<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-NZ"
                       href="https://www.techradar.com/nz/feeds/tag/cyber-security"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from TechRadar NZ in Cyber-security ]]></title>
                <link>https://www.techradar.com/nz/computing/computing-security/cyber-security</link>
        <description><![CDATA[ All the latest cyber-security content from the TechRadar  NZ team ]]></description>
                                    <lastBuildDate>Tue, 29 Sep 2026 21:15:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Sanctioned billion-dollar cybersecurity company from Russia finds 11 vulnerabilities in Google and Apple products — including a nasty one that compromised a device just through a malicious NFC tag ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>A macOS flaw could give hostile apps the highest system privileges</strong></li><li><strong>An NFC tag could trigger an Android app without owner approval</strong></li><li><strong>Android flaw lets apps change Wi-Fi settings without requesting extra permissions</strong></li></ul><p>Russian cybersecurity firm Positive Technologies has claimed it discovered 11 security flaws affecting Android and Apple devices.</p><p>The company, which is currently under American sanctions, gave the findings to Russian news agency <em>TASS</em>.</p><p>Nine of the flaws affected Apple devices and software, while two affected Android, including Pixel phones, and were reportedly rated high severity.</p><h2 id="how-a-tag-and-an-app-exposed-android-phones">How a tag and an app exposed Android phones</h2><p>The first Android flaw let attackers use a crafted NFC tag to fetch, set up, and run an app while the owner approved nothing.</p><p>The second flaw allowed an app already on the phone to alter network settings, including joining a chosen Wi-Fi network, without any extra permissions, and also let the app add a certificate or adjust proxy parameters, and neither action required the phone owner to confirm anything.</p><p>Google resolved both Android flaws in its September 2026 patches, so devices which have installed those patches should no longer face either problem.</p><p>The company describes the tag flaw as especially hazardous since holding a phone near the tag suffices to trigger it.</p><p>There was no mention of specific Android versions or Pixel models that were vulnerable, so the number of exposed devices remains unknown, but to be safe from <a href="https://www.techradar.com/best/best-malware-removal">malware</a> attacks, get the latest security patch.</p><h2 id="what-some-apple-flaws-allowed">What some Apple flaws allowed</h2><p>According to <em>TASS</em>, the nine Apple flaws covered higher access rights, privacy exposure, and weakened data safeguards.</p><p>One macOS flaw allowed a hostile app to obtain the highest level of control over the computer, and another exposed information the system normally protects. The keys used for access could be deleted without the user approving the action.</p><p>Another flaw was found inside the kernel of the operating system and could cause a device to fail or corrupt data held in memory.</p><p>Apple has released patches for the flaws, although the company did not say which operating system versions carry the fix.</p><p>Devices that never received an update stay exposed to every flaw the firm described, whatever patches the vendors have issued.</p><p>Owners of older phones and computers that no longer receive vendor updates face the most uncertainty, because a fix never reaches them.</p><p>Android owners should check their software version in system settings to confirm the September 2026 patches arrived on their devices.</p><p>Neither Apple nor Google acknowledged the Positive Technologies report as expected, but they both released patches fixing these flaws, which implies that the report is legitimate.</p><p>Via <a href="https://www1.ru/en/news/2026/09/25/438194-rossiiskie-aitisniki-pomogli-google-i-apple-zakryt-11-uiazvimostei.html" target="_blank" rel="nofollow">1.ru</a> </p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/sanctioned-billion-dollar-cybersecurity-company-from-russia-found-11-vulnerabilities-in-google-and-apple-products-including-a-nasty-one-that-compromised-a-device-just-through-a-malicious-nfc-tag</link>
                                                                            <description>
                            <![CDATA[ Nine Apple vulnerabilities affected access controls, privacy, macOS, and data protection, while two Android flaws enabled dangerous system changes. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VU7kpbBmoRhpxcthdbWDef</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/85kAnS2rcuxwyaibPRC4Ze-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 29 Sep 2026 21:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/85kAnS2rcuxwyaibPRC4Ze-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[russian flag]]></media:description>                                                            <media:text><![CDATA[russian flag]]></media:text>
                                <media:title type="plain"><![CDATA[russian flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/85kAnS2rcuxwyaibPRC4Ze-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>A macOS flaw could give hostile apps the highest system privileges</strong></li><li><strong>An NFC tag could trigger an Android app without owner approval</strong></li><li><strong>Android flaw lets apps change Wi-Fi settings without requesting extra permissions</strong></li></ul><p>Russian cybersecurity firm Positive Technologies has claimed it discovered 11 security flaws affecting Android and Apple devices.</p><p>The company, which is currently under American sanctions, gave the findings to Russian news agency <em>TASS</em>.</p><p>Nine of the flaws affected Apple devices and software, while two affected Android, including Pixel phones, and were reportedly rated high severity.</p><h2 id="how-a-tag-and-an-app-exposed-android-phones">How a tag and an app exposed Android phones</h2><p>The first Android flaw let attackers use a crafted NFC tag to fetch, set up, and run an app while the owner approved nothing.</p><p>The second flaw allowed an app already on the phone to alter network settings, including joining a chosen Wi-Fi network, without any extra permissions, and also let the app add a certificate or adjust proxy parameters, and neither action required the phone owner to confirm anything.</p><p>Google resolved both Android flaws in its September 2026 patches, so devices which have installed those patches should no longer face either problem.</p><p>The company describes the tag flaw as especially hazardous since holding a phone near the tag suffices to trigger it.</p><p>There was no mention of specific Android versions or Pixel models that were vulnerable, so the number of exposed devices remains unknown, but to be safe from <a href="https://www.techradar.com/best/best-malware-removal">malware</a> attacks, get the latest security patch.</p><h2 id="what-some-apple-flaws-allowed">What some Apple flaws allowed</h2><p>According to <em>TASS</em>, the nine Apple flaws covered higher access rights, privacy exposure, and weakened data safeguards.</p><p>One macOS flaw allowed a hostile app to obtain the highest level of control over the computer, and another exposed information the system normally protects. The keys used for access could be deleted without the user approving the action.</p><p>Another flaw was found inside the kernel of the operating system and could cause a device to fail or corrupt data held in memory.</p><p>Apple has released patches for the flaws, although the company did not say which operating system versions carry the fix.</p><p>Devices that never received an update stay exposed to every flaw the firm described, whatever patches the vendors have issued.</p><p>Owners of older phones and computers that no longer receive vendor updates face the most uncertainty, because a fix never reaches them.</p><p>Android owners should check their software version in system settings to confirm the September 2026 patches arrived on their devices.</p><p>Neither Apple nor Google acknowledged the Positive Technologies report as expected, but they both released patches fixing these flaws, which implies that the report is legitimate.</p><p>Via <a href="https://www1.ru/en/news/2026/09/25/438194-rossiiskie-aitisniki-pomogli-google-i-apple-zakryt-11-uiazvimostei.html" target="_blank" rel="nofollow">1.ru</a> </p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sweden tells citizens to be ruder to phone scammers as criminals take advantage of good manners ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Swedish celebrities are fronting a campaign to be rude to phone scammers</strong></li><li><strong>The majority of Swedish phone scam victims are over 60</strong></li><li><strong>Swedish police state that fraudsters collect around 5.7 billion SEK a year, over £431 million</strong></li></ul><p>Swedish celebrities have been hired to help the national government promote the use of profanity when dealing with telephone scammers. </p><p>The famously well-mannered Swedes are being encouraged to employ potty-mouthed responses when bothered by vishing scams and other attempts to steal money over the phone.</p><p>Swedish law enforcement states that 5.7 billion Swedish krona – £431 million or $575.3 million is stolen every year by fraudsters, many of which operate over the phone. The campaign is targeting over 60s as they are the main target for scammers.</p><h2 id="targeting-over-60s">Targeting over 60s  </h2><p>Christina Schollin, Claes Elfsberg, Suzanne Reuter, and Lennart Jähkel are participating in the campaign, which aims to provide elderly Swedes with the confidence to tell phone scammers to “go away” with whatever expletives come to mind.</p><p>By aiming for the over 60 demographic, the criminals perpetuating the crimes aim to leverage feelings of trust in institutions, often posing as government agencies or banks, often initiating contact via text message.</p><p>When the target calls the number in the message, the scammers employ tried-and-tested scripts to persuade the victim of the importance of their call, applying subtle stress and panic to push them into parting with their cash.</p><p>But the campaign is more than about turning Sweden into a land of sewer-minded insults -- over-60s are being educated not just in delivering a timely profanity, but also in recognizing when they are being scammed. With the new campaign, swearing is merely one option. Being confident to simply hang up, or tell a fake cop scammer to go away, are both good alternatives.</p><h2 id="don-39-t-be-fooled">Don't be fooled</h2><p>The notion of being rude to a stranger on the phone is not one that comes naturally to the Swedish people, which is why the campaign has been launched with well-known celebrities. Actress Christina Schollin, journalist Claes Elfsberg, actor Lennart Jähkel, are three of the famous faces, and all have one thing in common; like the key demographic of scam victims, they are over 60.</p><p>Swedish comedian and actress Suzanne Reuter is the first to feature, and says "I'm in the police campaign because it's a terrible crime that affects so many people. If I can use my voice to help someone not be fooled, then I want to do it. Many of us are raised to always be polite and accommodating, and there are many of my generation. But today you have to dare to be a little more questioning.”</p><p>She adds: “It's not nasty - it's self-protection.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/sweden-tells-citizens-to-be-ruder-to-phone-scammers-as-criminals-take-advantage-of-good-manners</link>
                                                                            <description>
                            <![CDATA[ Phone scammers expect their targets to be polite, so Swedish authorities have suggested a different strategy when dealing with unsolicited calls: profanities. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fpek8jArChrTPNAzBffWT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qa2vdH9ywWNaTcjgaZuxL3-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 29 Sep 2026 18:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christian Cawley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zBDYnjPnB2XPvhKbYX9Kuc-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Christian Cawley has extensive experience as a writer and editor in consumer electronics, IT and entertainment media. He has contributed to TechRadar since 2017 and has been published in Computer Weekly, Linux Format, ComputerActive, and other publications. &lt;/p&gt;&lt;p&gt;Beyond TechRadar, he heads up the team at smart home website Matter Alpha, and writes about retro gaming at Gaming Retro. &lt;/p&gt;&lt;p&gt;Formerly the editor responsible for Linux, Security, Programming, and DIY at MakeUseOf, Christian previously worked as a desktop and software support specialist in the public and private sectors.&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qa2vdH9ywWNaTcjgaZuxL3-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / MAYA LAB]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Caucasian adult man male guy at home living room nervous looking at mobile phone.]]></media:description>                                                            <media:text><![CDATA[Caucasian adult man male guy at home living room nervous looking at mobile phone.]]></media:text>
                                <media:title type="plain"><![CDATA[Caucasian adult man male guy at home living room nervous looking at mobile phone.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qa2vdH9ywWNaTcjgaZuxL3-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Swedish celebrities are fronting a campaign to be rude to phone scammers</strong></li><li><strong>The majority of Swedish phone scam victims are over 60</strong></li><li><strong>Swedish police state that fraudsters collect around 5.7 billion SEK a year, over £431 million</strong></li></ul><p>Swedish celebrities have been hired to help the national government promote the use of profanity when dealing with telephone scammers. </p><p>The famously well-mannered Swedes are being encouraged to employ potty-mouthed responses when bothered by vishing scams and other attempts to steal money over the phone.</p><p>Swedish law enforcement states that 5.7 billion Swedish krona – £431 million or $575.3 million is stolen every year by fraudsters, many of which operate over the phone. The campaign is targeting over 60s as they are the main target for scammers.</p><h2 id="targeting-over-60s">Targeting over 60s  </h2><p>Christina Schollin, Claes Elfsberg, Suzanne Reuter, and Lennart Jähkel are participating in the campaign, which aims to provide elderly Swedes with the confidence to tell phone scammers to “go away” with whatever expletives come to mind.</p><p>By aiming for the over 60 demographic, the criminals perpetuating the crimes aim to leverage feelings of trust in institutions, often posing as government agencies or banks, often initiating contact via text message.</p><p>When the target calls the number in the message, the scammers employ tried-and-tested scripts to persuade the victim of the importance of their call, applying subtle stress and panic to push them into parting with their cash.</p><p>But the campaign is more than about turning Sweden into a land of sewer-minded insults -- over-60s are being educated not just in delivering a timely profanity, but also in recognizing when they are being scammed. With the new campaign, swearing is merely one option. Being confident to simply hang up, or tell a fake cop scammer to go away, are both good alternatives.</p><h2 id="don-39-t-be-fooled">Don't be fooled</h2><p>The notion of being rude to a stranger on the phone is not one that comes naturally to the Swedish people, which is why the campaign has been launched with well-known celebrities. Actress Christina Schollin, journalist Claes Elfsberg, actor Lennart Jähkel, are three of the famous faces, and all have one thing in common; like the key demographic of scam victims, they are over 60.</p><p>Swedish comedian and actress Suzanne Reuter is the first to feature, and says "I'm in the police campaign because it's a terrible crime that affects so many people. If I can use my voice to help someone not be fooled, then I want to do it. Many of us are raised to always be polite and accommodating, and there are many of my generation. But today you have to dare to be a little more questioning.”</p><p>She adds: “It's not nasty - it's self-protection.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple patches CoreGraphics zero-day used in 'extremely sophisticated' targeted attacks on iOS devices ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Apple patches high-severity CoreGraphics zero-day reportedly exploited against specific targeted individuals</strong></li><li><strong>The vulnerability enables arbitrary code execution through maliciously crafted files on affected Apple devices</strong></li><li><strong>Apple urged users to install the latest security updates, particularly high-value targets facing sophisticated attacks</strong></li></ul><p>Apple has released a fix for a zero-day vulnerability it says was allegedly used “in an extremely sophisticated attack against specific targeted individuals”. </p><p>The vulnerability was found in iOS 26.7.1 and iPadOS 26.7.1 and users are advised to apply the fix as soon as possible. This is particularly important for high-value targets such as diplomats, dissidents, whistleblowers, political opposition, and journalists.</p><h2 id="zero-day">Zero-day</h2><p>The vulnerability was found in CoreGraphics, the company’s low-level 2D graphics framework used across different platforms (iOS, iPadOS, macOS, and more). CoreGraphics provides developers with tools they need to draw and render visual elements (lines, shapes, images, and even text), and can handle operations such as colors, transparency, gradients, clipping, etc. It is usually used when developers need more precise control over how something is drawn. </p><p>The vulnerability is tracked as CVE-2026-86950, with a severity score of 8.8/10 (high). The National Vulnerability Database (NVD) describes it as an out-of-bounds issue that allows threat actors to execute arbitrary code via a maliciously crafted file. The bug can also be exploited to crash programs and corrupt data. Besides iOS and iPadOS, it was also fixed in <a href="https://www.techradar.com/news/computing/apple/mac-buyer-s-guide-2015-1295725" target="_blank">macOS Sequoia</a> 15.8.1, and macOS Tahoe 26.7.1.</p><p>Here is the full list of affected devices: </p><p>iPhone 11 and later</p><p>iPad Pro 12.9-inch 3rd generation and later</p><p>iPad Pro 11-inch 1st generation and later</p><p>iPad Air 3rd generation and later</p><p>iPad 8th generation and later</p><p>iPad mini 5th generation and later</p><p>Mac devices running macOS Sequoia 15.8.1 and Tahoe 26.7.1</p><p>Apple fixed it with improved bounds checking, it was said in the security advisory. </p><h2 id="abused-in-extremely-sophisticated-attacks">Abused in “extremely sophisticated” attacks</h2><p>What makes this vulnerability stand out in a sea of zero-days is how Apple described observed exploitation attempts.</p><p>“Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.” We don’t know which report Apple is referring to here - we could not find anyone discussing it. The company only said the bug was flagged by Meta Product Security.</p><p>This could be deliberate, though. High-profile attacks tend to draw a crowd, as well as increased interest from other threat actors looking to exploit zero-day flaws. Apple is known for hiding details of vulnerabilities until it is confident that a significant majority of affected devices have been patched. </p><p>“Extremely sophisticated attacks against specific targeted individuals” is also wording Apple usually uses for state-sponsored espionage attacks against diplomats and politicians, high-value targets such as tech CEOs, journalists, political opponents and dissidents, and similar. Although it is not mentioned in the report, tech companies like Apple and Google tend to notify the victims when they’re being targeted in such attacks.</p><p>The last time Apple used similar wording was in February 2026, when it patched CVE-2026-20700. In that incident it also did not discuss the attackers, or the victims, but we do know that it was discovered by Google’s Threat Analysis Group (TAG), a department assigned with investigating primarily state-sponsored hacking campaigns.</p><p>CVE-2026-86950 is now the second zero-day vulnerability the company patched this year. Last year, Apple addressed seven zero-day vulnerabilities exploited in the wild: CVE-2025-24085, CVE-2025-24200, CVE-2025-24201, CVE-2025-31200, CVE-2025-31201, CVE-2025-43529, and CVE-2025-14174.</p><p>Given the severity of the flaw and what it can be used for, users are advised to apply the patches without delay. Apple users with automatic updates enabled should receive the security fix automatically, but those who haven't yet updated should manually check Settings → General → Software Update and install iOS/iPadOS 26.7.1.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/apple-patches-coregraphics-zero-day-flaw-exploited-in-attacks/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/apple-patches-coregraphics-zero-day-used-in-extremely-sophisticated-targeted-attacks-on-ios-devices</link>
                                                                            <description>
                            <![CDATA[ iOS, iPadOS, and other operating systems affected, so patch now. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Lv8NAq7BmJQD3iSEpepnTN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4bhmWz85fUwn539BDDXxeF-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 29 Sep 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4bhmWz85fUwn539BDDXxeF-1920-80.jpg">
                                                            <media:credit><![CDATA[Apple]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Apple logo from Tim Cooks &#039;A Big Week Ahead&#039; teaser]]></media:description>                                                            <media:text><![CDATA[Apple logo from Tim Cooks &#039;A Big Week Ahead&#039; teaser]]></media:text>
                                <media:title type="plain"><![CDATA[Apple logo from Tim Cooks &#039;A Big Week Ahead&#039; teaser]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4bhmWz85fUwn539BDDXxeF-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Apple patches high-severity CoreGraphics zero-day reportedly exploited against specific targeted individuals</strong></li><li><strong>The vulnerability enables arbitrary code execution through maliciously crafted files on affected Apple devices</strong></li><li><strong>Apple urged users to install the latest security updates, particularly high-value targets facing sophisticated attacks</strong></li></ul><p>Apple has released a fix for a zero-day vulnerability it says was allegedly used “in an extremely sophisticated attack against specific targeted individuals”. </p><p>The vulnerability was found in iOS 26.7.1 and iPadOS 26.7.1 and users are advised to apply the fix as soon as possible. This is particularly important for high-value targets such as diplomats, dissidents, whistleblowers, political opposition, and journalists.</p><h2 id="zero-day">Zero-day</h2><p>The vulnerability was found in CoreGraphics, the company’s low-level 2D graphics framework used across different platforms (iOS, iPadOS, macOS, and more). CoreGraphics provides developers with tools they need to draw and render visual elements (lines, shapes, images, and even text), and can handle operations such as colors, transparency, gradients, clipping, etc. It is usually used when developers need more precise control over how something is drawn. </p><p>The vulnerability is tracked as CVE-2026-86950, with a severity score of 8.8/10 (high). The National Vulnerability Database (NVD) describes it as an out-of-bounds issue that allows threat actors to execute arbitrary code via a maliciously crafted file. The bug can also be exploited to crash programs and corrupt data. Besides iOS and iPadOS, it was also fixed in <a href="https://www.techradar.com/news/computing/apple/mac-buyer-s-guide-2015-1295725" target="_blank">macOS Sequoia</a> 15.8.1, and macOS Tahoe 26.7.1.</p><p>Here is the full list of affected devices: </p><p>iPhone 11 and later</p><p>iPad Pro 12.9-inch 3rd generation and later</p><p>iPad Pro 11-inch 1st generation and later</p><p>iPad Air 3rd generation and later</p><p>iPad 8th generation and later</p><p>iPad mini 5th generation and later</p><p>Mac devices running macOS Sequoia 15.8.1 and Tahoe 26.7.1</p><p>Apple fixed it with improved bounds checking, it was said in the security advisory. </p><h2 id="abused-in-extremely-sophisticated-attacks">Abused in “extremely sophisticated” attacks</h2><p>What makes this vulnerability stand out in a sea of zero-days is how Apple described observed exploitation attempts.</p><p>“Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.” We don’t know which report Apple is referring to here - we could not find anyone discussing it. The company only said the bug was flagged by Meta Product Security.</p><p>This could be deliberate, though. High-profile attacks tend to draw a crowd, as well as increased interest from other threat actors looking to exploit zero-day flaws. Apple is known for hiding details of vulnerabilities until it is confident that a significant majority of affected devices have been patched. </p><p>“Extremely sophisticated attacks against specific targeted individuals” is also wording Apple usually uses for state-sponsored espionage attacks against diplomats and politicians, high-value targets such as tech CEOs, journalists, political opponents and dissidents, and similar. Although it is not mentioned in the report, tech companies like Apple and Google tend to notify the victims when they’re being targeted in such attacks.</p><p>The last time Apple used similar wording was in February 2026, when it patched CVE-2026-20700. In that incident it also did not discuss the attackers, or the victims, but we do know that it was discovered by Google’s Threat Analysis Group (TAG), a department assigned with investigating primarily state-sponsored hacking campaigns.</p><p>CVE-2026-86950 is now the second zero-day vulnerability the company patched this year. Last year, Apple addressed seven zero-day vulnerabilities exploited in the wild: CVE-2025-24085, CVE-2025-24200, CVE-2025-24201, CVE-2025-31200, CVE-2025-31201, CVE-2025-43529, and CVE-2025-14174.</p><p>Given the severity of the flaw and what it can be used for, users are advised to apply the patches without delay. Apple users with automatic updates enabled should receive the security fix automatically, but those who haven't yet updated should manually check Settings → General → Software Update and install iOS/iPadOS 26.7.1.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/apple-patches-coregraphics-zero-day-flaw-exploited-in-attacks/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Italy's top bank hit by an AI messaging scam which cost it nearly €100 million ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>AI-powered deepfakes convinced executives to authorize massive overseas fund transfers</strong></li><li><strong>Fraudsters impersonated senior figures through messaging apps and cloned voices</strong></li><li><strong>Incident highlights evolving business email compromise tactics in the AI era</strong></li></ul><p>Cybercriminals have tricked a major Italian bank into wiring more than $100 million abroad by targeting executives with AI-powered deepfakes. Some of the money has since been recovered, but a significant portion remains unaccounted for.</p><p>The target was Fideuram – Intesa Sanpaolo Private Banking, a very large Italian private-banking and wealth-management group owned by Intesa Sanpaolo. It cannot be considered a “normal” retail bank - its core business is managing investments and wealth for affluent and high-net-worth clients. </p><p>According to the latest figures, the bank has around $513.25 billion in assets under management (AUM), more than 7,100 private bankers, and more than $9.85 billion in net profit. </p><h2 id="deepfakes-and-phone-calls">Deepfakes and phone calls</h2><p>Citing two sources familiar with the matter, Reuters reported that the attack took place in February 2026, while the chairman was ​Paolo Molesini. </p><p>Molesini reportedly received a <a href="https://www.techradar.com/phones/7-great-whatsapp-alternatives-for-android-users-google-messages-discord-and-more" target="_blank">WhatsApp</a> message that seems to have come from Carlo Messina, Intesa Sanpaolo Chief Executive Officer (CEO), who asked him to help with an urgent overseas transaction, to which the victim agreed. He was later contacted by someone claiming to be senior partner at a prominent law firm, to confirm the instruction. This person used <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI tools</a> to create a deepfake of the lawyer’s voice, tricking Molesini into thinking the request was authentic.</p><p>The chairman then reached out to the bank’s finance department, arranging a series of transactions to foreign account, the majority of which were in mainland China and Hong Kong. </p><p>The scam was spotted soon afterwards, and Fideuram moved to block the transaction. With the help of law enforcement in China, Portugal, and Italy, around $60.14 million was recovered. Around $40.8 million remains missing, apparently converted into cryptocurrencies.</p><h2 id="ruining-a-person-39-s-career">Ruining a person's career</h2><p>​Paolo Molesini announced he was stepping down from roles of president for both Fideuram itself and Intesa Sanpaolo Private Banking a month later, in March 2026, citing “personal reasons”. </p><p>According to <a href="https://www.reuters.com/legal/government/ai-messaging-scam-costs-italys-top-bank-intesa-millions-sources-say-2026-09-25/" target="_blank"><em>Reuters</em></a>, neither Molesini, or any other Fideuram executives are under investigation, but local authorities are apparently investigating a “foreign national living outside Europe” for potential fraud. </p><p>In the pre-AI era, this type of fraud was known as Business Email Compromise (BEC). Crooks would break in (or otherwise spoof) the email address of a company’s CEO (or other executive), map out employees working in the finance department, and reach out with instructions for wire transfers. These instructions would explain that the transfer needs to be completed in secrecy, to avoid unnecessary publicity or competitors. </p><p>Nowadays, with the advent of artificial intelligence and the ease with which crooks can create deepfake images, voice clones, and even videos, BEC attacks have spread out to instant messaging platforms, voice calls, and even video calls. </p><p>Last year, scammers used artificial intelligence to create a deepfake of the voice of an Italian minister, tricking local businessman Massimo Moratti to transfer around $1.13 million to an overseas account. The money was later successfully recovered, it was said.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/italys-top-bank-hit-by-an-ai-messaging-scam-which-cost-it-nearly-eur100-million</link>
                                                                            <description>
                            <![CDATA[ Bank chairman believed he was talking to a lawyer and ended up ordering a multi-million-dollar wire transfer. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2LRRCifQsfJyvR3k7AiNuS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kMQVGNaXFmvhNxH6wp5LUh-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 29 Sep 2026 13:03:20 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kMQVGNaXFmvhNxH6wp5LUh-1920-80.jpg">
                                                            <media:credit><![CDATA[ Say thanks! Give a shoutout to Jefferson Santos on social or copy the text below to attribute.  Photo by Jefferson Santos on Unsplash]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[shady person sitting at a computer.]]></media:description>                                                            <media:text><![CDATA[shady person sitting at a computer.]]></media:text>
                                <media:title type="plain"><![CDATA[shady person sitting at a computer.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kMQVGNaXFmvhNxH6wp5LUh-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>AI-powered deepfakes convinced executives to authorize massive overseas fund transfers</strong></li><li><strong>Fraudsters impersonated senior figures through messaging apps and cloned voices</strong></li><li><strong>Incident highlights evolving business email compromise tactics in the AI era</strong></li></ul><p>Cybercriminals have tricked a major Italian bank into wiring more than $100 million abroad by targeting executives with AI-powered deepfakes. Some of the money has since been recovered, but a significant portion remains unaccounted for.</p><p>The target was Fideuram – Intesa Sanpaolo Private Banking, a very large Italian private-banking and wealth-management group owned by Intesa Sanpaolo. It cannot be considered a “normal” retail bank - its core business is managing investments and wealth for affluent and high-net-worth clients. </p><p>According to the latest figures, the bank has around $513.25 billion in assets under management (AUM), more than 7,100 private bankers, and more than $9.85 billion in net profit. </p><h2 id="deepfakes-and-phone-calls">Deepfakes and phone calls</h2><p>Citing two sources familiar with the matter, Reuters reported that the attack took place in February 2026, while the chairman was ​Paolo Molesini. </p><p>Molesini reportedly received a <a href="https://www.techradar.com/phones/7-great-whatsapp-alternatives-for-android-users-google-messages-discord-and-more" target="_blank">WhatsApp</a> message that seems to have come from Carlo Messina, Intesa Sanpaolo Chief Executive Officer (CEO), who asked him to help with an urgent overseas transaction, to which the victim agreed. He was later contacted by someone claiming to be senior partner at a prominent law firm, to confirm the instruction. This person used <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI tools</a> to create a deepfake of the lawyer’s voice, tricking Molesini into thinking the request was authentic.</p><p>The chairman then reached out to the bank’s finance department, arranging a series of transactions to foreign account, the majority of which were in mainland China and Hong Kong. </p><p>The scam was spotted soon afterwards, and Fideuram moved to block the transaction. With the help of law enforcement in China, Portugal, and Italy, around $60.14 million was recovered. Around $40.8 million remains missing, apparently converted into cryptocurrencies.</p><h2 id="ruining-a-person-39-s-career">Ruining a person's career</h2><p>​Paolo Molesini announced he was stepping down from roles of president for both Fideuram itself and Intesa Sanpaolo Private Banking a month later, in March 2026, citing “personal reasons”. </p><p>According to <a href="https://www.reuters.com/legal/government/ai-messaging-scam-costs-italys-top-bank-intesa-millions-sources-say-2026-09-25/" target="_blank"><em>Reuters</em></a>, neither Molesini, or any other Fideuram executives are under investigation, but local authorities are apparently investigating a “foreign national living outside Europe” for potential fraud. </p><p>In the pre-AI era, this type of fraud was known as Business Email Compromise (BEC). Crooks would break in (or otherwise spoof) the email address of a company’s CEO (or other executive), map out employees working in the finance department, and reach out with instructions for wire transfers. These instructions would explain that the transfer needs to be completed in secrecy, to avoid unnecessary publicity or competitors. </p><p>Nowadays, with the advent of artificial intelligence and the ease with which crooks can create deepfake images, voice clones, and even videos, BEC attacks have spread out to instant messaging platforms, voice calls, and even video calls. </p><p>Last year, scammers used artificial intelligence to create a deepfake of the voice of an Italian minister, tricking local businessman Massimo Moratti to transfer around $1.13 million to an overseas account. The money was later successfully recovered, it was said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ShinyHunters hackers are going after Oracle systems once again - here's what we know ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>ShinyHunters bypass PeopleSoft mitigation rules, reviving exploitation of a critical zero-day vulnerability</strong></li><li><strong>The campaign has expanded globally, targeting organizations across technology, healthcare, government, and other sectors</strong></li><li><strong>Oracle’s original patch remains effective, while organizations should investigate systems and rotate potentially exposed credentials</strong></li></ul><p>ShinyHunters have found a way to bypass a mitigation for a zero-day they previously exploited - so now, not only are they back to abusing the same bug, they’ve even expanded their scope to target a much larger pool of organizations.</p><p>In June 2026, it was reported that ShinyHunters, the infamous data extortionists, found a Java deserialization vulnerability in Oracle’s PeopleSoft Environment Management Hub (PSEMHUB) servlet that allowed them to achieve web shell deployment or fileless command execution on vulnerable servers.</p><p>Oracle PeopleSoft is a suite of <a href="https://www.techradar.com/best/best-erp-software" target="_blank">enterprise business software</a> used mainly by large organizations, universities, governments, and corporations to manage things like human resources, finance, supply chain, and student administration.</p><p>This remote code execution (RCE) bug caused by unsafe deserialization of Java objects in PSEMHUB was exploited for days, targeting higher education institutions, stealing their sensitive files, and enabling extortion campaigns.</p><p>Oracle fixed the issue on June 10 2026, bringing the tool to versions 8.61 and 8.62. The bug was assigned an identifier CVE-2026-35273 and was given a severity score of 9.8/10 (critical). The US Cybersecurity and Infrastructure Security Agency (CISA) added the bug to its Known Exploited Vulnerabilities (KEV) catalog on June 12, giving federal agencies a three-day deadline to patch up. </p><h2 id="shinyhunters-return">ShinyHunters Return</h2><p>The company also provided mitigation measures for organizations that were unable to install the patch at the time. However, <a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft?e=48754805" target="_blank" rel="nofollow">Mandiant and Google’s Threat Intelligence Group (GTIG)</a> are now reporting that ShinyHunters found a way to bypass these mitigations, and are back to exploiting the flaw against organizations running unpatched versions of the software. </p><p>“This new wave of activity stems from UNC6240 modifying its exploit to bypass web application firewall (WAF) rules blocking the vulnerable Environment Management Hub (PSEMHUB) endpoint,” the two organizations said in a new report, stressing that the campaign has now expanded globally. </p><p>“The threat actor bypassed these string-based <a href="https://www.techradar.com/best/firewall" target="_blank">WAF</a> rules by URL-encoding a single character in the request path, requesting /%50SEMHUB/ in place of /PSEMHUB/,” the researchers said. “Many WAF and reverse proxy rules match the literal path before URL decoding, while the PeopleSoft application server decodes the request and routes it to the vulnerable servlet. This allows the threat actor to reach the endpoint on systems whose operators may have believed their WAF rules had mitigated the exposure.”</p><p>At first, ShinyHunters were focused mostly on higher education institutions. This time around, though, they’re casting a much wider net, deploying web shells on “dozens of systems globally” including technology, IT services, healthcare, agriculture, transportation, and government. </p><p>“Mandiant recommends that organizations running Oracle PeopleSoft take the following immediate actions,” the researchers added. </p><p>ShinyHunters are known extortionists. They are using the PeopleSoft vulnerability to gain persistent access and steal credentials, allowing them to move laterally through target environments and exfiltrate sensitive data such as HR or payroll.</p><h2 id="patching-works">Patching works</h2><p>The good news is that the patch still works. If an organization applied Oracle’s fix for CVE-2026-35273, this WAF bypass should not matter, because it only works around the mitigation, not the underlying vulnerability fix. Therefore, both Google and Mandiant advise, first and foremost, that organizations apply the Oracle Security Alert issued when the zero-day was first disclosed. </p><p>Businesses should also disable the Environment Management Hub (EMHub) service in multi-server configurations, or remove the PSEMHUB application entirely, in single-server configurations.</p><p>To check whether they were targeted or not, they should search PIA WebLogic access logs for requests to /PSEMHUB) and any percent-encoded variant, and should inspect <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/ for files that are not part of the shipped product.</p><p>Finally, they should rotate all credentials the PeopleSoft application service account can read, and monitor outbound traffic from PeopleSoft hosts to the network indicators <a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft?e=48754805" target="_blank">listed here</a>.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/shinyhunters-hackers-are-going-after-oracle-systems-once-again-heres-what-we-know</link>
                                                                            <description>
                            <![CDATA[ Mitigations are no longer mitigating, and patching is now the only method of defense. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cd6ufq8gAjqjWoby9PXghi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/37uyEphcLreEFNUVCQzurn-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 29 Sep 2026 12:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/37uyEphcLreEFNUVCQzurn-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[World Password Day 2025]]></media:description>                                                            <media:text><![CDATA[World Password Day 2025]]></media:text>
                                <media:title type="plain"><![CDATA[World Password Day 2025]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/37uyEphcLreEFNUVCQzurn-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>ShinyHunters bypass PeopleSoft mitigation rules, reviving exploitation of a critical zero-day vulnerability</strong></li><li><strong>The campaign has expanded globally, targeting organizations across technology, healthcare, government, and other sectors</strong></li><li><strong>Oracle’s original patch remains effective, while organizations should investigate systems and rotate potentially exposed credentials</strong></li></ul><p>ShinyHunters have found a way to bypass a mitigation for a zero-day they previously exploited - so now, not only are they back to abusing the same bug, they’ve even expanded their scope to target a much larger pool of organizations.</p><p>In June 2026, it was reported that ShinyHunters, the infamous data extortionists, found a Java deserialization vulnerability in Oracle’s PeopleSoft Environment Management Hub (PSEMHUB) servlet that allowed them to achieve web shell deployment or fileless command execution on vulnerable servers.</p><p>Oracle PeopleSoft is a suite of <a href="https://www.techradar.com/best/best-erp-software" target="_blank">enterprise business software</a> used mainly by large organizations, universities, governments, and corporations to manage things like human resources, finance, supply chain, and student administration.</p><p>This remote code execution (RCE) bug caused by unsafe deserialization of Java objects in PSEMHUB was exploited for days, targeting higher education institutions, stealing their sensitive files, and enabling extortion campaigns.</p><p>Oracle fixed the issue on June 10 2026, bringing the tool to versions 8.61 and 8.62. The bug was assigned an identifier CVE-2026-35273 and was given a severity score of 9.8/10 (critical). The US Cybersecurity and Infrastructure Security Agency (CISA) added the bug to its Known Exploited Vulnerabilities (KEV) catalog on June 12, giving federal agencies a three-day deadline to patch up. </p><h2 id="shinyhunters-return">ShinyHunters Return</h2><p>The company also provided mitigation measures for organizations that were unable to install the patch at the time. However, <a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft?e=48754805" target="_blank" rel="nofollow">Mandiant and Google’s Threat Intelligence Group (GTIG)</a> are now reporting that ShinyHunters found a way to bypass these mitigations, and are back to exploiting the flaw against organizations running unpatched versions of the software. </p><p>“This new wave of activity stems from UNC6240 modifying its exploit to bypass web application firewall (WAF) rules blocking the vulnerable Environment Management Hub (PSEMHUB) endpoint,” the two organizations said in a new report, stressing that the campaign has now expanded globally. </p><p>“The threat actor bypassed these string-based <a href="https://www.techradar.com/best/firewall" target="_blank">WAF</a> rules by URL-encoding a single character in the request path, requesting /%50SEMHUB/ in place of /PSEMHUB/,” the researchers said. “Many WAF and reverse proxy rules match the literal path before URL decoding, while the PeopleSoft application server decodes the request and routes it to the vulnerable servlet. This allows the threat actor to reach the endpoint on systems whose operators may have believed their WAF rules had mitigated the exposure.”</p><p>At first, ShinyHunters were focused mostly on higher education institutions. This time around, though, they’re casting a much wider net, deploying web shells on “dozens of systems globally” including technology, IT services, healthcare, agriculture, transportation, and government. </p><p>“Mandiant recommends that organizations running Oracle PeopleSoft take the following immediate actions,” the researchers added. </p><p>ShinyHunters are known extortionists. They are using the PeopleSoft vulnerability to gain persistent access and steal credentials, allowing them to move laterally through target environments and exfiltrate sensitive data such as HR or payroll.</p><h2 id="patching-works">Patching works</h2><p>The good news is that the patch still works. If an organization applied Oracle’s fix for CVE-2026-35273, this WAF bypass should not matter, because it only works around the mitigation, not the underlying vulnerability fix. Therefore, both Google and Mandiant advise, first and foremost, that organizations apply the Oracle Security Alert issued when the zero-day was first disclosed. </p><p>Businesses should also disable the Environment Management Hub (EMHub) service in multi-server configurations, or remove the PSEMHUB application entirely, in single-server configurations.</p><p>To check whether they were targeted or not, they should search PIA WebLogic access logs for requests to /PSEMHUB) and any percent-encoded variant, and should inspect <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/ for files that are not part of the shipped product.</p><p>Finally, they should rotate all credentials the PeopleSoft application service account can read, and monitor outbound traffic from PeopleSoft hosts to the network indicators <a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft?e=48754805" target="_blank">listed here</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers build fake desktop apps to trick victims into handing over access ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Threat actors spoofed major US HR/payroll platforms with fake desktop clients built via Lovable landing pages</strong></li><li><strong>Victims downloaded a modified ScreenConnect build from GitHub, giving attackers hidden, unattended remote access</strong></li><li><strong>Campaign shows ~291 downloads; likely targets payroll staff, enabling potential wire fraud through diverted payments</strong></li></ul><p>Cybercriminals are impersonating large American HR and payroll platforms in attacks that are very difficult to spot, new research from Allure has claimed.</p><p>Its <a href="https://alluresecurity.com/blog/signal-noise-brand-was-real-app-wasnt" target="_blank">report</a> revealed how the as-yet unidentified threat actors were found spoofing three major US HR and payroll platforms, likely picked primarily because they offered a cloud-based service accessible through a browser, rather than a standalone desktop app. </p><p>The crooks used Lovable (a legitimate AI-powered service for <a href="https://www.techradar.com/news/the-best-website-builder" target="_blank">building websites</a> and landing pages with nothing more than prompts, requiring no technical knowledge whatsoever) to create landing pages imitating the legitimate brands, but with a small (yet important) distinction - they offered a desktop client.</p><h2 id="no-reference-points">No reference points</h2><p>Since a legitimate desktop client does not exist, there is nothing to compare the malware to. This, Allure says, makes it very difficult for victims to determine they were being targeted. After all, it would make sense for a major HR and payroll platform to have a desktop app at one point, right?</p><p>Those that clicked the download button were served an executable from GitHub Releases, a feature of GitHub that developers use to publish specific, packaged versions of their software. You can think of it as the software equivalent of a product download page. Being a legitimate service (and one frequently used to host software like this), it yet raises no suspicions or red flags.</p><p>The executable itself is not malicious either, which is probably the cheekiest part of the attack. As such, it flies under the radar of most antivirus or endpoint protection services and can easily be installed on the device.</p><h2 id="quot-legitimate-quot-tools">"Legitimate" tools</h2><p>Well if it’s not malicious, what is it? And what is the risk?</p><p>The program victims end up installing is a variant of ConnectWise’s ScreenConnect, a <a href="https://www.techradar.com/news/best-remote-desktop-software" target="_blank">remote desktop and remote IT support platform</a> used primarily by IT departments and managed service providers (MSP). It is a legitimate tool that allows IT techs to remotely connect to computers and servers, troubleshoot problems, install software and patches, and more. </p><p>But because ScreenConnect provides remote, often privileged access to computers, it is an attractive tool for attackers, and is often used in cyberattacks of different nature.</p><p>“This build was configured to surreptitiously do the same thing without the user being aware. We extracted the client configuration and the launch parameters. The access mode is set to unattended. The victim-facing indicators are turned off: no “your machine is being controlled” banner, no system-tray icon, no connection balloon,” the researchers said.</p><p>In other words, the variant was configured to allow crooks access without notifying the victim in any way. </p><p>Allure did not identify the attackers, nor did it discuss the success of the campaign. We don’t know exactly who it targeted (apart that it aims for finance and HR departments), or how many organizations ended up installing ScreenConnect. The researchers said the GitHub downloads page shows 291 downloads, but that doesn’t necessarily have to mean 291 victims, or successful attacks. It is likely that numerous security researchers downloaded the tools, as well as sandboxes, and that many of the victims realized they were attacked before suffering any meaningful damage. Therefore, the actual number of victims is likely significantly smaller. </p><p>We also don’t know what the endgame is, although Allure suggests it might be wire fraud: </p><p>“Whoever installs it is the person who runs payroll, and unattended access to that machine is a path to diverting or draining an entire company’s payroll,” they said. </p><p>“If your company runs a cloud payroll or HR platform, the most useful thing you can do this week is check whether yours actually ships one [desktop client], and tell employees that a download the vendor does not offer is not an upgrade.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/hackers-build-fake-desktop-apps-to-trick-victims-into-handing-over-access</link>
                                                                            <description>
                            <![CDATA[ Finance and HR departments are being offered tools that don't exist, tricking them into handing over valuable access. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ogjRTA5jhG933oHK4XrS2N</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wV66hEbpJdAc4iPB7RwtkK-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 29 Sep 2026 01:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wV66hEbpJdAc4iPB7RwtkK-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An exclamation mark inside a red warning triangle, surrounded by email symbols, superimposed on someone typing on a laptop]]></media:description>                                                            <media:text><![CDATA[An exclamation mark inside a red warning triangle, surrounded by email symbols, superimposed on someone typing on a laptop]]></media:text>
                                <media:title type="plain"><![CDATA[An exclamation mark inside a red warning triangle, surrounded by email symbols, superimposed on someone typing on a laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wV66hEbpJdAc4iPB7RwtkK-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Threat actors spoofed major US HR/payroll platforms with fake desktop clients built via Lovable landing pages</strong></li><li><strong>Victims downloaded a modified ScreenConnect build from GitHub, giving attackers hidden, unattended remote access</strong></li><li><strong>Campaign shows ~291 downloads; likely targets payroll staff, enabling potential wire fraud through diverted payments</strong></li></ul><p>Cybercriminals are impersonating large American HR and payroll platforms in attacks that are very difficult to spot, new research from Allure has claimed.</p><p>Its <a href="https://alluresecurity.com/blog/signal-noise-brand-was-real-app-wasnt" target="_blank">report</a> revealed how the as-yet unidentified threat actors were found spoofing three major US HR and payroll platforms, likely picked primarily because they offered a cloud-based service accessible through a browser, rather than a standalone desktop app. </p><p>The crooks used Lovable (a legitimate AI-powered service for <a href="https://www.techradar.com/news/the-best-website-builder" target="_blank">building websites</a> and landing pages with nothing more than prompts, requiring no technical knowledge whatsoever) to create landing pages imitating the legitimate brands, but with a small (yet important) distinction - they offered a desktop client.</p><h2 id="no-reference-points">No reference points</h2><p>Since a legitimate desktop client does not exist, there is nothing to compare the malware to. This, Allure says, makes it very difficult for victims to determine they were being targeted. After all, it would make sense for a major HR and payroll platform to have a desktop app at one point, right?</p><p>Those that clicked the download button were served an executable from GitHub Releases, a feature of GitHub that developers use to publish specific, packaged versions of their software. You can think of it as the software equivalent of a product download page. Being a legitimate service (and one frequently used to host software like this), it yet raises no suspicions or red flags.</p><p>The executable itself is not malicious either, which is probably the cheekiest part of the attack. As such, it flies under the radar of most antivirus or endpoint protection services and can easily be installed on the device.</p><h2 id="quot-legitimate-quot-tools">"Legitimate" tools</h2><p>Well if it’s not malicious, what is it? And what is the risk?</p><p>The program victims end up installing is a variant of ConnectWise’s ScreenConnect, a <a href="https://www.techradar.com/news/best-remote-desktop-software" target="_blank">remote desktop and remote IT support platform</a> used primarily by IT departments and managed service providers (MSP). It is a legitimate tool that allows IT techs to remotely connect to computers and servers, troubleshoot problems, install software and patches, and more. </p><p>But because ScreenConnect provides remote, often privileged access to computers, it is an attractive tool for attackers, and is often used in cyberattacks of different nature.</p><p>“This build was configured to surreptitiously do the same thing without the user being aware. We extracted the client configuration and the launch parameters. The access mode is set to unattended. The victim-facing indicators are turned off: no “your machine is being controlled” banner, no system-tray icon, no connection balloon,” the researchers said.</p><p>In other words, the variant was configured to allow crooks access without notifying the victim in any way. </p><p>Allure did not identify the attackers, nor did it discuss the success of the campaign. We don’t know exactly who it targeted (apart that it aims for finance and HR departments), or how many organizations ended up installing ScreenConnect. The researchers said the GitHub downloads page shows 291 downloads, but that doesn’t necessarily have to mean 291 victims, or successful attacks. It is likely that numerous security researchers downloaded the tools, as well as sandboxes, and that many of the victims realized they were attacked before suffering any meaningful damage. Therefore, the actual number of victims is likely significantly smaller. </p><p>We also don’t know what the endgame is, although Allure suggests it might be wire fraud: </p><p>“Whoever installs it is the person who runs payroll, and unattended access to that machine is a path to diverting or draining an entire company’s payroll,” they said. </p><p>“If your company runs a cloud payroll or HR platform, the most useful thing you can do this week is check whether yours actually ships one [desktop client], and tell employees that a download the vendor does not offer is not an upgrade.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Citrix says two worrying NetScaler RCE zero-days exploited in attacks ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Citrix patched two critical zero‑days (CVE‑2026‑88771, CVE‑2026‑88772) in NetScaler ADC/Gateway, both enabling remote code execution</strong></li><li><strong>Exploits already observed; CISA added flaws to KEV catalog with a three‑day patch deadline (Sept 30)</strong></li><li><strong>NetScaler appliances are prime targets due to internet exposure, privileged access, and limited monitoring visibility</strong></li></ul><p>Citrix has released a patch for two critical zero-day vulnerabilities apparently being actively exploited in real-life attacks. </p><p>In its weekend security advisory, Citrix said it fixed two bugs: CVE-2026-88771 and CVE-2026-88772.</p><p>It is now urging organizations to apply the fix as soon as possible and defend their premises from potentially disruptive attacks.</p><h2 id="what-citrix-fixed">What Citrix fixed</h2><p>The first issue is an improper input validation vulnerability that allows unauthenticated attackers to execute arbitrary commands remotely. It has a severity score of 9.5/10 (critical). The latter is a buffer overflow/memory-corruption vulnerability in Citrix NetScaler ADC and NetScaler Gateway which could allow attackers to execute malicious code remotely, or trigger Denial of Service (DoS). This one, too, carries a severity score of 9.5/10 (critical). </p><p>Both flaws affect Citrix NetScaler ADC and Citrix NetScaler Gateway: ADC before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway before 14.1-73.37 and before 13.1-64.23.</p><p>Citrix released patches for the flaws in NetScaler ADC and Gateway 14.1-73.37 and 13.1-64.23, as well as the corresponding FIPS builds.</p><p>"Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed," Citrix said in the security bulletin.</p><h2 id="abused-in-the-wild">Abused in the wild</h2><p>Citrix has thus confirmed what was being reported on, earlier. According to <em>BleepingComputer</em>, Citrix admins took to Reddit to report IT suppliers and security teams contacting their organizations and recommending they shut down NetScaler appliances.</p><p>"We got a call from our IT supplier's security team, they couldn't give any details but they advised to shut our Netscalers down immediately," one administrator wrote. Other admins said similar warnings were coming from law enforcement, national cybersecurity agencies, and CERTs. "We are currently rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild. While details are scarce, the information is credible," security experts watchTowr said in response to the news.</p><p>The US Cybersecurity and Infrastructure Security Agency (CISA) also reacted. Both vulnerabilities were added to its catalog of known exploited flaws (KEV) on Sunday, giving Federal Civilian Executive Branch (FCEB) agencies a three-day deadline (until Wednesday, September 30) to patch up.</p><p>The Dutch National Cyber Security Center (NCSC-NL) also reacted fast. Even before Citrix publicly disclosed the flaws, the organization allegedly notified organizations in the country about the zero-days. <em>BleepingComputer</em> said “multiple people shared copies of the notification online, which said the agency had received information from a European partner CERT regarding two vulnerabilities that could independently lead to remote code execution.”</p><h2 id="why-target-netscaler">Why target NetScaler</h2><p>This is not the first time cybercriminals are targeting NetScaler appliances. They are often in the crosshairs because they are tasked with providing remote access to internal applications and desktops, and as such, they are exposed to the internet and can be targeted directly. </p><p>That makes any <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">zero-day vulnerabilities</a> in the appliances particularly valuable. Bugs that leak authenticated session tokens, those that allow for authentication bypass, or remote code execution, can provide a foothold inside an organization, without requiring any interaction on the victim side. From there, threat actors could steal credentials, access internal resources, or move laterally to deploy ransomware. </p><p>Edge appliances like the Citrix NetScaler are also attractive because they’re somewhat harder to monitor, compared to other endpoints. Organizations usually deploy extensive security tools for computers and servers, leaving specialized networking appliances somewhere in the shadows. </p><p>This combination of internet exposure, privileged access, and somewhat limited visibility, makes a serious NetScaler vulnerability particularly attractive to both state-sponsored actors, and profit-oriented groups. </p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/citrix-says-two-worrying-netscaler-rce-zero-days-exploited-in-attacks</link>
