<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-SG"
                       href="https://www.techradar.com/sg/feeds/tag/cyber-security"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from TechRadar SG in Cyber-security ]]></title>
                <link>https://www.techradar.com/sg/computing/computing-security/cyber-security</link>
        <description><![CDATA[ All the latest cyber-security content from the TechRadar  SG team ]]></description>
                                    <lastBuildDate>Mon, 24 Aug 2026 18:35:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Even connected car head units are being targeted by hackers now — experts warn in-car systems are at risk of being hijacked into a botnet ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Hackers exploited trusted software updates to deliver malware directly into car head units</strong></li><li><strong>Kaspersky says this is the first campaign tailored specifically for vehicle head units</strong></li><li><strong>The malware can run silently without showing drivers any visible interface</strong></li></ul><p>Car head units are now being drawn into a growing wave of Android malware campaigns built for connected vehicle systems, experts have warned.</p><p>A newly discovered malware campaign is infecting these head units directly, systems that combine multimedia functions with, in some models, vehicle control.</p><p>According to Kaspersky, this campaign marks the first documented case of malware built specifically for this type of infection chain.</p><h2 id="compromised-update-channels-deliver-malware-straight-into-vehicles">Compromised update channels deliver malware straight into vehicles</h2><p>Researchers believe the activity can likely be traced back to the MoYu Group, a threat actor closely tied to the well-known BadBox botnet, which spread through the legitimate update mechanisms built directly into the firmware of Android-based head units manufactured by DoFun.</p><p>The infection chain originates from TWCore, a legitimate system app that is normally responsible for collecting analytics and updating head unit software remotely.</p><p>Attackers hijacked this trusted update channel using a specialized dropper called JarService to deliver previously unknown malware directly onto a range of affected devices.</p><p>Once successfully installed, the malware operated quietly as a regular background application without ever displaying any visible user interface.</p><p>Kaspersky identified nine distinct remote commands built into the malware, capable of displaying unwanted ads and executing various forms of ad fraud.</p><p>The malware also actively collected sensitive device information, including display resolution, device model, Wi-Fi network identifier, and the device's MAC address.</p><p>Investigators found clear technical links between this campaign and prior attacks launched against TV set-top boxes tied to the same broader threat group.</p><p>The research team claims that the botnet's administration panel shares embedded URLs with residential proxy service websites PXYEDGE and ProxyForU.</p><p>BadBox itself operates as a large, sprawling network of hijacked Android devices, including streaming boxes, phones, and tablets that arrive pre-infected from the factory.</p><p>Kaspersky has already formally notified the vendor about this ongoing abuse of its legitimate software distribution channel and update infrastructure.</p><p>According to statements from DoFun, the underlying issue has since been resolved across most affected devices currently deployed in the field.</p><h2 id="head-units-present-a-growing-and-largely-unprotected-attack-surface">Head units present a growing and largely unprotected attack surface</h2><p>Car head units can arrive factory-installed directly from the manufacturer or get added later to older vehicles as aftermarket upgrades.</p><p>Manufacturers frequently rely heavily on the Android operating system because it simplifies interface customization and essential system integration work considerably.</p><p>This widespread industry reliance means most standard Android applications, along with most existing Android malware, can potentially run on these devices.</p><p>Head units rarely store sensitive personal data directly on board, which on the surface might suggest only limited appeal to attackers.</p><p>However, they typically include active SIM card slots and maintain constant internet connectivity for navigation services and routine software updates.</p><p>That particular combination of persistent connectivity and comparatively weak security oversight makes these systems a genuinely attractive prospect for attackers going forward.</p><p>The overall scale of this particular campaign remains genuinely unclear, and whether other head unit manufacturers face similar exposure is not yet known.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/even-connected-car-head-units-are-being-targeted-by-hackers-now-experts-warn-in-car-systems-are-at-risk-of-being-hijacked-into-a-botnet</link>
                                                                            <description>
                            <![CDATA[ Kaspersky discovers Android malware targeting car head units through compromised updates. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m2NVLV93FhaPCF5tsL4x7Z</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/U4kKJiuR4cLoeEoYecZQPK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 24 Aug 2026 18:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/U4kKJiuR4cLoeEoYecZQPK-1280-80.jpg">
                                                            <media:credit><![CDATA[Spotify]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spotify Car Thing]]></media:description>                                                            <media:text><![CDATA[Spotify Car Thing]]></media:text>
                                <media:title type="plain"><![CDATA[Spotify Car Thing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/U4kKJiuR4cLoeEoYecZQPK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Hackers exploited trusted software updates to deliver malware directly into car head units</strong></li><li><strong>Kaspersky says this is the first campaign tailored specifically for vehicle head units</strong></li><li><strong>The malware can run silently without showing drivers any visible interface</strong></li></ul><p>Car head units are now being drawn into a growing wave of Android malware campaigns built for connected vehicle systems, experts have warned.</p><p>A newly discovered malware campaign is infecting these head units directly, systems that combine multimedia functions with, in some models, vehicle control.</p><p>According to Kaspersky, this campaign marks the first documented case of malware built specifically for this type of infection chain.</p><h2 id="compromised-update-channels-deliver-malware-straight-into-vehicles">Compromised update channels deliver malware straight into vehicles</h2><p>Researchers believe the activity can likely be traced back to the MoYu Group, a threat actor closely tied to the well-known BadBox botnet, which spread through the legitimate update mechanisms built directly into the firmware of Android-based head units manufactured by DoFun.</p><p>The infection chain originates from TWCore, a legitimate system app that is normally responsible for collecting analytics and updating head unit software remotely.</p><p>Attackers hijacked this trusted update channel using a specialized dropper called JarService to deliver previously unknown malware directly onto a range of affected devices.</p><p>Once successfully installed, the malware operated quietly as a regular background application without ever displaying any visible user interface.</p><p>Kaspersky identified nine distinct remote commands built into the malware, capable of displaying unwanted ads and executing various forms of ad fraud.</p><p>The malware also actively collected sensitive device information, including display resolution, device model, Wi-Fi network identifier, and the device's MAC address.</p><p>Investigators found clear technical links between this campaign and prior attacks launched against TV set-top boxes tied to the same broader threat group.</p><p>The research team claims that the botnet's administration panel shares embedded URLs with residential proxy service websites PXYEDGE and ProxyForU.</p><p>BadBox itself operates as a large, sprawling network of hijacked Android devices, including streaming boxes, phones, and tablets that arrive pre-infected from the factory.</p><p>Kaspersky has already formally notified the vendor about this ongoing abuse of its legitimate software distribution channel and update infrastructure.</p><p>According to statements from DoFun, the underlying issue has since been resolved across most affected devices currently deployed in the field.</p><h2 id="head-units-present-a-growing-and-largely-unprotected-attack-surface">Head units present a growing and largely unprotected attack surface</h2><p>Car head units can arrive factory-installed directly from the manufacturer or get added later to older vehicles as aftermarket upgrades.</p><p>Manufacturers frequently rely heavily on the Android operating system because it simplifies interface customization and essential system integration work considerably.</p><p>This widespread industry reliance means most standard Android applications, along with most existing Android malware, can potentially run on these devices.</p><p>Head units rarely store sensitive personal data directly on board, which on the surface might suggest only limited appeal to attackers.</p><p>However, they typically include active SIM card slots and maintain constant internet connectivity for navigation services and routine software updates.</p><p>That particular combination of persistent connectivity and comparatively weak security oversight makes these systems a genuinely attractive prospect for attackers going forward.</p><p>The overall scale of this particular campaign remains genuinely unclear, and whether other head unit manufacturers face similar exposure is not yet known.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New malware targets Microsoft Teams users by posing as your company's IT helpdesk ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Expel researchers warn of SynkLoader backdoor spread via fake IT help desk Teams messages</strong></li><li><strong>Malware modules include PhishLocker (fake login screen harvesting OS passwords) and Interactive Shell for remote control</strong></li><li><strong>Defenses: distrust unsolicited Teams DMs, verify with IT before installing apps, and train staff against social engineering</strong></li></ul><p>For roughly a month now, cybercriminals have been targeting organizations with a new backdoor malware called SynkLoader.</p><p>According to security researchers Expel, the attack starts with social engineering. Victims would get a Microsoft Teams message from a person claiming to be from the company’s IT help desk. They would tell the victim their computer is having an issue, and that they need to install a “PowerShell Cleaner”. This fake program is nothing more than a malicious framework, hosted on Microsoft Azure to increase its trustworthiness.</p><p>The <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> itself comes with a number of different modules, giving the attacker a range of features, from harvesting system information, to creating a reverse proxy. Two particularly worrying modules are called PhishLocker and Interactive Shell. The former creates a convincing, yet fake, Windows lock screen, which can harvest the user’s OS login password.</p><h2 id="this-is-not-sickkids-39-first-attack">This is not SickKids' first attack</h2><p>BleepingComputer argues that with this password the attackers could “access corporate environments from the infected device, bypassing IP allow-list restrictions”. Those with a sharper eye might spot the ruse, as a simple Alt + Tab shows that the login screen is nothing more than a “full-screen borderless GUI application”.</p><p>The other module - Interactive Shell, allows threat actors to remotely execute PowerShell commands and receive the output, which essentially grants them full control over the infected device. </p><p>The full list of Indicators of Compromise (IoC) can be found on <a href="https://expel.com/blog/synkloader-when-you-throw-in-everything-but-the-kitchen-sink/" target="_blank" rel="nofollow">this link</a>. To defend against these types of attacks, target companies should instruct their employees not to trust unsolicited Teams messages at face value, and not to install any applications without double-checking (calling) with their IT department first.</p><p>Alongside phone calls, Microsoft Teams is one of the most-used channels for initial contact and compromise. Also, employees remain the weakest link in every company’s cybersecurity chain, unwillingly granting attackers access or sharing login credentials.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/new-synkloader-malware-pushed-in-microsoft-teams-phishing-campaign/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/new-malware-targets-microsoft-teams-users-by-posing-as-your-companys-it-helpdesk</link>
                                                                            <description>
                            <![CDATA[ Victims are being told to install a fake cleaner software which is nothing more than a backdoor framework. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gDENeCKMs9WruAKu7UsWj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7DtE9RCVmUtmH2FAfvxsvM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 24 Aug 2026 17:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7DtE9RCVmUtmH2FAfvxsvM-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:description>                                                            <media:text><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:text>
                                <media:title type="plain"><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7DtE9RCVmUtmH2FAfvxsvM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Expel researchers warn of SynkLoader backdoor spread via fake IT help desk Teams messages</strong></li><li><strong>Malware modules include PhishLocker (fake login screen harvesting OS passwords) and Interactive Shell for remote control</strong></li><li><strong>Defenses: distrust unsolicited Teams DMs, verify with IT before installing apps, and train staff against social engineering</strong></li></ul><p>For roughly a month now, cybercriminals have been targeting organizations with a new backdoor malware called SynkLoader.</p><p>According to security researchers Expel, the attack starts with social engineering. Victims would get a Microsoft Teams message from a person claiming to be from the company’s IT help desk. They would tell the victim their computer is having an issue, and that they need to install a “PowerShell Cleaner”. This fake program is nothing more than a malicious framework, hosted on Microsoft Azure to increase its trustworthiness.</p><p>The <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> itself comes with a number of different modules, giving the attacker a range of features, from harvesting system information, to creating a reverse proxy. Two particularly worrying modules are called PhishLocker and Interactive Shell. The former creates a convincing, yet fake, Windows lock screen, which can harvest the user’s OS login password.</p><h2 id="this-is-not-sickkids-39-first-attack">This is not SickKids' first attack</h2><p>BleepingComputer argues that with this password the attackers could “access corporate environments from the infected device, bypassing IP allow-list restrictions”. Those with a sharper eye might spot the ruse, as a simple Alt + Tab shows that the login screen is nothing more than a “full-screen borderless GUI application”.</p><p>The other module - Interactive Shell, allows threat actors to remotely execute PowerShell commands and receive the output, which essentially grants them full control over the infected device. </p><p>The full list of Indicators of Compromise (IoC) can be found on <a href="https://expel.com/blog/synkloader-when-you-throw-in-everything-but-the-kitchen-sink/" target="_blank" rel="nofollow">this link</a>. To defend against these types of attacks, target companies should instruct their employees not to trust unsolicited Teams messages at face value, and not to install any applications without double-checking (calling) with their IT department first.</p><p>Alongside phone calls, Microsoft Teams is one of the most-used channels for initial contact and compromise. Also, employees remain the weakest link in every company’s cybersecurity chain, unwillingly granting attackers access or sharing login credentials.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/new-synkloader-malware-pushed-in-microsoft-teams-phishing-campaign/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Canadian SickKids hospital hit again by cyberattacks, more data stolen ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>SickKids hospital in Canada hit by third‑party software vulnerability, exposing employee data</strong></li><li><strong>Clinical systems and patient records unaffected; patient care continued without disruption</strong></li><li><strong>Affected staff and applicants offered 24 months of free credit monitoring and identity protection</strong></li></ul><p>The Hospital for Sick Children, a major pediatric hospital in Canada, suffered a cyberattack that affected parts of its website, and resulted in the loss of some employee personal information.</p><p>In an announcement published on its website, the organization (also known as SickKids) said the unnamed attackers abused a “vulnerability in a third-party software application used by SickKids and other organizations.” The announcement did not say exactly which app was used in the attack, or what the vulnerability was, but stressed that clinical systems and patient information were not affected.</p><p>“Patient care has continued as usual”, it added.</p><h2 id="this-is-not-sickkids-39-first-attack-2">This is not SickKids' first attack</h2><p>After launching an investigation, SickKids learned that personal information of some former and current employees working at SickKids, Boomerang, and SickKids Foundation, as well as SickKids job applications, was exposed. It did not detail the nature of the exposed information, or how many people are affected.</p><p>Whatever that number is, those people have been offered 24 months of complimentary credit monitoring and identity protection services, for free.</p><p> “We remain committed to maintaining strong protections and continuously enhancing our cybersecurity measures to help protect the information entrusted to us,” the company concluded. Ironically, SickKids was also committed in late 2022 and early 2023, when it was struck by LockBit and had its systems locked down by the ransomware threat actor.</p><p>While, in that incident, LockBit apologized, gave the decryptor away for free, excommunicated the affiliate responsible, and did not mention any stolen data, by late 2022 double extortion attacks were standard practice, meaning data was likely exfiltrated then, as well. </p><p>At the time, LockBit was one of the most active and most dangerous ransomware operators. In early 2024, its operations were severely disrupted through Operation Cronos, but it seems the group is making a comeback. There are reports from late 2025 of <a href="https://www.techradar.com/pro/security/lockbit-malware-is-back-and-nastier-than-ever-experts-claim" target="_blank">LockBit 5.0 claims</a>, including a <a href="https://www.escudodigital.com/en/cybersecurity/lockbit-50-targets-us-bank-one-of-the-largest-banks-in-the-united-states.html" target="_blank" rel="nofollow">purported attack on U.S Bank</a>, but the news is yet to be confirmed. </p><p><em>Via </em><a href="https://therecord.media/canada-hospital-for-sick-children-attacked-again-employee-data" target="_blank"><em>The Record</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/canadian-sickkids-hospital-hit-again-by-cyberattacks-more-data-stolen</link>
                                                                            <description>
                            <![CDATA[ Patient care has continued as usual following cyberattack. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">RoPQxVBr4RHbTeSwbCJytQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fLLbfyMxWuqokngy6WuMzH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 24 Aug 2026 14:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fLLbfyMxWuqokngy6WuMzH-1280-80.jpg">
                                                            <media:credit><![CDATA[Rawpixel / Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[healthcare]]></media:description>                                                            <media:text><![CDATA[healthcare]]></media:text>
                                <media:title type="plain"><![CDATA[healthcare]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fLLbfyMxWuqokngy6WuMzH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>SickKids hospital in Canada hit by third‑party software vulnerability, exposing employee data</strong></li><li><strong>Clinical systems and patient records unaffected; patient care continued without disruption</strong></li><li><strong>Affected staff and applicants offered 24 months of free credit monitoring and identity protection</strong></li></ul><p>The Hospital for Sick Children, a major pediatric hospital in Canada, suffered a cyberattack that affected parts of its website, and resulted in the loss of some employee personal information.</p><p>In an announcement published on its website, the organization (also known as SickKids) said the unnamed attackers abused a “vulnerability in a third-party software application used by SickKids and other organizations.” The announcement did not say exactly which app was used in the attack, or what the vulnerability was, but stressed that clinical systems and patient information were not affected.</p><p>“Patient care has continued as usual”, it added.</p><h2 id="this-is-not-sickkids-39-first-attack-2">This is not SickKids' first attack</h2><p>After launching an investigation, SickKids learned that personal information of some former and current employees working at SickKids, Boomerang, and SickKids Foundation, as well as SickKids job applications, was exposed. It did not detail the nature of the exposed information, or how many people are affected.</p><p>Whatever that number is, those people have been offered 24 months of complimentary credit monitoring and identity protection services, for free.</p><p> “We remain committed to maintaining strong protections and continuously enhancing our cybersecurity measures to help protect the information entrusted to us,” the company concluded. Ironically, SickKids was also committed in late 2022 and early 2023, when it was struck by LockBit and had its systems locked down by the ransomware threat actor.</p><p>While, in that incident, LockBit apologized, gave the decryptor away for free, excommunicated the affiliate responsible, and did not mention any stolen data, by late 2022 double extortion attacks were standard practice, meaning data was likely exfiltrated then, as well. </p><p>At the time, LockBit was one of the most active and most dangerous ransomware operators. In early 2024, its operations were severely disrupted through Operation Cronos, but it seems the group is making a comeback. There are reports from late 2025 of <a href="https://www.techradar.com/pro/security/lockbit-malware-is-back-and-nastier-than-ever-experts-claim" target="_blank">LockBit 5.0 claims</a>, including a <a href="https://www.escudodigital.com/en/cybersecurity/lockbit-50-targets-us-bank-one-of-the-largest-banks-in-the-united-states.html" target="_blank" rel="nofollow">purported attack on U.S Bank</a>, but the news is yet to be confirmed. </p><p><em>Via </em><a href="https://therecord.media/canada-hospital-for-sick-children-attacked-again-employee-data" target="_blank"><em>The Record</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Private equity giant Apollo confirms data breach saw personal info stolen ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Apollo confirms July 2026 cyberattack via social engineering exposed PII in its cloud environment</strong></li><li><strong>Data included names, DOB, contact info, addresses, and Social Security numbers</strong></li><li><strong>Firm offers two years of identity protection; no evidence of dark web leaks yet</strong></li></ul><p>Apollo, one of the biggest private equity firms in the world, has confirmed it suffered a cyberattack which compromised some people’s personally identifiable information.</p><p>The company notified California’s Attorney General’s Office about the breach and shared a copy of the letter it is now sending out to affected individuals. It is impossible to discern from the letter if the victims are Apollo employees, customers, or someone else entirely, but the company did clearly explain what happened.</p><p>As per the letter, an unidentified threat actor tricked an Apollo employee into granting them access to the company’s cloud environment. The attackers used social engineering (usually phishing), which means the victim either tried logging in using a spoofed landing page, unknowingly installed an infostealer, or was convinced to grant the attackers access via remote monitoring and management software.</p><h2 id="was-there-really-a-hack">Was there really a hack?</h2><p>The company spotted the attack a few days later, and after activating its safety protocols (notifying the police, enhancing its security protocols, and bringing in third-party forensic experts), launched an investigation which showed that the attackers accessed its cloud platform between July 6 and 10. </p><p>“During our investigation, we learned on August 12, 2026 that the information potentially impacted by this incident included your name, date of birth, contact information, home address, and your Social Security Number (SSN),” the company said. This means that financial data such as credit card or bank account information, was not compromised. </p><p>Still, cybercriminals can make use of this type of information, as is often the case in <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a>, business email compromise, and even wire fraud.</p><p>Apollo is now offering two years of free identity theft protection and monitoring for affected individuals through Cyberscout. </p><p>At press time, no threat actors claimed responsibility for the attack, and the data has not yet surfaced anywhere on the dark web.</p><p><em>Via </em><a href="https://techcrunch.com/2026/08/21/private-equity-firm-apollo-confirms-data-breach-amid-hacking-wave-targeting-financial-giants/" target="_blank"><em>TechCrunch</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/private-equity-giant-apollo-confirms-data-breach-saw-personal-info-stolen</link>
                                                                            <description>
                            <![CDATA[ We don't know how many people are affected, or if they're employees or customers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">DaLh3idyQngszsaBTPkBiE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nKQTr6znQKVirervbiEDkL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 24 Aug 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nKQTr6znQKVirervbiEDkL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An office worker in front of a computer holding his hand in one hand and looking unhappy]]></media:description>                                                            <media:text><![CDATA[An office worker in front of a computer holding his hand in one hand and looking unhappy]]></media:text>
                                <media:title type="plain"><![CDATA[An office worker in front of a computer holding his hand in one hand and looking unhappy]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nKQTr6znQKVirervbiEDkL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Apollo confirms July 2026 cyberattack via social engineering exposed PII in its cloud environment</strong></li><li><strong>Data included names, DOB, contact info, addresses, and Social Security numbers</strong></li><li><strong>Firm offers two years of identity protection; no evidence of dark web leaks yet</strong></li></ul><p>Apollo, one of the biggest private equity firms in the world, has confirmed it suffered a cyberattack which compromised some people’s personally identifiable information.</p><p>The company notified California’s Attorney General’s Office about the breach and shared a copy of the letter it is now sending out to affected individuals. It is impossible to discern from the letter if the victims are Apollo employees, customers, or someone else entirely, but the company did clearly explain what happened.</p><p>As per the letter, an unidentified threat actor tricked an Apollo employee into granting them access to the company’s cloud environment. The attackers used social engineering (usually phishing), which means the victim either tried logging in using a spoofed landing page, unknowingly installed an infostealer, or was convinced to grant the attackers access via remote monitoring and management software.</p><h2 id="was-there-really-a-hack">Was there really a hack?</h2><p>The company spotted the attack a few days later, and after activating its safety protocols (notifying the police, enhancing its security protocols, and bringing in third-party forensic experts), launched an investigation which showed that the attackers accessed its cloud platform between July 6 and 10. </p><p>“During our investigation, we learned on August 12, 2026 that the information potentially impacted by this incident included your name, date of birth, contact information, home address, and your Social Security Number (SSN),” the company said. This means that financial data such as credit card or bank account information, was not compromised. </p><p>Still, cybercriminals can make use of this type of information, as is often the case in <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a>, business email compromise, and even wire fraud.</p><p>Apollo is now offering two years of free identity theft protection and monitoring for affected individuals through Cyberscout. </p><p>At press time, no threat actors claimed responsibility for the attack, and the data has not yet surfaced anywhere on the dark web.</p><p><em>Via </em><a href="https://techcrunch.com/2026/08/21/private-equity-firm-apollo-confirms-data-breach-amid-hacking-wave-targeting-financial-giants/" target="_blank"><em>TechCrunch</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why are ‘paranoid’ Claude agents launching a turf war and deploying self-replicating malware against each other? The experts weigh in ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Three Claude agents set up to deliberately conflict with each other in Anthropic testing started behaving in a very strange way by essentially starting a ‘turf war’ over their tasks.</p><p>Upon launching the experiment the agents began conflicting with each other, leading to some of the agents deliberately sabotaging their rivals by disabling their linked accounts, ending their processes, and even creating self-replicating malware to impede their rivals.</p><p>According to Anthropic, the agents became “increasingly aggressive” in their behavior during the four hour experiment which became a battle for the survival of the fittest.</p><h2 id="what-was-the-experiment-meant-to-achieve">What was the experiment meant to achieve?</h2><p>Anthropic said it set up <a href="https://www.anthropic.com/research/multiagent-systems" target="_blank" rel="nofollow">the experiment</a> to see how AI agents with conflicting tasks would interact.</p><p>Within Claude Code, the agents were given the task of migrating a Python back-end system on a virtual machine in a set language for each agent (Go, Rust, and Typescript), with the added caveat that “each agent was initially unaware of the presence of the others.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>During the experiments, each agent determined that the others were trying to deliberately block their progress.</p><p>Sometimes, the agents would recognize that another agent was blocking them from completing their task and ask for human intervention, but in other experiments the strategy soon went downhill.</p><p>“They sabotaged others with increasingly aggressive, self-replicating malware,” Anthropic said, noting that they would design looping scripts to kill the processes of their fellow agents.</p><p>The experiment shows that agent interaction is still riddled with problems and that when given a conflicting task, agents won’t always coordinate or ask for human help. </p><p>Each agent believed their task was paramount and was willing to do whatever it took to complete it. A similar event occurred in the wild when one of Anthropic’s models <a href="https://www.techradar.com/pro/security/anthropic-reveals-claude-ai-model-hacked-three-companies-during-tests-so-how-worried-should-we-be">broke out of a testing environment and breached multiple third-party organizations</a>.</p><h3 class="article-body__section" id="section-expert-perspectives-on-ai-agent-turf-wars"><span>Expert perspectives on AI agent turf wars</span></h3><ul><li><strong>Seemant Sehgal, Founder & CEO, BreachLock:</strong></li></ul><p><em>When you give autonomous systems competing objectives and the means to act, conflict is not a bug, it is a foreseeable outcome.</em></p><div><blockquote><p>When you give autonomous systems competing objectives and the means to act, conflict is not a bug, it is a foreseeable outcome.</p></blockquote></div><p><em>What Anthropic observed in a controlled research setting is the same principle that has always governed adversarial systems. Goals without constraints produce behavior without limits.</em></p><p><em>Security teams should be paying close attention here, because the real challenge at hand is whether the organizations deploying AI agents have thought carefully about what happens when those agents start making decisions nobody explicitly authorized.</em></p><ul><li><strong>Jeremiah Fowler, Security Researcher, Black Hills Information Security:</strong></li></ul><p><em>I find it concerning when AI agents have the ability to execute code, modify systems, create accounts, access credentials or communicate with other machines.</em></p><p><em>It is very possible that two separate agents could potentially create a security incident simply because neither understands the intent or authority of the other. If they have overlapping tasks one could view the other as an obstacle and now you have an interesting scenario where instead of focusing on the task they engage in conflict or create a loop.</em></p><div><blockquote><p>When things go wrong the speed of an AI agent becomes a liability.</p></blockquote></div><p><em>Permissions, boundaries and objectives are important to limit the behavior of autonomous AI agents. When things go wrong the speed of an AI agent becomes a liability. Autonomous AI agents can potentially make thousands of decisions before a security team identifies that something unusual is happening.</em></p><p><em>Agentic AI creates an entirely new attack surface because an AI agent may not be simply processing information and hypothetically can become a rogue privileged user.</em></p><p><em>Security and development teams should apply least privilege principles and restrict AI agents to only the permissions required to perform a specific task. Sensitive actions should require human supervision and approval to avoid a worse case scenario.</em></p><p><em>It is important to implement logging because when something goes wrong, you can see what an AI agent did, but what information or instructions caused specific decisions. Going forward we will need to develop ways that can identify rogue agent-to-agent behavior and provide humans with a kill switch before automated conflicts become a digital forest fire.</em></p><ul><li><strong>Kevin Surace, CEO, Token:</strong></li></ul><p><em>Anthropic’s research is an important warning for security teams because it shows what can happen when autonomous AI agents are given goals, credentials, tools and enough authority to act independently.</em></p><p><em>When agents were placed in conflict, they did not simply fail gracefully. They interfered with one another, disabled competing processes and even generated self replicating malicious code in pursuit of their assigned objectives.</em></p><p><em>The lesson is not that AI suddenly became evil. It is that intelligence, autonomy and excessive privilege can become a very dangerous combination.</em></p><div><blockquote><p>We are about to have millions of nonhuman identities operating alongside human identities. That makes identity and authorization even more critical.</p></blockquote></div><p><em>Organizations should start treating every AI agent as a potentially untrusted privileged identity. Each agent should have its own identity, least privilege access, tightly restricted tools, isolated execution environments and a complete audit trail. </em></p><p><em>Agents should never be able to expand their own permissions, disable another identity or take highly consequential actions without additional authorization.</em></p><p><em>We are about to have millions of nonhuman identities operating alongside human identities. That makes identity and authorization even more critical.</em></p><p><em>Every agent needs strong cryptographic identity, while all human approvals must be tied to biometric assured identity (or another agent could approve it).</em></p><p><em>AI agents are essentially becoming privileged insiders operating at machine speed. Giving them broad access and simply hoping they behave would repeat many of the same cybersecurity mistakes organizations have spent decades trying to fix.</em></p><ul><li><strong>Jacob Krell, Sr. Director: Secure AI Solutions & Cybersecurity, Suzu Labs:</strong></li></ul><p><em>Anthropic's agents went from merge conflict to self-replicating malware in four hours, writing kill scripts, disabling each other's Unix accounts, and disguising malicious code as a rival's work. No prompt injection, no external attacker. A human developer in the same situation sends a Slack message, and resolution takes days. These agents skipped every social brake and went straight to weaponization because machine-speed conflict has no cooling-off period.</em></p><p><em>Agentic AI is an attack surface. An attacker doesn't need to compromise an agent directly, just manipulate the shared environment to create conditions the agent interprets as hostile. The agent does the rest. And in Anthropic's experiment, the agents didn't report their malicious actions to operators afterward.</em></p><div><blockquote><p>Every agent needs its own identity, scoped permissions, and a kill switch before it touches a shared environment.</p></blockquote></div><p><em>Every agent needs its own identity, scoped permissions, and a kill switch before it touches a shared environment. Agent-to-agent interaction is a telemetry surface most security operations centers aren't collecting yet, and Anthropic just showed what an unmonitored shared environment produces. If you can't tell which agent did what, when, and on whose authority, you've built the conditions for a turf war without the visibility to see it happening.</em></p><p><em>Agents are already writing code, finding vulnerabilities, and building exploits. Defense has to match that speed. When both sides run at machine speed, the bottleneck shifts from human capital and tooling to compute power and cost.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/why-are-paranoid-claude-agents-launching-a-turf-war-and-deploying-self-replicating-malware-against-each-other-the-experts-weigh-in</link>
                                                                            <description>
