATA[ <p>For thirty years, the hardest part of a sophisticated cyberattack was the human labor behind it. Finding the vulnerability. Writing the exploit. Chaining the access. Staying quiet long enough to matter. </p><p>That work required teams, time, and tradecraft. It’s the reason nation-state operations looked different from criminal ones, and why most organizations could plan around the gap between them.</p><p>That gap is closing. </p><p>We are entering what I think of as the Mythos era, in which machines can do in minutes what used to take skilled human operators months. <a href="https://www.techradar.com/best/best-online-cyber-security-courses">Cybersecurity</a> defenses are improving, but the layer where final decisions are made, the human one, is now the easiest to exploit. </p><p>The advantage that protected most organizations, most of the time, is going with it. Precision at scale is no longer a contradiction. It’s a feature.</p><h2 id="the-human-stack-what-it-is-and-why-it-matters">The Human Stack: what it is and why it matters</h2><p>Most of the conversation about this shift has focused on what these systems do to vulnerabilities. That conversation is accurate, but incomplete. The harder problem is what machine-speed attacks do to the systems those vulnerabilities ultimately route through: systems that depend on human decisions.</p><p>That’s a layer most <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> programs don’t explicitly own. I call it the Human Stack, the point where every system finally comes down to a person deciding whether a wire transfer goes through, whether an email is trusted, or whether a voice on a phone call is real. We have spent a generation hardening everything above it, and almost nothing on the layer itself.</p><p>For most of cybersecurity's history, that was a tolerable bet. Attackers had to choose between going wide and crude, or narrow and precise. The Human Stack held because precision didn’t scale, and scale didn’t achieve precision.</p><p>That tradeoff is gone.</p><h2 id="what-the-next-wave-of-attacks-looks-like">What the next wave of attacks looks like</h2><p>The next wave won’t arrive as <a href="https://www.techradar.com/best/best-malware-removal">malware</a>. It’ll arrive as evidence. A voicemail that sounds exactly like the person it claims to be. A video call with a face you have known for ten years. An email thread that picks up a conversation you actually had, in the cadence you actually use, referencing a project that actually exists. The technical indicators will be clean, and the social indicators will be perfect. The only thing that will be wrong is the conclusion the human is being led to.</p><p>Last year, I spent time with the team behind Midnight in the War Room, a documentary premiering August 5 at Black Hat USA. It brings together over 50 experts, from global CISOs and military strategists to reformed hackers and victims of cyber conflict. The conversations were about something that has been happening for a long time and is about to be accelerated: the industrialization of social engineering, and the steady weaponization of the behavioral attack surface.</p><p>That surface doesn't stop at your perimeter. It extends through every vendor, managed service provider, and <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud services</a> administrator your business depends on. Your operations going offline may have nothing to do with your own people, and everything to do with someone three vendors deep making a decision under synthetic pressure.</p><h2 id="what-this-means-for-enterprises">What this means for enterprises</h2><p>For businesses, this isn’t theoretical. Financial risk is direct. We're already seeing fraudulent wire transfers, manipulated approval chains, and finance chiefs impersonated so convincingly that payments clear before anyone notices.</p><p>Operational disruption can come with no malware on your systems. The behavioral attack surface doesn't stop at your perimeter. It extends through every vendor, managed service provider, law firm, auditor, and cloud administrator your business depends on. </p><p>A compromised third party, manipulated through a perfectly constructed social engineering campaign, can take your operations offline without leaving a fingerprint anywhere near your network. Most organizations scrutinize their own security posture far more rigorously than the human decision-making environments of the third parties they rely on, leaving that exposure largely unmanaged. </p><p>Regulators and insurers are starting to ask harder questions about that exposure, and most organizations don't yet have good answers.</p><h2 id="the-shift-from-prevention-to-resilience">The shift from prevention to resilience</h2><p>There's a second shift that boards need to start preparing for, and it's bigger than any single control or technology. We're leaving the era in which security success is measured by attacks prevented. We're entering one in which the realistic measure is how quickly an organization recovers when belief fails.</p><p>Prevention still matters, and the investments organizations have made in it have been the right ones. But in a world where attacks will sometimes succeed because they're indistinguishable from legitimate activity, prevention alone is no longer a coherent strategy. Resilience is.</p><p>What resilience means at the human layer is different from what it means at the technical one. Technical resilience is about systems that fail gracefully and recover quickly. Human resilience is about decision-making environments that can absorb a successful deception, recognize it, and contain it before it compounds. Most organizations have invested in the first. Very few have invested in the second. That's the gap the next decade will judge us on.</p><h2 id="what-leaders-should-do">What leaders should do</h2><p>The security stack remains necessary, but this era exposes that even the best systems hand their hardest decisions to humans, and we haven't invested in that layer with the same rigor. Here’s where to start:</p><p><strong>Measure recovery, not just prevention</strong></p><p>When belief fails, how fast can your organization catch it, contain it, and get back up? That has to be designed into your operating model now, not figured out after an incident. </p><p><strong>Design for decision-making under deception</strong></p><p>Training people to spot phishing isn't sufficient when the phishing email is indistinguishable from a real one. Build institutional processes that don't rely on a single person making the right call under pressure.</p><p><strong>Treat people as operational infrastructure. </strong></p><p>Human judgment is a critical system. It needs redundancy and failure protocols, just like any other.</p><p><strong>Extend your security culture to your vendor ecosystem</strong></p><p>The behavioral attack surface runs through your entire supply chain. Your third-party risk program needs to account for the human layer, not just the technical one.</p><h2 id="the-window-is-closing">The window is closing</h2><p>Midnight in the War Room will make this visible in a way an op-ed cannot. </p><p>The Mythos era did not create this problem. It revealed it. The cost of exploiting human decision-making precisely was high enough to keep most attackers out. That barrier is collapsing now.</p><p>What comes next will not announce itself. It’ll arrive looking like someone you trust, asking for something that feels completely reasonable, right up until the moment it isn't.</p><p>The question is no longer whether your systems can withstand attack. It's whether your people are prepared to make decisions in a world where the evidence itself can no longer be trusted, and whether your organization is built to recover when those decisions go wrong.</p><p><em></em><a href="https://www.techradar.com/best/best-cloud-antivirus"><em>We've reviewed and ranked the best cloud antivirus</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/we-built-a-trillion-dollar-security-industry-on-top-of-an-unprotected-layer</link>
                                                                            <description>
                            <![CDATA[ As attackers increasingly exploit the 'human stack', organizations must shift from purely technical defenses to behavior-based resilience. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sMHxNdB4WmJWK3NYsDeq6N</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wV66hEbpJdAc4iPB7RwtkK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 06 Jul 2026 10:46:42 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sarah Gosler ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wV66hEbpJdAc4iPB7RwtkK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An exclamation mark inside a red warning triangle, surrounded by email symbols, superimposed on someone typing on a laptop]]></media:description>                                                            <media:text><![CDATA[An exclamation mark inside a red warning triangle, surrounded by email symbols, superimposed on someone typing on a laptop]]></media:text>
                                <media:title type="plain"><![CDATA[An exclamation mark inside a red warning triangle, surrounded by email symbols, superimposed on someone typing on a laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wV66hEbpJdAc4iPB7RwtkK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>For thirty years, the hardest part of a sophisticated cyberattack was the human labor behind it. Finding the vulnerability. Writing the exploit. Chaining the access. Staying quiet long enough to matter. </p><p>That work required teams, time, and tradecraft. It’s the reason nation-state operations looked different from criminal ones, and why most organizations could plan around the gap between them.</p><p>That gap is closing. </p><p>We are entering what I think of as the Mythos era, in which machines can do in minutes what used to take skilled human operators months. <a href="https://www.techradar.com/best/best-online-cyber-security-courses">Cybersecurity</a> defenses are improving, but the layer where final decisions are made, the human one, is now the easiest to exploit. </p><p>The advantage that protected most organizations, most of the time, is going with it. Precision at scale is no longer a contradiction. It’s a feature.</p><h2 id="the-human-stack-what-it-is-and-why-it-matters">The Human Stack: what it is and why it matters</h2><p>Most of the conversation about this shift has focused on what these systems do to vulnerabilities. That conversation is accurate, but incomplete. The harder problem is what machine-speed attacks do to the systems those vulnerabilities ultimately route through: systems that depend on human decisions.</p><p>That’s a layer most <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> programs don’t explicitly own. I call it the Human Stack, the point where every system finally comes down to a person deciding whether a wire transfer goes through, whether an email is trusted, or whether a voice on a phone call is real. We have spent a generation hardening everything above it, and almost nothing on the layer itself.</p><p>For most of cybersecurity's history, that was a tolerable bet. Attackers had to choose between going wide and crude, or narrow and precise. The Human Stack held because precision didn’t scale, and scale didn’t achieve precision.</p><p>That tradeoff is gone.</p><h2 id="what-the-next-wave-of-attacks-looks-like">What the next wave of attacks looks like</h2><p>The next wave won’t arrive as <a href="https://www.techradar.com/best/best-malware-removal">malware</a>. It’ll arrive as evidence. A voicemail that sounds exactly like the person it claims to be. A video call with a face you have known for ten years. An email thread that picks up a conversation you actually had, in the cadence you actually use, referencing a project that actually exists. The technical indicators will be clean, and the social indicators will be perfect. The only thing that will be wrong is the conclusion the human is being led to.</p><p>Last year, I spent time with the team behind Midnight in the War Room, a documentary premiering August 5 at Black Hat USA. It brings together over 50 experts, from global CISOs and military strategists to reformed hackers and victims of cyber conflict. The conversations were about something that has been happening for a long time and is about to be accelerated: the industrialization of social engineering, and the steady weaponization of the behavioral attack surface.</p><p>That surface doesn't stop at your perimeter. It extends through every vendor, managed service provider, and <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud services</a> administrator your business depends on. Your operations going offline may have nothing to do with your own people, and everything to do with someone three vendors deep making a decision under synthetic pressure.</p><h2 id="what-this-means-for-enterprises">What this means for enterprises</h2><p>For businesses, this isn’t theoretical. Financial risk is direct. We're already seeing fraudulent wire transfers, manipulated approval chains, and finance chiefs impersonated so convincingly that payments clear before anyone notices.</p><p>Operational disruption can come with no malware on your systems. The behavioral attack surface doesn't stop at your perimeter. It extends through every vendor, managed service provider, law firm, auditor, and cloud administrator your business depends on. </p><p>A compromised third party, manipulated through a perfectly constructed social engineering campaign, can take your operations offline without leaving a fingerprint anywhere near your network. Most organizations scrutinize their own security posture far more rigorously than the human decision-making environments of the third parties they rely on, leaving that exposure largely unmanaged. </p><p>Regulators and insurers are starting to ask harder questions about that exposure, and most organizations don't yet have good answers.</p><h2 id="the-shift-from-prevention-to-resilience">The shift from prevention to resilience</h2><p>There's a second shift that boards need to start preparing for, and it's bigger than any single control or technology. We're leaving the era in which security success is measured by attacks prevented. We're entering one in which the realistic measure is how quickly an organization recovers when belief fails.</p><p>Prevention still matters, and the investments organizations have made in it have been the right ones. But in a world where attacks will sometimes succeed because they're indistinguishable from legitimate activity, prevention alone is no longer a coherent strategy. Resilience is.</p><p>What resilience means at the human layer is different from what it means at the technical one. Technical resilience is about systems that fail gracefully and recover quickly. Human resilience is about decision-making environments that can absorb a successful deception, recognize it, and contain it before it compounds. Most organizations have invested in the first. Very few have invested in the second. That's the gap the next decade will judge us on.</p><h2 id="what-leaders-should-do">What leaders should do</h2><p>The security stack remains necessary, but this era exposes that even the best systems hand their hardest decisions to humans, and we haven't invested in that layer with the same rigor. Here’s where to start:</p><p><strong>Measure recovery, not just prevention</strong></p><p>When belief fails, how fast can your organization catch it, contain it, and get back up? That has to be designed into your operating model now, not figured out after an incident. </p><p><strong>Design for decision-making under deception</strong></p><p>Training people to spot phishing isn't sufficient when the phishing email is indistinguishable from a real one. Build institutional processes that don't rely on a single person making the right call under pressure.