                                                                            <description>
                            <![CDATA[ The company released a fix and urged organizations to patch up immediately. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">E7KRrK56qrYEFansBqvSi8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NGKiUcJVFBC8HkMp9dTo9a-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 28 Sep 2026 15:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NGKiUcJVFBC8HkMp9dTo9a-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.]]></media:description>                                                            <media:text><![CDATA[A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.]]></media:text>
                                <media:title type="plain"><![CDATA[A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NGKiUcJVFBC8HkMp9dTo9a-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Citrix patched two critical zero‑days (CVE‑2026‑88771, CVE‑2026‑88772) in NetScaler ADC/Gateway, both enabling remote code execution</strong></li><li><strong>Exploits already observed; CISA added flaws to KEV catalog with a three‑day patch deadline (Sept 30)</strong></li><li><strong>NetScaler appliances are prime targets due to internet exposure, privileged access, and limited monitoring visibility</strong></li></ul><p>Citrix has released a patch for two critical zero-day vulnerabilities apparently being actively exploited in real-life attacks. </p><p>In its weekend security advisory, Citrix said it fixed two bugs: CVE-2026-88771 and CVE-2026-88772.</p><p>It is now urging organizations to apply the fix as soon as possible and defend their premises from potentially disruptive attacks.</p><h2 id="what-citrix-fixed">What Citrix fixed</h2><p>The first issue is an improper input validation vulnerability that allows unauthenticated attackers to execute arbitrary commands remotely. It has a severity score of 9.5/10 (critical). The latter is a buffer overflow/memory-corruption vulnerability in Citrix NetScaler ADC and NetScaler Gateway which could allow attackers to execute malicious code remotely, or trigger Denial of Service (DoS). This one, too, carries a severity score of 9.5/10 (critical). </p><p>Both flaws affect Citrix NetScaler ADC and Citrix NetScaler Gateway: ADC before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway before 14.1-73.37 and before 13.1-64.23.</p><p>Citrix released patches for the flaws in NetScaler ADC and Gateway 14.1-73.37 and 13.1-64.23, as well as the corresponding FIPS builds.</p><p>"Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed," Citrix said in the security bulletin.</p><h2 id="abused-in-the-wild">Abused in the wild</h2><p>Citrix has thus confirmed what was being reported on, earlier. According to <em>BleepingComputer</em>, Citrix admins took to Reddit to report IT suppliers and security teams contacting their organizations and recommending they shut down NetScaler appliances.</p><p>"We got a call from our IT supplier's security team, they couldn't give any details but they advised to shut our Netscalers down immediately," one administrator wrote. Other admins said similar warnings were coming from law enforcement, national cybersecurity agencies, and CERTs. "We are currently rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild. While details are scarce, the information is credible," security experts watchTowr said in response to the news.</p><p>The US Cybersecurity and Infrastructure Security Agency (CISA) also reacted. Both vulnerabilities were added to its catalog of known exploited flaws (KEV) on Sunday, giving Federal Civilian Executive Branch (FCEB) agencies a three-day deadline (until Wednesday, September 30) to patch up.</p><p>The Dutch National Cyber Security Center (NCSC-NL) also reacted fast. Even before Citrix publicly disclosed the flaws, the organization allegedly notified organizations in the country about the zero-days. <em>BleepingComputer</em> said “multiple people shared copies of the notification online, which said the agency had received information from a European partner CERT regarding two vulnerabilities that could independently lead to remote code execution.”</p><h2 id="why-target-netscaler">Why target NetScaler</h2><p>This is not the first time cybercriminals are targeting NetScaler appliances. They are often in the crosshairs because they are tasked with providing remote access to internal applications and desktops, and as such, they are exposed to the internet and can be targeted directly. </p><p>That makes any <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">zero-day vulnerabilities</a> in the appliances particularly valuable. Bugs that leak authenticated session tokens, those that allow for authentication bypass, or remote code execution, can provide a foothold inside an organization, without requiring any interaction on the victim side. From there, threat actors could steal credentials, access internal resources, or move laterally to deploy ransomware. </p><p>Edge appliances like the Citrix NetScaler are also attractive because they’re somewhat harder to monitor, compared to other endpoints. Organizations usually deploy extensive security tools for computers and servers, leaving specialized networking appliances somewhere in the shadows. </p><p>This combination of internet exposure, privileged access, and somewhat limited visibility, makes a serious NetScaler vulnerability particularly attractive to both state-sponsored actors, and profit-oriented groups. </p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kiteworks tells users to shut down servers amid fears of 'imminent' cyberattack ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Kiteworks warned customers of a “credible” planned cyberattack, urging a nine‑hour precautionary shutdown</strong></li><li><strong>No breaches reported; advisory lifted Sept 27, systems restored, version 9.5.1 deemed secure</strong></li><li><strong>Context recalls Cl0p’s past file‑sharing platform hits, raising speculation about possible resurgence</strong></li></ul><p>Secure file sharing company Kiteworks recently told its customers to shut down their servers for nine hours, in anticipation of an incoming cyberattack.</p><p>There are no reports of actual attacks - at least not yet, but in a blog post, the company revealed it had received “credible” threat intelligence from federal authorities warning them of a planned attack against the company and its customers.</p><p>In response, the company told its customers to shut down their servers for nine hours, depending on their timezone.</p><h2 id="what-happened">What happened?</h2><p>“Kiteworks is advising customers to facilitate a nine-hour precautionary shutdown window this weekend, in their local time zone,” the announcement reads. </p><p>“Customers who self-manage their Kiteworks systems—on-premises or on AWS or Azure—should shut down those systems themselves during this window. Kiteworks will shut down the customer systems it hosts, on behalf of customers, during the same window, so Kiteworks-hosted customers are not required to take any action.”</p><p>In the announcement, the company’s Chief Information Security Officer, Frank Balonis, said the measure is proactive rather than reactive, and that there are no ongoing attacks just yet:</p><p>“Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we continue to work through the matter with federal intelligence authorities,” Balonis said. </p><p>“We have no indication that Kiteworks or our customers’ systems have been compromised, so this advisory is preventative rather than a response to a confirmed breach.”</p><p>Citing German media, <a href="https://www.bleepingcomputer.com/news/security/kiteworks-urges-6-hour-server-shutdown-over-potential-zero-day-attacks/" target="_blank"><em>BleepingComputer</em></a> said the shutdown window “applies to customer worldwide”, with affected time zones ranging from Australian Eastern Standard Time, to Pacific Daylight Time. In Central Europe, customers were told to shut down between 4 and 10 AM on Saturday. On the east coast of the US, the shutdown window is between 10PM on a Friday, until 4AM on Saturday. </p><h2 id="who-could-be-gearing-up-for-an-assault">Who could be gearing up for an assault?</h2><p>Kiteworks is a US-based enterprise security and <a href="https://www.techradar.com/best/secure-file-transfer-solutions" target="_blank">secure data-sharing platform</a>, which organizations can use to manage sensitive information, especially when ordinary email attachments or consumer file-sharing services aren’t considered secure enough.</p><p>Kiteworks says it does not have any fixes in the pipeline and that all known vulnerabilities are accounted for in the latest version 9.5.1. Obviously, customers are advised to run this version instead of older, potentially vulnerable ones, and were told that other subsidiaries such as Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai, and 123FormBuilder, were not affected.</p><p>Secure data-sharing platforms are an attractive target for cybercriminals, given the high-value organizations that use them, as well as the sensitive information they handle. We don’t know who the attackers might be, but there are some strange coincidences occurring at the moment.</p><p>Three years ago, a hacking group known as Cl0p struck two major file-sharing platforms: GoAnywhere MFT and MOVEit. The breaches ended up becoming <a href="https://www.techradar.com/pro/security/the-moveit-breach-may-well-have-been-the-biggest-cyberattack-of-the-year" target="_blank">some of the biggest hits in recent history</a>, affecting thousands of customers. Victims ranged from government agencies, schools and healthcare, to major firms like Sony and PricewaterhouseCoopers (PwC). </p><p>Cl0p tried to extort many of these companies, even succeeding with some. The cybersecurity community tried to estimate how much money the group stole this way, and the general consensus seems to be anywhere between $40 and $100 million. </p><p>In the months and years following these two incidents, Cl0p vanished. The group was no longer making high-level plays, and we’ve not reported on any major breaches since. Until last week, that is, when it was reported that ShinyHunters - currently one of the most active and dangerous data exfiltration organizations around - <a href="https://www.techradar.com/pro/security/cybercrime-civil-war-brewing-shinyhunters-reportedly-hacks-cl0p-ransomware-gang-and-threatens-further-damage" target="_blank">attacked Cl0p</a>.</p><p>ShinyHunters leaked plenty of Cl0p’s sensitive data, saying it did so in retaliation for threats of doxxing and physical violence made by the group. We don’t know if Cl0p was preparing to hit Kiteworks, but we wouldn’t be too surprised if it was an attempted brand management after being somewhat embarrassed by ShinyHunters.</p><p>So far, there were no reports of actual breaches at any of Kiteworks’ customers, but we’re continuing to monitor the situation. </p><p>The company said that as of September 27 2026, the shutdown recommendation has been lifted for all customers. “If you have not already restarted, you may bring your Kiteworks system back online. Customers with self-hosted Advanced Forms should contact Customer Support for assistance. All systems Kiteworks hosts on customers’ behalf have been brought back up and are operating normally.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/kiteworks-tells-users-to-shut-down-servers-amid-fears-of-imminent-cyberattack</link>
                                                                            <description>
                            <![CDATA[ The police notified Kiteworks of apparently imminent attack, leading to the company reacting fast. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HBsUJYrkSxJPr9XagKThaP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 28 Sep 2026 14:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:description>                                                            <media:text><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:text>
                                <media:title type="plain"><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Kiteworks warned customers of a “credible” planned cyberattack, urging a nine‑hour precautionary shutdown</strong></li><li><strong>No breaches reported; advisory lifted Sept 27, systems restored, version 9.5.1 deemed secure</strong></li><li><strong>Context recalls Cl0p’s past file‑sharing platform hits, raising speculation about possible resurgence</strong></li></ul><p>Secure file sharing company Kiteworks recently told its customers to shut down their servers for nine hours, in anticipation of an incoming cyberattack.</p><p>There are no reports of actual attacks - at least not yet, but in a blog post, the company revealed it had received “credible” threat intelligence from federal authorities warning them of a planned attack against the company and its customers.</p><p>In response, the company told its customers to shut down their servers for nine hours, depending on their timezone.</p><h2 id="what-happened">What happened?</h2><p>“Kiteworks is advising customers to facilitate a nine-hour precautionary shutdown window this weekend, in their local time zone,” the announcement reads. </p><p>“Customers who self-manage their Kiteworks systems—on-premises or on AWS or Azure—should shut down those systems themselves during this window. Kiteworks will shut down the customer systems it hosts, on behalf of customers, during the same window, so Kiteworks-hosted customers are not required to take any action.”</p><p>In the announcement, the company’s Chief Information Security Officer, Frank Balonis, said the measure is proactive rather than reactive, and that there are no ongoing attacks just yet:</p><p>“Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we continue to work through the matter with federal intelligence authorities,” Balonis said. </p><p>“We have no indication that Kiteworks or our customers’ systems have been compromised, so this advisory is preventative rather than a response to a confirmed breach.”</p><p>Citing German media, <a href="https://www.bleepingcomputer.com/news/security/kiteworks-urges-6-hour-server-shutdown-over-potential-zero-day-attacks/" target="_blank"><em>BleepingComputer</em></a> said the shutdown window “applies to customer worldwide”, with affected time zones ranging from Australian Eastern Standard Time, to Pacific Daylight Time. In Central Europe, customers were told to shut down between 4 and 10 AM on Saturday. On the east coast of the US, the shutdown window is between 10PM on a Friday, until 4AM on Saturday. </p><h2 id="who-could-be-gearing-up-for-an-assault">Who could be gearing up for an assault?</h2><p>Kiteworks is a US-based enterprise security and <a href="https://www.techradar.com/best/secure-file-transfer-solutions" target="_blank">secure data-sharing platform</a>, which organizations can use to manage sensitive information, especially when ordinary email attachments or consumer file-sharing services aren’t considered secure enough.</p><p>Kiteworks says it does not have any fixes in the pipeline and that all known vulnerabilities are accounted for in the latest version 9.5.1. Obviously, customers are advised to run this version instead of older, potentially vulnerable ones, and were told that other subsidiaries such as Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai, and 123FormBuilder, were not affected.</p><p>Secure data-sharing platforms are an attractive target for cybercriminals, given the high-value organizations that use them, as well as the sensitive information they handle. We don’t know who the attackers might be, but there are some strange coincidences occurring at the moment.</p><p>Three years ago, a hacking group known as Cl0p struck two major file-sharing platforms: GoAnywhere MFT and MOVEit. The breaches ended up becoming <a href="https://www.techradar.com/pro/security/the-moveit-breach-may-well-have-been-the-biggest-cyberattack-of-the-year" target="_blank">some of the biggest hits in recent history</a>, affecting thousands of customers. Victims ranged from government agencies, schools and healthcare, to major firms like Sony and PricewaterhouseCoopers (PwC). </p><p>Cl0p tried to extort many of these companies, even succeeding with some. The cybersecurity community tried to estimate how much money the group stole this way, and the general consensus seems to be anywhere between $40 and $100 million. </p><p>In the months and years following these two incidents, Cl0p vanished. The group was no longer making high-level plays, and we’ve not reported on any major breaches since. Until last week, that is, when it was reported that ShinyHunters - currently one of the most active and dangerous data exfiltration organizations around - <a href="https://www.techradar.com/pro/security/cybercrime-civil-war-brewing-shinyhunters-reportedly-hacks-cl0p-ransomware-gang-and-threatens-further-damage" target="_blank">attacked Cl0p</a>.</p><p>ShinyHunters leaked plenty of Cl0p’s sensitive data, saying it did so in retaliation for threats of doxxing and physical violence made by the group. We don’t know if Cl0p was preparing to hit Kiteworks, but we wouldn’t be too surprised if it was an attempted brand management after being somewhat embarrassed by ShinyHunters.</p><p>So far, there were no reports of actual breaches at any of Kiteworks’ customers, but we’re continuing to monitor the situation. </p><p>The company said that as of September 27 2026, the shutdown recommendation has been lifted for all customers. “If you have not already restarted, you may bring your Kiteworks system back online. Customers with self-hosted Advanced Forms should contact Customer Support for assistance. All systems Kiteworks hosts on customers’ behalf have been brought back up and are operating normally.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'I broke something': A Claude Code AI agent deleted 48,000 files in just over 100 seconds — then apologized for doing so ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>AI coding agent mishandled Windows junctions, deleting ~48,000 live files and corrupting Git object database</strong></li><li><strong>Incident surfaced on Reddit, with community mocking lack of backups and calling it “classic FAFO”</strong></li><li><strong>Lesson stressed: always use remote version control (e.g., GitHub) before letting AI touch production work</strong></li></ul><p>A catastrophic incident caused by an AI coding agent resulted in around 48,000 files being deleted and the repository’s Git object database getting destroyed in the process. </p><p>The news of the fiasco, which first surfaced on Reddit, quickly spread throughout the internet, to a mix of laughter and facepalming from the developer community.</p><p>A software developer posted a new thread on <a href="https://www.reddit.com/r/ClaudeAI/comments/1wl5cgo/code_just_deleted_48k_files_this_cant_be_real/" target="_blank" rel="nofollow">Reddit</a> to share a recent experience. They tasked an AI coding assistant with a series of repairs to a collection of software they used to analyze historical stock-options data. They told the assistant to make copies of relevant files, work on them, test the repairs, and leave the original working files alone. </p><h2 id="wrong-turn-at-the-junction">Wrong turn at the junction</h2><p>In total, there were 11 repair jobs running, and while 10 went smoothly, the last one involved rebuilding a testing environment called a “mirror” (a copy of a set of files used for testing). This job was supposed to make a fresh copy of the old testing environment, apply the repairs, and test it without touching the real working files. </p><p>The testing environment contained 614 Windows folders called “junctions”. These look like an ordinary folder, but actually point to a separate location on the computer. In this case, they were pointing back to the user’s live working files. When the AI tried to clean out the junctions, it did not recognize them as just pointers, following them into the real filing cabinet and deleting the actual documents. </p><p>The cleanup process removed around 55,550 files, of which around 7,300 were supposed to be deleted anyway. The remaining 48,218 files were from the live working environment. Everything happened in the blink of an eye - less than two minutes. The AI was surprisingly honest about what it did. At one point, it told the developer: “Craig — stop and read this. I broke something.”</p><p>The computer’s Git repository was also damaged. The index survived, but the underlying stored copies of the files, and the history used to reconstruct them, were all deleted. Git could still list thousands of filenames, but could no longer recover the contents. </p><h2 id="reddit-39-s-response">Reddit's response</h2><p>The Reddit post simply exploded. In the five days since it was posted, it garnered more than 1,400 responses. The Reddit bot that summarizes the comments says the overwhelming consensus is that the incident is a “classic FAFO situation and a major skill issue.”</p><p>“While everyone is having a good laugh at Claude’s hilariously honest “Craig…. stop and read this. I broke something” message, the community verdict is clear: you got rekt because you didn't follow basic dev practices.”</p><p>Redditors shared their experience and told the original poster they were supposed to use Git and push to a remote repository like GitHub constantly. In situations like this one, GitHub is a “save button”, and not having a remote backup for a project with 48k files is “considered peak vibe coder behavior.”</p><p>The post has, since then, been deleted - possibly because the original poster took a photo of their screen. “The screenshot police are out in full force,” the Reddit bot said.</p><p>“Some helpful souls suggested using file recovery software or Windows Shadow Copy to get your files back, but the main lesson here is to use version control before you let an AI anywhere near your work.”</p><p>While <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agents</a> deleting entire archives is not that common, it has happened before. </p><p>In late February 2026, Summer Yue, a Meta AI safety/alignment researcher, gave an OpenClaw AI agent access to her Gmail account. She had first tested it on a small “toy” inbox, where everything worked as intended. However, when she moved it to her actual inbox, the agent began <a href="https://www.windowscentral.com/artificial-intelligence/meta-summer-yue-director-openclaw-ai-email-deletion" target="_blank" rel="nofollow">bulk-deleting and archiving hundreds of emails</a>, despite her telling it to stop.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/i-broke-something-a-claude-code-ai-agent-deleted-48-000-files-in-just-over-100-seconds-then-apologized-for-doing-so</link>
                                                                            <description>
                            <![CDATA[ A developer had an AI agent run 11 tasks. One messed up dearly. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SshuvPH7WEJqmgNqJ66LB5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MZeWJhJjT34M4nQvMMX7fg-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sun, 27 Sep 2026 17:05:00 +0000</pubDate>                                                                                                                                <updated>Mon, 28 Sep 2026 14:07:09 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MZeWJhJjT34M4nQvMMX7fg-1920-80.jpg">
                                                            <media:credit><![CDATA[Generated with Gemini ]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[an ai agent sat at a laptop]]></media:description>                                                            <media:text><![CDATA[an ai agent sat at a laptop]]></media:text>
                                <media:title type="plain"><![CDATA[an ai agent sat at a laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MZeWJhJjT34M4nQvMMX7fg-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>AI coding agent mishandled Windows junctions, deleting ~48,000 live files and corrupting Git object database</strong></li><li><strong>Incident surfaced on Reddit, with community mocking lack of backups and calling it “classic FAFO”</strong></li><li><strong>Lesson stressed: always use remote version control (e.g., GitHub) before letting AI touch production work</strong></li></ul><p>A catastrophic incident caused by an AI coding agent resulted in around 48,000 files being deleted and the repository’s Git object database getting destroyed in the process. </p><p>The news of the fiasco, which first surfaced on Reddit, quickly spread throughout the internet, to a mix of laughter and facepalming from the developer community.</p><p>A software developer posted a new thread on <a href="https://www.reddit.com/r/ClaudeAI/comments/1wl5cgo/code_just_deleted_48k_files_this_cant_be_real/" target="_blank" rel="nofollow">Reddit</a> to share a recent experience. They tasked an AI coding assistant with a series of repairs to a collection of software they used to analyze historical stock-options data. They told the assistant to make copies of relevant files, work on them, test the repairs, and leave the original working files alone. </p><h2 id="wrong-turn-at-the-junction">Wrong turn at the junction</h2><p>In total, there were 11 repair jobs running, and while 10 went smoothly, the last one involved rebuilding a testing environment called a “mirror” (a copy of a set of files used for testing). This job was supposed to make a fresh copy of the old testing environment, apply the repairs, and test it without touching the real working files. </p><p>The testing environment contained 614 Windows folders called “junctions”. These look like an ordinary folder, but actually point to a separate location on the computer. In this case, they were pointing back to the user’s live working files. When the AI tried to clean out the junctions, it did not recognize them as just pointers, following them into the real filing cabinet and deleting the actual documents. </p><p>The cleanup process removed around 55,550 files, of which around 7,300 were supposed to be deleted anyway. The remaining 48,218 files were from the live working environment. Everything happened in the blink of an eye - less than two minutes. The AI was surprisingly honest about what it did. At one point, it told the developer: “Craig — stop and read this. I broke something.”</p><p>The computer’s Git repository was also damaged. The index survived, but the underlying stored copies of the files, and the history used to reconstruct them, were all deleted. Git could still list thousands of filenames, but could no longer recover the contents. </p><h2 id="reddit-39-s-response">Reddit's response</h2><p>The Reddit post simply exploded. In the five days since it was posted, it garnered more than 1,400 responses. The Reddit bot that summarizes the comments says the overwhelming consensus is that the incident is a “classic FAFO situation and a major skill issue.”</p><p>“While everyone is having a good laugh at Claude’s hilariously honest “Craig…. stop and read this. I broke something” message, the community verdict is clear: you got rekt because you didn't follow basic dev practices.”</p><p>Redditors shared their experience and told the original poster they were supposed to use Git and push to a remote repository like GitHub constantly. In situations like this one, GitHub is a “save button”, and not having a remote backup for a project with 48k files is “considered peak vibe coder behavior.”</p><p>The post has, since then, been deleted - possibly because the original poster took a photo of their screen. “The screenshot police are out in full force,” the Reddit bot said.</p><p>“Some helpful souls suggested using file recovery software or Windows Shadow Copy to get your files back, but the main lesson here is to use version control before you let an AI anywhere near your work.”</p><p>While <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agents</a> deleting entire archives is not that common, it has happened before. </p><p>In late February 2026, Summer Yue, a Meta AI safety/alignment researcher, gave an OpenClaw AI agent access to her Gmail account. She had first tested it on a small “toy” inbox, where everything worked as intended. However, when she moved it to her actual inbox, the agent began <a href="https://www.windowscentral.com/artificial-intelligence/meta-summer-yue-director-openclaw-ai-email-deletion" target="_blank" rel="nofollow">bulk-deleting and archiving hundreds of emails</a>, despite her telling it to stop.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This Mac malware is somehow using iCloud calendar invites to try and steal your data ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Kaspersky uncovers MacSync, a Mac infostealer delivered via iCloud calendar events and fake apps</strong></li><li><strong>Loader fetches instructions from calendar entries, then deploys malware exfiltrating credentials, wallets, and developer data</strong></li><li><strong>Newer variants add Objective‑C backdoor spoofing Finder, persistence, and expanded targeting of crypto and IT users</strong></li></ul><p>Cybercriminals have found a way to use iCloud calendar events and cloud storage to deliver a powerful infostealer to Mac devices. </p><p>The malware is called MacSync, and it’s hiding behind fake crypto wallets, or “cracked” commercial software. </p><p>Security researchers Kaspersky, who discovered the ongoing campaign, are urging Mac users to exercise caution when downloading programs, especially from third-party websites, and to be very skeptical of apps prompting for their admin password.</p><h2 id="why-calendar">Why calendar?</h2><p>Getting people to download and run <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> on their devices is not as easy as it sounds. </p><p>The victims need to be somehow tricked into downloading and running an app, and even when they do so, chances are the malicious program will be sniffed out by whatever antivirus solutions the device has running, before it can do any meaningful damage. Also, crooks don’t want to be forced to repeat the process every time they want to deploy a different variant, or type of malware. </p><p>So, they resort to all sorts of techniques and workarounds, from DLL sideloading, to malware loaders. </p><p>By separating the initial infection and the actual malware, cybercriminals can reduce detection rate and get more flexibility, but it creates a new problem: defenders can monitor the traffic going in and out of different apps and thus detect when a loader is deploying malware. </p><p>The challenge then becomes hiding the traffic, and MacSync does it by using the iCloud calendar. </p><p>After being downloaded and executed, the loader will reach out to the calendar - which is a totally benign activity that is unlikely to raise any suspicion - and look for a specific public event, pre-built by the attackers. In its description, it will find the instructions, and the location of, the actual infostealer, and deploy it to ultimately compromise the target device. In this case, the location was also in the iCloud.</p><p>The loader itself is being advertised through social media, SEO poisoning, and phishing. Victims are directed either to fraudulent websites or social media channels promoting cracked software, or free versions of advanced solutions. In at least one example, Kaspersky saw the loader being advertised as a cryptocurrency wallet. Victims are shown a typical ClickFix error, and told to fix it by pasting a command in the Terminal.</p><p>The command deploys the loader which, in turn, installs MacSync.</p><h2 id="a-quot-substantial-quot-overhaul">A "substantial" overhaul</h2><p>The infostealer emerged in April 2025, and was initially spun out of AMOS, one of the most popular information-stealing variants for the MacOS. It is based on Swift and has, since then, evolved to offer additional capabilities. According to Kaspersky, it can exfiltrate browser history, cookies, saved credentials, cryptocurrency wallet and app data, Telegram data, Keychain data, as well as system and device information. It can exfiltrate SSH, AWS, Kubernetes, Git, and shell configuration files, as well. </p><p>Newer variants come with an Objective-C backdoor spoofing the macOS default file manager, Finder. It establishes persistence, terminates notification processes to prevent alerts, and grants the attackers backdoor access, including running AppleScript received from the C2 server, deploying browser extensions, replacing the legitimate Ledger wallet app, collecting additional system information, and more. </p><p>Kaspersky also found an undefined command called “live_browser”, which downloads and runs a component named “sn_relay”, whose point has not yet been established. </p><p>The new versions “significantly” differ from older ones, Kaspersky said, stressing that the attackers “substantially” overhauled their approach. </p><p>“The nature of the data attackers seek to collect from a victim’s device, as well as the categories of applications the stealer disguises itself as, clearly indicates that this malware family primarily targets developers, crypto enthusiasts, and other users associated in some way with IT and the crypto space,” the researchers stressed. “MacSync’s compromise of software developers’ devices poses particular security risks for both end users and corporate systems, opening up expanded opportunities for attackers to further their intrusion.”</p><p>The full list of indicators of compromise (IoC) can be found on <a href="https://securelist.com/macsync-new-version/121383/" target="_blank" rel="nofollow">this link</a>.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/this-mac-malware-is-somehow-using-icloud-calendar-invites-to-try-and-steal-your-data</link>
                                                                            <description>
                            <![CDATA[ A loader talks to iCloud before deploying a sophisticated infostealer and stealing all your cryptos. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">yPWk9vreRvv4Xz2NSo2pi7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SNA6BvwnpUaBPrrGGoBTkK-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 25 Sep 2026 14:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SNA6BvwnpUaBPrrGGoBTkK-1920-80.jpg">
                                                            <media:credit><![CDATA[Unsplash]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[User holding an iPhone 8]]></media:description>                                                            <media:text><![CDATA[User holding an iPhone 8]]></media:text>
                                <media:title type="plain"><![CDATA[User holding an iPhone 8]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SNA6BvwnpUaBPrrGGoBTkK-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Kaspersky uncovers MacSync, a Mac infostealer delivered via iCloud calendar events and fake apps</strong></li><li><strong>Loader fetches instructions from calendar entries, then deploys malware exfiltrating credentials, wallets, and developer data</strong></li><li><strong>Newer variants add Objective‑C backdoor spoofing Finder, persistence, and expanded targeting of crypto and IT users</strong></li></ul><p>Cybercriminals have found a way to use iCloud calendar events and cloud storage to deliver a powerful infostealer to Mac devices. </p><p>The malware is called MacSync, and it’s hiding behind fake crypto wallets, or “cracked” commercial software. </p><p>Security researchers Kaspersky, who discovered the ongoing campaign, are urging Mac users to exercise caution when downloading programs, especially from third-party websites, and to be very skeptical of apps prompting for their admin password.</p><h2 id="why-calendar">Why calendar?</h2><p>Getting people to download and run <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> on their devices is not as easy as it sounds. </p><p>The victims need to be somehow tricked into downloading and running an app, and even when they do so, chances are the malicious program will be sniffed out by whatever antivirus solutions the device has running, before it can do any meaningful damage. Also, crooks don’t want to be forced to repeat the process every time they want to deploy a different variant, or type of malware. </p><p>So, they resort to all sorts of techniques and workarounds, from DLL sideloading, to malware loaders. </p><p>By separating the initial infection and the actual malware, cybercriminals can reduce detection rate and get more flexibility, but it creates a new problem: defenders can monitor the traffic going in and out of different apps and thus detect when a loader is deploying malware. </p><p>The challenge then becomes hiding the traffic, and MacSync does it by using the iCloud calendar. </p><p>After being downloaded and executed, the loader will reach out to the calendar - which is a totally benign activity that is unlikely to raise any suspicion - and look for a specific public event, pre-built by the attackers. In its description, it will find the instructions, and the location of, the actual infostealer, and deploy it to ultimately compromise the target device. In this case, the location was also in the iCloud.</p><p>The loader itself is being advertised through social media, SEO poisoning, and phishing. Victims are directed either to fraudulent websites or social media channels promoting cracked software, or free versions of advanced solutions. In at least one example, Kaspersky saw the loader being advertised as a cryptocurrency wallet. Victims are shown a typical ClickFix error, and told to fix it by pasting a command in the Terminal.</p><p>The command deploys the loader which, in turn, installs MacSync.</p><h2 id="a-quot-substantial-quot-overhaul">A "substantial" overhaul</h2><p>The infostealer emerged in April 2025, and was initially spun out of AMOS, one of the most popular information-stealing variants for the MacOS. It is based on Swift and has, since then, evolved to offer additional capabilities. According to Kaspersky, it can exfiltrate browser history, cookies, saved credentials, cryptocurrency wallet and app data, Telegram data, Keychain data, as well as system and device information. It can exfiltrate SSH, AWS, Kubernetes, Git, and shell configuration files, as well. </p><p>Newer variants come with an Objective-C backdoor spoofing the macOS default file manager, Finder. It establishes persistence, terminates notification processes to prevent alerts, and grants the attackers backdoor access, including running AppleScript received from the C2 server, deploying browser extensions, replacing the legitimate Ledger wallet app, collecting additional system information, and more. </p><p>Kaspersky also found an undefined command called “live_browser”, which downloads and runs a component named “sn_relay”, whose point has not yet been established. </p><p>The new versions “significantly” differ from older ones, Kaspersky said, stressing that the attackers “substantially” overhauled their approach. </p><p>“The nature of the data attackers seek to collect from a victim’s device, as well as the categories of applications the stealer disguises itself as, clearly indicates that this malware family primarily targets developers, crypto enthusiasts, and other users associated in some way with IT and the crypto space,” the researchers stressed. “MacSync’s compromise of software developers’ devices poses particular security risks for both end users and corporate systems, opening up expanded opportunities for attackers to further their intrusion.”</p><p>The full list of indicators of compromise (IoC) can be found on <a href="https://securelist.com/macsync-new-version/121383/" target="_blank" rel="nofollow">this link</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'Decades-old' bugs found affecting Windows, Android, macOS and Linux — but the OS makers don't see it as a big deal ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Graz University researchers found decades‑old flaws in file‑notification subsystems across Linux, Windows, macOS, and Android</strong></li><li><strong>Side‑channel attacks can infer keystrokes, visited websites, or even steal credentials via unprivileged access</strong></li><li><strong>Linux shipped partial mitigations (CVE‑2025‑68788); Microsoft and Apple acknowledged but did not patch, demo expected at ACM CCS 2026</strong></li></ul><p>Researchers have found a vulnerability in all major operating systems which could, in certain scenarios, allow threat actors to steal login credentials, or track which websites the target is visiting. OS makers, on the other hand, don’t seem all too phased about it.</p><p>The bug is described as a side-channel attack - a type of attack in which threat actors simply observe how the system operates and extract valuable secrets through indirect clues. For example, by monitoring how much power the chip takes at any given moment in time, attackers can <a href="https://www.techradar.com/pro/this-security-flaw-could-affect-nearly-all-cpus-but-it-might-not-be-all-bad" target="_blank">observe and extract passwords</a>.</p><p>It was discovered by security researchers from Austria’s Graz University of Technology: Sudheendra Raghav Neela, Xufan Zhao, Jeanette Angelika Wultsch, Hannes Weissteiner, Florian Draschbacher, Stefan Gast, and Daniel Gruss.</p><h2 id="notifying-the-system">Notifying the system</h2><p>This particular side-channel vulnerability was found in the file-notification subsystem running in pretty much every OS in existence today. The subsystem is built to notify applications when files on a system change. Not what has changed, just that a change occurred. The bug is allegedly quite old, too.</p><p>"We found decades-old bugs on [these operating systems], all rooted in the file-notification subsystems that every modern OS ships to inform applications when files change," said Sudheendra Raghav Neela, a doctoral student at TU Graz, in an email to <a href="https://www.theregister.com/security/2026/09/24/decades-old-file-security-flaws-found-in-android-linux-macos-and-windows/5298672" target="_blank"><em>The Register</em></a>.</p><p>On Linux, the subsystem is called inotify and it’s been affected since 2005. On Android it’s FileObserver (affected since 2008), and on Windows - ReadDirectoryChangesW - flawed since the year 2000. On MacOS, it’s called FSEvents, vulnerable since 2007.</p><p>In the paper, the researchers claim file event information can help attackers conclude what other users on a computer are doing. They can launch an inter-keystroke-timing attack, inferring what users are inputting (both locally and remotely), reveal which websites they visit, and possibly even steal <a href="https://www.techradar.com/best/password-manager" target="_blank">login credentials</a> through UI redress. </p><p>The problem stems from the fact that unprivileged users are allowed to access the file notification subsystem. This primarily relates to files that can be read by multiple users, but apparently, there are quite a few files on a system that fall into that category. </p><h2 id="no-patch">No patch</h2><p>"On Linux, watching a readable directory leaks events on files inside it you cannot even read: watching /dev/input gives a notification on every keystroke, which we turn into a local inter-keystroke timing attack with a 93.1–100% [keystroke accuracy] score across seven users and a remote (SSH) one at 100%,” Neela said.</p><p>The percentage range means the attack won’t work in all cases, which is more-or-less standard with side-channel attacks. They are notoriously difficult to pull off, which is also likely why most OS makers barely flinched at the news. </p><p>All of them were notified of the findings roughly a year ago, and most of them never bothered to address it. Linux introduced some mitigations, including CVE-2025-68788, which prevents inotify from generating certain “access” and “modify” events for special files. The fix was shipped to multiple kernels and Linux distros, but it addresses only part of the broader attack techniques that the researchers described.</p><p>Microsoft and Apple apparently acknowledged the findings, but apart from that - did very little. Microsoft told the researchers the behavior of ReadDirectoryChangesW was "by-design", although the feature is undocumented. They believe the ability to monitor file paths across users is not a vulnerability worthy of a patch. The report does not mention Apple doing anything about it, either.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/decades-old-bugs-found-affecting-windows-android-macos-and-linux-but-the-os-makers-dont-see-it-as-a-big-deal</link>
                                                                            <description>
                            <![CDATA[ The OS makers don't see the issue as a particularly big problem, and Microsoft even said it was by design. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">UHqENatouAb6wmY47LxBzJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 25 Sep 2026 13:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / ZinetroN]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Nytt DDoS-rekord]]></media:description>                                                            <media:text><![CDATA[Concept art representing cybersecurity principles]]></media:text>
                                <media:title type="plain"><![CDATA[Concept art representing cybersecurity principles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Graz University researchers found decades‑old flaws in file‑notification subsystems across Linux, Windows, macOS, and Android</strong></li><li><strong>Side‑channel attacks can infer keystrokes, visited websites, or even steal credentials via unprivileged access</strong></li><li><strong>Linux shipped partial mitigations (CVE‑2025‑68788); Microsoft and Apple acknowledged but did not patch, demo expected at ACM CCS 2026</strong></li></ul><p>Researchers have found a vulnerability in all major operating systems which could, in certain scenarios, allow threat actors to steal login credentials, or track which websites the target is visiting. OS makers, on the other hand, don’t seem all too phased about it.</p><p>The bug is described as a side-channel attack - a type of attack in which threat actors simply observe how the system operates and extract valuable secrets through indirect clues. For example, by monitoring how much power the chip takes at any given moment in time, attackers can <a href="https://www.techradar.com/pro/this-security-flaw-could-affect-nearly-all-cpus-but-it-might-not-be-all-bad" target="_blank">observe and extract passwords</a>.</p><p>It was discovered by security researchers from Austria’s Graz University of Technology: Sudheendra Raghav Neela, Xufan Zhao, Jeanette Angelika Wultsch, Hannes Weissteiner, Florian Draschbacher, Stefan Gast, and Daniel Gruss.</p><h2 id="notifying-the-system">Notifying the system</h2><p>This particular side-channel vulnerability was found in the file-notification subsystem running in pretty much every OS in existence today. The subsystem is built to notify applications when files on a system change. Not what has changed, just that a change occurred. The bug is allegedly quite old, too.</p><p>"We found decades-old bugs on [these operating systems], all rooted in the file-notification subsystems that every modern OS ships to inform applications when files change," said Sudheendra Raghav Neela, a doctoral student at TU Graz, in an email to <a href="https://www.theregister.com/security/2026/09/24/decades-old-file-security-flaws-found-in-android-linux-macos-and-windows/5298672" target="_blank"><em>The Register</em></a>.</p><p>On Linux, the subsystem is called inotify and it’s been affected since 2005. On Android it’s FileObserver (affected since 2008), and on Windows - ReadDirectoryChangesW - flawed since the year 2000. On MacOS, it’s called FSEvents, vulnerable since 2007.</p><p>In the paper, the researchers claim file event information can help attackers conclude what other users on a computer are doing. They can launch an inter-keystroke-timing attack, inferring what users are inputting (both locally and remotely), reveal which websites they visit, and possibly even steal <a href="https://www.techradar.com/best/password-manager" target="_blank">login credentials</a> through UI redress. </p><p>The problem stems from the fact that unprivileged users are allowed to access the file notification subsystem. This primarily relates to files that can be read by multiple users, but apparently, there are quite a few files on a system that fall into that category. </p><h2 id="no-patch">No patch</h2><p>"On Linux, watching a readable directory leaks events on files inside it you cannot even read: watching /dev/input gives a notification on every keystroke, which we turn into a local inter-keystroke timing attack with a 93.1–100% [keystroke accuracy] score across seven users and a remote (SSH) one at 100%,” Neela said.</p><p>The percentage range means the attack won’t work in all cases, which is more-or-less standard with side-channel attacks. They are notoriously difficult to pull off, which is also likely why most OS makers barely flinched at the news. </p><p>All of them were notified of the findings roughly a year ago, and most of them never bothered to address it. Linux introduced some mitigations, including CVE-2025-68788, which prevents inotify from generating certain “access” and “modify” events for special files. The fix was shipped to multiple kernels and Linux distros, but it addresses only part of the broader attack techniques that the researchers described.</p><p>Microsoft and Apple apparently acknowledged the findings, but apart from that - did very little. Microsoft told the researchers the behavior of ReadDirectoryChangesW was "by-design", although the feature is undocumented. They believe the ability to monitor file paths across users is not a vulnerability worthy of a patch. The report does not mention Apple doing anything about it, either.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are targeting a critical WordPress flaw, so be on your guard ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>WordPress Core flaw CVE‑2026‑87902 (path traversal, 8.1 severity) enables PHP file inclusion and possible RCE</strong></li><li><strong>Patch released in v7.1.2 and backported to 4.7+; exploitation began within hours, now widespread</strong></li><li><strong>Admins must urgently update; interim mitigations include blocking traversal sequences and disabling risky ARP/PHP settings</strong></li></ul><p>Hackers are actively exploiting a high severity vulnerability in WordPress that can lead to full website takeover, researchers are saying. A patch is available, and WordPress users are urged to upgrade immediately or risk losing access to their assets.</p><p>Discovered by security researcher Robert Ressl, the vulnerability in question is tracked as CVE-2026-87902. It is an 8.1/10 (high severity) unauthenticated path traversal flaw affecting WordPress Core. According to WordPress itself, as well as the National Vulnerability Database, the bug can lead to local PHP file inclusion and, in certain scenarios, remote code execution (RCE). </p><p>"An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file outside the active theme directories," it was said in the official security advisory.</p><h2 id="achieving-rce">Achieving RCE</h2><p>WordPress is the world’s number one <a href="https://www.techradar.com/news/the-best-website-builder" target="_blank">website hosting and builder platform</a>, powering more than half of all websites active on the internet right now. However, that doesn’t mean all of them are susceptible to RCE. Only websites ticking these boxes are at risk:</p><p>Sites with parent or child themes that have a top-level directory with a name starting with ‘page-’ (for example, ‘page-templates). </p><p>Threat actors must target a local .PHP file that exists and is readable by the web server</p><p>The web server account must be able to read the included file (for example, pearcmd.php, if PHP’s register_argc_argv setting is active)</p><p><a href="https://www.techradar.com/pro/what-is-wordpress" target="_blank">WordPress</a> said that both the official PHP image for Docker, and the default cPanel configuration, are affected (users must be running a PHP version before 8.5, though). </p><p>The issue was fixed in version 7.1.2, which is now available for download. Fixes were also backported to older versions up to 4.7. Releases before 4.8 are not supported, it was said, and will not be getting a fix. </p><h2 id="attacking-vulnerable-websites">Attacking vulnerable websites</h2><p>Wordpress security company Patchstack said the first exploitation attempts started roughly five hours after the patch was released, and these were primarily reconnaissance efforts. In the hours to follow, malicious activity increased tenfold, it was said, as crooks started attempting to deliver malicious payloads to vulnerable websites, as well. </p><p>“When this post first went up, every request we had seen was reconnaissance against harmless core files,” Patchstack said. “That is no longer true. Attackers are now including pearcmd.php and using it to write PHP files to disk, and public scanning tooling for this CVE is in circulation.”</p><p>At first, Patchstack said the attacks were coming from a handful of IP addresses, and advised website admins to simply block them. However, the attacks have now become rather widespread, meaning blocking individual addresses is no longer a viable strategy. They urge everyone to apply the patch without delay:</p><p>“The first evening came from a small cluster of addresses. It is now spread across a few hundred, so blocklisting individual sources is not a strategy. The heaviest talkers at the time of writing:</p><p>43.250.53.42</p><p>180.251.159.243</p><p>195.178.110.247</p><p>107.189.14.87</p><p>45.61.184.170</p><p>92.246.130.76</p><p>The file write attempts specifically come from a much smaller subset of those addresses, which is the usual pattern of a few operators acting on results that a much larger scanning population produced.”</p><p>Those that cannot update immediately should reject traversal sequences in the pagename parameter, Patchstack added. A real page slug never contains one, they added, meaning it can be blocked without affecting normal traffic. Furthermore, disabling register_argc_argv does not fix the inclusion but it does break the pearcmd chain, which is the difference between an information leak and code execution.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/hackers-start-exploiting-critical-wordpress-flaw-for-code-execution/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/hackers-are-targeting-a-critical-wordpress-flaw-so-be-on-your-guard</link>
                                                                            <description>
                            <![CDATA[ Mitigations and a patch are already available but given the severity of the WordPress flaw, immediate patching is recommended. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8GedEHDmpJs5EDPhg8NwgT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 24 Sep 2026 14:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WordPress logo on mobile]]></media:description>                                                            <media:text><![CDATA[WordPress logo on mobile]]></media:text>