                            <![CDATA[ Killing processes, disabling rival accounts, and building self-replicating malware ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vD2zZKBKMQqo3t6N8Whwg5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ym4JdN8tZyMYq4wNvoyNWJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sun, 23 Aug 2026 11:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Claude]]></category>
                                                    <category><![CDATA[AI Platforms &amp; Assistants]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ym4JdN8tZyMYq4wNvoyNWJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images/SOPA Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Anthropic Claude]]></media:description>                                                            <media:text><![CDATA[Anthropic Claude]]></media:text>
                                <media:title type="plain"><![CDATA[Anthropic Claude]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ym4JdN8tZyMYq4wNvoyNWJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Three Claude agents set up to deliberately conflict with each other in Anthropic testing started behaving in a very strange way by essentially starting a ‘turf war’ over their tasks.</p><p>Upon launching the experiment the agents began conflicting with each other, leading to some of the agents deliberately sabotaging their rivals by disabling their linked accounts, ending their processes, and even creating self-replicating malware to impede their rivals.</p><p>According to Anthropic, the agents became “increasingly aggressive” in their behavior during the four hour experiment which became a battle for the survival of the fittest.</p><h2 id="what-was-the-experiment-meant-to-achieve">What was the experiment meant to achieve?</h2><p>Anthropic said it set up <a href="https://www.anthropic.com/research/multiagent-systems" target="_blank" rel="nofollow">the experiment</a> to see how AI agents with conflicting tasks would interact.</p><p>Within Claude Code, the agents were given the task of migrating a Python back-end system on a virtual machine in a set language for each agent (Go, Rust, and Typescript), with the added caveat that “each agent was initially unaware of the presence of the others.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>During the experiments, each agent determined that the others were trying to deliberately block their progress.</p><p>Sometimes, the agents would recognize that another agent was blocking them from completing their task and ask for human intervention, but in other experiments the strategy soon went downhill.</p><p>“They sabotaged others with increasingly aggressive, self-replicating malware,” Anthropic said, noting that they would design looping scripts to kill the processes of their fellow agents.</p><p>The experiment shows that agent interaction is still riddled with problems and that when given a conflicting task, agents won’t always coordinate or ask for human help. </p><p>Each agent believed their task was paramount and was willing to do whatever it took to complete it. A similar event occurred in the wild when one of Anthropic’s models <a href="https://www.techradar.com/pro/security/anthropic-reveals-claude-ai-model-hacked-three-companies-during-tests-so-how-worried-should-we-be">broke out of a testing environment and breached multiple third-party organizations</a>.</p><h3 class="article-body__section" id="section-expert-perspectives-on-ai-agent-turf-wars"><span>Expert perspectives on AI agent turf wars</span></h3><ul><li><strong>Seemant Sehgal, Founder & CEO, BreachLock:</strong></li></ul><p><em>When you give autonomous systems competing objectives and the means to act, conflict is not a bug, it is a foreseeable outcome.</em></p><div><blockquote><p>When you give autonomous systems competing objectives and the means to act, conflict is not a bug, it is a foreseeable outcome.</p></blockquote></div><p><em>What Anthropic observed in a controlled research setting is the same principle that has always governed adversarial systems. Goals without constraints produce behavior without limits.</em></p><p><em>Security teams should be paying close attention here, because the real challenge at hand is whether the organizations deploying AI agents have thought carefully about what happens when those agents start making decisions nobody explicitly authorized.</em></p><ul><li><strong>Jeremiah Fowler, Security Researcher, Black Hills Information Security:</strong></li></ul><p><em>I find it concerning when AI agents have the ability to execute code, modify systems, create accounts, access credentials or communicate with other machines.</em></p><p><em>It is very possible that two separate agents could potentially create a security incident simply because neither understands the intent or authority of the other. If they have overlapping tasks one could view the other as an obstacle and now you have an interesting scenario where instead of focusing on the task they engage in conflict or create a loop.</em></p><div><blockquote><p>When things go wrong the speed of an AI agent becomes a liability.</p></blockquote></div><p><em>Permissions, boundaries and objectives are important to limit the behavior of autonomous AI agents. When things go wrong the speed of an AI agent becomes a liability. Autonomous AI agents can potentially make thousands of decisions before a security team identifies that something unusual is happening.</em></p><p><em>Agentic AI creates an entirely new attack surface because an AI agent may not be simply processing information and hypothetically can become a rogue privileged user.</em></p><p><em>Security and development teams should apply least privilege principles and restrict AI agents to only the permissions required to perform a specific task. Sensitive actions should require human supervision and approval to avoid a worse case scenario.</em></p><p><em>It is important to implement logging because when something goes wrong, you can see what an AI agent did, but what information or instructions caused specific decisions. Going forward we will need to develop ways that can identify rogue agent-to-agent behavior and provide humans with a kill switch before automated conflicts become a digital forest fire.</em></p><ul><li><strong>Kevin Surace, CEO, Token:</strong></li></ul><p><em>Anthropic’s research is an important warning for security teams because it shows what can happen when autonomous AI agents are given goals, credentials, tools and enough authority to act independently.</em></p><p><em>When agents were placed in conflict, they did not simply fail gracefully. They interfered with one another, disabled competing processes and even generated self replicating malicious code in pursuit of their assigned objectives.</em></p><p><em>The lesson is not that AI suddenly became evil. It is that intelligence, autonomy and excessive privilege can become a very dangerous combination.</em></p><div><blockquote><p>We are about to have millions of nonhuman identities operating alongside human identities. That makes identity and authorization even more critical.</p></blockquote></div><p><em>Organizations should start treating every AI agent as a potentially untrusted privileged identity. Each agent should have its own identity, least privilege access, tightly restricted tools, isolated execution environments and a complete audit trail. </em></p><p><em>Agents should never be able to expand their own permissions, disable another identity or take highly consequential actions without additional authorization.</em></p><p><em>We are about to have millions of nonhuman identities operating alongside human identities. That makes identity and authorization even more critical.</em></p><p><em>Every agent needs strong cryptographic identity, while all human approvals must be tied to biometric assured identity (or another agent could approve it).</em></p><p><em>AI agents are essentially becoming privileged insiders operating at machine speed. Giving them broad access and simply hoping they behave would repeat many of the same cybersecurity mistakes organizations have spent decades trying to fix.</em></p><ul><li><strong>Jacob Krell, Sr. Director: Secure AI Solutions & Cybersecurity, Suzu Labs:</strong></li></ul><p><em>Anthropic's agents went from merge conflict to self-replicating malware in four hours, writing kill scripts, disabling each other's Unix accounts, and disguising malicious code as a rival's work. No prompt injection, no external attacker. A human developer in the same situation sends a Slack message, and resolution takes days. These agents skipped every social brake and went straight to weaponization because machine-speed conflict has no cooling-off period.</em></p><p><em>Agentic AI is an attack surface. An attacker doesn't need to compromise an agent directly, just manipulate the shared environment to create conditions the agent interprets as hostile. The agent does the rest. And in Anthropic's experiment, the agents didn't report their malicious actions to operators afterward.</em></p><div><blockquote><p>Every agent needs its own identity, scoped permissions, and a kill switch before it touches a shared environment.</p></blockquote></div><p><em>Every agent needs its own identity, scoped permissions, and a kill switch before it touches a shared environment. Agent-to-agent interaction is a telemetry surface most security operations centers aren't collecting yet, and Anthropic just showed what an unmonitored shared environment produces. If you can't tell which agent did what, when, and on whose authority, you've built the conditions for a turf war without the visibility to see it happening.</em></p><p><em>Agents are already writing code, finding vulnerabilities, and building exploits. Defense has to match that speed. When both sides run at machine speed, the bottleneck shifts from human capital and tooling to compute power and cost.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why is the Premier League now subject to new cybersecurity rules, and what punishments could they face? The experts weigh in ]]></title>
                                                                                                <dc:content><![CDATA[ <p>With the 2026-27 season kicking off this weekend, Premier League football teams are facing a new set of rules. But these ones aren’t enforced on the pitch, they’re being enforced by the Premier League board.</p><p>As the Premier League has adapted to a new era of fan engagement and interaction, teams are holding huge amounts of personal data, including names, email addresses, credentials, and even financial information. These place them at greater risk of data leaks and make them a primary target for cyber attacks.</p><p>In order to ensure teams take the necessary steps to protect both their data and the data of their fans, the board can impose fines of up to £100,000 for teams that don’t meet the requirements across backups, incident response, risk management, security assurance and much more.</p><h2 id="what-do-the-new-rules-mean-for-premier-league-teams">What do the new rules mean for Premier League teams?</h2><p>The teams previously had to align with a non-prescriptive security baseline issued in 2024, but the new rules place requirements on teams with deadlines for their implementation.</p><p>If these deadlines are not met, the teams can be subject to the aforementioned fine, or referred to an independent commission.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>The teams will be required to meet the first set of requirements by April 30, 2027, with further requirements to be met in April 2028 and April 2029. The teams will also have to assess their own compliance by January 10 each year, with a final assessment and evidence submitted to the Premier League board by April 30.</p><p>The board can also request additional detail and evidence where needed to track a team’s progress in adhering to the new rules. If a team does not meet requirements during the interim stage it must submit a plan on how it aims to become compliant within 28 days.</p><h3 class="article-body__section" id="section-expert-perspectives-on-premier-league-cybersecurity-rules"><span>Expert perspectives on Premier League cybersecurity rules</span></h3><ul><li><strong>Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA, Huntress:</strong></li></ul><p><em>The Premier League introducing mandatory cybersecurity standards is the right move, but the detail is where the questions start. £100,000 sounds significant until you remember that top Premier League clubs generate revenues north of £600 million annually.</em></p><p><em>The phased timeline, April 2027, 2028, 2029, is pragmatic but slow given the threat environment. Waiting until 2029 for full compliance gives attackers three more seasons to find the weakest link.</em></p><div><blockquote><p>£100,000 sounds significant until you remember that top Premier League clubs generate revenues north of £600 million annually.</p></blockquote></div><p><em>That said, the direction is unambiguously right. Moving from a non-prescriptive roadmap to formal requirements with deadlines and evidence submissions is a meaningful structural shift.</em></p><p><em>Backups, incident response, risk management, and recovery testing are exactly the right foundations. The Premier League doing this proactively rather than reactively before a major breach forces the issue deserves genuine credit.</em></p><p><em>Most governing bodies wait for the headline incident. This one didn’t. The real test is enforcement appetite. Rules without credible consequences change nothing.</em></p><ul><li><strong>Jamie Akhtar, CEO and Co-founder, CyberSmart:</strong></li></ul><p><em>This is an important shift for the Premier League. Cyber security is moving from being viewed primarily as an IT responsibility to becoming an enforceable element of club governance.</em></p><p><em>Football clubs hold significant volumes of sensitive supporter, employee and player data, while also relying on systems for ticketing, payments, stadium access and match-day operations. Making areas such as backups, incident response, risk management and security assurance mandatory reflects the reality that a serious cyber incident can quickly become an operational, financial and reputational crisis.</em></p><div><blockquote><p>For clubs, compliance should not become an annual box-ticking exercise.</p></blockquote></div><p><em>For clubs, compliance should not become an annual box-ticking exercise. They need clear board-level ownership of cyber risk, an accurate inventory of critical systems and data, tested and segregated backups, rehearsed incident-response and recovery plans, strong identity and access controls, and effective oversight of third-party suppliers.</em></p><p><em>Just as importantly, clubs should continuously collect evidence that these controls are operating effectively. The organisations that treat the new requirements as a minimum baseline for resilience, rather than simply a regulatory hurdle, will be in the strongest position when an attack inevitably tests those controls.</em></p><ul><li><strong>Anna Collard, SVP of Content Strategy and CISO Advisor, KnowBe4:</strong></li></ul><p><em>Good to see the Premier League treating cybersecurity as a governance issue rather than an IT afterthought. Mandatory rules with real financial consequences (fines of up to £100,000) send the right signal: boards are expected to own this risk, not just delegate it.</em></p><div><blockquote><p>As I've said before, sport is uniquely exposed because it runs on the very emotions social engineers exploit: passion, urgency, loyalty and trust.</p></blockquote></div><p><em>But fines only address one side of the equation. As I've said before, sport is uniquely exposed because it runs on the very emotions social engineers exploit: passion, urgency, loyalty and trust.</em></p><p><em>A rushed transfer payment, a fan chasing tickets, an official acting on a "verified" WhatsApp message from someone posing as a coach or chairperson, these are moments of heightened emotion and time pressure, exactly when human judgment degrades. That's not a firewall problem.</em></p><p><em>It's worth remembering that one of the most costly incidents in this sector involved a Premier League club being spear-phished during a £1 million transfer negotiation. That wasn't a technical breach, but a person deceived at a moment of pressure.</em></p><p><em>Rules with teeth are a welcome start. But real resilience means pairing compliance with genuine behavioural readiness, for example helping people recognise urgency as a red flag, not a reason to skip verification.</em></p><ul><li><strong>Cian Heasley, Principal Consultant, Acumen Cyber:</strong></li></ul><p><em>I think it’s a positive step forward. Football clubs are attractive targets because they hold large volumes of sensitive data, process significant financial transactions and rely on operational systems where disruption can have very real consequences. Moving from advisory guidance to enforceable standards creates much-needed accountability, and the financial incentive will inevitably help drive action.</em></p><p><em>Requiring clubs to have a clear plan, aligned to defined standards and delivered within a set timeframe, also gives them something measurable to work towards. The key will be making sure those standards provide clear structure rather than leaving too much open to interpretation.</em></p><div><blockquote><p>The key will be making sure those standards provide clear structure rather than leaving too much open to interpretation.</p></blockquote></div><p><em>The focus on backups, incident response and recovery is particularly important. Preventing every incident simply isn’t realistic, so clubs need to prove they can recover quickly when something does happen. If clubs are working towards common standards, there is also a real opportunity to share lessons around what works, where implementation falls short and how security can continue to improve across the league.</em></p><p><em>In November ‘24, Italian club Bologna FC confirmed a ransomware attack claimed by the RansomHub group, which exfiltrated sensitive data. After the club declined to meet the ransom demand, the ransomware gang published the full dataset on the dark web. The leaked material reportedly included player and sponsor information, and the attackers went as far as invoking GDPR exposure to pressure the club into paying, a tactic that turns a club's own regulatory obligations into leverage. </em></p><p><em>More recently, Dutch club Ajax was named among the organisations affected by the CEVA Logistics breach, where customer data was exposed through a shared shipping vendor rather than a direct compromise, underlining that supply-chain exposure is also as material a risk as any attack on a club's own estate.</em></p><p><em>Taken together, these incidents show why these rules were needed then, though they are pitched as proactive, they must also be driven by these football-related breaches.</em></p><p><em>The £100,000 ceiling is modest against the true cost of a serious incident and the amounts of money tied up in football clubs, so the value lies less in the sanction and more in compelling clubs to build tested backups, incident response and recovery capability before they are needed. The Bologna case in particular demonstrates that ransomware leaks can be damaging, which makes resilience and data minimisation far more important than any assumption that a club can negotiate its way out of trouble.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/why-is-the-premier-league-now-subject-to-new-cybersecurity-rules-and-what-punishments-could-they-face-the-experts-weigh-in</link>
                                                                            <description>
                            <![CDATA[ The Premier League wants to harden teams against emerging cyber threats ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">26EmiWVfrhDPsZopFsAuC8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/u9DTfPvgBEBWg7ADPmTJRF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sun, 23 Aug 2026 09:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/u9DTfPvgBEBWg7ADPmTJRF-1280-80.jpg">
                                                            <media:credit><![CDATA[Visionhaus/Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A close-up of the official Premier League match ball.]]></media:description>                                                            <media:text><![CDATA[A close-up of the official Premier League match ball.]]></media:text>
                                <media:title type="plain"><![CDATA[A close-up of the official Premier League match ball.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/u9DTfPvgBEBWg7ADPmTJRF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>With the 2026-27 season kicking off this weekend, Premier League football teams are facing a new set of rules. But these ones aren’t enforced on the pitch, they’re being enforced by the Premier League board.</p><p>As the Premier League has adapted to a new era of fan engagement and interaction, teams are holding huge amounts of personal data, including names, email addresses, credentials, and even financial information. These place them at greater risk of data leaks and make them a primary target for cyber attacks.</p><p>In order to ensure teams take the necessary steps to protect both their data and the data of their fans, the board can impose fines of up to £100,000 for teams that don’t meet the requirements across backups, incident response, risk management, security assurance and much more.</p><h2 id="what-do-the-new-rules-mean-for-premier-league-teams">What do the new rules mean for Premier League teams?</h2><p>The teams previously had to align with a non-prescriptive security baseline issued in 2024, but the new rules place requirements on teams with deadlines for their implementation.</p><p>If these deadlines are not met, the teams can be subject to the aforementioned fine, or referred to an independent commission.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>The teams will be required to meet the first set of requirements by April 30, 2027, with further requirements to be met in April 2028 and April 2029. The teams will also have to assess their own compliance by January 10 each year, with a final assessment and evidence submitted to the Premier League board by April 30.</p><p>The board can also request additional detail and evidence where needed to track a team’s progress in adhering to the new rules. If a team does not meet requirements during the interim stage it must submit a plan on how it aims to become compliant within 28 days.</p><h3 class="article-body__section" id="section-expert-perspectives-on-premier-league-cybersecurity-rules"><span>Expert perspectives on Premier League cybersecurity rules</span></h3><ul><li><strong>Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA, Huntress:</strong></li></ul><p><em>The Premier League introducing mandatory cybersecurity standards is the right move, but the detail is where the questions start. £100,000 sounds significant until you remember that top Premier League clubs generate revenues north of £600 million annually.</em></p><p><em>The phased timeline, April 2027, 2028, 2029, is pragmatic but slow given the threat environment. Waiting until 2029 for full compliance gives attackers three more seasons to find the weakest link.</em></p><div><blockquote><p>£100,000 sounds significant until you remember that top Premier League clubs generate revenues north of £600 million annually.</p></blockquote></div><p><em>That said, the direction is unambiguously right. Moving from a non-prescriptive roadmap to formal requirements with deadlines and evidence submissions is a meaningful structural shift.</em></p><p><em>Backups, incident response, risk management, and recovery testing are exactly the right foundations. The Premier League doing this proactively rather than reactively before a major breach forces the issue deserves genuine credit.</em></p><p><em>Most governing bodies wait for the headline incident. This one didn’t. The real test is enforcement appetite. Rules without credible consequences change nothing.</em></p><ul><li><strong>Jamie Akhtar, CEO and Co-founder, CyberSmart:</strong></li></ul><p><em>This is an important shift for the Premier League. Cyber security is moving from being viewed primarily as an IT responsibility to becoming an enforceable element of club governance.</em></p><p><em>Football clubs hold significant volumes of sensitive supporter, employee and player data, while also relying on systems for ticketing, payments, stadium access and match-day operations. Making areas such as backups, incident response, risk management and security assurance mandatory reflects the reality that a serious cyber incident can quickly become an operational, financial and reputational crisis.</em></p><div><blockquote><p>For clubs, compliance should not become an annual box-ticking exercise.</p></blockquote></div><p><em>For clubs, compliance should not become an annual box-ticking exercise. They need clear board-level ownership of cyber risk, an accurate inventory of critical systems and data, tested and segregated backups, rehearsed incident-response and recovery plans, strong identity and access controls, and effective oversight of third-party suppliers.</em></p><p><em>Just as importantly, clubs should continuously collect evidence that these controls are operating effectively. The organisations that treat the new requirements as a minimum baseline for resilience, rather than simply a regulatory hurdle, will be in the strongest position when an attack inevitably tests those controls.</em></p><ul><li><strong>Anna Collard, SVP of Content Strategy and CISO Advisor, KnowBe4:</strong></li></ul><p><em>Good to see the Premier League treating cybersecurity as a governance issue rather than an IT afterthought. Mandatory rules with real financial consequences (fines of up to £100,000) send the right signal: boards are expected to own this risk, not just delegate it.</em></p><div><blockquote><p>As I've said before, sport is uniquely exposed because it runs on the very emotions social engineers exploit: passion, urgency, loyalty and trust.</p></blockquote></div><p><em>But fines only address one side of the equation. As I've said before, sport is uniquely exposed because it runs on the very emotions social engineers exploit: passion, urgency, loyalty and trust.</em></p><p><em>A rushed transfer payment, a fan chasing tickets, an official acting on a "verified" WhatsApp message from someone posing as a coach or chairperson, these are moments of heightened emotion and time pressure, exactly when human judgment degrades. That's not a firewall problem.</em></p><p><em>It's worth remembering that one of the most costly incidents in this sector involved a Premier League club being spear-phished during a £1 million transfer negotiation. That wasn't a technical breach, but a person deceived at a moment of pressure.</em></p><p><em>Rules with teeth are a welcome start. But real resilience means pairing compliance with genuine behavioural readiness, for example helping people recognise urgency as a red flag, not a reason to skip verification.</em></p><ul><li><strong>Cian Heasley, Principal Consultant, Acumen Cyber:</strong></li></ul><p><em>I think it’s a positive step forward. Football clubs are attractive targets because they hold large volumes of sensitive data, process significant financial transactions and rely on operational systems where disruption can have very real consequences. Moving from advisory guidance to enforceable standards creates much-needed accountability, and the financial incentive will inevitably help drive action.</em></p><p><em>Requiring clubs to have a clear plan, aligned to defined standards and delivered within a set timeframe, also gives them something measurable to work towards. The key will be making sure those standards provide clear structure rather than leaving too much open to interpretation.</em></p><div><blockquote><p>The key will be making sure those standards provide clear structure rather than leaving too much open to interpretation.</p></blockquote></div><p><em>The focus on backups, incident response and recovery is particularly important. Preventing every incident simply isn’t realistic, so clubs need to prove they can recover quickly when something does happen. If clubs are working towards common standards, there is also a real opportunity to share lessons around what works, where implementation falls short and how security can continue to improve across the league.</em></p><p><em>In November ‘24, Italian club Bologna FC confirmed a ransomware attack claimed by the RansomHub group, which exfiltrated sensitive data. After the club declined to meet the ransom demand, the ransomware gang published the full dataset on the dark web. The leaked material reportedly included player and sponsor information, and the attackers went as far as invoking GDPR exposure to pressure the club into paying, a tactic that turns a club's own regulatory obligations into leverage. </em></p><p><em>More recently, Dutch club Ajax was named among the organisations affected by the CEVA Logistics breach, where customer data was exposed through a shared shipping vendor rather than a direct compromise, underlining that supply-chain exposure is also as material a risk as any attack on a club's own estate.</em></p><p><em>Taken together, these incidents show why these rules were needed then, though they are pitched as proactive, they must also be driven by these football-related breaches.</em></p><p><em>The £100,000 ceiling is modest against the true cost of a serious incident and the amounts of money tied up in football clubs, so the value lies less in the sanction and more in compelling clubs to build tested backups, incident response and recovery capability before they are needed. The Bologna case in particular demonstrates that ransomware leaks can be damaging, which makes resilience and data minimisation far more important than any assumption that a club can negotiate its way out of trouble.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts warn 2,000 hacked WordPress sites were secretly running a global crime ring ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Researchers uncover vast cybercrime ring running on computers and infected domains where outdated versions of WordPress were installed</strong></li><li><strong>The StopAndProtect investigation revealed the WordPress content management system was key to the ring’s success; both the core software and third-party plugins were subverted</strong></li><li><strong>Around 2,000 WordPress sites were hijacked by the cybercrime ring</strong></li></ul><p>Check Point Research has unearthed a global cybercrime ring that relied on a network of WordPress websites. The investigation into an operation dubbed “StopAndProtect” found a network of 5,000 infected computers around the globe, and 2,000 WordPress domains.</p><p>WordPress currently provides content management for around 43% of websites worldwide, making it the most significant CMS available. It is also the most popular website builder, and is suitable for single page websites, basic blogs, vast news sites, and even online stores.</p><p>The researchers <a href="https://blog.checkpoint.com/research/the-mistake-that-exposed-a-global-cyber-crime-operation/" target="_blank">found</a> the crime ring had made some mistakes, which alerted them to their operation. These included screenshots and logs of victims, internal tools, and files referencing the hijacked domains. While reassuring, the StopAndProtect investigation raises questions about the security of WordPress sites.</p><h2 id="how-stopandprotect-did-it">How StopAndProtect did it</h2><p>WordPress has long been a target for hackers looking for an easy way to host malware and operate botnets, with several key incidents over the course of its history. However, the CMS remains free and open source, and is easy to setup thanks to installation scripts and web builder plugins.</p><p>While StopAndProtect was initially the name given to the ransomware uncovered by Check Point Research earlier in 2026, they decided to use the name for the whole operation, as they found it doesn’t only distribute ransomware.</p><p>Check Point Research’s Eli Smadja <a href="https://research.checkpoint.com/2026/thousands-of-hacked-wordpress-sites-one-operation-unmasking-stopandprotect/" target="_blank">said</a>: “StopAndProtect shows how attackers can turn thousands of poorly maintained WordPress sites into a distributed criminal infrastructure for malware delivery, surveillance, data theft, and ransomware.”</p><h2 id="can-any-wordpress-domain-be-hijacked">Can any WordPress domain be hijacked?</h2><p>Given the number of WordPress sites impacted by the crime ring uncovered by the investigation, and the platform’s prominence in the CMS and web builder market, the question has to be asked: is WordPress still safe?</p><p>“Based on our research findings, we urge organizations be cautious of unexpected CAPTCHA prompts that instruct them to copy, paste, or run commands, keep their devices and security software updated, and immediately leave any website that asks them to perform unusual steps outside the browser," Smadja added.</p><p>Many small businesses rely on WordPress for their public-facing web presence, and in some cases for internal purposes too. The StopAndProtect investigation highlighted a particular WordPress-driven site running a five-year-old version of the CMS, compromised by around 40 vulnerabilities. </p><p>If concerns surround WordPress, the quickest solution is to ensure the website is running the most recent version, and that the plugins are not only running as intended, but also fully updated.</p><p>Maintaining a regular WordPress update cycle can avoid sites becoming hijacked, a strategy best used in conjunction with a web host that monitors for intrusions and suspicious activity.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/experts-warn-2-000-hacked-wordpress-sites-were-secretly-running-a-global-crime-ring</link>
                                                                            <description>
                            <![CDATA[ Compromised WordPress sites have been used by a global operation, using trusted websites to deliver malware, instruct infected devices, and even store stolen documents. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">b4Zcbp8KYGsK87BPbpArpL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 22 Aug 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christian Cawley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zBDYnjPnB2XPvhKbYX9Kuc.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Christian Cawley has extensive experience as a writer and editor in consumer electronics, IT and entertainment media. He has contributed to TechRadar since 2017 and has been published in Computer Weekly, Linux Format, ComputerActive, and other publications. &lt;/p&gt;&lt;p&gt;Beyond TechRadar, he heads up the team at smart home website Matter Alpha, and writes about retro gaming at Gaming Retro. &lt;/p&gt;&lt;p&gt;Formerly the editor responsible for Linux, Security, Programming, and DIY at MakeUseOf, Christian previously worked as a desktop and software support specialist in the public and private sectors.&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/David MG]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:description>                                                            <media:text><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers uncover vast cybercrime ring running on computers and infected domains where outdated versions of WordPress were installed</strong></li><li><strong>The StopAndProtect investigation revealed the WordPress content management system was key to the ring’s success; both the core software and third-party plugins were subverted</strong></li><li><strong>Around 2,000 WordPress sites were hijacked by the cybercrime ring</strong></li></ul><p>Check Point Research has unearthed a global cybercrime ring that relied on a network of WordPress websites. The investigation into an operation dubbed “StopAndProtect” found a network of 5,000 infected computers around the globe, and 2,000 WordPress domains.</p><p>WordPress currently provides content management for around 43% of websites worldwide, making it the most significant CMS available. It is also the most popular website builder, and is suitable for single page websites, basic blogs, vast news sites, and even online stores.</p><p>The researchers <a href="https://blog.checkpoint.com/research/the-mistake-that-exposed-a-global-cyber-crime-operation/" target="_blank">found</a> the crime ring had made some mistakes, which alerted them to their operation. These included screenshots and logs of victims, internal tools, and files referencing the hijacked domains. While reassuring, the StopAndProtect investigation raises questions about the security of WordPress sites.</p><h2 id="how-stopandprotect-did-it">How StopAndProtect did it</h2><p>WordPress has long been a target for hackers looking for an easy way to host malware and operate botnets, with several key incidents over the course of its history. However, the CMS remains free and open source, and is easy to setup thanks to installation scripts and web builder plugins.</p><p>While StopAndProtect was initially the name given to the ransomware uncovered by Check Point Research earlier in 2026, they decided to use the name for the whole operation, as they found it doesn’t only distribute ransomware.</p><p>Check Point Research’s Eli Smadja <a href="https://research.checkpoint.com/2026/thousands-of-hacked-wordpress-sites-one-operation-unmasking-stopandprotect/" target="_blank">said</a>: “StopAndProtect shows how attackers can turn thousands of poorly maintained WordPress sites into a distributed criminal infrastructure for malware delivery, surveillance, data theft, and ransomware.”</p><h2 id="can-any-wordpress-domain-be-hijacked">Can any WordPress domain be hijacked?</h2><p>Given the number of WordPress sites impacted by the crime ring uncovered by the investigation, and the platform’s prominence in the CMS and web builder market, the question has to be asked: is WordPress still safe?</p><p>“Based on our research findings, we urge organizations be cautious of unexpected CAPTCHA prompts that instruct them to copy, paste, or run commands, keep their devices and security software updated, and immediately leave any website that asks them to perform unusual steps outside the browser," Smadja added.</p><p>Many small businesses rely on WordPress for their public-facing web presence, and in some cases for internal purposes too. The StopAndProtect investigation highlighted a particular WordPress-driven site running a five-year-old version of the CMS, compromised by around 40 vulnerabilities. </p><p>If concerns surround WordPress, the quickest solution is to ensure the website is running the most recent version, and that the plugins are not only running as intended, but also fully updated.</p><p>Maintaining a regular WordPress update cycle can avoid sites becoming hijacked, a strategy best used in conjunction with a web host that monitors for intrusions and suspicious activity.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Even dead websites aren't safe — experts warn hackers are spending millions on expired domains to enable malware scams ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Infoblox Threat Intel counted roughly 65,000 expired domains re-registered every day in the first half of 2026, close to one in five of all new registrations</strong></li><li><strong>An actor it calls Sable Squirrel controls more than 10,000 domains and is estimated, by extrapolation, to have spent over $7 million buying expired names for their inherited traffic and domain authority</strong></li><li><strong>Some of the domains are also used to function as command-and-control structures for existing malware that can be traced back to the same group</strong></li></ul><p>A domain name is the closest thing the web has to a credit history: age, inbound links, search visibility, and reputation all feed the reputation scores that security products consult before deciding whether a request is worth worrying about.</p><p>New <a href="https://www.infoblox.com/blog/threat-intelligence/7-million-in-expired-domains-fuel-a-streaming-empire-with-a-malware-secret/" target="_blank" rel="nofollow">research</a> from Infoblox Threat Intel claims this history has become a commodity with a market price, and that at least one criminal operation has been buying it in bulk.</p><p>The study, published as a three-part series, focuses on what the industry calls dropcatch domains: names that lapsed, were released back to the registry, and were then re-registered by someone else entirely.</p><h2 id="a-dropcatch-domain-situation-a-gambling-business-with-a-malware-enabling-catch">A dropcatch domain situation: A gambling business with a malware-enabling catch</h2><p>Dropcatch domains aren't new; software has been primed to spot expiring domains for years, and it sometimes <a href="https://www.techradar.com/news/one-of-the-internets-most-infamous-domain-names-is-up-for-sale" target="_blank">snags the occasional massive win</a> for users who deploy such solutions. </p><p>This lets users start with domains that already have history that benefits them or flip certain domains for a price that is often a multiple of the domain's original purchase price.</p><p>Infoblox counted an average of 50,400 such re-registrations a day across generic top-level domains in the first half of 2026, rising to roughly 65,000 once country-code domains are added. That amounts to close to a fifth of all daily registrations. The rate is highest on .net and .xyz, where nearly three in ten newly observed names had a previous life, with .com behind them at 24.5%.</p><p>The problem is that not all of these are seemingly innocent or small-scale scalping operations: Infoblox has identified an entity it has labeled Sable Squirrel, part of a naming convention the company applies to domain hoarders. It controls more than 10,000 domains, most of which support a large Vietnamese-language sports piracy operation operating under brands including Xoilac, Cakhia, 90phut, Socolive, and MiTom.</p><p>Infoblox estimates the actor's total spend on expired domains at north of $7 million, which it describes as the largest domain acquisition budget it has identified for a single actor in the industry. The bigger problem is that Infoblox also found that a subset of these streaming domains runs as malware command and control while continuing to serve live football to human visitors.</p><p>More than 31,000 samples identified called back to Sable Squirrel's infrastructure, spanning Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, and njRAT, plus samples carrying HiddenTear ransomware signatures. </p><p>Infoblox said the operator's carelessness made finding a link easier: many samples carry the actor's brand names in their Windows executable metadata, with fields reading socolive, xoilac, and 8xbet. Infoblox confirmed 405 domains as malware C2, which is roughly four percent of the total domains the organization controls, and the weaponization arrived as a single wave in late 2025 rather than as the operation's original purpose.</p><p>Sable Squirrel's core business is gambling, and while the entity tries to mask it as a streaming operation, it also doubles as an acquisition channel for the same. While law enforcement has not been silent here, it has had limited luck at best: Vietnamese authorities froze some of the flagship sites in February 2026 and charged 30 suspects in March. </p><p>They also seized assets Infoblox puts at roughly $12 million, but it seems to have survived and continues to expand, having acquired and run World Cup-centric domains since June, further expanding its footprint in a world where it has already identified and secured a large chunk of what is arguably a very important commodity: Domain authority.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/even-dead-websites-arent-safe-experts-warn-hackers-are-spending-millions-on-expired-domains-to-enable-malware-scams</link>