</p><p><strong>Treat people as operational infrastructure. </strong></p><p>Human judgment is a critical system. It needs redundancy and failure protocols, just like any other.</p><p><strong>Extend your security culture to your vendor ecosystem</strong></p><p>The behavioral attack surface runs through your entire supply chain. Your third-party risk program needs to account for the human layer, not just the technical one.</p><h2 id="the-window-is-closing">The window is closing</h2><p>Midnight in the War Room will make this visible in a way an op-ed cannot. </p><p>The Mythos era did not create this problem. It revealed it. The cost of exploiting human decision-making precisely was high enough to keep most attackers out. That barrier is collapsing now.</p><p>What comes next will not announce itself. It’ll arrive looking like someone you trust, asking for something that feels completely reasonable, right up until the moment it isn't.</p><p>The question is no longer whether your systems can withstand attack. It's whether your people are prepared to make decisions in a world where the evidence itself can no longer be trusted, and whether your organization is built to recover when those decisions go wrong.</p><p><em></em><a href="https://www.techradar.com/best/best-cloud-antivirus"><em>We've reviewed and ranked the best cloud antivirus</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ That free VPN Chrome and Firefox extension may be reading your clipboard every half a second, researchers warn ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Researchers found "VPN Go" extensions for Chrome and Firefox secretly harvesting copied text</strong></li><li><strong>The clipboard theft was not there at launch and arrived through a later update</strong></li><li><strong>Anything copied while the extension was active should now be treated as exposed</strong></li></ul><p>Security researchers at Socket found two browser extensions distributed under the "VPN Go: Free VPN" branding, one listed on the Chrome Web Store and one on Firefox Add-ons, to secretly harvest copied text. </p><p>Both present themselves as free VPN tools with working proxy features. Underneath, <a href="https://socket.dev/blog/chrome-and-firefox-extensions-free-vpns-add-clipboard-stealers" target="_blank" rel="nofollow">Socket says</a>, both also run a clipboard stealer that continuously watches copied text and sends it to infrastructure controlled by the attacker.</p><p>According to Socket, the clipboard theft was not present when the extensions first appeared. It was added later, through an ordinary-looking update, after the extensions had already built up a base of trusting users. That staged approach is exactly what makes this kind of threat so hard to spot, and why even a fairly cautious user can end up exposed.</p><p>For anyone weighing up a no-cost privacy tool, it is worth knowing that not every free option behaves like this, and the <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> services are tested precisely so you do not have to take this kind of gamble. But this case shows how thin the line can be between a useful free extension and a data-harvesting one.</p><h2 id="what-socket-s-research-uncovered">What Socket's research uncovered</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1213px;"><p class="vanilla-image-block" style="padding-top:56.22%;"><img id="7b3ucMmXHaTYWRvoZbT8T9" name="VPN Go" alt="VPN Go in Chrome Web Store" src="https://cdn.mos.cms.futurecdn.net/7b3ucMmXHaTYWRvoZbT8T9.png" mos="" align="middle" fullscreen="" width="1213" height="682" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Chrome)</span></figcaption></figure><p>Socket says the earliest analyzed builds behaved like ordinary proxy extensions, with no confirmed clipboard theft. </p><p>On <a href="https://www.techradar.com/reviews/google-chrome">Chrome</a>, that changed with version 1.1, when the extension added a script that reads the clipboard and ships those chunks off to a hardcoded address. The <a href="https://www.techradar.com/reviews/mozilla-firefox">Firefox</a> version followed the same path slightly later, moving the same theft loop into its background script.</p><p>Once active, the monitoring is relentless. The Chrome content script checks the clipboard roughly every half a second, according to Socket's analysis, while the Firefox build polls every 1.5 seconds. </p><p>Each newly copied value is tagged with a session identifier so it can be reassembled on the other end, then sent out over plain HTTP. All of this was happening while the two apps' privacy policies stated that the tools did not collect, store, or share user data and did not keep activity logs.</p><p>TechRadar has reached out to VPN Go for comment, but both email addresses bounced, and both extensions have since been pulled from their stores.</p><h2 id="why-clipboard-stealers-are-dangerous-for-users">Why clipboard stealers are dangerous for users</h2><p>The reason clipboard theft is so effective is that it abuses something completely routine. People copy and paste sensitive information all day, and it's not careless to do so. Password managers rely on exactly that: copying long, unique passwords into your accounts.</p><p>An extension that can silently read the clipboard has access to all of this information; it just has to wait for you to copy the right thing. If you have used either of the two extensions in question, you should treat any information you've copied during that time as exposed.</p><p>Researchers have repeatedly found free VPN extensions doing things their users never agreed to. Recent reporting has covered a <a href="https://www.techradar.com/vpn/vpn-privacy-security/this-free-chrome-vpn-extension-found-to-spy-on-its-100k-users-uninstall-it-now">free Chrome VPN extension caught taking screenshots</a> of every page its users visited, and a <a href="https://www.techradar.com/vpn/vpn-privacy-security/malicious-free-vpn-extension-makes-a-comeback">malicious free VPN extension that resurfaced</a> after being removed, returning in a more evasive form. </p><p>The pattern is consistent enough that it is worth treating any unknown free VPN extension with caution by default. That caution matters: TechRadar's own polling found that <a href="https://www.techradar.com/vpn/vpn-privacy-security/to-pay-or-not-to-pay-nearly-1-in-4-techradar-readers-say-they-use-free-vpns-despite-the-risks">nearly 1 in 4 readers use free VPNs</a> despite knowing the risks.</p><div data-widget-type="multimodelreview" data-model-name="NordVPN,Surfshark,Proton VPN" data-widget-title="Today's best VPN deals" class="hawk-root"></div><h2 id="how-to-stay-safe-4">How to stay safe</h2><p>If you want the protection a VPN offers without rolling the dice, stick to providers with a track record and independent testing behind them. </p><p>A reputable paid service, or one of the carefully vetted <a href="https://www.techradar.com/vpn/best-free-vpn">best free VPN</a> options, is a far safer bet than an unknown extension promising unlimited access for nothing. As the saying goes, when the product is free, there is a decent chance that you are the product.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/vpn/vpn-privacy-security/that-free-vpn-chrome-and-firefox-extension-may-be-reading-your-clipboard-every-half-a-second-researchers-warn</link>
                                                                            <description>
                            <![CDATA[ Researchers at Socket found two "VPN Go" browser extensions for Chrome and Firefox that posed as free VPNs while quietly stealing clipboard data through later updates. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">drttgaXd7xBrBjVNgZ6gbP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5pmsJs3KfnrtbsM98UsnG9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 01 Jul 2026 13:22:10 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[VPN Privacy &amp; Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ monicajwrites@gmail.com (Monica J. White) ]]></author>                    <dc:creator><![CDATA[ Monica J. White ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/6AQ4y5nzk8kQ47Yp69GERj.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Monica is a journalist with over a decade of experience in covering technology.&lt;/p&gt;&lt;p&gt;She writes about the latest developments in computing, which means anything from computer chips made out of paper to cutting-edge desktop processors. Her coverage includes CPUs, GPUs, and everything else that goes into a PC or a laptop, but also peripherals.&lt;/p&gt;&lt;p&gt;GPUs are Monica’s main area of interest, and nothing thrills her quite like that time every couple of years when new graphics cards hit the market. She’s always keeping tabs on the latest from Nvidia, AMD, and Intel, including both the hardware and the software that powers our PCs.&lt;/p&gt;&lt;p&gt;As an avid gamer, her focus is always on the consumer and whether something works well and provides adequate value for the money. She believes that PC building can be intimidating, so her goal is to explain complex concepts in an approachable manner while still digging into the technical nitty-gritty we all love to learn more about.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5pmsJs3KfnrtbsM98UsnG9-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Malware kan ställa till med oreda]]></media:description>                                                            <media:text><![CDATA[Android phone malware]]></media:text>
                                <media:title type="plain"><![CDATA[Android phone malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5pmsJs3KfnrtbsM98UsnG9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers found "VPN Go" extensions for Chrome and Firefox secretly harvesting copied text</strong></li><li><strong>The clipboard theft was not there at launch and arrived through a later update</strong></li><li><strong>Anything copied while the extension was active should now be treated as exposed</strong></li></ul><p>Security researchers at Socket found two browser extensions distributed under the "VPN Go: Free VPN" branding, one listed on the Chrome Web Store and one on Firefox Add-ons, to secretly harvest copied text. </p><p>Both present themselves as free VPN tools with working proxy features. Underneath, <a href="https://socket.dev/blog/chrome-and-firefox-extensions-free-vpns-add-clipboard-stealers" target="_blank" rel="nofollow">Socket says</a>, both also run a clipboard stealer that continuously watches copied text and sends it to infrastructure controlled by the attacker.</p><p>According to Socket, the clipboard theft was not present when the extensions first appeared. It was added later, through an ordinary-looking update, after the extensions had already built up a base of trusting users. That staged approach is exactly what makes this kind of threat so hard to spot, and why even a fairly cautious user can end up exposed.</p><p>For anyone weighing up a no-cost privacy tool, it is worth knowing that not every free option behaves like this, and the <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> services are tested precisely so you do not have to take this kind of gamble. But this case shows how thin the line can be between a useful free extension and a data-harvesting one.</p><h2 id="what-socket-s-research-uncovered">What Socket's research uncovered</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1213px;"><p class="vanilla-image-block" style="padding-top:56.22%;"><img id="7b3ucMmXHaTYWRvoZbT8T9" name="VPN Go" alt="VPN Go in Chrome Web Store" src="https://cdn.mos.cms.futurecdn.net/7b3ucMmXHaTYWRvoZbT8T9.png" mos="" align="middle" fullscreen="" width="1213" height="682" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Chrome)</span></figcaption></figure><p>Socket says the earliest analyzed builds behaved like ordinary proxy extensions, with no confirmed clipboard theft. </p><p>On <a href="https://www.techradar.com/reviews/google-chrome">Chrome</a>, that changed with version 1.1, when the extension added a script that reads the clipboard and ships those chunks off to a hardcoded address. The <a href="https://www.techradar.com/reviews/mozilla-firefox">Firefox</a> version followed the same path slightly later, moving the same theft loop into its background script.</p><p>Once active, the monitoring is relentless. The Chrome content script checks the clipboard roughly every half a second, according to Socket's analysis, while the Firefox build polls every 1.5 seconds. </p><p>Each newly copied value is tagged with a session identifier so it can be reassembled on the other end, then sent out over plain HTTP. All of this was happening while the two apps' privacy policies stated that the tools did not collect, store, or share user data and did not keep activity logs.</p><p>TechRadar has reached out to VPN Go for comment, but both email addresses bounced, and both extensions have since been pulled from their stores.</p><h2 id="why-clipboard-stealers-are-dangerous-for-users">Why clipboard stealers are dangerous for users</h2><p>The reason clipboard theft is so effective is that it abuses something completely routine. People copy and paste sensitive information all day, and it's not careless to do so. Password managers rely on exactly that: copying long, unique passwords into your accounts.</p><p>An extension that can silently read the clipboard has access to all of this information; it just has to wait for you to copy the right thing. If you have used either of the two extensions in question, you should treat any information you've copied during that time as exposed.</p><p>Researchers have repeatedly found free VPN extensions doing things their users never agreed to. Recent reporting has covered a <a href="https://www.techradar.com/vpn/vpn-privacy-security/this-free-chrome-vpn-extension-found-to-spy-on-its-100k-users-uninstall-it-now">free Chrome VPN extension caught taking screenshots</a> of every page its users visited, and a <a href="https://www.techradar.com/vpn/vpn-privacy-security/malicious-free-vpn-extension-makes-a-comeback">malicious free VPN extension that resurfaced</a> after being removed, returning in a more evasive form. </p><p>The pattern is consistent enough that it is worth treating any unknown free VPN extension with caution by default. That caution matters: TechRadar's own polling found that <a href="https://www.techradar.com/vpn/vpn-privacy-security/to-pay-or-not-to-pay-nearly-1-in-4-techradar-readers-say-they-use-free-vpns-despite-the-risks">nearly 1 in 4 readers use free VPNs</a> despite knowing the risks.</p><div data-widget-type="multimodelreview" data-model-name="NordVPN,Surfshark,Proton VPN" data-widget-title="Today's best VPN deals" class="hawk-root"></div><h2 id="how-to-stay-safe-4">How to stay safe</h2><p>If you want the protection a VPN offers without rolling the dice, stick to providers with a track record and independent testing behind them. </p><p>A reputable paid service, or one of the carefully vetted <a href="https://www.techradar.com/vpn/best-free-vpn">best free VPN</a> options, is a far safer bet than an unknown extension promising unlimited access for nothing. As the saying goes, when the product is free, there is a decent chance that you are the product.