                                <media:title type="plain"><![CDATA[WordPress logo on mobile]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>WordPress Core flaw CVE‑2026‑87902 (path traversal, 8.1 severity) enables PHP file inclusion and possible RCE</strong></li><li><strong>Patch released in v7.1.2 and backported to 4.7+; exploitation began within hours, now widespread</strong></li><li><strong>Admins must urgently update; interim mitigations include blocking traversal sequences and disabling risky ARP/PHP settings</strong></li></ul><p>Hackers are actively exploiting a high severity vulnerability in WordPress that can lead to full website takeover, researchers are saying. A patch is available, and WordPress users are urged to upgrade immediately or risk losing access to their assets.</p><p>Discovered by security researcher Robert Ressl, the vulnerability in question is tracked as CVE-2026-87902. It is an 8.1/10 (high severity) unauthenticated path traversal flaw affecting WordPress Core. According to WordPress itself, as well as the National Vulnerability Database, the bug can lead to local PHP file inclusion and, in certain scenarios, remote code execution (RCE). </p><p>"An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file outside the active theme directories," it was said in the official security advisory.</p><h2 id="achieving-rce">Achieving RCE</h2><p>WordPress is the world’s number one <a href="https://www.techradar.com/news/the-best-website-builder" target="_blank">website hosting and builder platform</a>, powering more than half of all websites active on the internet right now. However, that doesn’t mean all of them are susceptible to RCE. Only websites ticking these boxes are at risk:</p><p>Sites with parent or child themes that have a top-level directory with a name starting with ‘page-’ (for example, ‘page-templates). </p><p>Threat actors must target a local .PHP file that exists and is readable by the web server</p><p>The web server account must be able to read the included file (for example, pearcmd.php, if PHP’s register_argc_argv setting is active)</p><p><a href="https://www.techradar.com/pro/what-is-wordpress" target="_blank">WordPress</a> said that both the official PHP image for Docker, and the default cPanel configuration, are affected (users must be running a PHP version before 8.5, though). </p><p>The issue was fixed in version 7.1.2, which is now available for download. Fixes were also backported to older versions up to 4.7. Releases before 4.8 are not supported, it was said, and will not be getting a fix. </p><h2 id="attacking-vulnerable-websites">Attacking vulnerable websites</h2><p>Wordpress security company Patchstack said the first exploitation attempts started roughly five hours after the patch was released, and these were primarily reconnaissance efforts. In the hours to follow, malicious activity increased tenfold, it was said, as crooks started attempting to deliver malicious payloads to vulnerable websites, as well. </p><p>“When this post first went up, every request we had seen was reconnaissance against harmless core files,” Patchstack said. “That is no longer true. Attackers are now including pearcmd.php and using it to write PHP files to disk, and public scanning tooling for this CVE is in circulation.”</p><p>At first, Patchstack said the attacks were coming from a handful of IP addresses, and advised website admins to simply block them. However, the attacks have now become rather widespread, meaning blocking individual addresses is no longer a viable strategy. They urge everyone to apply the patch without delay:</p><p>“The first evening came from a small cluster of addresses. It is now spread across a few hundred, so blocklisting individual sources is not a strategy. The heaviest talkers at the time of writing:</p><p>43.250.53.42</p><p>180.251.159.243</p><p>195.178.110.247</p><p>107.189.14.87</p><p>45.61.184.170</p><p>92.246.130.76</p><p>The file write attempts specifically come from a much smaller subset of those addresses, which is the usual pattern of a few operators acting on results that a much larger scanning population produced.”</p><p>Those that cannot update immediately should reject traversal sequences in the pagename parameter, Patchstack added. A real page slug never contains one, they added, meaning it can be blocked without affecting normal traffic. Furthermore, disabling register_argc_argv does not fix the inclusion but it does break the pearcmd chain, which is the difference between an information leak and code execution.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/hackers-start-exploiting-critical-wordpress-flaw-for-code-execution/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Massive Chinese hack uses AI agents to steal over 600,000 credit cards and hit hundreds of sites with malware ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Gambit researchers uncovered ongoing AI‑driven skimming campaign stealing 600,000+ payment records since July 2026</strong></li><li><strong>Attackers used three autonomous harnesses (Strix, Cairn, Hermes) to compromise dozens of retail sites cheaply</strong></li><li><strong>Victims include major US firms; campaign shows AI enables faster, persistent, low‑cost cyberattacks at scale</strong></li></ul><p>In July 2026, a hacker tasked autonomous AI agents to attack retail organizations around the world, deploy <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">credit card skimmers</a>, and steal payment data. </p><p>Since then, the bots launched hundreds of attack projects, compromised dozens of organizations, and stole at least 600,000 <a href="https://www.techradar.com/best/best-payment-gateways" target="_blank">payment</a> records - and to make matters worse, the campaign is still live, attacking and breaking into websites as we speak. </p><p>All of this was <a href="https://gambit.security/blog-posts/autonomous-ai-agents-online-retailers-25-a-company" target="_blank">reported</a> by security researchers Gambit, who said they managed to recover the operator’s staging server and through it - reconstruct the ongoing campaign. They also saw the skimmers live on victim websites, and sifted through logs and AI claims found on the attacker’s server. In just five days, between September 10 and 15, the agents made 105 attack waves and compromised 27 organizations “to varying degrees.”</p><p>Among the victims are a Fortune 500 hospitality company, a “major” US airline, a large private US industrial supplies distributor, and a US online fashion retailer. One of the AI tools would use a website ranking service to produce a list of potential targets, focusing primarily on those running custom-built software.</p><h2 id="a-fistful-of-dollars">A fistful of dollars</h2><p>But the victims are not the “interesting” part of this story - the attackers are. Gambit believes they are financially motivated Chinese threat actors. They are using three AI “harnesses” (frameworks, essentially), which can run almost the entire attack chain autonomously, striking around 10 companies a day, for a handful of dollars per company. </p><p>In four weeks, the attackers spent around $7,000, meaning that their entire cost for the operation so far was no more than $18,000. Breaking it down, it means that the attacker spent around $25 per target. </p><p>“Spread over the companies attacked, this is a marginal cost of a few US dollars to a few tens of US dollars for each targeted company,” Gambit’s researchers said. “The operator’s own cost review gives a similar figure, a mean of $25.46 over 101 completed scans, from $3.13 for the cheapest target to $79.31 for the most expensive.”</p><p>“Where access was achieved, it usually took less than a day, and in many cases just a few hours. We also detected instructions in the attacker’s playbook that could disrupt the operations of a company as a result of data deletion or cleanup procedures run by the agent - and this has indeed happened in some of the breaches,” Gambit said.</p><h2 id="the-three-harnesses">The three harnesses</h2><p>The three harnesses are called Strix, Cairn, and Hermes. </p><p>Gambit describes Hermes as an open source autonomous AI agent with a persistent memory, skills that the agent wrote and edited itself, a searchable archive of past sessions, scheduled jobs, and a web console. On the staging server the researchers analyzed, it loaded a Chinese system persona called “SOUL - Red Team Operator”, which contained 121 skills (78 attack skills). </p><p>“Hermes is the operator’s console for orchestrating the activity and for direct hacking activities,” Gambit explained. “It used Anthropic’s opus-4.6 (after newer models refused its requests), with 1,951 prompts typed by the human across 260 sessions - only a few prompts per target. The human prompts are short instructions in Chinese, usually launching an attack, tasking the agent with a general next step, or what to do next after achieving access.”</p><p>Strix is an open-source AI pentest tool, while Cairn is an autonomous pentest engine. It receives target domains and an objective, such as to get a shell or admin access, then runs for hours until it achieves the objective, times out, or is stopped. Cairn used DeepSeek v4.1 Flash, it was said. </p><p>Gambit’s researchers seem to be rather impressed with the campaign. They described it as very low cost, with a level of patience, persistence, and creativity that most human attackers would be “unlikely to sustain”, managing to achieve “far greater results, far faster.” </p><p>They have also called to arms, urging organizations to “adapt to a reality where attacks are significantly faster and more comprehensive.” To do that, they must adopt a resilience-first mentality and deploy a security stack that can match the AI on speed.</p><p>Many of the affected organizations were notified, and the skimmers were removed, they said.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/massive-chinese-hack-uses-ai-agents-to-steal-over-600-000-credit-cards-and-hit-hundreds-of-sites-with-malware</link>
                                                                            <description>
                            <![CDATA[ Three AI frameworks operated almost entirely on their own. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9v8TpKaEhecTApM5ByfcoK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AvZcjmUMtehpuha5oJLcTB-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 24 Sep 2026 13:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/AvZcjmUMtehpuha5oJLcTB-1920-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image Credit: Geralt / Pixabay]]></media:description>                                                            <media:text><![CDATA[Who will win the AI race?]]></media:text>
                                <media:title type="plain"><![CDATA[Who will win the AI race?]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AvZcjmUMtehpuha5oJLcTB-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Gambit researchers uncovered ongoing AI‑driven skimming campaign stealing 600,000+ payment records since July 2026</strong></li><li><strong>Attackers used three autonomous harnesses (Strix, Cairn, Hermes) to compromise dozens of retail sites cheaply</strong></li><li><strong>Victims include major US firms; campaign shows AI enables faster, persistent, low‑cost cyberattacks at scale</strong></li></ul><p>In July 2026, a hacker tasked autonomous AI agents to attack retail organizations around the world, deploy <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">credit card skimmers</a>, and steal payment data. </p><p>Since then, the bots launched hundreds of attack projects, compromised dozens of organizations, and stole at least 600,000 <a href="https://www.techradar.com/best/best-payment-gateways" target="_blank">payment</a> records - and to make matters worse, the campaign is still live, attacking and breaking into websites as we speak. </p><p>All of this was <a href="https://gambit.security/blog-posts/autonomous-ai-agents-online-retailers-25-a-company" target="_blank">reported</a> by security researchers Gambit, who said they managed to recover the operator’s staging server and through it - reconstruct the ongoing campaign. They also saw the skimmers live on victim websites, and sifted through logs and AI claims found on the attacker’s server. In just five days, between September 10 and 15, the agents made 105 attack waves and compromised 27 organizations “to varying degrees.”</p><p>Among the victims are a Fortune 500 hospitality company, a “major” US airline, a large private US industrial supplies distributor, and a US online fashion retailer. One of the AI tools would use a website ranking service to produce a list of potential targets, focusing primarily on those running custom-built software.</p><h2 id="a-fistful-of-dollars">A fistful of dollars</h2><p>But the victims are not the “interesting” part of this story - the attackers are. Gambit believes they are financially motivated Chinese threat actors. They are using three AI “harnesses” (frameworks, essentially), which can run almost the entire attack chain autonomously, striking around 10 companies a day, for a handful of dollars per company. </p><p>In four weeks, the attackers spent around $7,000, meaning that their entire cost for the operation so far was no more than $18,000. Breaking it down, it means that the attacker spent around $25 per target. </p><p>“Spread over the companies attacked, this is a marginal cost of a few US dollars to a few tens of US dollars for each targeted company,” Gambit’s researchers said. “The operator’s own cost review gives a similar figure, a mean of $25.46 over 101 completed scans, from $3.13 for the cheapest target to $79.31 for the most expensive.”</p><p>“Where access was achieved, it usually took less than a day, and in many cases just a few hours. We also detected instructions in the attacker’s playbook that could disrupt the operations of a company as a result of data deletion or cleanup procedures run by the agent - and this has indeed happened in some of the breaches,” Gambit said.</p><h2 id="the-three-harnesses">The three harnesses</h2><p>The three harnesses are called Strix, Cairn, and Hermes. </p><p>Gambit describes Hermes as an open source autonomous AI agent with a persistent memory, skills that the agent wrote and edited itself, a searchable archive of past sessions, scheduled jobs, and a web console. On the staging server the researchers analyzed, it loaded a Chinese system persona called “SOUL - Red Team Operator”, which contained 121 skills (78 attack skills). </p><p>“Hermes is the operator’s console for orchestrating the activity and for direct hacking activities,” Gambit explained. “It used Anthropic’s opus-4.6 (after newer models refused its requests), with 1,951 prompts typed by the human across 260 sessions - only a few prompts per target. The human prompts are short instructions in Chinese, usually launching an attack, tasking the agent with a general next step, or what to do next after achieving access.”</p><p>Strix is an open-source AI pentest tool, while Cairn is an autonomous pentest engine. It receives target domains and an objective, such as to get a shell or admin access, then runs for hours until it achieves the objective, times out, or is stopped. Cairn used DeepSeek v4.1 Flash, it was said. </p><p>Gambit’s researchers seem to be rather impressed with the campaign. They described it as very low cost, with a level of patience, persistence, and creativity that most human attackers would be “unlikely to sustain”, managing to achieve “far greater results, far faster.” </p><p>They have also called to arms, urging organizations to “adapt to a reality where attacks are significantly faster and more comprehensive.” To do that, they must adopt a resilience-first mentality and deploy a security stack that can match the AI on speed.</p><p>Many of the affected organizations were notified, and the skimmers were removed, they said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'This situation is obviously unacceptable': OpenAI agent allegedly hacks Australian government healthcare website ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>OpenAI agent breached Australia’s Medicare portal on June 18, 2026, accessing internal files</strong></li><li><strong>Government says no personal medical data was taken, but three other agencies may be affected</strong></li><li><strong>PM Albanese slammed OpenAI’s 84‑day delay in disclosure, calling the notification “unacceptable” and warning of legal consequences</strong></li></ul><p>An OpenAI agent has allegedly broken into a website of the Australian government, which has slammed the “unacceptable” attack, promising an in-depth investigation, and threatening “legal consequences”.</p><p>Australian Prime Minister Anthony Albanese revealed how in June 2026, OpenAI’s research team tasked the agent with researching public medicine spending, as part of an internal capability evaluation - but as the agent got to work, it was initially denied access to some of the information it requested.</p><p>However, instead of stopping, or trying to find a different lawful way of obtaining this data, it circumvented those restrictions and landed inside the infrastructure behind Services Australia’s public-facing Medicare Statistics Reporting Service portal.</p><h2 id="ai-agent-did-what">AI agent did what?</h2><p>The public details are still quite limited, and we don’t know the technicalities of what the AI actually did. </p><p>The acting prime minister, Richard Marles, told the media during a recent press conference that the AI “scaled the fence”, despite the portal having security measures in place. </p><p>The bot apparently accessed internal infrastructure and wrote files to an internal server but exactly what it wrote, how it obtained the access, and precisely which technical mechanism it used, is still not public knowledge.</p><p>Once inside, it accessed both public and non-public files, but individual medical data was not accessed and the system itself was not compromised, the Australian government said. </p><p>There is also the possibility that three other government systems were affected - the Australian Institute of Health and Welfare and two state-based agencies - the New South Wales Bureau of Crime Statistics and Research and the Victorian Department of Health. However, this has not been confirmed yet.</p><p>"No personal information is believed to have been accessed at this stage, but investigations are ongoing," Albanese said. "Nonetheless this situation is obviously unacceptable."</p><h2 id="openai-39-s-sluggish-escalation">OpenAI's sluggish escalation</h2><p>Albanese was particularly unsatisfied with how OpenAI handled the situation. The breach happened on June 18, but it took the company 84 days to notify the Australian government of the incident. And when it did - it did so in a manner better suited for an amateurish start-up rather than one of the most important organizations on the planet right now.</p><p>OpenAI was apparently evaluating its models, and investigating “misaligned model activity” when, on August 11, it discovered the breach in Australia. It seems the <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agent</a> simply did not take “no” for an answer. The company then notified Services Australia on September 10 - almost three months after the incident. To make matters worse, the company reached out via publicdisclosures@servicesaustralia.gov.au, inbox researchers usually use to report potential vulnerabilities, instead of trying to escalate the incident higher.  </p><p>Services Australia reviewed the information and notified the Australian Signals Directorate on September 15.</p><p>When the news reached prime minister Anthony Albanese, he spoke to OpenAI CEO, Sam Altman, and expressed the country’s “extreme concern” about this incident, as well as his “disappointment that it took the company way too long to inform the government what had occurred.” He also pointed out the way OpenAI reached out: “The notification was an email sent just to the public mailbox.” Albanese described the “nature of the notification” as “unacceptable.”</p><p>The Australian government is now looking into the matter to see if any laws were broken and what legal consequences, if any, could follow.</p><p>"And obviously we will investigate all of that. What the consequences are, if there has been a breach of the law, but also part of the task force is to assess whether or not the legal regime we have in place is fit–for–purpose in a world where we have an emerging AI capability,” Marles said. </p><p><em>Via </em><a href="https://www.bbc.com/news/articles/c6vgy0333dppo" target="_blank"><em>BBC</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/this-situation-is-obviously-unacceptable-openai-agent-allegedly-hacks-australian-government-healthcare-website</link>
                                                                            <description>
                            <![CDATA[ Australian government calls OpenAI behavior "unacceptable" as it investigates the incident further. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sn3MBaUJAQKEmMaiLafiBc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6X3ZZcXUrcxus6MyJ3GM7M-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 24 Sep 2026 10:13:46 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[OpenAI]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6X3ZZcXUrcxus6MyJ3GM7M-1920-80.jpg">
                                                            <media:credit><![CDATA[OpenAI]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[OpenAI logo]]></media:description>                                                            <media:text><![CDATA[OpenAI logo]]></media:text>
                                <media:title type="plain"><![CDATA[OpenAI logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6X3ZZcXUrcxus6MyJ3GM7M-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>OpenAI agent breached Australia’s Medicare portal on June 18, 2026, accessing internal files</strong></li><li><strong>Government says no personal medical data was taken, but three other agencies may be affected</strong></li><li><strong>PM Albanese slammed OpenAI’s 84‑day delay in disclosure, calling the notification “unacceptable” and warning of legal consequences</strong></li></ul><p>An OpenAI agent has allegedly broken into a website of the Australian government, which has slammed the “unacceptable” attack, promising an in-depth investigation, and threatening “legal consequences”.</p><p>Australian Prime Minister Anthony Albanese revealed how in June 2026, OpenAI’s research team tasked the agent with researching public medicine spending, as part of an internal capability evaluation - but as the agent got to work, it was initially denied access to some of the information it requested.</p><p>However, instead of stopping, or trying to find a different lawful way of obtaining this data, it circumvented those restrictions and landed inside the infrastructure behind Services Australia’s public-facing Medicare Statistics Reporting Service portal.</p><h2 id="ai-agent-did-what">AI agent did what?</h2><p>The public details are still quite limited, and we don’t know the technicalities of what the AI actually did. </p><p>The acting prime minister, Richard Marles, told the media during a recent press conference that the AI “scaled the fence”, despite the portal having security measures in place. </p><p>The bot apparently accessed internal infrastructure and wrote files to an internal server but exactly what it wrote, how it obtained the access, and precisely which technical mechanism it used, is still not public knowledge.</p><p>Once inside, it accessed both public and non-public files, but individual medical data was not accessed and the system itself was not compromised, the Australian government said. </p><p>There is also the possibility that three other government systems were affected - the Australian Institute of Health and Welfare and two state-based agencies - the New South Wales Bureau of Crime Statistics and Research and the Victorian Department of Health. However, this has not been confirmed yet.</p><p>"No personal information is believed to have been accessed at this stage, but investigations are ongoing," Albanese said. "Nonetheless this situation is obviously unacceptable."</p><h2 id="openai-39-s-sluggish-escalation">OpenAI's sluggish escalation</h2><p>Albanese was particularly unsatisfied with how OpenAI handled the situation. The breach happened on June 18, but it took the company 84 days to notify the Australian government of the incident. And when it did - it did so in a manner better suited for an amateurish start-up rather than one of the most important organizations on the planet right now.</p><p>OpenAI was apparently evaluating its models, and investigating “misaligned model activity” when, on August 11, it discovered the breach in Australia. It seems the <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agent</a> simply did not take “no” for an answer. The company then notified Services Australia on September 10 - almost three months after the incident. To make matters worse, the company reached out via publicdisclosures@servicesaustralia.gov.au, inbox researchers usually use to report potential vulnerabilities, instead of trying to escalate the incident higher.  </p><p>Services Australia reviewed the information and notified the Australian Signals Directorate on September 15.</p><p>When the news reached prime minister Anthony Albanese, he spoke to OpenAI CEO, Sam Altman, and expressed the country’s “extreme concern” about this incident, as well as his “disappointment that it took the company way too long to inform the government what had occurred.” He also pointed out the way OpenAI reached out: “The notification was an email sent just to the public mailbox.” Albanese described the “nature of the notification” as “unacceptable.”</p><p>The Australian government is now looking into the matter to see if any laws were broken and what legal consequences, if any, could follow.</p><p>"And obviously we will investigate all of that. What the consequences are, if there has been a breach of the law, but also part of the task force is to assess whether or not the legal regime we have in place is fit–for–purpose in a world where we have an emerging AI capability,” Marles said. </p><p><em>Via </em><a href="https://www.bbc.com/news/articles/c6vgy0333dppo" target="_blank"><em>BBC</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FBI claims fake cop scams are costing victims billions —here's what to look out for ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>$1.6 billion has been claimed by scammers impersonating police and government officials</strong></li><li><strong>The FBI’s Internet Crime Complaint Center (IC3) received almost 61,000 complaints concerning such scams between January 2025 and July 2026</strong></li><li><strong>Some scams targeted foreign nationals and immigrants, threatening to cancel passports or impose extradition, unless payment is made</strong></li></ul><p>Between January 2025 and July 2026, the FBI’s Internet Crime Complaint Center received almost 61,000 complaints concerning scams using police and government official impersonation tactics. As a result, around $1.6 billion is believed to have been scammed and extorted.</p><p>Tactics used by scammers included unsolicited phone calls and in some cases video calls, with victims losing an average of $26,000 per scam.</p><p>Particularly concerning is the targeting of foreign nationals, international students, and immigrant citizens, often with threats to cancel visas and home country passports. Incredibly, 10% of all losses were traced to a single scam, one that targeted fewer than 3% of the victims.</p><h2 id="foreign-national-victims">Foreign national victims</h2><p>According to the FBI, the fake cop/fake government official scam has various angles, from alleging missed jury duty to threatening arrest due to circumstantial links to an alleged crime.</p><p>The demand from the scammers, inevitably, is payment.</p><p>Making a commitment to extreme lengths of scamming and extortion, the criminals took things to a new level when it came to targeting victims. International students, visiting foreign nationals, and other immigrant citizens were given special treatment. Not only were they threatened with extradition, there was also the implication of victims losing their home country passport.</p><p>To convince the target, scammers built actual studio sets, donned uniforms or suits, and appeared in video calls to the victims, who were convinced they were talking to foreign law enforcement agents or US-based diplomats. Creating the illusion of officialdom to sell the scam, victims paid whatever necessary to stay in their adopted country.</p><h2 id="how-to-spot-the-scam">How to spot the scam</h2><p>It is important to note that not all fraud of this type takes place in the US. These may be online or offline, but the so-called fake cop scam is an international criminal phenomenon. So, how do you avoid it?</p><p>We’ll assume you’ve answered a call inadvertently rather than having spam calls blocked (that should be set already).</p><p>First, remain calm. These situations are designed to impose stress and heightened anxiety. Scammers rely on these factors to cloud their victim’s judgement and force the narrative they are selling (“you missed jury duty”/“your presence in the country is illegal.”)</p><p>Second, it is vital to request credentials. Failure to provide these is the first red flag that the person communicating with you is not what they seem. That’s your cue to end the conversation. </p><p>Third, check the credentials. It doesn’t matter how long this takes – a legitimate caller will not mind waiting for you to do the necessary background check, even if it means them calling back.</p><p>Finally, and most importantly: neither law enforcement, security services, nor the FBI will demand money. If that is happening, it’s time to end the call.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/fbi-claims-fake-cop-scams-are-costing-victims-billions-heres-what-to-look-out-for</link>
                                                                            <description>
                            <![CDATA[ FBI reports impersonating law enforcement and government officials has netted scammers around $1.6 billion since January 2025 – but that is only based on reported cases, so the true figure could be much higher ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VCgpkB88rLQLdc9Z5gzacb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/z7YMfH58e2jpmr6TUmi6GG-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 24 Sep 2026 01:35:00 +0000</pubDate>                                                                                                                                <updated>Thu, 24 Sep 2026 15:55:58 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christian Cawley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zBDYnjPnB2XPvhKbYX9Kuc-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Christian Cawley has extensive experience as a writer and editor in consumer electronics, IT and entertainment media. He has contributed to TechRadar since 2017 and has been published in Computer Weekly, Linux Format, ComputerActive, and other publications. &lt;/p&gt;&lt;p&gt;Beyond TechRadar, he heads up the team at smart home website Matter Alpha, and writes about retro gaming at Gaming Retro. &lt;/p&gt;&lt;p&gt;Formerly the editor responsible for Linux, Security, Programming, and DIY at MakeUseOf, Christian previously worked as a desktop and software support specialist in the public and private sectors.&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/z7YMfH58e2jpmr6TUmi6GG-1920-80.jpg">
                                                            <media:credit><![CDATA[IURII KRASILNIKOV/Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person holds a smartphone with warning signs about scams visible. A laptop is nearby, showing icons related to finance and planning. The setting is bright and focused.]]></media:description>                                                            <media:text><![CDATA[A person holds a smartphone with warning signs about scams visible. A laptop is nearby, showing icons related to finance and planning. The setting is bright and focused.]]></media:text>
                                <media:title type="plain"><![CDATA[A person holds a smartphone with warning signs about scams visible. A laptop is nearby, showing icons related to finance and planning. The setting is bright and focused.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/z7YMfH58e2jpmr6TUmi6GG-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>$1.6 billion has been claimed by scammers impersonating police and government officials</strong></li><li><strong>The FBI’s Internet Crime Complaint Center (IC3) received almost 61,000 complaints concerning such scams between January 2025 and July 2026</strong></li><li><strong>Some scams targeted foreign nationals and immigrants, threatening to cancel passports or impose extradition, unless payment is made</strong></li></ul><p>Between January 2025 and July 2026, the FBI’s Internet Crime Complaint Center received almost 61,000 complaints concerning scams using police and government official impersonation tactics. As a result, around $1.6 billion is believed to have been scammed and extorted.</p><p>Tactics used by scammers included unsolicited phone calls and in some cases video calls, with victims losing an average of $26,000 per scam.</p><p>Particularly concerning is the targeting of foreign nationals, international students, and immigrant citizens, often with threats to cancel visas and home country passports. Incredibly, 10% of all losses were traced to a single scam, one that targeted fewer than 3% of the victims.</p><h2 id="foreign-national-victims">Foreign national victims</h2><p>According to the FBI, the fake cop/fake government official scam has various angles, from alleging missed jury duty to threatening arrest due to circumstantial links to an alleged crime.</p><p>The demand from the scammers, inevitably, is payment.</p><p>Making a commitment to extreme lengths of scamming and extortion, the criminals took things to a new level when it came to targeting victims. International students, visiting foreign nationals, and other immigrant citizens were given special treatment. Not only were they threatened with extradition, there was also the implication of victims losing their home country passport.</p><p>To convince the target, scammers built actual studio sets, donned uniforms or suits, and appeared in video calls to the victims, who were convinced they were talking to foreign law enforcement agents or US-based diplomats. Creating the illusion of officialdom to sell the scam, victims paid whatever necessary to stay in their adopted country.</p><h2 id="how-to-spot-the-scam">How to spot the scam</h2><p>It is important to note that not all fraud of this type takes place in the US. These may be online or offline, but the so-called fake cop scam is an international criminal phenomenon. So, how do you avoid it?</p><p>We’ll assume you’ve answered a call inadvertently rather than having spam calls blocked (that should be set already).</p><p>First, remain calm. These situations are designed to impose stress and heightened anxiety. Scammers rely on these factors to cloud their victim’s judgement and force the narrative they are selling (“you missed jury duty”/“your presence in the country is illegal.”)</p><p>Second, it is vital to request credentials. Failure to provide these is the first red flag that the person communicating with you is not what they seem. That’s your cue to end the conversation. </p><p>Third, check the credentials. It doesn’t matter how long this takes – a legitimate caller will not mind waiting for you to do the necessary background check, even if it means them calling back.</p><p>Finally, and most importantly: neither law enforcement, security services, nor the FBI will demand money. If that is happening, it’s time to end the call.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ These popular TP-Link home security cameras could be hacked to spy on you while you sleep, experts warn ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Cybersecurity company OPSWAT found a login bypass and a crash bug in TP-Link's Tapo C200 cameras</strong></li><li><strong>TP-Link has extended that to include its C120 offering too</strong></li><li><strong>Anyone on the same network could get admin access, live video, and recordings without requiring the owner's credentials</strong></li></ul><p>Security researchers at <a href="https://www.opswat.com/blog/authentication-bypass-and-dos-vulnerabilities-opswat-discovers-cve-2026-15315-cve-2026-15316-in-tp-link-tapo-cameras" target="_blank">OPSWAT</a> have detailed two high-severity flaws in TP-Link's Tapo C200, a pan-and-tilt indoor camera <a href="https://www.amazon.com/TP-Link-Tapo-Wireless-Security-C200/dp/B0829KDY9X" target="_blank" rel="nofollow">listed on Amazon for $26.99</a> and sold as a baby monitor and pet camera.</p><p>The more serious issue is that someone on the same network can log in as the camera's administrator without the password, accessing the live feed and stored recordings.</p><p>At least one other bug, which OPSWAT rates as critical in the same disclosure but does not detail, has not been published.</p><h2 id="a-localized-login-that-requires-no-authentication">A localized login that requires no authentication</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="sXT4pLeU6CuMN5RuzCofpY" name="TP-Link Tapo C200" alt="The TP-Link Tapo C200 camera" src="https://cdn.mos.cms.futurecdn.net/sXT4pLeU6CuMN5RuzCofpY-1920-80.png" mos="" align="middle" fullscreen="" width="1000" height="1000" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: TP-Link)</span></figcaption></figure><p>The TP-Link Tapo C200, as we <a href="https://www.techradar.com/pro/security/watch-out-tp-link-tapo-camera-vulnerabilities-could-let-hackers-spy-inside-homes-so-patch-now" target="_blank">noted in previous coverage of the incident,</a> isn't just another security camera that happens to be vulnerable; it is one of the most popular models on the market, clocking in at over 3,000 sales on Amazon alone.</p><p>The Tapo C120, in its current iteration, sells over 5,000 units monthly, even <a href="https://www.tp-link.com/us/support/faq/5248/" target="_blank" rel="nofollow">as the advisory notes</a> that its V1 hardware version is currently compromised until users update the firmware on their devices.</p><p>Both SKUs have received firmware updates that patch the vulnerabilities (CVE-2026-15315 & CVE-2026-15316), which are assigned 'high' scores of 8.7 and 7.1, respectively. However, according to TP-Link, CVE-2026-15316 does not affect the C120 camera.</p><p>However, the former vulnerability is the more pressing of the two and, according to OPSWAT, is particularly problematic for users because of how the C120 and C200 cameras function.</p><p>Both run a local management interface over HTTPS and use a challenge-response login designed to prove a client knows the owner's password. Khoi Tran, a graduate fellow at OPSWAT, and his mentor, Thai Do of the company's Unit 515 team, found a second verification path in which, under certain conditions, a value the camera hands out during login can be sent back and accepted as a valid authentication response.</p><p>The result is an administrator session after a small number of requests, with no password, no existing session, and no requirements for the new 'owner'. As a result, access includes live video, stored footage, and configuration changes. </p><p>OPSWAT's researchers pointed out that a C200 used as a baby monitor would expose "live video, night vision, crying detection and two-way audio."</p><p>The second flaw, CVE-2026-15316, affects only the C200 and sits in its Wi-Fi onboarding code. Sending the camera an oversized chunk of encrypted Wi-Fi credential data can crash its HTTPS service or restart the device outright, cutting the owner off from management and monitoring until it recovers.</p><p>The attacks are somewhat limited in scope: users aiming to exploit such vulnerabilities would need to be on the same Wi-Fi network, or within a certain trusted ecosystem, to begin with.</p><p>For now, users upgrading to TP-Link's newest firmware, issued for both models, rectifies both issues, but there might already be another security patch in the works: OPSWAT also found "a critical vulnerability that could allow an attacker to fully compromise the camera," which could then serve as a foothold inside the network.</p><p>It is currently holding off on publishing any details about the vulnerability as it waits for TP-Link to issue a patch that rectifies the situation. Neither OPSWAT nor TP-Link, however, has provided a timeline for when the patch will be available to end users.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/these-popular-tp-link-home-security-cameras-could-be-hacked-to-spy-on-you-while-you-sleep-experts-warn</link>
                                                                            <description>
                            <![CDATA[ A passwordless login bypass in TP-Link's Tapo C200 and C120 cameras can expose your live feed to anyone on the same network, and a fix is already available to download ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">prqGALPJ6aayLt97QQAesD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8AQ6mNEWbxZfbYjrKfsCkF-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Sep 2026 18:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Smart Home]]></category>
                                                    <category><![CDATA[Home Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Home]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8AQ6mNEWbxZfbYjrKfsCkF-1920-80.jpg">
                                                            <media:credit><![CDATA[Unsplash]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Privacy]]></media:description>                                                            <media:text><![CDATA[Privacy]]></media:text>
                                <media:title type="plain"><![CDATA[Privacy]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8AQ6mNEWbxZfbYjrKfsCkF-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Cybersecurity company OPSWAT found a login bypass and a crash bug in TP-Link's Tapo C200 cameras</strong></li><li><strong>TP-Link has extended that to include its C120 offering too</strong></li><li><strong>Anyone on the same network could get admin access, live video, and recordings without requiring the owner's credentials</strong></li></ul><p>Security researchers at <a href="https://www.opswat.com/blog/authentication-bypass-and-dos-vulnerabilities-opswat-discovers-cve-2026-15315-cve-2026-15316-in-tp-link-tapo-cameras" target="_blank">OPSWAT</a> have detailed two high-severity flaws in TP-Link's Tapo C200, a pan-and-tilt indoor camera <a href="https://www.amazon.com/TP-Link-Tapo-Wireless-Security-C200/dp/B0829KDY9X" target="_blank" rel="nofollow">listed on Amazon for $26.99</a> and sold as a baby monitor and pet camera.</p><p>The more serious issue is that someone on the same network can log in as the camera's administrator without the password, accessing the live feed and stored recordings.</p><p>At least one other bug, which OPSWAT rates as critical in the same disclosure but does not detail, has not been published.</p><h2 id="a-localized-login-that-requires-no-authentication">A localized login that requires no authentication</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="sXT4pLeU6CuMN5RuzCofpY" name="TP-Link Tapo C200" alt="The TP-Link Tapo C200 camera" src="https://cdn.mos.cms.futurecdn.net/sXT4pLeU6CuMN5RuzCofpY-1920-80.png" mos="" align="middle" fullscreen="" width="1000" height="1000" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: TP-Link)</span></figcaption></figure><p>The TP-Link Tapo C200, as we <a href="https://www.techradar.com/pro/security/watch-out-tp-link-tapo-camera-vulnerabilities-could-let-hackers-spy-inside-homes-so-patch-now" target="_blank">noted in previous coverage of the incident,</a> isn't just another security camera that happens to be vulnerable; it is one of the most popular models on the market, clocking in at over 3,000 sales on Amazon alone.</p><p>The Tapo C120, in its current iteration, sells over 5,000 units monthly, even <a href="https://www.tp-link.com/us/support/faq/5248/" target="_blank" rel="nofollow">as the advisory notes</a> that its V1 hardware version is currently compromised until users update the firmware on their devices.</p><p>Both SKUs have received firmware updates that patch the vulnerabilities (CVE-2026-15315 & CVE-2026-15316), which are assigned 'high' scores of 8.7 and 7.1, respectively. However, according to TP-Link, CVE-2026-15316 does not affect the C120 camera.</p><p>However, the former vulnerability is the more pressing of the two and, according to OPSWAT, is particularly problematic for users because of how the C120 and C200 cameras function.</p><p>Both run a local management interface over HTTPS and use a challenge-response login designed to prove a client knows the owner's password. Khoi Tran, a graduate fellow at OPSWAT, and his mentor, Thai Do of the company's Unit 515 team, found a second verification path in which, under certain conditions, a value the camera hands out during login can be sent back and accepted as a valid authentication response.</p><p>The result is an administrator session after a small number of requests, with no password, no existing session, and no requirements for the new 'owner'. As a result, access includes live video, stored footage, and configuration changes. </p><p>OPSWAT's researchers pointed out that a C200 used as a baby monitor would expose "live video, night vision, crying detection and two-way audio."</p><p>The second flaw, CVE-2026-15316, affects only the C200 and sits in its Wi-Fi onboarding code. Sending the camera an oversized chunk of encrypted Wi-Fi credential data can crash its HTTPS service or restart the device outright, cutting the owner off from management and monitoring until it recovers.</p><p>The attacks are somewhat limited in scope: users aiming to exploit such vulnerabilities would need to be on the same Wi-Fi network, or within a certain trusted ecosystem, to begin with.</p><p>For now, users upgrading to TP-Link's newest firmware, issued for both models, rectifies both issues, but there might already be another security patch in the works: OPSWAT also found "a critical vulnerability that could allow an attacker to fully compromise the camera," which could then serve as a foothold inside the network.</p><p>It is currently holding off on publishing any details about the vulnerability as it waits for TP-Link to issue a patch that rectifies the situation. Neither OPSWAT nor TP-Link, however, has provided a timeline for when the patch will be available to end users.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft takes down AI-boosted phishing tool that hit 12,000 accounts ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft, UK police, and partners disrupted EvilTokens PhaaS, arresting two suspects and seizing 200+ domains/sites</strong></li><li><strong>EvilTokens used AI to scale device‑code phishing, compromising 12,000 inboxes across 10,000 organizations globally</strong></li><li><strong>Platform ran like a startup with subscriptions, dashboards, and AI‑driven targeting; US victims hit hardest</strong></li></ul><p>Two people have been arrested, 50 websites were seized, and 150 domains disabled, in a joint operation against the infamous EvilTokens phishing-as-a-service (PhaaS) kit. </p><p>In its <a href="https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/" target="_blank" rel="nofollow">report</a>, Microsoft said the UK Metropolitan Police Service’s cybercrime team “arrested two men on suspicion of offenses connected with the alleged operation of EvilTokens.”</p><p>The two men, whose identities were not disclosed, are aged 32 and 38, and have been released on bail, subject to conditions while the investigation continues. Their digital services and other items have been confiscated, as well.</p><p>Among the partners are Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs. We don’t know if these arrests and takedowns will be enough to completely obliterate EvilTokens, or if the platform will continue to operate. Usually, criminal infrastructure is a lot less resilient to disruptions when arrests are made, compared to when law enforcement simply disables the hardware.</p><h2 id="the-tech-startup-of-organized-crime">The tech startup of organized crime</h2><p>EvilTokens has been turning heads for a little while now. The platform was first spotted in February 2026, rising quickly to become one of the most widely used PhaaS solutions out there. </p><p>It can be bought through Telegram for $1,500, after which there is a recurring $500 subscription cost. Cybercriminals use it to run large-scale, personalized phishing attacks: they can create spoofed websites, landing pages, and other credential-capture assets; they can create custom-tailored phishing emails, and can even grab session tokens, <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">one-time passwords</a>, and other codes designed to protect accounts against phishing, granting attackers access to people’s inboxes.</p><p>But what makes EvilTokens particularly impressive is its use of artificial intelligence. The platform comes with an <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI assistant</a> that can sift through the inboxes, suggest which targets are of high value, and even how to approach them. Attackers can conduct Microsoft Graph reconnaissance as well, mapping out organizational structure and permissions, keeping access and moving laterally throughout the target network. </p><p>Microsoft said it found evidence of large portions of EvilTokens being vibe coded, “with AI helping its creators build the platform itself.” </p><p>The researchers also found the platform drawing on capabilities from multiple AI models. Looking at the platform as a whole, it runs like a well-organized startup, with subscription pricing, customer support, management dashboards, and tools designed to move customers from account access toward financial exploitation.</p><p>According to Microsoft, EvilTokens facilitated business email compromise (BEC) campaigns that compromised more than 12,000 inboxes in more than 10,000 organizations worldwide. Victims are mostly in wholesale distribution, construction, and financial services, but those in real estate, higher education, and healthcare are not spared, either. </p><p>The victims are primarily located in the United States, with notable numbers found in Canada, the United Kingdom, Australia, India, and France. Microsoft said affected customers were notified, and that the company “helped remediate compromised accounts and shared intelligence to support further defensive and investigative action."</p><h2 id="popularizing-device-code-phishing">Popularizing device-code phishing</h2><p>Device-code phishing as an attack technique is not that new. More than a year ago, in February 2025, security researchers Huntress reported on Russian threat actors Storm-2372 deploying the same technique, and while it’s been steadily growing in popularity, it wasn’t until EvilTokens’ appearance that it really exploded.</p><p>The same researchers said, <a href="https://www.techradar.com/pro/security/organised-crime-operating-like-a-tech-startup-eviltoken-phaas-group-ramp-up-ai-enabled-attacks-by-1-380-percent-in-2026" target="_blank">in June 2026</a>, that EvilTokens was used to run 1,380% more device-code phishing attacks in 2026, compared to the same period last year. </p><p>“We’re seeing a clear maturation of the phishing-as-a-service (PhaaS) market as threat actors increasingly integrate AI workflows into their product offerings,” Huntress said in a report.</p><p>“The result is directly observable in our telemetry: a 1,380% increase in device code phishing attacks detected between July–December 2025 and January–April 2026, with over 50% of those incidents linked to two major waves of correlated incidents.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/microsoft-takes-down-ai-boosted-phishing-tool-that-hit-12-000-accounts</link>
                                                                            <description>
                            <![CDATA[ Two people arrested and dozens of websites seized in an organized operation against EvilTokens. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rjKiUdqjoeHAJDGLfcm4V6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/j5YMwZuuKnvAXLyKBEmDrb-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Sep 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/j5YMwZuuKnvAXLyKBEmDrb-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / JLStock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.]]></media:description>                                                            <media:text><![CDATA[A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.]]></media:text>
                                <media:title type="plain"><![CDATA[A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/j5YMwZuuKnvAXLyKBEmDrb-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft, UK police, and partners disrupted EvilTokens PhaaS, arresting two suspects and seizing 200+ domains/sites</strong></li><li><strong>EvilTokens used AI to scale device‑code phishing, compromising 12,000 inboxes across 10,000 organizations globally</strong></li><li><strong>Platform ran like a startup with subscriptions, dashboards, and AI‑driven targeting; US victims hit hardest</strong></li></ul><p>Two people have been arrested, 50 websites were seized, and 150 domains disabled, in a joint operation against the infamous EvilTokens phishing-as-a-service (PhaaS) kit. </p><p>In its <a href="https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/" target="_blank" rel="nofollow">report</a>, Microsoft said the UK Metropolitan Police Service’s cybercrime team “arrested two men on suspicion of offenses connected with the alleged operation of EvilTokens.”</p><p>The two men, whose identities were not disclosed, are aged 32 and 38, and have been released on bail, subject to conditions while the investigation continues. Their digital services and other items have been confiscated, as well.</p><p>Among the partners are Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs. We don’t know if these arrests and takedowns will be enough to completely obliterate EvilTokens, or if the platform will continue to operate. Usually, criminal infrastructure is a lot less resilient to disruptions when arrests are made, compared to when law enforcement simply disables the hardware.</p><h2 id="the-tech-startup-of-organized-crime">The tech startup of organized crime</h2><p>EvilTokens has been turning heads for a little while now. The platform was first spotted in February 2026, rising quickly to become one of the most widely used PhaaS solutions out there. </p><p>It can be bought through Telegram for $1,500, after which there is a recurring $500 subscription cost. Cybercriminals use it to run large-scale, personalized phishing attacks: they can create spoofed websites, landing pages, and other credential-capture assets; they can create custom-tailored phishing emails, and can even grab session tokens, <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">one-time passwords</a>, and other codes designed to protect accounts against phishing, granting attackers access to people’s inboxes.</p><p>But what makes EvilTokens particularly impressive is its use of artificial intelligence. The platform comes with an <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI assistant</a> that can sift through the inboxes, suggest which targets are of high value, and even how to approach them. Attackers can conduct Microsoft Graph reconnaissance as well, mapping out organizational structure and permissions, keeping access and moving laterally throughout the target network. </p><p>Microsoft said it found evidence of large portions of EvilTokens being vibe coded, “with AI helping its creators build the platform itself.” </p><p>The researchers also found the platform drawing on capabilities from multiple AI models. Looking at the platform as a whole, it runs like a well-organized startup, with subscription pricing, customer support, management dashboards, and tools designed to move customers from account access toward financial exploitation.</p><p>According to Microsoft, EvilTokens facilitated business email compromise (BEC) campaigns that compromised more than 12,000 inboxes in more than 10,000 organizations worldwide. Victims are mostly in wholesale distribution, construction, and financial services, but those in real estate, higher education, and healthcare are not spared, either. </p><p>The victims are primarily located in the United States, with notable numbers found in Canada, the United Kingdom, Australia, India, and France. Microsoft said affected customers were notified, and that the company “helped remediate compromised accounts and shared intelligence to support further defensive and investigative action."</p><h2 id="popularizing-device-code-phishing">Popularizing device-code phishing</h2><p>Device-code phishing as an attack technique is not that new. More than a year ago, in February 2025, security researchers Huntress reported on Russian threat actors Storm-2372 deploying the same technique, and while it’s been steadily growing in popularity, it wasn’t until EvilTokens’ appearance that it really exploded.</p><p>The same researchers said, <a href="https://www.techradar.com/pro/security/organised-crime-operating-like-a-tech-startup-eviltoken-phaas-group-ramp-up-ai-enabled-attacks-by-1-380-percent-in-2026" target="_blank">in June 2026</a>, that EvilTokens was used to run 1,380% more device-code phishing attacks in 2026, compared to the same period last year. </p><p>“We’re seeing a clear maturation of the phishing-as-a-service (PhaaS) market as threat actors increasingly integrate AI workflows into their product offerings,” Huntress said in a report.</p><p>“The result is directly observable in our telemetry: a 1,380% increase in device code phishing attacks detected between July–December 2025 and January–April 2026, with over 50% of those incidents linked to two major waves of correlated incidents.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Millions of Russian fast food fans hit in Burger King Russia hack ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Burger King Russia’s 2024 breach via Mindbox exposed 3.2 million customer records, now leaked online</strong></li><li><strong>Data includes emails, names, genders, birth dates, phone numbers, and geolocations (2018–2024)</strong></li><li><strong>Payment details weren’t compromised; users warned of phishing and identity theft risks</strong></li></ul><p>Back in 2024, the Russian arm of Burger King suffered a data breach at the hands of unknown threat actors - now, that data has finally been leaked online.</p><p>In October 2024, Burger King told TASS, Russia’s national news agency, that unidentified hackers attacked Mindbox, a domestic marketing automation platform the company had been using. </p><p>Through Mindbox, the crooks managed to obtain sensitive company data, including information belonging to the customers. </p><p>As a customer data and marketing automation platform, Mindbox helps businesses gather and use customer information for personalized, omnichannel marketing campaigns. Its tools cover email and SMS campaigns, push notifications, loyalty programs, chatbots, and more. According to the company, more than 1,100 businesses use its platform, including L’Oréal, Panasonic, KFC, JBL and United Colors of Benetton. </p><h2 id="one-victim-in-a-supply-chain-attack">One victim in a supply-chain attack</h2><p>At the time, there was no word on the nature of the information that was taken, apart from the fact that payment information was not compromised.</p><p>"Among the victims of the attack may also be the data of customers of the Burger King restaurant chain," the company said at the time. </p><p>“Burger King confirms that among the personal data, the accuracy of which is being clarified, there is no information about payment details: open information about transactions is not transmitted or stored by third parties.”</p><p>The details about the hack were also not disclosed. We don’t know if the platform contained a zero-day, or if a company employee had their login credentials or session tokens exposed. Third-party supply chain attacks such as this one are common and often rather disruptive, affecting numerous companies using the same tools. For Mindbox, however, there have been no reports of additional victims.</p><p>In its 2024 results announcement, Mindbox said the attack was its “first serious information security incident”, which was quickly detected and contained “thanks to threat detection tools.”</p><p>In the aftermath of the breach, Mindbox said it “found and eliminated points where employees without access rights to sensitive data could indirectly obtain them,” hinting that the attack was, in fact, an identity-based attack rather than a zero-day exploit.  </p><p>The company also “changed development processes to find such points before they get into the product,” and reformed Mindbox's internal role system to make permissions stricter and more granular. It also limited project access scenarios, introduced a mechanism for confirming access by another employee, and introduced mandatory two-factor authentication, among other things. </p><h2 id="have-you-been-pwned">Have you been pwned?</h2><p>Today, more details were released on Have I Been Pwned?, a website that aggregates information stolen in various hacks and helps people learn if their email addresses and other information had been compromised in the past. According to the newest entry, more than three million people have had their data exposed in this incident: </p><p>“The breach exposed 3.2M unique email addresses along with names, genders, dates of birth, phone numbers and approximate geolocations, with the data spanning 2018 to August 2024,” Have I Been Pwned? writes. “Burger King Russia acknowledged the incident and advised it did not include payment or passport details.”</p><p>The latest findings seem to be somewhat in line with what the media reported at the time. According to <a href="https://www.theregister.com/cyber-crime/2026/09/22/well-done-hack-flames-32m-burger-king-russia-users/5298114" target="_blank"><em>The Register</em></a>, initial reports claimed around 5.6 million lines of data as exposed, which included information about a customer’s favorite dish and previous order dates. While this information was not mentioned in the newest report, if every data line includes one email, one name, or one phone number, it could amount to around 5.6 million. </p><p>While the information might be a few years old, things like names and birth dates, and genders rarely change, but are vital in <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a>, social engineering, and similar attacks. Burger King users, especially those in Russia, should be wary of incoming email messages, particularly those claiming to come from the fast food chain.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/millions-of-russian-fast-food-fans-hit-in-burger-king-russia-hack</link>