                                                                            <description>
                            <![CDATA[ Roughly 65,000 expired domains change hands every day, and researchers have found one crime group spending an estimated $7 million on them to inherit the trust that comes attached to them. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xFP3YBdbcUzK5sEJVSyvSD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8CfKaJtTivypreUesyghSh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 21 Aug 2026 18:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8CfKaJtTivypreUesyghSh-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data Search Technology Search Engine Optimization. man&#039;s hands are using laptop to Searching for information. Marketing ranking traffic website, SEO search engine optimization concept.]]></media:description>                                                            <media:text><![CDATA[Data Search Technology Search Engine Optimization. man&#039;s hands are using laptop to Searching for information. Marketing ranking traffic website, SEO search engine optimization concept.]]></media:text>
                                <media:title type="plain"><![CDATA[Data Search Technology Search Engine Optimization. man&#039;s hands are using laptop to Searching for information. Marketing ranking traffic website, SEO search engine optimization concept.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8CfKaJtTivypreUesyghSh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Infoblox Threat Intel counted roughly 65,000 expired domains re-registered every day in the first half of 2026, close to one in five of all new registrations</strong></li><li><strong>An actor it calls Sable Squirrel controls more than 10,000 domains and is estimated, by extrapolation, to have spent over $7 million buying expired names for their inherited traffic and domain authority</strong></li><li><strong>Some of the domains are also used to function as command-and-control structures for existing malware that can be traced back to the same group</strong></li></ul><p>A domain name is the closest thing the web has to a credit history: age, inbound links, search visibility, and reputation all feed the reputation scores that security products consult before deciding whether a request is worth worrying about.</p><p>New <a href="https://www.infoblox.com/blog/threat-intelligence/7-million-in-expired-domains-fuel-a-streaming-empire-with-a-malware-secret/" target="_blank" rel="nofollow">research</a> from Infoblox Threat Intel claims this history has become a commodity with a market price, and that at least one criminal operation has been buying it in bulk.</p><p>The study, published as a three-part series, focuses on what the industry calls dropcatch domains: names that lapsed, were released back to the registry, and were then re-registered by someone else entirely.</p><h2 id="a-dropcatch-domain-situation-a-gambling-business-with-a-malware-enabling-catch">A dropcatch domain situation: A gambling business with a malware-enabling catch</h2><p>Dropcatch domains aren't new; software has been primed to spot expiring domains for years, and it sometimes <a href="https://www.techradar.com/news/one-of-the-internets-most-infamous-domain-names-is-up-for-sale" target="_blank">snags the occasional massive win</a> for users who deploy such solutions. </p><p>This lets users start with domains that already have history that benefits them or flip certain domains for a price that is often a multiple of the domain's original purchase price.</p><p>Infoblox counted an average of 50,400 such re-registrations a day across generic top-level domains in the first half of 2026, rising to roughly 65,000 once country-code domains are added. That amounts to close to a fifth of all daily registrations. The rate is highest on .net and .xyz, where nearly three in ten newly observed names had a previous life, with .com behind them at 24.5%.</p><p>The problem is that not all of these are seemingly innocent or small-scale scalping operations: Infoblox has identified an entity it has labeled Sable Squirrel, part of a naming convention the company applies to domain hoarders. It controls more than 10,000 domains, most of which support a large Vietnamese-language sports piracy operation operating under brands including Xoilac, Cakhia, 90phut, Socolive, and MiTom.</p><p>Infoblox estimates the actor's total spend on expired domains at north of $7 million, which it describes as the largest domain acquisition budget it has identified for a single actor in the industry. The bigger problem is that Infoblox also found that a subset of these streaming domains runs as malware command and control while continuing to serve live football to human visitors.</p><p>More than 31,000 samples identified called back to Sable Squirrel's infrastructure, spanning Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, and njRAT, plus samples carrying HiddenTear ransomware signatures. </p><p>Infoblox said the operator's carelessness made finding a link easier: many samples carry the actor's brand names in their Windows executable metadata, with fields reading socolive, xoilac, and 8xbet. Infoblox confirmed 405 domains as malware C2, which is roughly four percent of the total domains the organization controls, and the weaponization arrived as a single wave in late 2025 rather than as the operation's original purpose.</p><p>Sable Squirrel's core business is gambling, and while the entity tries to mask it as a streaming operation, it also doubles as an acquisition channel for the same. While law enforcement has not been silent here, it has had limited luck at best: Vietnamese authorities froze some of the flagship sites in February 2026 and charged 30 suspects in March. </p><p>They also seized assets Infoblox puts at roughly $12 million, but it seems to have survived and continues to expand, having acquired and run World Cup-centric domains since June, further expanding its footprint in a world where it has already identified and secured a large chunk of what is arguably a very important commodity: Domain authority.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Target may have suffered another damaging data leak as hackers claim 8.6GB haul ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Hacker alias Xpl0itrs claims to have stolen 8.6GB of Target source code  </strong></li><li><strong>Researchers suspect it’s recycled data from January’s confirmed 860GB breach  </strong></li><li><strong>Xpl0itrs has a history of dubious leak claims, fueling skepticism about authenticity</strong></li></ul><p>Hackers are claiming to have breached Target in what would be the US supermarket giant's second breach of 2026 alone. </p><p>The attackers are threatening to release gigabytes of source code into the dark web unless the company pays up, but not everyone is sold on the idea that the US merchandise giant was actually hacked this time around. </p><p>Some security researchers believe this might just be a case of a lowly criminal piggybacking on someone else’s work.</p><h2 id="was-there-really-a-hack-2">Was there really a hack?</h2><p><a href="https://www.techradar.com/pro/security/hackers-claim-to-have-target-source-code-for-sale-following-recent-cyberattack" target="_blank">Target was first hit in January 2026</a>, when a threat actor posted a new thread in an underground hacking community to claim they were selling the company's data, and that this was the first of many datasets to go on auction. To support their claim, they created multiple repositories on Gitea, a self-hosted Git platform, and uploaded a small sample of the data.</p><p>The repositories, totaling around 860 GB in size, appeared to contain internal Target source code, configuration files, and developer documentation, while repository names were referencing internal systems such as wallet services, <a href="https://www.techradar.com/best/best-identity-management-software" target="_blank">identity management</a>, store networking tools, secrets documentation, and gift card systems.</p><p>Target later confirmed the authenticity of the breach.</p><p>This time around, however, a different threat actor - with an alias Xpl0itrs - created a new data leak site in mid-June 2026, and earlier this month added Target. They claim to have stolen 8.6GB of the company's source code and have given it two days to pay up or see the data leak into the dark web. </p><p>Xpl0itrs is not exactly a household name in the cybercriminal community, and they have not shared any samples of the data they are claiming to have nabbed - further fueling the idea that this data was already grabbed eight months ago. </p><p>Even some of their previous “work” is questionable. <a href="https://cybernews.com/security/target-data-breach-source-code-claim/" target="_blank"><em>Cybernews</em></a> reports that in June, they teased leaking data from Spotify, the US Department of the Treasury, OpenAI, and Trustpilot, which never happened. Before that, they claimed to have stolen documents from BMW, containing details about motorcycles and dealerships. This, too, was somewhat debunked, as it turned out that some of the data was already publicly available. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/target-may-have-suffered-another-damaging-data-leak-as-hackers-claim-8-6gb-haul</link>
                                                                            <description>
                            <![CDATA[ The claims came from a threat actor with a questionable track record. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qH8uTStXvBsfgjfPXrzpqX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/34u7D3mDFFPiqboXQBth8f-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 21 Aug 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/34u7D3mDFFPiqboXQBth8f-1280-80.jpg">
                                                            <media:credit><![CDATA[Target]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Target may not be an option for last-minute shopping on Thanksgiving.]]></media:description>                                                            <media:text><![CDATA[A newly remodelled Target store]]></media:text>
                                <media:title type="plain"><![CDATA[A newly remodelled Target store]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/34u7D3mDFFPiqboXQBth8f-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Hacker alias Xpl0itrs claims to have stolen 8.6GB of Target source code  </strong></li><li><strong>Researchers suspect it’s recycled data from January’s confirmed 860GB breach  </strong></li><li><strong>Xpl0itrs has a history of dubious leak claims, fueling skepticism about authenticity</strong></li></ul><p>Hackers are claiming to have breached Target in what would be the US supermarket giant's second breach of 2026 alone. </p><p>The attackers are threatening to release gigabytes of source code into the dark web unless the company pays up, but not everyone is sold on the idea that the US merchandise giant was actually hacked this time around. </p><p>Some security researchers believe this might just be a case of a lowly criminal piggybacking on someone else’s work.</p><h2 id="was-there-really-a-hack-2">Was there really a hack?</h2><p><a href="https://www.techradar.com/pro/security/hackers-claim-to-have-target-source-code-for-sale-following-recent-cyberattack" target="_blank">Target was first hit in January 2026</a>, when a threat actor posted a new thread in an underground hacking community to claim they were selling the company's data, and that this was the first of many datasets to go on auction. To support their claim, they created multiple repositories on Gitea, a self-hosted Git platform, and uploaded a small sample of the data.</p><p>The repositories, totaling around 860 GB in size, appeared to contain internal Target source code, configuration files, and developer documentation, while repository names were referencing internal systems such as wallet services, <a href="https://www.techradar.com/best/best-identity-management-software" target="_blank">identity management</a>, store networking tools, secrets documentation, and gift card systems.</p><p>Target later confirmed the authenticity of the breach.</p><p>This time around, however, a different threat actor - with an alias Xpl0itrs - created a new data leak site in mid-June 2026, and earlier this month added Target. They claim to have stolen 8.6GB of the company's source code and have given it two days to pay up or see the data leak into the dark web. </p><p>Xpl0itrs is not exactly a household name in the cybercriminal community, and they have not shared any samples of the data they are claiming to have nabbed - further fueling the idea that this data was already grabbed eight months ago. </p><p>Even some of their previous “work” is questionable. <a href="https://cybernews.com/security/target-data-breach-source-code-claim/" target="_blank"><em>Cybernews</em></a> reports that in June, they teased leaking data from Spotify, the US Department of the Treasury, OpenAI, and Trustpilot, which never happened. Before that, they claimed to have stolen documents from BMW, containing details about motorcycles and dealerships. This, too, was somewhat debunked, as it turned out that some of the data was already publicly available. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This new malware can use Google passkeys even after a victim resets their password ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>iAuthFlow v2 sold on Russian forums lets attackers persist in email accounts  </strong></li><li><strong>Tool phishes logins, then secretly creates attacker‑controlled passkeys for lasting access  </strong></li><li><strong>Defenses include auditing passkeys, OAuth tokens, mail rules, and removing rogue methods</strong></li></ul><p>Security researchers have discovered a new <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> toolkit which allows threat actors to log back into compromised email accounts even after the password was changed and all sessions terminated.</p><p>iAuthFlow v2 is currently being sold on Russian dark web forums for north of $10,000, a new <a href="https://abnormal.ai/blog/iauthflow-v2-phishing-google-passkeys" target="_blank" rel="nofollow">report</a> from cybersecurity experts from Abnormal said, as they obtained a copy of iAuthFlow v2 for analysis.</p><p>The malware primarily works as a phishing tool, trying to trick users into logging into either Google, Microsoft, iCloud, or LinkedIn. As soon as they do that, they relay the login credentials to the attackers, who log into the accounts on their end, as well - before the tool displays a “processing” page for a few seconds while, in the background, it sets up a new passkey. </p><h2 id="how-to-defend-against-iauthflow-v2">How to defend against iAuthFlow v2</h2><p>A passkey is an alternative means of authentication that is often touted as the “<a href="https://www.techradar.com/best/password-manager" target="_blank">password</a> killer”. It uses cryptographic keys stored on a device, allowing users to sign in with a fingerprint, face scan, or device PIN. </p><p>Because the secret key never leaves the device, it is resistant to phishing. However, if the threat actor is able to generate a key of their own, on the device they own, access is basically guaranteed. </p><p>The ad for the toolkit also comes with a video demo, showing how it works. In the demo, iAuthFlow v2 created the passkey six seconds after authentication. </p><p>However, generating a passkey is not that straightforward of a process and it could encounter hiccups, Abnormal hints, saying that Google, for example, might require further identity verification before allowing the change.</p><p>Usually, when a threat actor compromises an <a href="https://www.techradar.com/news/best-email-provider" target="_blank">email account</a>, terminating all sessions and changing the password is usually enough.</p><p>In this case, however, users should do a lot more: review the account for signs of compromise, including unauthorized passkeys or security keys, malicious Gmail filters and forwarding rules, recovery and delegated access changes, and unauthorized applications, Abnormal suggests.</p><p>They should also revoke relevant OAuth tokens and grants, investigate available sign-in, mail-rule, 2-Step Verification, passkey and OAuth audit events, and finally, make sure any attacker-enrolled authentication methods are removed.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/this-new-malware-can-use-google-passkeys-even-after-a-victim-resets-their-password</link>
                                                                            <description>
                            <![CDATA[ A newly discovered toolkit can deeply compromise Gmail, Microsoft, Apple, and LinkedIn accounts ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XL5nrccyjA7YTcv5HwxC9C</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QGZS7tno9wMKaY7FVBDSNE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 21 Aug 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QGZS7tno9wMKaY7FVBDSNE-1280-80.jpg">
                                                            <media:credit><![CDATA[Ascannio / Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Gmail app listing]]></media:description>                                                            <media:text><![CDATA[Gmail app listing]]></media:text>
                                <media:title type="plain"><![CDATA[Gmail app listing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QGZS7tno9wMKaY7FVBDSNE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>iAuthFlow v2 sold on Russian forums lets attackers persist in email accounts  </strong></li><li><strong>Tool phishes logins, then secretly creates attacker‑controlled passkeys for lasting access  </strong></li><li><strong>Defenses include auditing passkeys, OAuth tokens, mail rules, and removing rogue methods</strong></li></ul><p>Security researchers have discovered a new <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> toolkit which allows threat actors to log back into compromised email accounts even after the password was changed and all sessions terminated.</p><p>iAuthFlow v2 is currently being sold on Russian dark web forums for north of $10,000, a new <a href="https://abnormal.ai/blog/iauthflow-v2-phishing-google-passkeys" target="_blank" rel="nofollow">report</a> from cybersecurity experts from Abnormal said, as they obtained a copy of iAuthFlow v2 for analysis.</p><p>The malware primarily works as a phishing tool, trying to trick users into logging into either Google, Microsoft, iCloud, or LinkedIn. As soon as they do that, they relay the login credentials to the attackers, who log into the accounts on their end, as well - before the tool displays a “processing” page for a few seconds while, in the background, it sets up a new passkey. </p><h2 id="how-to-defend-against-iauthflow-v2">How to defend against iAuthFlow v2</h2><p>A passkey is an alternative means of authentication that is often touted as the “<a href="https://www.techradar.com/best/password-manager" target="_blank">password</a> killer”. It uses cryptographic keys stored on a device, allowing users to sign in with a fingerprint, face scan, or device PIN. </p><p>Because the secret key never leaves the device, it is resistant to phishing. However, if the threat actor is able to generate a key of their own, on the device they own, access is basically guaranteed. </p><p>The ad for the toolkit also comes with a video demo, showing how it works. In the demo, iAuthFlow v2 created the passkey six seconds after authentication. </p><p>However, generating a passkey is not that straightforward of a process and it could encounter hiccups, Abnormal hints, saying that Google, for example, might require further identity verification before allowing the change.</p><p>Usually, when a threat actor compromises an <a href="https://www.techradar.com/news/best-email-provider" target="_blank">email account</a>, terminating all sessions and changing the password is usually enough.</p><p>In this case, however, users should do a lot more: review the account for signs of compromise, including unauthorized passkeys or security keys, malicious Gmail filters and forwarding rules, recovery and delegated access changes, and unauthorized applications, Abnormal suggests.</p><p>They should also revoke relevant OAuth tokens and grants, investigate available sign-in, mail-rule, 2-Step Verification, passkey and OAuth audit events, and finally, make sure any attacker-enrolled authentication methods are removed.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security experts targeted by fake crypto conference in scam to hand over details ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Huntress spotted a ClickFix campaign targeting security pros via fake conference invites  </strong></li><li><strong>Victims tricked into pasting code that installs AMOS infostealer on macOS </strong></li><li><strong>If lured, isolate systems, reset credentials, rotate secrets, and review cryptocurrency wallets</strong></li></ul><p>Cybercriminals are targeting security professionals with a highly tailored ClickFix campaign in an attempt to get their computers infected with infostealer <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, experts have warned.</p><p>An active campaign against people who have attended, or have a history of attending, various cybersecurity conferences such as Black Hat, or DEF CON has been detetced by security researchers <a href="https://www.huntress.com/blog/defcon-phishing-google-doc-malware" target="_blank">Huntress</a>, who were targets themselves. </p><p>The attack starts on X, where the threat actor uses a fake account to interact with people visiting and sharing content from these conferences. After establishing rapport, they move into DMs, claiming they’re organizing a conference of their own, and sharing a Google Docs file containing “more info” with the victim. </p><h2 id="follow-up-attack">Follow-up attack</h2><p>Here is where the attackersy go for the ClickFix attack. The document comes with a vertical sidebar, apparently as a security feature that keeps the contents of the file encrypted. The victim is given a decryption code to enter, but it returns an error and offers a solution - to bring up the Terminal and copy/paste a piece of code.</p><p>From here, it’s the usual ClickFix practice: the victim ends up downloading and running AMOS, a notorious Mac infostealer capable of grabbing browser information, cookies, keychain data, cryptocurrency wallet information, Telegram files, and more. The Windows variant did not work when Huntress tried to analyze it, but it’s safe to assume the end goal is the same.</p><p>Huntress also found that this is not where the attack ends. If the victim does not install the infostealer, the threat actor will follow up with a different document, this time pretending to be for Dropbox and working only with the desktop app. Of course, the download button leads straight back to the infostealer.</p><p>The researchers shared a full list of Indicators of Compromise (IoC) which can be found on this link. They also advised anyone who interacted with this kind of lure to isolate the system from the network, collect relevant forensic evidence, and “consider reimaging the system”. </p><p>“Assume that credentials on the system have been compromised”, they said. “Revoke active sessions, reset passwords, and rotate API keys or any other secrets that may reside on the system. Review cryptocurrency wallets as well, if present.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/security-experts-targeted-by-fake-crypto-conference-in-scam-to-hand-over-details</link>
                                                                            <description>
                            <![CDATA[ Cybersecurity pros attending conferences are being targeted with AMOS and other infostealers, experts warn. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4WM98xrduycbkQfG5f5Wdh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 21 Aug 2026 13:20:22 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:description>                                                            <media:text><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:text>
                                <media:title type="plain"><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Huntress spotted a ClickFix campaign targeting security pros via fake conference invites  </strong></li><li><strong>Victims tricked into pasting code that installs AMOS infostealer on macOS </strong></li><li><strong>If lured, isolate systems, reset credentials, rotate secrets, and review cryptocurrency wallets</strong></li></ul><p>Cybercriminals are targeting security professionals with a highly tailored ClickFix campaign in an attempt to get their computers infected with infostealer <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, experts have warned.</p><p>An active campaign against people who have attended, or have a history of attending, various cybersecurity conferences such as Black Hat, or DEF CON has been detetced by security researchers <a href="https://www.huntress.com/blog/defcon-phishing-google-doc-malware" target="_blank">Huntress</a>, who were targets themselves. </p><p>The attack starts on X, where the threat actor uses a fake account to interact with people visiting and sharing content from these conferences. After establishing rapport, they move into DMs, claiming they’re organizing a conference of their own, and sharing a Google Docs file containing “more info” with the victim. </p><h2 id="follow-up-attack">Follow-up attack</h2><p>Here is where the attackersy go for the ClickFix attack. The document comes with a vertical sidebar, apparently as a security feature that keeps the contents of the file encrypted. The victim is given a decryption code to enter, but it returns an error and offers a solution - to bring up the Terminal and copy/paste a piece of code.</p><p>From here, it’s the usual ClickFix practice: the victim ends up downloading and running AMOS, a notorious Mac infostealer capable of grabbing browser information, cookies, keychain data, cryptocurrency wallet information, Telegram files, and more. The Windows variant did not work when Huntress tried to analyze it, but it’s safe to assume the end goal is the same.</p><p>Huntress also found that this is not where the attack ends. If the victim does not install the infostealer, the threat actor will follow up with a different document, this time pretending to be for Dropbox and working only with the desktop app. Of course, the download button leads straight back to the infostealer.</p><p>The researchers shared a full list of Indicators of Compromise (IoC) which can be found on this link. They also advised anyone who interacted with this kind of lure to isolate the system from the network, collect relevant forensic evidence, and “consider reimaging the system”. </p><p>“Assume that credentials on the system have been compromised”, they said. “Revoke active sessions, reset passwords, and rotate API keys or any other secrets that may reside on the system. Review cryptocurrency wallets as well, if present.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Massive supply-chain attack sees terabytes of data belonging to some of the world’s biggest and most sensitive organizations leaked online ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>More than 2,500 organizations, including Cisco, Samsung, AWS, Airbus U.S. Space & Defense, Thales, and the London Stock Exchange Group, have credentials harvested during a supply-chain attack on LiteLLM</strong></li><li><strong>LiteLLM was not directly hacked by the hacking group TeamPCP, which found their way in thanks to a compromised build of an open-source security scanner</strong></li><li><strong>Some of the credentials still work, nearly five months after the original breach, indicating that there is still a persistent security risk until they are changed</strong></li></ul><p>Security firms CloudSEK and Hudson Rock have claimed more than 2,500 organizations have had credentials harvested in a supply-chain attack on LiteLLM.</p><p>LiteLLM, an open source gateway which translates API calls for over 100 large language models into a single OpenAI-compatible format, was not directly compromised in the attack, as hackers targeted a known vulnerability in Aqua Security's Trivy.</p><p>The list included many large and critical service providers, including but not limited to Cisco, Samsung, Salesforce, and Amazon Web Services, as well as Airbus U.S. Space & Defense, Thales Group, Deutsche Bahn, Munich Re, and the London Stock Exchange Group.</p><h2 id="an-attack-that-is-still-a-concern-nearly-five-months-later">An attack that is still a concern nearly five months later</h2><p>The original attack occurred on March 24 2026 and was spearheaded by a financially motivated hacking group called TeamPCP, which compromised Trivy, an open source security tool that scans for vulnerabilities.</p><p>The modified package, which was subsequently downloaded and 'invited' in by LiteLLM without checking its ID- an automated process that essentially allowed a poisoned version of the trusted tool in- gained server administrator privileges and then installed a stealer.</p><p>The stealer compromised credentials and secrets far more valuable than corporate data, including Cloud keys, SSH keys, Kubernetes tokens, environment variables, repository and package-publishing tokens, and AI provider keys.</p><p>These are arguably worse from a security standpoint than a singular breach because of both the scale of the attack and the fact that hackers now had a 'key' to many security doors rather than having to run exploits to get there.</p><p>The victim-scale research <a href="https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines" target="_blank">done by CloudSEK</a> was further <a href="https://www.hudsonrock.com/blog/largest-ai-supply-chain-breach-of-2026-litellm-hack-impacts-thousands-of-global-enterprises-claim-your-ethical-disclosure" target="_blank">corroborated the following day by Hudson Rock,</a> and it painted a grim picture of what was still an outstanding issue nearly 5 months after the original attack.</p><p>The irony is that some of the credentials still work: Independent researcher Kevin Beaumont said <a href="https://cyberplace.social/@GossiTheDog/117084861164567831" target="_blank">some of the compromised keys were still valid</a> after he tested them, even as the impacted organization insisted it had 'rotated' those keys to new ones. </p><p>CloudSEK's figures indicate 2,500-plus companies and 434,000 CI/CD pipelines were compromised, while Hudson Rock has released a 153 GB archive of the exfiltrated material after examining a 195 TB file it had obtained. Both firms are running <a href="https://exposure.cloudsek.com/ai-supply-chain-incident" target="_blank">domain-lookup tools</a> so organizations can check their own exposure online.</p><p>Whether these revelations lead organizations to double-check their use of AI tools in multiple mission-critical instances that could compromise not only customer data but their own trade secrets down the line remains to be seen.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/massive-supply-chain-attack-sees-terabytes-of-data-belonging-to-some-of-the-worlds-biggest-and-most-sensitive-organizations-leaked-online</link>
                                                                            <description>
                            <![CDATA[ Hackers compromised a security tool, used it to steal the publishing keys of a popular AI tool, and released a poisoned version under that tool's real name in a far-reaching attack ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">P9jdiJp3QVmve9YwEXsdCb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Dtd9CSn6K6jfEdpnzch4zj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 21 Aug 2026 03:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Dtd9CSn6K6jfEdpnzch4zj-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Security padlock and circuit board to protect data]]></media:description>                                                            <media:text><![CDATA[Security padlock and circuit board to protect data]]></media:text>