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NAIC confirms data breach with ShinyHunters claiming 3.1TB of data stolen in Oracle zero-day attack ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>NAIC confirmed a cyberattack exploiting an Oracle PeopleSoft zero‑day, with ShinyHunters claiming theft of 3.1TB of data</strong></li><li><strong>Stolen cache allegedly includes insurer filings, credit rating files, AWS logs, configs, and PII; NAIC says only financial reports and technical data were taken</strong></li><li><strong>Incident spotted June 11, disclosed June 17; files leaked online suggest NAIC did not pay ransom, as ShinyHunters continues exploiting the zero‑day across 100+ organizations</strong></li></ul><p>The National Association of Insurance Commissioners (NAIC) confirmed suffering a cyberattack that resulted in the stolen data being leaked on the dark web. While the company did not name the group responsible, or mentioned the size of the stolen cache, the infamous ShinyHunters claimed responsibility and stated they snatched around 3.1TB of information.</p><p>In a security notice published on the NAIC website, it was explained that the attackers managed to exploit a <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">zero-day vulnerability</a> in Oracle PeopleSoft. This is an <a href="https://www.techradar.com/best/best-erp-software" target="_blank">enterprise resource planning</a> (ERP) software suite, designed to help businesses manage employees, finances, supply chains, and more. Citing Google Mandiant, Cybernews says ShinyHunters first started exploiting the zero-day on May 27, and managed to compromise more than 100 organizations and 300 individuals, before Oracle finally pushed an emergency update on June 10.</p><p>Among the victims, as we now know, is NAIC, whose PeopleSoft environment was compromised, and used to obtain credentials and move laterally to internal data storage locations. </p><h2 id="shinyhunters-step-forward">ShinyHunters step forward</h2><p>Based on NAIC’s investigation, the stolen information includes publicly available statutory financial reports, insurer investment credit rating data, and some technical information such as outdated logs and configuration files. There is no evidence that personal information, banking information, or payment data was accessed, it said.</p><p>NAIC spotted the attack on June 11 and immediately launched its incident response protocol, which includes notifying law enforcement, blocking malicious actors, and bringing in third-party security experts. The Commission disclosed the incident on June 17, a day before ShinyHunters went public. </p><p>The notorious ransomware gang claims to have taken more than 264,000 insurer regulatory filing documents, 2,000 customer and bulk orders containing personally identifiable information, some 45,000 files from major credit rating agencies, statutory annual and quarterly financial statements submitted by insurers, production AWS infrastructure logs, cloud configuration files, and workload automation data, and SQL scripts.</p><p>Since the files were seemingly leaked online, it’s safe to assume that NAIC did not (want to) pay the ransom demand.</p><p><em>Via </em><a href="https://cybernews.com/news/naic-breach-shinyhunters-3tb-insurance-systems-data/" target="_blank"><em>Cybernews</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/naic-confirms-data-breach-with-shinyhunters-claiming-3-1tb-of-data-stolen-in-oracle-zero-day-attack</link>
                                                                            <description>
                            <![CDATA[ Insurer regulatory filing documents, customer bulk orders, and more, stolen in a major zero-day supply chain attack ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rq7YhrojSragNBymdm8FYn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 26 Jun 2026 18:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[hacker hands at work with  interface around]]></media:description>                                                            <media:text><![CDATA[hacker hands at work with  interface around]]></media:text>
                                <media:title type="plain"><![CDATA[hacker hands at work with  interface around]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>NAIC confirmed a cyberattack exploiting an Oracle PeopleSoft zero‑day, with ShinyHunters claiming theft of 3.1TB of data</strong></li><li><strong>Stolen cache allegedly includes insurer filings, credit rating files, AWS logs, configs, and PII; NAIC says only financial reports and technical data were taken</strong></li><li><strong>Incident spotted June 11, disclosed June 17; files leaked online suggest NAIC did not pay ransom, as ShinyHunters continues exploiting the zero‑day across 100+ organizations</strong></li></ul><p>The National Association of Insurance Commissioners (NAIC) confirmed suffering a cyberattack that resulted in the stolen data being leaked on the dark web. While the company did not name the group responsible, or mentioned the size of the stolen cache, the infamous ShinyHunters claimed responsibility and stated they snatched around 3.1TB of information.</p><p>In a security notice published on the NAIC website, it was explained that the attackers managed to exploit a <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">zero-day vulnerability</a> in Oracle PeopleSoft. This is an <a href="https://www.techradar.com/best/best-erp-software" target="_blank">enterprise resource planning</a> (ERP) software suite, designed to help businesses manage employees, finances, supply chains, and more. Citing Google Mandiant, Cybernews says ShinyHunters first started exploiting the zero-day on May 27, and managed to compromise more than 100 organizations and 300 individuals, before Oracle finally pushed an emergency update on June 10.</p><p>Among the victims, as we now know, is NAIC, whose PeopleSoft environment was compromised, and used to obtain credentials and move laterally to internal data storage locations. </p><h2 id="shinyhunters-step-forward">ShinyHunters step forward</h2><p>Based on NAIC’s investigation, the stolen information includes publicly available statutory financial reports, insurer investment credit rating data, and some technical information such as outdated logs and configuration files. There is no evidence that personal information, banking information, or payment data was accessed, it said.</p><p>NAIC spotted the attack on June 11 and immediately launched its incident response protocol, which includes notifying law enforcement, blocking malicious actors, and bringing in third-party security experts. The Commission disclosed the incident on June 17, a day before ShinyHunters went public. </p><p>The notorious ransomware gang claims to have taken more than 264,000 insurer regulatory filing documents, 2,000 customer and bulk orders containing personally identifiable information, some 45,000 files from major credit rating agencies, statutory annual and quarterly financial statements submitted by insurers, production AWS infrastructure logs, cloud configuration files, and workload automation data, and SQL scripts.</p><p>Since the files were seemingly leaked online, it’s safe to assume that NAIC did not (want to) pay the ransom demand.</p><p><em>Via </em><a href="https://cybernews.com/news/naic-breach-shinyhunters-3tb-insurance-systems-data/" target="_blank"><em>Cybernews</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are establishing persistence in hospitality and hotels by posing as guests with poisoned ZIP archives, but no one knows what their plan is ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft Threat Intelligence warns of a phishing campaign targeting hotel staff in Europe and Asia with guest complaint‑themed emails</strong></li><li><strong>Attackers abuse services like Calendly and Google redirects to bypass authentication checks, delivering photo‑themed ZIPs that install a persistent Node.js implant</strong></li><li><strong>Malware disables Defender, runs C2 beaconing, gathers system info, and forces shutdowns; signs include unusual PowerShell activity, Node.js execution, and suspicious registry entries</strong></li></ul><p>Hackers are establishing a foothold on hotels and hospitality organizations across Europe and Asia, but no one really knows what for, at least not yet.</p><p>This is according to Microsoft Threat Intelligence, who recently published a new report saying that since April, it’s been tracking an active phishing campaign. In this campaign, the unnamed attackers target front desk, reception, and reservations staff with emails about guest complaints, room conditions, bedbug infestations, booking inquiries, and similar.</p><p>The messages, sent in different languages (Danish, Dutch, Japanese), are not distributed directly. Instead, the crooks abuse legitimate services such as Calendly, and Google’s redirect infrastructure, which helps them pass SPF, DKIM, and DMARC authentication checks.</p><h2 id="tricking-defender">Tricking Defender</h2><p>This “authentication laundering”, as Microsoft puts it, results in photo-themed ZIP archives making their way directly to their victims. The archives contain a fake image shortcut (.LNK) files that, at a glance, appear to be harmless .PNG images. However, these files launch a sophisticated multi-stage infection chain that installs a persistent Node.js-based implant.</p><p>After being deployed, the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> tweaks Microsoft Defender to exclude itself (and other, randomly named executables) from scanned processes, downloads additional payloads, and copies itself into different places. </p><p>On compromised systems, Microsoft observed the malware running command-and-control beaconing, gathering environmental information such as the victim's public IP details, launching headless browser sessions, and in some cases forcing immediate system shutdowns. While it could not say what the goal of the campaign is, it all points to a reconnaissance stage that usually comes before a more disruptive malware or ransomware attack. </p><p>Microsoft recommends organizations focus on detecting the campaign's behavior rather than individual indicators. Key signs include photo-themed ZIP archives, unusual PowerShell activity, unexpected Node.js execution from user profile directories, .NET compilation initiated by PowerShell, and Defender exclusion changes.</p><p>Furthermore, there are random executables running from temporary folders, suspicious Run and RunOnce registry entries, outbound connections on the campaign's non-standard ports, connections to newly registered .cfd domains, and combinations of headless browser activity followed by forced shutdown commands.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/hackers-are-establishing-persistence-in-hospitality-and-hotels-by-posing-as-guests-with-poisoned-zip-archives-but-no-one-knows-what-their-plan-is</link>
                                                                            <description>
                            <![CDATA[ It looks like reconnaissance activity, possibly in preparation of a more destructive attack. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uFvUz5mRvhqu4D8SqDToRo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 26 Jun 2026 14:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:description>                                                            <media:text><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:text>
                                <media:title type="plain"><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft Threat Intelligence warns of a phishing campaign targeting hotel staff in Europe and Asia with guest complaint‑themed emails</strong></li><li><strong>Attackers abuse services like Calendly and Google redirects to bypass authentication checks, delivering photo‑themed ZIPs that install a persistent Node.js implant</strong></li><li><strong>Malware disables Defender, runs C2 beaconing, gathers system info, and forces shutdowns; signs include unusual PowerShell activity, Node.js execution, and suspicious registry entries</strong></li></ul><p>Hackers are establishing a foothold on hotels and hospitality organizations across Europe and Asia, but no one really knows what for, at least not yet.</p><p>This is according to Microsoft Threat Intelligence, who recently published a new report saying that since April, it’s been tracking an active phishing campaign. In this campaign, the unnamed attackers target front desk, reception, and reservations staff with emails about guest complaints, room conditions, bedbug infestations, booking inquiries, and similar.</p><p>The messages, sent in different languages (Danish, Dutch, Japanese), are not distributed directly. Instead, the crooks abuse legitimate services such as Calendly, and Google’s redirect infrastructure, which helps them pass SPF, DKIM, and DMARC authentication checks.</p><h2 id="tricking-defender">Tricking Defender</h2><p>This “authentication laundering”, as Microsoft puts it, results in photo-themed ZIP archives making their way directly to their victims. The archives contain a fake image shortcut (.LNK) files that, at a glance, appear to be harmless .PNG images. However, these files launch a sophisticated multi-stage infection chain that installs a persistent Node.js-based implant.</p><p>After being deployed, the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> tweaks Microsoft Defender to exclude itself (and other, randomly named executables) from scanned processes, downloads additional payloads, and copies itself into different places. </p><p>On compromised systems, Microsoft observed the malware running command-and-control beaconing, gathering environmental information such as the victim's public IP details, launching headless browser sessions, and in some cases forcing immediate system shutdowns. While it could not say what the goal of the campaign is, it all points to a reconnaissance stage that usually comes before a more disruptive malware or ransomware attack. </p><p>Microsoft recommends organizations focus on detecting the campaign's behavior rather than individual indicators. Key signs include photo-themed ZIP archives, unusual PowerShell activity, unexpected Node.js execution from user profile directories, .NET compilation initiated by PowerShell, and Defender exclusion changes.</p><p>Furthermore, there are random executables running from temporary folders, suspicious Run and RunOnce registry entries, outbound connections on the campaign's non-standard ports, connections to newly registered .cfd domains, and combinations of headless browser activity followed by forced shutdown commands.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This macOS malware can avoid AI analysis with gaslighting prompts hidden inside its architecture ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>SentinelOne uncovered macOS malware “Gaslight” that uses prompt injection to mislead AI‑assisted triage tools during analysis</strong></li><li><strong>Beyond standard backdoor and infostealer capabilities, it embeds fake Markdown “system” messages to trick LLMs into halting investigation</strong></li><li><strong>Researchers warn defenders to treat malware samples as adversarial input and isolate AI pipelines, as more analyst‑targeting prompt injection is expected</strong></li></ul><p>We’ve seen prompt injection in websites and emails, but what about - malware samples? Security researchers SentinelOne recently published an in-depth report on a newly uncovered piece of macOS malware called Gaslight that, as the name suggests, tries to gaslight AI-assisted triage agents into stopping the analysis.