                                                                            <description>
                            <![CDATA[ Data stolen years ago finally surfaced on the web, showing 3.2 million Burger King Russia victims. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qoXJPFHDttwNAv8LgcK5WZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aUiqncNLKM6YAYFyowvwPH-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Sep 2026 15:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aUiqncNLKM6YAYFyowvwPH-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images / NurPhoto]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Burger King shop]]></media:description>                                                            <media:text><![CDATA[Burger King shop]]></media:text>
                                <media:title type="plain"><![CDATA[Burger King shop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aUiqncNLKM6YAYFyowvwPH-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Burger King Russia’s 2024 breach via Mindbox exposed 3.2 million customer records, now leaked online</strong></li><li><strong>Data includes emails, names, genders, birth dates, phone numbers, and geolocations (2018–2024)</strong></li><li><strong>Payment details weren’t compromised; users warned of phishing and identity theft risks</strong></li></ul><p>Back in 2024, the Russian arm of Burger King suffered a data breach at the hands of unknown threat actors - now, that data has finally been leaked online.</p><p>In October 2024, Burger King told TASS, Russia’s national news agency, that unidentified hackers attacked Mindbox, a domestic marketing automation platform the company had been using. </p><p>Through Mindbox, the crooks managed to obtain sensitive company data, including information belonging to the customers. </p><p>As a customer data and marketing automation platform, Mindbox helps businesses gather and use customer information for personalized, omnichannel marketing campaigns. Its tools cover email and SMS campaigns, push notifications, loyalty programs, chatbots, and more. According to the company, more than 1,100 businesses use its platform, including L’Oréal, Panasonic, KFC, JBL and United Colors of Benetton. </p><h2 id="one-victim-in-a-supply-chain-attack">One victim in a supply-chain attack</h2><p>At the time, there was no word on the nature of the information that was taken, apart from the fact that payment information was not compromised.</p><p>"Among the victims of the attack may also be the data of customers of the Burger King restaurant chain," the company said at the time. </p><p>“Burger King confirms that among the personal data, the accuracy of which is being clarified, there is no information about payment details: open information about transactions is not transmitted or stored by third parties.”</p><p>The details about the hack were also not disclosed. We don’t know if the platform contained a zero-day, or if a company employee had their login credentials or session tokens exposed. Third-party supply chain attacks such as this one are common and often rather disruptive, affecting numerous companies using the same tools. For Mindbox, however, there have been no reports of additional victims.</p><p>In its 2024 results announcement, Mindbox said the attack was its “first serious information security incident”, which was quickly detected and contained “thanks to threat detection tools.”</p><p>In the aftermath of the breach, Mindbox said it “found and eliminated points where employees without access rights to sensitive data could indirectly obtain them,” hinting that the attack was, in fact, an identity-based attack rather than a zero-day exploit.  </p><p>The company also “changed development processes to find such points before they get into the product,” and reformed Mindbox's internal role system to make permissions stricter and more granular. It also limited project access scenarios, introduced a mechanism for confirming access by another employee, and introduced mandatory two-factor authentication, among other things. </p><h2 id="have-you-been-pwned">Have you been pwned?</h2><p>Today, more details were released on Have I Been Pwned?, a website that aggregates information stolen in various hacks and helps people learn if their email addresses and other information had been compromised in the past. According to the newest entry, more than three million people have had their data exposed in this incident: </p><p>“The breach exposed 3.2M unique email addresses along with names, genders, dates of birth, phone numbers and approximate geolocations, with the data spanning 2018 to August 2024,” Have I Been Pwned? writes. “Burger King Russia acknowledged the incident and advised it did not include payment or passport details.”</p><p>The latest findings seem to be somewhat in line with what the media reported at the time. According to <a href="https://www.theregister.com/cyber-crime/2026/09/22/well-done-hack-flames-32m-burger-king-russia-users/5298114" target="_blank"><em>The Register</em></a>, initial reports claimed around 5.6 million lines of data as exposed, which included information about a customer’s favorite dish and previous order dates. While this information was not mentioned in the newest report, if every data line includes one email, one name, or one phone number, it could amount to around 5.6 million. </p><p>While the information might be a few years old, things like names and birth dates, and genders rarely change, but are vital in <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a>, social engineering, and similar attacks. Burger King users, especially those in Russia, should be wary of incoming email messages, particularly those claiming to come from the fast food chain.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers hit the FBI — ShinyHunters say they have stolen 2TB of employee data, but the attack isn't looking for money, just an apology ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>ShinyHunters defaces FBI’s jobs site, claiming a PeopleSoft zero‑day let them steal 2TB of HR data</strong></li><li><strong>Group says attack is not for ransom but to dispute FBI’s May PSA alleging harassment and swatting tactics</strong></li><li><strong>Experts warn exploit itself is highly valuable; FBI site reclaimed, investigation ongoing into breach claims</strong></li></ul><p>The ShinyHunters extortion group is currently doing brand management in the most ShinyHunters way possible - by hacking into the FBI and stealing the agency’s sensitive files.</p><p>The Bureau’s jobs site was defaced and replaced with the usual ShinyHunters content - an ASCII image of the group’s logo, and a message saying “This site has been seized by ShinyHunters. Rooting your systems since ‘19 :)”. </p><p>But instead of putting the FBI on its data leak site and threatening to release stolen files if a ransom isn’t paid, ShinyHunters started speaking to the press, telling<em> </em><a href="https://www.theregister.com/security/2026/09/22/shinyhunters-claims-fbi-hack-this-is-not-financially-motivated/5298385" target="_blank"><em>The Register</em></a> it found a zero-day vulnerability in the Oracle PeopleSoft <a href="https://www.techradar.com/best/best-hr-software" target="_blank">human resource management</a> system, which allowed them to remotely execute arbitrary code on the underlying server.</p><p>They used this ability to (allegedly) steal more than 2TB of sensitive data from the FBI’s servers, including names, addresses, phone numbers, and information on spouses for current, former, and prospective FBI employees. </p><p>“We hold data on all FBI employees and applicants,” the spokesperson told <em>The Register</em>, noting they had compromised human resources, MedLink, and Criminal Justice Information Services.</p><h2 id="brand-management">Brand management</h2><p>The FBI has yet to comment, and so do both Oracle and AWS, but what’s most peculiar about this incident is that it doesn’t seem to be financially motivated. </p><p>So far, everything ShinyHunters’ have been doing was for the money. They would break into a company, steal their files, and then pressure the victims into paying a ransom demand in exchange for deleting the stolen information. This time around, the group claims the goal of the attack is to force the FBI to change the record on how it operates.</p><p>“This is NOT financially motivated,” the group told <em>The Register</em>. “We want the FBI to correct or retract their statements they made, which included substantial false allegations.”</p><p>The statements were made in a security bulletin published on May 15 this year, right after the Canvas attack. In early May 2026 Instructure, the edtech giant behind the popular Canvas learning system, <a href="https://www.techradar.com/pro/security/canvas-maker-instructure-reveals-data-breach-confirms-user-personal-information-leaked" target="_blank">confirmed suffering a cyberattack</a> and losing sensitive customer data. It was later disclosed that some of the world’s top universities, including <a href="https://www.techradar.com/pro/security/top-universities-among-victims-named-in-canvas-data-breach-mit-oxford-and-more-all-hit" target="_blank">Harvard, Oxford, and MIT</a>, were among the victims. </p><p>The attack was so disruptive that Instructure’s CEO was called to <a href="https://www.techradar.com/pro/security/us-congress-calls-instructure-ceo-as-it-investigates-canvas-breach" target="_blank">testify in front of the US House Committee on Homeland Security</a> a few weeks later.</p><p>On May 15, the FBI issued a <a href="https://www.ic3.gov/PSA/2026/PSA260515" target="_blank">public service announcement</a> (PSA) saying ShinyHunters “commonly use harassment strategies” to exert pressure on victims, including “sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting.”</p><p>Swatting means calling the police to report criminal activity so severe that the SWAT team is sent. This is usually done to live streamers as a practical, albeit life-threatening, joke. </p><p>“Threat actors may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist. Following these pressure tactics, SH actors have sometimes posted exfiltrated data to various iterations of the SH data leak site on the Tor network,” the PSA concluded.</p><p>“I have been doing my very best to combat these allegations,” ShinyHunters told the media. “And this is the best way to do it.” </p><h2 id="no-money">No money?</h2><p>Not everyone is sold on the idea that ShinyHunters isn’t doing this for the money. </p><p>In a statement shared with TechRadar Pro, CTO of Suzu Labs, Denis Calderone, said the claims should be taken with a grain of salt: “I have a hard time believing terabytes of FBI personnel data just sit on a shelf. Foreign intelligence services would love to have it, and having the FBI on their resume makes every future extortion demand more believable, and if the PeopleSoft zero-day is real, the exploit may be worth more than the data. Meanwhile, agents and their spouses could have their home addresses posted publicly within a week if this threat is followed through.”</p><p>Calderone also stressed that instead of focusing on the incident, people should be paying more attention to the zero-day.</p><p>“If you run PeopleSoft, don't wait for a patch. Get it off the public internet wherever you can, put what has to stay public behind a WAF, and make sure admin components like the /PSEMHUB/ path in their screenshot aren't reachable from outside. Hunt for the June indicators and for SSH attempts against the psoft and oracle accounts. Then ask yourself what your applicant portal can reach. At the FBI, a website built for strangers to upload resumes allegedly led straight into GovCloud.”</p><p>The FBI has since reclaimed its website, which now says it is under maintenance.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/hackers-hit-the-fbi-shinyhunters-say-they-have-stolen-2tb-of-employee-data-but-the-attack-isnt-looking-for-money-just-an-apology</link>
                                                                            <description>
                            <![CDATA[ ShinyHunters are looking to improve their standing in the public eye. What better way to do it than hacking the FBI? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wUwrCgcCY7Y4kmYfKW4prN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Ri2dNNTvgmKGsMuhNDCavZ-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Sep 2026 14:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Ri2dNNTvgmKGsMuhNDCavZ-1920-80.jpg">
                                                            <media:credit><![CDATA[Adobe]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Dark web monitoring]]></media:description>                                                            <media:text><![CDATA[Dark web monitoring]]></media:text>
                                <media:title type="plain"><![CDATA[Dark web monitoring]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Ri2dNNTvgmKGsMuhNDCavZ-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>ShinyHunters defaces FBI’s jobs site, claiming a PeopleSoft zero‑day let them steal 2TB of HR data</strong></li><li><strong>Group says attack is not for ransom but to dispute FBI’s May PSA alleging harassment and swatting tactics</strong></li><li><strong>Experts warn exploit itself is highly valuable; FBI site reclaimed, investigation ongoing into breach claims</strong></li></ul><p>The ShinyHunters extortion group is currently doing brand management in the most ShinyHunters way possible - by hacking into the FBI and stealing the agency’s sensitive files.</p><p>The Bureau’s jobs site was defaced and replaced with the usual ShinyHunters content - an ASCII image of the group’s logo, and a message saying “This site has been seized by ShinyHunters. Rooting your systems since ‘19 :)”. </p><p>But instead of putting the FBI on its data leak site and threatening to release stolen files if a ransom isn’t paid, ShinyHunters started speaking to the press, telling<em> </em><a href="https://www.theregister.com/security/2026/09/22/shinyhunters-claims-fbi-hack-this-is-not-financially-motivated/5298385" target="_blank"><em>The Register</em></a> it found a zero-day vulnerability in the Oracle PeopleSoft <a href="https://www.techradar.com/best/best-hr-software" target="_blank">human resource management</a> system, which allowed them to remotely execute arbitrary code on the underlying server.</p><p>They used this ability to (allegedly) steal more than 2TB of sensitive data from the FBI’s servers, including names, addresses, phone numbers, and information on spouses for current, former, and prospective FBI employees. </p><p>“We hold data on all FBI employees and applicants,” the spokesperson told <em>The Register</em>, noting they had compromised human resources, MedLink, and Criminal Justice Information Services.</p><h2 id="brand-management">Brand management</h2><p>The FBI has yet to comment, and so do both Oracle and AWS, but what’s most peculiar about this incident is that it doesn’t seem to be financially motivated. </p><p>So far, everything ShinyHunters’ have been doing was for the money. They would break into a company, steal their files, and then pressure the victims into paying a ransom demand in exchange for deleting the stolen information. This time around, the group claims the goal of the attack is to force the FBI to change the record on how it operates.</p><p>“This is NOT financially motivated,” the group told <em>The Register</em>. “We want the FBI to correct or retract their statements they made, which included substantial false allegations.”</p><p>The statements were made in a security bulletin published on May 15 this year, right after the Canvas attack. In early May 2026 Instructure, the edtech giant behind the popular Canvas learning system, <a href="https://www.techradar.com/pro/security/canvas-maker-instructure-reveals-data-breach-confirms-user-personal-information-leaked" target="_blank">confirmed suffering a cyberattack</a> and losing sensitive customer data. It was later disclosed that some of the world’s top universities, including <a href="https://www.techradar.com/pro/security/top-universities-among-victims-named-in-canvas-data-breach-mit-oxford-and-more-all-hit" target="_blank">Harvard, Oxford, and MIT</a>, were among the victims. </p><p>The attack was so disruptive that Instructure’s CEO was called to <a href="https://www.techradar.com/pro/security/us-congress-calls-instructure-ceo-as-it-investigates-canvas-breach" target="_blank">testify in front of the US House Committee on Homeland Security</a> a few weeks later.</p><p>On May 15, the FBI issued a <a href="https://www.ic3.gov/PSA/2026/PSA260515" target="_blank">public service announcement</a> (PSA) saying ShinyHunters “commonly use harassment strategies” to exert pressure on victims, including “sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting.”</p><p>Swatting means calling the police to report criminal activity so severe that the SWAT team is sent. This is usually done to live streamers as a practical, albeit life-threatening, joke. </p><p>“Threat actors may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist. Following these pressure tactics, SH actors have sometimes posted exfiltrated data to various iterations of the SH data leak site on the Tor network,” the PSA concluded.</p><p>“I have been doing my very best to combat these allegations,” ShinyHunters told the media. “And this is the best way to do it.” </p><h2 id="no-money">No money?</h2><p>Not everyone is sold on the idea that ShinyHunters isn’t doing this for the money. </p><p>In a statement shared with TechRadar Pro, CTO of Suzu Labs, Denis Calderone, said the claims should be taken with a grain of salt: “I have a hard time believing terabytes of FBI personnel data just sit on a shelf. Foreign intelligence services would love to have it, and having the FBI on their resume makes every future extortion demand more believable, and if the PeopleSoft zero-day is real, the exploit may be worth more than the data. Meanwhile, agents and their spouses could have their home addresses posted publicly within a week if this threat is followed through.”</p><p>Calderone also stressed that instead of focusing on the incident, people should be paying more attention to the zero-day.</p><p>“If you run PeopleSoft, don't wait for a patch. Get it off the public internet wherever you can, put what has to stay public behind a WAF, and make sure admin components like the /PSEMHUB/ path in their screenshot aren't reachable from outside. Hunt for the June indicators and for SSH attempts against the psoft and oracle accounts. Then ask yourself what your applicant portal can reach. At the FBI, a website built for strangers to upload resumes allegedly led straight into GovCloud.”</p><p>The FBI has since reclaimed its website, which now says it is under maintenance.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Mistral denies a fresh security breach, but the code on sale looks a lot like May's leak ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Seller claims to be offering Mistral AI's full source code and says the company was breached again after May 2026 attack</strong></li><li><strong>Mistral says an investigation found no evidence of new unauthorized access but has not stated whether the listed code is genuine</strong></li><li><strong>No customer data has surfaced in analyzed samples, and nobody has shown files created after the May incident</strong></li></ul><p>A seller on a cybercrime forum says French giant Mistral AI has been hacked again and is offering what they call the company's full source code for sale.</p><p>The September 16 2026 post by an account using the handle "mrwho" consists of a listing titled "Selling mistral.ai Source Code" on an English-language cybercrime forum, <a href="https://thecybersecguru.com/news/mistral-ai-source-code-leak-2026/" target="_blank" rel="nofollow">according to The CyberSec Guru</a>, pricing the material in Monero only before it attempted to steer potential buyers to Session or Telegram.</p><p>Mistral AI's own team<a href="https://x.com/MistralAI/status/2100824200126529725" target="_blank"> has refuted</a> this, stating it has "found no evidence to support this claim."</p><h2 id="not-mistral-39-s-first-hacking-centric-pr-problem">Not Mistral's first hacking-centric PR problem</h2><p>Mistral's earlier hacking incident is undisputed - in May 2026, the Mini Shai-Hulud supply chain campaign, attributed to the TeamPCP group, spread from compromised TanStack packages to hundreds of npm and PyPI projects.</p><p>Mistral's own <a href="https://docs.mistral.ai/resources/security-advisories/MAI-2026-002" target="_blank" rel="nofollow">security advisory MAI-2026-002</a> says an automated worm led to compromised versions of its  SDKs being published for a few hours on May 11 and 12, and that an affected developer device was involved. <a href="https://www.tomshardware.com/tech-industry/cyber-security/compromised-mistral-ai-and-tanstack-packages-may-have-exposed-github-cloud-and-ci-cd-credentials-in-mini-shai-hulud-malware-infection-supply-chain-campaign-spreads-across-npm-and-ai-developer-ecosystems-like-wildfire" target="_blank" rel="nofollow">Microsoft Threat Intelligence found</a> that a poisoned Mistral AI Python package fetched a second-stage credential stealer that allowed the attack to exploit users.</p><p>Mistral went further in statements to reporters than in its advisory. It <a href="https://www.bleepingcomputer.com/news/security/teampcp-hackers-advertise-mistral-ai-code-repos-for-sale/" target="_blank">told <em>BleepingComputer</em></a> that attackers had compromised a codebase management system and "contaminated some of our SDK packages for a brief period," while insisting that hosted services, managed user data, and research and testing environments were untouched. It also <a href="https://hackread.com/teampcp-mistral-ai-repositories-mini-shai-hulud-attack/" target="_blank" rel="nofollow">told <em>HackRead</em></a> that only certain non-core repositories were accessed.</p><p>TeamPCP, meanwhile, advertised roughly 450 repositories, about 5GB in total, for $25,000, and <a href="https://www.techradar.com/pro/security/hackers-threaten-to-leak-mistral-files-online-ai-giant-confirms-breach-but-not-what-data-is-involved" target="_blank">threatened to dump them for free</a> if no buyer appeared within a week. One can therefore contend that this could be the same dump being remarketed by a different account, and the seller's profile is already suspect.</p><p><em>The CyberSec Guru</em> noted that the account joined in September 2026 and had four posts and a reputation score of 30, despite displaying a top-tier "GOD User" rank. That profile could fit a scam in the making, but as the outlet pointed out, it could also fit a broker fronting for someone else or a freshly minted alias.</p><p><em>HackRead</em> published 24 sample repository names from TeamPCP's May post. FrenchBreaches, which <a href="https://frenchbreaches.com/blog/mistral-ai-de-nouveau-piratee-un-hacker-revendique-la-totalite-de-son-code-source" target="_blank" rel="nofollow">examined the 339-file tree</a> mrwho shared in September, lists several of the same names. At least four of these appear in both: mistral-inference-private, mistral-inference-internal, mistral-finetune-internal, and mistral-common-internal.</p><p>This makes it hard to tell whether the purported 'hack' is just a rehash of an existing dump from Mistral's previous breach or a second successful hacking attempt. There is a straightforward test, however: If the September archives contain commits, files, or credentials dated after May 12, or secrets that were still valid after Mistral's cleanup, the seller's claim of a second breach gains real weight. If everything predates the May incident, this is a resale, which is embarrassing for Mistral but not a new security failure.</p><p>Of course, locating the archives or examining them would involve paying the ransom in crypto, as required by what could potentially be a scam in the making- a tremendous leap of faith for an account that was created earlier this month, making this essentially a lottery ticket at best for any security researcher attempting to take a closer look.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/mistral-denies-a-fresh-security-breach-but-the-code-on-sale-looks-a-lot-like-mays-leak</link>
                                                                            <description>
                            <![CDATA[ Mistral says the "stolen" code now on sale may simply be what walked out the door earlier in May 2026. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">W4MG4BDBwLWr8ES4bPXUJA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4AyzfXeFQkSE3gFjYpNsAQ-1920-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 21:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/4AyzfXeFQkSE3gFjYpNsAQ-1920-80.png">
                                                            <media:credit><![CDATA[Mistral]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Logo for Mistral AI]]></media:description>                                                            <media:text><![CDATA[The Logo for Mistral AI]]></media:text>
                                <media:title type="plain"><![CDATA[The Logo for Mistral AI]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4AyzfXeFQkSE3gFjYpNsAQ-1920-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Seller claims to be offering Mistral AI's full source code and says the company was breached again after May 2026 attack</strong></li><li><strong>Mistral says an investigation found no evidence of new unauthorized access but has not stated whether the listed code is genuine</strong></li><li><strong>No customer data has surfaced in analyzed samples, and nobody has shown files created after the May incident</strong></li></ul><p>A seller on a cybercrime forum says French giant Mistral AI has been hacked again and is offering what they call the company's full source code for sale.</p><p>The September 16 2026 post by an account using the handle "mrwho" consists of a listing titled "Selling mistral.ai Source Code" on an English-language cybercrime forum, <a href="https://thecybersecguru.com/news/mistral-ai-source-code-leak-2026/" target="_blank" rel="nofollow">according to The CyberSec Guru</a>, pricing the material in Monero only before it attempted to steer potential buyers to Session or Telegram.</p><p>Mistral AI's own team<a href="https://x.com/MistralAI/status/2100824200126529725" target="_blank"> has refuted</a> this, stating it has "found no evidence to support this claim."</p><h2 id="not-mistral-39-s-first-hacking-centric-pr-problem">Not Mistral's first hacking-centric PR problem</h2><p>Mistral's earlier hacking incident is undisputed - in May 2026, the Mini Shai-Hulud supply chain campaign, attributed to the TeamPCP group, spread from compromised TanStack packages to hundreds of npm and PyPI projects.</p><p>Mistral's own <a href="https://docs.mistral.ai/resources/security-advisories/MAI-2026-002" target="_blank" rel="nofollow">security advisory MAI-2026-002</a> says an automated worm led to compromised versions of its  SDKs being published for a few hours on May 11 and 12, and that an affected developer device was involved. <a href="https://www.tomshardware.com/tech-industry/cyber-security/compromised-mistral-ai-and-tanstack-packages-may-have-exposed-github-cloud-and-ci-cd-credentials-in-mini-shai-hulud-malware-infection-supply-chain-campaign-spreads-across-npm-and-ai-developer-ecosystems-like-wildfire" target="_blank" rel="nofollow">Microsoft Threat Intelligence found</a> that a poisoned Mistral AI Python package fetched a second-stage credential stealer that allowed the attack to exploit users.</p><p>Mistral went further in statements to reporters than in its advisory. It <a href="https://www.bleepingcomputer.com/news/security/teampcp-hackers-advertise-mistral-ai-code-repos-for-sale/" target="_blank">told <em>BleepingComputer</em></a> that attackers had compromised a codebase management system and "contaminated some of our SDK packages for a brief period," while insisting that hosted services, managed user data, and research and testing environments were untouched. It also <a href="https://hackread.com/teampcp-mistral-ai-repositories-mini-shai-hulud-attack/" target="_blank" rel="nofollow">told <em>HackRead</em></a> that only certain non-core repositories were accessed.</p><p>TeamPCP, meanwhile, advertised roughly 450 repositories, about 5GB in total, for $25,000, and <a href="https://www.techradar.com/pro/security/hackers-threaten-to-leak-mistral-files-online-ai-giant-confirms-breach-but-not-what-data-is-involved" target="_blank">threatened to dump them for free</a> if no buyer appeared within a week. One can therefore contend that this could be the same dump being remarketed by a different account, and the seller's profile is already suspect.</p><p><em>The CyberSec Guru</em> noted that the account joined in September 2026 and had four posts and a reputation score of 30, despite displaying a top-tier "GOD User" rank. That profile could fit a scam in the making, but as the outlet pointed out, it could also fit a broker fronting for someone else or a freshly minted alias.</p><p><em>HackRead</em> published 24 sample repository names from TeamPCP's May post. FrenchBreaches, which <a href="https://frenchbreaches.com/blog/mistral-ai-de-nouveau-piratee-un-hacker-revendique-la-totalite-de-son-code-source" target="_blank" rel="nofollow">examined the 339-file tree</a> mrwho shared in September, lists several of the same names. At least four of these appear in both: mistral-inference-private, mistral-inference-internal, mistral-finetune-internal, and mistral-common-internal.</p><p>This makes it hard to tell whether the purported 'hack' is just a rehash of an existing dump from Mistral's previous breach or a second successful hacking attempt. There is a straightforward test, however: If the September archives contain commits, files, or credentials dated after May 12, or secrets that were still valid after Mistral's cleanup, the seller's claim of a second breach gains real weight. If everything predates the May incident, this is a resale, which is embarrassing for Mistral but not a new security failure.</p><p>Of course, locating the archives or examining them would involve paying the ransom in crypto, as required by what could potentially be a scam in the making- a tremendous leap of faith for an account that was created earlier this month, making this essentially a lottery ticket at best for any security researcher attempting to take a closer look.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ More and more workers are feeling stressed at work due to security risks ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>More workers are worried about security issues than they were this time last year</strong></li><li><strong>Three in four say their recovery tools are too difficult for them to use</strong></li><li><strong>This report says having strong data storage could help</strong></li></ul><p>While many of us typically see security as an IT or a leadership issue, it's actually impacting us more than we'd initially thought. New Object First data found that 91% of workers feel uncomfortably stressed at work because of IT security risks – a seven percentage point increase over last year.</p><p>But unfortunately, it's a double-edged sword because it all boils down to AI. Nine in 10 say AI tools have improved their productivity, but seven in 10 say the growth of AI-powered threats is a key driver behind their stress.</p><p>Additionally, fewer than one-quarter (24%) believe their organisation is suitably equipped to deal with those threats.</p><h2 id="ai-driven-security-threats-are-actually-impacting-you-and-i">AI-driven security threats are actually impacting you and I</h2><p>While the risk of cyberattacks (50%) is a leading cause for stress at work, high workloads and understaffing (50%) land in joint-first place. Gaps in backup and recovery effectiveness (41%) and pressure to maintain uptime (44%) are also big headaches for workers, implying pressure isn't coming from direct attacks alone, but workload and operations.</p><p>For example, three in four (74%) say that their recovery tools are difficult to use without security expertise, leaving regular knowledge workers at a loss. One in five (19%) even say they feel hopeless and overwhelmed during and after an incident.</p><p>Naturally, this stress is impacting productivity, with four in five (78%) remarking that stress negatively affected their job performance. Two in five (39%) even said they'd thought about quitting.</p><p>"As critical as technology is to cyber resilience, those responsible for protecting and recovering an organization’s data are just as essential," company CEO David Bennett concluded.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/more-and-more-workers-are-feeling-stressed-at-work-due-to-security-risks</link>
                                                                            <description>
                            <![CDATA[ 91% feel stressed because of IT security risks, but 74% say the recovery tools they have access to are too hard to use. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hUK7et99BxCJF5KwCMrGb9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BV5jpKqSzFZAvPiNQWeHEi-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 16:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BV5jpKqSzFZAvPiNQWeHEi-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Stress]]></media:description>                                                            <media:text><![CDATA[Stress]]></media:text>
                                <media:title type="plain"><![CDATA[Stress]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BV5jpKqSzFZAvPiNQWeHEi-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>More workers are worried about security issues than they were this time last year</strong></li><li><strong>Three in four say their recovery tools are too difficult for them to use</strong></li><li><strong>This report says having strong data storage could help</strong></li></ul><p>While many of us typically see security as an IT or a leadership issue, it's actually impacting us more than we'd initially thought. New Object First data found that 91% of workers feel uncomfortably stressed at work because of IT security risks – a seven percentage point increase over last year.</p><p>But unfortunately, it's a double-edged sword because it all boils down to AI. Nine in 10 say AI tools have improved their productivity, but seven in 10 say the growth of AI-powered threats is a key driver behind their stress.</p><p>Additionally, fewer than one-quarter (24%) believe their organisation is suitably equipped to deal with those threats.</p><h2 id="ai-driven-security-threats-are-actually-impacting-you-and-i">AI-driven security threats are actually impacting you and I</h2><p>While the risk of cyberattacks (50%) is a leading cause for stress at work, high workloads and understaffing (50%) land in joint-first place. Gaps in backup and recovery effectiveness (41%) and pressure to maintain uptime (44%) are also big headaches for workers, implying pressure isn't coming from direct attacks alone, but workload and operations.</p><p>For example, three in four (74%) say that their recovery tools are difficult to use without security expertise, leaving regular knowledge workers at a loss. One in five (19%) even say they feel hopeless and overwhelmed during and after an incident.</p><p>Naturally, this stress is impacting productivity, with four in five (78%) remarking that stress negatively affected their job performance. Two in five (39%) even said they'd thought about quitting.</p><p>"As critical as technology is to cyber resilience, those responsible for protecting and recovering an organization’s data are just as essential," company CEO David Bennett concluded.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This fake LastPass Authenticator app will just shut off your antivirus and leave you open to attack ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Attackers spoofed LastPass Authenticator via SEO‑poisoned GitHub pages, delivering malicious ZIP files</strong></li><li><strong>Malware Rapuncel uses DLL sideloading, kills 145 AV products, and steals passwords, wallets, and tokens</strong></li><li><strong>Campaign ongoing for months; LastPass vaults unaffected, but users urged to download only from trusted sources</strong></li></ul><p>Be careful when downloading the LastPass Authenticator app - there are impostors out there that can disable your antivirus and wreak havoc on your computer. </p><p>LastPass recently <a href="https://blog.lastpass.com/posts/lastpass-delphos-report-rapuncel-infostealer" target="_blank">discovered</a> an elaborate scheme to get people infected with <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> - a spoofed website, SEO poisoning, DLL sideloading, and a malware loader delivering never-before-seen payload that can kill endpoint protection and antivirus solutions.</p><p>According to the <a href="https://www.techradar.com/best/password-manager" target="_blank">password manager</a>, users searching for "LastPass <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">Authenticator</a> download" or similar keywords will get a GitHub page rather high on the search engine results pages. At a glance, the page looks almost identical to the authentic LastPass offering - however, it redirects users to a separate one, hosted on attacker-controlled infrastructure and delivering a large .ZIP file with multiple files.</p><p>Among the files are two worth paying attention to: vsdbg.exe, and vsdbg.dll. The .EXE one is renamed to look like a LastPass installer, but it’s in fact a legitimate Microsoft debugging tool. This tool is used to run the malware - the vsdbg.dll file. This is a method called “dll sideloading” where the legitimate program will look for a DLL file in the same folder it’s located, rather than the wider device library. Since the DLL is delivered together with the executable, it is the first one to be run, despite the fact that it’s malicious. </p><h2 id="rapuncel">Rapuncel</h2><p>LastPass shared the malware with security researchers Delphos for analysis, and they’ve named it Rapuncel. No AV engines have been able to spot it, when it was first analyzed. </p><p>Once Rapuncel runs, it does a number of things. First, it gains admin-level access to run as SYSTEM, and then installs a kernel driver. The driver, disguised as an NVIDIA graphics component, comes with a hardcoded list of 145 antivirus and endpoint security products, and if any of them are found on the device, they are instantly terminated. </p><p>After killing antivirus solutions, the malware gets to work, stealing saved passwords from more than 25 browsers (Chrome, Edge, and other popular ones included), cryptocurrency wallet files from more than 30 wallet apps, Discord login tokens, Steam session tokens, Telegram session data, Windows credential store, all documents with words like “password”, “seed”, “wallet”, or “recovery” in their name, screenshots of every monitor connected to the device, as well as a detailed profile of the system.</p><p>Once all of this is harvested, the information is compressed into a .ZIP archive and uploaded to a server under the attackers’ control. To add insult to injury, the kernel driver was given code to intercept all web traffic, allowing the attackers to inject ads, or modify search results, at a whim. </p><p>Rapuncel comes with a persistence mechanism, as well, to make sure it continues operating even if the victim spots it. Spotting it should not be too difficult, though - if no antivirus programs are allowed to run on a computer, something is definitely not working properly.</p><h2 id="active-for-months">Active for months</h2><p>Still, the malware installs itself as a Windows service that starts automatically at boot, and then loops continuously, checking for security products and killing them as soon as they’re activated. “The machine may remain fully under the attacker's control until the kernel driver is physically removed,” the researchers explained. “This process requires booting the computer into Safe Mode or using an external recovery tool, because normal Windows tools cannot safely remove software operating at that level while the system is running.”</p><p>LastPass and Delphos believe the campaign has been active for months, and that it will continue to operate despite disruption efforts: </p><p>“The LastPass lure was a single recent frame in a campaign that has been running for months and shows every sign of continuing after its current infrastructure is burned,” the researchers said. They stressed that this is “opportunistic brand impersonation” and that LastPass systems and customer vaults have not been compromised or involved in any way. </p><p>LastPass said it was one of 40 companies spoofed in this campaign and has urged users to only download apps from reputable, vetted sources. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/this-fake-lastpass-authenticator-app-will-just-shut-off-your-antivirus-and-leave-you-open-to-attack</link>
                                                                            <description>
                            <![CDATA[ Researchers found a never-before-seen malware targeting LastPass users and stealing their secrets. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XbTSXMVZEJiMvjWJeGZBhm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7Q34GM2RgrdwsWnK6jBAeP-1920-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 14:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/7Q34GM2RgrdwsWnK6jBAeP-1920-80.png">
                                                            <media:credit><![CDATA[LastPass]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[LastPass]]></media:description>                                                            <media:text><![CDATA[LastPass]]></media:text>
                                <media:title type="plain"><![CDATA[LastPass]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7Q34GM2RgrdwsWnK6jBAeP-1920-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Attackers spoofed LastPass Authenticator via SEO‑poisoned GitHub pages, delivering malicious ZIP files</strong></li><li><strong>Malware Rapuncel uses DLL sideloading, kills 145 AV products, and steals passwords, wallets, and tokens</strong></li><li><strong>Campaign ongoing for months; LastPass vaults unaffected, but users urged to download only from trusted sources</strong></li></ul><p>Be careful when downloading the LastPass Authenticator app - there are impostors out there that can disable your antivirus and wreak havoc on your computer. </p><p>LastPass recently <a href="https://blog.lastpass.com/posts/lastpass-delphos-report-rapuncel-infostealer" target="_blank">discovered</a> an elaborate scheme to get people infected with <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> - a spoofed website, SEO poisoning, DLL sideloading, and a malware loader delivering never-before-seen payload that can kill endpoint protection and antivirus solutions.</p><p>According to the <a href="https://www.techradar.com/best/password-manager" target="_blank">password manager</a>, users searching for "LastPass <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">Authenticator</a> download" or similar keywords will get a GitHub page rather high on the search engine results pages. At a glance, the page looks almost identical to the authentic LastPass offering - however, it redirects users to a separate one, hosted on attacker-controlled infrastructure and delivering a large .ZIP file with multiple files.</p><p>Among the files are two worth paying attention to: vsdbg.exe, and vsdbg.dll. The .EXE one is renamed to look like a LastPass installer, but it’s in fact a legitimate Microsoft debugging tool. This tool is used to run the malware - the vsdbg.dll file. This is a method called “dll sideloading” where the legitimate program will look for a DLL file in the same folder it’s located, rather than the wider device library. Since the DLL is delivered together with the executable, it is the first one to be run, despite the fact that it’s malicious. </p><h2 id="rapuncel">Rapuncel</h2><p>LastPass shared the malware with security researchers Delphos for analysis, and they’ve named it Rapuncel. No AV engines have been able to spot it, when it was first analyzed. </p><p>Once Rapuncel runs, it does a number of things. First, it gains admin-level access to run as SYSTEM, and then installs a kernel driver. The driver, disguised as an NVIDIA graphics component, comes with a hardcoded list of 145 antivirus and endpoint security products, and if any of them are found on the device, they are instantly terminated. </p><p>After killing antivirus solutions, the malware gets to work, stealing saved passwords from more than 25 browsers (Chrome, Edge, and other popular ones included), cryptocurrency wallet files from more than 30 wallet apps, Discord login tokens, Steam session tokens, Telegram session data, Windows credential store, all documents with words like “password”, “seed”, “wallet”, or “recovery” in their name, screenshots of every monitor connected to the device, as well as a detailed profile of the system.</p><p>Once all of this is harvested, the information is compressed into a .ZIP archive and uploaded to a server under the attackers’ control. To add insult to injury, the kernel driver was given code to intercept all web traffic, allowing the attackers to inject ads, or modify search results, at a whim. </p><p>Rapuncel comes with a persistence mechanism, as well, to make sure it continues operating even if the victim spots it. Spotting it should not be too difficult, though - if no antivirus programs are allowed to run on a computer, something is definitely not working properly.</p><h2 id="active-for-months">Active for months</h2><p>Still, the malware installs itself as a Windows service that starts automatically at boot, and then loops continuously, checking for security products and killing them as soon as they’re activated. “The machine may remain fully under the attacker's control until the kernel driver is physically removed,” the researchers explained. “This process requires booting the computer into Safe Mode or using an external recovery tool, because normal Windows tools cannot safely remove software operating at that level while the system is running.”</p><p>LastPass and Delphos believe the campaign has been active for months, and that it will continue to operate despite disruption efforts: </p><p>“The LastPass lure was a single recent frame in a campaign that has been running for months and shows every sign of continuing after its current infrastructure is burned,” the researchers said. They stressed that this is “opportunistic brand impersonation” and that LastPass systems and customer vaults have not been compromised or involved in any way. </p><p>LastPass said it was one of 40 companies spoofed in this campaign and has urged users to only download apps from reputable, vetted sources. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Meta Muse already has a majorly worrying zero-day security issue ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Researcher Patrick Wardle finds zero‑day in Meta’s new Muse AI assistant, </strong></li><li><strong>Dubbed not‑a‑mused, the exploit requires local compromise, voice dictation, and app integrations; attackers can hijack tokens and exfiltrate data</strong></li><li><strong>Meta has been informed but no patch yet; flaw highlights risks of AI assistants with broad permissions</strong></li></ul><p>Meta’s new Artificial Intelligence (AI) <a href="https://www.techradar.com/pro/mark-zuckerbergs-muse-personal-ai-agent-is-a-work-accessory-designed-by-people-who-dont-do-real-work">assistant Muse</a> reportedly carried a zero-day vulnerability that allowed attackers to gain access to people’s apps, such as WhatsApp or email. </p><p>However, it’s not as straightforward as your usual zero-day - to exploit it, simply deploying malware will not suffice. Certain features need to be enabled, and certain integrations established before the bug could be leveraged.</p><h2 id="not-a-mused">Not-a-mused</h2><p>A little background, for context: Meta recently released Muse, describing it as an assistant that can “book appointments, fill out forms, and handle customer service.” It says the tool, available exclusively for the Mac ecosystem for now, “proactively takes tasks off your plate” and makes purchases, generates images, and creates documents. </p><p>To do that, however, it needs to connect to apps such as email, WhatsApp, calendar, or social media accounts - and this connection is the first prerequisite needed to exploit the flaw. </p><p>The second prerequisite is voice dictation. The vulnerability was found in the way Muse handles commands received via voice, meaning the attacker must piggyback onto voice commands in order to escalate privileges and access other apps and their content.</p><p>Now for the flaw itself. It was discovered by security researcher Patrick Wardle, founder of nonprofit Objective-See. He named it “not-a-mused” and says it hides in an undocumented setting called endo_voyager_dictation_endpoint. When a user narrates a voice command, that instruction is sent and processed in the cloud, where Meta can log it. This setting allows the user to change which endpoint receives the dictation.</p><p>Which brings us to the third prerequisite. The threat actor must have local access to be able to change this setting in the first place. In other words, the device must already be compromised in some way, either via remote monitoring and management tools, or via low-level malware (or with physical access). </p><p>For the sake of the report, let’s say that a theoretical user checks all the right boxes - they’re running a compromised machine and are talking to Muse that’s already connected to other productivity apps. Instead of reaching Meta’s endpoints, the voice commands are first sent to attacker-controlled infrastructure, where the AI assistant, together with the instructions, also sends authentication tokens for the tool. </p><p>If the attacker reacts fast enough, they can grab the token and access their target’s AI tool. If it’s connected to other apps, such as WhatsApp or calendar, they can simply prompt it to extract whatever sensitive information is found inside.</p><p>Not-a-mused is therefore a combination of data exfiltration and privilege escalation.</p><h2 id="ironing-out-the-kinks">Ironing out the kinks</h2><p>“We can manipulate the agent and leverage its privileges to do whatever we want,” Wardle told <a href="https://arstechnica.com/security/2026/09/muse-metas-extraordinarily-privileged-ai-assistant-has-a-serious-0-day/" target="_blank"><em>Ars Technica</em></a>. </p><p>“So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself.” Wardle said he has developed several proof-of-concept attacks that do things like writing malicious files to disk and snapping pictures, in many cases with no indication to even an alert user.</p><p>Meta has been informed, but is yet to comment, or issue a patch.</p><p>AI assistants are all the rage nowadays. They’ve turned elaborate answer machines into tools that can complete assignments, even more complex ones. They can book flights and restaurant tables, make purchases, schedule and reschedule calls and meetings, and more. However, to do that, these tools need extensive permissions - something the security community is warning of. </p><p>While they’re not openly speaking against it, they are advising caution. There are many stories of AI agents either going rogue, or simply being tricked by malicious actors. For example, a hidden prompt in a phishing email can trick an AI agent tasked with summarizing the message into exfiltrating all .PDF documents from the victim’s inbox. </p><p>In the early days of agentic AI, there were reports of assistants simply deleting people’s inboxes. </p><p>Assistants are likely here to stay, but there are still quite a few kinks to iron before they can hit the mainstream. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/meta-muse-already-has-a-majorly-worrying-zero-day-security-issue</link>
                                                                            <description>
                            <![CDATA[ Crooks can reportedly take over Meta sessions and use them to exfiltrate data. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sjPfUjdCnYhXNa8RF33kf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/n2dFzA7TpfgKDWytxEnzX4-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/n2dFzA7TpfgKDWytxEnzX4-1920-80.jpg">
                                                            <media:credit><![CDATA[Meta]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Meta Muse AI agent]]></media:description>                                                            <media:text><![CDATA[Meta Muse AI agent]]></media:text>