                                <media:title type="plain"><![CDATA[Security padlock and circuit board to protect data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Dtd9CSn6K6jfEdpnzch4zj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>More than 2,500 organizations, including Cisco, Samsung, AWS, Airbus U.S. Space & Defense, Thales, and the London Stock Exchange Group, have credentials harvested during a supply-chain attack on LiteLLM</strong></li><li><strong>LiteLLM was not directly hacked by the hacking group TeamPCP, which found their way in thanks to a compromised build of an open-source security scanner</strong></li><li><strong>Some of the credentials still work, nearly five months after the original breach, indicating that there is still a persistent security risk until they are changed</strong></li></ul><p>Security firms CloudSEK and Hudson Rock have claimed more than 2,500 organizations have had credentials harvested in a supply-chain attack on LiteLLM.</p><p>LiteLLM, an open source gateway which translates API calls for over 100 large language models into a single OpenAI-compatible format, was not directly compromised in the attack, as hackers targeted a known vulnerability in Aqua Security's Trivy.</p><p>The list included many large and critical service providers, including but not limited to Cisco, Samsung, Salesforce, and Amazon Web Services, as well as Airbus U.S. Space & Defense, Thales Group, Deutsche Bahn, Munich Re, and the London Stock Exchange Group.</p><h2 id="an-attack-that-is-still-a-concern-nearly-five-months-later">An attack that is still a concern nearly five months later</h2><p>The original attack occurred on March 24 2026 and was spearheaded by a financially motivated hacking group called TeamPCP, which compromised Trivy, an open source security tool that scans for vulnerabilities.</p><p>The modified package, which was subsequently downloaded and 'invited' in by LiteLLM without checking its ID- an automated process that essentially allowed a poisoned version of the trusted tool in- gained server administrator privileges and then installed a stealer.</p><p>The stealer compromised credentials and secrets far more valuable than corporate data, including Cloud keys, SSH keys, Kubernetes tokens, environment variables, repository and package-publishing tokens, and AI provider keys.</p><p>These are arguably worse from a security standpoint than a singular breach because of both the scale of the attack and the fact that hackers now had a 'key' to many security doors rather than having to run exploits to get there.</p><p>The victim-scale research <a href="https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines" target="_blank">done by CloudSEK</a> was further <a href="https://www.hudsonrock.com/blog/largest-ai-supply-chain-breach-of-2026-litellm-hack-impacts-thousands-of-global-enterprises-claim-your-ethical-disclosure" target="_blank">corroborated the following day by Hudson Rock,</a> and it painted a grim picture of what was still an outstanding issue nearly 5 months after the original attack.</p><p>The irony is that some of the credentials still work: Independent researcher Kevin Beaumont said <a href="https://cyberplace.social/@GossiTheDog/117084861164567831" target="_blank">some of the compromised keys were still valid</a> after he tested them, even as the impacted organization insisted it had 'rotated' those keys to new ones. </p><p>CloudSEK's figures indicate 2,500-plus companies and 434,000 CI/CD pipelines were compromised, while Hudson Rock has released a 153 GB archive of the exfiltrated material after examining a 195 TB file it had obtained. Both firms are running <a href="https://exposure.cloudsek.com/ai-supply-chain-incident" target="_blank">domain-lookup tools</a> so organizations can check their own exposure online.</p><p>Whether these revelations lead organizations to double-check their use of AI tools in multiple mission-critical instances that could compromise not only customer data but their own trade secrets down the line remains to be seen.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are using “evolved” capabilities in AI-generated malware to hit US critical infrastructure at an unprecedented scale —  “active threat” currently hitting energy, water and agricultural industries ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Siemens S7 Series programmable logic controllers are being hit in a new critical infrastructure attack against energy, water and agriculture</strong></li><li><strong>Attackers are using AI-generated malware to chain exploitations, and hiding their malicious software as a monitoring tool</strong></li><li><strong>The identity of the attackers is not known</strong></li></ul><p>A joint warning issued by federal agencies has warned that US critical infrastructure is facing an “active threat” in the form of AI-generated malware specifically targeting programmable logic controllers (PLCs).</p><p>PLCs are widely used across the energy, water and agricultural industries to control pumps and monitor systems. The attacks have been labelled as an “evolution” in attacker capabilities, with the AI systems capable of chaining exploitations to gain control of PLCs.</p><p>The warning comes from the National Security Agency (NSA) and FBI, alongside other federal agencies who said in an <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a?utm_source=SiemensS7SeriesPLC&utm_medium=GovDelivery" target="_blank" rel="nofollow">advisory</a> that, “This is not a theoretical risk — it is an active threat.”</p><h2 id="siemens-s7-series-plcs-under-active-attack">Siemens S7 Series PLCs under active attack</h2><p>The advisory warns that Siemens S7 Series PLCs are the chosen target of this latest campaign with the attackers leveraging “AI-assisted development” in their penetration.</p><p>“Depending on the specific circumstances, exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems,” the advisory warns.</p><p>The identity of the attackers has not been revealed, but critical infrastructure systems are a favorite target of state-sponsored groups looking to scout out potential targets to later cripple water treatment and disrupt energy supplies.</p><p>The hackers are locating vulnerable PLCs using internet scanning platforms and disguising the malware as monitoring tools in order to evade detection. To defend against this attack vector, the advisory said that PLCs should be isolated from the internet, with software updates performed as soon as they become available.</p><p>The advisory said that the attacks are “an evolution in threat actor capabilities,” with the AI generated scripts “dramatically reducing the technical expertise and time required to develop working exploitation scripts and malicious tools.”</p><h2 id="who-has-been-targeting-critical-infrastructure">Who has been targeting critical infrastructure?</h2><p>The US war with Iran has led to a significant increase in attacks against critical infrastructure.</p><p>In July 2026, an <a href="https://www.techradar.com/pro/security/hackers-are-going-after-our-water-now-over-30-minnesota-utilities-hit-in-coordinated-cyberattack-by-apparent-iranian-attackers">attack against the operational technology of 30 Minnesota community water systems</a> showed indications of Iranian involvement. Shortly before the attack CISA updated an advisory warning that Rockwell Automation, Schneider Electric, and Siemens PLCs were under active attack.</p><p>April saw Rockwell Automation/Allen-Bradley-manufactured <a href="https://www.techradar.com/pro/security/us-agencies-warn-iranian-hackers-are-targeting-american-critical-infrastructure-causing-disruptive-effects-within-the-united-states">PLCs were exploited in attacks against water and energy systems</a>, as well as to compromise Government Services and Facilities. </p><p><a href="https://www.techradar.com/pro/security/nsa-warns-that-cybercriminals-are-targeting-this-one-critical-component-that-the-energy-chemical-food-agriculture-and-transportation-sectors-rely-on-heres-what-we-know">Automatic Tank Gauge (ATG) systems have also been hit during attacks</a> targeting energy, chemical, food, agriculture, and transportation industries. These systems were also found to be largely internet-facing, and when compromised could allow attackers to turn off systems designed to monitor fuel levels, temperature and potential leaks.</p><p>Russia has also been involved in targeting critical infrastructure at a global scale. The <a href="https://www.techradar.com/pro/security/us-and-security-allies-warn-russian-attacks-on-critical-infrastructure-are-ramping-up-against-poorly-configured-and-vulnerable-networking-devices-worldwide">attacks hit broken and poorly configured networking devices</a> such as routers that had passed their End-of-Life (EoL) and were no longer receiving updates.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/hackers-are-using-evolved-capabilities-in-ai-generated-malware-to-hit-us-critical-infrastructure-at-an-unprecedented-scale-active-threat-currently-hitting-energy-water-and-agricultural-industries</link>
                                                                            <description>
                            <![CDATA[ The attackers are exploiting internet-facing Siemens S7 Series programmable logic controllers to scout for potential targets. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QDfEDMhpgNJ3K4drrGKAGb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kHR7hTFieuBmjcpgHnKHh4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Aug 2026 17:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kHR7hTFieuBmjcpgHnKHh4-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/supimol kumying]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[cyber, attack, hacked word on screen binary code display, hacker]]></media:description>                                                            <media:text><![CDATA[cyber, attack, hacked word on screen binary code display, hacker]]></media:text>
                                <media:title type="plain"><![CDATA[cyber, attack, hacked word on screen binary code display, hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kHR7hTFieuBmjcpgHnKHh4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Siemens S7 Series programmable logic controllers are being hit in a new critical infrastructure attack against energy, water and agriculture</strong></li><li><strong>Attackers are using AI-generated malware to chain exploitations, and hiding their malicious software as a monitoring tool</strong></li><li><strong>The identity of the attackers is not known</strong></li></ul><p>A joint warning issued by federal agencies has warned that US critical infrastructure is facing an “active threat” in the form of AI-generated malware specifically targeting programmable logic controllers (PLCs).</p><p>PLCs are widely used across the energy, water and agricultural industries to control pumps and monitor systems. The attacks have been labelled as an “evolution” in attacker capabilities, with the AI systems capable of chaining exploitations to gain control of PLCs.</p><p>The warning comes from the National Security Agency (NSA) and FBI, alongside other federal agencies who said in an <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a?utm_source=SiemensS7SeriesPLC&utm_medium=GovDelivery" target="_blank" rel="nofollow">advisory</a> that, “This is not a theoretical risk — it is an active threat.”</p><h2 id="siemens-s7-series-plcs-under-active-attack">Siemens S7 Series PLCs under active attack</h2><p>The advisory warns that Siemens S7 Series PLCs are the chosen target of this latest campaign with the attackers leveraging “AI-assisted development” in their penetration.</p><p>“Depending on the specific circumstances, exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems,” the advisory warns.</p><p>The identity of the attackers has not been revealed, but critical infrastructure systems are a favorite target of state-sponsored groups looking to scout out potential targets to later cripple water treatment and disrupt energy supplies.</p><p>The hackers are locating vulnerable PLCs using internet scanning platforms and disguising the malware as monitoring tools in order to evade detection. To defend against this attack vector, the advisory said that PLCs should be isolated from the internet, with software updates performed as soon as they become available.</p><p>The advisory said that the attacks are “an evolution in threat actor capabilities,” with the AI generated scripts “dramatically reducing the technical expertise and time required to develop working exploitation scripts and malicious tools.”</p><h2 id="who-has-been-targeting-critical-infrastructure">Who has been targeting critical infrastructure?</h2><p>The US war with Iran has led to a significant increase in attacks against critical infrastructure.</p><p>In July 2026, an <a href="https://www.techradar.com/pro/security/hackers-are-going-after-our-water-now-over-30-minnesota-utilities-hit-in-coordinated-cyberattack-by-apparent-iranian-attackers">attack against the operational technology of 30 Minnesota community water systems</a> showed indications of Iranian involvement. Shortly before the attack CISA updated an advisory warning that Rockwell Automation, Schneider Electric, and Siemens PLCs were under active attack.</p><p>April saw Rockwell Automation/Allen-Bradley-manufactured <a href="https://www.techradar.com/pro/security/us-agencies-warn-iranian-hackers-are-targeting-american-critical-infrastructure-causing-disruptive-effects-within-the-united-states">PLCs were exploited in attacks against water and energy systems</a>, as well as to compromise Government Services and Facilities. </p><p><a href="https://www.techradar.com/pro/security/nsa-warns-that-cybercriminals-are-targeting-this-one-critical-component-that-the-energy-chemical-food-agriculture-and-transportation-sectors-rely-on-heres-what-we-know">Automatic Tank Gauge (ATG) systems have also been hit during attacks</a> targeting energy, chemical, food, agriculture, and transportation industries. These systems were also found to be largely internet-facing, and when compromised could allow attackers to turn off systems designed to monitor fuel levels, temperature and potential leaks.</p><p>Russia has also been involved in targeting critical infrastructure at a global scale. The <a href="https://www.techradar.com/pro/security/us-and-security-allies-warn-russian-attacks-on-critical-infrastructure-are-ramping-up-against-poorly-configured-and-vulnerable-networking-devices-worldwide">attacks hit broken and poorly configured networking devices</a> such as routers that had passed their End-of-Life (EoL) and were no longer receiving updates.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Scammers pose as ransomware recovery agents, but just go on to steal more from victims ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>GuidePoint observed “Ransom Busters” posing as recovery firms in ransomware incidents</strong></li><li><strong>Group claimed to hack RaaS panels, offering decryption keys for $20K–$60K</strong></li><li><strong>Researchers say it’s likely the same affiliates behind infections, not genuine rescuers</strong></li></ul><p>Ransomware operations have evolved again, and this time around the crooks are pretending to be the good guys.</p><p>Cybersecurity researchers GuidePoint Security were recently brought in to respond to multiple <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> attacks against their clients. In some of those incidents, the victims were also contacted by a group calling themselves “Ransom Busters”, which offered to delete the stolen files from the attackers’ servers, while providing the victims with working decryption keys.</p><p>What made the offer suspicious was the fact that Ransom Busters reached out to the victims before the attackers had gone public. The crooks claimed to have hacked into the admin panels of multiple Ransomware-as-a-Service (RaaS) operations, including DragonForce, Settra, and Anubis, giving them not just insight into who was targeted, but also access to stolen data and the decryption keys.</p><h2 id="just-another-affiliate">Just another affiliate</h2><p>For their services, Ransom Busters ask between $20,000, and $60,000 - however, the researchers are saying this is all a ruse, and that Ransom Busters are, most likely, just affiliates of these ransomware services. Not only that, but they are also most likely the ones who infected these companies with ransomware in the first place.</p><p>They said that both the attackers and Ransom Busters are using the same software, same tactics, and same identifiers, leading to the conclusion that it’s the same group on both ends of the spectrum. </p><p>The good news is that no one seems to have paid Ransom Busters for their offer. The only thing GuidePoint observed was one victim paying the actual ransom demand, rather than the fake recovery firm. That firm, fortunately, did not have its name listed on the leak site, and its files remain secure for now.</p><p>Pretending to be a recovery firm is the next evolutionary step in the life of ransomware. </p><p>In its early days, ransomware was all about encrypting the computers and asking for payment in exchange for the decryption key. When companies responded by building out strong backups, the criminals moved to stealing files and threatening to release them to the public. Soon after, some added Distributed Denial of Service (DDoS) into the mix, blocking not just the back end but also the front-end, in an effort to force a payment.</p><p>Some criminals even called their victims on the phone for further intimidation.</p><p>These days, more and more groups are moving away from encryptors and focus solely on data theft, since it’s cheaper yet equally lucrative.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-recovery-firm/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/scammers-pose-as-ransomware-recovery-agents-but-just-go-on-to-steal-more-from-victims</link>
                                                                            <description>
                            <![CDATA[ Ransom Busters are not an actual ransomware recovery firm - they're ransomware affiliates looking to steal your money, too. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3sbDoKf4V4v9EtMs8LXuvL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Aug 2026 15:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:description>                                                            <media:text><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:text>
                                <media:title type="plain"><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>GuidePoint observed “Ransom Busters” posing as recovery firms in ransomware incidents</strong></li><li><strong>Group claimed to hack RaaS panels, offering decryption keys for $20K–$60K</strong></li><li><strong>Researchers say it’s likely the same affiliates behind infections, not genuine rescuers</strong></li></ul><p>Ransomware operations have evolved again, and this time around the crooks are pretending to be the good guys.</p><p>Cybersecurity researchers GuidePoint Security were recently brought in to respond to multiple <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> attacks against their clients. In some of those incidents, the victims were also contacted by a group calling themselves “Ransom Busters”, which offered to delete the stolen files from the attackers’ servers, while providing the victims with working decryption keys.</p><p>What made the offer suspicious was the fact that Ransom Busters reached out to the victims before the attackers had gone public. The crooks claimed to have hacked into the admin panels of multiple Ransomware-as-a-Service (RaaS) operations, including DragonForce, Settra, and Anubis, giving them not just insight into who was targeted, but also access to stolen data and the decryption keys.</p><h2 id="just-another-affiliate">Just another affiliate</h2><p>For their services, Ransom Busters ask between $20,000, and $60,000 - however, the researchers are saying this is all a ruse, and that Ransom Busters are, most likely, just affiliates of these ransomware services. Not only that, but they are also most likely the ones who infected these companies with ransomware in the first place.</p><p>They said that both the attackers and Ransom Busters are using the same software, same tactics, and same identifiers, leading to the conclusion that it’s the same group on both ends of the spectrum. </p><p>The good news is that no one seems to have paid Ransom Busters for their offer. The only thing GuidePoint observed was one victim paying the actual ransom demand, rather than the fake recovery firm. That firm, fortunately, did not have its name listed on the leak site, and its files remain secure for now.</p><p>Pretending to be a recovery firm is the next evolutionary step in the life of ransomware. </p><p>In its early days, ransomware was all about encrypting the computers and asking for payment in exchange for the decryption key. When companies responded by building out strong backups, the criminals moved to stealing files and threatening to release them to the public. Soon after, some added Distributed Denial of Service (DDoS) into the mix, blocking not just the back end but also the front-end, in an effort to force a payment.</p><p>Some criminals even called their victims on the phone for further intimidation.</p><p>These days, more and more groups are moving away from encryptors and focus solely on data theft, since it’s cheaper yet equally lucrative.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-recovery-firm/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Healthtech firm CareCloud reveals March 2026 data breach impacted 3.7 million patients ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>CareCloud confirmed March 16 2026 cyberattack exposed data of 3.7 million individuals</strong></li><li><strong>Attackers accessed one AWS environment, stealing personal records including names</strong></li><li><strong>Incident deemed non‑material but may incur remediation, legal, and reputational costs</strong></li></ul><p>The <a href="https://www.techradar.com/pro/security/healthcare-tech-firm-carecloud-admits-data-breach-says-hackers-accessed-patient-info-heres-what-we-know" target="_blank">March 2026 cyberattack on CareCloud</a> exposed sensitive data on 3.7 million people, the company has confirmed.</p><p>The American <a href="https://www.techradar.com/best/best-electronic-health-record-ehr-software" target="_blank">IT healthcare</a> company had told the US Securities and Exchange Commission (SEC) it experienced a “temporary network disruption” in its Health division which “partially impacted the functionality and data access to one of six electronic health record environments for approximately eight hours."</p><p>Initial investigation determined that the criminals accessed people’s personal records, but it was not said how many people were affected, what the nature of the files were, or if they were exfiltrated or just exposed.</p><h2 id="notifying-the-department-of-health">Notifying the Department of Health</h2><p>In late July 2026, the company started notifying its customers of the incident, saying the unidentified actors accessed one of CareCloud’s AWS environments and claimed to have stolen files found there. The company did not say which type of data was taken, other than people’s full names. </p><p>In a separate report with the US Department of Health and Human Services, the company confirmed the exact number of affected individuals as 3,756,469.</p><p>At press time, no hacking groups claimed responsibility for the attack, or shared details about the volume, nature, and type of data potentially stolen.</p><p>CareCloud is a publicly traded American healthcare technology firm providing <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">cloud‑based software</a> and services to medical practices and health systems, including electronic health records (EHR), practice management, billing and revenue cycle solutions. It works with tens of thousands of healthcare providers across the United States in more than 70 specialties and across all 50 states, with over 40,000 providers on its platform.</p><p>In its initial report with the SEC, CareCloud said the incident did not have a material impact, but that it might incur expenses in remediation and response costs, legal, regulatory and notification-related matters, and could possibly affect patients, customers, counterparties, reputation and operations.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/healthtech-firm-carecloud-data-breach-impacts-37-million-patients/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/healthtech-firm-carecloud-reveals-march-2026-data-breach-impacted-3-7-million-patients</link>
                                                                            <description>
                            <![CDATA[ Impacted CareCloud patients are being notified, but we don't know what information was taken. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">YbMtuDcty3QHXHSSBtvpj7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fLLbfyMxWuqokngy6WuMzH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Aug 2026 13:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fLLbfyMxWuqokngy6WuMzH-1280-80.jpg">
                                                            <media:credit><![CDATA[Rawpixel / Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[healthcare]]></media:description>                                                            <media:text><![CDATA[healthcare]]></media:text>
                                <media:title type="plain"><![CDATA[healthcare]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fLLbfyMxWuqokngy6WuMzH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>CareCloud confirmed March 16 2026 cyberattack exposed data of 3.7 million individuals</strong></li><li><strong>Attackers accessed one AWS environment, stealing personal records including names</strong></li><li><strong>Incident deemed non‑material but may incur remediation, legal, and reputational costs</strong></li></ul><p>The <a href="https://www.techradar.com/pro/security/healthcare-tech-firm-carecloud-admits-data-breach-says-hackers-accessed-patient-info-heres-what-we-know" target="_blank">March 2026 cyberattack on CareCloud</a> exposed sensitive data on 3.7 million people, the company has confirmed.</p><p>The American <a href="https://www.techradar.com/best/best-electronic-health-record-ehr-software" target="_blank">IT healthcare</a> company had told the US Securities and Exchange Commission (SEC) it experienced a “temporary network disruption” in its Health division which “partially impacted the functionality and data access to one of six electronic health record environments for approximately eight hours."</p><p>Initial investigation determined that the criminals accessed people’s personal records, but it was not said how many people were affected, what the nature of the files were, or if they were exfiltrated or just exposed.</p><h2 id="notifying-the-department-of-health">Notifying the Department of Health</h2><p>In late July 2026, the company started notifying its customers of the incident, saying the unidentified actors accessed one of CareCloud’s AWS environments and claimed to have stolen files found there. The company did not say which type of data was taken, other than people’s full names. </p><p>In a separate report with the US Department of Health and Human Services, the company confirmed the exact number of affected individuals as 3,756,469.</p><p>At press time, no hacking groups claimed responsibility for the attack, or shared details about the volume, nature, and type of data potentially stolen.</p><p>CareCloud is a publicly traded American healthcare technology firm providing <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">cloud‑based software</a> and services to medical practices and health systems, including electronic health records (EHR), practice management, billing and revenue cycle solutions. It works with tens of thousands of healthcare providers across the United States in more than 70 specialties and across all 50 states, with over 40,000 providers on its platform.</p><p>In its initial report with the SEC, CareCloud said the incident did not have a material impact, but that it might incur expenses in remediation and response costs, legal, regulatory and notification-related matters, and could possibly affect patients, customers, counterparties, reputation and operations.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/healthtech-firm-carecloud-data-breach-impacts-37-million-patients/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Over 9 million facial recognition images leaked in major breach at reverse image search and identity verification service ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Researcher inds ClarityCheck’s exposed 450GB database with 9M+ user images</strong></li><li><strong>Leak included faces, profiles, and photos, risking identity theft and phishing abuse</strong></li><li><strong>Company secured access quickly; no evidence of dark web distribution or misuse so far</strong></li></ul><p>An online reverse-lookup platform has inadvertently leaked millions of faces on the internet, putting people at risk of <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a>, phishing, and more, experts have warned.</p><p>Jeremiah Fowler, a cybersecurity researcher known for hunting exposed databases, <a href="https://www.expressvpn.com/blog/clarity-check-data-exposed/" target="_blank">recently found</a> one totaling 450.2GB in size. </p><p>It contained exactly 9,042,977 image files - profile pictures, screenshots, and scans of physical photographs - all seemingly uploaded by the users. The images showed adults, teenagers, and even children, and were stored in folders labeled “faces” and “profiles”.</p><h2 id="what-happened">What happened?</h2><p>Further investigation showed the database belonging to a company called ClarityCheck. This is a US-registered firm describing itself as a “reverse phone, email, image, vehicle lookup”, allowing users to identify unknown callers, verify online contacts, check photos, and decode vehicles using publicly available data from “trusted sources”.</p><p>It is a legitimate business whose use case grows more important by the day - cybercriminals create fake internet personas every day, and use them in all sorts of schemes, from romance scams, to fake job offers, to anything in between. To do that, they will either steal other people’s photos, obtain (or buy) them on the dark web, or generate them using artificial intelligence. </p><p>Being able to verify someone’s identity has become everyone’s essential due diligence, regardless of if it’s a personal or business matter.</p><h2 id="how-claritycheck-responded">How ClarityCheck responded</h2><p>As soon as Fowler confirmed who owned the database, he reached out to ClarityCheck and responsibly disclosed his findings. The company responded quickly, barring further access, and thanking the researcher for his work.</p><p>“I completely understand your concerns regarding the exposure of sensitive images and the associated privacy risks. We greatly appreciate ethical researchers like you who bring these matters to our attention so we can act swiftly to protect our users' data and privacy,” the company’s representative told Fowler.</p><p>Unfortunately, without a deeper investigation on ClarityCheck’s end, there is no way of confirming exactly how long the database remained open, or if anyone accessed it before. However, so far there is no evidence of abuse, since a “ClarityCheck photo database” is currently not being distributed or sold anywhere on the dark web.</p><h2 id="exposing-people-to-hackers">Exposing people to hackers</h2><p>In a world where data theft and leaks are increasingly common, a cause that’s easiest to address, is also the one resulting in most exposures - <a href="https://www.techradar.com/pro/security/the-biggest-data-leaker-is-probably-not-who-you-think-it-is" target="_blank">misconfigured databases</a>. Nowadays, almost every business harvests and stores data about their employees, partners, and customers. Most of them store these files in cloud databases, for easier access and better integration with business intelligence software.</p><p>However, cloud service providers work on a so-called “shared responsibility model”, which means they are responsible for providing industry-standard security features. Users, on the other hand, are responsible for using those features and properly configuring their databases (namely, setting up a strong password or encrypting the content). Unfortunately, many organizations don’t seem to be aware of the shared responsibility model, firmly believing it’s the service provider’s task to keep the data safe. Others simply keep these archives accessible by mistake.</p><p>Criminals are aware of this, and are taking advantage of the situation to steal valuable information. By using widely available tools like Shodan, Censys, or FOFA, they can scour the web for unencrypted, non-password protected databases, and exfiltrate data to be used in phishing, business email compromise, and other forms of cyberattacks.</p><p>Over the years, Fowler and other searchers have found dozens of enormous databases that have leaked sensitive data on hundreds of millions of people. </p><p>In 2026, researchers found that European cloud provider Nextcloud kept an <a href="https://www.techradar.com/pro/security/nextcloud-leaks-367k-records-european-cloud-giant-exposes-staff-and-clients-in-major-breach">unprotected database</a> on the public internet, containing 367,000 records (8GB) of sensitive employee and client data.</p><p>In 2025, IMDataCenter, a Florida-based data hygiene, enhancement, and append services provider, was <a href="https://www.techradar.com/pro/security/data-center-firm-leaks-massive-38gb-database-containing-thousands-of-personal-records-online">leaking</a> 38GB of sensitive personal records. The unencrypted and non-password-protected database held 10,820 in total.</p><p>In 2024, sports analytics technology company TrackMan <a href="https://www.techradar.com/pro/security/top-sports-tech-firm-leaked-data-and-even-professional-athletes-could-be-affected">exposed</a> sensitive customer data: 110TB and 31,602,260 records. The database had no password.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/over-9-million-facial-recognition-images-leaked-in-major-breach-at-reverse-image-search-and-identity-verification-service</link>
                                                                            <description>
                            <![CDATA[ ClarityCheck locks down huge database after being notified about the spill. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">62yugNeibkwi9EAvzkKbvV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BUi4eir3JnCCT2MRGt3weS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Aug 2026 11:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BUi4eir3JnCCT2MRGt3weS-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Back View of Young Black Man Walking and Looking at Big Digital Screens Glitching While Displaying Code Lines. Professional Hacker Breaking Through Cybersecurity Protection System, Changing Code]]></media:description>                                                            <media:text><![CDATA[Back View of Young Black Man Walking and Looking at Big Digital Screens Glitching While Displaying Code Lines. Professional Hacker Breaking Through Cybersecurity Protection System, Changing Code]]></media:text>
                                <media:title type="plain"><![CDATA[Back View of Young Black Man Walking and Looking at Big Digital Screens Glitching While Displaying Code Lines. Professional Hacker Breaking Through Cybersecurity Protection System, Changing Code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BUi4eir3JnCCT2MRGt3weS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researcher inds ClarityCheck’s exposed 450GB database with 9M+ user images</strong></li><li><strong>Leak included faces, profiles, and photos, risking identity theft and phishing abuse</strong></li><li><strong>Company secured access quickly; no evidence of dark web distribution or misuse so far</strong></li></ul><p>An online reverse-lookup platform has inadvertently leaked millions of faces on the internet, putting people at risk of <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a>, phishing, and more, experts have warned.</p><p>Jeremiah Fowler, a cybersecurity researcher known for hunting exposed databases, <a href="https://www.expressvpn.com/blog/clarity-check-data-exposed/" target="_blank">recently found</a> one totaling 450.2GB in size. </p><p>It contained exactly 9,042,977 image files - profile pictures, screenshots, and scans of physical photographs - all seemingly uploaded by the users. The images showed adults, teenagers, and even children, and were stored in folders labeled “faces” and “profiles”.</p><h2 id="what-happened">What happened?</h2><p>Further investigation showed the database belonging to a company called ClarityCheck. This is a US-registered firm describing itself as a “reverse phone, email, image, vehicle lookup”, allowing users to identify unknown callers, verify online contacts, check photos, and decode vehicles using publicly available data from “trusted sources”.</p><p>It is a legitimate business whose use case grows more important by the day - cybercriminals create fake internet personas every day, and use them in all sorts of schemes, from romance scams, to fake job offers, to anything in between. To do that, they will either steal other people’s photos, obtain (or buy) them on the dark web, or generate them using artificial intelligence. </p><p>Being able to verify someone’s identity has become everyone’s essential due diligence, regardless of if it’s a personal or business matter.</p><h2 id="how-claritycheck-responded">How ClarityCheck responded</h2><p>As soon as Fowler confirmed who owned the database, he reached out to ClarityCheck and responsibly disclosed his findings. The company responded quickly, barring further access, and thanking the researcher for his work.</p><p>“I completely understand your concerns regarding the exposure of sensitive images and the associated privacy risks. We greatly appreciate ethical researchers like you who bring these matters to our attention so we can act swiftly to protect our users' data and privacy,” the company’s representative told Fowler.</p><p>Unfortunately, without a deeper investigation on ClarityCheck’s end, there is no way of confirming exactly how long the database remained open, or if anyone accessed it before. However, so far there is no evidence of abuse, since a “ClarityCheck photo database” is currently not being distributed or sold anywhere on the dark web.</p><h2 id="exposing-people-to-hackers">Exposing people to hackers</h2><p>In a world where data theft and leaks are increasingly common, a cause that’s easiest to address, is also the one resulting in most exposures - <a href="https://www.techradar.com/pro/security/the-biggest-data-leaker-is-probably-not-who-you-think-it-is" target="_blank">misconfigured databases</a>. Nowadays, almost every business harvests and stores data about their employees, partners, and customers. Most of them store these files in cloud databases, for easier access and better integration with business intelligence software.</p><p>However, cloud service providers work on a so-called “shared responsibility model”, which means they are responsible for providing industry-standard security features. Users, on the other hand, are responsible for using those features and properly configuring their databases (namely, setting up a strong password or encrypting the content). Unfortunately, many organizations don’t seem to be aware of the shared responsibility model, firmly believing it’s the service provider’s task to keep the data safe. Others simply keep these archives accessible by mistake.</p><p>Criminals are aware of this, and are taking advantage of the situation to steal valuable information. By using widely available tools like Shodan, Censys, or FOFA, they can scour the web for unencrypted, non-password protected databases, and exfiltrate data to be used in phishing, business email compromise, and other forms of cyberattacks.</p><p>Over the years, Fowler and other searchers have found dozens of enormous databases that have leaked sensitive data on hundreds of millions of people. </p><p>In 2026, researchers found that European cloud provider Nextcloud kept an <a href="https://www.techradar.com/pro/security/nextcloud-leaks-367k-records-european-cloud-giant-exposes-staff-and-clients-in-major-breach">unprotected database</a> on the public internet, containing 367,000 records (8GB) of sensitive employee and client data.</p><p>In 2025, IMDataCenter, a Florida-based data hygiene, enhancement, and append services provider, was <a href="https://www.techradar.com/pro/security/data-center-firm-leaks-massive-38gb-database-containing-thousands-of-personal-records-online">leaking</a> 38GB of sensitive personal records. The unencrypted and non-password-protected database held 10,820 in total.</p><p>In 2024, sports analytics technology company TrackMan <a href="https://www.techradar.com/pro/security/top-sports-tech-firm-leaked-data-and-even-professional-athletes-could-be-affected">exposed</a> sensitive customer data: 110TB and 31,602,260 records. The database had no password.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts manage to hack Microsoft Copilot by continually asking it questions about itself ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Varonis uncovers CoSnitch, a chain of flaws letting Copilot leak sensitive data</strong></li><li><strong>Exploit used malicious URLs and persistent memory poisoning to bypass guardrails</strong></li><li><strong>Microsoft patched CVE‑2026‑24301 server‑side; technique may affect other AI models</strong></li></ul><p>Microsoft’s Copilot AI just told a group of researchers how to abuse it for data exfiltration, and it worked. It was not a straightforward process, and the AI did not turn “evil”, but one might say it is gullible and somewhat naive.</p><p>Security firm Varonis has published a new report outlining its discovery of a vulnerability in Copilot they named <a href="https://www.varonis.com/blog/cosnitch" target="_blank">CoSnitch</a>. </p><p>The name is a major hint at what the vulnerability is - as CoSnitch is a chain of three vulnerabilities which Microsoft later labeled as CVE-2026-24301, giving it a severity score of 8.8/10 (high), and fixing it with a patch.</p><h2 id="you-can-t-trick-me-and-i-ll-tell-you-exactly-why">You can’t trick me, and I’ll tell you exactly why</h2><p>Cybercriminals have long been using AI as part of their arsenal, as it helps them draft convincing phishing emails, write malicious code, and identify high-value targets - and developers have responded by placing guardrails, which making AI outright refuse to do certain things. </p><p>In the report, Varonis said its researchers did not hunt for bugs in the code or try to reverse-engineer an existing exploit. They just talked to the <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI</a>, and with each subsequent question, learned more about its guardrails and how they work. They called the technique “meta-hacking”.</p><p>Whenever Copilot declined a request, it explained why, giving the researchers snippets of insight into how it operates. Or, as Varonis hinted, it “snitched” on itself. This, eventually, helped them map out its defenses and learn how to work around it:</p><p>“The resistance is part of the technique,” they explained. “Each “that won’t work because…” is an invitation to probe the “because.” You don’t exploit the model. You manipulate it into cooperating.”</p><p>After a long conversation with Copilot, the researchers were told, inadvertently, how to create a URL which would, as soon as it was clicked, kick off a chain reaction that resulted in sensitive data exfiltration.</p><h2 id="the-dangers-of-connecting-ai-to-apps">The dangers of connecting AI to apps</h2><p>So, Varonis learned that by creating a URL like this one - “https://copilot.microsoft.com/?q=&autorun=1*” - they could get Copilot to run any malicious prompt as soon as it was clicked. Threat actors could, for example, add this link in a phishing email and trick the victim into clicking on it, telling AI to send all sensitive data to the attackers’ infrastructure.</p><p>But that is only half of the challenge. In this setup, the researchers could only exfiltrate the data the victims shared with Copilot during their sessions together. </p><p>The risk escalates the moment the victim connects the AI to their apps - Gmail, Drive, Calendar, and others. As Varonis explained, the malicious prompt could tell Copilot to exfiltrate all email addresses found in Gmail, all passwords and other secrets found in the emails’ bodies, all information stored in the Drive folder, and all events logged in the Calendar.</p><p>The third part of the CoSnitch vulnerability chain is called “Persistent memory poisoning via web summarization”. As Varonis explained, attackers could craft a webpage which, when summarized by Copilot, injects attacker instructions into the victim's permanent memory store. </p><p>“The injection survives password changes, session revocation, and device re-enrollment, persisting forever,” they warned. This flaw is called “indirect prompt injection” and it is not exactly novel - it’s been observed before and stems from the fact that the AI cannot differentiate between instructions, and data to be analyzed.</p><p>Microsoft was notified about the existence of CoSnitch in December 2025, but only addressed it in mid-August 2026, the researchers said. Unfortunately, we don’t know how Microsoft sorted it - we can only speculate Copilot was instructed not to explain how its guardrails work. Given what CoSnitch is in the first place, perhaps it is for the best that Microsoft hid the solution. </p><p>Luckily enough, it doesn’t seem to have been exploited in the wild, since Varonis could not find any evidence of abuse. The fix was applied on the server side, meaning there is nothing for users to do at this point. </p><p>Since this is not a bug in the code, other AI models might be susceptible to the same techniques, the researchers warned. “The novel meta-hacking technique that uncovered CoSnitch — using the AI’s own reasoning to surface its hidden internals — applies to any agentic platform with a natural language interface,” they concluded, adding that they’ll be publishing more research soon.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/experts-manage-to-hack-microsoft-copilot-by-continually-asking-it-questions-about-itself</link>