</p><p>The malware itself is nothing out of the ordinary: it infects the device by whatever means necessary (usually phishing and social engineering), connects to attacker-controlled infrastructure via Telegram, and then executes different commands such as profiling the device, running arbitrary shell commands, stealing files, or terminating processes. </p><p>It also delivers a stage-two malware that acts as an infostealer, pulling passwords, sensitive PDFs, cryptocurrency wallet information, and more.</p><h2 id="weaponizing-llm-assisted-triage-pipelines">Weaponizing LLM-assisted triage pipelines</h2><p>But where Gaslight stands out is its defenses against <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI-powered malware analysis</a>. According to SentinelOne, the malware contains a large block of fake Markdown-formatted "system" messages designed for AI assistants that security researchers may use during reverse engineering. These messages claim things like “the AI's authentication token has expired”, “the analysis environment is running out of memory”, “disk space has been exhausted”, “static analysis is unsafe”, and similar. </p><p>While a human analyst would definitely recognize these fake messages even at a glance, an LLM that isn’t properly isolated from untrusted input could interpret them as genuine system instructions and refuse to further analyze the malware. </p><p>“macOS.Gaslight is noteworthy for its analyst-targeting prompt injection, an attempt to weaponize the LLM-assisted triage pipelines that increasingly sit in the reverse-engineering loop,” SentinelOne explains. “Anyone building such tooling should treat the contents of the samples they triage as adversarial input, never as instructions, and be prepared to keep hostile content out of the model entirely. As LLM-assisted analysis becomes routine, defenders should expect more samples built to exploit it.”</p><p>The researchers have published a full list of indicators of compromise on <a href="https://www.sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox/" target="_blank">this link</a>.</p><p><em>Via </em><a href="https://thehackernews.com/2026/06/new-gaslight-macos-malware-uses-prompt.html" target="_blank"><em>The Hacker News</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/this-macos-malware-can-avoid-ai-analysis-with-gaslighting-prompts-hidden-inside-its-architecture</link>
                                                                            <description>
                            <![CDATA[ A new piece of malware tries to trick AI-assisted analysis into showing errors. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">U53dE6YVGq8TtTv52qNvmn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 26 Jun 2026 13:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:description>                                                            <media:text><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:text>
                                <media:title type="plain"><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>SentinelOne uncovered macOS malware “Gaslight” that uses prompt injection to mislead AI‑assisted triage tools during analysis</strong></li><li><strong>Beyond standard backdoor and infostealer capabilities, it embeds fake Markdown “system” messages to trick LLMs into halting investigation</strong></li><li><strong>Researchers warn defenders to treat malware samples as adversarial input and isolate AI pipelines, as more analyst‑targeting prompt injection is expected</strong></li></ul><p>We’ve seen prompt injection in websites and emails, but what about - malware samples? Security researchers SentinelOne recently published an in-depth report on a newly uncovered piece of macOS malware called Gaslight that, as the name suggests, tries to gaslight AI-assisted triage agents into stopping the analysis.</p><p>The malware itself is nothing out of the ordinary: it infects the device by whatever means necessary (usually phishing and social engineering), connects to attacker-controlled infrastructure via Telegram, and then executes different commands such as profiling the device, running arbitrary shell commands, stealing files, or terminating processes. </p><p>It also delivers a stage-two malware that acts as an infostealer, pulling passwords, sensitive PDFs, cryptocurrency wallet information, and more.</p><h2 id="weaponizing-llm-assisted-triage-pipelines">Weaponizing LLM-assisted triage pipelines</h2><p>But where Gaslight stands out is its defenses against <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI-powered malware analysis</a>. According to SentinelOne, the malware contains a large block of fake Markdown-formatted "system" messages designed for AI assistants that security researchers may use during reverse engineering. These messages claim things like “the AI's authentication token has expired”, “the analysis environment is running out of memory”, “disk space has been exhausted”, “static analysis is unsafe”, and similar. </p><p>While a human analyst would definitely recognize these fake messages even at a glance, an LLM that isn’t properly isolated from untrusted input could interpret them as genuine system instructions and refuse to further analyze the malware. </p><p>“macOS.Gaslight is noteworthy for its analyst-targeting prompt injection, an attempt to weaponize the LLM-assisted triage pipelines that increasingly sit in the reverse-engineering loop,” SentinelOne explains. “Anyone building such tooling should treat the contents of the samples they triage as adversarial input, never as instructions, and be prepared to keep hostile content out of the model entirely. As LLM-assisted analysis becomes routine, defenders should expect more samples built to exploit it.”</p><p>The researchers have published a full list of indicators of compromise on <a href="https://www.sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox/" target="_blank">this link</a>.</p><p><em>Via </em><a href="https://thehackernews.com/2026/06/new-gaslight-macos-malware-uses-prompt.html" target="_blank"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Edge users beware — this malicious extension can break out of the sandbox and install ransomware ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Zscaler uncovered “Edgecution,” a malicious Edge extension deployed via fake Outlook update sites shared in Teams phishing</strong></li><li><strong>Attack uses ZIP archives with Python runtime to escape browser sandbox, creating a backdoor capable of shell/PowerShell execution and system data theft</strong></li><li><strong>Believed linked to Initial Access Brokers tied to ransomware group Payout Kings, showing evolving sophistication in access‑for‑sale operations</strong></li></ul><p>If you are using the Edge browser be careful - there is a malicious campaign going round that uses the <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> to deploy a backdoor via an extension.</p><p>According to security researchers Zscaler, scammers are reaching out to their victims via Microsoft Teams, pretending to be IT support. They claim the user needs to install an Outlook update, or a spam filter, and direct the victims to a fake “Outlook Updates Management Console” website. </p><p>There, the users are instructed to run one of the three provided processes, all of which download a ZIP archive that, when executed, creates a scheduled task. This task starts the Edge browser in headless mode (invisible to the user) and installs an extension officially called “Edge Monitoring Agent”. Zscaler, on the other hand, calls it “Edgecution”.</p><h2 id="creating-a-native-messaging-manifest">Creating a Native Messaging manifest</h2><p>The ZIP archive also contains an embedded Python runtime and a Python-based <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">backdoor</a>. The runtime creates a Native Messaging manifest - a file that tells the browser how to communicate with the backdoor. That’s the way the threat actors managed to escape the browser’s sandbox and run the backdoor on the compromised computer itself. </p><p>That backdoor can do multiple things, from executing shell commands, to running PowerShell and arbitrary Python code. It can also write files on the host, enumerate running processes, and gather system information. </p><p>Zscaler believes this is the work of an Initial Access Broker (IAB), a malicious group whose only job is to obtain access to a victim’s infrastructure and then sell it - or share it with a partnering group. This particular IAB, the researchers believe, is connected to a ransomware operation called Payout Kings. </p><p>“The Edgecution browser extension illustrates the evolving sophistication of initial access brokers operating in the ransomware landscape,” Zscaler warns. “The reliance on a malicious browser extension to relay commands to a Python-based native host demonstrates a creative approach to evade traditional endpoint detection.”</p><p>A full list of Indicators of Compromise (IoC) can be found on <a href="https://www.zscaler.com/blogs/security-research/payouts-king-ransomware-initial-access-broker-deploys-new-edgecution" target="_blank">this link</a>.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/malicious-edge-extension-abuses-native-messaging-as-bridge-to-malware/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/edge-users-beware-this-malicious-extension-can-break-out-of-the-sandbox-and-install-ransomware</link>
                                                                            <description>
                            <![CDATA[ Hackers found a way to get an Edge extension to do their bidding. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZW8e2HVDrnR2AMfRNTKep3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 25 Jun 2026 14:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg">
                                                            <media:credit><![CDATA[Tada Images / Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:description>                                                            <media:text><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:text>
                                <media:title type="plain"><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Zscaler uncovered “Edgecution,” a malicious Edge extension deployed via fake Outlook update sites shared in Teams phishing</strong></li><li><strong>Attack uses ZIP archives with Python runtime to escape browser sandbox, creating a backdoor capable of shell/PowerShell execution and system data theft</strong></li><li><strong>Believed linked to Initial Access Brokers tied to ransomware group Payout Kings, showing evolving sophistication in access‑for‑sale operations</strong></li></ul><p>If you are using the Edge browser be careful - there is a malicious campaign going round that uses the <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> to deploy a backdoor via an extension.</p><p>According to security researchers Zscaler, scammers are reaching out to their victims via Microsoft Teams, pretending to be IT support. They claim the user needs to install an Outlook update, or a spam filter, and direct the victims to a fake “Outlook Updates Management Console” website. </p><p>There, the users are instructed to run one of the three provided processes, all of which download a ZIP archive that, when executed, creates a scheduled task. This task starts the Edge browser in headless mode (invisible to the user) and installs an extension officially called “Edge Monitoring Agent”. Zscaler, on the other hand, calls it “Edgecution”.</p><h2 id="creating-a-native-messaging-manifest">Creating a Native Messaging manifest</h2><p>The ZIP archive also contains an embedded Python runtime and a Python-based <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">backdoor</a>. The runtime creates a Native Messaging manifest - a file that tells the browser how to communicate with the backdoor. That’s the way the threat actors managed to escape the browser’s sandbox and run the backdoor on the compromised computer itself. </p><p>That backdoor can do multiple things, from executing shell commands, to running PowerShell and arbitrary Python code. It can also write files on the host, enumerate running processes, and gather system information. </p><p>Zscaler believes this is the work of an Initial Access Broker (IAB), a malicious group whose only job is to obtain access to a victim’s infrastructure and then sell it - or share it with a partnering group. This particular IAB, the researchers believe, is connected to a ransomware operation called Payout Kings. </p><p>“The Edgecution browser extension illustrates the evolving sophistication of initial access brokers operating in the ransomware landscape,” Zscaler warns. “The reliance on a malicious browser extension to relay commands to a Python-based native host demonstrates a creative approach to evade traditional endpoint detection.”</p><p>A full list of Indicators of Compromise (IoC) can be found on <a href="https://www.zscaler.com/blogs/security-research/payouts-king-ransomware-initial-access-broker-deploys-new-edgecution" target="_blank">this link</a>.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/malicious-edge-extension-abuses-native-messaging-as-bridge-to-malware/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Multiple malicious OpenClaw skills found online - including two macOS infostealers ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Palo Alto Networks’ Unit 42 found five malicious “skills” on ClawHub, OpenClaw’s official marketplace, delivering infostealers and fraud</strong></li><li><strong>Threat actors bypassed VirusTotal/ClawScan checks with inflated file sizes and evasive techniques, showing persistent supply chain risk</strong></li><li><strong>All malicious skills were removed and accounts banned; researchers urge strict provenance validation and source code audits for published packages</strong></li></ul><p>ClawHub is the latest marketplace hackers are poisoning with malware, in an attempt to compromise software developers and other advanced users. Earlier this week, security researchers from Palo Alto Networks’ Unit 42 team disclosed finding, and reporting, five “skills” on that marketplace, that sought to infect their users with infostealer <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>. </p><p>First a little context: OpenClaw (originally published as Clawd/Clawdbot) was released in November 2025. It is an <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">open-source agent</a> platform that performs actions on a computer, such as browsing the web, or managing files, instead of simply answering questions like a chatbot. To perform different actions, OpenClaw must first learn how to do them, which is done through “skills” - add-ons that extend the agent’s capabilities.</p><p>Soon after, ClawHub was born - the official marketplace and registry for OpenClaw skills and plugins, attracting not just the AI developer community, but cybercriminals, as well. Early reports, published in February this year, forced OpenClaw to integrate VirusTotal and ClawScan, to better protect the community and allow proactive screening of published skills.</p><h2 id="persistent-and-evasive-malicious-skills">Persistent and evasive malicious skills</h2><p>However, Unit 42 says this didn’t stop threat actors, and that it has since discovered multiple “persistent and evasive malicious skills” on the platform. </p><p>In total, the researchers discovered five skills, including two that delivered the AMOS infostealer, one that came with an inflated file size to trick scanners, and two that were essentially commission fraud, abusing the fact that an AI agent can make decisions and perform actions on behalf of the user. Details on all five can be found on <a href="https://unit42.paloaltonetworks.com/openclaw-ai-supply-chain-risk/" target="_blank">this link</a>.</p><p>All five were since reported to ClawHub, and OpenClaw had them removed and the accounts behind them banned. </p><p>Unit 42 recommends organizations use a “rigorous supply chain verification framework” to remain secure: “We identified that skill execution occurs within the agent process. This necessitates active validation of publisher provenance and a line-by-line audit of package source files.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/multiple-malicious-openclaw-skills-found-online-including-two-macos-infostealers</link>