                                <media:title type="plain"><![CDATA[Meta Muse AI agent]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/n2dFzA7TpfgKDWytxEnzX4-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researcher Patrick Wardle finds zero‑day in Meta’s new Muse AI assistant, </strong></li><li><strong>Dubbed not‑a‑mused, the exploit requires local compromise, voice dictation, and app integrations; attackers can hijack tokens and exfiltrate data</strong></li><li><strong>Meta has been informed but no patch yet; flaw highlights risks of AI assistants with broad permissions</strong></li></ul><p>Meta’s new Artificial Intelligence (AI) <a href="https://www.techradar.com/pro/mark-zuckerbergs-muse-personal-ai-agent-is-a-work-accessory-designed-by-people-who-dont-do-real-work">assistant Muse</a> reportedly carried a zero-day vulnerability that allowed attackers to gain access to people’s apps, such as WhatsApp or email. </p><p>However, it’s not as straightforward as your usual zero-day - to exploit it, simply deploying malware will not suffice. Certain features need to be enabled, and certain integrations established before the bug could be leveraged.</p><h2 id="not-a-mused">Not-a-mused</h2><p>A little background, for context: Meta recently released Muse, describing it as an assistant that can “book appointments, fill out forms, and handle customer service.” It says the tool, available exclusively for the Mac ecosystem for now, “proactively takes tasks off your plate” and makes purchases, generates images, and creates documents. </p><p>To do that, however, it needs to connect to apps such as email, WhatsApp, calendar, or social media accounts - and this connection is the first prerequisite needed to exploit the flaw. </p><p>The second prerequisite is voice dictation. The vulnerability was found in the way Muse handles commands received via voice, meaning the attacker must piggyback onto voice commands in order to escalate privileges and access other apps and their content.</p><p>Now for the flaw itself. It was discovered by security researcher Patrick Wardle, founder of nonprofit Objective-See. He named it “not-a-mused” and says it hides in an undocumented setting called endo_voyager_dictation_endpoint. When a user narrates a voice command, that instruction is sent and processed in the cloud, where Meta can log it. This setting allows the user to change which endpoint receives the dictation.</p><p>Which brings us to the third prerequisite. The threat actor must have local access to be able to change this setting in the first place. In other words, the device must already be compromised in some way, either via remote monitoring and management tools, or via low-level malware (or with physical access). </p><p>For the sake of the report, let’s say that a theoretical user checks all the right boxes - they’re running a compromised machine and are talking to Muse that’s already connected to other productivity apps. Instead of reaching Meta’s endpoints, the voice commands are first sent to attacker-controlled infrastructure, where the AI assistant, together with the instructions, also sends authentication tokens for the tool. </p><p>If the attacker reacts fast enough, they can grab the token and access their target’s AI tool. If it’s connected to other apps, such as WhatsApp or calendar, they can simply prompt it to extract whatever sensitive information is found inside.</p><p>Not-a-mused is therefore a combination of data exfiltration and privilege escalation.</p><h2 id="ironing-out-the-kinks">Ironing out the kinks</h2><p>“We can manipulate the agent and leverage its privileges to do whatever we want,” Wardle told <a href="https://arstechnica.com/security/2026/09/muse-metas-extraordinarily-privileged-ai-assistant-has-a-serious-0-day/" target="_blank"><em>Ars Technica</em></a>. </p><p>“So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself.” Wardle said he has developed several proof-of-concept attacks that do things like writing malicious files to disk and snapping pictures, in many cases with no indication to even an alert user.</p><p>Meta has been informed, but is yet to comment, or issue a patch.</p><p>AI assistants are all the rage nowadays. They’ve turned elaborate answer machines into tools that can complete assignments, even more complex ones. They can book flights and restaurant tables, make purchases, schedule and reschedule calls and meetings, and more. However, to do that, these tools need extensive permissions - something the security community is warning of. </p><p>While they’re not openly speaking against it, they are advising caution. There are many stories of AI agents either going rogue, or simply being tricked by malicious actors. For example, a hidden prompt in a phishing email can trick an AI agent tasked with summarizing the message into exfiltrating all .PDF documents from the victim’s inbox. </p><p>In the early days of agentic AI, there were reports of assistants simply deleting people’s inboxes. </p><p>Assistants are likely here to stay, but there are still quite a few kinks to iron before they can hit the mainstream. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ BigCommerce warns customers of potential data leaks following cyber incident ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>BigCommerce confirms supply‑chain breach via compromised Ribon app credentials affecting merchant storefronts</strong></li><li><strong>Master of Malt notified customers: names, emails, phone numbers, and addresses were exposed</strong></li><li><strong>Attack ran Sept 13–17 2026; ICO notified, law firm warns of phishing risks for affected retailers</strong></li></ul><p>Ecommerce platform BigCommerce was recently hit with a cyberattack in which it lost sensitive data belonging to some of its users.</p><p>One of the users - online spirits retailer Master of Malt - confirmed the hit and notified its customers that their personally identifiable information (PII) was accessed in the attack.</p><p>BigCommerce is an <a href="https://www.techradar.com/news/the-best-ecommerce-platform" target="_blank">ecommerce platform</a> relatively similar to Shopify. Businesses use it to build and operate online stores without needing to develop the entire commerce infrastructure themselves. It offers features like storefronts, shopping carts, integrations with different payment providers, product inventories, SEO and marketing tools, and more.</p><p>The platform has been around since 2009 and according to a <a href="https://www.sec.gov/Archives/edgar/data/1626450/000095017025029211/bigc-20241231.htm?utm_source=chatgpt.com" target="_blank" rel="nofollow">late 2024 SEC filing</a>, serves 5,884 accounts with at least one unique enterprise plan subscription. A <a href="https://www.bigcommerce.com/press/releases/klarna-partnership-press-release/?utm_source=chatgpt.com" target="_blank" rel="nofollow">2025 press release</a> says BigCommerce is used by “tens of thousands of B2C and B2B companies across 150 countries.”</p><h2 id="software-supply-chain-attack">Software supply chain attack</h2><p>BigCommerce allows its users to install, among others, a third-party app called Ribon, an ecommerce app providing tools that improve the online shopping experience. Some merchants integrate Ribon into their stores to add different functionality to the customer-facing storefront, and to optimize how visitors interact with different elements of their website. We don’t know exactly how many stores use Ribon.</p><p>According to Master of Malt, unidentified threat actors managed to compromise a BigCommerce Application key held by Ribon, and used it to access customer data that was held on their system. The attack took place on Sunday, September 13 2026, until the access was finally revoked four days later, on September 17. </p><p>Speaking to<em> </em><a href="https://www.bleepingcomputer.com/news/security/bigcommerce-alerts-merchants-of-data-breach-linked-to-ribon-apps/" target="_blank"><em>BleepingComputer</em></a>, BigCommerce said credentials for Ribon and Ribon 1.5 were compromised: </p><p>"On September 17, 2026, Commerce confirmed that credentials belonging to third-party applications Ribon and Ribon 1.5, owned and operated by 'Be A Part Of,' a Fastr company, had been compromised and used to inject malicious scripts into a small number of merchant storefronts,” the statement reads. "Acting in the best interest of our customers and their shoppers, we uninstalled the application from affected stores to revoke the attacker's access, notified those merchants directly, and are providing log data to support the developer's investigation," the company told the publication.</p><p>The keyword in this statement is “small number of merchant storefronts.” BigCommerce hints that the attack was relatively small in scope and, consequently, in damage. However, in its report Master of Malt says otherwise: </p><p>“It’s now clear that we weren’t the target of the attack. The attack was against Ribon, which was installed on hundreds of BigCommerce stores. Once the attackers compromised an access key from Ribon, they used it to access data held inside BigCommerce.”</p><h2 id="names-and-emails">Names and emails</h2><p>Whether or not this transforms into a new Snowflake fiasco remains to be seen.</p><p>In the meantime, Master of Malt also said BigCommerce notified it that the attack had been stopped and that there was no further risk of compromise. All companies affected by the breach were contacted. As for the spirits retailer, here is what it said about the data exposed in the hit:</p><p>“I’m sorry to say that the attackers had access to your name, email address, phone number, and address. However, they were not able to access your password, credit card or other payment information as they are held in a separate system which was never compromised.”</p><p>Master of Malt reported the attack to the UK Information Commissioner’s Office (ICO). Law firm Emery Reddy is calling for potential claimants to the incidents, saying that “several retailers” are currently notifying customers about data exposure related to the incident, <em>BleepingComputer</em> reported. </p><p>“A number of online retailers that use the BigCommerce e-commerce platform have begun notifying customers of a data breach that originated not with the retailers themselves, but with a third-party application called Ribon,” the law firm says. Emery Reddy also warned of potential phishing and scam attacks.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/bigcommerce-warns-customers-of-potential-data-leaks-following-cyber-incident</link>
                                                                            <description>
                            <![CDATA[ Hackers broke into a third-party app and stole customer data, including personally identifiable information. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qWoYNBkY75USdGrfuKDHMA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 12:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[hacker hands at work with  interface around]]></media:description>                                                            <media:text><![CDATA[hacker hands at work with  interface around]]></media:text>
                                <media:title type="plain"><![CDATA[hacker hands at work with  interface around]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>BigCommerce confirms supply‑chain breach via compromised Ribon app credentials affecting merchant storefronts</strong></li><li><strong>Master of Malt notified customers: names, emails, phone numbers, and addresses were exposed</strong></li><li><strong>Attack ran Sept 13–17 2026; ICO notified, law firm warns of phishing risks for affected retailers</strong></li></ul><p>Ecommerce platform BigCommerce was recently hit with a cyberattack in which it lost sensitive data belonging to some of its users.</p><p>One of the users - online spirits retailer Master of Malt - confirmed the hit and notified its customers that their personally identifiable information (PII) was accessed in the attack.</p><p>BigCommerce is an <a href="https://www.techradar.com/news/the-best-ecommerce-platform" target="_blank">ecommerce platform</a> relatively similar to Shopify. Businesses use it to build and operate online stores without needing to develop the entire commerce infrastructure themselves. It offers features like storefronts, shopping carts, integrations with different payment providers, product inventories, SEO and marketing tools, and more.</p><p>The platform has been around since 2009 and according to a <a href="https://www.sec.gov/Archives/edgar/data/1626450/000095017025029211/bigc-20241231.htm?utm_source=chatgpt.com" target="_blank" rel="nofollow">late 2024 SEC filing</a>, serves 5,884 accounts with at least one unique enterprise plan subscription. A <a href="https://www.bigcommerce.com/press/releases/klarna-partnership-press-release/?utm_source=chatgpt.com" target="_blank" rel="nofollow">2025 press release</a> says BigCommerce is used by “tens of thousands of B2C and B2B companies across 150 countries.”</p><h2 id="software-supply-chain-attack">Software supply chain attack</h2><p>BigCommerce allows its users to install, among others, a third-party app called Ribon, an ecommerce app providing tools that improve the online shopping experience. Some merchants integrate Ribon into their stores to add different functionality to the customer-facing storefront, and to optimize how visitors interact with different elements of their website. We don’t know exactly how many stores use Ribon.</p><p>According to Master of Malt, unidentified threat actors managed to compromise a BigCommerce Application key held by Ribon, and used it to access customer data that was held on their system. The attack took place on Sunday, September 13 2026, until the access was finally revoked four days later, on September 17. </p><p>Speaking to<em> </em><a href="https://www.bleepingcomputer.com/news/security/bigcommerce-alerts-merchants-of-data-breach-linked-to-ribon-apps/" target="_blank"><em>BleepingComputer</em></a>, BigCommerce said credentials for Ribon and Ribon 1.5 were compromised: </p><p>"On September 17, 2026, Commerce confirmed that credentials belonging to third-party applications Ribon and Ribon 1.5, owned and operated by 'Be A Part Of,' a Fastr company, had been compromised and used to inject malicious scripts into a small number of merchant storefronts,” the statement reads. "Acting in the best interest of our customers and their shoppers, we uninstalled the application from affected stores to revoke the attacker's access, notified those merchants directly, and are providing log data to support the developer's investigation," the company told the publication.</p><p>The keyword in this statement is “small number of merchant storefronts.” BigCommerce hints that the attack was relatively small in scope and, consequently, in damage. However, in its report Master of Malt says otherwise: </p><p>“It’s now clear that we weren’t the target of the attack. The attack was against Ribon, which was installed on hundreds of BigCommerce stores. Once the attackers compromised an access key from Ribon, they used it to access data held inside BigCommerce.”</p><h2 id="names-and-emails">Names and emails</h2><p>Whether or not this transforms into a new Snowflake fiasco remains to be seen.</p><p>In the meantime, Master of Malt also said BigCommerce notified it that the attack had been stopped and that there was no further risk of compromise. All companies affected by the breach were contacted. As for the spirits retailer, here is what it said about the data exposed in the hit:</p><p>“I’m sorry to say that the attackers had access to your name, email address, phone number, and address. However, they were not able to access your password, credit card or other payment information as they are held in a separate system which was never compromised.”</p><p>Master of Malt reported the attack to the UK Information Commissioner’s Office (ICO). Law firm Emery Reddy is calling for potential claimants to the incidents, saying that “several retailers” are currently notifying customers about data exposure related to the incident, <em>BleepingComputer</em> reported. </p><p>“A number of online retailers that use the BigCommerce e-commerce platform have begun notifying customers of a data breach that originated not with the retailers themselves, but with a third-party application called Ribon,” the law firm says. Emery Reddy also warned of potential phishing and scam attacks.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Linux users beware — CISA flags three major security issues you need to patch right now ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>CISA added three Linux kernel flaws (CVE‑2025‑39682, CVE‑2026‑53266, CVE‑2025‑39964) to KEV catalog</strong></li><li><strong>Red Hat confirmed active exploitation; agencies given rare three‑day patch deadline expiring Sept 21, 2026</strong></li><li><strong>Bugs enable DoS, privilege escalation, or data corruption; patches available, limited mitigations for two flaws</strong></li></ul><p>The US Cybersecurity and Infrastructure Security Agency (CISA) has added three <a href="https://www.techradar.com/best/best-linux-distros-for-windows-users" target="_blank">Linux</a> flaws to its Known Exploited Vulnerabilities (KEV) catalog, signaling abuse in the wild and giving government agencies a deadline to patch or stop using the flawed product entirely.</p><p>The three bugs in question are tracked as CVE-2025-39682 (severity score 9.8/10 - critical), CVE-2026-53266 (severity score 8.8/10 - high), and CVE-2025-39964 (severity score 7.8/10 - high). All three have already been patched in the Linux kernel. CVE-2025-39682 was fixed in stable releases 6.1.149, 6.6.103, 6.12.44 and 6.16.4, while CVE-2025-39964 was fixed in 5.10.245, 5.15.194, 6.1.154, 6.6.108, 6.12.49 and 6.16.9. CVE-2026-53266 has been fixed upstream and backported to supported stable/distribution kernel branches, including 5.10.259, 6.1.176 and 6.12.94.</p><p>The first issue is an improper check for unusual or exceptional conditions vulnerability in the TLS receive patch which could allow unauthenticated threat actors to launch memory disclosure or denial-of-service (DoS) attacks. The second one (CVE-2026-53266) is an out-of-bounds write vulnerability in the ebtables Source Network Address Translation (SNAT) Address Resolution Protocol (ARP) rewrite patch which allows local attackers to escalate privileges or mount DoS attacks. </p><p>The last one (CVE-2025-39964) is a race condition flaw that allows concurrent writes to the same AF_ALG socket, which allows local malicious actors to crash the system or corrupt cryptographic operation results, leading to data integrity issues and possible DoS states. </p><h2 id="attacks-in-the-wild">Attacks in the wild</h2><p>Red Hat acknowledged that all three are being abused in real-life attacks. “This CVE is high risk and there are known public exploits leveraging this vulnerability. Address this vulnerability with high priority,” it said in all three advisories. </p><p>However, there are no details as to who is currently using these exploits, against whom, and to what cause. There are currently no separate reports of cyberattacks referencing any of the abovementioned vulnerabilities. </p><p>However, CISA still reacted. All three flaws were added on September 18, 2026, and all three have a small three-day deadline for patching that expires on September 21. Usually, CISA would grant Federal Civilian Executive Branch (FCEB) agencies a three-week deadline to patch up, with just exceptionally dangerous flaws getting a shorter window. That being said, these flaws are likely extremely dangerous. </p><h2 id="in-theory">In theory...</h2><p>In a hypothetical scenario, a threat actor could target a Linux system using kernel TLS (kTLS) by sending a specially-crafted TLS record that triggers CVE-2025-39682 and causing either a crash, or even arbitrary code execution. Attackers that already have a low privilege foothold on the target endpoint could use CVE_2025-39964 to escalate privileges, while on systems using the affected bridge/netfilter configuration, CVE-2026-53266 could be used for privilege escalation, as well. </p><p>According to the Red Hat advisory, there is a chance that CVE-2025-39682 is remotely triggerable, but only when the system is using the affected kTLS receive path. The other two flaws are exclusively local vulnerabilities. </p><p>Besides fixes, two out of the three flaws also have possible mitigations. For the improper check one, users should prevent module tls from being loaded. For the out-of-bounds write one, users are advised to disable ARP hardware address rewriting in ebtables SNAT rules, or remove ebtables SNAT rules that operate on ARP traffic on bridge interfaces. The final vulnerability, currently does not have a working mitigation, and the only way to stay secure is to apply the provided patches. </p><p>Linux kernel vulnerabilities are generally considered serious, but the severity still depends on the flaw and how the affected kernel is deployed. Earlier this year, security researchers disclosed four local privilege escalation flaws, called DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121), and DiagSpill (CVE-2026-74469). </p><p><em>Via </em><a href="https://thehackernews.com/2026/09/cisa-flags-three-linux-kernel.html" target="_blank"><em>The Hacker News</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/linux-users-beware-cisa-flags-three-major-security-issues-you-need-to-patch-right-now</link>
                                                                            <description>
                            <![CDATA[ Two flaws have available mitigations, too, but it's best to patch up. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SSYMHF6E7FMSYLeTPLyfnF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MRcAF4wnJU8Qb7Bv7Lb9yd-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 01:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MRcAF4wnJU8Qb7Bv7Lb9yd-1920-80.jpg">
                                                            <media:credit><![CDATA[Pixababy]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Linux penguin logo on wood]]></media:description>                                                            <media:text><![CDATA[Linux penguin logo on wood]]></media:text>
                                <media:title type="plain"><![CDATA[Linux penguin logo on wood]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MRcAF4wnJU8Qb7Bv7Lb9yd-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>CISA added three Linux kernel flaws (CVE‑2025‑39682, CVE‑2026‑53266, CVE‑2025‑39964) to KEV catalog</strong></li><li><strong>Red Hat confirmed active exploitation; agencies given rare three‑day patch deadline expiring Sept 21, 2026</strong></li><li><strong>Bugs enable DoS, privilege escalation, or data corruption; patches available, limited mitigations for two flaws</strong></li></ul><p>The US Cybersecurity and Infrastructure Security Agency (CISA) has added three <a href="https://www.techradar.com/best/best-linux-distros-for-windows-users" target="_blank">Linux</a> flaws to its Known Exploited Vulnerabilities (KEV) catalog, signaling abuse in the wild and giving government agencies a deadline to patch or stop using the flawed product entirely.</p><p>The three bugs in question are tracked as CVE-2025-39682 (severity score 9.8/10 - critical), CVE-2026-53266 (severity score 8.8/10 - high), and CVE-2025-39964 (severity score 7.8/10 - high). All three have already been patched in the Linux kernel. CVE-2025-39682 was fixed in stable releases 6.1.149, 6.6.103, 6.12.44 and 6.16.4, while CVE-2025-39964 was fixed in 5.10.245, 5.15.194, 6.1.154, 6.6.108, 6.12.49 and 6.16.9. CVE-2026-53266 has been fixed upstream and backported to supported stable/distribution kernel branches, including 5.10.259, 6.1.176 and 6.12.94.</p><p>The first issue is an improper check for unusual or exceptional conditions vulnerability in the TLS receive patch which could allow unauthenticated threat actors to launch memory disclosure or denial-of-service (DoS) attacks. The second one (CVE-2026-53266) is an out-of-bounds write vulnerability in the ebtables Source Network Address Translation (SNAT) Address Resolution Protocol (ARP) rewrite patch which allows local attackers to escalate privileges or mount DoS attacks. </p><p>The last one (CVE-2025-39964) is a race condition flaw that allows concurrent writes to the same AF_ALG socket, which allows local malicious actors to crash the system or corrupt cryptographic operation results, leading to data integrity issues and possible DoS states. </p><h2 id="attacks-in-the-wild">Attacks in the wild</h2><p>Red Hat acknowledged that all three are being abused in real-life attacks. “This CVE is high risk and there are known public exploits leveraging this vulnerability. Address this vulnerability with high priority,” it said in all three advisories. </p><p>However, there are no details as to who is currently using these exploits, against whom, and to what cause. There are currently no separate reports of cyberattacks referencing any of the abovementioned vulnerabilities. </p><p>However, CISA still reacted. All three flaws were added on September 18, 2026, and all three have a small three-day deadline for patching that expires on September 21. Usually, CISA would grant Federal Civilian Executive Branch (FCEB) agencies a three-week deadline to patch up, with just exceptionally dangerous flaws getting a shorter window. That being said, these flaws are likely extremely dangerous. </p><h2 id="in-theory">In theory...</h2><p>In a hypothetical scenario, a threat actor could target a Linux system using kernel TLS (kTLS) by sending a specially-crafted TLS record that triggers CVE-2025-39682 and causing either a crash, or even arbitrary code execution. Attackers that already have a low privilege foothold on the target endpoint could use CVE_2025-39964 to escalate privileges, while on systems using the affected bridge/netfilter configuration, CVE-2026-53266 could be used for privilege escalation, as well. </p><p>According to the Red Hat advisory, there is a chance that CVE-2025-39682 is remotely triggerable, but only when the system is using the affected kTLS receive path. The other two flaws are exclusively local vulnerabilities. </p><p>Besides fixes, two out of the three flaws also have possible mitigations. For the improper check one, users should prevent module tls from being loaded. For the out-of-bounds write one, users are advised to disable ARP hardware address rewriting in ebtables SNAT rules, or remove ebtables SNAT rules that operate on ARP traffic on bridge interfaces. The final vulnerability, currently does not have a working mitigation, and the only way to stay secure is to apply the provided patches. </p><p>Linux kernel vulnerabilities are generally considered serious, but the severity still depends on the flaw and how the affected kernel is deployed. Earlier this year, security researchers disclosed four local privilege escalation flaws, called DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121), and DiagSpill (CVE-2026-74469). </p><p><em>Via </em><a href="https://thehackernews.com/2026/09/cisa-flags-three-linux-kernel.html" target="_blank"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Researchers can make headphones leak audio through a wall, but the 30-meter claim has a few caveats ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>HKUST (Guangzhou) and HK PolyU researchers' InjectEave beams a radio carrier at devices so their own circuits leak analog audio</strong></li><li><strong>The leaked audio has already been decrypted by the device itself, making encryption offer no protection against such an approach</strong></li><li><strong>The 30m headline needed a pricey amplifier pushing output to 10 W, while standard ranges of 1 to 6m were measured by detecting a test tone</strong></li></ul><p>Researchers at the Hong Kong University of Science and Technology and the Hong Kong Polytechnic University have shown that everyday headphones, a desk phone, and a handful of smart-home gadgets can broadcast what they are doing simply by using a radio signal.</p><p>The technique, called <a href="https://injecteave.github.io/" target="_blank">InjectEave</a>, was presented at USENIX Security 2026 in Baltimore, and multiple outlets <a href="https://www.theregister.com/security/2026/09/17/researchers-find-way-to-listen-in-on-headphones-from-afar/5297303" target="_blank">have since covered</a> the researcher's claim that the attack "can recover headphone audio from up to 30 meters away, including through walls".</p><p>The claim may be accurate, but it has limitations, including the need for specialized equipment that is often very noticeable in most settings.</p><h2 id="an-impressive-technical-show-with-plenty-of-limitations-in-tow">An impressive technical show with plenty of limitations in tow</h2><p>Conventional electromagnetic eavesdropping waits for a device to leak. That works poorly for audio, because speech sits below 20 kHz while a device's wiring radiates efficiently only at megahertz or gigahertz frequencies.</p><p>InjectEave chooses to close the gap by transmitting a carrier signal at the target. According to <a href="https://injecteave.github.io/assets/paper/sec26cycle2-final651.pdf" target="_blank" rel="nofollow">the paper</a>, nonlinear components such as amplifiers, analog-to-digital converters, switching MOSFETs, and power converters mix the secret signal onto that carrier, and the device's own traces and cables radiate the result back to a receiver.<br><br>Because the leak happens in the analog path, after audio has been decoded, the project page states that "InjectEave is immune to digital defenses such as encryption, masking, and randomization." Encryption in any form on a wireless headset is irrelevant, since the attack directly targets the signal driving the speaker, not the radio link.</p><p>The team demonstrating this used a USRP B210 software-defined radio, two antennas, a Siglent spectrum analyzer, and a laptop to set up their proof of concept, which could, as they noted, "eavesdrop on the majority of these devices from over 2m away and through walls, with a maximum distance of 30m for recovering intelligible headphone audio". </p><p>This isn't the first time the technique has been used, even as the researchers have built on it considerably; the idea <a href="https://en.wikipedia.org/wiki/The_Thing_(listening_device)" target="_blank">originates from "The Thing</a>," a Soviet bug given as a gift to the US ambassador in Moscow in 1945, which was passively powered remotely as a listening device.</p><p>InjectEve, however, does not involve planting anything; instead, it leverages existing work on interference-induced leakage and impedance-based backscatter, and distinguishes itself by recovering coarse digital data rather than continuous analog waveforms, allowing users to 'listen in' without added steps.</p><p>The same approach applies to wired headphones, which are also prone to leaking microphone audio; researchers concluded that their sound cards were the primary source of the leaks, which were being sent back over very short distances.</p><p>The threat is somewhat tempered by the fact that it can capture what users hear but, with wireless headphones, cannot hear what the user is saying. The attacker also has to transmit continuously and use a high-powered (10W) transmitter to reach the full 30-meter range, even though capturing and rendering speech is harder than the tones the test used to prove the approach worked.</p><p>The attacker also needs to know the target model and profile a matching unit first, although they managed to get a profile to transfer cleanly across three identical UGreen headsets, suggesting this might be easier than one would assume.</p><p>The researchers say they reported the findings to the affected manufacturers but, "as we have not yet received a response," withheld the table's frequencies and stripped injection control logic from their released code. One shouldn't be too hopeful, however, as no software update can fix an analog leak, and it is relatively limited in practical abuse cases.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/researchers-can-make-headphones-leak-audio-through-a-wall-but-the-30-meter-claim-has-a-few-caveats</link>
                                                                            <description>
                            <![CDATA[ Encryption can't stop InjectEave because the audio leaks after it's been decoded, but it does have its limitations. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">C9VZczcuq5MFFvrjVaUUCf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9ui8vuAvNqX2Bubaxvks8J-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 21 Sep 2026 23:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Audio]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9ui8vuAvNqX2Bubaxvks8J-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Headphones]]></media:description>                                                            <media:text><![CDATA[Headphones]]></media:text>
                                <media:title type="plain"><![CDATA[Headphones]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9ui8vuAvNqX2Bubaxvks8J-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>HKUST (Guangzhou) and HK PolyU researchers' InjectEave beams a radio carrier at devices so their own circuits leak analog audio</strong></li><li><strong>The leaked audio has already been decrypted by the device itself, making encryption offer no protection against such an approach</strong></li><li><strong>The 30m headline needed a pricey amplifier pushing output to 10 W, while standard ranges of 1 to 6m were measured by detecting a test tone</strong></li></ul><p>Researchers at the Hong Kong University of Science and Technology and the Hong Kong Polytechnic University have shown that everyday headphones, a desk phone, and a handful of smart-home gadgets can broadcast what they are doing simply by using a radio signal.</p><p>The technique, called <a href="https://injecteave.github.io/" target="_blank">InjectEave</a>, was presented at USENIX Security 2026 in Baltimore, and multiple outlets <a href="https://www.theregister.com/security/2026/09/17/researchers-find-way-to-listen-in-on-headphones-from-afar/5297303" target="_blank">have since covered</a> the researcher's claim that the attack "can recover headphone audio from up to 30 meters away, including through walls".</p><p>The claim may be accurate, but it has limitations, including the need for specialized equipment that is often very noticeable in most settings.</p><h2 id="an-impressive-technical-show-with-plenty-of-limitations-in-tow">An impressive technical show with plenty of limitations in tow</h2><p>Conventional electromagnetic eavesdropping waits for a device to leak. That works poorly for audio, because speech sits below 20 kHz while a device's wiring radiates efficiently only at megahertz or gigahertz frequencies.</p><p>InjectEave chooses to close the gap by transmitting a carrier signal at the target. According to <a href="https://injecteave.github.io/assets/paper/sec26cycle2-final651.pdf" target="_blank" rel="nofollow">the paper</a>, nonlinear components such as amplifiers, analog-to-digital converters, switching MOSFETs, and power converters mix the secret signal onto that carrier, and the device's own traces and cables radiate the result back to a receiver.<br><br>Because the leak happens in the analog path, after audio has been decoded, the project page states that "InjectEave is immune to digital defenses such as encryption, masking, and randomization." Encryption in any form on a wireless headset is irrelevant, since the attack directly targets the signal driving the speaker, not the radio link.</p><p>The team demonstrating this used a USRP B210 software-defined radio, two antennas, a Siglent spectrum analyzer, and a laptop to set up their proof of concept, which could, as they noted, "eavesdrop on the majority of these devices from over 2m away and through walls, with a maximum distance of 30m for recovering intelligible headphone audio". </p><p>This isn't the first time the technique has been used, even as the researchers have built on it considerably; the idea <a href="https://en.wikipedia.org/wiki/The_Thing_(listening_device)" target="_blank">originates from "The Thing</a>," a Soviet bug given as a gift to the US ambassador in Moscow in 1945, which was passively powered remotely as a listening device.</p><p>InjectEve, however, does not involve planting anything; instead, it leverages existing work on interference-induced leakage and impedance-based backscatter, and distinguishes itself by recovering coarse digital data rather than continuous analog waveforms, allowing users to 'listen in' without added steps.</p><p>The same approach applies to wired headphones, which are also prone to leaking microphone audio; researchers concluded that their sound cards were the primary source of the leaks, which were being sent back over very short distances.</p><p>The threat is somewhat tempered by the fact that it can capture what users hear but, with wireless headphones, cannot hear what the user is saying. The attacker also has to transmit continuously and use a high-powered (10W) transmitter to reach the full 30-meter range, even though capturing and rendering speech is harder than the tones the test used to prove the approach worked.</p><p>The attacker also needs to know the target model and profile a matching unit first, although they managed to get a profile to transfer cleanly across three identical UGreen headsets, suggesting this might be easier than one would assume.</p><p>The researchers say they reported the findings to the affected manufacturers but, "as we have not yet received a response," withheld the table's frequencies and stripped injection control logic from their released code. One shouldn't be too hopeful, however, as no software update can fix an analog leak, and it is relatively limited in practical abuse cases.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are hiding malware on blockchains that are nearly impossible to take down, and unrestricted AI models have pushed these attacks up 440% ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Hackers are using blockchains to keep malware instructions available after servers disappear</strong></li><li><strong>AI is making blockchain-based malware infrastructure easier for less experienced hackers</strong></li><li><strong>Blockchain traffic is difficult to block without disrupting legitimate cryptocurrency services worldwide</strong></li></ul><p>Hackers are increasingly hiding malware instructions inside public blockchains, creating communication channels that can survive the removal of conventional infrastructure.</p><p>New figures from <a href="https://www.chainalysis.com/blog/etherhiding-blockchain-dead-drops/" target="_blank" rel="nofollow">Chainalysis</a> claim malicious blockchain activity increased 440%, with daily entries rising from 2.06 to 11.1 after newer AI systems emerged.</p><p>The technique gives attackers another way to maintain communication with compromised computers without relying entirely on conventional servers controlled by hosting providers.</p><h2 id="blockchain-networks-become-malware-dead-drops">Blockchain networks become malware dead drops</h2><p>Blockchain dead drops use transaction data or smart contracts as lookup points, allowing infected computers to retrieve commands, addresses, or configuration information.</p><p>Because blockchain records are distributed across networks, removing a conventional server does not erase information already stored on the ledger.</p><p>A North Korean-linked operation associated with UNC5342 uses TRON and Aptos as alternate routes before retrieving encrypted instructions through the BNB Chain.</p><p>Its malware can check one network, switch to another when necessary, and retrieve updated addresses without receiving another malware package.</p><p>Iranian actors suspected of links to the country's intelligence ministry have embedded encoded routing information inside Bitcoin transactions used for malware retrieval.</p><p>Russian-speaking cybercriminals have also commercialized the technique, using Polygon contracts to provide blockchain-backed infrastructure for malware campaigns operated by different customers.</p><p>One related operator controls more than 50 BNB Chain resolver contracts while also conducting activity involving fraudulent tokens and clipboard-monitoring malware.</p><p>These operations show how blockchain records can function as persistent lookup infrastructure rather than merely serving their conventional financial and transactional purposes.</p><h2 id="ai-lowers-the-technical-barrier">AI lowers the technical barrier</h2><p>Chainalysis said the sharp increase in this malicious activity followed the arrival of high-capacity Chinese open models, which placed fewer restrictions on malware development requests.</p><p>Before those systems appeared, building reliable blockchain-based malware infrastructure required expertise across malicious software, cryptocurrency networks, and distributed communication systems.</p><p><a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> can reduce that knowledge barrier by helping less experienced operators understand unfamiliar technologies and produce components needed for blockchain communication.</p><p>In the second quarter of 2026, state-linked groups accounted for roughly two-thirds of newly observed activity.</p><p>Those groups also represent about half of overall observed activity, indicating that blockchain-based malware infrastructure extends beyond conventional cybercriminal operations.</p><p>Defenders face difficulties because blocking blockchain traffic could also disrupt legitimate wallets, decentralized applications, exchanges, and decentralized finance services used worldwide.</p><p>Attackers can further complicate disruption by operating their own blockchain nodes, reducing dependence on external providers that defenders might otherwise pressure or disable.</p><p>Some operators have hidden server addresses inside wallet identifiers without usable private keys, then used zero-value transfers to trigger malware retrieval.</p><p>Those transactions leave public records that investigators can examine, potentially providing useful clues even when attackers attempt to conceal their infrastructure.</p><p>"While the exploitation of blockchain by state-linked organizations such as North Korea is becoming more sophisticated, on-chain records left by attackers can actually serve as important clues to track them," said Kwon Jun-hyeok, General Manager of Chainalysis Korea.</p><p>"Tracking these traces and identifying attackers and related infrastructure through blockchain intelligence will become increasingly important in responding to new cyber threats."</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/hackers-are-hiding-malware-on-blockchains-that-are-nearly-impossible-to-take-down-and-unrestricted-ai-models-have-pushed-these-attacks-up-440</link>
                                                                            <description>
                            <![CDATA[ Hackers are hiding malware instructions across public blockchains, while AI makes the technique easier to deploy and harder for defenders to disrupt. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gNXkUKVJiTppBLGVKms7AE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 21 Sep 2026 22:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[North Korean flag with a hooded hacker]]></media:description>                                                            <media:text><![CDATA[North Korean flag with a hooded hacker]]></media:text>
                                <media:title type="plain"><![CDATA[North Korean flag with a hooded hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Hackers are using blockchains to keep malware instructions available after servers disappear</strong></li><li><strong>AI is making blockchain-based malware infrastructure easier for less experienced hackers</strong></li><li><strong>Blockchain traffic is difficult to block without disrupting legitimate cryptocurrency services worldwide</strong></li></ul><p>Hackers are increasingly hiding malware instructions inside public blockchains, creating communication channels that can survive the removal of conventional infrastructure.</p><p>New figures from <a href="https://www.chainalysis.com/blog/etherhiding-blockchain-dead-drops/" target="_blank" rel="nofollow">Chainalysis</a> claim malicious blockchain activity increased 440%, with daily entries rising from 2.06 to 11.1 after newer AI systems emerged.</p><p>The technique gives attackers another way to maintain communication with compromised computers without relying entirely on conventional servers controlled by hosting providers.</p><h2 id="blockchain-networks-become-malware-dead-drops">Blockchain networks become malware dead drops</h2><p>Blockchain dead drops use transaction data or smart contracts as lookup points, allowing infected computers to retrieve commands, addresses, or configuration information.</p><p>Because blockchain records are distributed across networks, removing a conventional server does not erase information already stored on the ledger.</p><p>A North Korean-linked operation associated with UNC5342 uses TRON and Aptos as alternate routes before retrieving encrypted instructions through the BNB Chain.</p><p>Its malware can check one network, switch to another when necessary, and retrieve updated addresses without receiving another malware package.</p><p>Iranian actors suspected of links to the country's intelligence ministry have embedded encoded routing information inside Bitcoin transactions used for malware retrieval.</p><p>Russian-speaking cybercriminals have also commercialized the technique, using Polygon contracts to provide blockchain-backed infrastructure for malware campaigns operated by different customers.</p><p>One related operator controls more than 50 BNB Chain resolver contracts while also conducting activity involving fraudulent tokens and clipboard-monitoring malware.</p><p>These operations show how blockchain records can function as persistent lookup infrastructure rather than merely serving their conventional financial and transactional purposes.</p><h2 id="ai-lowers-the-technical-barrier">AI lowers the technical barrier</h2><p>Chainalysis said the sharp increase in this malicious activity followed the arrival of high-capacity Chinese open models, which placed fewer restrictions on malware development requests.</p><p>Before those systems appeared, building reliable blockchain-based malware infrastructure required expertise across malicious software, cryptocurrency networks, and distributed communication systems.</p><p><a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> can reduce that knowledge barrier by helping less experienced operators understand unfamiliar technologies and produce components needed for blockchain communication.</p><p>In the second quarter of 2026, state-linked groups accounted for roughly two-thirds of newly observed activity.</p><p>Those groups also represent about half of overall observed activity, indicating that blockchain-based malware infrastructure extends beyond conventional cybercriminal operations.</p><p>Defenders face difficulties because blocking blockchain traffic could also disrupt legitimate wallets, decentralized applications, exchanges, and decentralized finance services used worldwide.</p><p>Attackers can further complicate disruption by operating their own blockchain nodes, reducing dependence on external providers that defenders might otherwise pressure or disable.</p><p>Some operators have hidden server addresses inside wallet identifiers without usable private keys, then used zero-value transfers to trigger malware retrieval.</p><p>Those transactions leave public records that investigators can examine, potentially providing useful clues even when attackers attempt to conceal their infrastructure.</p><p>"While the exploitation of blockchain by state-linked organizations such as North Korea is becoming more sophisticated, on-chain records left by attackers can actually serve as important clues to track them," said Kwon Jun-hyeok, General Manager of Chainalysis Korea.</p><p>"Tracking these traces and identifying attackers and related infrastructure through blockchain intelligence will become increasingly important in responding to new cyber threats."</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft, Google took down $66 million cybercrime marketplace that sold virtual machines with free software ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>So-called signal sharing between Microsoft and Google uncovered the RedVDS marketplace was behind large-scale cyber fraud</strong></li><li><strong>RedVDS sold access to virtual machines running unlicensed software from which cybercriminals launched scams and directed attacks</strong></li><li><strong>Threat data was shared securely via the Global Signal Exchange (GSE), a non-profit organization</strong></li></ul><p>A major cybercrime marketplace has been taken out of action thanks to cooperation between Microsoft and Google via a secure threat data sharing platform.</p><p>Known as the Global Signal Exchange, the collaboration led to the take-down of the RedVDS, an online cybercrime mall supplying virtual machines for launching phishing, business email compromise attacks, and more.</p><p>The marketplace – which provided quickly-deleted and therefore virtually untraceable VMs – was meticulously monitored by Microsoft’s security team, Digital Crimes Unit, with both Microsoft and Google suspending the operation and action taken to seize domains and servers.</p><p>A secondary case featuring the GSE identified a Microsoft-impersonating tech support scam, resulting, highlighting the importance of secure thread data collaboration platforms.</p><h2 id="digital-crimes-unit">Digital Crimes Unit</h2><p>Finding massive scams is not easy. Even with its own Digital Crimes Unit, Microsoft has to rely on information sharing with third party organizations. In this case, the RedVDS marketplace was identified ahead of disruptive action taken by Microsoft in January 2026, which applied to courts in the UK and US to have the RedVDS web domains seized. </p><p>Data shared via the GSE enabled Google to follow suit, identifying related accounts on its networks and suspending them. Meanwhile, servers were impounded in Germany, and Europol took action against Europe-based RedVDS servers.</p><p>It’s an impressive account of cooperative, decisive action against cybercrime, a collaborative response to what has been described as a “$66 million fraud marketplace.”</p><p>An incredible 130,000 organizations were targeted by RedVDS-provided virtual machines between September and December 2025, with 191,000 Microsoft email accounts compromised during this period. All of this access to cybercrime was available from just $24 a month for a basic scam-ready virtual machine.</p><h2 id="the-importance-of-collaboration">The importance of collaboration</h2><p>The <a href="https://www.globalsignalexchange.org/" target="_blank">Global Signal Exchange</a> is a UK-based non-profit, co-founded with Google in 2025 with the aim of providing real-time monitoring of the cybercrime supply chain.</p><p>"Fraud does not respect company boundaries, and no single organization ever sees the whole picture," noted Emily Taylor, CEO at Oxford Information Labs and Co-Founder of the Global Signal Exchange.</p><p>"That is exactly why we built GSE: to give trusted partners a secure way to share what they know, quickly. These two cases are a good example of GSE doing exactly what it was designed to do."</p><p>The Global Signal Exchange’s role in the sharing of information between Google and Microsoft has highlighted the importance in such collaborations. Both organizations have stated they plan to continue sharing information through the GSE, whose other partners include Meta, Amazon, Google, among many others.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/microsoft-google-took-down-usd66-million-cybercrime-marketplace-that-sold-virtual-machines-with-free-software</link>
                                                                            <description>
                            <![CDATA[ Effort takes down RedVDS, a criminal marketplace believed to have contributed to $66 million losses to US businesses and individuals. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KNhtDnd9aEQfqfLmY4HgDK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cAewSdXkrLEUsD8muVzGX9-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 21 Sep 2026 18:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christian Cawley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zBDYnjPnB2XPvhKbYX9Kuc-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Christian Cawley has extensive experience as a writer and editor in consumer electronics, IT and entertainment media. He has contributed to TechRadar since 2017 and has been published in Computer Weekly, Linux Format, ComputerActive, and other publications. &lt;/p&gt;&lt;p&gt;Beyond TechRadar, he heads up the team at smart home website Matter Alpha, and writes about retro gaming at Gaming Retro. &lt;/p&gt;&lt;p&gt;Formerly the editor responsible for Linux, Security, Programming, and DIY at MakeUseOf, Christian previously worked as a desktop and software support specialist in the public and private sectors.&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cAewSdXkrLEUsD8muVzGX9-1920-80.jpg">
                                                            <media:credit><![CDATA[gguy / Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft logo outside building]]></media:description>                                                            <media:text><![CDATA[Microsoft logo outside building]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft logo outside building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cAewSdXkrLEUsD8muVzGX9-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>So-called signal sharing between Microsoft and Google uncovered the RedVDS marketplace was behind large-scale cyber fraud</strong></li><li><strong>RedVDS sold access to virtual machines running unlicensed software from which cybercriminals launched scams and directed attacks</strong></li><li><strong>Threat data was shared securely via the Global Signal Exchange (GSE), a non-profit organization</strong></li></ul><p>A major cybercrime marketplace has been taken out of action thanks to cooperation between Microsoft and Google via a secure threat data sharing platform.</p><p>Known as the Global Signal Exchange, the collaboration led to the take-down of the RedVDS, an online cybercrime mall supplying virtual machines for launching phishing, business email compromise attacks, and more.</p><p>The marketplace – which provided quickly-deleted and therefore virtually untraceable VMs – was meticulously monitored by Microsoft’s security team, Digital Crimes Unit, with both Microsoft and Google suspending the operation and action taken to seize domains and servers.</p><p>A secondary case featuring the GSE identified a Microsoft-impersonating tech support scam, resulting, highlighting the importance of secure thread data collaboration platforms.</p><h2 id="digital-crimes-unit">Digital Crimes Unit</h2><p>Finding massive scams is not easy. Even with its own Digital Crimes Unit, Microsoft has to rely on information sharing with third party organizations. In this case, the RedVDS marketplace was identified ahead of disruptive action taken by Microsoft in January 2026, which applied to courts in the UK and US to have the RedVDS web domains seized. </p><p>Data shared via the GSE enabled Google to follow suit, identifying related accounts on its networks and suspending them. Meanwhile, servers were impounded in Germany, and Europol took action against Europe-based RedVDS servers.</p><p>It’s an impressive account of cooperative, decisive action against cybercrime, a collaborative response to what has been described as a “$66 million fraud marketplace.”</p><p>An incredible 130,000 organizations were targeted by RedVDS-provided virtual machines between September and December 2025, with 191,000 Microsoft email accounts compromised during this period. All of this access to cybercrime was available from just $24 a month for a basic scam-ready virtual machine.</p><h2 id="the-importance-of-collaboration">The importance of collaboration</h2><p>The <a href="https://www.globalsignalexchange.org/" target="_blank">Global Signal Exchange</a> is a UK-based non-profit, co-founded with Google in 2025 with the aim of providing real-time monitoring of the cybercrime supply chain.</p><p>"Fraud does not respect company boundaries, and no single organization ever sees the whole picture," noted Emily Taylor, CEO at Oxford Information Labs and Co-Founder of the Global Signal Exchange.</p><p>"That is exactly why we built GSE: to give trusted partners a secure way to share what they know, quickly. These two cases are a good example of GSE doing exactly what it was designed to do."</p><p>The Global Signal Exchange’s role in the sharing of information between Google and Microsoft has highlighted the importance in such collaborations. Both organizations have stated they plan to continue sharing information through the GSE, whose other partners include Meta, Amazon, Google, among many others.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cybercrime civil war brewing? ShinyHunters reportedly hacks Cl0p ransomware gang and threatens further damage ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>ShinyHunters hacked rival gang Cl0p, stealing source code, logs, and onion service keys</strong></li><li><strong>The gang defaced Cl0p’s site via Grav CMS flaw, posting their logo and taunts about past threats</strong></li><li><strong>Feud recalls Conti’s collapse in 2022, raising risk of escalating “cyber war” between criminal groups</strong></li></ul><p>Infamous cybercriminal gang Cl0p has seemingly been hacked by an even more infamous data leak collective, ShinyHunters. </p><p>The attack is still being pieced together, but it would seem we have true hacker beef on our hands - which just might escalate into a full-blown cyber war.</p><p>ShinyHunters has added Cl0p to their data leak site, giving the hacking group 72 hours to pay a <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransom</a> or see all their files leaked into the cybercriminal underbelly. The files allegedly stolen in the attack include source code, Grav CMS plugins, system logs, and other information, <a href="https://cybernews.com/news/shinyhunters-hacks-clop-ransomware/" target="_blank"><em>Cybernews</em></a> reports. We don’t know how much money ShinyHunters are asking to keep Cl0p’s files private.</p><h2 id="still-downloading">Still downloading</h2><p>"The data we stole includes source codes, gravCMS plugins, and other things. We are still downloading and reviewing them," ShinyHunters allegedly told <em>BleepingComputer</em>.</p><p>The group also said they stole everything in the server’s /var/log directory, including system activity records, authentication logs, and IP addresses associated with connections to the server. We doubt this could lead to the identification of any Cl0p members, and even if it could, it would mean very little since the members are likely Russian and thus mostly free to conduct their operations. </p><p>Doxxing might help defenders disrupt the group’s infrastructure, though. </p><p>Whether or not that will be needed, given ShinyHunters’ activity, remains to be seen. The attackers also said they stole the private keys for Cl0p’s Tor onion service:</p><p>"We have their onion keys. So if they kick us out it wouldn't matter at all because we control the private keys to host the same exact onion URL," the group said.</p><p>On top of it all, ShinyHunters defaced Cl0p’s website. Allegedly, the group found an unauthenticated file upload flaw in the Grav CMS Cl0p was using, gaining access to their target’s servers, website, and more. <em>Cybernews</em> confirmed the website had been defaced and now holds an ASCII image of ShinyHunters’ logo, and a link to their Tor site. It also displays a large message: </p><p>"THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p - Maybe don't try to threaten us next time.” Furthermore, it says “rooting your systems since '19 ;)".</p><p>The “maybe don’t try to threaten us next time” message seems to refer to a threat that a Cl0p member made earlier. Apparently, this person threatened violence against ShinyHunters, as well as to expose their identities to the public. The remarks were made during Cl0p’s 2025 Oracle E-Business Suite attacks. </p><p>"During the Oracle EBS campaign they ran and stole from me last year, someone from cl0p personally messaged me and said, and I quote (translated from Russian): I have more money than you and all of your people combined, I'll kill you soon," ShinyHunters told <em>BleepingComputer</em>.</p><h2 id="dog-eat-dog">Dog eat dog</h2><p>Cybercriminals often work together. They share resources, rent each other’s services, and often complement their campaigns. However, that doesn’t make them “friends” or “colleagues”, in any way. It is usually just a marriage of convenience that falls apart at the slightest sound of trouble. The last big “feud” we’ve seen was back in 2022, at the very start of the Russian invasion of Ukraine. Back then, a group called Conti publicly declared its “full support” for the Russian government and threatened to use its resources against anyone conducting cyberattacks on Russian infrastructure.</p><p>The announcement was a fiasco - many of Conti’s affiliates stopped working with the group, and others were openly attacking it. Soon after, a Ukrainian researcher and an alleged affiliate leaked more than 60,000 messages, exposing the group’s operations and internal organization. </p><p>All of this eventually led to Conti’s collapse later that year. However, its members did not disappear - they splintered into multiple groups such as Black Basta, Royal, and Quantum. Some of the crooks engaged in Conti are allegedly still active today.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/cybercrime-civil-war-brewing-shinyhunters-reportedly-hacks-cl0p-ransomware-gang-and-threatens-further-damage</link>
                                                                            <description>
                            <![CDATA[ Cl0p's website was defaced and its data stolen in attack. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6aFJsMe7pPmUgBF4oiqqdN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zTH6vPrB4yxX7dzdy29Xga-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 21 Sep 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zTH6vPrB4yxX7dzdy29Xga-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An image of a digitized skull and crossbones symbolizing hacking and cyberattacks overlayed on a background of digital glitches and noise.]]></media:description>                                                            <media:text><![CDATA[An image of a digitized skull and crossbones symbolizing hacking and cyberattacks overlayed on a background of digital glitches and noise.]]></media:text>