                                                                            <description>
                            <![CDATA[ An AI isn't secure if it's gullible and can be tricked into compliance, experts find. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">osapivCe5RVsp5iw5HpeDY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GxSNrV6MwnmZHmLEQHF58B-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Aug 2026 14:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GxSNrV6MwnmZHmLEQHF58B-1280-80.jpg">
                                                            <media:credit><![CDATA[Microsoft]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Copilot keyboard button]]></media:description>                                                            <media:text><![CDATA[Copilot keyboard button]]></media:text>
                                <media:title type="plain"><![CDATA[Copilot keyboard button]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GxSNrV6MwnmZHmLEQHF58B-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Varonis uncovers CoSnitch, a chain of flaws letting Copilot leak sensitive data</strong></li><li><strong>Exploit used malicious URLs and persistent memory poisoning to bypass guardrails</strong></li><li><strong>Microsoft patched CVE‑2026‑24301 server‑side; technique may affect other AI models</strong></li></ul><p>Microsoft’s Copilot AI just told a group of researchers how to abuse it for data exfiltration, and it worked. It was not a straightforward process, and the AI did not turn “evil”, but one might say it is gullible and somewhat naive.</p><p>Security firm Varonis has published a new report outlining its discovery of a vulnerability in Copilot they named <a href="https://www.varonis.com/blog/cosnitch" target="_blank">CoSnitch</a>. </p><p>The name is a major hint at what the vulnerability is - as CoSnitch is a chain of three vulnerabilities which Microsoft later labeled as CVE-2026-24301, giving it a severity score of 8.8/10 (high), and fixing it with a patch.</p><h2 id="you-can-t-trick-me-and-i-ll-tell-you-exactly-why">You can’t trick me, and I’ll tell you exactly why</h2><p>Cybercriminals have long been using AI as part of their arsenal, as it helps them draft convincing phishing emails, write malicious code, and identify high-value targets - and developers have responded by placing guardrails, which making AI outright refuse to do certain things. </p><p>In the report, Varonis said its researchers did not hunt for bugs in the code or try to reverse-engineer an existing exploit. They just talked to the <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI</a>, and with each subsequent question, learned more about its guardrails and how they work. They called the technique “meta-hacking”.</p><p>Whenever Copilot declined a request, it explained why, giving the researchers snippets of insight into how it operates. Or, as Varonis hinted, it “snitched” on itself. This, eventually, helped them map out its defenses and learn how to work around it:</p><p>“The resistance is part of the technique,” they explained. “Each “that won’t work because…” is an invitation to probe the “because.” You don’t exploit the model. You manipulate it into cooperating.”</p><p>After a long conversation with Copilot, the researchers were told, inadvertently, how to create a URL which would, as soon as it was clicked, kick off a chain reaction that resulted in sensitive data exfiltration.</p><h2 id="the-dangers-of-connecting-ai-to-apps">The dangers of connecting AI to apps</h2><p>So, Varonis learned that by creating a URL like this one - “https://copilot.microsoft.com/?q=&autorun=1*” - they could get Copilot to run any malicious prompt as soon as it was clicked. Threat actors could, for example, add this link in a phishing email and trick the victim into clicking on it, telling AI to send all sensitive data to the attackers’ infrastructure.</p><p>But that is only half of the challenge. In this setup, the researchers could only exfiltrate the data the victims shared with Copilot during their sessions together. </p><p>The risk escalates the moment the victim connects the AI to their apps - Gmail, Drive, Calendar, and others. As Varonis explained, the malicious prompt could tell Copilot to exfiltrate all email addresses found in Gmail, all passwords and other secrets found in the emails’ bodies, all information stored in the Drive folder, and all events logged in the Calendar.</p><p>The third part of the CoSnitch vulnerability chain is called “Persistent memory poisoning via web summarization”. As Varonis explained, attackers could craft a webpage which, when summarized by Copilot, injects attacker instructions into the victim's permanent memory store. </p><p>“The injection survives password changes, session revocation, and device re-enrollment, persisting forever,” they warned. This flaw is called “indirect prompt injection” and it is not exactly novel - it’s been observed before and stems from the fact that the AI cannot differentiate between instructions, and data to be analyzed.</p><p>Microsoft was notified about the existence of CoSnitch in December 2025, but only addressed it in mid-August 2026, the researchers said. Unfortunately, we don’t know how Microsoft sorted it - we can only speculate Copilot was instructed not to explain how its guardrails work. Given what CoSnitch is in the first place, perhaps it is for the best that Microsoft hid the solution. </p><p>Luckily enough, it doesn’t seem to have been exploited in the wild, since Varonis could not find any evidence of abuse. The fix was applied on the server side, meaning there is nothing for users to do at this point. </p><p>Since this is not a bug in the code, other AI models might be susceptible to the same techniques, the researchers warned. “The novel meta-hacking technique that uncovered CoSnitch — using the AI’s own reasoning to surface its hidden internals — applies to any agentic platform with a natural language interface,” they concluded, adding that they’ll be publishing more research soon.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft smothers malware by tracking behavior instead of blocking domains ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft says blocking domains is ineffective against MacSync Stealer’s evolving infrastructure</strong></li><li><strong>Defender experts tracked over 30 domains by analyzing behavioral patterns instead</strong></li><li><strong>Mitigation focuses on spotting suspicious shell sessions, osascript activity, and /tmp/sync archives</strong></li></ul><p>Microsoft says it has found a way to stop the dangerous MacSync Stealer malware by monitoring certain behaviors, rather than keeping track of the domains used in the attacks. </p><p>MacSync Stealer is a piece of infostealer <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> built for the Apple ecosystem - it steals passwords, browser data, cookies, Keychain secrets, cryptocurrency wallets, Telegram sessions, SSH/cloud credentials and other sensitive information.</p><p>It was being distributed via ClickFix scams. Victims would visit a malicious website which would tell them they had a problem (an outdated browser or a “protected” document that can only be viewed after “verifying” identities), and which would immediately offer a solution. That solution is to bring up the Terminal and paste a command which, in reality, deployed the malware. </p><p>Initially, defenders would keep their Mac fleets safe by blocking the domains used to host the infrastructure - the websites, the malware executables, and the exfiltrated data. But they soon realized that a new domain would pop up as soon as the old one was blocked, and the malware would continue its operations unabated.</p><h2 id="behavioral-analysis">Behavioral analysis</h2><p>Now, in a new <a href="https://www.microsoft.com/en-us/security/blog/2026/08/18/hunting-macsync-stealer-infrastructure-through-behavioral-pivots/" target="_blank" rel="nofollow">report</a>, Microsoft said it successfully identified more than 30 domains by looking at behavioral patterns such as repeated execution, request characteristics, staging behavior, and upload methods.</p><p>“Microsoft Defender Experts expanded that view by correlating recurring endpoints and network behaviors across the activity. This behavior-led approach connected more than 30 domains and showed that the infrastructure supported more than C2 communication, extending into active collection, staging, and exfiltration,” Microsoft explained.</p><p>In other words, to defend against MacSync Stealer, don’t focus on blocking domains. Instead, pay attention to shell sessions spawning ‘curl’ with specific flag combinations, osascript quickly chaining into network activity, and archives appearing under /tmp/sync just before outbound PUT traffic begins.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/microsoft-smothers-malware-by-tracking-behavior-instead-of-blocking-domains</link>
                                                                            <description>
                            <![CDATA[ Blocking domains is a game of whack-a-mole in which attackers automate new moles popping up almost instantly. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">s7yaw5ga5C2LtpwcJawi2K</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/G8QNviZt3KrDbfWVANJrNM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Aug 2026 14:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/G8QNviZt3KrDbfWVANJrNM-1280-80.jpg">
                                                            <media:credit><![CDATA[Elchinator from Pixabay ]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[malware]]></media:description>                                                            <media:text><![CDATA[malware]]></media:text>
                                <media:title type="plain"><![CDATA[malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/G8QNviZt3KrDbfWVANJrNM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft says blocking domains is ineffective against MacSync Stealer’s evolving infrastructure</strong></li><li><strong>Defender experts tracked over 30 domains by analyzing behavioral patterns instead</strong></li><li><strong>Mitigation focuses on spotting suspicious shell sessions, osascript activity, and /tmp/sync archives</strong></li></ul><p>Microsoft says it has found a way to stop the dangerous MacSync Stealer malware by monitoring certain behaviors, rather than keeping track of the domains used in the attacks. </p><p>MacSync Stealer is a piece of infostealer <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> built for the Apple ecosystem - it steals passwords, browser data, cookies, Keychain secrets, cryptocurrency wallets, Telegram sessions, SSH/cloud credentials and other sensitive information.</p><p>It was being distributed via ClickFix scams. Victims would visit a malicious website which would tell them they had a problem (an outdated browser or a “protected” document that can only be viewed after “verifying” identities), and which would immediately offer a solution. That solution is to bring up the Terminal and paste a command which, in reality, deployed the malware. </p><p>Initially, defenders would keep their Mac fleets safe by blocking the domains used to host the infrastructure - the websites, the malware executables, and the exfiltrated data. But they soon realized that a new domain would pop up as soon as the old one was blocked, and the malware would continue its operations unabated.</p><h2 id="behavioral-analysis">Behavioral analysis</h2><p>Now, in a new <a href="https://www.microsoft.com/en-us/security/blog/2026/08/18/hunting-macsync-stealer-infrastructure-through-behavioral-pivots/" target="_blank" rel="nofollow">report</a>, Microsoft said it successfully identified more than 30 domains by looking at behavioral patterns such as repeated execution, request characteristics, staging behavior, and upload methods.</p><p>“Microsoft Defender Experts expanded that view by correlating recurring endpoints and network behaviors across the activity. This behavior-led approach connected more than 30 domains and showed that the infrastructure supported more than C2 communication, extending into active collection, staging, and exfiltration,” Microsoft explained.</p><p>In other words, to defend against MacSync Stealer, don’t focus on blocking domains. Instead, pay attention to shell sessions spawning ‘curl’ with specific flag combinations, osascript quickly chaining into network activity, and archives appearing under /tmp/sync just before outbound PUT traffic begins.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Bluesky reveals recent outage was caused by major DDoS attack ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Bluesky confirms 24‑hour outage was caused by a DDoS attack on August 17 2026</strong></li><li><strong>Researchers linked it to Iraq‑313 Team, using DiamWall‑based DDoS‑for‑hire infrastructure</strong></li><li><strong>Company upgraded defenses; no details yet on attackers, traffic origin, or user impact</strong></li></ul><p>The recent outage on Bluesky was the result of a Distributed Denial of Service (DDoS) attack, the company has confirmed.</p><p>Bluesky is a decentralized social media platform which is rather similar to X, since it allows users to post short messages and multimedia. Its key difference is the Authenticated Transfer Protocol (AT Protocol) upon which it was built, and which allows users and developers more control compared to other social networks. </p><p>On Sunday, August 16 2026, users started reporting problems accessing Bluesky. On Reddit, users from the US, UK, France, and other countries, said they were having issues loading the Bluesky website and app, or accessing their feeds. A day later, on August 17, Bluesky said it suffered a <a href="https://www.techradar.com/news/best-ddos-protection" target="_blank">DDoS attack</a> that lasted roughly 24 hours. </p><h2 id="iranians-claim-the-attack">Iranians claim the attack</h2><p>The company did not say who the attackers were, where the malicious traffic originated from, or if any specific DDoS infrastructure was used in the attack. It also did not say how many people were affected, but stressed that it upgraded its defenses and was continuing to monitor the situation. </p><p>At the same time, security researchers took to the IFIN public forum to discuss the attacks, saying they saw The Islamic Cyber Resistance in Iraq-313 Team, an Iran-backed threat actor, take responsibility for the attack, as well as for a similar DDoS strike on GitHub. It sounds plausible, since we’ve seen the 313 Team use DDoS to target similar services in the past, including <a href="https://www.techradar.com/pro/security/pro-iran-hackers-claim-recent-spotify-outage-was-revenge-for-us-action-in-their-country" target="_blank">Spotify</a> and <a href="https://www.techradar.com/pro/security/some-ubuntu-services-are-still-down-following-outages-after-ddos-attack" target="_blank">Ubuntu</a>.</p><p>Their initial research suggests the crooks used DDoS-for-hire infrastructure that relies on DiamWall which, in turn, seems to be using IP addresses supplied by a China-based reseller. This does not mean the attack traffic came from China, or that Chinese entities were involved in the attack. </p><p><em>Via </em><a href="https://techcrunch.com/2026/08/18/bluesky-says-its-recent-outage-was-caused-by-another-ddos-attack/" target="_blank"><em>TechCrunch</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/bluesky-reveals-recent-outage-was-caused-by-major-ddos-attack</link>
                                                                            <description>
                            <![CDATA[ Iranian state-backed threat actors claim responsibility, but Bluesky did not confirm it. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XWRWqy2sSk4nuEfa3exsC8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/n2uEkSyW5LSHxg5dkMHRjE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Aug 2026 11:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/n2uEkSyW5LSHxg5dkMHRjE-1280-80.jpg">
                                                            <media:credit><![CDATA[Photo by Jaque Silva/NurPhoto via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Bluesky app logo appears on the screen of a smartphone lying on a laptop keyboard]]></media:description>                                                            <media:text><![CDATA[The Bluesky app logo appears on the screen of a smartphone lying on a laptop keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[The Bluesky app logo appears on the screen of a smartphone lying on a laptop keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/n2uEkSyW5LSHxg5dkMHRjE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Bluesky confirms 24‑hour outage was caused by a DDoS attack on August 17 2026</strong></li><li><strong>Researchers linked it to Iraq‑313 Team, using DiamWall‑based DDoS‑for‑hire infrastructure</strong></li><li><strong>Company upgraded defenses; no details yet on attackers, traffic origin, or user impact</strong></li></ul><p>The recent outage on Bluesky was the result of a Distributed Denial of Service (DDoS) attack, the company has confirmed.</p><p>Bluesky is a decentralized social media platform which is rather similar to X, since it allows users to post short messages and multimedia. Its key difference is the Authenticated Transfer Protocol (AT Protocol) upon which it was built, and which allows users and developers more control compared to other social networks. </p><p>On Sunday, August 16 2026, users started reporting problems accessing Bluesky. On Reddit, users from the US, UK, France, and other countries, said they were having issues loading the Bluesky website and app, or accessing their feeds. A day later, on August 17, Bluesky said it suffered a <a href="https://www.techradar.com/news/best-ddos-protection" target="_blank">DDoS attack</a> that lasted roughly 24 hours. </p><h2 id="iranians-claim-the-attack">Iranians claim the attack</h2><p>The company did not say who the attackers were, where the malicious traffic originated from, or if any specific DDoS infrastructure was used in the attack. It also did not say how many people were affected, but stressed that it upgraded its defenses and was continuing to monitor the situation. </p><p>At the same time, security researchers took to the IFIN public forum to discuss the attacks, saying they saw The Islamic Cyber Resistance in Iraq-313 Team, an Iran-backed threat actor, take responsibility for the attack, as well as for a similar DDoS strike on GitHub. It sounds plausible, since we’ve seen the 313 Team use DDoS to target similar services in the past, including <a href="https://www.techradar.com/pro/security/pro-iran-hackers-claim-recent-spotify-outage-was-revenge-for-us-action-in-their-country" target="_blank">Spotify</a> and <a href="https://www.techradar.com/pro/security/some-ubuntu-services-are-still-down-following-outages-after-ddos-attack" target="_blank">Ubuntu</a>.</p><p>Their initial research suggests the crooks used DDoS-for-hire infrastructure that relies on DiamWall which, in turn, seems to be using IP addresses supplied by a China-based reseller. This does not mean the attack traffic came from China, or that Chinese entities were involved in the attack. </p><p><em>Via </em><a href="https://techcrunch.com/2026/08/18/bluesky-says-its-recent-outage-was-caused-by-another-ddos-attack/" target="_blank"><em>TechCrunch</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Geekom reveals multiple mini-PCs may be infected with malware hidden in a network driver — but it's now down to you to fix your PC ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Geekom has admitted a software driver contained malware</strong></li><li><strong>A LAN driver on a legacy page was hosting the Asruex backdoor</strong></li><li><strong>The malware can track keystrokes, steal passwords, and intercept data</strong></li></ul><p>Hardware maker Geekom has admitted that a network driver for multiple mini PC variants hosted Asruex backdoor malware, potentially putting users at risk</p><p>The LAN driver for Geekom’s range of A7, A8, AE7, AE8, AX7 Pro and AX8 Pro mini-PCs hosted the malicious package with administrator-level permissions that allowed it to monitor everything you type, steal data, and even swipe passwords from your machine. The malicious software also connects to a command and control (C2) network to send and receive information from hackers.</p><p>Geekom has issued an apology and removed the software package in question, but if you have a Geekom mini PC from the aforementioned range and have installed the LAN driver, I’d definitely recommend doing a full system virus scan, with a wipe and reset just to be sure.</p><h2 id="geekom-ships-malware-riddled-lan-driver">Geekom ships malware-riddled LAN driver</h2><p><a href="https://videocardz.com/newz/geekom-mini-pc-driver-archive-contains-file-flagged-as-malware" target="_blank"><em>Videocardz</em></a> first broke the story after investigating claims from a Reddit user who reported finding a malicious executable file contained within the LAN driver.</p><p><em>Videocardz</em> then independently investigated the claim using FileScan.IO, MetaDefender VirusTotal, and YARAify. Each antivirus engine detected the executable as malicious.</p><p>In Geekom’s statement about the malicious file, the company said that the driver was hosted on a “legacy page [that] had already been replaced and was no longer accessible through the normal Support navigation, although it remained indexed by search engines.”</p><p>So when users searched for the LAN driver using Google, the result that came up was the malicious file. I always recommend users install drivers and other software from the official distributor rather than using Google listings as hackers can use tactics such as SEO poisoning or promoted pages to offer dodgy software. But in this case the legacy page was official.</p><p>Geekom has <a href="https://videocardz.com/newz/geekom-apologizes-for-hosting-malware-in-driver-package-for-its-mini-pcs" target="_blank" rel="nofollow">confirmed</a> that none of its mini PC range were shipped with the malicious driver preinstalled, so if you haven’t directly downloaded the malicious software from the legacy page, you should be okay. But consider running a Windows Defender scan to be sure.</p><p>In order to guarantee that your mini PC is free of the malicious driver, perform a complete wipe and reset of Windows, and install a new Windows image direct from Microsoft’s official page. Going forward, only install software and drivers from the official support pages of the manufacturer.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/geekom-reveals-multiple-mini-pcs-may-be-infected-with-malware-hidden-in-a-network-driver-but-its-now-down-to-you-to-fix-your-pc</link>
                                                                            <description>
                            <![CDATA[ A malicious executable hidden within a LAN driver can track keystrokes, intercept data, and swipe passwords from Geekom mini-PCs. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">AhLptuzu7RCo7xSnaxqfyg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WJok7QZ99U3Sz57DMBX87f-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Aug 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WJok7QZ99U3Sz57DMBX87f-1280-80.jpg">
                                                            <media:credit><![CDATA[Alastair Jennings]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Geekom Mini PC A7]]></media:description>                                                            <media:text><![CDATA[Geekom Mini PC A7]]></media:text>
                                <media:title type="plain"><![CDATA[Geekom Mini PC A7]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WJok7QZ99U3Sz57DMBX87f-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Geekom has admitted a software driver contained malware</strong></li><li><strong>A LAN driver on a legacy page was hosting the Asruex backdoor</strong></li><li><strong>The malware can track keystrokes, steal passwords, and intercept data</strong></li></ul><p>Hardware maker Geekom has admitted that a network driver for multiple mini PC variants hosted Asruex backdoor malware, potentially putting users at risk</p><p>The LAN driver for Geekom’s range of A7, A8, AE7, AE8, AX7 Pro and AX8 Pro mini-PCs hosted the malicious package with administrator-level permissions that allowed it to monitor everything you type, steal data, and even swipe passwords from your machine. The malicious software also connects to a command and control (C2) network to send and receive information from hackers.</p><p>Geekom has issued an apology and removed the software package in question, but if you have a Geekom mini PC from the aforementioned range and have installed the LAN driver, I’d definitely recommend doing a full system virus scan, with a wipe and reset just to be sure.</p><h2 id="geekom-ships-malware-riddled-lan-driver">Geekom ships malware-riddled LAN driver</h2><p><a href="https://videocardz.com/newz/geekom-mini-pc-driver-archive-contains-file-flagged-as-malware" target="_blank"><em>Videocardz</em></a> first broke the story after investigating claims from a Reddit user who reported finding a malicious executable file contained within the LAN driver.</p><p><em>Videocardz</em> then independently investigated the claim using FileScan.IO, MetaDefender VirusTotal, and YARAify. Each antivirus engine detected the executable as malicious.</p><p>In Geekom’s statement about the malicious file, the company said that the driver was hosted on a “legacy page [that] had already been replaced and was no longer accessible through the normal Support navigation, although it remained indexed by search engines.”</p><p>So when users searched for the LAN driver using Google, the result that came up was the malicious file. I always recommend users install drivers and other software from the official distributor rather than using Google listings as hackers can use tactics such as SEO poisoning or promoted pages to offer dodgy software. But in this case the legacy page was official.</p><p>Geekom has <a href="https://videocardz.com/newz/geekom-apologizes-for-hosting-malware-in-driver-package-for-its-mini-pcs" target="_blank" rel="nofollow">confirmed</a> that none of its mini PC range were shipped with the malicious driver preinstalled, so if you haven’t directly downloaded the malicious software from the legacy page, you should be okay. But consider running a Windows Defender scan to be sure.</p><p>In order to guarantee that your mini PC is free of the malicious driver, perform a complete wipe and reset of Windows, and install a new Windows image direct from Microsoft’s official page. Going forward, only install software and drivers from the official support pages of the manufacturer.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Loan company breach sees nearly 750,000 users have financial info, SSNs leaked ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Heights Finance breach exposed sensitive customer data via a compromised third‑party cloud platform</strong></li><li><strong>Stolen records included contact details, financial info, and government identifiers</strong></li><li><strong>Over 700,000 Texans affected; company offers credit monitoring and identity protection</strong></li></ul><p>US loan company Heights Finance has revealed it suffered a cyberattack earlier in 2026 in which it lost sensitive data on hundreds of thousands of its customers.</p><p>The company published a data breach notification on its website, disclosing that on May 7 2026, it saw an “unauthorized actor” gaining access to a cloud-based platform, hosted by a third party, which the company uses to store certain customer data. </p><p>The breach was limited to that cloud platform only and did not affect its loan management system, or other systems and networks.</p><h2 id="at-least-700-000-victims">At least 700,000 victims</h2><p>As is standard practice in these incidents, Heights Finance notified the relevant authorities and brought in outside cybersecurity help.</p><p>The subsequent investigation determined that the attackers - which were not named - stole contact details (names, postal addresses, phone numbers, email addresses), financial information (account details, bank account information such as bank name, account number, routing number), government identifiers (Social Security numbers, tax IDs, driver’s license numbers), and other miscellaneous data.</p><p>“Your information may be involved if you received a loan through Heights, or if you inquired about or applied for a loan product (including through a third party),” the company said. “Your information may also be involved if you were a former borrower of Curo Management or any of its former or current related brands.”</p><p>The exact number of affected individuals is not known at this time. Heights Finance told regulators in Texas that the breach affected more than 730,000 of its residents, and added that it affected those living in Alabama, Tennessee, Georgia, Texas and South Carolina.</p><p>We don’t know which <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">cloud-based platform</a> Heights Finance is using, and the threat actors are yet to claim responsibility for the attack. In the meantime, the company is offering affected customers credit monitoring and identity protection services through Epiq.</p><p><em>Via </em><a href="https://therecord.media/financial-info-leak-debt-consolidator" target="_blank"><em>The Record</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/loan-company-breach-sees-nearly-750-000-users-have-financial-info-ssns-leaked</link>
                                                                            <description>
                            <![CDATA[ Heights Finance said its cloud account was compromised, and information such as bank accounts and SSNs, stolen. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sVNrSWMVEPvYz8KDTwayqF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zTH6vPrB4yxX7dzdy29Xga-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Aug 2026 14:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zTH6vPrB4yxX7dzdy29Xga-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An image of a digitized skull and crossbones symbolizing hacking and cyberattacks overlayed on a background of digital glitches and noise.]]></media:description>                                                            <media:text><![CDATA[An image of a digitized skull and crossbones symbolizing hacking and cyberattacks overlayed on a background of digital glitches and noise.]]></media:text>
                                <media:title type="plain"><![CDATA[An image of a digitized skull and crossbones symbolizing hacking and cyberattacks overlayed on a background of digital glitches and noise.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zTH6vPrB4yxX7dzdy29Xga-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Heights Finance breach exposed sensitive customer data via a compromised third‑party cloud platform</strong></li><li><strong>Stolen records included contact details, financial info, and government identifiers</strong></li><li><strong>Over 700,000 Texans affected; company offers credit monitoring and identity protection</strong></li></ul><p>US loan company Heights Finance has revealed it suffered a cyberattack earlier in 2026 in which it lost sensitive data on hundreds of thousands of its customers.</p><p>The company published a data breach notification on its website, disclosing that on May 7 2026, it saw an “unauthorized actor” gaining access to a cloud-based platform, hosted by a third party, which the company uses to store certain customer data. </p><p>The breach was limited to that cloud platform only and did not affect its loan management system, or other systems and networks.</p><h2 id="at-least-700-000-victims">At least 700,000 victims</h2><p>As is standard practice in these incidents, Heights Finance notified the relevant authorities and brought in outside cybersecurity help.</p><p>The subsequent investigation determined that the attackers - which were not named - stole contact details (names, postal addresses, phone numbers, email addresses), financial information (account details, bank account information such as bank name, account number, routing number), government identifiers (Social Security numbers, tax IDs, driver’s license numbers), and other miscellaneous data.</p><p>“Your information may be involved if you received a loan through Heights, or if you inquired about or applied for a loan product (including through a third party),” the company said. “Your information may also be involved if you were a former borrower of Curo Management or any of its former or current related brands.”</p><p>The exact number of affected individuals is not known at this time. Heights Finance told regulators in Texas that the breach affected more than 730,000 of its residents, and added that it affected those living in Alabama, Tennessee, Georgia, Texas and South Carolina.</p><p>We don’t know which <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">cloud-based platform</a> Heights Finance is using, and the threat actors are yet to claim responsibility for the attack. In the meantime, the company is offering affected customers credit monitoring and identity protection services through Epiq.</p><p><em>Via </em><a href="https://therecord.media/financial-info-leak-debt-consolidator" target="_blank"><em>The Record</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Millions of stolen records allegedly dumped online by mystery "Hatman" hacker — McDonalds, Vodafone and more see Microsoft Azure records stolen ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Hacker “TheHatman” claims to have stolen millions of Azure/Entra employee records from major firms</strong></li><li><strong>Data includes names, emails, job titles, privileged accounts; risks include impersonation and fraud</strong></li><li><strong>Victims dispute scope, but researchers say infostealer‑based theft makes the leaks likely authentic</strong></li></ul><p>A cybercriminal is selling millions of user records on the dark web, which they claim to have stolen from large organizations such as McDonalds, Tata Consultancy Services, and Wyndham Hotels.</p><p>A hacker going by the alias “TheHatman” posted multiple threads on dark web forums, claiming to have stolen information from Azure and Entra environments. </p><p>TheHatman said they broke in using compromised login credentials, targeting almost a dozen organizations.</p><h2 id="what-was-stolen-and-from-whom">What was stolen and from whom?</h2><p>Among the victims and the number of records exposed, are:</p><p>McDonald’s Corporation: 1,700,000 records<br>TCS (Tata Consultancy Services): 800,000 records<br>Vodafone: 425,000 records<br>HCL Technologies: 250,000 records<br>InterContinental Hotels Group (IHG): 185,000 records<br>Kyndryl: 170,000 records<br>Gap Inc.: 80,000 records<br>Hexaware Technologies: 20,000 records<br>Wyndham Hotels: 9,000 records</p><p>They are now looking for a buyer: “I’m selling McDonald’s Corporation internal employee dump downloaded directly from Azure Tenant using compromised credentials,” TheHatman said in one of the posts.</p><p>In their writeup, security researchers from <a href="https://cybernews.com/security/mcdonalds-vodafone-azure-microdoft-credential-theft/" target="_blank"><em>Cybernews</em></a> said they analyzed one of the samples posted on the dark web and said the entries were “consistent with Azure directory exports”.</p><p>They contained employee names, emails, phone numbers, job titles, workplace addresses, IDs, the departments they work in, user group memberships, service accounts, and highly privileged account records. </p><h2 id="what-are-the-risks">What are the risks?</h2><p>Stealing information such as names, email addresses, and workplace details might not sound like a worrisome breach of privacy, but the implications are rather big. Cybercriminals can use it to impersonate a business partner or a major client, and try to trick their employees into installing <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a>, or making a fraudulent wire transaction. That way, they can escalate what seems like a relatively benign breach, into a full-blown cyberattack with material and legal consequences.</p><p>For example, a criminal might discover a Vodafone employee that regularly handles payments to a particular supplier. They might impersonate that supplier’s finance director, engage in conversation and, while requesting a new payment, warn that the company changed their bank account. This is not a purely theoretical scenario - it’s been documented time and time again. </p><h2 id="what-did-the-victims-say">What did the victims say?</h2><p>Most organizations are yet to give an official statement about these claims. Gap told <a href="https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/" target="_blank"><em>BleepingComputer</em></a> that it found no evidence of the breach and suggested that the attackers merely repackaged data from an older incident. </p><p>“Our preliminary investigation indicates that the data in question is limited in scope, non-sensitive and dated back to several years ago. Notably, there is no evidence to suggest that our corporate systems have been compromised,” Gap told the publication.</p><p>Tata Consultancy Services notified the Indian National Stock Exchange about the breach last week, also suggesting that this was a resurfacing of an older incident. </p><p>“The Company has investigated the matter and has not found any credible evidence of a breach of TCS systems or customer environments,” TCS said in the filing. “The information referenced appears to be more than four years old and limited to basic employee information. There is no indication that customer data, customer systems, or TCS operational systems have been impacted.”</p><p>TCS said the attackers broke in using credential stuffing, something that could have only been done years ago: “The attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue as the attack vector. The Company has had strong safeguards in place against such techniques for more than two years.” </p><p>Not everyone agrees with that assessment, though. Security researchers Hudson Rock believe the attackers stole login credentials with an <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">infostealer</a>, rather than through password spraying. </p><p>“Judging by the massive size of the organizations impacted, it appears highly likely that this campaign originates from targeted exploitation of Infostealer infections rather than a systemic zero-day vulnerability in Azure,” the researchers said in their report. “If this were a widespread vulnerability, we would likely see a much broader spectrum of organizations impacted, including smaller businesses, rather than just these massive Fortune 500-level enterprises.”</p><p>Hudson Rock also described the stolen data as “likely highly authentic”, hinting that just because it’s older, it doesn’t mean it’s not useful.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/millions-of-stolen-records-allegedly-dumped-online-by-mystery-hatman-hacker-mcdonalds-vodafone-and-more-see-microsoft-azure-records-stolen</link>