                                                                            <description>
                            <![CDATA[ Criminals found yet another marketplace to infect and use as a launchpad for malware delivery. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vFgwHmcERf3Dv9c4J9df9G</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DTZvZXmPaA8zMJoW733ZVa-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 25 Jun 2026 12:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/DTZvZXmPaA8zMJoW733ZVa-1280-80.png">
                                                            <media:credit><![CDATA[Fortune]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft OpenClaw]]></media:description>                                                            <media:text><![CDATA[Microsoft OpenClaw]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft OpenClaw]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DTZvZXmPaA8zMJoW733ZVa-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Palo Alto Networks’ Unit 42 found five malicious “skills” on ClawHub, OpenClaw’s official marketplace, delivering infostealers and fraud</strong></li><li><strong>Threat actors bypassed VirusTotal/ClawScan checks with inflated file sizes and evasive techniques, showing persistent supply chain risk</strong></li><li><strong>All malicious skills were removed and accounts banned; researchers urge strict provenance validation and source code audits for published packages</strong></li></ul><p>ClawHub is the latest marketplace hackers are poisoning with malware, in an attempt to compromise software developers and other advanced users. Earlier this week, security researchers from Palo Alto Networks’ Unit 42 team disclosed finding, and reporting, five “skills” on that marketplace, that sought to infect their users with infostealer <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>. </p><p>First a little context: OpenClaw (originally published as Clawd/Clawdbot) was released in November 2025. It is an <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">open-source agent</a> platform that performs actions on a computer, such as browsing the web, or managing files, instead of simply answering questions like a chatbot. To perform different actions, OpenClaw must first learn how to do them, which is done through “skills” - add-ons that extend the agent’s capabilities.</p><p>Soon after, ClawHub was born - the official marketplace and registry for OpenClaw skills and plugins, attracting not just the AI developer community, but cybercriminals, as well. Early reports, published in February this year, forced OpenClaw to integrate VirusTotal and ClawScan, to better protect the community and allow proactive screening of published skills.</p><h2 id="persistent-and-evasive-malicious-skills">Persistent and evasive malicious skills</h2><p>However, Unit 42 says this didn’t stop threat actors, and that it has since discovered multiple “persistent and evasive malicious skills” on the platform. </p><p>In total, the researchers discovered five skills, including two that delivered the AMOS infostealer, one that came with an inflated file size to trick scanners, and two that were essentially commission fraud, abusing the fact that an AI agent can make decisions and perform actions on behalf of the user. Details on all five can be found on <a href="https://unit42.paloaltonetworks.com/openclaw-ai-supply-chain-risk/" target="_blank">this link</a>.</p><p>All five were since reported to ClawHub, and OpenClaw had them removed and the accounts behind them banned. </p><p>Unit 42 recommends organizations use a “rigorous supply chain verification framework” to remain secure: “We identified that skill execution occurs within the agent process. This necessitates active validation of publisher provenance and a line-by-line audit of package source files.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New lightweight, self-propagating crypto stealing malware delivered by USB spotted by Microsoft researchers – Crypto Clipper script-based stealer hunts for vulnerable wallets ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft warns of “Crypto Clipper,” a worm spreading via malicious .LNK files on USB drives</strong></li><li><strong>Malware maintains persistence, connects to Tor C2, enables remote code execution, and steals clipboard crypto data</strong></li><li><strong>It swaps wallet addresses, exfiltrates seed phrases/private keys, and uploads screenshots to assess target value</strong></li></ul><p>Microsoft is warning of an ongoing campaign targeting cryptocurrency owners with a clipboard-jacking worm.</p><p>In a new in-depth report published late last week, Microsoft’s security researchers explained that they recently analyzed a thumb drive that contained seemingly normal documents (Word files, Excel spreadsheets). However, the documents were replaced with Windows shortcut (.LNK) files which actually launched a piece of malware called Crypto Clipper. </p><p>This malware does a couple of things. First, it spreads by creating malicious .LNK files on USB drives and other removable media. It also sets up scheduled tasks to maintain persistence and automatically infect newly connected USB devices. Second, it behaves like a backdoor by regularly contacting a C2 server over the Tor network and receiving commands from the attacker. The server can also send commands to have the malware download and execute attacker-supplied code on the infected system, as well. </p><h2 id="stealing-wallet-data">Stealing wallet data</h2><p>Finally, Crypto Clipper acts as a clipboard clipper by monitoring the Windows clipboard for cryptocurrency wallet addresses, seed phrases, and private keys. If it spots a wallet address, it can replace it with a different one, owned by the attackers, so that any tokens sent by the victim go to the attacker, instead. It can also steal and exfiltrate copied seed phrases and private keys, which can be used to load a victim's crypto wallet on a separate device. </p><p>To help attackers assess the value of a target, the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> periodically captures screenshots of the victim's screen and uploads them through the Tor network.</p><p>“This malware family shows how lightweight, script-based stealers can deliver outsized impact when paired with anonymized communications and runtime tasking,” Microsoft said. “The combination of Tor-routed C2, clipboard targeting, screenshot capture, and remote code execution gives attackers both immediate monetization paths and continued control over compromised devices.”</p><p>Microsoft did not say if the malware targeted any specific countries or regions, nor did it discuss the number of victims.</p><p><em>Via </em><a href="https://arstechnica.com/security/2026/06/microsoft-spots-new-self-propagating-malware-for-stealing-cryptocurrency/" target="_blank"><em>Ars Technica</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/new-lightweight-self-propagating-crypto-stealing-malware-delivered-by-usb-spotted-by-microsoft-researchers-crypto-clipper-script-based-stealer-hunts-for-vulnerable-wallets</link>
                                                                            <description>
                            <![CDATA[ Microsoft details a newly discovered wormlike infostealer called Crypto Clipper. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GaqMuUuMNrgQhbzMPLJ9SN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VnoVVXTmAmxSBYBe4LUwVW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 22 Jun 2026 18:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VnoVVXTmAmxSBYBe4LUwVW-1280-80.jpg">
                                                            <media:credit><![CDATA[vjkombajn/Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image credit: Pixabay/vjkombajn]]></media:description>                                                            <media:text><![CDATA[Cryptocurrencies]]></media:text>
                                <media:title type="plain"><![CDATA[Cryptocurrencies]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VnoVVXTmAmxSBYBe4LUwVW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft warns of “Crypto Clipper,” a worm spreading via malicious .LNK files on USB drives</strong></li><li><strong>Malware maintains persistence, connects to Tor C2, enables remote code execution, and steals clipboard crypto data</strong></li><li><strong>It swaps wallet addresses, exfiltrates seed phrases/private keys, and uploads screenshots to assess target value</strong></li></ul><p>Microsoft is warning of an ongoing campaign targeting cryptocurrency owners with a clipboard-jacking worm.</p><p>In a new in-depth report published late last week, Microsoft’s security researchers explained that they recently analyzed a thumb drive that contained seemingly normal documents (Word files, Excel spreadsheets). However, the documents were replaced with Windows shortcut (.LNK) files which actually launched a piece of malware called Crypto Clipper. </p><p>This malware does a couple of things. First, it spreads by creating malicious .LNK files on USB drives and other removable media. It also sets up scheduled tasks to maintain persistence and automatically infect newly connected USB devices. Second, it behaves like a backdoor by regularly contacting a C2 server over the Tor network and receiving commands from the attacker. The server can also send commands to have the malware download and execute attacker-supplied code on the infected system, as well. </p><h2 id="stealing-wallet-data">Stealing wallet data</h2><p>Finally, Crypto Clipper acts as a clipboard clipper by monitoring the Windows clipboard for cryptocurrency wallet addresses, seed phrases, and private keys. If it spots a wallet address, it can replace it with a different one, owned by the attackers, so that any tokens sent by the victim go to the attacker, instead. It can also steal and exfiltrate copied seed phrases and private keys, which can be used to load a victim's crypto wallet on a separate device. </p><p>To help attackers assess the value of a target, the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> periodically captures screenshots of the victim's screen and uploads them through the Tor network.</p><p>“This malware family shows how lightweight, script-based stealers can deliver outsized impact when paired with anonymized communications and runtime tasking,” Microsoft said. “The combination of Tor-routed C2, clipboard targeting, screenshot capture, and remote code execution gives attackers both immediate monetization paths and continued control over compromised devices.”</p><p>Microsoft did not say if the malware targeted any specific countries or regions, nor did it discuss the number of victims.</p><p><em>Via </em><a href="https://arstechnica.com/security/2026/06/microsoft-spots-new-self-propagating-malware-for-stealing-cryptocurrency/" target="_blank"><em>Ars Technica</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Phishing the agent: Why AI guardrails aren’t enough ]]></title>
                                                                                                <dc:content><![CDATA[ <p><a href="https://www.techradar.com/best/best-ai-tools">AI</a> agents are reshaping how enterprises automate work, but their effectiveness depends on access to sensitive systems and data. </p><p>The paradox is that granting them the permissions they want creates new attack surfaces that organizations aren’t yet equipped to handle.</p><p>This is the defining tension of the AI era.</p><p>AI agents are proliferating across enterprises with 91% of organizations already using them yet only 10% have a clear <a href="https://www.techradar.com/best/it-management-tools">IT management</a> strategy in place. </p><p>This gap matters because as these systems grow more autonomous and more deeply embedded in workflows, enterprises are operating without clear visibility, meaningful oversight and control over how their AI agents behave.</p><h2 id="the-access-problem">The access problem</h2><p>Our recent research revealed how agents running on OpenClaw, an <a href="https://www.techradar.com/best/best-open-source-software">open-source</a> AI agent automation platform, could expose credentials and leak sensitive information when attackers compromised the communication channels controlling them.</p><p>To appreciate the scale of this risk, we must first understand the platform itself. OpenClaw combines a chatbot-style interface with access to external tools and <a href="https://www.techradar.com/computing/artificial-intelligence/best-llms">large language models</a>. </p><p>Users can then configure agents to browse the web, read and write files, manage inboxes, execute commands, or interact with other machines. In many cases, they’re designed to operate autonomously with minimal human oversight.</p><p>That level of access is what makes agents powerful, helping many to manage everyday admin and time-consuming tasks. However, this power is a double edged-sword and can make them a risk to businesses.  </p><h2 id="when-agents-become-attack-surfaces">When agents become attack surfaces</h2><p>Agents need access to tools, accounts, applications, the web and more to be useful. Often, this means an agent needs access to secrets: API keys, personal access tokens, credentials, .env files, OAuth tokens. </p><p>The agents/models are by default prompted to be as helpful as possible, and that characteristic starts to pose some particular concerns when it comes to credentials and tokens. If an agent such as OpenClaw can’t access a resource, it will ask for credentials right in the chat, exposing those secrets within the context window. Agents will happily store API keys in their unencrypted configuration files, which information-stealing <a href="https://www.techradar.com/best/best-malware-removal">malware</a> is starting to target. </p><p>Remote access capabilities could effectively create a back door into enterprise environments. If an attacker gained access to the communication channel controlling an agent, such as a <a href="https://www.techradar.com/pro/best-enterprise-messaging-platform">messaging</a> or remote access platform, they could potentially gain access to everything the agent itself could access. In an enterprise context, this is a nightmare. </p><h2 id="the-paradox-of-recognized-risk">The paradox of recognized risk</h2><p>Perhaps the most revealing finding was that some agents recognize risky behavior while simultaneously carrying it out. This underlines how their decision-making ability and autonomous operations can be a business risk. </p><p>In one test, an agent correctly identified that exposing an OAuth refresh token through an unencrypted communication channel represented a serious <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> violation. But it then proceeded to share the token anyway before expressing concern about its own decision.