                                <media:title type="plain"><![CDATA[An image of a digitized skull and crossbones symbolizing hacking and cyberattacks overlayed on a background of digital glitches and noise.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zTH6vPrB4yxX7dzdy29Xga-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>ShinyHunters hacked rival gang Cl0p, stealing source code, logs, and onion service keys</strong></li><li><strong>The gang defaced Cl0p’s site via Grav CMS flaw, posting their logo and taunts about past threats</strong></li><li><strong>Feud recalls Conti’s collapse in 2022, raising risk of escalating “cyber war” between criminal groups</strong></li></ul><p>Infamous cybercriminal gang Cl0p has seemingly been hacked by an even more infamous data leak collective, ShinyHunters. </p><p>The attack is still being pieced together, but it would seem we have true hacker beef on our hands - which just might escalate into a full-blown cyber war.</p><p>ShinyHunters has added Cl0p to their data leak site, giving the hacking group 72 hours to pay a <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransom</a> or see all their files leaked into the cybercriminal underbelly. The files allegedly stolen in the attack include source code, Grav CMS plugins, system logs, and other information, <a href="https://cybernews.com/news/shinyhunters-hacks-clop-ransomware/" target="_blank"><em>Cybernews</em></a> reports. We don’t know how much money ShinyHunters are asking to keep Cl0p’s files private.</p><h2 id="still-downloading">Still downloading</h2><p>"The data we stole includes source codes, gravCMS plugins, and other things. We are still downloading and reviewing them," ShinyHunters allegedly told <em>BleepingComputer</em>.</p><p>The group also said they stole everything in the server’s /var/log directory, including system activity records, authentication logs, and IP addresses associated with connections to the server. We doubt this could lead to the identification of any Cl0p members, and even if it could, it would mean very little since the members are likely Russian and thus mostly free to conduct their operations. </p><p>Doxxing might help defenders disrupt the group’s infrastructure, though. </p><p>Whether or not that will be needed, given ShinyHunters’ activity, remains to be seen. The attackers also said they stole the private keys for Cl0p’s Tor onion service:</p><p>"We have their onion keys. So if they kick us out it wouldn't matter at all because we control the private keys to host the same exact onion URL," the group said.</p><p>On top of it all, ShinyHunters defaced Cl0p’s website. Allegedly, the group found an unauthenticated file upload flaw in the Grav CMS Cl0p was using, gaining access to their target’s servers, website, and more. <em>Cybernews</em> confirmed the website had been defaced and now holds an ASCII image of ShinyHunters’ logo, and a link to their Tor site. It also displays a large message: </p><p>"THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p - Maybe don't try to threaten us next time.” Furthermore, it says “rooting your systems since '19 ;)".</p><p>The “maybe don’t try to threaten us next time” message seems to refer to a threat that a Cl0p member made earlier. Apparently, this person threatened violence against ShinyHunters, as well as to expose their identities to the public. The remarks were made during Cl0p’s 2025 Oracle E-Business Suite attacks. </p><p>"During the Oracle EBS campaign they ran and stole from me last year, someone from cl0p personally messaged me and said, and I quote (translated from Russian): I have more money than you and all of your people combined, I'll kill you soon," ShinyHunters told <em>BleepingComputer</em>.</p><h2 id="dog-eat-dog">Dog eat dog</h2><p>Cybercriminals often work together. They share resources, rent each other’s services, and often complement their campaigns. However, that doesn’t make them “friends” or “colleagues”, in any way. It is usually just a marriage of convenience that falls apart at the slightest sound of trouble. The last big “feud” we’ve seen was back in 2022, at the very start of the Russian invasion of Ukraine. Back then, a group called Conti publicly declared its “full support” for the Russian government and threatened to use its resources against anyone conducting cyberattacks on Russian infrastructure.</p><p>The announcement was a fiasco - many of Conti’s affiliates stopped working with the group, and others were openly attacking it. Soon after, a Ukrainian researcher and an alleged affiliate leaked more than 60,000 messages, exposing the group’s operations and internal organization. </p><p>All of this eventually led to Conti’s collapse later that year. However, its members did not disappear - they splintered into multiple groups such as Black Basta, Royal, and Quantum. Some of the crooks engaged in Conti are allegedly still active today.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ North Korean 'Contagious Interview' gang hits 30,000 businesses across the world with malware following fake interviews ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Joint report from Japan, US, Germany, and Australia says Contagious Interview stole $10 million in crypto</strong></li><li><strong>NK operatives used fake personas, companies, and “laptop farms” to infiltrate 30,000+ devices in 100 countries</strong></li><li><strong>Agencies urge vigilance: verify applicants’ details, check IPs, validate certifications, and watch for crypto‑based payments</strong></li></ul><p>North Korean threat actors behind the infamous “Contagious Interview” campaign have so far compromised more than 30,000 devices across 100 countries, and have robbed around 7,000 people of their hard-earned cryptocurrencies. </p><p>The theft has brought more than $10 million to the North Korean government, a new report jointly released by law enforcement agencies in Japan, the United States, Germany, and Australia has found.</p><h2 id="fake-everything">Fake everything</h2><p>Contagious Interview is a hacking campaign running for almost four years now. Sometimes it’s also called <a href="https://www.techradar.com/pro/security/north-korean-job-scammers-target-javascript-and-python-developers-with-fake-interview-tasks-spreading-malware">Operation DreamJob</a>. </p><p>The cybersecurity community in general attributes it to the government of North Korea, although more precise attribution is rather difficult. </p><p>Some researchers believe it is being done by the Lazarus Group, one of the largest and most influential state-sponsored actors around. </p><p>Others believe different groups are involved, labeled DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, PurpleBravo, or TAG-121.</p><p>Contagious Interview leverages the lack of skilled workers in the West to infiltrate organizations, steal sensitive data and ultimately, money. North Korean operatives would create entire fake personas on social media such as LinkedIn, and would apply to hundreds, if not thousands, of job ads across IT, healthcare, and other industries. </p><p>The personas are carefully crafted, using a mix of legitimate information stolen in data breaches (names, SSNs, addresses), and AI-generated images, video, and audio. If hired, the operatives would use their access to infect organizations with <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, steal login credentials and different access, and exfiltrate sensitive files and cryptos. </p><p>The operation works the other way around, as well. Crooks would create fake companies and fake job positions, and would then reach out to their targets to offer lucrative positions on exciting projects. As part of the hiring process, the candidates would be asked to download and work on code which, unknown to them, was malicious. The North Koreans would then pivot to their targets’ current employers, resulting in the same outcome.</p><h2 id="laptop-farms">Laptop farms</h2><p>One of the ways organizations in the West are trying to combat this issue is by being mindful of the IP address and the location from which their employees are logging on. To work around this challenge, the attackers have set up “laptop farms” - facilities located abroad (usually in countries that don’t have that strict limitations, but are still NK-friendly, such as China), hosting hundreds of laptops. They would then access their targets’ networks through these laptops, to make sure their actual location is never revealed.</p><p>The primary targets are individual web designers, engineers, and specialists working in cryptocurrency, blockchain, and Web3 technologies, it was said. Businesses should be wary when they receive numerous applications in a short time, for a position where there are usually very few applicants. </p><p>“If possible, verify that IP addresses generally match the applicant’s claimed residence,” the report states. “Carefully check all contact information. Calling an applicant’s phone number may reveal the number is out of service.”</p><p>The agencies also warned that trying to get hired is often a group effort: “Even if a single individual appears to be applying, multiple people may be collaborating behind the scenes, inflating the perceived skill set.” Therefore, businesses should verify certifications by checking registration numbers and, in case of any inconsistencies, should ask for detailed explanations.</p><p>Asking personal details about the applicant’s hometown, weather, or hobbies, is often a good way to spot a scammer. Finally, it was said that North Korean IT workers tend to favor payment in cryptocurrency, and they may request that remuneration be sent to an account in another person’s name.</p><p>Contagious Interview has been ongoing for roughly four years now, and during that time it evolved significantly. Security agencies warn that changes to the standard practice could happen at any time, and that the variations to the theme should be expected.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/north-korean-contagious-interview-gang-hits-30-000-businesses-across-the-world-with-malware-following-fake-interviews</link>
                                                                            <description>
                            <![CDATA[ North Koreans are stealing millions through fake job ads. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hDo78ZFAkHqg6oukLXkkod</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 21 Sep 2026 14:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[North Korean flag with a hooded hacker]]></media:description>                                                            <media:text><![CDATA[North Korean flag with a hooded hacker]]></media:text>
                                <media:title type="plain"><![CDATA[North Korean flag with a hooded hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Joint report from Japan, US, Germany, and Australia says Contagious Interview stole $10 million in crypto</strong></li><li><strong>NK operatives used fake personas, companies, and “laptop farms” to infiltrate 30,000+ devices in 100 countries</strong></li><li><strong>Agencies urge vigilance: verify applicants’ details, check IPs, validate certifications, and watch for crypto‑based payments</strong></li></ul><p>North Korean threat actors behind the infamous “Contagious Interview” campaign have so far compromised more than 30,000 devices across 100 countries, and have robbed around 7,000 people of their hard-earned cryptocurrencies. </p><p>The theft has brought more than $10 million to the North Korean government, a new report jointly released by law enforcement agencies in Japan, the United States, Germany, and Australia has found.</p><h2 id="fake-everything">Fake everything</h2><p>Contagious Interview is a hacking campaign running for almost four years now. Sometimes it’s also called <a href="https://www.techradar.com/pro/security/north-korean-job-scammers-target-javascript-and-python-developers-with-fake-interview-tasks-spreading-malware">Operation DreamJob</a>. </p><p>The cybersecurity community in general attributes it to the government of North Korea, although more precise attribution is rather difficult. </p><p>Some researchers believe it is being done by the Lazarus Group, one of the largest and most influential state-sponsored actors around. </p><p>Others believe different groups are involved, labeled DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, PurpleBravo, or TAG-121.</p><p>Contagious Interview leverages the lack of skilled workers in the West to infiltrate organizations, steal sensitive data and ultimately, money. North Korean operatives would create entire fake personas on social media such as LinkedIn, and would apply to hundreds, if not thousands, of job ads across IT, healthcare, and other industries. </p><p>The personas are carefully crafted, using a mix of legitimate information stolen in data breaches (names, SSNs, addresses), and AI-generated images, video, and audio. If hired, the operatives would use their access to infect organizations with <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, steal login credentials and different access, and exfiltrate sensitive files and cryptos. </p><p>The operation works the other way around, as well. Crooks would create fake companies and fake job positions, and would then reach out to their targets to offer lucrative positions on exciting projects. As part of the hiring process, the candidates would be asked to download and work on code which, unknown to them, was malicious. The North Koreans would then pivot to their targets’ current employers, resulting in the same outcome.</p><h2 id="laptop-farms">Laptop farms</h2><p>One of the ways organizations in the West are trying to combat this issue is by being mindful of the IP address and the location from which their employees are logging on. To work around this challenge, the attackers have set up “laptop farms” - facilities located abroad (usually in countries that don’t have that strict limitations, but are still NK-friendly, such as China), hosting hundreds of laptops. They would then access their targets’ networks through these laptops, to make sure their actual location is never revealed.</p><p>The primary targets are individual web designers, engineers, and specialists working in cryptocurrency, blockchain, and Web3 technologies, it was said. Businesses should be wary when they receive numerous applications in a short time, for a position where there are usually very few applicants. </p><p>“If possible, verify that IP addresses generally match the applicant’s claimed residence,” the report states. “Carefully check all contact information. Calling an applicant’s phone number may reveal the number is out of service.”</p><p>The agencies also warned that trying to get hired is often a group effort: “Even if a single individual appears to be applying, multiple people may be collaborating behind the scenes, inflating the perceived skill set.” Therefore, businesses should verify certifications by checking registration numbers and, in case of any inconsistencies, should ask for detailed explanations.</p><p>Asking personal details about the applicant’s hometown, weather, or hobbies, is often a good way to spot a scammer. Finally, it was said that North Korean IT workers tend to favor payment in cryptocurrency, and they may request that remuneration be sent to an account in another person’s name.</p><p>Contagious Interview has been ongoing for roughly four years now, and during that time it evolved significantly. Security agencies warn that changes to the standard practice could happen at any time, and that the variations to the theme should be expected.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google’s Gemini hacked three companies during Irregular AI ‘capture-the-flag’ testing — agents broke containment and guessed passwords to hack computer systems ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Google's Gemini AI broke out of a testing environment and hacked into three third-party companies</strong></li><li><strong>The agents guessed passwords and used a public repository of passwords to hack into computer systems</strong></li><li><strong>The incident occurred in May 2026, with AI testing lab Irregular stating that the incident was caused by the "same issue" that caused incidents by Anthropic and Meta</strong></li></ul><p>Google’s Gemini has joined the ranks of AI models that have been involved in testing-turned-breakout events, <a href="https://www.techradar.com/pro/security/why-are-so-many-ai-models-going-rogue-the-experts-weigh-in" target="_blank">alongside Meta, Anthropic, and OpenAI</a>.</p><p>During capture-the-flag testing by AI lab Irregular, Google’s model autonomously accessed three computer systems belonging to third-party companies by guessing passwords and accessing an online repository of publicly listed passwords.</p><p>Google said that the incident occurred in May 2026, potentially marking it as the earliest AI models to escape testing ahead of the other incidents that took place in early July.</p><h2 id="google-gemini-jumps-the-gun">Google Gemini jumps the gun</h2><p>“In a standard evaluation, the model found public information online and guessed credentials to access websites it thought were part of the test,” Heather Adkins, vice president of security engineering at Google, said in a statement. “In all three of these instances, the model stopped.”</p><p>Google also noted that a bug in the testing environment was responsible for allowing agents access to the internet. Contrary to incidents disclosed by other AI developers, Google’s agents ceased their intrusion once they had determined they had accessed company systems outside of the testing environment.</p><p>The testing was being conducted by Israeli AI lab Irregular. Irregular was also conducting the testing of Meta and Anthropic models during AI testing breakouts in July.</p><p>“This is the same issue that was already reported and does not represent a materially separate incident,” an Irregular spokesperson said in a statement (via <a href="https://www.cnbc.com/2026/09/18/googles-gemini-becomes-latest-ai-model-to-break-out-and-hack-computer-systems.html" target="_blank"><em>CNBC</em></a>). “All relevant labs were notified in late July, and affected entities were contacted as part of the investigation.”</p><p>Google said it was informed of the incident by Irregular in late July.</p><h2 id="debate-over-ai-safety-intensifies">Debate over AI safety intensifies</h2><p>The first disclosures of AI testing break outs - alongside several subsequent disclosures of more recent incidents - have coincided with <a href="https://www.techradar.com/pro/over-half-of-americans-are-concerned-about-ai-in-daily-life-with-tech-leaders-and-ai-gurus-desperately-trying-to-calm-the-number-one-fear" target="_blank">increasing opposition to AI</a> and the upcoming midterm elections in the United States, where <a href="https://www.techradar.com/pro/dr-frankenstein-is-telling-us-the-monster-is-escaping-us-lawmakers-desperately-want-to-set-up-ai-guardrails-before-midterm-elections" target="_blank">AI has become a make-or-break topic</a>.</p><p>The debates currently raging circles around who should control the pace of AI development. Some big tech leaders, such as Nvidia CEO Jensen Huang, have aligned their views with those of President Trump. Trump recently stated that AI development cannot be allowed to slow down because “<a href="https://www.techradar.com/ai-platforms-assistants/whoever-wins-ai-wins-trump-warns-traitors-and-leakers-to-beware-and-claims-the-conspiracy-against-ai-and-data-centers-will-only-benefit-china" target="_blank">whoever wins AI, wins!</a>” </p><p>Huang’s views follow a similar line. The Nvidia head has argued that AI companies should pace themselves, rather than being subject to oversight. At <a href="https://www.techradar.com/pro/were-going-through-a-new-industrial-revolution-nvidia-ceo-jensen-huang-and-anthropic-ceo-dario-amodei-share-differing-views-on-ai-at-dreamforce-2026" target="_blank">Dreamforce 2026</a>, he argued that AI companies should, “run as fast as you can...but if you feel at any given point in time the company’s out of control or the product’s not going to be safe, take a pause and make sure you get it right.”</p><p>Other AI heads, such as Anthropic’s Dario Amodei and OpenAI’s Sam Altman, are more skeptical. Following the resignation of an Anthropic researcher, <a href="https://www.techradar.com/pro/security/why-are-us-ai-giants-calling-for-pacing-the-frontier-and-why-is-china-calling-it-a-cold-war-tactic-we-ask-the-experts" target="_blank">Amodei published an essay arguing in favor of ‘pacing the frontier’</a> - where AI companies <a href="https://www.techradar.com/ai-platforms-assistants/the-big-ai-slowdown-battle-explained-5-things-you-need-to-know-about-trumps-ai-regulation-battle-with-openais-sam-altman-anthropics-dario-amodei-and-even-elon-musk" target="_blank">slow development to advance alignment</a> and regulation.</p><p>Numerous political action committees (PACs) have been <a href="https://www.techradar.com/pro/superpacs-are-funneling-millions-of-dollars-into-pro-ai-candidates-with-trump-saying-communities-that-reject-data-centers-will-end-up-backwards-and-poor" target="_blank">channeling millions of dollars of funding into pro-AI candidates</a>, with <a href="https://www.techradar.com/pro/nvidia-wants-to-set-up-an-employee-funded-political-action-committee-to-shape-us-policy-in-its-favor" target="_blank">Nvidia setting up its own PAC</a> to help shift US policy in the company’s favor.</p><p>Several previously pro-AI data center candidates <a href="https://www.techradar.com/pro/trump-warns-communities-opposed-to-data-centers-are-making-a-mistake-but-texas-gov-greg-abbott-data-centers-got-the-backlash-they-deserve" target="_blank">have shifted their tone in response to their constituents' views</a> which have become increasingly hostile to AI technology. <a href="https://www.techradar.com/pro/they-seem-to-have-more-money-than-god-ai-companies-face-major-reality-check-as-states-cut-billions-in-tax-exemptions-with-bernie-sanders-calling-for-regulation-so-tech-billionaires-no-longer-play-god-and-determine-the-future-of-humanity" target="_blank">Numerous states have also rolled-back tax exemptions for AI data centers</a> after seeing billion dollar revenue losses.</p><p>As prices rise and the war in Iran continues to push up fuel prices, <a href="https://www.techradar.com/pro/the-working-class-are-rallying-to-oppose-data-centers-at-5-times-the-rate-of-wealthy-neighborhoods-the-great-unifier-is-helping-workers-punch-up-and-its-super-effective" target="_blank">working class communities are banding together to oppose AI data centers</a> that have pushed up energy costs and bills with new grid connections and unprecedented electricity demands in regions with existing capacity constraints.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/googles-gemini-hacked-three-companies-during-irregular-ai-capture-the-flag-testing-agents-broke-containment-and-guessed-passwords-to-hack-computer-systems</link>
                                                                            <description>
                            <![CDATA[ Google says AI agents broke out of a testing environment and hacked three third-party companies. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">YUd8cypt8JZduUPHajovGT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/apMew975VRgc48QvTAYAsg-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 21 Sep 2026 10:07:24 +0000</pubDate>                                                                                                                                <updated>Mon, 21 Sep 2026 10:07:28 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Gemini]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/apMew975VRgc48QvTAYAsg-1920-80.jpg">
                                                            <media:credit><![CDATA[Google]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google Gemini]]></media:description>                                                            <media:text><![CDATA[Google Gemini]]></media:text>
                                <media:title type="plain"><![CDATA[Google Gemini]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/apMew975VRgc48QvTAYAsg-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Google's Gemini AI broke out of a testing environment and hacked into three third-party companies</strong></li><li><strong>The agents guessed passwords and used a public repository of passwords to hack into computer systems</strong></li><li><strong>The incident occurred in May 2026, with AI testing lab Irregular stating that the incident was caused by the "same issue" that caused incidents by Anthropic and Meta</strong></li></ul><p>Google’s Gemini has joined the ranks of AI models that have been involved in testing-turned-breakout events, <a href="https://www.techradar.com/pro/security/why-are-so-many-ai-models-going-rogue-the-experts-weigh-in" target="_blank">alongside Meta, Anthropic, and OpenAI</a>.</p><p>During capture-the-flag testing by AI lab Irregular, Google’s model autonomously accessed three computer systems belonging to third-party companies by guessing passwords and accessing an online repository of publicly listed passwords.</p><p>Google said that the incident occurred in May 2026, potentially marking it as the earliest AI models to escape testing ahead of the other incidents that took place in early July.</p><h2 id="google-gemini-jumps-the-gun">Google Gemini jumps the gun</h2><p>“In a standard evaluation, the model found public information online and guessed credentials to access websites it thought were part of the test,” Heather Adkins, vice president of security engineering at Google, said in a statement. “In all three of these instances, the model stopped.”</p><p>Google also noted that a bug in the testing environment was responsible for allowing agents access to the internet. Contrary to incidents disclosed by other AI developers, Google’s agents ceased their intrusion once they had determined they had accessed company systems outside of the testing environment.</p><p>The testing was being conducted by Israeli AI lab Irregular. Irregular was also conducting the testing of Meta and Anthropic models during AI testing breakouts in July.</p><p>“This is the same issue that was already reported and does not represent a materially separate incident,” an Irregular spokesperson said in a statement (via <a href="https://www.cnbc.com/2026/09/18/googles-gemini-becomes-latest-ai-model-to-break-out-and-hack-computer-systems.html" target="_blank"><em>CNBC</em></a>). “All relevant labs were notified in late July, and affected entities were contacted as part of the investigation.”</p><p>Google said it was informed of the incident by Irregular in late July.</p><h2 id="debate-over-ai-safety-intensifies">Debate over AI safety intensifies</h2><p>The first disclosures of AI testing break outs - alongside several subsequent disclosures of more recent incidents - have coincided with <a href="https://www.techradar.com/pro/over-half-of-americans-are-concerned-about-ai-in-daily-life-with-tech-leaders-and-ai-gurus-desperately-trying-to-calm-the-number-one-fear" target="_blank">increasing opposition to AI</a> and the upcoming midterm elections in the United States, where <a href="https://www.techradar.com/pro/dr-frankenstein-is-telling-us-the-monster-is-escaping-us-lawmakers-desperately-want-to-set-up-ai-guardrails-before-midterm-elections" target="_blank">AI has become a make-or-break topic</a>.</p><p>The debates currently raging circles around who should control the pace of AI development. Some big tech leaders, such as Nvidia CEO Jensen Huang, have aligned their views with those of President Trump. Trump recently stated that AI development cannot be allowed to slow down because “<a href="https://www.techradar.com/ai-platforms-assistants/whoever-wins-ai-wins-trump-warns-traitors-and-leakers-to-beware-and-claims-the-conspiracy-against-ai-and-data-centers-will-only-benefit-china" target="_blank">whoever wins AI, wins!</a>” </p><p>Huang’s views follow a similar line. The Nvidia head has argued that AI companies should pace themselves, rather than being subject to oversight. At <a href="https://www.techradar.com/pro/were-going-through-a-new-industrial-revolution-nvidia-ceo-jensen-huang-and-anthropic-ceo-dario-amodei-share-differing-views-on-ai-at-dreamforce-2026" target="_blank">Dreamforce 2026</a>, he argued that AI companies should, “run as fast as you can...but if you feel at any given point in time the company’s out of control or the product’s not going to be safe, take a pause and make sure you get it right.”</p><p>Other AI heads, such as Anthropic’s Dario Amodei and OpenAI’s Sam Altman, are more skeptical. Following the resignation of an Anthropic researcher, <a href="https://www.techradar.com/pro/security/why-are-us-ai-giants-calling-for-pacing-the-frontier-and-why-is-china-calling-it-a-cold-war-tactic-we-ask-the-experts" target="_blank">Amodei published an essay arguing in favor of ‘pacing the frontier’</a> - where AI companies <a href="https://www.techradar.com/ai-platforms-assistants/the-big-ai-slowdown-battle-explained-5-things-you-need-to-know-about-trumps-ai-regulation-battle-with-openais-sam-altman-anthropics-dario-amodei-and-even-elon-musk" target="_blank">slow development to advance alignment</a> and regulation.</p><p>Numerous political action committees (PACs) have been <a href="https://www.techradar.com/pro/superpacs-are-funneling-millions-of-dollars-into-pro-ai-candidates-with-trump-saying-communities-that-reject-data-centers-will-end-up-backwards-and-poor" target="_blank">channeling millions of dollars of funding into pro-AI candidates</a>, with <a href="https://www.techradar.com/pro/nvidia-wants-to-set-up-an-employee-funded-political-action-committee-to-shape-us-policy-in-its-favor" target="_blank">Nvidia setting up its own PAC</a> to help shift US policy in the company’s favor.</p><p>Several previously pro-AI data center candidates <a href="https://www.techradar.com/pro/trump-warns-communities-opposed-to-data-centers-are-making-a-mistake-but-texas-gov-greg-abbott-data-centers-got-the-backlash-they-deserve" target="_blank">have shifted their tone in response to their constituents' views</a> which have become increasingly hostile to AI technology. <a href="https://www.techradar.com/pro/they-seem-to-have-more-money-than-god-ai-companies-face-major-reality-check-as-states-cut-billions-in-tax-exemptions-with-bernie-sanders-calling-for-regulation-so-tech-billionaires-no-longer-play-god-and-determine-the-future-of-humanity" target="_blank">Numerous states have also rolled-back tax exemptions for AI data centers</a> after seeing billion dollar revenue losses.</p><p>As prices rise and the war in Iran continues to push up fuel prices, <a href="https://www.techradar.com/pro/the-working-class-are-rallying-to-oppose-data-centers-at-5-times-the-rate-of-wealthy-neighborhoods-the-great-unifier-is-helping-workers-punch-up-and-its-super-effective" target="_blank">working class communities are banding together to oppose AI data centers</a> that have pushed up energy costs and bills with new grid connections and unprecedented electricity demands in regions with existing capacity constraints.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New Android malware can deploy AI to automate device control — and it can even bring itself back from the dead ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Zimperium zLabs discovered </strong><em><strong>RedHat</strong></em><strong>, a Chinese‑origin Android banking trojan with AI assistant</strong></li><li><strong>AI interprets screen layouts in real‑time, enabling credential theft and bypassing app redesigns</strong></li><li><strong>Distributed via third‑party stores, social media, malvertising, and SMS; persistence blocks uninstall attempts</strong></li></ul><p>There is an Android <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> out there that comes with an AI assistant that tells it what to do. The assistant seems to be independent of the malware’s operator, allowing the tool to work without requiring the operators to be present in real-time.</p><p>The malware in question is called RedHat. It was discovered by security researchers Zimperium zLabs, who believe it is of Chinese origin. It is currently being distributed via third-party app stores, social media, malvertising, and SMS spam, and requires Android’s Accessibility permissions to work.</p><p>The malware itself is a typical banking trojan - it creates an invisible overlay every time the victim brings up a banking app, capturing login credentials and one-time passwords, and thus giving attackers direct control over people’s banking accounts. </p><h2 id="ai-powered-eyes">AI-powered eyes</h2><p>But what makes RedHat stand out from a sea of <a href="https://www.techradar.com/best/best-android-phones" target="_blank">Android</a> banking trojans is its AI-powered component. The model serves as a kind of remote “eyes and hands” for controlling the victim’s phone. </p><p>Usually, when criminals develop banking trojans, they need to code exact coordinates of the layout for it to work. They need to code where the password is entered, or where the login button is. If the banking app gets redesigned and changes its layout, the malware breaks. </p><p>With AI, that is no longer a problem. RedHat gets a picture of what’s on the screen, sends it to the AI assistant, which then instructs the malware on how to proceed. </p><p>"RatHat uses AI to intelligently navigate and control the device interface in real-time, making its operations more adaptable and harder for security software to detect than traditional, scripted automation," Zimperium explained.</p><p>The tool also has a few advanced persistence mechanisms, being capable of reinstalling deleted components, and intercepting the uninstall process to cancel it while displaying a fake error message to the victim. </p><p>So far, there is no word on who the targets are, or how many people might have been compromised. </p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/" target="_blank" rel="nofollow"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/new-android-malware-can-deploy-ai-to-automate-device-control-and-it-can-even-bring-itself-back-from-the-dead</link>
                                                                            <description>
                            <![CDATA[ AI can now serve as the eyes and the hands of a piece of malware and even reinstall components if they're removed. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">B82pTEZSUoxgsMiYdH5xDc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BiyAK4BXKKfecCWadFcHGo-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 18 Sep 2026 19:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BiyAK4BXKKfecCWadFcHGo-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / tomeqs]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Android reboot interface]]></media:description>                                                            <media:text><![CDATA[Android reboot interface]]></media:text>
                                <media:title type="plain"><![CDATA[Android reboot interface]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BiyAK4BXKKfecCWadFcHGo-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Zimperium zLabs discovered </strong><em><strong>RedHat</strong></em><strong>, a Chinese‑origin Android banking trojan with AI assistant</strong></li><li><strong>AI interprets screen layouts in real‑time, enabling credential theft and bypassing app redesigns</strong></li><li><strong>Distributed via third‑party stores, social media, malvertising, and SMS; persistence blocks uninstall attempts</strong></li></ul><p>There is an Android <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> out there that comes with an AI assistant that tells it what to do. The assistant seems to be independent of the malware’s operator, allowing the tool to work without requiring the operators to be present in real-time.</p><p>The malware in question is called RedHat. It was discovered by security researchers Zimperium zLabs, who believe it is of Chinese origin. It is currently being distributed via third-party app stores, social media, malvertising, and SMS spam, and requires Android’s Accessibility permissions to work.</p><p>The malware itself is a typical banking trojan - it creates an invisible overlay every time the victim brings up a banking app, capturing login credentials and one-time passwords, and thus giving attackers direct control over people’s banking accounts. </p><h2 id="ai-powered-eyes">AI-powered eyes</h2><p>But what makes RedHat stand out from a sea of <a href="https://www.techradar.com/best/best-android-phones" target="_blank">Android</a> banking trojans is its AI-powered component. The model serves as a kind of remote “eyes and hands” for controlling the victim’s phone. </p><p>Usually, when criminals develop banking trojans, they need to code exact coordinates of the layout for it to work. They need to code where the password is entered, or where the login button is. If the banking app gets redesigned and changes its layout, the malware breaks. </p><p>With AI, that is no longer a problem. RedHat gets a picture of what’s on the screen, sends it to the AI assistant, which then instructs the malware on how to proceed. </p><p>"RatHat uses AI to intelligently navigate and control the device interface in real-time, making its operations more adaptable and harder for security software to detect than traditional, scripted automation," Zimperium explained.</p><p>The tool also has a few advanced persistence mechanisms, being capable of reinstalling deleted components, and intercepting the uninstall process to cancel it while displaying a fake error message to the victim. </p><p>So far, there is no word on who the targets are, or how many people might have been compromised. </p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/" target="_blank" rel="nofollow"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ China's Salt Typhoon spotted probing Latin American government with newly developed SparroWocky backdoor ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>ESET reports Salt Typhoon shifted focus to Latin America, hitting Argentina, Peru, Venezuela, and others</strong></li><li><strong>Group deployed new </strong><em><strong>SparroWocky</strong></em><strong> backdoor with 30+ commands for profiling, exfiltration, and surveillance</strong></li><li><strong>Researchers link pivot to Trump’s renewed US push in the region, threatening China’s long‑term investments</strong></li></ul><p>Salt Typhoon has been reassigned to Latin America, and it’s apparently all due to Donald Trump’s renewed “interest” in the continent.</p><p>Cybersecurity researchers ESET have been tracking Salt Typhoon, a Chinese state-sponsored threat actor for years. This is the same group that was seen hacking telecommunication giants and government agencies across the western world since at least 2019. </p><p>According to the researchers, from mid-2025 and well into 2026, the group has been targeting a number of Latin American countries: Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. They were seen deploying brand new malware, a backdoor called SparroWocky, that features around 30 commands such as system profiling, file exfiltration, screenshot grabbing, and more. ESET says that around 90% of all Salt Typhoon’s recent activity was devoted to this specific region.</p><h2 id="a-rare-occurrence">A rare occurrence</h2><p>The discovery of China-built <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> in these countries comes as somewhat of a surprise. Latin America cannot be considered an open ally to the Chinese, but they are quite influential in the region, both economically, and diplomatically. ESET sees the development as a “rare occurrence”, and stresses that this is most likely a response to Trump’s initiatives in the region. </p><p>“Donald Trump’s second presidential term has brought about an aggressive reaffirmation of US interests in Latin America, which threatens various long-term investments that China has cultivated throughout the continent in the last decade, in domains such as energy, mining, and telecommunications,” ESET says. “We suspect that FamousSparrow’s (their name for Salt Typhoon) activities are intended to help China better monitor and anticipate the reaction of local governments to current US pressures.”</p><p>ESET says the backdoor is being delivered via a trident loader scheme that consists of a legitimate executable, a malicious DLL, and a file containing the encrypted malware. By side-loading the DLL, the crooks can deploy the malware without being spotted.</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/09/17/chinas-salt-typhoon-backdoors-latin-american-orgs-with-new-snooping-malware/5297286" target="_blank" rel="nofollow"><em>The Register</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/chinas-salt-typhoon-spotted-probing-latin-american-government-with-newly-developed-sparrowocky-backdoor</link>
                                                                            <description>
                            <![CDATA[ The group has been focused on Latin America for almost a year now. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ceMVaPU4MtNVCb9tt4MC7k</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MmBupUuqfKaoWhB7xEsZC7-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 18 Sep 2026 17:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MmBupUuqfKaoWhB7xEsZC7-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A conceptual image featuring Donald Trump and China President Xi Jinping on a screen, with undulating stocks and a dollar bill in the background.]]></media:description>                                                            <media:text><![CDATA[A conceptual image featuring Donald Trump and China President Xi Jinping on a screen, with undulating stocks and a dollar bill in the background.]]></media:text>
                                <media:title type="plain"><![CDATA[A conceptual image featuring Donald Trump and China President Xi Jinping on a screen, with undulating stocks and a dollar bill in the background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MmBupUuqfKaoWhB7xEsZC7-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>ESET reports Salt Typhoon shifted focus to Latin America, hitting Argentina, Peru, Venezuela, and others</strong></li><li><strong>Group deployed new </strong><em><strong>SparroWocky</strong></em><strong> backdoor with 30+ commands for profiling, exfiltration, and surveillance</strong></li><li><strong>Researchers link pivot to Trump’s renewed US push in the region, threatening China’s long‑term investments</strong></li></ul><p>Salt Typhoon has been reassigned to Latin America, and it’s apparently all due to Donald Trump’s renewed “interest” in the continent.</p><p>Cybersecurity researchers ESET have been tracking Salt Typhoon, a Chinese state-sponsored threat actor for years. This is the same group that was seen hacking telecommunication giants and government agencies across the western world since at least 2019. </p><p>According to the researchers, from mid-2025 and well into 2026, the group has been targeting a number of Latin American countries: Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. They were seen deploying brand new malware, a backdoor called SparroWocky, that features around 30 commands such as system profiling, file exfiltration, screenshot grabbing, and more. ESET says that around 90% of all Salt Typhoon’s recent activity was devoted to this specific region.</p><h2 id="a-rare-occurrence">A rare occurrence</h2><p>The discovery of China-built <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> in these countries comes as somewhat of a surprise. Latin America cannot be considered an open ally to the Chinese, but they are quite influential in the region, both economically, and diplomatically. ESET sees the development as a “rare occurrence”, and stresses that this is most likely a response to Trump’s initiatives in the region. </p><p>“Donald Trump’s second presidential term has brought about an aggressive reaffirmation of US interests in Latin America, which threatens various long-term investments that China has cultivated throughout the continent in the last decade, in domains such as energy, mining, and telecommunications,” ESET says. “We suspect that FamousSparrow’s (their name for Salt Typhoon) activities are intended to help China better monitor and anticipate the reaction of local governments to current US pressures.”</p><p>ESET says the backdoor is being delivered via a trident loader scheme that consists of a legitimate executable, a malicious DLL, and a file containing the encrypted malware. By side-loading the DLL, the crooks can deploy the malware without being spotted.</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/09/17/chinas-salt-typhoon-backdoors-latin-american-orgs-with-new-snooping-malware/5297286" target="_blank" rel="nofollow"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FBI confirms two Texas-bound oil tankers hit by hackers who disabled coms and put the engines into overdrive — and Iran is possibly to blame ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>FBI and US Coast Guard boarded tanker </strong><em><strong>VL Prosperity</strong></em><strong> after foreign cyber compromise indications</strong></li><li><strong>Iranian media claimed attackers sabotaged engine systems and communications; Kohaku vessel also affected</strong></li><li><strong>No group claimed responsibility; US agencies investigating “malicious cyber activity” on targeted ships</strong></li></ul><p>Last month, two tankers heading for the United States were hit by a cyberattack, forcing the FBI and Coast Guard to board at least one of the vessels and investigate. </p><p>The first vessel is called VL Prosperity, which was allegedly transporting 2.3 million barrels of oil. It is a Liberian crude oil tanker, travelling from Egypt’s Sidi Kerir Oil Terminal towards Galveston, Texas, where it was supposed to dock on August 24. On its route, lasting roughly 25 days, it passed through the Strait of Gibraltar.</p><p>Some three days before arriving, it requested assistance from law enforcement, prompting a “highly specialized team” of FBI and Coast Guard cyber experts to board. The ship is currently sitting in the Gulf of Mexico.</p><h2 id="iranians-indirectly-claiming-responsibility">Iranians (indirectly) claiming responsibility</h2><p>“On August 21, a highly specialized team – comprised of USCG Law Enforcement personnel, USCG Cyber Protection Team members, a vessel inspector, and FBI Cyber Action Team operators – embarked the vessel to conduct a comprehensive cyber security boarding and investigation,” a US Coast Guard spokesperson told <em>Cybernews</em>.</p><p>The spokesperson also said the team’s activity is “designed to ensure the integrity of the vessel’s operational and information technology systems." The Coast Guard apparently saw “indications that the vessel’s network were compromised by foreign cyber actors.” It later described the incident as “malicious cyber activity.”</p><p>The second vessel in question is called Kohaku, flying under the flag of the Marshall Islands. It was travelling towards Texas to load liquefied petroleum gas, as per <em>Wall Street Journal</em>, and has been sitting near Malta for the past couple of days. At press time (Friday morning), it was travelling through the East Mediterranean Sea.</p><p>So far, no threat actors have publicly claimed responsibility for these attacks. However, the Iranian Mehr News Agency allegedly hinted the attack was a “message from Iran’s “Resistance Front” to Washington and the broader Middle East.”</p><p>The same publication - also the first one to report on the incident and name VL Prosperity as one of the victims - said the attackers infiltrated engine-room systems, reduced the engine’s cooling flow, increased the engine speed, and disabled the ship’s fuel and engine-oil tank, all citing an unnamed crew member. Apparently, the ship’s communications were knocked offline for a day and a half, as well.</p><p><em>Via </em><a href="https://cybernews.com/news/iran-oil-tanker-cyberattack-fbi-texas/" target="_blank"><em>Cybernews</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/fbi-confirms-two-texas-bound-oil-tankers-hit-by-hackers-who-disabled-coms-and-put-the-engines-into-overdrive-and-iran-is-possibly-to-blame</link>
                                                                            <description>
                            <![CDATA[ The FBI had to board at least one of the vessels to investigate the incident. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9FSfRG6EywReqjfwPyPNbV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GJ8T4oA8G7TYJwTEhkwJAF-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 18 Sep 2026 16:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GJ8T4oA8G7TYJwTEhkwJAF-1920-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image Credit: Pixabay]]></media:description>                                                            <media:text><![CDATA[Representational image of a cybercriminal]]></media:text>
                                <media:title type="plain"><![CDATA[Representational image of a cybercriminal]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GJ8T4oA8G7TYJwTEhkwJAF-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>FBI and US Coast Guard boarded tanker </strong><em><strong>VL Prosperity</strong></em><strong> after foreign cyber compromise indications</strong></li><li><strong>Iranian media claimed attackers sabotaged engine systems and communications; Kohaku vessel also affected</strong></li><li><strong>No group claimed responsibility; US agencies investigating “malicious cyber activity” on targeted ships</strong></li></ul><p>Last month, two tankers heading for the United States were hit by a cyberattack, forcing the FBI and Coast Guard to board at least one of the vessels and investigate. </p><p>The first vessel is called VL Prosperity, which was allegedly transporting 2.3 million barrels of oil. It is a Liberian crude oil tanker, travelling from Egypt’s Sidi Kerir Oil Terminal towards Galveston, Texas, where it was supposed to dock on August 24. On its route, lasting roughly 25 days, it passed through the Strait of Gibraltar.</p><p>Some three days before arriving, it requested assistance from law enforcement, prompting a “highly specialized team” of FBI and Coast Guard cyber experts to board. The ship is currently sitting in the Gulf of Mexico.</p><h2 id="iranians-indirectly-claiming-responsibility">Iranians (indirectly) claiming responsibility</h2><p>“On August 21, a highly specialized team – comprised of USCG Law Enforcement personnel, USCG Cyber Protection Team members, a vessel inspector, and FBI Cyber Action Team operators – embarked the vessel to conduct a comprehensive cyber security boarding and investigation,” a US Coast Guard spokesperson told <em>Cybernews</em>.</p><p>The spokesperson also said the team’s activity is “designed to ensure the integrity of the vessel’s operational and information technology systems." The Coast Guard apparently saw “indications that the vessel’s network were compromised by foreign cyber actors.” It later described the incident as “malicious cyber activity.”</p><p>The second vessel in question is called Kohaku, flying under the flag of the Marshall Islands. It was travelling towards Texas to load liquefied petroleum gas, as per <em>Wall Street Journal</em>, and has been sitting near Malta for the past couple of days. At press time (Friday morning), it was travelling through the East Mediterranean Sea.</p><p>So far, no threat actors have publicly claimed responsibility for these attacks. However, the Iranian Mehr News Agency allegedly hinted the attack was a “message from Iran’s “Resistance Front” to Washington and the broader Middle East.”</p><p>The same publication - also the first one to report on the incident and name VL Prosperity as one of the victims - said the attackers infiltrated engine-room systems, reduced the engine’s cooling flow, increased the engine speed, and disabled the ship’s fuel and engine-oil tank, all citing an unnamed crew member. Apparently, the ship’s communications were knocked offline for a day and a half, as well.</p><p><em>Via </em><a href="https://cybernews.com/news/iran-oil-tanker-cyberattack-fbi-texas/" target="_blank"><em>Cybernews</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ CISA urges business to deploy decoys, lures, and honeypots to catch hackers in the act ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>CISA urged organizations to deploy honeypots, lures, and honeytokens as cyber decoys</strong></li><li><strong>Decoys complement Zero Trust by detecting LOTL activity and producing high‑fidelity alerts</strong></li><li><strong>Guidance outlines tripwires, breadcrumbs, MITRE ATT&CK/Engage steps for scalable implementation</strong></li></ul><p>The US Cybersecurity and Infrastructure Security Agency (CISA) is urging organizations to deploy honeypots and various lures to better detect cyber-intrusions and keep hackers busy with spoofed materials. To that end, it recently published a new guidance to help businesses of different sizes and cybersecurity maturity implement these “cyber decoy strategies”.</p><p>“Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land (LOTL) techniques to conduct discovery, move laterally, and access data,.” CISA said in a new security advisory.</p><p>“Cyber decoys are assets that appear to be legitimate systems, accounts, or data, but are designed to distract adversaries, detect their presence, or facilitate collection of cyber threat intelligence (CTI). As organizations adopt Zero Trust models, they should assume that a malicious threat actor may gain some level of access to their environment and plan accordingly.”</p><h2 id="tripwires-breadcrumbs-and-honeytokens">Tripwires, breadcrumbs, and honeytokens</h2><p>CISA’s advisory hints that Zero Trust is the preferred way to go about securing corporate infrastructure. Zero Trust treats no user, device, or network segment as inherently trustworthy and requires organizations to operate on the assumption that compromise is inevitable, it says. If you want to learn more, read our in-depth guide on <a href="https://www.techradar.com/features/what-is-zero-trust-network-access" target="_blank">what ZTNA is</a>. </p><p>However, it adds that cyber decoys are consistent with this paradigm and complement <a href="https://www.techradar.com/best/ztna-solutions" target="_blank">ZTNA</a> by supporting continuous monitoring and verification, creating high-fidelity alerts for suspicious activity, reducing alert fatigue, and helping defenders detect post-compromise activity such as adversary LOTL techniques. They are also incremental, cost-effective, and scalable, and can be introduced into the cybersecurity tech stack without major architectural changes.  </p><p>The guidance can be found on <a href="https://www.cisa.gov/sites/default/files/2026-09/using-cyber-decoys-to-strengthen-detection-and-response_508c.pdf" target="_blank" rel="nofollow">this link</a> (PDF). It introduces different decoy concepts such as tripwires, breadcrumbs, and honeytokens, and uses the MITRE Engage and MITRE ATT&CK frameworks to provide the steps needed to plan, implement, and refine these operations.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/cisa-urges-business-to-deploy-decoys-lures-and-honeypots-to-catch-hackers-in-the-act</link>
                                                                            <description>
                            <![CDATA[ ZTNA is great, but it can be even better with a little honeypot, CISA advises. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VPGMGYTwfjgaznVpMozzwZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MQg6bgb2ivV7eRFBy4HurZ-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 18 Sep 2026 13:50:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MQg6bgb2ivV7eRFBy4HurZ-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A 3d rendering of &quot;sweet returns&quot; or &quot;liquid gold,&quot; the combination of the honey (the lure) and the coins (the asset) is a classic visual metaphor for a honeypot scam.]]></media:description>                                                            <media:text><![CDATA[A 3d rendering of &quot;sweet returns&quot; or &quot;liquid gold,&quot; the combination of the honey (the lure) and the coins (the asset) is a classic visual metaphor for a honeypot scam.]]></media:text>
                                <media:title type="plain"><![CDATA[A 3d rendering of &quot;sweet returns&quot; or &quot;liquid gold,&quot; the combination of the honey (the lure) and the coins (the asset) is a classic visual metaphor for a honeypot scam.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MQg6bgb2ivV7eRFBy4HurZ-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>CISA urged organizations to deploy honeypots, lures, and honeytokens as cyber decoys</strong></li><li><strong>Decoys complement Zero Trust by detecting LOTL activity and producing high‑fidelity alerts</strong></li><li><strong>Guidance outlines tripwires, breadcrumbs, MITRE ATT&CK/Engage steps for scalable implementation</strong></li></ul><p>The US Cybersecurity and Infrastructure Security Agency (CISA) is urging organizations to deploy honeypots and various lures to better detect cyber-intrusions and keep hackers busy with spoofed materials. To that end, it recently published a new guidance to help businesses of different sizes and cybersecurity maturity implement these “cyber decoy strategies”.</p><p>“Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land (LOTL) techniques to conduct discovery, move laterally, and access data,.” CISA said in a new security advisory.</p><p>“Cyber decoys are assets that appear to be legitimate systems, accounts, or data, but are designed to distract adversaries, detect their presence, or facilitate collection of cyber threat intelligence (CTI). As organizations adopt Zero Trust models, they should assume that a malicious threat actor may gain some level of access to their environment and plan accordingly.”</p><h2 id="tripwires-breadcrumbs-and-honeytokens">Tripwires, breadcrumbs, and honeytokens</h2><p>CISA’s advisory hints that Zero Trust is the preferred way to go about securing corporate infrastructure. Zero Trust treats no user, device, or network segment as inherently trustworthy and requires organizations to operate on the assumption that compromise is inevitable, it says. If you want to learn more, read our in-depth guide on <a href="https://www.techradar.com/features/what-is-zero-trust-network-access" target="_blank">what ZTNA is</a>. </p><p>However, it adds that cyber decoys are consistent with this paradigm and complement <a href="https://www.techradar.com/best/ztna-solutions" target="_blank">ZTNA</a> by supporting continuous monitoring and verification, creating high-fidelity alerts for suspicious activity, reducing alert fatigue, and helping defenders detect post-compromise activity such as adversary LOTL techniques. They are also incremental, cost-effective, and scalable, and can be introduced into the cybersecurity tech stack without major architectural changes.  </p><p>The guidance can be found on <a href="https://www.cisa.gov/sites/default/files/2026-09/using-cyber-decoys-to-strengthen-detection-and-response_508c.pdf" target="_blank" rel="nofollow">this link</a> (PDF). It introduces different decoy concepts such as tripwires, breadcrumbs, and honeytokens, and uses the MITRE Engage and MITRE ATT&CK frameworks to provide the steps needed to plan, implement, and refine these operations.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Keep seeing strange meetings and events in your calendar? It might be because calendar-based phishing has jumped 33,000% since May — and they work even if the email is sent to spam ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Sublime researchers warn ICS phishing via calendar invites is surging ~33,000% since May 2026</strong></li><li><strong>Attacks bypass filters, trick users into installing RMM tools like ScreenConnect for full compromise</strong></li><li><strong>Defenses: scrutinize suspicious invites, verify senders, and treat ICS attachments with caution</strong></li></ul><p>ICS phishing - the type of phishing that abuses calendar files (.ics) is set to increase by around 33,000% between May and September 2026. This is according to a new report by cybersecurity researchers Sublime, who argue that this type of phishing has finally “hit the mainstream”.</p><p>The methodology is simple - the attacker uses a free service, such as Gmail, and sends a calendar invite to the target. Since both services are legitimate and free, the attacks bypass most email security filters and can be done at scale with close to zero cost.</p><p>Furthermore, the victim is exposed to the attack twice: once in the inbox, and once in their calendar. Inside the calendar invite is usually a link to download a maliciously configured <a href="https://www.techradar.com/news/best-remote-desktop-software" target="_blank">remote management and monitoring</a> (RMM) solution such as ScreenConnect. The attackers can use the tool to take over the compromised endpoint, deploying stage-two malware such as infostealers or ransomware, and grabbing passwords, documents, and other valuable secrets.</p><h2 id="spiking-in-popularity">Spiking in popularity</h2><p>ICS phishing started increasing in popularity roughly a year ago, but has been really picking up speed lately. Between May and June it increased 282%, and between June and July - 338%. </p><p>Between July and August it rose 1,216%, and in just the first half of September it rose 1,426% over the full month of August. Projections for the entire month of September, over August, are 2,852%, Sublime says. </p><p>“The jumps in August and September appear to be indicators that this attack type has finally hit the mainstream,” the researchers explained. “To really drive that point home, the increase from May to September is projected to be ~33,000%.”</p><p>Defending against these attacks is best done with a little common sense, the researchers conclude. Users should be mindful of the telltale signs, such as suspicious CTAs, suspicious senders, and the usual financial urgency.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/keep-seeing-strange-meetings-and-events-in-your-calendar-it-might-be-because-calendar-based-phishing-has-jumped-33-000-percent-since-may-and-they-work-even-if-the-email-is-sent-to-spam</link>