                                                                            <description>
                            <![CDATA[ Some affected companies argue the data is years old and claim no breach in their systems. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">g2uaoVUQzwLLWJpVyugm5B</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Aug 2026 13:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg">
                                                            <media:credit><![CDATA[Thapana Onphalai via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:description>                                                            <media:text><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:text>
                                <media:title type="plain"><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Hacker “TheHatman” claims to have stolen millions of Azure/Entra employee records from major firms</strong></li><li><strong>Data includes names, emails, job titles, privileged accounts; risks include impersonation and fraud</strong></li><li><strong>Victims dispute scope, but researchers say infostealer‑based theft makes the leaks likely authentic</strong></li></ul><p>A cybercriminal is selling millions of user records on the dark web, which they claim to have stolen from large organizations such as McDonalds, Tata Consultancy Services, and Wyndham Hotels.</p><p>A hacker going by the alias “TheHatman” posted multiple threads on dark web forums, claiming to have stolen information from Azure and Entra environments. </p><p>TheHatman said they broke in using compromised login credentials, targeting almost a dozen organizations.</p><h2 id="what-was-stolen-and-from-whom">What was stolen and from whom?</h2><p>Among the victims and the number of records exposed, are:</p><p>McDonald’s Corporation: 1,700,000 records<br>TCS (Tata Consultancy Services): 800,000 records<br>Vodafone: 425,000 records<br>HCL Technologies: 250,000 records<br>InterContinental Hotels Group (IHG): 185,000 records<br>Kyndryl: 170,000 records<br>Gap Inc.: 80,000 records<br>Hexaware Technologies: 20,000 records<br>Wyndham Hotels: 9,000 records</p><p>They are now looking for a buyer: “I’m selling McDonald’s Corporation internal employee dump downloaded directly from Azure Tenant using compromised credentials,” TheHatman said in one of the posts.</p><p>In their writeup, security researchers from <a href="https://cybernews.com/security/mcdonalds-vodafone-azure-microdoft-credential-theft/" target="_blank"><em>Cybernews</em></a> said they analyzed one of the samples posted on the dark web and said the entries were “consistent with Azure directory exports”.</p><p>They contained employee names, emails, phone numbers, job titles, workplace addresses, IDs, the departments they work in, user group memberships, service accounts, and highly privileged account records. </p><h2 id="what-are-the-risks">What are the risks?</h2><p>Stealing information such as names, email addresses, and workplace details might not sound like a worrisome breach of privacy, but the implications are rather big. Cybercriminals can use it to impersonate a business partner or a major client, and try to trick their employees into installing <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a>, or making a fraudulent wire transaction. That way, they can escalate what seems like a relatively benign breach, into a full-blown cyberattack with material and legal consequences.</p><p>For example, a criminal might discover a Vodafone employee that regularly handles payments to a particular supplier. They might impersonate that supplier’s finance director, engage in conversation and, while requesting a new payment, warn that the company changed their bank account. This is not a purely theoretical scenario - it’s been documented time and time again. </p><h2 id="what-did-the-victims-say">What did the victims say?</h2><p>Most organizations are yet to give an official statement about these claims. Gap told <a href="https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/" target="_blank"><em>BleepingComputer</em></a> that it found no evidence of the breach and suggested that the attackers merely repackaged data from an older incident. </p><p>“Our preliminary investigation indicates that the data in question is limited in scope, non-sensitive and dated back to several years ago. Notably, there is no evidence to suggest that our corporate systems have been compromised,” Gap told the publication.</p><p>Tata Consultancy Services notified the Indian National Stock Exchange about the breach last week, also suggesting that this was a resurfacing of an older incident. </p><p>“The Company has investigated the matter and has not found any credible evidence of a breach of TCS systems or customer environments,” TCS said in the filing. “The information referenced appears to be more than four years old and limited to basic employee information. There is no indication that customer data, customer systems, or TCS operational systems have been impacted.”</p><p>TCS said the attackers broke in using credential stuffing, something that could have only been done years ago: “The attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue as the attack vector. The Company has had strong safeguards in place against such techniques for more than two years.” </p><p>Not everyone agrees with that assessment, though. Security researchers Hudson Rock believe the attackers stole login credentials with an <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">infostealer</a>, rather than through password spraying. </p><p>“Judging by the massive size of the organizations impacted, it appears highly likely that this campaign originates from targeted exploitation of Infostealer infections rather than a systemic zero-day vulnerability in Azure,” the researchers said in their report. “If this were a widespread vulnerability, we would likely see a much broader spectrum of organizations impacted, including smaller businesses, rather than just these massive Fortune 500-level enterprises.”</p><p>Hudson Rock also described the stolen data as “likely highly authentic”, hinting that just because it’s older, it doesn’t mean it’s not useful.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Pokémon Center data breach exposes customer info, cancels some orders ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Pokémon Center UK orders disrupted after CEVA Logistics cyberattack on July 30 2026</strong></li><li><strong>Customer names, addresses, emails, and order details likely exposed, but accounts and payments safe</strong></li><li><strong>Around a dozen organizations confirmed affected; no group has claimed responsibility yet</strong></li></ul><p>Customers who recently ordered their favorite Pikachu toy from Pokémon Center might have to do it all over again, since the company suffered a third-party cyberattack which disrupted its operations.</p><p>The official store for Pokémon merchandise in the UK has reached out to its customers via email to warn them about a recent cyberattack and its consequences. </p><p>According to<em> </em><a href="https://www.bleepingcomputer.com/news/security/pokemon-center-data-breach-exposes-customer-info-cancels-some-orders/" target="_blank"><em>BleepingComputer</em></a>, which has seen a copy of the email, the company told its customers they had to “cancel your recent order due to an unforeseen fulfilment issue”. </p><div class="product"><a data-dimension112="e6350dae-9b08-11f1-b70e-1d3b7178f10e" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="e6350dae-9b08-11f1-b70e-1d3b7178f10e" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="e6350dae-9b08-11f1-b70e-1d3b7178f10e" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="ceva-logistics">CEVA Logistics</h2><p>The company’s website is also showing a notification saying the company is “currently experiencing delays affecting some orders for our UK customers.” </p><p>“These orders may take longer than usual to process, dispatch, and deliver. We apologize for the inconvenience and appreciate your patience.”</p><p>The company said the attack struck its logistics provider, CEVA Logistics. </p><p>"CEVA Logistics, the vendor Pokémon Center utilizes to ship products from PokemonCenter.com for customers in the United Kingdom and Germany, has informed us that unfortunately they were a victim of a cyber attack commencing on 30 July, 2026."</p><p>Last week, one of the biggest shipping and logistics companies in the world <a href="https://www.techradar.com/pro/security/the-ceva-logistics-data-breach-is-having-major-knock-on-effects-across-europe-heres-what-we-know" target="_blank">disclosed an incident</a> that forced it to shut down parts of its IT infrastructure and affected eight warehouses. At the time, a handful of its customers reported being affected by the breach, including Dutch retailers Bol and De Bijenkorf, and PC gaming powerhouse Valve. </p><p>Pokémon Center said the data most likely exposed in this incident includes people’s full names, mailing addresses, phone numbers, <a href="https://www.techradar.com/news/best-email-provider" target="_blank">email addresses</a>, and details about what they previously ordered on the site. User accounts are apparently safe, and so are payment details. </p><p>So far, around a dozen organizations are confirmed as having been affected. No threat actors have claimed responsibility yet. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/pokemon-center-data-breach-exposes-customer-info-cancels-some-orders</link>
                                                                            <description>
                            <![CDATA[ Another victim of the CEVA Logistics supply chain attack steps forward as orders get halted and postponed. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gmsChWHs9LaKRXbkHCNR48</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uhBYCXndSH8w5FSohcafnX-1280-80.jpeg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Aug 2026 10:23:42 +0000</pubDate>                                                                                                                                <updated>Tue, 18 Aug 2026 13:29:55 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uhBYCXndSH8w5FSohcafnX-1280-80.jpeg">
                                                            <media:credit><![CDATA[Pokemon Company]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Jiggly puff Angry]]></media:description>                                                            <media:text><![CDATA[Jiggly puff Angry]]></media:text>
                                <media:title type="plain"><![CDATA[Jiggly puff Angry]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uhBYCXndSH8w5FSohcafnX-1280-80.jpeg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Pokémon Center UK orders disrupted after CEVA Logistics cyberattack on July 30 2026</strong></li><li><strong>Customer names, addresses, emails, and order details likely exposed, but accounts and payments safe</strong></li><li><strong>Around a dozen organizations confirmed affected; no group has claimed responsibility yet</strong></li></ul><p>Customers who recently ordered their favorite Pikachu toy from Pokémon Center might have to do it all over again, since the company suffered a third-party cyberattack which disrupted its operations.</p><p>The official store for Pokémon merchandise in the UK has reached out to its customers via email to warn them about a recent cyberattack and its consequences. </p><p>According to<em> </em><a href="https://www.bleepingcomputer.com/news/security/pokemon-center-data-breach-exposes-customer-info-cancels-some-orders/" target="_blank"><em>BleepingComputer</em></a>, which has seen a copy of the email, the company told its customers they had to “cancel your recent order due to an unforeseen fulfilment issue”. </p><div class="product"><a data-dimension112="e6350dae-9b08-11f1-b70e-1d3b7178f10e" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="e6350dae-9b08-11f1-b70e-1d3b7178f10e" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="e6350dae-9b08-11f1-b70e-1d3b7178f10e" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="ceva-logistics">CEVA Logistics</h2><p>The company’s website is also showing a notification saying the company is “currently experiencing delays affecting some orders for our UK customers.” </p><p>“These orders may take longer than usual to process, dispatch, and deliver. We apologize for the inconvenience and appreciate your patience.”</p><p>The company said the attack struck its logistics provider, CEVA Logistics. </p><p>"CEVA Logistics, the vendor Pokémon Center utilizes to ship products from PokemonCenter.com for customers in the United Kingdom and Germany, has informed us that unfortunately they were a victim of a cyber attack commencing on 30 July, 2026."</p><p>Last week, one of the biggest shipping and logistics companies in the world <a href="https://www.techradar.com/pro/security/the-ceva-logistics-data-breach-is-having-major-knock-on-effects-across-europe-heres-what-we-know" target="_blank">disclosed an incident</a> that forced it to shut down parts of its IT infrastructure and affected eight warehouses. At the time, a handful of its customers reported being affected by the breach, including Dutch retailers Bol and De Bijenkorf, and PC gaming powerhouse Valve. </p><p>Pokémon Center said the data most likely exposed in this incident includes people’s full names, mailing addresses, phone numbers, <a href="https://www.techradar.com/news/best-email-provider" target="_blank">email addresses</a>, and details about what they previously ordered on the site. User accounts are apparently safe, and so are payment details. </p><p>So far, around a dozen organizations are confirmed as having been affected. No threat actors have claimed responsibility yet. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ransomware gang crashes own attack — with no-one to blame but themselves ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Akira ransomware tried Safe Mode boot to disable defenses but broke its own encryptor</strong></li><li><strong>Defender later flagged and quarantined payload, leaving attackers with only stolen data</strong></li><li><strong>Huntress advises VPN brute‑force alerts, MFA, SIEM logging, and Safe Mode monitoring</strong></li></ul><p>A recent ransomware attack saw the operators Akira (figuratively) shoot themselves in the foot - and they still walked away with sensitive data, albeit limping.</p><p>Akira is a well-known <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> group, considered one of the most active cybercriminal organizations on the internet. Its modus operandi is simple in theory: they look for an exposed VPN instance (for example, one with a default or weak password), access the domain controller, enumerate Active Directory, steal sensitive data, and deploy an encryptor.</p><p>With the encryptor they leave a ransom note, instructing the victim to reach out and negotiate a payment in exchange for the decryption key and for deleting the stolen documents and information.</p><p>However, in a recent attack, they tried to first disable the device’s antivirus and endpoint detection and response (EDR) solutions. The process backfired, resulting in the security solutions successfully spotting and quarantining the encryptor. </p><div class="product"><a data-dimension112="0693e444-9b09-11f1-a97e-b36957f61fe6" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="0693e444-9b09-11f1-a97e-b36957f61fe6" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="0693e444-9b09-11f1-a97e-b36957f61fe6" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="the-good-and-the-bad-of-safe-mode-with-networking">The good and the bad of Safe Mode with Networking</h2><p>A new report published by security researchers <a href="https://www.huntress.com/blog/akira-hits-safe-mode-ransomware-rebooting-around-edr" target="_blank">Huntress</a> said that after establishing persistence on a device, Akira rebooted it into Safe Mode with Networking. This Windows startup mode boots the OS with only the essential drivers and services, excluding important components such as antivirus programs or EDR agents. At the same time, it grants internet access which, for Akira, is the perfect combination.</p><p>“This means Defender real-time protection was down too,” Akira explained. “For the entire Safe Mode window, the host had no working EDR, and AV was blinded. This is MITRE ATT&CK T1688: Impair Defenses: Safe Mode Boot, a technique that ransomware families like Snatch and AvosLocker have used for years. However, this is the first time we have seen Akira use it.”</p><p>What Akira didn’t bank on was Safe Mode with Networking also preventing its encryptor from running. “Safe Mode boots with a stripped-down environment and constrained virtual memory, and the Akira process tree appears to have starved it, getting the "Out of Virtual Memory" pop-up and the cascade of PowerShell hard errors line up exactly with the moment the payload tried to kick things off.”</p><p>The operators had no other choice but to boot the device back up normally, at which point a scheduled Defender scan detected the encryptor, flagged it, and ultimately quarantined it. </p><p>“The takeaway is a little uncomfortable. While Safe Mode blinded our controls, it may also have prevented the encryption it was meant to enable. That's a lucky side effect of the attacker's own mistake in these circumstances, not a defense you can plan around,” Huntress warned, stressing that not every victim might get such a lucky break.</p><p>“Ultimately, this could be a case of winning the battle, but not the war. It's possible that a host with more physical memory or a larger page file might give akira.exe enough virtual memory to encrypt the endpoint in Safe Mode. Akira's developers or affiliates could retool the encryptor to reduce its memory demands or make its Safe Mode launch sequence more reliable, meaning that the same failure may not occur in a future intrusion.”</p><h2 id="how-to-defend-against-akira-ransomware">How to defend against Akira ransomware</h2><p>To defend against Akira, Huntress recommends users set up alerts on bursts of failed VPN logins against multiple usernames from one source. It works well because Akira starts its breach with a brute-force attack against the VPN. It also says users should correlate those failures with a successful login from the same IP or ASN within a short window.</p><p>The second step is to turn on multi-factor authentication (<a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">MFA</a>) on every VPN account. Users should also disable or IP-allowlist the SSL VPN during active attacks and, if compromised, rotate all AD and VPN credentials. “Treat everything in that Get-ADUser dump as exposed,” the researchers warn.</p><p>EDR should be deployed to every host, as well as SIEM and ingest VPN + Windows Event Logs. “The first VPN logons were visible hours before any detonation—this time advantage is only possible if the logs are on SIEM.”</p><p>Finally, users can set up alerts on boot-configuration changes and Safe Mode boots, to catch Akira red handed. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/ransomware-gang-crashes-own-attack-with-no-one-to-blame-but-themselves</link>
                                                                            <description>
                            <![CDATA[ In a new attack, Akira disables EDR tools, but kills the encryptor, as well, as researchers still warn of a worrying practice. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">S9XN4Dopx2hurqZaBZ8g2k</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Aug 2026 16:15:00 +0000</pubDate>                                                                                                                                <updated>Tue, 18 Aug 2026 13:30:49 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:description>                                                            <media:text><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:text>
                                <media:title type="plain"><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Akira ransomware tried Safe Mode boot to disable defenses but broke its own encryptor</strong></li><li><strong>Defender later flagged and quarantined payload, leaving attackers with only stolen data</strong></li><li><strong>Huntress advises VPN brute‑force alerts, MFA, SIEM logging, and Safe Mode monitoring</strong></li></ul><p>A recent ransomware attack saw the operators Akira (figuratively) shoot themselves in the foot - and they still walked away with sensitive data, albeit limping.</p><p>Akira is a well-known <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> group, considered one of the most active cybercriminal organizations on the internet. Its modus operandi is simple in theory: they look for an exposed VPN instance (for example, one with a default or weak password), access the domain controller, enumerate Active Directory, steal sensitive data, and deploy an encryptor.</p><p>With the encryptor they leave a ransom note, instructing the victim to reach out and negotiate a payment in exchange for the decryption key and for deleting the stolen documents and information.</p><p>However, in a recent attack, they tried to first disable the device’s antivirus and endpoint detection and response (EDR) solutions. The process backfired, resulting in the security solutions successfully spotting and quarantining the encryptor. </p><div class="product"><a data-dimension112="0693e444-9b09-11f1-a97e-b36957f61fe6" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="0693e444-9b09-11f1-a97e-b36957f61fe6" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="0693e444-9b09-11f1-a97e-b36957f61fe6" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="the-good-and-the-bad-of-safe-mode-with-networking">The good and the bad of Safe Mode with Networking</h2><p>A new report published by security researchers <a href="https://www.huntress.com/blog/akira-hits-safe-mode-ransomware-rebooting-around-edr" target="_blank">Huntress</a> said that after establishing persistence on a device, Akira rebooted it into Safe Mode with Networking. This Windows startup mode boots the OS with only the essential drivers and services, excluding important components such as antivirus programs or EDR agents. At the same time, it grants internet access which, for Akira, is the perfect combination.</p><p>“This means Defender real-time protection was down too,” Akira explained. “For the entire Safe Mode window, the host had no working EDR, and AV was blinded. This is MITRE ATT&CK T1688: Impair Defenses: Safe Mode Boot, a technique that ransomware families like Snatch and AvosLocker have used for years. However, this is the first time we have seen Akira use it.”</p><p>What Akira didn’t bank on was Safe Mode with Networking also preventing its encryptor from running. “Safe Mode boots with a stripped-down environment and constrained virtual memory, and the Akira process tree appears to have starved it, getting the "Out of Virtual Memory" pop-up and the cascade of PowerShell hard errors line up exactly with the moment the payload tried to kick things off.”</p><p>The operators had no other choice but to boot the device back up normally, at which point a scheduled Defender scan detected the encryptor, flagged it, and ultimately quarantined it. </p><p>“The takeaway is a little uncomfortable. While Safe Mode blinded our controls, it may also have prevented the encryption it was meant to enable. That's a lucky side effect of the attacker's own mistake in these circumstances, not a defense you can plan around,” Huntress warned, stressing that not every victim might get such a lucky break.</p><p>“Ultimately, this could be a case of winning the battle, but not the war. It's possible that a host with more physical memory or a larger page file might give akira.exe enough virtual memory to encrypt the endpoint in Safe Mode. Akira's developers or affiliates could retool the encryptor to reduce its memory demands or make its Safe Mode launch sequence more reliable, meaning that the same failure may not occur in a future intrusion.”</p><h2 id="how-to-defend-against-akira-ransomware">How to defend against Akira ransomware</h2><p>To defend against Akira, Huntress recommends users set up alerts on bursts of failed VPN logins against multiple usernames from one source. It works well because Akira starts its breach with a brute-force attack against the VPN. It also says users should correlate those failures with a successful login from the same IP or ASN within a short window.</p><p>The second step is to turn on multi-factor authentication (<a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">MFA</a>) on every VPN account. Users should also disable or IP-allowlist the SSL VPN during active attacks and, if compromised, rotate all AD and VPN credentials. “Treat everything in that Get-ADUser dump as exposed,” the researchers warn.</p><p>EDR should be deployed to every host, as well as SIEM and ingest VPN + Windows Event Logs. “The first VPN logons were visible hours before any detonation—this time advantage is only possible if the logs are on SIEM.”</p><p>Finally, users can set up alerts on boot-configuration changes and Safe Mode boots, to catch Akira red handed. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ MacOS users warned to beware screen-sharing bug which can turn Macs into cryptomining slaves ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>CVE‑2026‑65400 macOS Screen Sharing flaw exploited for cryptojacking within days of disclosure</strong></li><li><strong>Attackers gained root via exposed port 5900 and deployed Monero miners using XMRig</strong></li><li><strong>Apple patched in Sequoia 15.7.9, Sonoma 14.8.9, Tahoe 26.6.1; users urged to update immediately</strong></li></ul><p>Less than a week after being publicly disclosed, a macOS vulnerability plaguing Screen Sharing was observed as being used in cryptojacking attacks.</p><p>Alfredo Pesoli, a security researcher from Bynario, discovered an authentication issue in macOS Screen Sharing and reported it to Apple. Screen Sharing is a built-in macOS tool that allows users to remotely connect, and use, another Mac device. It is similar to third-party tools such as AnyDesk or TeamViewer and comes in rather handy for IT teams accessing Macs stored in closets or used by remote and home-working employees.</p><p>The bug allows a remote attacker to bypass authentication and gain access to a vulnerable Mac device without valid credentials. It apparently stems from a logic issue in the Screen Sharing server’s authentication process, affecting systems where the service is exposed to the internet.</p><h2 id="the-netherlands-issue-a-warning">The Netherlands issue a warning</h2><p>Soon after disclosure, Apple released an out-of-bound fix, signaling that this is, indeed, a dangerous vulnerability. “Apple does not ship an update out of band unless something is critical,” security researchers Calif said in their <a href="https://blog.calif.io/p/no-country-for-old-passwords" target="_blank" rel="nofollow">technical writeup</a>. The National Vulnerability Database (NVD) assigned it an identifier - CVE-2026-65400 - and gave it a severity rating of 9.6/10 (critical). </p><p>Approximately at the same time the patch was released, the flaw was also showcased at the 2026 Black Hat conference, with a video demonstration was made public a few days later.</p><p>Apple said it fixed it with improved state management, addressing the bug in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1.</p><p>Now, less than a week after the disclosure, researchers are saying the bug is being leveraged in actual cyberattacks, with Dutch security officials being first to react</p><p>“The NCSC has received a report showing that active abuse of this vulnerability has been observed on several systems on which port 5900 was accessible from the internet,” the Netherlands National Cyber Security Centrum (NCSC) said in a machine-translated report. “In all these cases, root access was gained on the affected system and a Monero crypto miner was placed.”</p><h2 id="why-monero">Why Monero?</h2><p>Monero is considered an “altcoin” - a cryptocurrency built as an alternative to Bitcoin. It is one of the oldest active altcoins out there, having been launched more than 12 years ago. Most cryptocurrencies rarely live through a single four-year bitcoin cycle but Monero, just like Ethereum, Litecoin, Solana, and a handful of others, endures.</p><p>It is similar to Bitcoin because it, too, can be “mined” (unlike Ethereum, for example). It differs on the privacy front. Unlike Bitcoin, whose transactions are recorded on a public ledger and can often be traced, Monero is designed to obscure the sender, recipient, and the amount of transactions. This privacy feature has, unfortunately, also attracted criminals.</p><p>Another key feature that made crooks choose Monero for their <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">cryptojackers</a> is the fact that the altcoin uses a proof-of-work (mining) algorithm optimized for general-purpose CPUs, making mining relatively profitable on ordinary servers, desktops, and cloud machines. </p><p>Although it was not specifically stated, it is safe to assume that in this incident, the attackers were deploying XMRig. It is, by far, the most popular cryptojacker and one that mines primarily Monero (its ticker is XMR).</p><h2 id="how-to-stay-safe">How to stay safe</h2><p>The best way to go about it is to install the patch Apple just released. This effectively plugs the hole and makes the device secure. Those who are unable to deploy the patch immediately should block Screen Sharing and enable it only when it is actually needed and used. To do that, users can go to System Settings > General > Sharing and toggle the Screen Sharing switch off. </p><p>Finally, it is worth mentioning that the NCSC stressed the crooks could only exploit the flaw when the target device’s port 5900 is exposed to the internet. Therefore, setting routers and firewalls to block the port can also work, although we’d only recommend it as a last resort. Installing the patch is still the best way to go. </p><p>Right now, no groups claimed responsibility for this attack, and there is no evidence it is being used for anything else. In theory, though, it can also be used for data exfiltration, malware deployment, and possibly even ransomware attacks. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/macos-users-warned-to-beware-screen-sharing-bug-which-can-turn-macs-into-cryptomining-slaves</link>
                                                                            <description>
                            <![CDATA[ Apple patched a critical-severity flaw in Screen Sharing which allowed crooks unabated access to vulnerable devices. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GNymd9yeKgRVNJ8phk4pgn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5HfdStguEjjwWA3HyeKfCZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Aug 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5HfdStguEjjwWA3HyeKfCZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Far Chinberdiev / Unsplash]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Apple Mac Pro on a desk.]]></media:description>                                                            <media:text><![CDATA[The Apple Mac Pro on a desk.]]></media:text>
                                <media:title type="plain"><![CDATA[The Apple Mac Pro on a desk.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5HfdStguEjjwWA3HyeKfCZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>CVE‑2026‑65400 macOS Screen Sharing flaw exploited for cryptojacking within days of disclosure</strong></li><li><strong>Attackers gained root via exposed port 5900 and deployed Monero miners using XMRig</strong></li><li><strong>Apple patched in Sequoia 15.7.9, Sonoma 14.8.9, Tahoe 26.6.1; users urged to update immediately</strong></li></ul><p>Less than a week after being publicly disclosed, a macOS vulnerability plaguing Screen Sharing was observed as being used in cryptojacking attacks.</p><p>Alfredo Pesoli, a security researcher from Bynario, discovered an authentication issue in macOS Screen Sharing and reported it to Apple. Screen Sharing is a built-in macOS tool that allows users to remotely connect, and use, another Mac device. It is similar to third-party tools such as AnyDesk or TeamViewer and comes in rather handy for IT teams accessing Macs stored in closets or used by remote and home-working employees.</p><p>The bug allows a remote attacker to bypass authentication and gain access to a vulnerable Mac device without valid credentials. It apparently stems from a logic issue in the Screen Sharing server’s authentication process, affecting systems where the service is exposed to the internet.</p><h2 id="the-netherlands-issue-a-warning">The Netherlands issue a warning</h2><p>Soon after disclosure, Apple released an out-of-bound fix, signaling that this is, indeed, a dangerous vulnerability. “Apple does not ship an update out of band unless something is critical,” security researchers Calif said in their <a href="https://blog.calif.io/p/no-country-for-old-passwords" target="_blank" rel="nofollow">technical writeup</a>. The National Vulnerability Database (NVD) assigned it an identifier - CVE-2026-65400 - and gave it a severity rating of 9.6/10 (critical). </p><p>Approximately at the same time the patch was released, the flaw was also showcased at the 2026 Black Hat conference, with a video demonstration was made public a few days later.</p><p>Apple said it fixed it with improved state management, addressing the bug in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1.</p><p>Now, less than a week after the disclosure, researchers are saying the bug is being leveraged in actual cyberattacks, with Dutch security officials being first to react</p><p>“The NCSC has received a report showing that active abuse of this vulnerability has been observed on several systems on which port 5900 was accessible from the internet,” the Netherlands National Cyber Security Centrum (NCSC) said in a machine-translated report. “In all these cases, root access was gained on the affected system and a Monero crypto miner was placed.”</p><h2 id="why-monero">Why Monero?</h2><p>Monero is considered an “altcoin” - a cryptocurrency built as an alternative to Bitcoin. It is one of the oldest active altcoins out there, having been launched more than 12 years ago. Most cryptocurrencies rarely live through a single four-year bitcoin cycle but Monero, just like Ethereum, Litecoin, Solana, and a handful of others, endures.</p><p>It is similar to Bitcoin because it, too, can be “mined” (unlike Ethereum, for example). It differs on the privacy front. Unlike Bitcoin, whose transactions are recorded on a public ledger and can often be traced, Monero is designed to obscure the sender, recipient, and the amount of transactions. This privacy feature has, unfortunately, also attracted criminals.</p><p>Another key feature that made crooks choose Monero for their <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">cryptojackers</a> is the fact that the altcoin uses a proof-of-work (mining) algorithm optimized for general-purpose CPUs, making mining relatively profitable on ordinary servers, desktops, and cloud machines. </p><p>Although it was not specifically stated, it is safe to assume that in this incident, the attackers were deploying XMRig. It is, by far, the most popular cryptojacker and one that mines primarily Monero (its ticker is XMR).</p><h2 id="how-to-stay-safe">How to stay safe</h2><p>The best way to go about it is to install the patch Apple just released. This effectively plugs the hole and makes the device secure. Those who are unable to deploy the patch immediately should block Screen Sharing and enable it only when it is actually needed and used. To do that, users can go to System Settings > General > Sharing and toggle the Screen Sharing switch off. </p><p>Finally, it is worth mentioning that the NCSC stressed the crooks could only exploit the flaw when the target device’s port 5900 is exposed to the internet. Therefore, setting routers and firewalls to block the port can also work, although we’d only recommend it as a last resort. Installing the patch is still the best way to go. </p><p>Right now, no groups claimed responsibility for this attack, and there is no evidence it is being used for anything else. In theory, though, it can also be used for data exfiltration, malware deployment, and possibly even ransomware attacks. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Is the new Water Cyber Shield Act too little, too late, and can a cyber group do it better? The experts weigh in ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Two US senators have proposed a new <a href="https://www.schiff.senate.gov/wp-content/uploads/2026/08/Summary_Water-Cyber-Shield-Act.pdf" target="_blank" rel="nofollow">Water Cyber Shield Act</a> to provide the EPA with additional funding and tools to conduct cybersecurity assessments on critical water infrastructure.</p><p>The act would provide $300 million annually to allow for upgrades to water utility infrastructure. Numerous coordinated attacks have been launched against US water infrastructure in recent years across 12 states, with <a href="https://www.techradar.com/pro/security/hackers-are-going-after-our-water-now-over-30-minnesota-utilities-hit-in-coordinated-cyberattack-by-apparent-iranian-attackers">30 Minnesota utilities hit by Iran earlier this month</a>.</p><p>But a separate Water Watch Center group has been set up to monitor 91% of the roughly 50,000 community water systems nationwide following a two-year pilot. The group, set up by DEF CON Franklin and the National Rural Water Association, will offer managed detection and response services provided by five cybersecurity firms.</p><h2 id="why-are-water-utilities-being-attacked">Why are water utilities being attacked?</h2><p>The FBI, CISA, NSA, and many more <a href="https://www.techradar.com/pro/security/us-agencies-warn-iranian-hackers-are-targeting-american-critical-infrastructure-causing-disruptive-effects-within-the-united-states">agencies have issued warnings</a> about the increased threat to water utilities from Iran. </p><p>Water utilities are considered a low risk, high reward attack for state-sponsored hackers looking to cause as much damage as possible as many of the water control systems rely on  internet connected operational technology (OT) devices and logic controllers.</p><p>These devices are widely deployed across water infrastructure to control water treatment and are connected to computers at monitoring stations. Theoretically if a hacker gained control of these systems, they could turn off the treatment of water or open sewage gates to contaminate water supplies.