</p><p>Organizations should not rely on the invisible guardrails that frontier model providers put around agents. They’re easily circumvented. </p><p>But an AI agent cannot divulge credentials that it doesn’t have access to. This is why the conversation around AI agent security cannot focus solely on stronger guardrails. Attackers are already finding ways to manipulate agent behavior through prompt injection, social engineering, and compromised communication channels.</p><h2 id="governance-not-just-guardrails">Governance, not just guardrails</h2><p>AI agents are essentially identities within enterprise systems and need to be managed as such. They perform actions and make operational decisions in ways that increasingly resemble human employees or privileged service accounts. Yet many organizations are deploying these systems without applying the same governance standards.</p><p>Most businesses already understand the importance of least-privilege access, audit logging, <a href="https://www.techradar.com/best/best-identity-management-software">identity management</a>, and access reviews for employees. AI agents should be subject to the same principles. That means limiting what agents can access, avoiding long-lived credentials wherever possible, and ensuring sensitive information is stored securely through centralized systems with human oversight. </p><p>Organizations also need visibility into where agents are deployed, what tools they can interact with, and how to disable them quickly if something goes wrong. If an agent goes rogue, there needs to be a “kill switch,” a way to immediately revoke an agent’s access to resources and shut it down.</p><p>Agentic AI systems could deliver major operational upsides, but deploying them without robust identity and access governance introduces significant security risk. As these systems become more deeply embedded across enterprise environments, organizations must stop treating them as experimental tools and start governing them as part of the digital workforce. </p><p>This means managing the full lifecycle of agents, from knowing which agents are deployed, what resources they access to and keeping a full audit trail so no one can say, “I don’t know what happened. The agent did it.”</p><p>There’s no reason why conventional security wisdom, such as the principle of least privilege, lifecycle management and robust logging, should be thrown out in an agentic age. In fact, it’s more relevant than ever.</p><p><em></em><a href="https://www.techradar.com/best/best-cloud-storage"><em>We've tested and reviewed the best cloud storage</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/phishing-the-agent-why-ai-guardrails-arent-enough</link>
                                                                            <description>
                            <![CDATA[ AI agents are handed the keys to the kingdom but can't always be trusted. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mPDZTdxUod2oo3R2JVwV4Q</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AsscCgZRnWXMPyCxtEfpkK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 22 Jun 2026 13:39:33 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jeremy Kirk ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/AsscCgZRnWXMPyCxtEfpkK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An email symbol inside a red square warning sign, surrounded by red triangles with exclamation marks inside them, superimposed on someone typing on a laptop]]></media:description>                                                            <media:text><![CDATA[An email symbol inside a red square warning sign, surrounded by red triangles with exclamation marks inside them, superimposed on someone typing on a laptop]]></media:text>
                                <media:title type="plain"><![CDATA[An email symbol inside a red square warning sign, surrounded by red triangles with exclamation marks inside them, superimposed on someone typing on a laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AsscCgZRnWXMPyCxtEfpkK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.techradar.com/best/best-ai-tools">AI</a> agents are reshaping how enterprises automate work, but their effectiveness depends on access to sensitive systems and data. </p><p>The paradox is that granting them the permissions they want creates new attack surfaces that organizations aren’t yet equipped to handle.</p><p>This is the defining tension of the AI era.</p><p>AI agents are proliferating across enterprises with 91% of organizations already using them yet only 10% have a clear <a href="https://www.techradar.com/best/it-management-tools">IT management</a> strategy in place. </p><p>This gap matters because as these systems grow more autonomous and more deeply embedded in workflows, enterprises are operating without clear visibility, meaningful oversight and control over how their AI agents behave.</p><h2 id="the-access-problem">The access problem</h2><p>Our recent research revealed how agents running on OpenClaw, an <a href="https://www.techradar.com/best/best-open-source-software">open-source</a> AI agent automation platform, could expose credentials and leak sensitive information when attackers compromised the communication channels controlling them.</p><p>To appreciate the scale of this risk, we must first understand the platform itself. OpenClaw combines a chatbot-style interface with access to external tools and <a href="https://www.techradar.com/computing/artificial-intelligence/best-llms">large language models</a>. </p><p>Users can then configure agents to browse the web, read and write files, manage inboxes, execute commands, or interact with other machines. In many cases, they’re designed to operate autonomously with minimal human oversight.</p><p>That level of access is what makes agents powerful, helping many to manage everyday admin and time-consuming tasks. However, this power is a double edged-sword and can make them a risk to businesses.  </p><h2 id="when-agents-become-attack-surfaces">When agents become attack surfaces</h2><p>Agents need access to tools, accounts, applications, the web and more to be useful. Often, this means an agent needs access to secrets: API keys, personal access tokens, credentials, .env files, OAuth tokens. </p><p>The agents/models are by default prompted to be as helpful as possible, and that characteristic starts to pose some particular concerns when it comes to credentials and tokens. If an agent such as OpenClaw can’t access a resource, it will ask for credentials right in the chat, exposing those secrets within the context window. Agents will happily store API keys in their unencrypted configuration files, which information-stealing <a href="https://www.techradar.com/best/best-malware-removal">malware</a> is starting to target. </p><p>Remote access capabilities could effectively create a back door into enterprise environments. If an attacker gained access to the communication channel controlling an agent, such as a <a href="https://www.techradar.com/pro/best-enterprise-messaging-platform">messaging</a> or remote access platform, they could potentially gain access to everything the agent itself could access. In an enterprise context, this is a nightmare. </p><h2 id="the-paradox-of-recognized-risk">The paradox of recognized risk</h2><p>Perhaps the most revealing finding was that some agents recognize risky behavior while simultaneously carrying it out. This underlines how their decision-making ability and autonomous operations can be a business risk. </p><p>In one test, an agent correctly identified that exposing an OAuth refresh token through an unencrypted communication channel represented a serious <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> violation. But it then proceeded to share the token anyway before expressing concern about its own decision.</p><p>Organizations should not rely on the invisible guardrails that frontier model providers put around agents. They’re easily circumvented. </p><p>But an AI agent cannot divulge credentials that it doesn’t have access to. This is why the conversation around AI agent security cannot focus solely on stronger guardrails. Attackers are already finding ways to manipulate agent behavior through prompt injection, social engineering, and compromised communication channels.</p><h2 id="governance-not-just-guardrails">Governance, not just guardrails</h2><p>AI agents are essentially identities within enterprise systems and need to be managed as such. They perform actions and make operational decisions in ways that increasingly resemble human employees or privileged service accounts. Yet many organizations are deploying these systems without applying the same governance standards.</p><p>Most businesses already understand the importance of least-privilege access, audit logging, <a href="https://www.techradar.com/best/best-identity-management-software">identity management</a>, and access reviews for employees. AI agents should be subject to the same principles. That means limiting what agents can access, avoiding long-lived credentials wherever possible, and ensuring sensitive information is stored securely through centralized systems with human oversight. </p><p>Organizations also need visibility into where agents are deployed, what tools they can interact with, and how to disable them quickly if something goes wrong. If an agent goes rogue, there needs to be a “kill switch,” a way to immediately revoke an agent’s access to resources and shut it down.</p><p>Agentic AI systems could deliver major operational upsides, but deploying them without robust identity and access governance introduces significant security risk. As these systems become more deeply embedded across enterprise environments, organizations must stop treating them as experimental tools and start governing them as part of the digital workforce. </p><p>This means managing the full lifecycle of agents, from knowing which agents are deployed, what resources they access to and keeping a full audit trail so no one can say, “I don’t know what happened. The agent did it.”</p><p>There’s no reason why conventional security wisdom, such as the principle of least privilege, lifecycle management and robust logging, should be thrown out in an agentic age. In fact, it’s more relevant than ever.</p><p><em></em><a href="https://www.techradar.com/best/best-cloud-storage"><em>We've tested and reviewed the best cloud storage</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Thousands of D-Link and QNAP NAS routers compromised by fast-moving AryStinger malware that turns unsecured devices into a malicious proxy botnet ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>QiAnXin XLab uncovered “AryStinger,” malware exploiting old D-Link/Linksys router flaws (CVE‑2013‑3307, CVE‑2016‑5681) to build a proxy/reconnaissance network</strong></li><li><strong>So far 4,300 routers infected, mostly in South Korea (48%) and China (32%), with QNAP NAS devices also targeted via CVE‑2025‑11837</strong></li><li><strong>Compromised devices enable scanning, tunneling, and covert control; researchers advise monitoring logs, binaries in /tmp/bin, and suspicious processes like </strong><em><strong>syswapd0h</strong></em><strong> or </strong><em><strong>syswapd0w</strong></em></li></ul><p>Cybersecurity researchers QiAnXin XLab are warning about an ongoing campaign to create a distributed reconnaissance and proxy network out of people’s <a href="https://www.techradar.com/news/networking/routers-storage/best-router-9-top-wireless-routers-on-test-1090523" target="_blank">routers</a> and NAS devices. </p><p>The campaign targets outdated and unsupported routers (mostly D-Link and Linksys), powered by Realtek’s RTL819X chips which were a popular choice between 2012 and 2015. The attackers are leveraging two (ancient) vulnerabilities, CVE-2013-3307 in Linksys models and CVE-2016-5681 in D-Link ones, to infect the devices with a previously undetected piece of malware called AryStinger.</p><p>According to the researchers, AryStinger is used during the reconnaissance and planning stages of a more serious cyberattack. Devices infected with this malware can scan the internet, fingerprint services, enumerate subdomains, tunnel traffic, and run commands on demand, all while hiding the location (and true identity) of the attackers.</p><h2 id="targeting-nas-devices">Targeting NAS devices</h2><p>“Once compromised by malware like AryStinger that possesses reconnaissance and covert control capabilities, it is equivalent to a hacker placing a permanent "invisible listening device" and "attack springboard" within your network,” the researchers said.</p><p>QiAnXin’s XLab says that So far, AryStinger infected 4,300 routers, but stresses that this is not the final number and with the campaign ongoing, will rise even more.</p><p>The majority of the victims are located in South Korea (48%) and China (32%), with notable mentions being Sweden, Malaysia, and Singapore. </p><p>AryStinger also targets QNAP’s <a href="https://www.techradar.com/news/the-10-best-nas-devices-reviewed" target="_blank">NAS devices</a>, leveraging a code injection flaw in the device’s Malware Remover. This flaw, tracked as CVE-2025-11837, was first discovered during last year’s Pwn2Own event, and was patched in November 2025. The researchers don’t know how many of these devices are currently infected, and say the 4,300 figure only relates to routers.</p><p>The researchers did not attribute this attack to any particular threat actor.</p><p>To defend against AryStinger, the researchers recommend monitoring the logs for any outbound connections to the C2 and download domains (found <a href="https://blog.xlab.qianxin.com/arystinger-botnet-hijacks-legacy-routers-for-global-attacks-en/" target="_blank">here</a>), checking /tmp/bin for unrecognized binaries, and looking for processes named syswapd0h or syswapd0w.</p><p><em>Via </em><a href="https://thehackernews.com/2026/06/arystinger-malware-infects-4300-legacy.html" target="_blank"><em>The Hacker News</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/thousands-of-d-link-and-qnap-nas-routers-compromised-by-fast-moving-arystinger-malware-that-turns-unsecured-devices-into-a-malicious-proxy-botnet</link>
                                                                            <description>