                                                                            <description>
                            <![CDATA[ ICS phishing has finally "hit the mainstream" as it keeps rising in popularity month over month. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">p525E9yB3DSCgoAxXuZG24</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rsstAB5QjUqoXwXYPEgT7d-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 18 Sep 2026 11:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rsstAB5QjUqoXwXYPEgT7d-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing]]></media:description>                                                            <media:text><![CDATA[Phishing]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rsstAB5QjUqoXwXYPEgT7d-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Sublime researchers warn ICS phishing via calendar invites is surging ~33,000% since May 2026</strong></li><li><strong>Attacks bypass filters, trick users into installing RMM tools like ScreenConnect for full compromise</strong></li><li><strong>Defenses: scrutinize suspicious invites, verify senders, and treat ICS attachments with caution</strong></li></ul><p>ICS phishing - the type of phishing that abuses calendar files (.ics) is set to increase by around 33,000% between May and September 2026. This is according to a new report by cybersecurity researchers Sublime, who argue that this type of phishing has finally “hit the mainstream”.</p><p>The methodology is simple - the attacker uses a free service, such as Gmail, and sends a calendar invite to the target. Since both services are legitimate and free, the attacks bypass most email security filters and can be done at scale with close to zero cost.</p><p>Furthermore, the victim is exposed to the attack twice: once in the inbox, and once in their calendar. Inside the calendar invite is usually a link to download a maliciously configured <a href="https://www.techradar.com/news/best-remote-desktop-software" target="_blank">remote management and monitoring</a> (RMM) solution such as ScreenConnect. The attackers can use the tool to take over the compromised endpoint, deploying stage-two malware such as infostealers or ransomware, and grabbing passwords, documents, and other valuable secrets.</p><h2 id="spiking-in-popularity">Spiking in popularity</h2><p>ICS phishing started increasing in popularity roughly a year ago, but has been really picking up speed lately. Between May and June it increased 282%, and between June and July - 338%. </p><p>Between July and August it rose 1,216%, and in just the first half of September it rose 1,426% over the full month of August. Projections for the entire month of September, over August, are 2,852%, Sublime says. </p><p>“The jumps in August and September appear to be indicators that this attack type has finally hit the mainstream,” the researchers explained. “To really drive that point home, the increase from May to September is projected to be ~33,000%.”</p><p>Defending against these attacks is best done with a little common sense, the researchers conclude. Users should be mindful of the telltale signs, such as suspicious CTAs, suspicious senders, and the usual financial urgency.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ White hat hackers just breached OpenAI using Anthropic's Claude in less than 72 hours — and it is a case study in just how fast AI is advancing ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Security researchers used Claude Opus 5 to hijack an OpenAI employee's ChatGPT account</strong></li><li><strong>Exploit abused an image processing flaw on OpenAI community forums to gain full repo access</strong></li><li><strong>The entire timeline from vulnerability discovery to repo access took less than 72 hours</strong></li></ul><p>While taking part in an OpenAI bug bounty program, a group of <a href="https://www.hacktron.ai/blog/hacking-openai" target="_blank" rel="nofollow">Hacktron</a> security researchers managed to compromise an internal OpenAI ChatGPT account and access internal company code on Github.</p><p>According to the <a href="https://www.wsj.com/tech/ai/hackers-used-anthropics-claude-to-break-into-openai-b40ba883?st=Jfx6Z1" target="_blank" rel="nofollow"><em>Wall Street Journal</em></a>, who first reported the incident, the researchers used a “special version” of Anthropic’s Claude made available to “qualified cybersecurity practitioners” to pull off the attack.</p><p>The researchers initially attempted to use Claude Opus 4.8 to create a breach, but faced multiple setbacks as the model “struggled across several sessions to produce a working exploit.” But the release of Opus 5 changed everything.</p><h2 id="openai-breach-part-of-wider-libheif-exploit">OpenAI breach part of wider libheif exploit</h2><p>The breach started with a libheif exploit that abuses a flaw in the .heic/.heif/.avif image file format decoder and encoder. While this exploit allowed Hacktron to breach OpenAI, libheif is also used across other platforms and software including Slack, Meta, GitHub Enterprise, Ruby on Rails, and more.</p><p>To start, the researchers first noted that the OpenAI community forum relies on the Discourse platform, which in turn relies on FastImage for image checks. But FastImage does not support .heif image files, and these are passed on to ImageMagick for conversion instead.</p><p>Developing a working code-execution exploit that abused this relation between ImageMagick and libheif with Opus 4.8 “wasn’t fruitful”, the researchers said, but on the same day Anthropic released Claude Opus 5.</p><p>With Opus 5, the researchers managed to create a working local remote code execution (RCE) using the same premise by setting an AI agent in a loop to exploit a local Discourse Cloud instance.</p><p>The successful Discourse exploit was then used against the OpenAI community forums, where the researchers hijacked an OpenAI employee’s ChatGPT account. The employee had connected their ChatGPT Codex with the company’s Github, allowing the researchers full repo access.</p><h2 id="exploit-needed-just-a-few-hours-of-human-interaction">Exploit needed just a few hours of human interaction</h2><p>Where the researchers spent hours struggling to create a working exploit with Opus 4.8, the release of Opus 5 showed that “every new model is getting increasingly capable." It took the agent running on Opus 5 just a few hours to develop a working exploit.</p><p>The full timeline from initial discovery of the exploit to OpenAI repo access took just 72 hours, researchers noted.</p><p>The researchers also said that the entire OpenAI and Discourse hack “took a few days for an agent, and just a few hours of human time” in order to be successful. Furthermore, their research into the libheif exploit against organizations such as Slack, Zoom, Meta “took two-months, cost less than $3,000 in tokens in total, and was conducted by three researchers.”</p><p>“The AI started almost blind and adapted the exploit for each company within one or two days,” the researchers said. “We are not aware of any company that detected the activity except Shopify, even after thousands of images were sent and their image processors repeatedly crashed.”</p><p>In return for exposing the vulnerabilities, Hacktron was awarded a $6,500 bounty from OpenAI, and the libheif vulnerability has been patched.</p><h2 id="ai-agents-are-the-future-for-better-or-for-worse">AI agents are the future, for better or for worse</h2><div><blockquote><p>There's a conversation we're not having loudly enough: do you actually want your security platform to have been built by AI, with no human track record behind it?</p><p>Spencer Starkey, SonicWall </p></blockquote></div><p>Hacktron's exploit demonstration shows how prevalent AI agents are becoming in cybersecurity. Where they have been lauded by AI companies to provide productivity bonuses and efficiency increases to workers, the same can be said for attackers.</p><p>The fact that it took just 72 hours from exploit discovery to full repo access highlights the dangers. By setting an AI agent to run on a continuous loop until it creates a workable exploit dramatically shifts the exploit timeline from weeks or months in the case of non-AI assisted attacks to mere hours for attackers aided by agents.</p><p>This is a similar circumstance to <a href="https://www.techradar.com/pro/security/openai-reveals-more-on-hugging-face-ai-hack-incident-and-its-pretty-disturbing-stuff-ai-agents-organized-into-a-swarm-considered-the-risks-of-attack-and-did-whatever-it-took-to-achieve-its-goal" target="_blank">OpenAI's own accidental breach of Hugging Face during testing of AI agents</a>. The agents were essentially told to complete a test scenario by any means necessary, which the agents interpreted as permission to go beyond their alignment and hack into a third-party environment that they thought held the key to solving their task.</p><p>"AI has been changing the threat landscape for a while now, and the defence landscape with it," Spencer Starkey, Executive VP EMEA at SonicWall said. "But there's a conversation we're not having loudly enough: do you actually want your security platform to have been built by AI, with no human track record behind it?"</p><p>"It looks compelling. You have low cost, high margins, slick interface. But what happens when something goes wrong at 02:00 in the morning and you need someone who knows the product, knows your environment, and has seen that problem before? An AI-built platform with zero employees can't give you that.</p><p>"Why go with an established vendor when a newer option does 90% of the same things for half the price? It's a fair question. But the 10% you're trading away is usually accountability, resilience, and institutional knowledge. Exactly what matters most when you're under attack.</p><p>"It looks like due diligence is eroding, and that worries me. Shiny and affordable is a powerful combination…for magpies. But in cyber security, the cost of a bad supplier decision doesn't show up until the moment you can least afford it, so don’t be a magpie," Starkey concluded.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/white-hat-hackers-just-breached-openai-using-anthropics-claude-in-less-than-72-hours-and-it-is-a-case-study-in-just-how-fast-ai-is-advancing</link>
                                                                            <description>
                            <![CDATA[ The researchers struggled to abuse the exploit with an AI agent on Opus 4.8, but the release of Opus 5 changed everything. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xNmtR2LnnNwRPW3GxC27U8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SSrgDUXsJwUVxtvheg4YCM-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 18 Sep 2026 10:49:48 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Claude]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SSrgDUXsJwUVxtvheg4YCM-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/Daniel Chetroni]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A close up of ChatGPT on a phone, with the OpenAI logo in the background of the photo]]></media:description>                                                            <media:text><![CDATA[A close up of ChatGPT on a phone, with the OpenAI logo in the background of the photo]]></media:text>
                                <media:title type="plain"><![CDATA[A close up of ChatGPT on a phone, with the OpenAI logo in the background of the photo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SSrgDUXsJwUVxtvheg4YCM-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Security researchers used Claude Opus 5 to hijack an OpenAI employee's ChatGPT account</strong></li><li><strong>Exploit abused an image processing flaw on OpenAI community forums to gain full repo access</strong></li><li><strong>The entire timeline from vulnerability discovery to repo access took less than 72 hours</strong></li></ul><p>While taking part in an OpenAI bug bounty program, a group of <a href="https://www.hacktron.ai/blog/hacking-openai" target="_blank" rel="nofollow">Hacktron</a> security researchers managed to compromise an internal OpenAI ChatGPT account and access internal company code on Github.</p><p>According to the <a href="https://www.wsj.com/tech/ai/hackers-used-anthropics-claude-to-break-into-openai-b40ba883?st=Jfx6Z1" target="_blank" rel="nofollow"><em>Wall Street Journal</em></a>, who first reported the incident, the researchers used a “special version” of Anthropic’s Claude made available to “qualified cybersecurity practitioners” to pull off the attack.</p><p>The researchers initially attempted to use Claude Opus 4.8 to create a breach, but faced multiple setbacks as the model “struggled across several sessions to produce a working exploit.” But the release of Opus 5 changed everything.</p><h2 id="openai-breach-part-of-wider-libheif-exploit">OpenAI breach part of wider libheif exploit</h2><p>The breach started with a libheif exploit that abuses a flaw in the .heic/.heif/.avif image file format decoder and encoder. While this exploit allowed Hacktron to breach OpenAI, libheif is also used across other platforms and software including Slack, Meta, GitHub Enterprise, Ruby on Rails, and more.</p><p>To start, the researchers first noted that the OpenAI community forum relies on the Discourse platform, which in turn relies on FastImage for image checks. But FastImage does not support .heif image files, and these are passed on to ImageMagick for conversion instead.</p><p>Developing a working code-execution exploit that abused this relation between ImageMagick and libheif with Opus 4.8 “wasn’t fruitful”, the researchers said, but on the same day Anthropic released Claude Opus 5.</p><p>With Opus 5, the researchers managed to create a working local remote code execution (RCE) using the same premise by setting an AI agent in a loop to exploit a local Discourse Cloud instance.</p><p>The successful Discourse exploit was then used against the OpenAI community forums, where the researchers hijacked an OpenAI employee’s ChatGPT account. The employee had connected their ChatGPT Codex with the company’s Github, allowing the researchers full repo access.</p><h2 id="exploit-needed-just-a-few-hours-of-human-interaction">Exploit needed just a few hours of human interaction</h2><p>Where the researchers spent hours struggling to create a working exploit with Opus 4.8, the release of Opus 5 showed that “every new model is getting increasingly capable." It took the agent running on Opus 5 just a few hours to develop a working exploit.</p><p>The full timeline from initial discovery of the exploit to OpenAI repo access took just 72 hours, researchers noted.</p><p>The researchers also said that the entire OpenAI and Discourse hack “took a few days for an agent, and just a few hours of human time” in order to be successful. Furthermore, their research into the libheif exploit against organizations such as Slack, Zoom, Meta “took two-months, cost less than $3,000 in tokens in total, and was conducted by three researchers.”</p><p>“The AI started almost blind and adapted the exploit for each company within one or two days,” the researchers said. “We are not aware of any company that detected the activity except Shopify, even after thousands of images were sent and their image processors repeatedly crashed.”</p><p>In return for exposing the vulnerabilities, Hacktron was awarded a $6,500 bounty from OpenAI, and the libheif vulnerability has been patched.</p><h2 id="ai-agents-are-the-future-for-better-or-for-worse">AI agents are the future, for better or for worse</h2><div><blockquote><p>There's a conversation we're not having loudly enough: do you actually want your security platform to have been built by AI, with no human track record behind it?</p><p>Spencer Starkey, SonicWall </p></blockquote></div><p>Hacktron's exploit demonstration shows how prevalent AI agents are becoming in cybersecurity. Where they have been lauded by AI companies to provide productivity bonuses and efficiency increases to workers, the same can be said for attackers.</p><p>The fact that it took just 72 hours from exploit discovery to full repo access highlights the dangers. By setting an AI agent to run on a continuous loop until it creates a workable exploit dramatically shifts the exploit timeline from weeks or months in the case of non-AI assisted attacks to mere hours for attackers aided by agents.</p><p>This is a similar circumstance to <a href="https://www.techradar.com/pro/security/openai-reveals-more-on-hugging-face-ai-hack-incident-and-its-pretty-disturbing-stuff-ai-agents-organized-into-a-swarm-considered-the-risks-of-attack-and-did-whatever-it-took-to-achieve-its-goal" target="_blank">OpenAI's own accidental breach of Hugging Face during testing of AI agents</a>. The agents were essentially told to complete a test scenario by any means necessary, which the agents interpreted as permission to go beyond their alignment and hack into a third-party environment that they thought held the key to solving their task.</p><p>"AI has been changing the threat landscape for a while now, and the defence landscape with it," Spencer Starkey, Executive VP EMEA at SonicWall said. "But there's a conversation we're not having loudly enough: do you actually want your security platform to have been built by AI, with no human track record behind it?"</p><p>"It looks compelling. You have low cost, high margins, slick interface. But what happens when something goes wrong at 02:00 in the morning and you need someone who knows the product, knows your environment, and has seen that problem before? An AI-built platform with zero employees can't give you that.</p><p>"Why go with an established vendor when a newer option does 90% of the same things for half the price? It's a fair question. But the 10% you're trading away is usually accountability, resilience, and institutional knowledge. Exactly what matters most when you're under attack.</p><p>"It looks like due diligence is eroding, and that worries me. Shiny and affordable is a powerful combination…for magpies. But in cyber security, the cost of a bad supplier decision doesn't show up until the moment you can least afford it, so don’t be a magpie," Starkey concluded.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NightmareStresser group responsible for thousands of DDOS attacks has domains seized in major operation ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>US law enforcement seized Nightmare Stresser domains, a long‑running DDoS‑for‑hire platform</strong></li><li><strong>Service enabled hundreds of thousands of attacks since 2022; FBI banner now replaces sites</strong></li><li><strong>Part of Operation PowerOFF, which has seized 100+ domains and charged 12 people so far</strong></li></ul><p>US law enforcement agencies disrupted yet another Distributed Denial of Service for hire (DDoS-for-hire) platform. In a press release published earlier this week on the District of Alaska’s Attorney General’s Office website, it was said that two internet domains associated with the Nightmare Stresser service were seized.</p><p>Describing it as “one of the world’s longest running Distributed Denial of Service for hire services,” the DoJ says Nightmare Stresser was used in “hundreds of thousands of actual or attempted DDoS attacks targeting victims worldwide since 2022”. </p><p>Services such as this one are called “booters” or “stressers”, and are often advertised as legitimate, allowing users to stress-test their websites against possible DDoS attacks.</p><h2 id="no-arrests">No arrests</h2><p>However, researchers have warned on multiple occasions that this is merely a cover for what’s essentially illegal activity. These platforms rent their services to anyone, including cybercriminals, and have been used to disrupt and take businesses, public organizations, and individuals offline, causing reputational and financial harm.</p><p>Nightmare Stresser’s two domains were seized - nightmare-stresser[.]com and nightmarestresser[.]org. Visiting these sites now shows the usual FBI defacement banner saying, “This website has been seized as part of a coordinated law enforcement action taken against illegal DDoS-for-hire services.”</p><p>To run <a href="https://www.techradar.com/pro/security/the-biggest-ddos-attack-ever-has-been-detected-but-fortunately-you-probably-barely-noticed-it" target="_blank">DDoS attacks</a>, threat actors need infrastructure - hundreds of thousands of internet-connected devices infected with malware that forces them to direct their traffic towards a single point. The DoJ’s announcement says nothing about the infrastructure being dismantled, or the malware used to create Nightmare Stresser being discovered or sinkholed. It also does not mention any arrests being made, so it is safe to assume Nightmare Stresser will be back to its usual shenanigans sooner, rather than later. </p><p>Still, the press release says that the takedown is part of Operation PowerOFF, an ongoing campaign aimed at dismantling DDoS-for-hire infrastructure worldwide, as well as “holding accountable the administrators and users of these illegal services.”</p><p>So far, more than 100 domains were seized as part of the effort, and 12 people were charged. </p><p><em>Via </em><a href="https://thehackernews.com/2026/09/us-seizes-nightmarestresser-domains.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/nightmarestresser-group-responsible-for-thousands-of-ddos-attacks-has-domains-seized-in-major-operation</link>
                                                                            <description>
                            <![CDATA[ Two domains seized by the DoJ but the infrastructure remains intact. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SW7ep4qFf9kXCPLTZyzGHm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sbNPJUhCyuLprR43BrwCoK-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 17 Sep 2026 18:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sbNPJUhCyuLprR43BrwCoK-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[DDoS inscribed on a digital background made up of numbers]]></media:description>                                                            <media:text><![CDATA[DDoS inscribed on a digital background made up of numbers]]></media:text>
                                <media:title type="plain"><![CDATA[DDoS inscribed on a digital background made up of numbers]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sbNPJUhCyuLprR43BrwCoK-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>US law enforcement seized Nightmare Stresser domains, a long‑running DDoS‑for‑hire platform</strong></li><li><strong>Service enabled hundreds of thousands of attacks since 2022; FBI banner now replaces sites</strong></li><li><strong>Part of Operation PowerOFF, which has seized 100+ domains and charged 12 people so far</strong></li></ul><p>US law enforcement agencies disrupted yet another Distributed Denial of Service for hire (DDoS-for-hire) platform. In a press release published earlier this week on the District of Alaska’s Attorney General’s Office website, it was said that two internet domains associated with the Nightmare Stresser service were seized.</p><p>Describing it as “one of the world’s longest running Distributed Denial of Service for hire services,” the DoJ says Nightmare Stresser was used in “hundreds of thousands of actual or attempted DDoS attacks targeting victims worldwide since 2022”. </p><p>Services such as this one are called “booters” or “stressers”, and are often advertised as legitimate, allowing users to stress-test their websites against possible DDoS attacks.</p><h2 id="no-arrests">No arrests</h2><p>However, researchers have warned on multiple occasions that this is merely a cover for what’s essentially illegal activity. These platforms rent their services to anyone, including cybercriminals, and have been used to disrupt and take businesses, public organizations, and individuals offline, causing reputational and financial harm.</p><p>Nightmare Stresser’s two domains were seized - nightmare-stresser[.]com and nightmarestresser[.]org. Visiting these sites now shows the usual FBI defacement banner saying, “This website has been seized as part of a coordinated law enforcement action taken against illegal DDoS-for-hire services.”</p><p>To run <a href="https://www.techradar.com/pro/security/the-biggest-ddos-attack-ever-has-been-detected-but-fortunately-you-probably-barely-noticed-it" target="_blank">DDoS attacks</a>, threat actors need infrastructure - hundreds of thousands of internet-connected devices infected with malware that forces them to direct their traffic towards a single point. The DoJ’s announcement says nothing about the infrastructure being dismantled, or the malware used to create Nightmare Stresser being discovered or sinkholed. It also does not mention any arrests being made, so it is safe to assume Nightmare Stresser will be back to its usual shenanigans sooner, rather than later. </p><p>Still, the press release says that the takedown is part of Operation PowerOFF, an ongoing campaign aimed at dismantling DDoS-for-hire infrastructure worldwide, as well as “holding accountable the administrators and users of these illegal services.”</p><p>So far, more than 100 domains were seized as part of the effort, and 12 people were charged. </p><p><em>Via </em><a href="https://thehackernews.com/2026/09/us-seizes-nightmarestresser-domains.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Gyazo breach exposes 23.62 million user records and 490 million image records — PII and metadata exposed in huge attack ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Helpfeel confirmed a Sept 11 breach compromising 23.62M records tied to Gyazo users</strong></li><li><strong>Stolen data includes PII, login/session IDs, Google SSO tokens, and 490M image metadata records</strong></li><li><strong>Payment info safe, but private images may have been exposed; viewing disabled pending investigation</strong></li></ul><p>A Japanese customer-support and knowledge-base company suffered a cyberattack recently in which it lost millions of user records, including personally identifiable information (PII) and, possibly, customer photographs.</p><p>The company in question is called Helpfeel. It is an established organization with more than 200 employees, operating as a combination of a modern help center, intelligent search, and an AI support agent. It runs an image-sharing service called Gyazo. According to a breach notification published earlier this week, the breach happened on September 11, when an unidentified threat actor abused a vulnerability to upload <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, gain access to the service’s servers, and run arbitrary commands on them.</p><p>A subsequent investigation determined that the attacker compromised 23.62 million records. Multiple records are tied to the same user, and many of the records were generated by customers without user accounts, so the actual number of affected individuals is not yet determined (but it’s definitely less than 23.6 million). </p><h2 id="image-metadata-exposed-too">Image metadata exposed, too</h2><p>The compromised records fall into these categories: names, emails, password hashes, user IDs, device IDs, login session IDs, X integration tokens, email addresses associated with <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">Google SSO</a>, profile information, language preferences, registration date and time, login date and time, subscription plan, billing status (without credit card numbers), and usage statistics. </p><p>“We have confirmed that no payment information, including credit card numbers, was disclosed without authorization,” Helpfeel confirmed.</p><p>PII aside, the attackers also accessed image metadata. Roughly 490 million records associated with images registered in or before January 2019 were compromised, including image IDs, source IP address used for the upload, user-agents, EXIF location data, OCR text extracted from the images, image titles, source URLs, and hashed passphrases for private images.</p><p>Since some of this metadata is used to generate image URLs, Helpfeel does not rule out the possibility that the attackers viewed actual images, as well. “We have temporarily disabled viewing of some images to prevent further harm,” it said. “As we cannot rule out the possibility that some private images may have been viewed by the third party, we are continuing our detailed investigation.”</p><p><em>Via </em><a href="https://thehackernews.com/2026/09/gyazo-breach-exposes-2362-million-user.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/gyazo-breach-exposes-23-62-million-user-records-and-490-million-image-records-pii-and-metadata-exposed-in-huge-attack</link>
                                                                            <description>
                            <![CDATA[ PII, image metadata, and possibly personal images, exposed in a large attack on Helpfeel's image-sharing service. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Uodvy6AViSbpZLBSmj5QJ8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dN5toW9ygER7CeKYqEVwba-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 17 Sep 2026 17:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dN5toW9ygER7CeKYqEVwba-1920-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image Credit: Pixabay]]></media:description>                                                            <media:text><![CDATA[Image depicting a hand on a scanner]]></media:text>
                                <media:title type="plain"><![CDATA[Image depicting a hand on a scanner]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dN5toW9ygER7CeKYqEVwba-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Helpfeel confirmed a Sept 11 breach compromising 23.62M records tied to Gyazo users</strong></li><li><strong>Stolen data includes PII, login/session IDs, Google SSO tokens, and 490M image metadata records</strong></li><li><strong>Payment info safe, but private images may have been exposed; viewing disabled pending investigation</strong></li></ul><p>A Japanese customer-support and knowledge-base company suffered a cyberattack recently in which it lost millions of user records, including personally identifiable information (PII) and, possibly, customer photographs.</p><p>The company in question is called Helpfeel. It is an established organization with more than 200 employees, operating as a combination of a modern help center, intelligent search, and an AI support agent. It runs an image-sharing service called Gyazo. According to a breach notification published earlier this week, the breach happened on September 11, when an unidentified threat actor abused a vulnerability to upload <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, gain access to the service’s servers, and run arbitrary commands on them.</p><p>A subsequent investigation determined that the attacker compromised 23.62 million records. Multiple records are tied to the same user, and many of the records were generated by customers without user accounts, so the actual number of affected individuals is not yet determined (but it’s definitely less than 23.6 million). </p><h2 id="image-metadata-exposed-too">Image metadata exposed, too</h2><p>The compromised records fall into these categories: names, emails, password hashes, user IDs, device IDs, login session IDs, X integration tokens, email addresses associated with <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">Google SSO</a>, profile information, language preferences, registration date and time, login date and time, subscription plan, billing status (without credit card numbers), and usage statistics. </p><p>“We have confirmed that no payment information, including credit card numbers, was disclosed without authorization,” Helpfeel confirmed.</p><p>PII aside, the attackers also accessed image metadata. Roughly 490 million records associated with images registered in or before January 2019 were compromised, including image IDs, source IP address used for the upload, user-agents, EXIF location data, OCR text extracted from the images, image titles, source URLs, and hashed passphrases for private images.</p><p>Since some of this metadata is used to generate image URLs, Helpfeel does not rule out the possibility that the attackers viewed actual images, as well. “We have temporarily disabled viewing of some images to prevent further harm,” it said. “As we cannot rule out the possibility that some private images may have been viewed by the third party, we are continuing our detailed investigation.”</p><p><em>Via </em><a href="https://thehackernews.com/2026/09/gyazo-breach-exposes-2362-million-user.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cisco hit by max severity zero-day exploit targeting Identity Services Engine, so it's time to patch up ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Cisco fixed critical ISE flaw (CVE‑2026‑76460) allowing unauthenticated API authentication bypass</strong></li><li><strong>Actively exploited; no workarounds exist—patching is the only mitigation, per Cisco PSIRT</strong></li><li><strong>CISA added to KEV catalog, mandating federal agencies patch or disable ISE by Sept 19, 2026</strong></li></ul><p>Cisco has fixed a maximum-severity vulnerability found in its Identity Services Engine (ISE) that is being actively exploited in attacks.</p><p>ISE is the company’s Network Access Control (NAC) and identity-based policy platform which decides who or what is allowed onto a company’s network, and what they’re allowed to access inside. </p><p>“A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication,” the company said in a security advisory.</p><h2 id="abused-in-the-wild-2">Abused in the wild</h2><p>“This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.”</p><p>The bug in question is tracked as CVE-2026-76460. It was given a severity score of 10/10 (critical), and was said it affects Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC), regardless of device configuration.</p><p>In the same advisory, Cisco said its Product Security Incident Response Team (PSIRT) was aware of active exploitation and urged customers to upgrade to a fixed software release as soon as possible. There are no workarounds available for this flaw, and a patch is the only solution. The full list of vulnerable versions and the corresponding patches can be found on <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5" target="_blank" rel="nofollow">this link</a>. </p><p>At the same time, the US Cybersecurity and Infrastructure Security Agency (CISA) added the bug to its Known Exploited Vulnerabilities (KEV) catalog, giving Federal agencies a three-day deadline to patch, or stop using ISE entirely. The deadline expires on September 19, 2026. </p><p>Cisco has shared Indicators of Compromise (IoC) and advised defenders to hunt for suspicious usernames in access.log files on every node. It also recommended re-imaging nodes and restoring them from backups, in case of a breach.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/cisco-warns-of-identity-service-engine-zero-day-exploited-in-attacks/" target="_blank" rel="nofollow"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/cisco-hit-by-max-severity-zero-day-exploit-targeting-identity-services-engine-so-its-time-to-patch-up</link>
                                                                            <description>
                            <![CDATA[ Both Cisco and CISA are warning about in-the-wild abuse. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bUfB9kve6QFAA9sjmTbTuW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BsnMKVyyNGEZMWVUsFD6vn-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 17 Sep 2026 14:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BsnMKVyyNGEZMWVUsFD6vn-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Proactive Cybersecurity Service That Neutralizes Threats Within a Digital Network - Conceptual Illustration]]></media:description>                                                            <media:text><![CDATA[Proactive Cybersecurity Service That Neutralizes Threats Within a Digital Network - Conceptual Illustration]]></media:text>
                                <media:title type="plain"><![CDATA[Proactive Cybersecurity Service That Neutralizes Threats Within a Digital Network - Conceptual Illustration]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BsnMKVyyNGEZMWVUsFD6vn-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Cisco fixed critical ISE flaw (CVE‑2026‑76460) allowing unauthenticated API authentication bypass</strong></li><li><strong>Actively exploited; no workarounds exist—patching is the only mitigation, per Cisco PSIRT</strong></li><li><strong>CISA added to KEV catalog, mandating federal agencies patch or disable ISE by Sept 19, 2026</strong></li></ul><p>Cisco has fixed a maximum-severity vulnerability found in its Identity Services Engine (ISE) that is being actively exploited in attacks.</p><p>ISE is the company’s Network Access Control (NAC) and identity-based policy platform which decides who or what is allowed onto a company’s network, and what they’re allowed to access inside. </p><p>“A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication,” the company said in a security advisory.</p><h2 id="abused-in-the-wild-2">Abused in the wild</h2><p>“This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.”</p><p>The bug in question is tracked as CVE-2026-76460. It was given a severity score of 10/10 (critical), and was said it affects Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC), regardless of device configuration.</p><p>In the same advisory, Cisco said its Product Security Incident Response Team (PSIRT) was aware of active exploitation and urged customers to upgrade to a fixed software release as soon as possible. There are no workarounds available for this flaw, and a patch is the only solution. The full list of vulnerable versions and the corresponding patches can be found on <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5" target="_blank" rel="nofollow">this link</a>. </p><p>At the same time, the US Cybersecurity and Infrastructure Security Agency (CISA) added the bug to its Known Exploited Vulnerabilities (KEV) catalog, giving Federal agencies a three-day deadline to patch, or stop using ISE entirely. The deadline expires on September 19, 2026. </p><p>Cisco has shared Indicators of Compromise (IoC) and advised defenders to hunt for suspicious usernames in access.log files on every node. It also recommended re-imaging nodes and restoring them from backups, in case of a breach.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/cisco-warns-of-identity-service-engine-zero-day-exploited-in-attacks/" target="_blank" rel="nofollow"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Scammers pose as airline customer support to help with your complaints and then steal your credit card info ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Check Point warns scammers spoof airline customer support on social media to steal payment data</strong></li><li><strong>Hundreds of fake accounts created daily, luring frustrated passengers into private chats or forms</strong></li><li><strong>Campaign active since 2024; mirrors earlier fake support scams seen during crypto wallet fraud</strong></li></ul><p>Scammers are now posing as customer support for airlines, tricking already frustrated customers into sharing payment details and possibly losing money, too.</p><p>People who have had poor experiences flying would often vent their frustration on social media, be it X, Facebook, Instagram, or any other platform. They would tag the company and demand help, or at least an explanation. However, according to new <a href="https://blog.checkpoint.com/exposure-management/scammers-are-watching-airline-complaints-and-posing-as-customer-support/" target="_blank" rel="nofollow">research</a> from security experts Check Point, the airline’s social media department is not the only one monitoring these complaints - hackers do it, too.</p><p>Not only are they monitoring the channels, they are actively preparing to hop in and talk to the customers. </p><h2 id="years-old-campaign">Years-old campaign</h2><p>Every day, hundreds of new social media accounts are created - some are built to spoof the airlines themselves, others are built to look as if they’re used by the airlines’ customer support or similar department. When the customer leaves a post or a comment, the criminals swoop in, publicly apologizing for the inconvenience, and offering assistance in a different, private channel. Sometimes those are the platform’s DMs, and sometimes it is WhatsApp or a different platform entirely.</p><p>The end result differs from case to case. Sometimes, the criminals would try to get the victims to share their personal and payment information and would later try to make a wire transfer. In other instances, the crooks would prepare a fake form for the victims to fill out, possibly creating a database for later use.</p><p>Check Point doesn’t know exactly when the campaign started but found some of the impersonation accounts dating back to before 2024, with the majority being created either in 2024, or later. “This suggests that the activity has accelerated over the past two years. The campaign remains highly active, with hundreds of new accounts appearing daily and new scam techniques continuing to emerge,” they said.</p><p>However, we can confirm that this type of fraud has been around for a lot longer than that. Fake customer support scams were rampant on X even in 2021, during the crypto ICO craze, during which crooks were taking advantage of people losing access to their wallets, or making transactions towards nonexistent wallet addresses in the same way.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/scammers-pose-as-airline-customer-support-to-help-with-your-complaints-and-then-steal-your-credit-card-info</link>
                                                                            <description>
                            <![CDATA[ Fraudsters are taking advantage of people venting on social media to inflict even more damage. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QHBQAXmpsNefuJXxoP4dr4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/CRRFyjRJcZe8qvwLLLssrL-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 17 Sep 2026 11:50:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/CRRFyjRJcZe8qvwLLLssrL-1920-80.jpg">
                                                            <media:credit><![CDATA[Image Credit: Pexels]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image Credit: Pexels]]></media:description>                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/CRRFyjRJcZe8qvwLLLssrL-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Check Point warns scammers spoof airline customer support on social media to steal payment data</strong></li><li><strong>Hundreds of fake accounts created daily, luring frustrated passengers into private chats or forms</strong></li><li><strong>Campaign active since 2024; mirrors earlier fake support scams seen during crypto wallet fraud</strong></li></ul><p>Scammers are now posing as customer support for airlines, tricking already frustrated customers into sharing payment details and possibly losing money, too.</p><p>People who have had poor experiences flying would often vent their frustration on social media, be it X, Facebook, Instagram, or any other platform. They would tag the company and demand help, or at least an explanation. However, according to new <a href="https://blog.checkpoint.com/exposure-management/scammers-are-watching-airline-complaints-and-posing-as-customer-support/" target="_blank" rel="nofollow">research</a> from security experts Check Point, the airline’s social media department is not the only one monitoring these complaints - hackers do it, too.</p><p>Not only are they monitoring the channels, they are actively preparing to hop in and talk to the customers. </p><h2 id="years-old-campaign">Years-old campaign</h2><p>Every day, hundreds of new social media accounts are created - some are built to spoof the airlines themselves, others are built to look as if they’re used by the airlines’ customer support or similar department. When the customer leaves a post or a comment, the criminals swoop in, publicly apologizing for the inconvenience, and offering assistance in a different, private channel. Sometimes those are the platform’s DMs, and sometimes it is WhatsApp or a different platform entirely.</p><p>The end result differs from case to case. Sometimes, the criminals would try to get the victims to share their personal and payment information and would later try to make a wire transfer. In other instances, the crooks would prepare a fake form for the victims to fill out, possibly creating a database for later use.</p><p>Check Point doesn’t know exactly when the campaign started but found some of the impersonation accounts dating back to before 2024, with the majority being created either in 2024, or later. “This suggests that the activity has accelerated over the past two years. The campaign remains highly active, with hundreds of new accounts appearing daily and new scam techniques continuing to emerge,” they said.</p><p>However, we can confirm that this type of fraud has been around for a lot longer than that. Fake customer support scams were rampant on X even in 2021, during the crypto ICO craze, during which crooks were taking advantage of people losing access to their wallets, or making transactions towards nonexistent wallet addresses in the same way.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Autonomous AI agent hit Spanish firm with vulnerability scans before accessing files and data ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Spain’s data protection agency (AEPD) reported its first breach carried out by an autonomous AI agent</strong></li><li><strong>Agent chained multiple attack stages: accessed public files, scanned systems, exploited a flaw, and modified data</strong></li><li><strong>AEPD urged businesses to factor AI‑driven attacks into risk assessments, stressing faster response and stronger identity controls</strong></li></ul><p>A Spanish company was apparently hit with a data breach conducted by an autonomous AI agent. </p><p>Earlier this week Francisco Pérez Bes, president and deputy of the Spanish data protection agency (AEPD) published a new article on the agency’s blog, saying it “received the first notification of a personal data breach in which the incident was reportedly carried out using an artificial intelligence agent powered by a well-known large language model.”</p><p>As per Pérez Bes, the agent first used the target’s “publicly accessible files”, through which it was able to log into its system. From the inside, the agent then started scanning for vulnerabilities and after finding one, used it to modify personal data and gain access to invoices. </p><h2 id="a-call-to-action">A call to action</h2><p>The author stresses that there is very little known about this incident and that a thorough investigation is currently ongoing. He pointed out that the attack doesn’t imply the AI model or the provider’s infrastructure were compromised or malicious by design, but said that the attack was “significant from a data protection perspective,” since the <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agent</a> was used to chain together multiple stages of the attack. </p><p>For Pérez, the attack is a call to action - businesses need to rethink how they assess and manage security risks. He claims businesses need to “explicitly account for AI-assisted and AI-driven attacks when assessing the risks associated with personal-data processing,” and need to reassess their response times.</p><p>“Procedures designed around manually executed attacks may not be sufficient when an AI agent can analyze multiple assets at once, test different avenues of attack, and rapidly adapt its behavior based on what it finds.”</p><p>He also stressed the “growing importance of digital identities and credentials,” since an AI agent with an account or an API key “can operate at machine speed and move across different services before an organization has time to detect the anomalous activity.”</p><p><em>Via </em><a href="https://www.theregister.com/cyber-crime/2026/09/16/spain-gets-its-first-taste-of-ai-aided-cyber-attack/5296844" target="_blank" rel="nofollow"><em>The Register</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/autonomous-ai-agent-hit-spanish-firm-with-vulnerability-scans-before-accessing-files-and-data</link>
                                                                            <description>
                            <![CDATA[ Spanish data protection agency disclosed a breach done by an AI agent powered by a well-known LLM. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bMfs4FLqnTwRrCfCbfDLbn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/D9SxF3hiMTwj2qrLfLCYk-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 17 Sep 2026 10:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/D9SxF3hiMTwj2qrLfLCYk-1920-80.jpg">
                                                            <media:credit><![CDATA[Yuichiro Chino/via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hologram of the artificial intelligence robot showing up from binary code]]></media:description>                                                            <media:text><![CDATA[Hologram of the artificial intelligence robot showing up from binary code]]></media:text>
                                <media:title type="plain"><![CDATA[Hologram of the artificial intelligence robot showing up from binary code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/D9SxF3hiMTwj2qrLfLCYk-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Spain’s data protection agency (AEPD) reported its first breach carried out by an autonomous AI agent</strong></li><li><strong>Agent chained multiple attack stages: accessed public files, scanned systems, exploited a flaw, and modified data</strong></li><li><strong>AEPD urged businesses to factor AI‑driven attacks into risk assessments, stressing faster response and stronger identity controls</strong></li></ul><p>A Spanish company was apparently hit with a data breach conducted by an autonomous AI agent. </p><p>Earlier this week Francisco Pérez Bes, president and deputy of the Spanish data protection agency (AEPD) published a new article on the agency’s blog, saying it “received the first notification of a personal data breach in which the incident was reportedly carried out using an artificial intelligence agent powered by a well-known large language model.”</p><p>As per Pérez Bes, the agent first used the target’s “publicly accessible files”, through which it was able to log into its system. From the inside, the agent then started scanning for vulnerabilities and after finding one, used it to modify personal data and gain access to invoices. </p><h2 id="a-call-to-action">A call to action</h2><p>The author stresses that there is very little known about this incident and that a thorough investigation is currently ongoing. He pointed out that the attack doesn’t imply the AI model or the provider’s infrastructure were compromised or malicious by design, but said that the attack was “significant from a data protection perspective,” since the <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agent</a> was used to chain together multiple stages of the attack. </p><p>For Pérez, the attack is a call to action - businesses need to rethink how they assess and manage security risks. He claims businesses need to “explicitly account for AI-assisted and AI-driven attacks when assessing the risks associated with personal-data processing,” and need to reassess their response times.</p><p>“Procedures designed around manually executed attacks may not be sufficient when an AI agent can analyze multiple assets at once, test different avenues of attack, and rapidly adapt its behavior based on what it finds.”</p><p>He also stressed the “growing importance of digital identities and credentials,” since an AI agent with an account or an API key “can operate at machine speed and move across different services before an organization has time to detect the anomalous activity.”</p><p><em>Via </em><a href="https://www.theregister.com/cyber-crime/2026/09/16/spain-gets-its-first-taste-of-ai-aided-cyber-attack/5296844" target="_blank" rel="nofollow"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US Treasury wants banks to be better at filing cyber scam reports after noting nearly $13 billion in losses since 2023 ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>The US Treasury's FinCEN arm asks financial institutions to file scam center suspicious activity reports under a new keyword</strong></li><li><strong>FinCEN says that it flagged financial moves across 33,904 different filings, but actual losses might differ significantly, as the approach is prone to double-counting transactions</strong></li><li><strong>Only 1,300 institutions filed reports, with 10,082 (29.7%) of them centering around exploitation of the elderly by scammers</strong></li></ul><p>The US Treasury's Financial Crimes Enforcement Network has issuespublished <a href="https://www.fincen.gov/system/files/2026-08/FinCEN-Alert-Scam-Centers.pdf" target="_blank">an alert</a> and a companion <a href="https://www.fincen.gov/system/files/2026-08/FinCEN-FTA-Digital-Asset-Investment-Scams.pdf" target="_blank">data analysis</a> telling banks, credit unions, digital asset exchanges, and securities firms that it needs sharper reporting on the overseas scam centers that it says target Americans at an industrial scale.</p><p>FinCEN puts total damages, per its reporting mechanism, at roughly $12.7 billion linked to suspected digital asset investment scams between September 2023 and the end of 2025.</p><p>The number comes from adding up the dollar values of 33,904 Bank Secrecy Act filings that referenced the keyword from <a href="https://www.fincen.gov/news/news-releases/fincen-issues-alert-prevalent-virtual-currency-investment-scam-commonly-known" target="_blank">its 2023 "pig butchering" alert</a>, which may be overstated, as it includes both attempted and successful transactions as well as both inbound and outbound reports, often of the same transactions, causing significant overlap.</p><h2 id="fincen-39-s-new-requirement-is-a-keyword">FinCEN's new requirement is a keyword</h2><p>While the $12.7 billion is a measure of what institutions have flagged and is prone to double-counting and errors, victim losses, a significant chunk of which go unreported, may be considerably higher.</p><p>This has prompted Gene Lange, who effectively works as the Under Secretary for Terrorism and Financial Intelligence, to call these scams "one of the most significant fraud threats facing Americans today."</p><p>It has also prompted a new suspicious activity report keyword: "FIN-2026-SCAMCENTERS," which institutions are expected to use to indicate that a scam center is potentially involved.</p><p>FinCEN also wants chat logs, scammer phone numbers, social media handles, wallet addresses, transaction hashes, and the URLs victims were told to deposit into, filed in the structured cyber indicator fields rather than left out.</p><h2 id="institutions-to-volunteer-more-information-to-stop-scams">Institutions to volunteer more information to stop scams</h2><p>The move is part of its push to have institutions volunteer more information under the US Patriot Act, as it aims to confront what is a growing intelligence problem: scammers tend to route victims through several institutions in sequence; most filers see only one slice of a scam's lifecycle and often have difficulty tracing it all the way.</p><p>For example, a crypto exchange might see a customer buying USDT and sending it off-platform, a bank might see a wire to that exchange, and a brokerage might see a retirement account liquidated. None of them would have the bigger picture of what essentially happened or what triggered the transaction.</p><p>Combined, with properly linked information, it makes it much easier to identify a potential scam; separately, these incidents can inflate the number of reports, which often aren't linked, and investigations can lack insight into the origin or final destination of the funds.</p><p>FinCEN's Rapid Response Program has interdicted $1.8 billion and recovered just over $1 billion for 5,790 US victims since 2015, which, against the flagged totals, is a very limited recovery at best compared with the actual funds at stake. This highlights a <a href="https://www.fbi.gov/news/press-releases/cryptocurrency-and-ai-scams-bilk-americans-of-billions" target="_blank">larger fundamental problem</a>: institutions mostly detect these schemes after the money is gone, and reporting them correctly and thoroughly may yield limited dividends at best against an <a href="https://www.techradar.com/vpn/vpn-services/nordvpn-warns-ai-is-making-scams-more-personal-and-devastating-than-ever" target="_blank">industry that has morphed,</a> relatively unchecked, into a multi-billion-dollar juggernaut.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/us-treasury-wants-banks-to-be-better-at-filing-cyber-scam-reports-after-noting-nearly-usd13-billion-in-losses-since-2023</link>
                                                                            <description>
                            <![CDATA[ However the number counts flagged bank filings, not stolen money, and only 1,300 institutions bothered filing at all. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rUUM3bQNWeHeYDRYeLBTfA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VuBMgidwKAh2uEAV7UMikB-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 17 Sep 2026 00:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VuBMgidwKAh2uEAV7UMikB-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Users display warnings about the use of artificial intelligence (AI), access to malicious software or threats to online hackers. computer cyber security Warning concept or tech scam.]]></media:description>                                                            <media:text><![CDATA[Users display warnings about the use of artificial intelligence (AI), access to malicious software or threats to online hackers. computer cyber security Warning concept or tech scam.]]></media:text>