</p><p>Many water treatment systems are designed to last decades, with these OT devices and logic controllers expected to last as long as possible. But as new tech and hardware is developed, these devices stop receiving software updates that can put them at a greater risk of being attacked.</p><p>For many in the cybersecurity industry though, the Water Cyber Shield Act is too little, too late.</p><h3 class="article-body__section" id="section-expert-perspectives-on-hardening-water-utilities"><span>Expert perspectives on hardening water utilities</span></h3><h2 id="will-the-water-cyber-shield-act-be-passed">Will the Water Cyber Shield Act be passed?</h2><p><strong>Dahvid Schloss, OSCP, Chief Operating Officer, Suzu Labs: </strong></p><p><em>While it's always exciting to see Congress attempt to get some good cybersecurity hygiene laws in place, it's likely a far reach from what will actually happen. The Water Cyber Shield Act feels a lot like a round two attempt from when this was attempted back in 2023 under the existing Safe Drinking Water Act authority as a rule, but that got shut down when water industry groups and a coalition of GOP states argued that it would increase costs on ratepayers, and then the EPA folded and pulled the rule. (More info can be found </em><a href="https://www.epa.gov/cyberwater/cybersecurity-sanitary-surveys" target="_blank" rel="nofollow"><em>here</em></a><em>)</em></p><div><blockquote><p>Hopefully, in light of recent attacks, this will push Senators and House Representatives to actually move the needle forward, but this isn't the first time we have had this situation happen before.  So, my fingers are crossed, but I'm not holding my breath.</p></blockquote></div><p><em>I hate to say it, but historically speaking, this is likely to fail before making it to a vote, just like all other bills that have been attempted to improve water cybersecurity in the past.  If we look at just the 118</em><sup><em>th</em></sup><em> and 119</em><sup><em>th</em></sup><em> Congress, we have had 9 bills introduced, as far as I'm aware, that pushed language that would have focused on either providing monetary assistance for, directly enforcing industry standards, and/or regulation around cybersecurity for water systems and CI, each varying in degree of what they would have provided and who they would have protected (rural vs non), but of those 9, all from within the 118th congress died within committees and without comments or markup, meaning no one even bothered to fight for them to get a vote across. Technically, the 4 from this congress (119) are still "pending' but considering no movement has occurred on them, they will likely reach the same fate.</em></p><p><em>Ultimately, Congress has been unreliable in pushing forward regulation and standards towards CI for quite some time, and the mantle thankfully has been picked up by private organizations and security practitioners who wish to have a safer and more secure water source. Even though it shouldn't be dependent on the goodwill of private citizens to protect public infrastructure.</em></p><p><em>Hopefully, in light of recent attacks, this will push Senators and House Representatives to actually move the needle forward, but this isn't the first time we have had this situation happen before.  So, my fingers are crossed, but I'm not holding my breath.</em></p><h2 id="too-little-too-late">Too little, too late?</h2><p><strong>John Strand, Owner, Black Hills Information Security, Inc.:</strong> </p><p><em>I think this type of legislation is important, but it’s also long overdue. People have known about the security weaknesses in critical infrastructure, especially within municipalities, for well over a decade.</em></p><div><blockquote><p>This is the kind of investment that should have been made more than a decade ago, not after the attacks have already demonstrated the consequences of inaction.</p></blockquote></div><p><em>Unfortunately, this is another example of a reactive approach to cybersecurity. Too often, meaningful action doesn’t happen until the damage has already been done.</em></p><p><em>My concern is that by the time these programs are fully implemented and organizations begin benefiting from them, many of the municipalities with the same vulnerabilities that enabled recent attacks will have already been compromised.</em></p><p><em>It’s a positive step, but it’s arriving years after the underlying risks were widely understood. This is the kind of investment that should have been made more than a decade ago, not after the attacks have already demonstrated the consequences of inaction.</em></p><h2 id="is-300-million-even-enough">Is $300 million even enough?</h2><p><strong>Damon Small, Board of Directors, Xcape, Inc.:</strong> </p><p><em>The Water Cyber Shield Act attempts to address a major regulatory gap by granting the Environmental Protection Agency explicit authority to enforce baseline security standards and allocate $300 million annually for utility upgrades, but federal dollars alone cannot fix this sector's systemic fragility.</em></p><div><blockquote><p>Spread across roughly 50,000 community water systems nationwide, that funding yields a negligible $6,000 per facility, an amount that barely covers an initial architecture audit, let alone operational technology overhauls.</p></blockquote></div><p><em>Spread across roughly 50,000 community water systems nationwide, that funding yields a negligible $6,000 per facility, an amount that barely covers an initial architecture audit, let alone operational technology overhauls.</em></p><p><em>The industry already possesses robust reference architectures and standards for protecting control systems, so the primary barrier is execution rather than a lack of guidance. Furthermore, claiming that capital injections will solve the threat ignores the reality that maintenance windows are rare in continuous operational technology environments.</em></p><p><em>Rather than waiting on Congressional appropriations, security leaders and asset owners must immediately execute foundational controls: strictly isolate industrial control networks from corporate IT, eliminate publicly exposed management interfaces to the Internet, enforce multi-factor authentication, and replace default device credentials.</em></p><p><em>Operational security standards already exist; what utilities lack is not awareness, but the uptime flexibility to actually apply patches.</em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/is-the-new-water-cyber-shield-act-too-little-too-late-and-can-a-cyber-group-do-it-better-the-experts-weigh-in</link>
                                                                            <description>
                            <![CDATA[ Numerous recent attacks are prompting Congress to do something ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tjiX2NnAd6dGXFsmpcTECc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZtdYh6C8PhDP5njg8EtK6M-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sun, 16 Aug 2026 13:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZtdYh6C8PhDP5njg8EtK6M-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Aerial view of water treatment factory at city wastewater cleaning facility]]></media:description>                                                            <media:text><![CDATA[Aerial view of water treatment factory at city wastewater cleaning facility]]></media:text>
                                <media:title type="plain"><![CDATA[Aerial view of water treatment factory at city wastewater cleaning facility]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZtdYh6C8PhDP5njg8EtK6M-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Two US senators have proposed a new <a href="https://www.schiff.senate.gov/wp-content/uploads/2026/08/Summary_Water-Cyber-Shield-Act.pdf" target="_blank" rel="nofollow">Water Cyber Shield Act</a> to provide the EPA with additional funding and tools to conduct cybersecurity assessments on critical water infrastructure.</p><p>The act would provide $300 million annually to allow for upgrades to water utility infrastructure. Numerous coordinated attacks have been launched against US water infrastructure in recent years across 12 states, with <a href="https://www.techradar.com/pro/security/hackers-are-going-after-our-water-now-over-30-minnesota-utilities-hit-in-coordinated-cyberattack-by-apparent-iranian-attackers">30 Minnesota utilities hit by Iran earlier this month</a>.</p><p>But a separate Water Watch Center group has been set up to monitor 91% of the roughly 50,000 community water systems nationwide following a two-year pilot. The group, set up by DEF CON Franklin and the National Rural Water Association, will offer managed detection and response services provided by five cybersecurity firms.</p><h2 id="why-are-water-utilities-being-attacked">Why are water utilities being attacked?</h2><p>The FBI, CISA, NSA, and many more <a href="https://www.techradar.com/pro/security/us-agencies-warn-iranian-hackers-are-targeting-american-critical-infrastructure-causing-disruptive-effects-within-the-united-states">agencies have issued warnings</a> about the increased threat to water utilities from Iran. </p><p>Water utilities are considered a low risk, high reward attack for state-sponsored hackers looking to cause as much damage as possible as many of the water control systems rely on  internet connected operational technology (OT) devices and logic controllers.</p><p>These devices are widely deployed across water infrastructure to control water treatment and are connected to computers at monitoring stations. Theoretically if a hacker gained control of these systems, they could turn off the treatment of water or open sewage gates to contaminate water supplies.</p><p>Many water treatment systems are designed to last decades, with these OT devices and logic controllers expected to last as long as possible. But as new tech and hardware is developed, these devices stop receiving software updates that can put them at a greater risk of being attacked.</p><p>For many in the cybersecurity industry though, the Water Cyber Shield Act is too little, too late.</p><h3 class="article-body__section" id="section-expert-perspectives-on-hardening-water-utilities"><span>Expert perspectives on hardening water utilities</span></h3><h2 id="will-the-water-cyber-shield-act-be-passed">Will the Water Cyber Shield Act be passed?</h2><p><strong>Dahvid Schloss, OSCP, Chief Operating Officer, Suzu Labs: </strong></p><p><em>While it's always exciting to see Congress attempt to get some good cybersecurity hygiene laws in place, it's likely a far reach from what will actually happen. The Water Cyber Shield Act feels a lot like a round two attempt from when this was attempted back in 2023 under the existing Safe Drinking Water Act authority as a rule, but that got shut down when water industry groups and a coalition of GOP states argued that it would increase costs on ratepayers, and then the EPA folded and pulled the rule. (More info can be found </em><a href="https://www.epa.gov/cyberwater/cybersecurity-sanitary-surveys" target="_blank" rel="nofollow"><em>here</em></a><em>)</em></p><div><blockquote><p>Hopefully, in light of recent attacks, this will push Senators and House Representatives to actually move the needle forward, but this isn't the first time we have had this situation happen before.  So, my fingers are crossed, but I'm not holding my breath.</p></blockquote></div><p><em>I hate to say it, but historically speaking, this is likely to fail before making it to a vote, just like all other bills that have been attempted to improve water cybersecurity in the past.  If we look at just the 118</em><sup><em>th</em></sup><em> and 119</em><sup><em>th</em></sup><em> Congress, we have had 9 bills introduced, as far as I'm aware, that pushed language that would have focused on either providing monetary assistance for, directly enforcing industry standards, and/or regulation around cybersecurity for water systems and CI, each varying in degree of what they would have provided and who they would have protected (rural vs non), but of those 9, all from within the 118th congress died within committees and without comments or markup, meaning no one even bothered to fight for them to get a vote across. Technically, the 4 from this congress (119) are still "pending' but considering no movement has occurred on them, they will likely reach the same fate.</em></p><p><em>Ultimately, Congress has been unreliable in pushing forward regulation and standards towards CI for quite some time, and the mantle thankfully has been picked up by private organizations and security practitioners who wish to have a safer and more secure water source. Even though it shouldn't be dependent on the goodwill of private citizens to protect public infrastructure.</em></p><p><em>Hopefully, in light of recent attacks, this will push Senators and House Representatives to actually move the needle forward, but this isn't the first time we have had this situation happen before.  So, my fingers are crossed, but I'm not holding my breath.</em></p><h2 id="too-little-too-late">Too little, too late?</h2><p><strong>John Strand, Owner, Black Hills Information Security, Inc.:</strong> </p><p><em>I think this type of legislation is important, but it’s also long overdue. People have known about the security weaknesses in critical infrastructure, especially within municipalities, for well over a decade.</em></p><div><blockquote><p>This is the kind of investment that should have been made more than a decade ago, not after the attacks have already demonstrated the consequences of inaction.</p></blockquote></div><p><em>Unfortunately, this is another example of a reactive approach to cybersecurity. Too often, meaningful action doesn’t happen until the damage has already been done.</em></p><p><em>My concern is that by the time these programs are fully implemented and organizations begin benefiting from them, many of the municipalities with the same vulnerabilities that enabled recent attacks will have already been compromised.</em></p><p><em>It’s a positive step, but it’s arriving years after the underlying risks were widely understood. This is the kind of investment that should have been made more than a decade ago, not after the attacks have already demonstrated the consequences of inaction.</em></p><h2 id="is-300-million-even-enough">Is $300 million even enough?</h2><p><strong>Damon Small, Board of Directors, Xcape, Inc.:</strong> </p><p><em>The Water Cyber Shield Act attempts to address a major regulatory gap by granting the Environmental Protection Agency explicit authority to enforce baseline security standards and allocate $300 million annually for utility upgrades, but federal dollars alone cannot fix this sector's systemic fragility.</em></p><div><blockquote><p>Spread across roughly 50,000 community water systems nationwide, that funding yields a negligible $6,000 per facility, an amount that barely covers an initial architecture audit, let alone operational technology overhauls.</p></blockquote></div><p><em>Spread across roughly 50,000 community water systems nationwide, that funding yields a negligible $6,000 per facility, an amount that barely covers an initial architecture audit, let alone operational technology overhauls.</em></p><p><em>The industry already possesses robust reference architectures and standards for protecting control systems, so the primary barrier is execution rather than a lack of guidance. Furthermore, claiming that capital injections will solve the threat ignores the reality that maintenance windows are rare in continuous operational technology environments.</em></p><p><em>Rather than waiting on Congressional appropriations, security leaders and asset owners must immediately execute foundational controls: strictly isolate industrial control networks from corporate IT, eliminate publicly exposed management interfaces to the Internet, enforce multi-factor authentication, and replace default device credentials.</em></p><p><em>Operational security standards already exist; what utilities lack is not awareness, but the uptime flexibility to actually apply patches.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why was there an 'evil’ Delta airlines Wi-Fi network? The experts weigh in ]]></title>
                                                                                                <dc:content><![CDATA[ <p>As many attendees of this year’s DEF CON hacker conference departed Las Vegas recently, many unsuspecting passengers on Delta Flight 591 attempted to access an onboard Wi-Fi network.</p><p>What they didn’t know was that ‘Delta WiFi Fast’ was actually a fake network, allegedly set up by a fellow passenger intended to mimic the actual onboard Wi-Fi network and scam other users.</p><p>The unknown passenger was able to disable the legitimate Wi-Fi networks for 30 minutes while they launched the attack, and in doing so, may have violated United States federal law.</p><h2 id="how-did-the-attack-take-place">How did the attack take place?</h2><p>According to Aircraft Communications Addressing and Reporting System (ACARS) messages, the situation was first brought to light by the crew of the flight, who shared the following message:</p><p>“HEY ALERT CORP SECURITY WE HAVE A PAX [passenger] ON THAT HAS CREATED A SCAM WIFI CALLED DELTA WIFI FAST WE BELIEVE THEY ARE TRYING TO SCAM THE OTH PAX”</p><p>Another message <a href="https://app.airframes.io/messages/7299585926" target="_blank" rel="nofollow">read</a>:</p><p>“NO INFO AS OF NOW WE HAVE A BUNCH OF PAX THAT WERE AT A CYBER CONFRENCE IN LAS THE WERE ABLE TO JAM OUR WIFI AND BRODCAST THERE SIGNIAL”</p><p>The actual details of what happened on the flight outside of these messages isn’t clear, but according to Monika Hathaway, head of press for DEF CON, similar attacks happened in Las Vegas: “Our conference this year also suffered from multiple similar ‘deauthorization’ Wi-Fi attacks and it impacted some of our operations.”</p><p>Delta airlines confirmed that no aircraft operating systems were affected and flight safety was never in question.</p><p>Wi-Fi deauthorization attacks can be launched with cheap, widely available ‘deauth boards’ which are small, battery powered devices that send deauthentication frames to devices within their range. On board a plane, these could easily reach most devices.</p><p>Once the legitimate Wi-Fi has been jammed and the other users booted from the network, the attacker can then set up an ‘evil twin’ network that users will attempt to connect to, which can be used to snoop on their internet traffic, steal credentials, and perform other malicious activities.</p><h3 class="article-body__section" id="section-expert-perspectives-on-the-delta-wi-fi-attack"><span>Expert perspectives on the Delta Wi-Fi attack</span></h3><h2 id="evil-twin-attacks-and-the-risks-of-connecting">‘Evil twin’ attacks and the risks of connecting</h2><p><strong>Aras Nazarovas, Senior Information Security Researcher at Cybernews:</strong></p><p><em>An evil twin attack is when hackers create fake Wi-Fi networks with the goal of stealing sensitive information from people, or exploiting known vulnerabilities present on victim devices. The fake networks often have a very similar (or identical) name to the legitimate network, which was the case here.</em></p><p><em>Once a person connects to the hacker’s Wi-Fi network, the hacker may be able to see what the victim is doing online and what data they transfer. However, since most websites have HTTPS/TLS encryption, much of what the user does, even on the rogue network, is private.</em></p><p><em>The risk here is that the hacker may attempt to redirect the victim to a phishing website – for instance, in this case, it may have been a fake Delta login page asking for personal data like name, email, address, etc. Or, the hacker may even go further and provide fake login pages for banks, social media, and try to extract login details from the victims.</em></p><div><blockquote><p>Connecting to a network controlled by a threat actor allows them to probe your device for potential vulnerabilities and maliciously redirect your internet traffic to their own servers.</p></blockquote></div><p><em>Connecting to such a network comes with some risk in itself. Connecting to a network controlled by a threat actor allows them to probe your device for potential vulnerabilities and maliciously redirect your internet traffic to their own servers. </em></p><p><em>If a person entered credentials into a Wi-Fi login page, noticed security warnings popping up after visiting a website, downloaded something, or entered payment information into an unfamiliar page, then they may have had their data stolen. In that case, the victim should immediately change any passwords that were transmitted, do a thorough scan of their device for malware, and if bank details were transmitted, freeze the bank account until new credentials are received.</em></p><p><em>However, if a user just connected and disconnected to the Wi-Fi without entering any details or clicking suspicious links, they should be fine.</em></p><h2 id="who-would-launch-the-attack">Who would launch the attack?</h2><p><strong>Seemant Sehgal, Founder & CEO, BreachLock:</strong></p><p><em>Flying out of Vegas after Black Hat myself just a few days before this incident, I can tell you the security conference crowd that passes through that airport is unlike any other, and the crew on Flight 591 made the right call with the information they had in front of them.</em></p><div><blockquote><p>The people most likely to pull something like this on a DEF CON departure flight are the ones who know exactly where that line is, which makes crossing it a choice rather than a mistake. Disabling the Wi-Fi and investigating was exactly the right instinct.</p></blockquote></div><p><em>Rogue access points impersonating a legitimate network are one of the oldest tricks in the book, and doing it on an aircraft to scam passengers is a federal crime regardless of the sophistication involved.</em></p><p><em>The people most likely to pull something like this on a DEF CON departure flight are the ones who know exactly where that line is, which makes crossing it a choice rather than a mistake. Disabling the Wi-Fi and investigating was exactly the right instinct.</em></p><p><strong>Denis Calderone, CTO, Suzu Labs:</strong></p><p><em>Hackers will hack. I go to DEF CON most years, and it's pretty common to have a terrible wifi experience on those flights because everyone is playing with their WiFi Pineapples and whatnot. That said, my flight home this year had no rogue SSIDs that I could see, and although, as usual, the wifi was shoddy, I never took the time to analyze the radio signals in the cabin, but if a few deauths were flying around, I wouldn't have been too surprised. It is concerning to hear about attempted credential harvesting on the flight though, and I feel that that's taking the expected hijinks way too far.</em></p><div><blockquote><p>These sorts of wifi threats are very common. DEF CON still displays their famed Wall of Sheep which displays the sniffing clear text credentials on the conference network, and every year the WiFi Pineapples have been selling out at the Hak5 booth.</p></blockquote></div><p><em>The deauthentication and evil twin combination used on Flight 591 is a well-documented attack that the security community has been demonstrating for a good two decades. These sorts of wifi threats are very common. DEF CON still displays their famed Wall of Sheep which displays the sniffing clear text credentials on the conference network, and every year the WiFi Pineapples have been selling out at the Hak5 booth.</em></p><p><em>But there's a significant difference between demonstrating a technique at a conference and deploying it against 199 unsuspecting passengers on a commercial aircraft. Last November, an Australian man was sentenced to seven years and four months in prison for running the exact same attack on domestic flights using a WiFi Pineapple and now the FBI is already involved in this case. There is definitely a legal exposure here.</em></p><p><em>For anyone who travels for work, in-flight WiFi should be treated as an untrusted network, period. The enterprise advice is encrypted DNS through your MDM and always-on VPN with captive portal remediation configured. But honestly, a VPN is something every traveler should be using, not just corporate road warriors. I make sure mine is on whenever I travel, and my family does the same.</em></p><p><em>Beyond that, if a WiFi network on a plane doesn't match what the crew announced or what's printed on the seat card, don't connect to it. If a network asks you to log in with your Google account or email credentials to get WiFi access, that's not how airline WiFi works. Airline captive portals ask for a credit card or a loyalty account, not your personal email password. If you're being asked for something that doesn't make sense for the context, you're probably not on the real network.</em></p><h2 id="reputational-harm-for-the-cybersecurity-industry">Reputational harm for the cybersecurity industry</h2><p><strong>Jacob Warner, Director of IT, Xcape, Inc.:</strong></p><p><em>While a rogue Wi-Fi access point on a commercial airliner poses zero direct risk to air-gapped flight safety controls, it creates a serious enterprise security hazard for business travelers relying on inflight networks.</em></p><p><em>Dismissing an onboard network impersonation as a harmless prank ignores the reality of man-in-the-middle attacks, credential harvesting, and fake authentication portals targeting captive passengers connecting to the Internet.</em></p><div><blockquote><p>Given that the flight departed Las Vegas immediately following DEF CON, it requires little imagination to conclude an attendee deployed the unauthorized access point.</p></blockquote></div><p><em>Given that the flight departed Las Vegas immediately following DEF CON, it requires little imagination to conclude an attendee deployed the unauthorized access point.</em></p><p><em>This juvenile behavior is precisely why hackers suffer such a poor reputation among non-technical audiences and why security professionals struggle to build mainstream trust. Enterprise security teams must mandate always-on virtual private networks or zero-trust network access, disable automatic connections to open SSIDs on corporate endpoints, and instruct travelers to treat cabin wireless environments as untrusted networks.</em></p><p><em>Setting up an evil twin at 30,000 feet does not make you a clever researcher; it just proves why we cannot have nice things.</em></p><p><strong>John Strand, Owner, Black Hills Information Security, Inc.:</strong></p><p><em>This one hits differently because this is my community. These are my people. When security professionals engage in this kind of behavior, they’re betraying the very community they’re claim to represent.</em></p><div><blockquote><p>There’s nothing impressive about it. It doesn’t make you look clever, and it certainly doesn’t make you an elite hacker. In most cases, these attacks aren’t even technically sophisticated.</p></blockquote></div><p><em>There’s nothing impressive about it. It doesn’t make you look clever, and it certainly doesn’t make you an elite hacker. In most cases, these attacks aren’t even technically sophisticated. They’re simply people with enough technical knowledge taking advantage of others who don’t have the experience to recognize what’s happening. That isn’t skill. It’s bullying.</em></p><p><em>I hope the people responsible are held accountable. This isn’t funny, it isn’t clever, and it doesn’t demonstrate technical excellence. It’s just people abusing their knowledge to prey on those who are at a disadvantage. That’s not what this profession should stand for.</em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/why-was-there-an-evil-delta-airlines-wi-fi-network-the-experts-weigh-in</link>
                                                                            <description>
                            <![CDATA[ A passenger set up an evil Wi-Fi network on a post-DEF CON Delta flight - we find out what the experts think. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZAjHb9bTEpdhjJqTyEPWfb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KZMrozx7RQQq5F2nbhK2iZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 15 Aug 2026 13:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Servers &amp; Network Devices]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Computing Components]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KZMrozx7RQQq5F2nbhK2iZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wi-Fi]]></media:description>                                                            <media:text><![CDATA[Wi-Fi]]></media:text>
                                <media:title type="plain"><![CDATA[Wi-Fi]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KZMrozx7RQQq5F2nbhK2iZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As many attendees of this year’s DEF CON hacker conference departed Las Vegas recently, many unsuspecting passengers on Delta Flight 591 attempted to access an onboard Wi-Fi network.</p><p>What they didn’t know was that ‘Delta WiFi Fast’ was actually a fake network, allegedly set up by a fellow passenger intended to mimic the actual onboard Wi-Fi network and scam other users.</p><p>The unknown passenger was able to disable the legitimate Wi-Fi networks for 30 minutes while they launched the attack, and in doing so, may have violated United States federal law.</p><h2 id="how-did-the-attack-take-place">How did the attack take place?</h2><p>According to Aircraft Communications Addressing and Reporting System (ACARS) messages, the situation was first brought to light by the crew of the flight, who shared the following message:</p><p>“HEY ALERT CORP SECURITY WE HAVE A PAX [passenger] ON THAT HAS CREATED A SCAM WIFI CALLED DELTA WIFI FAST WE BELIEVE THEY ARE TRYING TO SCAM THE OTH PAX”</p><p>Another message <a href="https://app.airframes.io/messages/7299585926" target="_blank" rel="nofollow">read</a>:</p><p>“NO INFO AS OF NOW WE HAVE A BUNCH OF PAX THAT WERE AT A CYBER CONFRENCE IN LAS THE WERE ABLE TO JAM OUR WIFI AND BRODCAST THERE SIGNIAL”</p><p>The actual details of what happened on the flight outside of these messages isn’t clear, but according to Monika Hathaway, head of press for DEF CON, similar attacks happened in Las Vegas: “Our conference this year also suffered from multiple similar ‘deauthorization’ Wi-Fi attacks and it impacted some of our operations.”</p><p>Delta airlines confirmed that no aircraft operating systems were affected and flight safety was never in question.</p><p>Wi-Fi deauthorization attacks can be launched with cheap, widely available ‘deauth boards’ which are small, battery powered devices that send deauthentication frames to devices within their range. On board a plane, these could easily reach most devices.</p><p>Once the legitimate Wi-Fi has been jammed and the other users booted from the network, the attacker can then set up an ‘evil twin’ network that users will attempt to connect to, which can be used to snoop on their internet traffic, steal credentials, and perform other malicious activities.</p><h3 class="article-body__section" id="section-expert-perspectives-on-the-delta-wi-fi-attack"><span>Expert perspectives on the Delta Wi-Fi attack</span></h3><h2 id="evil-twin-attacks-and-the-risks-of-connecting">‘Evil twin’ attacks and the risks of connecting</h2><p><strong>Aras Nazarovas, Senior Information Security Researcher at Cybernews:</strong></p><p><em>An evil twin attack is when hackers create fake Wi-Fi networks with the goal of stealing sensitive information from people, or exploiting known vulnerabilities present on victim devices. The fake networks often have a very similar (or identical) name to the legitimate network, which was the case here.</em></p><p><em>Once a person connects to the hacker’s Wi-Fi network, the hacker may be able to see what the victim is doing online and what data they transfer. However, since most websites have HTTPS/TLS encryption, much of what the user does, even on the rogue network, is private.</em></p><p><em>The risk here is that the hacker may attempt to redirect the victim to a phishing website – for instance, in this case, it may have been a fake Delta login page asking for personal data like name, email, address, etc. Or, the hacker may even go further and provide fake login pages for banks, social media, and try to extract login details from the victims.</em></p><div><blockquote><p>Connecting to a network controlled by a threat actor allows them to probe your device for potential vulnerabilities and maliciously redirect your internet traffic to their own servers.</p></blockquote></div><p><em>Connecting to such a network comes with some risk in itself. Connecting to a network controlled by a threat actor allows them to probe your device for potential vulnerabilities and maliciously redirect your internet traffic to their own servers. </em></p><p><em>If a person entered credentials into a Wi-Fi login page, noticed security warnings popping up after visiting a website, downloaded something, or entered payment information into an unfamiliar page, then they may have had their data stolen. In that case, the victim should immediately change any passwords that were transmitted, do a thorough scan of their device for malware, and if bank details were transmitted, freeze the bank account until new credentials are received.</em></p><p><em>However, if a user just connected and disconnected to the Wi-Fi without entering any details or clicking suspicious links, they should be fine.</em></p><h2 id="who-would-launch-the-attack">Who would launch the attack?</h2><p><strong>Seemant Sehgal, Founder & CEO, BreachLock:</strong></p><p><em>Flying out of Vegas after Black Hat myself just a few days before this incident, I can tell you the security conference crowd that passes through that airport is unlike any other, and the crew on Flight 591 made the right call with the information they had in front of them.</em></p><div><blockquote><p>The people most likely to pull something like this on a DEF CON departure flight are the ones who know exactly where that line is, which makes crossing it a choice rather than a mistake. Disabling the Wi-Fi and investigating was exactly the right instinct.</p></blockquote></div><p><em>Rogue access points impersonating a legitimate network are one of the oldest tricks in the book, and doing it on an aircraft to scam passengers is a federal crime regardless of the sophistication involved.</em></p><p><em>The people most likely to pull something like this on a DEF CON departure flight are the ones who know exactly where that line is, which makes crossing it a choice rather than a mistake. Disabling the Wi-Fi and investigating was exactly the right instinct.</em></p><p><strong>Denis Calderone, CTO, Suzu Labs:</strong></p><p><em>Hackers will hack. I go to DEF CON most years, and it's pretty common to have a terrible wifi experience on those flights because everyone is playing with their WiFi Pineapples and whatnot. That said, my flight home this year had no rogue SSIDs that I could see, and although, as usual, the wifi was shoddy, I never took the time to analyze the radio signals in the cabin, but if a few deauths were flying around, I wouldn't have been too surprised. It is concerning to hear about attempted credential harvesting on the flight though, and I feel that that's taking the expected hijinks way too far.</em></p><div><blockquote><p>These sorts of wifi threats are very common. DEF CON still displays their famed Wall of Sheep which displays the sniffing clear text credentials on the conference network, and every year the WiFi Pineapples have been selling out at the Hak5 booth.</p></blockquote></div><p><em>The deauthentication and evil twin combination used on Flight 591 is a well-documented attack that the security community has been demonstrating for a good two decades. These sorts of wifi threats are very common. DEF CON still displays their famed Wall of Sheep which displays the sniffing clear text credentials on the conference network, and every year the WiFi Pineapples have been selling out at the Hak5 booth.</em></p><p><em>But there's a significant difference between demonstrating a technique at a conference and deploying it against 199 unsuspecting passengers on a commercial aircraft. Last November, an Australian man was sentenced to seven years and four months in prison for running the exact same attack on domestic flights using a WiFi Pineapple and now the FBI is already involved in this case. There is definitely a legal exposure here.</em></p><p><em>For anyone who travels for work, in-flight WiFi should be treated as an untrusted network, period. The enterprise advice is encrypted DNS through your MDM and always-on VPN with captive portal remediation configured. But honestly, a VPN is something every traveler should be using, not just corporate road warriors. I make sure mine is on whenever I travel, and my family does the same.</em></p><p><em>Beyond that, if a WiFi network on a plane doesn't match what the crew announced or what's printed on the seat card, don't connect to it. If a network asks you to log in with your Google account or email credentials to get WiFi access, that's not how airline WiFi works. Airline captive portals ask for a credit card or a loyalty account, not your personal email password. If you're being asked for something that doesn't make sense for the context, you're probably not on the real network.</em></p><h2 id="reputational-harm-for-the-cybersecurity-industry">Reputational harm for the cybersecurity industry</h2><p><strong>Jacob Warner, Director of IT, Xcape, Inc.:</strong></p><p><em>While a rogue Wi-Fi access point on a commercial airliner poses zero direct risk to air-gapped flight safety controls, it creates a serious enterprise security hazard for business travelers relying on inflight networks.</em></p><p><em>Dismissing an onboard network impersonation as a harmless prank ignores the reality of man-in-the-middle attacks, credential harvesting, and fake authentication portals targeting captive passengers connecting to the Internet.</em></p><div><blockquote><p>Given that the flight departed Las Vegas immediately following DEF CON, it requires little imagination to conclude an attendee deployed the unauthorized access point.</p></blockquote></div><p><em>Given that the flight departed Las Vegas immediately following DEF CON, it requires little imagination to conclude an attendee deployed the unauthorized access point.</em></p><p><em>This juvenile behavior is precisely why hackers suffer such a poor reputation among non-technical audiences and why security professionals struggle to build mainstream trust. Enterprise security teams must mandate always-on virtual private networks or zero-trust network access, disable automatic connections to open SSIDs on corporate endpoints, and instruct travelers to treat cabin wireless environments as untrusted networks.</em></p><p><em>Setting up an evil twin at 30,000 feet does not make you a clever researcher; it just proves why we cannot have nice things.</em></p><p><strong>John Strand, Owner, Black Hills Information Security, Inc.:</strong></p><p><em>This one hits differently because this is my community. These are my people. When security professionals engage in this kind of behavior, they’re betraying the very community they’re claim to represent.</em></p><div><blockquote><p>There’s nothing impressive about it. It doesn’t make you look clever, and it certainly doesn’t make you an elite hacker. In most cases, these attacks aren’t even technically sophisticated.</p></blockquote></div><p><em>There’s nothing impressive about it. It doesn’t make you look clever, and it certainly doesn’t make you an elite hacker. In most cases, these attacks aren’t even technically sophisticated. They’re simply people with enough technical knowledge taking advantage of others who don’t have the experience to recognize what’s happening. That isn’t skill. It’s bullying.</em></p><p><em>I hope the people responsible are held accountable. This isn’t funny, it isn’t clever, and it doesn’t demonstrate technical excellence. It’s just people abusing their knowledge to prey on those who are at a disadvantage. That’s not what this profession should stand for.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'This one just needs a script': Researchers find ultimate Windows kill switch which can disable antivirus with almost no user interaction ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Researchers uncovered “Download more RAM” flaw in consumer DDR4/DDR5 memory</strong></li><li><strong>Attack bypassed Windows VBS and HVCI, disabling antivirus and protections</strong></li><li><strong>Microsoft patched CVE‑2026‑23670; tools now help enable memory write protection</strong></li></ul><p>Microsoft has recently fixed a vulnerability that allowed threat actors to bypass advanced security measures, disable antivirus software, and expose the target device to full system takeover. </p><p>All of this, it seems, could have been possible with a very simple script, and a single click from the victim’s side.</p><p>Luckily, the vulnerability was discovered by white hat hackers, reported to Microsoft and remedied before falling into the wrong hands.</p><h2 id="download-more-ram">Download more RAM</h2><p>During the 2026 USENIX Security Symposium, security researchers from the University of Birmingham and Durham University presented a discovery they called “Download more RAM”. </p><p>According to the researchers, some consumer memory chips (DDR4 and <a href="https://www.techradar.com/computing/best-ddr5-ram" target="_blank">DDR5</a> DIMM) allowed software to alter the configuration reports it sends to the motherboard. In practice, it means that a threat actor could instruct the RAM chip to tell the computer it was bigger than it actually was, making the device “think” it has twice as much RAM memory as it actually has.</p><p>The researchers then established that this phantom extra memory can serve as an alias for real memory locations, granting them the ability to both read, and modify, memory allocations that should be under the processor’s, and Windows’ protection.</p><p>This window let them work around both Virtualization-based Security (VBS) and Hypervisor-Enforced Code Integrity (HVCI). </p><p>VBS, first introduced with Windows 10, is a security feature that uses hardware virtualization to isolate critical security functions from the OS, while HVCI uses virtualization to make sure only trusted and verified code can run in the Windows kernel.</p><p>The researchers also used the flaw to disable both antivirus and endpoint detection and response (EDR) software, re-introduce older, vulnerable drivers, compromise corporate systems under lockdown, and bypass kernel-level game anti-cheat protections. </p><p>The worst part is that this entire process can be chained together into a one-click script. In theory, if a victim is served this script as a file and they run it, they would trigger a chain of events that includes creating memory aliases, rebooting the computer, and disabling security protections. </p><p>"Our work exploits the fact that all processes share the same memory to bypass Windows' strongest security guarantees,” said Professor Tom Chothia, from the University of Birmingham. “Previous attacks of this kind needed a screwdriver and physical access to the machine. This one just needs a script. That changes who can carry it out and how far it can spread."</p><h2 id="who-is-vulnerable-and-how-to-stay-safe">Who is vulnerable and how to stay safe</h2><p>The attack surface is rather large, as well. The researchers analyzed the market and found three major manufacturers (Corsair, G.Skill, and ADATA) shipping at least one consumer memory product line in which the configuration chip was left entirely unprotected. Together, these vendors make up more than half (55%) of the high-performance consumer memory market and more than 70% of the gaming market (this doesn’t mean that 55% of the high-performance market is vulnerable - many devices are running other modules, too).</p><p>Modules from Crucial, Kingston and HyperX, and some G.Skill lines, were found to use partial write protection, but still enough to keep the device secure. </p><p>Before publishing their work, the researchers disclosed their findings to Microsoft, who quickly addressed it. The bug is now tracked as CVE-2026-23670, and is described on the National Vulnerability Database (NVD) as an “untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave” which “allows an authorized attacker to bypass a security feature locally.”</p><p>The bug was given a severity score of 5.7/10 (medium), and was fixed as part of the April 2026 Patch Tuesday cumulative update. Therefore, systems with Secure Boot running should be protected against this vulnerability. </p><p>Corsair added a feature to its iCue tools that lets users retroactively enable write protection on their memory modules. There is also a free tool called HWinfo with the same functionality, the researchers said, stressing that it mitigates the issue on non-Corsair models. Also, some motherboards offer a BIOS setting to block writes to memory configuration chips, which users can enable as an interim measure.</p><p>“The ‘Download More RAM’ attack demonstrates once more the importance of understanding systems, especially in terms of security guarantees. If a lower layer can become compromised, it puts the full system at risk,” said Dr Marius Muench, from the University of Birmingham.  </p><p>“Windows makes a strong promise: that even an attacker with administrator rights can't touch the secure kernel. We found that promise rests on the assumption that your memory is telling the truth about itself - on a lot of the memory people actually buy, it doesn't have to." </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/this-one-just-needs-a-script-researchers-find-ultimate-windows-kill-switch-which-can-disable-antivirus-with-almost-no-user-interaction</link>