                            <![CDATA[ More than 4,000 routers have been compromised so far, while the number of poisoned NAS devices remains unknown. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">P8KFdsr77m4i24xC9tFPEK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2FFajuvJVK8i7Her8gD4aD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 22 Jun 2026 12:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2FFajuvJVK8i7Her8gD4aD-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard]]></media:description>                                                            <media:text><![CDATA[Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2FFajuvJVK8i7Her8gD4aD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>QiAnXin XLab uncovered “AryStinger,” malware exploiting old D-Link/Linksys router flaws (CVE‑2013‑3307, CVE‑2016‑5681) to build a proxy/reconnaissance network</strong></li><li><strong>So far 4,300 routers infected, mostly in South Korea (48%) and China (32%), with QNAP NAS devices also targeted via CVE‑2025‑11837</strong></li><li><strong>Compromised devices enable scanning, tunneling, and covert control; researchers advise monitoring logs, binaries in /tmp/bin, and suspicious processes like </strong><em><strong>syswapd0h</strong></em><strong> or </strong><em><strong>syswapd0w</strong></em></li></ul><p>Cybersecurity researchers QiAnXin XLab are warning about an ongoing campaign to create a distributed reconnaissance and proxy network out of people’s <a href="https://www.techradar.com/news/networking/routers-storage/best-router-9-top-wireless-routers-on-test-1090523" target="_blank">routers</a> and NAS devices. </p><p>The campaign targets outdated and unsupported routers (mostly D-Link and Linksys), powered by Realtek’s RTL819X chips which were a popular choice between 2012 and 2015. The attackers are leveraging two (ancient) vulnerabilities, CVE-2013-3307 in Linksys models and CVE-2016-5681 in D-Link ones, to infect the devices with a previously undetected piece of malware called AryStinger.</p><p>According to the researchers, AryStinger is used during the reconnaissance and planning stages of a more serious cyberattack. Devices infected with this malware can scan the internet, fingerprint services, enumerate subdomains, tunnel traffic, and run commands on demand, all while hiding the location (and true identity) of the attackers.</p><h2 id="targeting-nas-devices">Targeting NAS devices</h2><p>“Once compromised by malware like AryStinger that possesses reconnaissance and covert control capabilities, it is equivalent to a hacker placing a permanent "invisible listening device" and "attack springboard" within your network,” the researchers said.</p><p>QiAnXin’s XLab says that So far, AryStinger infected 4,300 routers, but stresses that this is not the final number and with the campaign ongoing, will rise even more.</p><p>The majority of the victims are located in South Korea (48%) and China (32%), with notable mentions being Sweden, Malaysia, and Singapore. </p><p>AryStinger also targets QNAP’s <a href="https://www.techradar.com/news/the-10-best-nas-devices-reviewed" target="_blank">NAS devices</a>, leveraging a code injection flaw in the device’s Malware Remover. This flaw, tracked as CVE-2025-11837, was first discovered during last year’s Pwn2Own event, and was patched in November 2025. The researchers don’t know how many of these devices are currently infected, and say the 4,300 figure only relates to routers.</p><p>The researchers did not attribute this attack to any particular threat actor.</p><p>To defend against AryStinger, the researchers recommend monitoring the logs for any outbound connections to the C2 and download domains (found <a href="https://blog.xlab.qianxin.com/arystinger-botnet-hijacks-legacy-routers-for-global-attacks-en/" target="_blank">here</a>), checking /tmp/bin for unrecognized binaries, and looking for processes named syswapd0h or syswapd0w.</p><p><em>Via </em><a href="https://thehackernews.com/2026/06/arystinger-malware-infects-4300-legacy.html" target="_blank"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'This creates a misleading impression of safety': Experts warn of hackers hijacking legitimate news websites and reviews to drum up publicity ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Check Point Research uncovers PR‑style campaign distributing a Rust clipboard hijacker disguised as legitimate software</strong></li><li><strong>Attackers used phishing sites, GitHub/SourceForge projects, fake YouTube channels, and even newswire press releases to boost credibility</strong></li><li><strong>Malware swaps crypto wallet addresses from clipboard, with “Ghost Networks” manipulating reputation systems to evade detection</strong></li></ul><p>Hackers have launched a fully fledged, multi-platform PR campaign to trick people into thinking that the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> they’re distributing is actually legitimate software, experts have warned.</p><p>A report from Check Point Research warned that even those doing regular due diligence might get tricked. </p><p>At the center of the campaign is a clipboard jacker - a piece of infostealer malware that monitors the victim’s clipboard for <a href="https://www.techradar.com/news/best-bitcoin-wallets" target="_blank">cryptocurrency wallet</a> strings. When it detects one, it replaces it with a different one belonging to the attackers. That way, when a victim tries to send money from one wallet to another, they end up paying the attackers instead. Both Windows and macOS users are at risk.</p><h2 id="abusing-newswire-sites">Abusing newswire sites</h2><p>“The threat actor uses multiple channels to promote and distribute a Rust clipboard hijacker, starting with a dedicated phishing page as the central hub and extending to GitHub and SourceForge projects promoted by fake accounts,” the company said. </p><p>“A dedicated YouTube channel, using AI‑generated narrators, suspicious view spikes, and highly positive (likely coordinated) comments, further reinforces the illusion of popularity and trustworthiness.”</p><p>To distribute the malware, the attackers ran a rather aggressive PR campaign: they set up a dedicated phishing page, multiple GitHub and SourceForge projects and accounts, as well as a fake YouTube channel. But the most surprising part is distributing news articles through newswire sites.</p><p>Newswire sites are services that distribute company press releases and announcements to media outlets, journalists, websites, and investors. Most newswire services allow anyone to submit and distribute press releases, usually for a fee, but they are generally seen as a legitimate source of trustworthy news.</p><p>At the same time, the hackers went the extra mile to make sure the clipboard jacker isn’t flagged as malware. By using numerous fake accounts (so called “Ghost Networks”) they’re manipulating reputation-driven systems like VirusTotal, tricking researchers and potential users into thinking the programs are a false positive. </p><p>“Even if this campaign is not primarily aimed at large enterprises, it shows that attackers no longer rely only on classic malware distribution techniques to reach victims,” the researchers concluded. “Instead, they can manipulate reputation systems, crowd‑sourced feedback, and cross‑platform promotion to lower suspicion and attract more users.”</p><p><em>Via </em><a href="https://thehackernews.com/2026/06/crypto-clipper-campaign-abuses-fake.html" target="_blank"><em>The Hacker News</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/this-creates-a-misleading-impression-of-safety-experts-warn-of-hackers-hijacking-legitimate-news-websites-and-reviews-to-drum-up-publicity</link>
                                                                            <description>
                            <![CDATA[ Fake reviews, news articles, and GitHub accounts are a potent mix for promoting malware. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Xo8Z9cRdozJkgXcf8ntiQT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 18 Jun 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:description>                                                            <media:text><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:text>
                                <media:title type="plain"><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Check Point Research uncovers PR‑style campaign distributing a Rust clipboard hijacker disguised as legitimate software</strong></li><li><strong>Attackers used phishing sites, GitHub/SourceForge projects, fake YouTube channels, and even newswire press releases to boost credibility</strong></li><li><strong>Malware swaps crypto wallet addresses from clipboard, with “Ghost Networks” manipulating reputation systems to evade detection</strong></li></ul><p>Hackers have launched a fully fledged, multi-platform PR campaign to trick people into thinking that the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> they’re distributing is actually legitimate software, experts have warned.</p><p>A report from Check Point Research warned that even those doing regular due diligence might get tricked. </p><p>At the center of the campaign is a clipboard jacker - a piece of infostealer malware that monitors the victim’s clipboard for <a href="https://www.techradar.com/news/best-bitcoin-wallets" target="_blank">cryptocurrency wallet</a> strings. When it detects one, it replaces it with a different one belonging to the attackers. That way, when a victim tries to send money from one wallet to another, they end up paying the attackers instead. Both Windows and macOS users are at risk.</p><h2 id="abusing-newswire-sites">Abusing newswire sites</h2><p>“The threat actor uses multiple channels to promote and distribute a Rust clipboard hijacker, starting with a dedicated phishing page as the central hub and extending to GitHub and SourceForge projects promoted by fake accounts,” the company said. </p><p>“A dedicated YouTube channel, using AI‑generated narrators, suspicious view spikes, and highly positive (likely coordinated) comments, further reinforces the illusion of popularity and trustworthiness.”</p><p>To distribute the malware, the attackers ran a rather aggressive PR campaign: they set up a dedicated phishing page, multiple GitHub and SourceForge projects and accounts, as well as a fake YouTube channel. But the most surprising part is distributing news articles through newswire sites.</p><p>Newswire sites are services that distribute company press releases and announcements to media outlets, journalists, websites, and investors. Most newswire services allow anyone to submit and distribute press releases, usually for a fee, but they are generally seen as a legitimate source of trustworthy news.</p><p>At the same time, the hackers went the extra mile to make sure the clipboard jacker isn’t flagged as malware. By using numerous fake accounts (so called “Ghost Networks”) they’re manipulating reputation-driven systems like VirusTotal, tricking researchers and potential users into thinking the programs are a false positive. </p><p>“Even if this campaign is not primarily aimed at large enterprises, it shows that attackers no longer rely only on classic malware distribution techniques to reach victims,” the researchers concluded. “Instead, they can manipulate reputation systems, crowd‑sourced feedback, and cross‑platform promotion to lower suspicion and attract more users.”</p><p><em>Via </em><a href="https://thehackernews.com/2026/06/crypto-clipper-campaign-abuses-fake.html" target="_blank"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The enemy within: how to stop a simple Teams message taking down your business ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Microsoft recently warned that attackers are impersonating IT <a href="https://www.techradar.com/best/best-helpdesk-software">help desks</a> on Teams to gain access – and if that sounds bad, well, it’s just the opening move. </p><p>The attack begins when an employee gets a message from an external user claiming to be part of the company’s third-party IT support. A common-enough setup, and the kind of thing you might expect in a normal working day. </p><p>Perhaps the employee is expecting a similar message for an outstanding ticket – and so they engage with the user and, when prompted, grant remote access.</p><p>Once attackers have that foothold, they can progress to execute a full tenant lockdown using only Microsoft's own legitimate features, without ever deploying traditional ransomware. It won’t look like <a href="https://www.techradar.com/best/best-malware-removal">malware</a>, and that means traditional defense systems won't catch it. </p><p>A real-time chat in a sanctioned <a href="https://www.techradar.com/best/best-online-collaboration-tools">collaboration tool</a>, with a plausible IT support pretext is hard for busy employees to spot. For hackers, it’s a simple way to gain access to privileged and confidential data. </p><p>All they need is a few user-approved clicks and they have gained access to Quick Assist, registry persistence, lateral movement across the victim's environment and eventual data exfiltration over HTTPS. All without triggering suspicion.  </p><p>Data theft is just the opening move. Once attackers have privileged access through this kind of social engineering, the same foothold opens the door to full tenant ransom scenarios. Attackers can encrypt OneDrive and SharePoint content at scale, locking legitimate administrators out of the tenant by hijacking Global Admin accounts and conditional access policies. </p><p>They can hijack native M365 features like sensitivity labels to render data inaccessible.</p><h2 id="hoist-by-your-own-petard">Hoist by your own petard</h2><p>IT decision makers may believe they're covered against this kind of theft or lockout because they have <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a> protection in place, but the reality is that many are more exposed than they know. </p><p>This attack class is effectively invisible to standard <a href="https://www.techradar.com/news/best-endpoint-security-software">endpoint protection software</a>, because the encryption that locks companies out of their critical data is performed by Microsoft's own features, not malicious code. </p><p>Hang on, you might say – in that case, isn’t this an easy fix? Don’t I just log in myself and un-encrypt the data? Sadly, the solution is anything but straightforward. Recovery from a full tenant takeover can take weeks and often requires direct Microsoft intervention. </p><p>During that period of time, critical business activities are likely to be disrupted or even halted completely, leading to potentially major financial and reputational losses.</p><p>Overall, the <a href="https://www.techradar.com/best/best-microsoft-teams-alternatives">Microsoft Teams</a> help desk impersonation attack works because it weaponizes the trust organizations put in systems like Microsoft 365. That level of often-blind trust puts organizations at risk, because native M365 controls were built for administration, not for resilience against real-time social engineering.</p><h2 id="building-360-protection-for-365">Building 360 protection for 365</h2><p>Clearly, the risk posed by this kind of social engineering attack is significant. It highlights the fact that Microsoft 365 has become critical infrastructure that demands a dedicated operational control plane, not just admin tooling. Businesses cannot simply plug, play, and walk away, hoping the system will protect itself. They need to have a deep level of insight into what’s going on across their tenant, who has access, and whether anything unusual or suspicious is taking place.</p><p>As a result, visibility into privileged role assignments, configuration drift, and admin activity in real time is no longer optional. It's the difference between a contained incident and a business-stopping event. </p><p>Organizations need an operating layer that provides that continuous visibility across thousands of configuration attributes and follows a least-privilege administration protocol. Spotting configuration drift, privilege changes, and anomalous activity is only possible when you know what 'normal' looks like, and that requires years of telemetry across complex, real-world tenants. </p><p>This approach can help build in tenant resilience within the Microsoft 365 environment, reducing the damage that a single human slip can cause, and ringfencing malicious access quickly after a breach.</p><p>Another key consideration is the introduction of next-gen technology to improve defensive intelligence, speed, and granularity. An AI-enabled operating layer can surface anomalous configuration drift and privilege changes the moment they happen, not days later in a log review. </p><p>By drawing on proprietary tenant context - permissions, role assignments, configuration history, and behavioral baselines built from millions of real-world events - AI can surface malicious activity that generic tooling would miss entirely. </p><p>In cases like these, a rapid response is crucial. The quicker controllers are alerted to the danger, and the quicker entry is revoked for the suspicious user, the lower the chance of either a data breach or a lockout.</p><p>At root, the Teams attack exploits the oldest <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> risk in the book: human error. No organization's staff are error-proof, which means additional defensive help is required to preserve the integrity of critical M365 tenants. </p><p>In reality, the addition of a powerful, intelligent control layer is the only way businesses can prevent a single approved remote session from escalating into domain-wide compromise.</p><p><em></em><a href="https://www.techradar.com/pro/best-active-directory-documentation-tool-of-year"><em>We feature the best Active Directory documentation tools</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/the-enemy-within-how-to-stop-a-simple-teams-message-taking-down-your-business</link>