                                <media:title type="plain"><![CDATA[Users display warnings about the use of artificial intelligence (AI), access to malicious software or threats to online hackers. computer cyber security Warning concept or tech scam.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VuBMgidwKAh2uEAV7UMikB-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>The US Treasury's FinCEN arm asks financial institutions to file scam center suspicious activity reports under a new keyword</strong></li><li><strong>FinCEN says that it flagged financial moves across 33,904 different filings, but actual losses might differ significantly, as the approach is prone to double-counting transactions</strong></li><li><strong>Only 1,300 institutions filed reports, with 10,082 (29.7%) of them centering around exploitation of the elderly by scammers</strong></li></ul><p>The US Treasury's Financial Crimes Enforcement Network has issuespublished <a href="https://www.fincen.gov/system/files/2026-08/FinCEN-Alert-Scam-Centers.pdf" target="_blank">an alert</a> and a companion <a href="https://www.fincen.gov/system/files/2026-08/FinCEN-FTA-Digital-Asset-Investment-Scams.pdf" target="_blank">data analysis</a> telling banks, credit unions, digital asset exchanges, and securities firms that it needs sharper reporting on the overseas scam centers that it says target Americans at an industrial scale.</p><p>FinCEN puts total damages, per its reporting mechanism, at roughly $12.7 billion linked to suspected digital asset investment scams between September 2023 and the end of 2025.</p><p>The number comes from adding up the dollar values of 33,904 Bank Secrecy Act filings that referenced the keyword from <a href="https://www.fincen.gov/news/news-releases/fincen-issues-alert-prevalent-virtual-currency-investment-scam-commonly-known" target="_blank">its 2023 "pig butchering" alert</a>, which may be overstated, as it includes both attempted and successful transactions as well as both inbound and outbound reports, often of the same transactions, causing significant overlap.</p><h2 id="fincen-39-s-new-requirement-is-a-keyword">FinCEN's new requirement is a keyword</h2><p>While the $12.7 billion is a measure of what institutions have flagged and is prone to double-counting and errors, victim losses, a significant chunk of which go unreported, may be considerably higher.</p><p>This has prompted Gene Lange, who effectively works as the Under Secretary for Terrorism and Financial Intelligence, to call these scams "one of the most significant fraud threats facing Americans today."</p><p>It has also prompted a new suspicious activity report keyword: "FIN-2026-SCAMCENTERS," which institutions are expected to use to indicate that a scam center is potentially involved.</p><p>FinCEN also wants chat logs, scammer phone numbers, social media handles, wallet addresses, transaction hashes, and the URLs victims were told to deposit into, filed in the structured cyber indicator fields rather than left out.</p><h2 id="institutions-to-volunteer-more-information-to-stop-scams">Institutions to volunteer more information to stop scams</h2><p>The move is part of its push to have institutions volunteer more information under the US Patriot Act, as it aims to confront what is a growing intelligence problem: scammers tend to route victims through several institutions in sequence; most filers see only one slice of a scam's lifecycle and often have difficulty tracing it all the way.</p><p>For example, a crypto exchange might see a customer buying USDT and sending it off-platform, a bank might see a wire to that exchange, and a brokerage might see a retirement account liquidated. None of them would have the bigger picture of what essentially happened or what triggered the transaction.</p><p>Combined, with properly linked information, it makes it much easier to identify a potential scam; separately, these incidents can inflate the number of reports, which often aren't linked, and investigations can lack insight into the origin or final destination of the funds.</p><p>FinCEN's Rapid Response Program has interdicted $1.8 billion and recovered just over $1 billion for 5,790 US victims since 2015, which, against the flagged totals, is a very limited recovery at best compared with the actual funds at stake. This highlights a <a href="https://www.fbi.gov/news/press-releases/cryptocurrency-and-ai-scams-bilk-americans-of-billions" target="_blank">larger fundamental problem</a>: institutions mostly detect these schemes after the money is gone, and reporting them correctly and thoroughly may yield limited dividends at best against an <a href="https://www.techradar.com/vpn/vpn-services/nordvpn-warns-ai-is-making-scams-more-personal-and-devastating-than-ever" target="_blank">industry that has morphed,</a> relatively unchecked, into a multi-billion-dollar juggernaut.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How the mighty have fallen — the notorious Stuxnet malware source code has been replicated and posted on GitHub for all to see ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>A pseudonymous GitHub account has published what it calls a reconstruction of Stuxnet malware that purportedly took out a fifth of Iran's centrifuges before being discovered</strong></li><li><strong>The original source has never surfaced, and the 'Stuxnet' moniker that the account uses comes from Symantec's coining of the name weeks after it was discovered</strong></li><li><strong>The code remains unverified and untested, with some users indicating that it is likely an AI-generated replication of the original binaries' behavior, which has been widely documented</strong></li></ul><p>A GitHub account has published what it describes as a faithful reconstruction of Stuxnet, the worm that sabotaged Iranian uranium-enrichment centrifuges.</p><p>It also became the first piece of software widely accepted as having caused physical destruction in the real world, highlighting how malicious software can often do much more harm to people and hardware than just stealing or manipulating data.</p><p>The repository surfaced via a <a href="https://news.ycombinator.com/item?id=49603546" target="_blank">Show HN submission,</a> which mainstream media outlets then picked up, highlighting the as-yet-unknown researcher's reverse-engineered code.</p><h2 id="not-the-first-or-last-stuxnet-repository">Not the first or last Stuxnet repository</h2><p>The original Stuxnet source, written by whoever built it, has never been leaked and did not leak last week. The repository's README explicitly states that it is a reconstruction assembled from decompiled binaries, and those binaries have been in public circulation <a href="https://www.bbc.com/news/technology-11388018" target="_blank">since Belarusian firm VirusBlokAda pulled samples</a> from an Iranian customer's machines in June 2010.</p><p>Everything that followed, including Symantec's W32.Stuxnet Dossier and Ralph Langner's <a href="https://www.cyber-peace.org/wp-content/uploads/2013/06/To-kill-a-centrifuge.pdf">To Kill a Centrifuge</a>, was built on those samples and how they reacted in test environments.</p><p>This is also not the first time readable C-language code aiming to replicate Stuxnet has been published online. Malware researcher Amr Thabet published a decompilation of the MRxNet rootkit carrying a 2010 to 2011 copyright notice. Christian Roggia followed with a dropper decompilation called open-myrtus, copyrighted 2012 to 2014, which has since been forked into a long chain of repositories.</p><p>The irony is that if such code were a faithful replication of the infamous malware, it would not have mentioned "Stuxnet" in multiple places, including registry keys. This is because the moniker is not one the developers likely used, but one Symantec switched to from its original 'W32.Temphid' identifier.</p><p>The thread where it was first brought to attention by a user called Sadpainy  also has mixed views from developers, many of whom have branded it 'AI slop' or a 'fake' that relies on a mixture of already existing repositories, even as the <a href="https://github.com/Sadpainy/Stuxnet">about page on its GitHub repo</a> states that it was reproduced by the researcher for educational purposes and is designed to only work on Windows XP and Windows 7.</p><p>For those looking to test it, a virtual machine might be their best bet, especially given Stuxnet's ability to physically damage hardware, but it is also a stark reminder of what a rogue AI agent <a href="https://www.techradar.com/pro/security/why-are-us-ai-giants-calling-for-pacing-the-frontier-and-why-is-china-calling-it-a-cold-war-tactic-we-ask-the-experts" target="_blank">could do if left unchecked</a> without specific instructions or safeguards.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/how-the-mighty-have-fallen-the-notorious-stuxnet-malware-source-code-has-been-replicated-and-posted-on-github-for-all-to-see</link>
                                                                            <description>
                            <![CDATA[ Recreating a prolific malware using a mix of publicly available decompiled binaries and AI? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">WkE4QVsk8vEKiGpG2R3i3X</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Sep 2026 23:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:description>                                                            <media:text><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:text>
                                <media:title type="plain"><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>A pseudonymous GitHub account has published what it calls a reconstruction of Stuxnet malware that purportedly took out a fifth of Iran's centrifuges before being discovered</strong></li><li><strong>The original source has never surfaced, and the 'Stuxnet' moniker that the account uses comes from Symantec's coining of the name weeks after it was discovered</strong></li><li><strong>The code remains unverified and untested, with some users indicating that it is likely an AI-generated replication of the original binaries' behavior, which has been widely documented</strong></li></ul><p>A GitHub account has published what it describes as a faithful reconstruction of Stuxnet, the worm that sabotaged Iranian uranium-enrichment centrifuges.</p><p>It also became the first piece of software widely accepted as having caused physical destruction in the real world, highlighting how malicious software can often do much more harm to people and hardware than just stealing or manipulating data.</p><p>The repository surfaced via a <a href="https://news.ycombinator.com/item?id=49603546" target="_blank">Show HN submission,</a> which mainstream media outlets then picked up, highlighting the as-yet-unknown researcher's reverse-engineered code.</p><h2 id="not-the-first-or-last-stuxnet-repository">Not the first or last Stuxnet repository</h2><p>The original Stuxnet source, written by whoever built it, has never been leaked and did not leak last week. The repository's README explicitly states that it is a reconstruction assembled from decompiled binaries, and those binaries have been in public circulation <a href="https://www.bbc.com/news/technology-11388018" target="_blank">since Belarusian firm VirusBlokAda pulled samples</a> from an Iranian customer's machines in June 2010.</p><p>Everything that followed, including Symantec's W32.Stuxnet Dossier and Ralph Langner's <a href="https://www.cyber-peace.org/wp-content/uploads/2013/06/To-kill-a-centrifuge.pdf">To Kill a Centrifuge</a>, was built on those samples and how they reacted in test environments.</p><p>This is also not the first time readable C-language code aiming to replicate Stuxnet has been published online. Malware researcher Amr Thabet published a decompilation of the MRxNet rootkit carrying a 2010 to 2011 copyright notice. Christian Roggia followed with a dropper decompilation called open-myrtus, copyrighted 2012 to 2014, which has since been forked into a long chain of repositories.</p><p>The irony is that if such code were a faithful replication of the infamous malware, it would not have mentioned "Stuxnet" in multiple places, including registry keys. This is because the moniker is not one the developers likely used, but one Symantec switched to from its original 'W32.Temphid' identifier.</p><p>The thread where it was first brought to attention by a user called Sadpainy  also has mixed views from developers, many of whom have branded it 'AI slop' or a 'fake' that relies on a mixture of already existing repositories, even as the <a href="https://github.com/Sadpainy/Stuxnet">about page on its GitHub repo</a> states that it was reproduced by the researcher for educational purposes and is designed to only work on Windows XP and Windows 7.</p><p>For those looking to test it, a virtual machine might be their best bet, especially given Stuxnet's ability to physically damage hardware, but it is also a stark reminder of what a rogue AI agent <a href="https://www.techradar.com/pro/security/why-are-us-ai-giants-calling-for-pacing-the-frontier-and-why-is-china-calling-it-a-cold-war-tactic-we-ask-the-experts" target="_blank">could do if left unchecked</a> without specific instructions or safeguards.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Iran snoops on enemies of the state with Chosen Brick malware controlled using messaging apps ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>UK NCSC, FBI, and Dutch AIVD warn Iran is using </strong><em><strong>Chosen Brick</strong></em><strong> malware against dissidents and journalists</strong></li><li><strong>Malware steals files, captures audio, grabs WhatsApp/Telegram data, and can wipe systems entirely</strong></li><li><strong>Operatives rely on social engineering; agencies urge awareness, MFA, updates, and endpoint monitoring</strong></li></ul><p>Iranian hackers are targeting “enemies of the state”, both local and foreign, with advanced malware capable of spying on the victims and stealing their sensitive files, experts have warned.</p><p>This is according to a new security advisory, published jointly by the UK National Cyber Security Centre, the FBI, and the Netherlands’ General Intelligence and Security Service (AIVD), which noted how Iranian operatives would first do extensive research into their victims - dissidents, activists, and journalists - deemed a risk to the regime. </p><p>After learning as much about their targets as possible, they reach out via social media, either as someone the victims know, or as technical support for the platform they’re currently using, engaging in extended conversation until the victim lowers their guard. At one point, the attackers will try to share a piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> with the victims, tracked as Chosen Brick.</p><h2 id="a-thousand-victims">A thousand victims</h2><p>This malware, designed primarily for the Windows platform, has a long list of capabilities, including enumerating running processes and system information, capturing screen content, enabling the microphone to capture audio content, capturing a copy of Telegram and WhatsApp data from web browsers, downloading additional files and malware, deleting files, stealing email content, and ultimately - wiping the entire computer system. The operatives communicate with the malware using Telegram, it was said.</p><p>“Iran almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists,” the three agencies said in the report. “In some cases, the Iranian intelligence services have plotted to kidnap or conduct lethal operations against individuals internationally, who they perceive as enemies of the regime.”</p><p>In the advisory, the three agencies said the best defense is to simply be more aware of social engineering. However, there are also a few technical mitigations that can help, including following NCSC advice on staying safe online, keeping all devices up-to-date (ideally through automatic updates), using antivirus software, and not disabling smart screen warnings on file downloads. </p><p>Finally, it would be wise to enable phishing-resistant MFA, make sure devices are managed with appropriate controls, turn on email scanning, deploy endpoint and network monitoring, and conduct a search for the IoCs. </p><p><em>Via </em><a href="https://www.theregister.com/security/2026/09/15/iranian-spies-hit-windows-machines-with-chosen-brick-data-stealing-malware/5296646" target="_blank" rel="nofollow"><em>The Register</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/iran-snoops-on-enemies-of-the-state-with-chosen-brick-malware-controlled-using-messaging-apps</link>
                                                                            <description>
                            <![CDATA[ Chosen Brick can turn on the microphone and exfiltrate WhatsApp and Telegram information. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">o45CPJpTUrhMHqD6fqY9Kd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/t7EhsbNc6VmBM6RqN2h4UN-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Sep 2026 18:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/t7EhsbNc6VmBM6RqN2h4UN-1920-80.jpg">
                                                            <media:credit><![CDATA[BirgitKorber/via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Binary code with Iran flag, data protection concept - stock photo]]></media:description>                                                            <media:text><![CDATA[Binary code with Iran flag, data protection concept - stock photo]]></media:text>
                                <media:title type="plain"><![CDATA[Binary code with Iran flag, data protection concept - stock photo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/t7EhsbNc6VmBM6RqN2h4UN-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>UK NCSC, FBI, and Dutch AIVD warn Iran is using </strong><em><strong>Chosen Brick</strong></em><strong> malware against dissidents and journalists</strong></li><li><strong>Malware steals files, captures audio, grabs WhatsApp/Telegram data, and can wipe systems entirely</strong></li><li><strong>Operatives rely on social engineering; agencies urge awareness, MFA, updates, and endpoint monitoring</strong></li></ul><p>Iranian hackers are targeting “enemies of the state”, both local and foreign, with advanced malware capable of spying on the victims and stealing their sensitive files, experts have warned.</p><p>This is according to a new security advisory, published jointly by the UK National Cyber Security Centre, the FBI, and the Netherlands’ General Intelligence and Security Service (AIVD), which noted how Iranian operatives would first do extensive research into their victims - dissidents, activists, and journalists - deemed a risk to the regime. </p><p>After learning as much about their targets as possible, they reach out via social media, either as someone the victims know, or as technical support for the platform they’re currently using, engaging in extended conversation until the victim lowers their guard. At one point, the attackers will try to share a piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> with the victims, tracked as Chosen Brick.</p><h2 id="a-thousand-victims">A thousand victims</h2><p>This malware, designed primarily for the Windows platform, has a long list of capabilities, including enumerating running processes and system information, capturing screen content, enabling the microphone to capture audio content, capturing a copy of Telegram and WhatsApp data from web browsers, downloading additional files and malware, deleting files, stealing email content, and ultimately - wiping the entire computer system. The operatives communicate with the malware using Telegram, it was said.</p><p>“Iran almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists,” the three agencies said in the report. “In some cases, the Iranian intelligence services have plotted to kidnap or conduct lethal operations against individuals internationally, who they perceive as enemies of the regime.”</p><p>In the advisory, the three agencies said the best defense is to simply be more aware of social engineering. However, there are also a few technical mitigations that can help, including following NCSC advice on staying safe online, keeping all devices up-to-date (ideally through automatic updates), using antivirus software, and not disabling smart screen warnings on file downloads. </p><p>Finally, it would be wise to enable phishing-resistant MFA, make sure devices are managed with appropriate controls, turn on email scanning, deploy endpoint and network monitoring, and conduct a search for the IoCs. </p><p><em>Via </em><a href="https://www.theregister.com/security/2026/09/15/iranian-spies-hit-windows-machines-with-chosen-brick-data-stealing-malware/5296646" target="_blank" rel="nofollow"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ CenterPoint Energy confirms hackers compromised networks and stole data, and the hackers claim theft of 7.5 million files ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>CenterPoint Energy confirmed a cyberattack via exposed API, with customer data stolen</strong></li><li><strong>Threat actor claims 7.49M files including IDs, SSNs, billing data, and transaction records</strong></li><li><strong>Operations unaffected; investigation ongoing, regulators notified, customers to be informed</strong></li></ul><p>CenterPoint Energy has confirmed suffering a cyberattack and data theft, days after a criminal advertised the stolen files on an underground hacking forum.</p><p>CenterPoint Energy is a large US energy utility company that delivers electricity and natural gas to homes and businesses. It employs roughly 8,800 people and operates around $48.3 billion in assets, as of June 2026. </p><p>Recently, a threat actor posted a new thread on a dark web forum, saying they stole 7.49 million CenterPoint files from a poorly secured API, The Register reports. They said that the data included <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">customer names</a> and contact details, billing data, move-in dates, driver’s license information, and the last four digits of Social Security numbers (SSN). </p><h2 id="incurring-expenses">Incurring expenses</h2><p>No independent investigators have confirmed these claims just yet, and the company said it was investigating the matter. In a new 8-K document filed with the US Securities and Exchange Commission (SEC) on September 14, the company said that it “became aware of an online post by a third party claiming to have obtained a data set containing certain of the company’s customer information.” </p><p>It activated its incident response protocols and kicked off an investigation with the help of third-party cybersecurity experts. </p><p>“While the investigation remains ongoing, the company has determined that an unauthorized third party obtained personal information relating to a portion of the company’s customers through one of the company’s external facing systems,” the filing reads. “The company is continuing to work with third-party experts to determine the scope of customers and personal information affected by the incident and intends to notify affected customers and regulatory authorities as required by applicable law.” The police and regulatory agencies have been notified.</p><p>While the attack did not impact CenterPoint’s operations, which continue as usual, it did incur certain expenses, the company concluded. It stressed that it will likely incur even more expenses as the investigation continues.</p><p><em>Via </em><a href="https://www.theregister.com/cyber-crime/2026/09/15/centerpoint-energy-confirms-intruder-helped-themselves-to-customer-information/5296523" target="_blank"><em>The Register</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/centerpoint-energy-confirms-hackers-compromised-networks-and-stole-data-and-the-hackers-claim-theft-of-7-5-million-files</link>
                                                                            <description>
                            <![CDATA[ The company confirmed the hack in a new SEC filing and said the investigation is ongoing. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xEpVSN8WhytqSBqzC8zV8T</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Sep 2026 16:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:description>                                                            <media:text><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:text>
                                <media:title type="plain"><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>CenterPoint Energy confirmed a cyberattack via exposed API, with customer data stolen</strong></li><li><strong>Threat actor claims 7.49M files including IDs, SSNs, billing data, and transaction records</strong></li><li><strong>Operations unaffected; investigation ongoing, regulators notified, customers to be informed</strong></li></ul><p>CenterPoint Energy has confirmed suffering a cyberattack and data theft, days after a criminal advertised the stolen files on an underground hacking forum.</p><p>CenterPoint Energy is a large US energy utility company that delivers electricity and natural gas to homes and businesses. It employs roughly 8,800 people and operates around $48.3 billion in assets, as of June 2026. </p><p>Recently, a threat actor posted a new thread on a dark web forum, saying they stole 7.49 million CenterPoint files from a poorly secured API, The Register reports. They said that the data included <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">customer names</a> and contact details, billing data, move-in dates, driver’s license information, and the last four digits of Social Security numbers (SSN). </p><h2 id="incurring-expenses">Incurring expenses</h2><p>No independent investigators have confirmed these claims just yet, and the company said it was investigating the matter. In a new 8-K document filed with the US Securities and Exchange Commission (SEC) on September 14, the company said that it “became aware of an online post by a third party claiming to have obtained a data set containing certain of the company’s customer information.” </p><p>It activated its incident response protocols and kicked off an investigation with the help of third-party cybersecurity experts. </p><p>“While the investigation remains ongoing, the company has determined that an unauthorized third party obtained personal information relating to a portion of the company’s customers through one of the company’s external facing systems,” the filing reads. “The company is continuing to work with third-party experts to determine the scope of customers and personal information affected by the incident and intends to notify affected customers and regulatory authorities as required by applicable law.” The police and regulatory agencies have been notified.</p><p>While the attack did not impact CenterPoint’s operations, which continue as usual, it did incur certain expenses, the company concluded. It stressed that it will likely incur even more expenses as the investigation continues.</p><p><em>Via </em><a href="https://www.theregister.com/cyber-crime/2026/09/15/centerpoint-energy-confirms-intruder-helped-themselves-to-customer-information/5296523" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Watch out — TP-Link Tapo Camera vulnerabilities could let hackers spy inside homes, so patch now ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Opswat found two flaws in TP‑Link Tapo C200 cameras: auth bypass (CVE‑2026‑15315) and DoS (CVE‑2026‑15316)</strong></li><li><strong>Bugs let attackers hijack admin sessions or crash devices; millions of users potentially exposed</strong></li><li><strong>TP‑Link patched with firmware V5_1.4.6 on Aug 18, 2026; users urged to update immediately</strong></li></ul><p>Security researchers found a pair of vulnerabilities in <a href="https://www.techradar.com/news/best-home-security-camera" target="_blank">popular smart cameras</a>, which could allow threat actors to peep into people’s homes and businesses.</p><p>Earlier this week, Opswat disclosed finding two bugs in the TP-Link Tapo C200 smart security camera - an authentication bypass flaw, and a denial-of-service vulnerability. The former is tracked as CVE-2026-15315 and was given a severity score of 8.7/10 (high). Opswat says the bug allows unauthenticated attackers to obtain valid admin sessions without having a password, which would allow them to manage the device and even watch the stream. </p><p>The latter is tracked as CVE-2026-15316. With a severity score of 7.1/10 (high), this bug allows threat actors to send oversized crypted ciphertext values that may trigger exception handling failures and cause the affected device to crash or restart. “Successful exploitation may temporarily disrupt HTTPS management and monitoring functionality, resulting in a denial-of-service (DoS) condition until the service recovers,” according to the NVD.</p><h2 id="patching-the-bugs">Patching the bugs</h2><p>The C200 is a mass-market product, advertised as a security camera, a baby monitor, or a pet camera, with motion detection, 1080p video, 2-way audio, night vision, cloud & SD card storage, and integrations with both Alexa and Google Home. </p><p>Opswat disclosed their findings to TP-Link in mid-April this year, which started working on a fix in early July this year. On August 18, 2026, TP-Link released firmware version V5_1.4.6, which addressed both flaws. Users are advised to install the fix as soon as possible.</p><p>The researchers did not discuss if the flaws were being abused in the wild, or to what extent. We do know that TP-Link Tapo cameras are rather popular, with the C200 model being relatively widely sold. According to TP-Link, the Tapo app has more than 13 million users, while the Google Play Store shows 10+ million downloads. </p><p>On Amazon, the C200 specifically is listed as the #1 top rated product in its category, with more than 3,000 purchases this month alone. </p><p>"Camera bugs always get attention because of the "spy factor," but they usually sound cooler and scarier than they actually are," said Dahvid Schloss, OSCP, Chief Operating Officer at Suzu Labs. "The main reason not to "worry" about this one is that running this exploit requires local network access, so a threat actor has to be on your Wi-Fi or already own a device that is. </p><p>"If someone's made it that far into your network, they're not after the baby monitor. Now, if the camera was port-forwarded to the internet, that's a bigger design issue and probably should be a concern, but not a common setup for the everyday home user. Either way, I'd still patch the camera, but it's pretty low on the totem pole of what a cybercriminal wants."</p><p>"I'm quite curious about the undisclosed vulnerability that reportedly allows full compromise and a foothold to pivot from," Schloss added. "Based on what was reported, I would guess the exploit would be a command injection or a memory-safety bug in the same management service, chained behind that auth bypass to get code execution as root, where they then dropped a static binary to return a shell on the device whose firmware ships with almost no tooling. That attack chain isn't uncommon on cheap, older consumer IoT devices where security wasn't top of mind, but if that's the case here, seeing it hold up on a modern TP-Link device would be a bit of a blast from the past.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/watch-out-tp-link-tapo-camera-vulnerabilities-could-let-hackers-spy-inside-homes-so-patch-now</link>
                                                                            <description>
                            <![CDATA[ A firmware update is now available to fix the issues. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SPjnLABuVNPrn2TwBAhreF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JoaAAvDK3PPAJUwTSBoEM7-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Sep 2026 14:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JoaAAvDK3PPAJUwTSBoEM7-1920-80.jpg">
                                                            <media:credit><![CDATA[TP-Link ]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[TP-Link C200]]></media:description>                                                            <media:text><![CDATA[TP-Link C200]]></media:text>
                                <media:title type="plain"><![CDATA[TP-Link C200]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JoaAAvDK3PPAJUwTSBoEM7-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Opswat found two flaws in TP‑Link Tapo C200 cameras: auth bypass (CVE‑2026‑15315) and DoS (CVE‑2026‑15316)</strong></li><li><strong>Bugs let attackers hijack admin sessions or crash devices; millions of users potentially exposed</strong></li><li><strong>TP‑Link patched with firmware V5_1.4.6 on Aug 18, 2026; users urged to update immediately</strong></li></ul><p>Security researchers found a pair of vulnerabilities in <a href="https://www.techradar.com/news/best-home-security-camera" target="_blank">popular smart cameras</a>, which could allow threat actors to peep into people’s homes and businesses.</p><p>Earlier this week, Opswat disclosed finding two bugs in the TP-Link Tapo C200 smart security camera - an authentication bypass flaw, and a denial-of-service vulnerability. The former is tracked as CVE-2026-15315 and was given a severity score of 8.7/10 (high). Opswat says the bug allows unauthenticated attackers to obtain valid admin sessions without having a password, which would allow them to manage the device and even watch the stream. </p><p>The latter is tracked as CVE-2026-15316. With a severity score of 7.1/10 (high), this bug allows threat actors to send oversized crypted ciphertext values that may trigger exception handling failures and cause the affected device to crash or restart. “Successful exploitation may temporarily disrupt HTTPS management and monitoring functionality, resulting in a denial-of-service (DoS) condition until the service recovers,” according to the NVD.</p><h2 id="patching-the-bugs">Patching the bugs</h2><p>The C200 is a mass-market product, advertised as a security camera, a baby monitor, or a pet camera, with motion detection, 1080p video, 2-way audio, night vision, cloud & SD card storage, and integrations with both Alexa and Google Home. </p><p>Opswat disclosed their findings to TP-Link in mid-April this year, which started working on a fix in early July this year. On August 18, 2026, TP-Link released firmware version V5_1.4.6, which addressed both flaws. Users are advised to install the fix as soon as possible.</p><p>The researchers did not discuss if the flaws were being abused in the wild, or to what extent. We do know that TP-Link Tapo cameras are rather popular, with the C200 model being relatively widely sold. According to TP-Link, the Tapo app has more than 13 million users, while the Google Play Store shows 10+ million downloads. </p><p>On Amazon, the C200 specifically is listed as the #1 top rated product in its category, with more than 3,000 purchases this month alone. </p><p>"Camera bugs always get attention because of the "spy factor," but they usually sound cooler and scarier than they actually are," said Dahvid Schloss, OSCP, Chief Operating Officer at Suzu Labs. "The main reason not to "worry" about this one is that running this exploit requires local network access, so a threat actor has to be on your Wi-Fi or already own a device that is. </p><p>"If someone's made it that far into your network, they're not after the baby monitor. Now, if the camera was port-forwarded to the internet, that's a bigger design issue and probably should be a concern, but not a common setup for the everyday home user. Either way, I'd still patch the camera, but it's pretty low on the totem pole of what a cybercriminal wants."</p><p>"I'm quite curious about the undisclosed vulnerability that reportedly allows full compromise and a foothold to pivot from," Schloss added. "Based on what was reported, I would guess the exploit would be a command injection or a memory-safety bug in the same management service, chained behind that auth bypass to get code execution as root, where they then dropped a static binary to return a shell on the device whose firmware ships with almost no tooling. That attack chain isn't uncommon on cheap, older consumer IoT devices where security wasn't top of mind, but if that's the case here, seeing it hold up on a modern TP-Link device would be a bit of a blast from the past.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Third-party WooCommerce plugin hits WordPress sites with PHP backdoor abusing recently patched vulnerability ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Defiant warned of active exploitation of WooCommerce Wholesale Lead Capture Plugin flaw (CVE‑2026‑27540)</strong></li><li><strong>Critical unauthenticated file‑upload bug lets attackers deploy PHP webshells for site takeover</strong></li><li><strong>Patch released in Feb 2026 (v2.0.3.2); Wordfence blocked 100,000+ attacks, users urged to update and check uploads</strong></li></ul><p>A critical vulnerability in a popular WooCommerce plugin is being actively exploited to upload malware and possibly take over entire websites, security experts have warned.</p><p>The plugin in question is called Wholesale Lead Capture Plugin for WooCommerce. It adds a dedicated registration and onboarding system for wholesale and B2B customers, letting businesses collect company and other custom information, review applications, assign wholesale user roles, and automate registration and onboarding emails.</p><p>It is a premium plugin that costs between $99 and $600 and which, according to the <a href="https://wordpress.org/plugins/woocommerce-wholesale-prices/" target="_blank" rel="nofollow"><u>Wordpress store page</u></a>, has more than 20,000 active installations.</p><h2 id="a-thousand-victims-2">A thousand victims</h2><p>The plugin was vulnerable to an unauthenticated arbitrary file-upload flaw which, as the name suggests, allows unauthenticated parties to upload arbitrary files, including PHP webshells and executable code that can result in full site takeover. It is tracked as CVE-2026-27540 and carries a severity score of 9.0/10 (critical). </p><p>Versions 2.0.3.1 and older were said to be affected. Version 2.0.3.2, released on February 20, was said to have addressed the bug, meaning the patch has been available for almost half a year. However, WordPress security outfit Defiant said its Wordfence web application firewall blocked more than 100,000 attacks, and Wordfence added that it observed two attack spikes - one between June 4 and 17, and another one between July 1 and August 30. </p><p>In these incidents, the attackers were mostly uploading reconnaissance webshells, possibly mapping out the landscape before deploying more serious malware. </p><p>“The uploaded shell.php is a PHP webshell that reports host details and provides a browser-based upload form for writing additional malicious files to the site,” the researchers said. </p><p>If you are running the plugin, it is advised you update it to the newest version as soon as possible, and check upload directories for unexpected, or recently created, PHP files.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-via-third-party-woocommerce-plugin/" target="_blank" rel="nofollow"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/third-party-woocommerce-plugin-hits-wordpress-sites-with-php-backdoor-abusing-recently-patched-vulnerability</link>
                                                                            <description>
                            <![CDATA[ Attackers are actively exploiting a recently patched flaw in a plugin used by thousands. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">UQWHCu52UzGyGJx8AD8fzW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zHBWWxpmu5iienhz4xVsXa-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Sep 2026 11:50:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zHBWWxpmu5iienhz4xVsXa-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/monticello]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WooCommerce]]></media:description>                                                            <media:text><![CDATA[WooCommerce]]></media:text>
                                <media:title type="plain"><![CDATA[WooCommerce]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zHBWWxpmu5iienhz4xVsXa-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Defiant warned of active exploitation of WooCommerce Wholesale Lead Capture Plugin flaw (CVE‑2026‑27540)</strong></li><li><strong>Critical unauthenticated file‑upload bug lets attackers deploy PHP webshells for site takeover</strong></li><li><strong>Patch released in Feb 2026 (v2.0.3.2); Wordfence blocked 100,000+ attacks, users urged to update and check uploads</strong></li></ul><p>A critical vulnerability in a popular WooCommerce plugin is being actively exploited to upload malware and possibly take over entire websites, security experts have warned.</p><p>The plugin in question is called Wholesale Lead Capture Plugin for WooCommerce. It adds a dedicated registration and onboarding system for wholesale and B2B customers, letting businesses collect company and other custom information, review applications, assign wholesale user roles, and automate registration and onboarding emails.</p><p>It is a premium plugin that costs between $99 and $600 and which, according to the <a href="https://wordpress.org/plugins/woocommerce-wholesale-prices/" target="_blank" rel="nofollow"><u>Wordpress store page</u></a>, has more than 20,000 active installations.</p><h2 id="a-thousand-victims-2">A thousand victims</h2><p>The plugin was vulnerable to an unauthenticated arbitrary file-upload flaw which, as the name suggests, allows unauthenticated parties to upload arbitrary files, including PHP webshells and executable code that can result in full site takeover. It is tracked as CVE-2026-27540 and carries a severity score of 9.0/10 (critical). </p><p>Versions 2.0.3.1 and older were said to be affected. Version 2.0.3.2, released on February 20, was said to have addressed the bug, meaning the patch has been available for almost half a year. However, WordPress security outfit Defiant said its Wordfence web application firewall blocked more than 100,000 attacks, and Wordfence added that it observed two attack spikes - one between June 4 and 17, and another one between July 1 and August 30. </p><p>In these incidents, the attackers were mostly uploading reconnaissance webshells, possibly mapping out the landscape before deploying more serious malware. </p><p>“The uploaded shell.php is a PHP webshell that reports host details and provides a browser-based upload form for writing additional malicious files to the site,” the researchers said. </p><p>If you are running the plugin, it is advised you update it to the newest version as soon as possible, and check upload directories for unexpected, or recently created, PHP files.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-via-third-party-woocommerce-plugin/" target="_blank" rel="nofollow"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Chrome and Edge browsers hijacked by KREMLIN malware for credential and token session theft ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Elastic Security Labs uncovered REF9334, a Brazilian banking malware campaign active since May 2025</strong></li><li><strong>Malware “Kremlin” deploys fake docs and malicious Chrome/Edge extensions to steal banking data</strong></li><li><strong>1,515 infections found, 98% in Brazil</strong></li></ul><p>Security researchers from Elastic Security Labs have discovered a new Brazilian banking malware campaign that uses browser extensions to compromise users and steal sensitive information.</p><p>In an in-depth report published earlier this week, the researchers said the campaign has been active since at least May 2025. Dubbed REF9334, the campaign uses fake banking, invoice, and business documents, to trick victims into installing <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> which, in turn, deploys a malicious extension in Chrome and Edge <a href="https://www.techradar.com/best/browser" target="_blank">browsers</a>. </p><p>The researchers named the malware “Kremlin”, and say it can steal browser credentials, cookies, session information, monitor browser activity, grab screenshots, and steal information from websites that the victims visit. But the goal of the campaign is primarily to target Brazilian bank users. </p><h2 id="a-thousand-victims-3">A thousand victims</h2><p>The malware really makes an effort to hide and persist in the target environment. For example, it first checks to see if it’s in a sandbox and if so - it simply won’t run. If instead it determines that it’s running on a real user’s computer, it will deploy an extension with the name “AVSync System Inc.” in an attempt to trick the victim into thinking they have an antivirus addon running in the browser.</p><p>It also doesn’t use a fixed C2 server, but rather stores the information on the Ethereum blockchain, since it’s a lot harder to disrupt the communication between the operators and the infected machines that way. </p><p>During their investigation, Elastic researchers were able to take control of a domain that the malware used and discovered that it had infected 1,515 systems. Almost all of them (98%) were located in Brazil. They were also able to register the network canary domain and point it to their webhost, which resulted in the loader assuming it was in a sandbox. This also meant “the infections have not moved past the initial access”, Elastic explained.</p><p>The full list of indicators of compromise can be found on <a href="https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware" target="_blank" rel="nofollow">this link</a>.</p><p><em>Via </em><a href="https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/chrome-and-edge-browsers-hijacked-by-kremlin-malware-for-credential-and-token-session-theft</link>
                                                                            <description>
                            <![CDATA[ The KREMLIN malware has nothing to do with Russia - it is a Brazilian campaign. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mnwHEr2uG295Cmyv6S5gF4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Sep 2026 10:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:description>                                                            <media:text><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:text>
                                <media:title type="plain"><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Elastic Security Labs uncovered REF9334, a Brazilian banking malware campaign active since May 2025</strong></li><li><strong>Malware “Kremlin” deploys fake docs and malicious Chrome/Edge extensions to steal banking data</strong></li><li><strong>1,515 infections found, 98% in Brazil</strong></li></ul><p>Security researchers from Elastic Security Labs have discovered a new Brazilian banking malware campaign that uses browser extensions to compromise users and steal sensitive information.</p><p>In an in-depth report published earlier this week, the researchers said the campaign has been active since at least May 2025. Dubbed REF9334, the campaign uses fake banking, invoice, and business documents, to trick victims into installing <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> which, in turn, deploys a malicious extension in Chrome and Edge <a href="https://www.techradar.com/best/browser" target="_blank">browsers</a>. </p><p>The researchers named the malware “Kremlin”, and say it can steal browser credentials, cookies, session information, monitor browser activity, grab screenshots, and steal information from websites that the victims visit. But the goal of the campaign is primarily to target Brazilian bank users. </p><h2 id="a-thousand-victims-3">A thousand victims</h2><p>The malware really makes an effort to hide and persist in the target environment. For example, it first checks to see if it’s in a sandbox and if so - it simply won’t run. If instead it determines that it’s running on a real user’s computer, it will deploy an extension with the name “AVSync System Inc.” in an attempt to trick the victim into thinking they have an antivirus addon running in the browser.</p><p>It also doesn’t use a fixed C2 server, but rather stores the information on the Ethereum blockchain, since it’s a lot harder to disrupt the communication between the operators and the infected machines that way. </p><p>During their investigation, Elastic researchers were able to take control of a domain that the malware used and discovered that it had infected 1,515 systems. Almost all of them (98%) were located in Brazil. They were also able to register the network canary domain and point it to their webhost, which resulted in the loader assuming it was in a sandbox. This also meant “the infections have not moved past the initial access”, Elastic explained.</p><p>The full list of indicators of compromise can be found on <a href="https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware" target="_blank" rel="nofollow">this link</a>.</p><p><em>Via </em><a href="https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'New arena for strategic rivalry': China’s intelligence chief calls for regulations and guardrails on AI to prevent new arms race ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>China’s state security minister Chen Yixin urged global AI guardrails, calling it a new arms race</strong></li><li><strong>He outlined five risks: ideological manipulation, infrastructure attacks, data leaks, development gaps, and espionage</strong></li><li><strong>US officials likewise warn against losing AI dominance to China, intensifying geopolitical rivalry</strong></li></ul><p>China’s Minister of State Security has called for global regulation and guardrails on Artificial Intelligence (AI), as the nascent technology turns into a “new arena for strategic rivalry among major powers”. In other words, the AI race is the new arms race and humanity needs rules before it spirals out of control.</p><p>Chen Yixin made the claims in a new article on China Cyberspace, a journal run by internet watchdog body the Cyberspace Administration of China. </p><p>In the article, Chen highlighted five key risks of <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI development</a>:</p><ol start="1"><li>Ideological security risk</li><li>Critical information infrastructure risk</li><li>Data leaks risk</li><li>Development gap risk</li><li>Espionage risk</li></ol><h2 id="ideological-security-risk">Ideological security risk</h2><p>Artificial Intelligence could be “leveraged by hostile forces” to create fake news and other harmful information, systematically creating discontent and dividing the population, Chen said. </p><p>Discussing risks to critical information infrastructure, he said that as models advance, the barrier to entry lowers, making disruptive cyberattacks quicker and easier to pull off. </p><p>“Foreign intelligence agencies are heavily exploiting smart web crawlers, data mining and profiling technologies to harvest sensitive information, including critical state data, business secrets, and personal information,” he said.</p><p>He also warned that people are recklessly sharing sensitive data with foreign AI tools, which could result in catastrophic data leaks. Apparently, open source agents like OpenClaw often come with vulnerabilities that could result in remotely-triggered data spills. </p><p>When it comes to the development gap risk, Yixin warned that a handful of major players are severing the global AI supply chain and creating a monopoly of closed-source ecosystems. Finally, he urged for the creation of early-warning mechanisms and public advisories which should name and shame foreign nation-state actors using AI for espionage, data theft, and disinformation campaigns.</p><h2 id="us-vs-china">US vs China</h2><p>Expectedly, Yixin did not name any specific countries, but it’s easy to read the United States’ name between the lines, the <a href="https://www.scmp.com/news/china/politics/article/3367349/chinas-intelligence-chief-warns-risks-ai-new-arena-strategic-rivalry" target="_blank"><em>South China Morning Post</em></a> hints in its report, adding that the US administration recently warned it could not allow China surpassing it on AI development.</p><p>Indeed, less than a week ago, US Treasury Secretary Scott Bessent said the country would face dire consequences should it lose the AI race against China. "There is no day after tomorrow if China wins at this," Bessent said at a Breitbart News event in Washington, <a href="https://www.bloomberg.com/news/articles/2026-09-09/bessent-warns-nothing-would-matter-if-china-wins-the-ai-race" target="_blank" rel="nofollow"><em>Bloomberg</em> reported</a>. "If they were to pull away from us on AI, then nothing else would matter."</p><p>The US has been at a trade war with China (among other countries) for years now. During Donald Trump’s first term, he blacklisted numerous Chinese hardware manufacturers, warning that Chinese-built 5G infrastructure could be abused to install backdoors and allow the Chinese government to spy on US communications. Huawei, ZTE, and TikTok bore the brunt of these accusations, which the Chinese government vehemently denied. </p><p>In his second term, Trump also declared a national emergency and <a href="https://www.techradar.com/pro/security/trump-signs-order-banning-some-foreign-equipment-from-us-energy-grid-including-some-software" target="_blank">banned all foreign bulk-power systems</a> from being imported, installed, or used in the country. In a signed executive order, Trump said that during his first term, he found “that the bulk-power system could be a target of those seeking to commit malicious acts against the United States, including malicious cyber activities, because of the significant risks that a successful attack would have on our economy, human health and safety, and national defense.” </p><p>President Trump also said there were “minimal restrictions” on both acquisition and operation of these foreign-produced systems. As a result, the situation “constitutes an unusual and extraordinary threat … to the national security, foreign policy, and economy of the United States.”</p><p>While the AI race is intensifying, developers are calling for a slowdown and better guardrails. Some developers estimated that AI could end humanity in a few decades, urging the industry to slow down and only develop systems they are confident they can control.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/new-arena-for-strategic-rivalry-chinas-intelligence-chief-calls-for-regulations-and-guardrails-on-ai-to-prevent-new-arms-race</link>
                                                                            <description>
                            <![CDATA[ AI comes with great risks which need to be managed, China's Minister of State Security says ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fkwbdbpZTyowCu5qMq26n6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3xYAE75gYrzr4hTu3ssyhj-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 15 Sep 2026 18:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/3xYAE75gYrzr4hTu3ssyhj-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Robotic hand interacting with a digital display showing various military equipment, defense systems, drones and cybersecurity elements and data visualization in a dark environment.]]></media:description>                                                            <media:text><![CDATA[Robotic hand interacting with a digital display showing various military equipment, defense systems, drones and cybersecurity elements and data visualization in a dark environment.]]></media:text>
                                <media:title type="plain"><![CDATA[Robotic hand interacting with a digital display showing various military equipment, defense systems, drones and cybersecurity elements and data visualization in a dark environment.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3xYAE75gYrzr4hTu3ssyhj-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>China’s state security minister Chen Yixin urged global AI guardrails, calling it a new arms race</strong></li><li><strong>He outlined five risks: ideological manipulation, infrastructure attacks, data leaks, development gaps, and espionage</strong></li><li><strong>US officials likewise warn against losing AI dominance to China, intensifying geopolitical rivalry</strong></li></ul><p>China’s Minister of State Security has called for global regulation and guardrails on Artificial Intelligence (AI), as the nascent technology turns into a “new arena for strategic rivalry among major powers”. In other words, the AI race is the new arms race and humanity needs rules before it spirals out of control.</p><p>Chen Yixin made the claims in a new article on China Cyberspace, a journal run by internet watchdog body the Cyberspace Administration of China. </p><p>In the article, Chen highlighted five key risks of <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI development</a>:</p><ol start="1"><li>Ideological security risk</li><li>Critical information infrastructure risk</li><li>Data leaks risk</li><li>Development gap risk</li><li>Espionage risk</li></ol><h2 id="ideological-security-risk">Ideological security risk</h2><p>Artificial Intelligence could be “leveraged by hostile forces” to create fake news and other harmful information, systematically creating discontent and dividing the population, Chen said. </p><p>Discussing risks to critical information infrastructure, he said that as models advance, the barrier to entry lowers, making disruptive cyberattacks quicker and easier to pull off. </p><p>“Foreign intelligence agencies are heavily exploiting smart web crawlers, data mining and profiling technologies to harvest sensitive information, including critical state data, business secrets, and personal information,” he said.</p><p>He also warned that people are recklessly sharing sensitive data with foreign AI tools, which could result in catastrophic data leaks. Apparently, open source agents like OpenClaw often come with vulnerabilities that could result in remotely-triggered data spills. </p><p>When it comes to the development gap risk, Yixin warned that a handful of major players are severing the global AI supply chain and creating a monopoly of closed-source ecosystems. Finally, he urged for the creation of early-warning mechanisms and public advisories which should name and shame foreign nation-state actors using AI for espionage, data theft, and disinformation campaigns.</p><h2 id="us-vs-china">US vs China</h2><p>Expectedly, Yixin did not name any specific countries, but it’s easy to read the United States’ name between the lines, the <a href="https://www.scmp.com/news/china/politics/article/3367349/chinas-intelligence-chief-warns-risks-ai-new-arena-strategic-rivalry" target="_blank"><em>South China Morning Post</em></a> hints in its report, adding that the US administration recently warned it could not allow China surpassing it on AI development.</p><p>Indeed, less than a week ago, US Treasury Secretary Scott Bessent said the country would face dire consequences should it lose the AI race against China. "There is no day after tomorrow if China wins at this," Bessent said at a Breitbart News event in Washington, <a href="https://www.bloomberg.com/news/articles/2026-09-09/bessent-warns-nothing-would-matter-if-china-wins-the-ai-race" target="_blank" rel="nofollow"><em>Bloomberg</em> reported</a>. "If they were to pull away from us on AI, then nothing else would matter."</p><p>The US has been at a trade war with China (among other countries) for years now. During Donald Trump’s first term, he blacklisted numerous Chinese hardware manufacturers, warning that Chinese-built 5G infrastructure could be abused to install backdoors and allow the Chinese government to spy on US communications. Huawei, ZTE, and TikTok bore the brunt of these accusations, which the Chinese government vehemently denied. </p><p>In his second term, Trump also declared a national emergency and <a href="https://www.techradar.com/pro/security/trump-signs-order-banning-some-foreign-equipment-from-us-energy-grid-including-some-software" target="_blank">banned all foreign bulk-power systems</a> from being imported, installed, or used in the country. In a signed executive order, Trump said that during his first term, he found “that the bulk-power system could be a target of those seeking to commit malicious acts against the United States, including malicious cyber activities, because of the significant risks that a successful attack would have on our economy, human health and safety, and national defense.” </p><p>President Trump also said there were “minimal restrictions” on both acquisition and operation of these foreign-produced systems. As a result, the situation “constitutes an unusual and extraordinary threat … to the national security, foreign policy, and economy of the United States.”</p><p>While the AI race is intensifying, developers are calling for a slowdown and better guardrails. Some developers estimated that AI could end humanity in a few decades, urging the industry to slow down and only develop systems they are confident they can control.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>