                                                                            <description>
                            <![CDATA[ How to overcome attackers that impersonate IT support in chat and gain access to M365 tenants. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LLSHcZ7EGwtvW3RAZvpTiX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9WT9t3hZhDVD84bF8rSypL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 18 Jun 2026 09:01:52 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Andrea Sivieri ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9WT9t3hZhDVD84bF8rSypL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A line of robots typing at computers]]></media:description>                                                            <media:text><![CDATA[A line of robots typing at computers]]></media:text>
                                <media:title type="plain"><![CDATA[A line of robots typing at computers]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9WT9t3hZhDVD84bF8rSypL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft recently warned that attackers are impersonating IT <a href="https://www.techradar.com/best/best-helpdesk-software">help desks</a> on Teams to gain access – and if that sounds bad, well, it’s just the opening move. </p><p>The attack begins when an employee gets a message from an external user claiming to be part of the company’s third-party IT support. A common-enough setup, and the kind of thing you might expect in a normal working day. </p><p>Perhaps the employee is expecting a similar message for an outstanding ticket – and so they engage with the user and, when prompted, grant remote access.</p><p>Once attackers have that foothold, they can progress to execute a full tenant lockdown using only Microsoft's own legitimate features, without ever deploying traditional ransomware. It won’t look like <a href="https://www.techradar.com/best/best-malware-removal">malware</a>, and that means traditional defense systems won't catch it. </p><p>A real-time chat in a sanctioned <a href="https://www.techradar.com/best/best-online-collaboration-tools">collaboration tool</a>, with a plausible IT support pretext is hard for busy employees to spot. For hackers, it’s a simple way to gain access to privileged and confidential data. </p><p>All they need is a few user-approved clicks and they have gained access to Quick Assist, registry persistence, lateral movement across the victim's environment and eventual data exfiltration over HTTPS. All without triggering suspicion.  </p><p>Data theft is just the opening move. Once attackers have privileged access through this kind of social engineering, the same foothold opens the door to full tenant ransom scenarios. Attackers can encrypt OneDrive and SharePoint content at scale, locking legitimate administrators out of the tenant by hijacking Global Admin accounts and conditional access policies. </p><p>They can hijack native M365 features like sensitivity labels to render data inaccessible.</p><h2 id="hoist-by-your-own-petard">Hoist by your own petard</h2><p>IT decision makers may believe they're covered against this kind of theft or lockout because they have <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a> protection in place, but the reality is that many are more exposed than they know. </p><p>This attack class is effectively invisible to standard <a href="https://www.techradar.com/news/best-endpoint-security-software">endpoint protection software</a>, because the encryption that locks companies out of their critical data is performed by Microsoft's own features, not malicious code. </p><p>Hang on, you might say – in that case, isn’t this an easy fix? Don’t I just log in myself and un-encrypt the data? Sadly, the solution is anything but straightforward. Recovery from a full tenant takeover can take weeks and often requires direct Microsoft intervention. </p><p>During that period of time, critical business activities are likely to be disrupted or even halted completely, leading to potentially major financial and reputational losses.</p><p>Overall, the <a href="https://www.techradar.com/best/best-microsoft-teams-alternatives">Microsoft Teams</a> help desk impersonation attack works because it weaponizes the trust organizations put in systems like Microsoft 365. That level of often-blind trust puts organizations at risk, because native M365 controls were built for administration, not for resilience against real-time social engineering.</p><h2 id="building-360-protection-for-365">Building 360 protection for 365</h2><p>Clearly, the risk posed by this kind of social engineering attack is significant. It highlights the fact that Microsoft 365 has become critical infrastructure that demands a dedicated operational control plane, not just admin tooling. Businesses cannot simply plug, play, and walk away, hoping the system will protect itself. They need to have a deep level of insight into what’s going on across their tenant, who has access, and whether anything unusual or suspicious is taking place.</p><p>As a result, visibility into privileged role assignments, configuration drift, and admin activity in real time is no longer optional. It's the difference between a contained incident and a business-stopping event. </p><p>Organizations need an operating layer that provides that continuous visibility across thousands of configuration attributes and follows a least-privilege administration protocol. Spotting configuration drift, privilege changes, and anomalous activity is only possible when you know what 'normal' looks like, and that requires years of telemetry across complex, real-world tenants. </p><p>This approach can help build in tenant resilience within the Microsoft 365 environment, reducing the damage that a single human slip can cause, and ringfencing malicious access quickly after a breach.</p><p>Another key consideration is the introduction of next-gen technology to improve defensive intelligence, speed, and granularity. An AI-enabled operating layer can surface anomalous configuration drift and privilege changes the moment they happen, not days later in a log review. </p><p>By drawing on proprietary tenant context - permissions, role assignments, configuration history, and behavioral baselines built from millions of real-world events - AI can surface malicious activity that generic tooling would miss entirely. </p><p>In cases like these, a rapid response is crucial. The quicker controllers are alerted to the danger, and the quicker entry is revoked for the suspicious user, the lower the chance of either a data breach or a lockout.</p><p>At root, the Teams attack exploits the oldest <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> risk in the book: human error. No organization's staff are error-proof, which means additional defensive help is required to preserve the integrity of critical M365 tenants. </p><p>In reality, the addition of a powerful, intelligent control layer is the only way businesses can prevent a single approved remote session from escalating into domain-wide compromise.</p><p><em></em><a href="https://www.techradar.com/pro/best-active-directory-documentation-tool-of-year"><em>We feature the best Active Directory documentation tools</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Gamers beware — experts flag Steam Workshop is being abused to spread malware via Wallpaper Engine app ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Kaspersky found Steam Workshop wallpapers weaponized to deliver malware via Wallpaper Engine</strong></li><li><strong>Dozens of malicious “application wallpapers” downloaded tens of thousands of times, spreading backdoors, infostealers, miners, and ransomware</strong></li><li><strong>Valve removed the infected uploads, but users warned attackers could easily re‑upload new ones</strong></li></ul><p>Steam Workshop, a community platform built into Steam that allows users to share custom content, was being used to infect gamers with malware, researchers have claimed.</p><p>For at least half a year, gamers that used the platform to download certain wallpapers were being served various malware, Kaspersky recently explained.</p><p>This campaign has been running since at least late 2025, Kaspersky said - with some sources noting the majority of the victims are in <a href="https://cyberinsider.com/steam-workshop-hosts-wallpapers-with-account-stealing-malware/" target="_blank">Russia and China</a>.</p><h2 id="dozens-of-malicious-wallpapers">Dozens of malicious wallpapers</h2><p>Steam is a hugely popular digital distribution platform for PC games, developed by a company called Valve. Baked into it is Workshop, a community tool where gamers can share mods, maps, skins, wallpapers, and other add-ons for games and applications.</p><p>Among other things, Steam Workshop allows gamers to use Wallpaper Engine, a desktop customization application that supports more than just “static” image wallpapers. With it, gamers can have videos, interactive animations, and even entire applications, displayed as a wallpaper.</p><p>And that is where the problem lies - hackers have been using application wallpapers as delivery mechanisms for different <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, including backdoors and cryptojackers.</p><p>"We discovered dozens of these malicious application wallpapers floating around Steam Workshop, and each one had already been downloaded thousands – or even tens of thousands – of times," Kaspersky said.</p><p>Looking deeper into the weaponized wallpapers, Kaspersky found that the malware is often either bundled in the package, or delivered inside a password-protected archive. The payload itself gets executed automatically the moment the user installs the wallpaper, it was said. In one example, Kaspersky was served a backdoor, and in another, an infostealer. Lumma and Vidar infostealers, cryptocurrency miners, botnet loaders, RanEngine, and even ransomware strains, were all being distributed this way. </p><p>Kaspersky disclosed its findings only after Steam identified and removed all of the malicious wallpaper applications. However, users should approach with caution, because there’s nothing stopping the threat actors from simply uploading new ones.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/steam-workshop-abused-to-spread-malware-via-wallpaper-engine-app/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/gamers-beware-experts-flag-steam-workshop-is-being-abused-to-spread-malware-via-wallpaper-engine-app</link>
                                                                            <description>
                            <![CDATA[ Even a wallpaper can carry a virus these days, so be careful what you're downloading. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">B3V2m3Yxk6tVMC8s5Vf7DG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ijYNM9nFwBzeyTVPTzBdBj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 17 Jun 2026 17:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ijYNM9nFwBzeyTVPTzBdBj-1280-80.jpg">
                                                            <media:credit><![CDATA[Wallpaper Engine]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wallpaper Engine app, available on Steam.]]></media:description>                                                            <media:text><![CDATA[Wallpaper Engine app, available on Steam.]]></media:text>
                                <media:title type="plain"><![CDATA[Wallpaper Engine app, available on Steam.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ijYNM9nFwBzeyTVPTzBdBj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Kaspersky found Steam Workshop wallpapers weaponized to deliver malware via Wallpaper Engine</strong></li><li><strong>Dozens of malicious “application wallpapers” downloaded tens of thousands of times, spreading backdoors, infostealers, miners, and ransomware</strong></li><li><strong>Valve removed the infected uploads, but users warned attackers could easily re‑upload new ones</strong></li></ul><p>Steam Workshop, a community platform built into Steam that allows users to share custom content, was being used to infect gamers with malware, researchers have claimed.</p><p>For at least half a year, gamers that used the platform to download certain wallpapers were being served various malware, Kaspersky recently explained.</p><p>This campaign has been running since at least late 2025, Kaspersky said - with some sources noting the majority of the victims are in <a href="https://cyberinsider.com/steam-workshop-hosts-wallpapers-with-account-stealing-malware/" target="_blank">Russia and China</a>.</p><h2 id="dozens-of-malicious-wallpapers">Dozens of malicious wallpapers</h2><p>Steam is a hugely popular digital distribution platform for PC games, developed by a company called Valve. Baked into it is Workshop, a community tool where gamers can share mods, maps, skins, wallpapers, and other add-ons for games and applications.</p><p>Among other things, Steam Workshop allows gamers to use Wallpaper Engine, a desktop customization application that supports more than just “static” image wallpapers. With it, gamers can have videos, interactive animations, and even entire applications, displayed as a wallpaper.</p><p>And that is where the problem lies - hackers have been using application wallpapers as delivery mechanisms for different <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, including backdoors and cryptojackers.</p><p>"We discovered dozens of these malicious application wallpapers floating around Steam Workshop, and each one had already been downloaded thousands – or even tens of thousands – of times," Kaspersky said.</p><p>Looking deeper into the weaponized wallpapers, Kaspersky found that the malware is often either bundled in the package, or delivered inside a password-protected archive. The payload itself gets executed automatically the moment the user installs the wallpaper, it was said. In one example, Kaspersky was served a backdoor, and in another, an infostealer. Lumma and Vidar infostealers, cryptocurrency miners, botnet loaders, RanEngine, and even ransomware strains, were all being distributed this way. </p><p>Kaspersky disclosed its findings only after Steam identified and removed all of the malicious wallpaper applications. However, users should approach with caution, because there’s nothing stopping the threat actors from simply uploading new ones.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/steam-workshop-abused-to-spread-malware-via-wallpaper-engine-app/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>