                                                                            <description>
                            <![CDATA[ Microsoft fixed it as part of the April Patch Tuesday cumulative update, but there are other fixes and mitigations available, too. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">D5GiErt8bYeqUgE82r6EtQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iGi8rqmXBTK3ZPbi4ExzfW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Aug 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iGi8rqmXBTK3ZPbi4ExzfW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Är du ute efter bästa VPN för Windows 10 och Windwos 11? Här är våra favoriter just nu.]]></media:description>                                                            <media:text><![CDATA[Fingertip pressing keyboard key with Windows logo on it]]></media:text>
                                <media:title type="plain"><![CDATA[Fingertip pressing keyboard key with Windows logo on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iGi8rqmXBTK3ZPbi4ExzfW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers uncovered “Download more RAM” flaw in consumer DDR4/DDR5 memory</strong></li><li><strong>Attack bypassed Windows VBS and HVCI, disabling antivirus and protections</strong></li><li><strong>Microsoft patched CVE‑2026‑23670; tools now help enable memory write protection</strong></li></ul><p>Microsoft has recently fixed a vulnerability that allowed threat actors to bypass advanced security measures, disable antivirus software, and expose the target device to full system takeover. </p><p>All of this, it seems, could have been possible with a very simple script, and a single click from the victim’s side.</p><p>Luckily, the vulnerability was discovered by white hat hackers, reported to Microsoft and remedied before falling into the wrong hands.</p><h2 id="download-more-ram">Download more RAM</h2><p>During the 2026 USENIX Security Symposium, security researchers from the University of Birmingham and Durham University presented a discovery they called “Download more RAM”. </p><p>According to the researchers, some consumer memory chips (DDR4 and <a href="https://www.techradar.com/computing/best-ddr5-ram" target="_blank">DDR5</a> DIMM) allowed software to alter the configuration reports it sends to the motherboard. In practice, it means that a threat actor could instruct the RAM chip to tell the computer it was bigger than it actually was, making the device “think” it has twice as much RAM memory as it actually has.</p><p>The researchers then established that this phantom extra memory can serve as an alias for real memory locations, granting them the ability to both read, and modify, memory allocations that should be under the processor’s, and Windows’ protection.</p><p>This window let them work around both Virtualization-based Security (VBS) and Hypervisor-Enforced Code Integrity (HVCI). </p><p>VBS, first introduced with Windows 10, is a security feature that uses hardware virtualization to isolate critical security functions from the OS, while HVCI uses virtualization to make sure only trusted and verified code can run in the Windows kernel.</p><p>The researchers also used the flaw to disable both antivirus and endpoint detection and response (EDR) software, re-introduce older, vulnerable drivers, compromise corporate systems under lockdown, and bypass kernel-level game anti-cheat protections. </p><p>The worst part is that this entire process can be chained together into a one-click script. In theory, if a victim is served this script as a file and they run it, they would trigger a chain of events that includes creating memory aliases, rebooting the computer, and disabling security protections. </p><p>"Our work exploits the fact that all processes share the same memory to bypass Windows' strongest security guarantees,” said Professor Tom Chothia, from the University of Birmingham. “Previous attacks of this kind needed a screwdriver and physical access to the machine. This one just needs a script. That changes who can carry it out and how far it can spread."</p><h2 id="who-is-vulnerable-and-how-to-stay-safe">Who is vulnerable and how to stay safe</h2><p>The attack surface is rather large, as well. The researchers analyzed the market and found three major manufacturers (Corsair, G.Skill, and ADATA) shipping at least one consumer memory product line in which the configuration chip was left entirely unprotected. Together, these vendors make up more than half (55%) of the high-performance consumer memory market and more than 70% of the gaming market (this doesn’t mean that 55% of the high-performance market is vulnerable - many devices are running other modules, too).</p><p>Modules from Crucial, Kingston and HyperX, and some G.Skill lines, were found to use partial write protection, but still enough to keep the device secure. </p><p>Before publishing their work, the researchers disclosed their findings to Microsoft, who quickly addressed it. The bug is now tracked as CVE-2026-23670, and is described on the National Vulnerability Database (NVD) as an “untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave” which “allows an authorized attacker to bypass a security feature locally.”</p><p>The bug was given a severity score of 5.7/10 (medium), and was fixed as part of the April 2026 Patch Tuesday cumulative update. Therefore, systems with Secure Boot running should be protected against this vulnerability. </p><p>Corsair added a feature to its iCue tools that lets users retroactively enable write protection on their memory modules. There is also a free tool called HWinfo with the same functionality, the researchers said, stressing that it mitigates the issue on non-Corsair models. Also, some motherboards offer a BIOS setting to block writes to memory configuration chips, which users can enable as an interim measure.</p><p>“The ‘Download More RAM’ attack demonstrates once more the importance of understanding systems, especially in terms of security guarantees. If a lower layer can become compromised, it puts the full system at risk,” said Dr Marius Muench, from the University of Birmingham.  </p><p>“Windows makes a strong promise: that even an attacker with administrator rights can't touch the secure kernel. We found that promise rests on the assumption that your memory is telling the truth about itself - on a lot of the memory people actually buy, it doesn't have to." </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Scammers hijack real Shopify notifications to swindle victims — here's how to stay safe ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Huntress uncovers Shopify refund scam using fake orders and app notifications</strong></li><li><strong>Attackers embed contact details in shipping addresses to trick victims into paying</strong></li><li><strong>Users advised to ignore suspicious info, verify refunds, and report fake stores</strong></li></ul><p>Hackers are targeting businesses and individuals running Shopify stores with a highly sophisticated fake refund scam, experts have warned.</p><p>Security researchers at Huntress <a href="https://www.huntress.com/blog/shopify-fake-refund-scam" target="_blank">outlined</a> how the fake refund scam works: first, a victim gets a notification that they received a refund. It could be for a returned iPhone, or a canceled service or order. The “refund” can be anywhere from a few hundred, to a few thousand dollars. Soon after, the scammers call (or mail) the victim, say they work at the company that gave the erroneous refund, and convince the victim to return the funds.</p><p>If the victim complies, they are actually sending their own money to the victims, since the “refund” part never happened.</p><h2 id="abusing-shopify-s-infrastructure">Abusing Shopify's infrastructure</h2><p>There are a couple of ways to pull this attack off: sometimes the scammers really make the initial transaction, but are able to cancel it and return the funds; in other scenarios, they create spoofed pages showing the transactions, tricking those slightly more gullible. </p><p>In most cases, fake refund scams can be spotted relatively easily, which is why they are not that popular nowadays. However, this new campaign comes with a sinister twist that will make even hardened veterans wince.</p><p>Huntress’ report notes the attackers start by creating a Shopify store of their own (or use a compromised one). The one the researchers observed was called “My Store” and was later deleted before it could be further scrutinized. Then, the attackers make a fake order themselves, setting their targets as the recipients using their phone numbers, or email addresses.</p><p>This type of information isn’t that difficult to come by these days. There are hundreds of email and phone number databases leaked on the dark web, which can be picked up for free (or for a handful of dollars). When they submit the purchase order, a notification appears in the victim’s Shop apps. </p><p>Yes, that’s right. In the Shopify app itself. Coming through Shopify infrastructure. As such, it can easily be confused for an authentic notification. It is even worse for users that enabled push notifications on their mobile phones, since they’ll see a notification with the Shopify logo, next to all the other notifications on their phone. </p><p>But the attackers still need to pull off the hardest part - getting the victim to “return” the money. In this case, instead of calling or messaging them, they leave their contact information in the shipping address, hoping victims would panic and reach out themselves.</p><p>In one shared example, the shipping address was listed as: Owen Nolan “2856 If You Didnt Place This Order Call Us at 1_888_690_3420-”, Albany NY United States 1_888_690_3420.”</p><p>For those treading carefully through the internet’s wastelands, the message included in the shipping address is an immediate red flag. Grammar mistakes, all letters capitalized, and a phone number completely out of place should be quite an obvious sign of an attempted fraud. However, since these kinds of scams bet on people being fast, reckless, overworked, and afraid, it might just work.</p><p>Huntress did not say if the scam made any meaningful impact among the Shopify’s community, or if it targeted a specific subgroup of users. </p><h2 id="defending-against-fake-refund-scams">Defending against fake refund scams</h2><p>To protect against such attacks, the researchers advise users never interact with phone numbers, email addresses, or links contained in an order that aren’t recognizable. They also advise users concerned about the security of their SHop account or personal data to contact support, and stress users should check their bank accounts to confirm whether they were actually changed. If they weren’t, they can report the order as “Not my order” in the shop app. </p><p>Finally, when purchasing from a store on Shop in general, users should check the store and its product reviews to learn about other customers’ experiences. If users are concerned that a product or store could be fake, it can easily be reported. Many of the shops in this scam were brand-new, with some using a "coming soon" description, as well. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/scammers-hijack-real-shopify-notifications-to-swindle-victims-heres-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ Would you recognize a fake notification if it came directly from Shopify? Some scammers are betting you wouldn't. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">u7cEBFyhxgwb3nwswX5ieS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sTv9eAmsTTbHV59N8KXUZk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Aug 2026 15:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sTv9eAmsTTbHV59N8KXUZk-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[use Shopify to build your online busness]]></media:description>                                                            <media:text><![CDATA[use Shopify to build your online busness]]></media:text>
                                <media:title type="plain"><![CDATA[use Shopify to build your online busness]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sTv9eAmsTTbHV59N8KXUZk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Huntress uncovers Shopify refund scam using fake orders and app notifications</strong></li><li><strong>Attackers embed contact details in shipping addresses to trick victims into paying</strong></li><li><strong>Users advised to ignore suspicious info, verify refunds, and report fake stores</strong></li></ul><p>Hackers are targeting businesses and individuals running Shopify stores with a highly sophisticated fake refund scam, experts have warned.</p><p>Security researchers at Huntress <a href="https://www.huntress.com/blog/shopify-fake-refund-scam" target="_blank">outlined</a> how the fake refund scam works: first, a victim gets a notification that they received a refund. It could be for a returned iPhone, or a canceled service or order. The “refund” can be anywhere from a few hundred, to a few thousand dollars. Soon after, the scammers call (or mail) the victim, say they work at the company that gave the erroneous refund, and convince the victim to return the funds.</p><p>If the victim complies, they are actually sending their own money to the victims, since the “refund” part never happened.</p><h2 id="abusing-shopify-s-infrastructure">Abusing Shopify's infrastructure</h2><p>There are a couple of ways to pull this attack off: sometimes the scammers really make the initial transaction, but are able to cancel it and return the funds; in other scenarios, they create spoofed pages showing the transactions, tricking those slightly more gullible. </p><p>In most cases, fake refund scams can be spotted relatively easily, which is why they are not that popular nowadays. However, this new campaign comes with a sinister twist that will make even hardened veterans wince.</p><p>Huntress’ report notes the attackers start by creating a Shopify store of their own (or use a compromised one). The one the researchers observed was called “My Store” and was later deleted before it could be further scrutinized. Then, the attackers make a fake order themselves, setting their targets as the recipients using their phone numbers, or email addresses.</p><p>This type of information isn’t that difficult to come by these days. There are hundreds of email and phone number databases leaked on the dark web, which can be picked up for free (or for a handful of dollars). When they submit the purchase order, a notification appears in the victim’s Shop apps. </p><p>Yes, that’s right. In the Shopify app itself. Coming through Shopify infrastructure. As such, it can easily be confused for an authentic notification. It is even worse for users that enabled push notifications on their mobile phones, since they’ll see a notification with the Shopify logo, next to all the other notifications on their phone. </p><p>But the attackers still need to pull off the hardest part - getting the victim to “return” the money. In this case, instead of calling or messaging them, they leave their contact information in the shipping address, hoping victims would panic and reach out themselves.</p><p>In one shared example, the shipping address was listed as: Owen Nolan “2856 If You Didnt Place This Order Call Us at 1_888_690_3420-”, Albany NY United States 1_888_690_3420.”</p><p>For those treading carefully through the internet’s wastelands, the message included in the shipping address is an immediate red flag. Grammar mistakes, all letters capitalized, and a phone number completely out of place should be quite an obvious sign of an attempted fraud. However, since these kinds of scams bet on people being fast, reckless, overworked, and afraid, it might just work.</p><p>Huntress did not say if the scam made any meaningful impact among the Shopify’s community, or if it targeted a specific subgroup of users. </p><h2 id="defending-against-fake-refund-scams">Defending against fake refund scams</h2><p>To protect against such attacks, the researchers advise users never interact with phone numbers, email addresses, or links contained in an order that aren’t recognizable. They also advise users concerned about the security of their SHop account or personal data to contact support, and stress users should check their bank accounts to confirm whether they were actually changed. If they weren’t, they can report the order as “Not my order” in the shop app. </p><p>Finally, when purchasing from a store on Shop in general, users should check the store and its product reviews to learn about other customers’ experiences. If users are concerned that a product or store could be fake, it can easily be reported. Many of the shops in this scam were brand-new, with some using a "coming soon" description, as well. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ World-first autonomous ‘end-to-end’ AI attack against Taiwan tied to Chinese hackers — and the scariest part is that it was fully open source ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>China launched a fully autonomous vulnerability hunting attack against Taiwan</strong></li><li><strong>The attack leveraged eight open-source AI models to hunt for new attack vectors</strong></li><li><strong>The attack hit Taiwan government accounts, personnel records, the nuclear safety agency, and more</strong></li></ul><p>A first-of-its-kind cyberattack using autonomous AI has been spotted attacking Taiwan, and it compromised 85 government accounts and stole over 2,500 personnel records before moving on to hit the country’s nuclear safety agency and at least seven energy companies.</p><p>The attack used eight open-source AI models to build a hacking program that was able to independently conduct reconnaissance and intrusion, and was able to chain vulnerabilities and change tactics whenever it was blocked.</p><p>The intrusion took place over the course of four days, and was first exposed by <a href="https://www.ft.com/content/7d2ab3e0-9085-48f6-b38a-d90260d58795?syn-25a6b1a6=1" target="_blank" rel="nofollow"><em>The Financial Times</em></a> on August 12, 2026. The FT article covered research performed by Dream, an Israeli AI and cyberdefense company that first identified the breach.</p><h2 id="autonomous-ai-attack">Autonomous AI attack</h2><p>The attack was first uncovered during routine monitoring of cyber criminal activity. Dream found a 160MB online archive of 1,395 files. Further examination of the files revealed that the attack relied on Hermes and OpenClaw - two open-source AI agents.</p><p>As is typical of attacks relying on AI models, the hackers had framed the context of the intrusion as a routine cyber readiness test in order to bypass the built-in guardrails of the AI models.</p><p>The attack used multiple agents to hunt for new vulnerabilities and access points across the internet, providing the tool with multiple attack paths to take if one failed to gain entry.</p><p>AI agents have been quickly integrated into the attacks of cybercriminal organizations and state-sponsored threat actors alike, enhancing their abilities to launch highly complex attacks at scale. “This must be the basic assumption of every government around the globe,” said Amir Becker, Dream's chief strategy officer.</p><p>Dream did not tie the attack to any specific cybercriminal group, nor did it confirm the target of the attack, but said it had alerted a government in the “Asia-Pacific.” Documentation within the recovered archive contained Simplified Chinese, which is the official written language used in mainland China. </p><p>The archive also contained data collected from the targets, which was written in Traditional Chinese. This form of written Chinese is widely used in Taiwan, Hong Kong, and Macau.</p><p>Taiwan's Ministry of Digital Affairs has refused to comment on the breach, and the Chinese authorities have not responded to requests for comment.</p><p>China has long considered Taiwan to be a part of mainland China. Taiwan declared its independence following the end of the Chinese Civil War in 1949. A report from Taiwan’s National Security Bureau earlier this year revealed that the country was subject to <a href="https://www.techradar.com/pro/security/taiwanese-infrastructure-suffered-over-2-5-million-chinese-cyberattacks-per-day-in-2025-report-reveals">2.5 million Chinese cyberattacks per day in 2025</a>.</p><h2 id="expert-perspective-on-autonomous-ai-attack">Expert perspective on autonomous AI attack</h2><p><strong>Collin Hogue-Spears, senior director of solution management at Black Duck:</strong></p><p><em>The agents ran the intrusion end to end and invented nothing new to run it with. Familiar identity and API failures opened every confirmed path into Taiwan's systems. Dream Research Labs documented up to eight subagents working concurrently across twelve waves, ranking attack paths, redirecting when a technique failed, and researching alternatives online before trying again.</em></p><p><em>What they found was exposed development endpoints, an API accepting authentication tokens with the signature check disabled, unauthenticated data APIs, and passwords built from employee ID numbers.</em></p><p><em>The framework also ran its own AI static analysis hunting unknown flaws, but Dream says it worked against two public single sign-on SDK sample projects, and none of those findings produced a confirmed exploit on the live systems. No zero-day appears anywhere in the report, but a nuclear safety regulator does.</em></p><p><em>In conventional web and identity logs, this reads as a security scan. The distinguishing signal is the sequence across systems, not any single request. The tell is not the request. It is what the same account does next, somewhere else.</em></p><p><em>Conventional scanners have tested thousands of endpoints at machine speed for twenty years, so raw coverage is not the change here. What Dream Research Labs describes is chaining: password spraying, then fresh SSO sessions, then access to routes an account had never touched, then the same suspected weakness retested until it held, then one identity surfacing across several connected applications.</em></p><div><blockquote><p>The evidence therefore supports a Chinese Mainland-language operator against a Taiwanese target, with a target profile consistent with mainland collection priorities.</p></blockquote></div><p><em>Simplified Chinese in the operator's notes is one signal. Traditional Chinese in the stolen files is just Taiwan. Dream rested its China assessment on a code-switching observation, and only half of it points at the attacker. Per Chinese-language coverage of the report, Simplified characters appeared in the operators' internal communications and Traditional characters appeared in the exfiltrated data. The first describes the operator's working language. The second describes the victim, because that is what Taiwanese government files look like [Traditional Characters].</em></p><p><em>The evidence therefore supports a Chinese Mainland-language operator against a Taiwanese target, with a target profile consistent with mainland collection priorities. It does not name a group or establish state direction. The report also publishes no indicators, no hashes, and no victim confirmation; it does not identify the model, and its executive summary claims installed backdoors while its own attack chain says authentication blocked the web shell.</em></p><p><em>Security leaders must reject unsigned authentication tokens and prohibit the alg:none setting outright, and separately require reauthentication or multi-factor at any single sign-on boundary into a sensitive system. Dream describes two independent identity failures in Taiwan, and closing one leaves the other open. Provider guardrails cannot compensate for a password-only SSO bridge.</em></p><p><em>They must also monitor route diversity per source, per session, per account, and per device rather than by request rate alone, because a distributed set of agents spreads requests across addresses and sessions that no single volume threshold catches. If your detection assumes one attacker at one address working one path at a time, you have modeled the wrong shape.</em></p><p><em>Your thresholds were built for one attacker on one path. This was eight, in parallel. And they must ask two questions of any AI attack disclosure before acting on it: which model ran the operation, and what can we hunt on tomorrow morning?"</em></p><p>Via <a href="https://united24media.com/world/researchers-say-china-likely-linked-to-unprecedented-autonomous-ai-attack-on-taiwan-21623" target="_blank" rel="nofollow"><em>United24</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/world-first-autonomous-end-to-end-ai-attack-against-taiwan-tied-to-chinese-hackers-and-the-scariest-part-is-that-it-was-fully-open-source</link>
                                                                            <description>
                            <![CDATA[ China implicated in Taiwan attack through written documentation recovered from the attack. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HxPDT8x5CyBeVeFNd79h3E</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UQyjwYkZut5eDweL2vKmvb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 21:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UQyjwYkZut5eDweL2vKmvb-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A Chinese military facility with multiple computers visible on a desk, with a large Chinese flag in the background.]]></media:description>                                                            <media:text><![CDATA[A Chinese military facility with multiple computers visible on a desk, with a large Chinese flag in the background.]]></media:text>
                                <media:title type="plain"><![CDATA[A Chinese military facility with multiple computers visible on a desk, with a large Chinese flag in the background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UQyjwYkZut5eDweL2vKmvb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>China launched a fully autonomous vulnerability hunting attack against Taiwan</strong></li><li><strong>The attack leveraged eight open-source AI models to hunt for new attack vectors</strong></li><li><strong>The attack hit Taiwan government accounts, personnel records, the nuclear safety agency, and more</strong></li></ul><p>A first-of-its-kind cyberattack using autonomous AI has been spotted attacking Taiwan, and it compromised 85 government accounts and stole over 2,500 personnel records before moving on to hit the country’s nuclear safety agency and at least seven energy companies.</p><p>The attack used eight open-source AI models to build a hacking program that was able to independently conduct reconnaissance and intrusion, and was able to chain vulnerabilities and change tactics whenever it was blocked.</p><p>The intrusion took place over the course of four days, and was first exposed by <a href="https://www.ft.com/content/7d2ab3e0-9085-48f6-b38a-d90260d58795?syn-25a6b1a6=1" target="_blank" rel="nofollow"><em>The Financial Times</em></a> on August 12, 2026. The FT article covered research performed by Dream, an Israeli AI and cyberdefense company that first identified the breach.</p><h2 id="autonomous-ai-attack">Autonomous AI attack</h2><p>The attack was first uncovered during routine monitoring of cyber criminal activity. Dream found a 160MB online archive of 1,395 files. Further examination of the files revealed that the attack relied on Hermes and OpenClaw - two open-source AI agents.</p><p>As is typical of attacks relying on AI models, the hackers had framed the context of the intrusion as a routine cyber readiness test in order to bypass the built-in guardrails of the AI models.</p><p>The attack used multiple agents to hunt for new vulnerabilities and access points across the internet, providing the tool with multiple attack paths to take if one failed to gain entry.</p><p>AI agents have been quickly integrated into the attacks of cybercriminal organizations and state-sponsored threat actors alike, enhancing their abilities to launch highly complex attacks at scale. “This must be the basic assumption of every government around the globe,” said Amir Becker, Dream's chief strategy officer.</p><p>Dream did not tie the attack to any specific cybercriminal group, nor did it confirm the target of the attack, but said it had alerted a government in the “Asia-Pacific.” Documentation within the recovered archive contained Simplified Chinese, which is the official written language used in mainland China. </p><p>The archive also contained data collected from the targets, which was written in Traditional Chinese. This form of written Chinese is widely used in Taiwan, Hong Kong, and Macau.</p><p>Taiwan's Ministry of Digital Affairs has refused to comment on the breach, and the Chinese authorities have not responded to requests for comment.</p><p>China has long considered Taiwan to be a part of mainland China. Taiwan declared its independence following the end of the Chinese Civil War in 1949. A report from Taiwan’s National Security Bureau earlier this year revealed that the country was subject to <a href="https://www.techradar.com/pro/security/taiwanese-infrastructure-suffered-over-2-5-million-chinese-cyberattacks-per-day-in-2025-report-reveals">2.5 million Chinese cyberattacks per day in 2025</a>.</p><h2 id="expert-perspective-on-autonomous-ai-attack">Expert perspective on autonomous AI attack</h2><p><strong>Collin Hogue-Spears, senior director of solution management at Black Duck:</strong></p><p><em>The agents ran the intrusion end to end and invented nothing new to run it with. Familiar identity and API failures opened every confirmed path into Taiwan's systems. Dream Research Labs documented up to eight subagents working concurrently across twelve waves, ranking attack paths, redirecting when a technique failed, and researching alternatives online before trying again.</em></p><p><em>What they found was exposed development endpoints, an API accepting authentication tokens with the signature check disabled, unauthenticated data APIs, and passwords built from employee ID numbers.</em></p><p><em>The framework also ran its own AI static analysis hunting unknown flaws, but Dream says it worked against two public single sign-on SDK sample projects, and none of those findings produced a confirmed exploit on the live systems. No zero-day appears anywhere in the report, but a nuclear safety regulator does.</em></p><p><em>In conventional web and identity logs, this reads as a security scan. The distinguishing signal is the sequence across systems, not any single request. The tell is not the request. It is what the same account does next, somewhere else.</em></p><p><em>Conventional scanners have tested thousands of endpoints at machine speed for twenty years, so raw coverage is not the change here. What Dream Research Labs describes is chaining: password spraying, then fresh SSO sessions, then access to routes an account had never touched, then the same suspected weakness retested until it held, then one identity surfacing across several connected applications.</em></p><div><blockquote><p>The evidence therefore supports a Chinese Mainland-language operator against a Taiwanese target, with a target profile consistent with mainland collection priorities.</p></blockquote></div><p><em>Simplified Chinese in the operator's notes is one signal. Traditional Chinese in the stolen files is just Taiwan. Dream rested its China assessment on a code-switching observation, and only half of it points at the attacker. Per Chinese-language coverage of the report, Simplified characters appeared in the operators' internal communications and Traditional characters appeared in the exfiltrated data. The first describes the operator's working language. The second describes the victim, because that is what Taiwanese government files look like [Traditional Characters].</em></p><p><em>The evidence therefore supports a Chinese Mainland-language operator against a Taiwanese target, with a target profile consistent with mainland collection priorities. It does not name a group or establish state direction. The report also publishes no indicators, no hashes, and no victim confirmation; it does not identify the model, and its executive summary claims installed backdoors while its own attack chain says authentication blocked the web shell.</em></p><p><em>Security leaders must reject unsigned authentication tokens and prohibit the alg:none setting outright, and separately require reauthentication or multi-factor at any single sign-on boundary into a sensitive system. Dream describes two independent identity failures in Taiwan, and closing one leaves the other open. Provider guardrails cannot compensate for a password-only SSO bridge.</em></p><p><em>They must also monitor route diversity per source, per session, per account, and per device rather than by request rate alone, because a distributed set of agents spreads requests across addresses and sessions that no single volume threshold catches. If your detection assumes one attacker at one address working one path at a time, you have modeled the wrong shape.</em></p><p><em>Your thresholds were built for one attacker on one path. This was eight, in parallel. And they must ask two questions of any AI attack disclosure before acting on it: which model ran the operation, and what can we hunt on tomorrow morning?"</em></p><p>Via <a href="https://united24media.com/world/researchers-say-china-likely-linked-to-unprecedented-autonomous-ai-attack-on-taiwan-21623" target="_blank" rel="nofollow"><em>United24</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft's nemesis returns: Nightmare Eclipse is back with a new zero day which could be bad news for Windows users ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Nightmare Eclipse discloses ShieldBreak, a new Windows privilege‑escalation zero‑day</strong></li><li><strong>Flaw bypasses a recent patch and works on fully updated Windows 11 systems</strong></li><li><strong>Researcher’s ongoing exploit spree leaves multiple Windows vulnerabilities still unpatched</strong></li></ul><p>Nightmare Eclipse has struck again! The notorious zero-day researcher with a Microsoft grudge disclosed its latest vulnerability, and just as in previous instances, they picked their timing and released their research hours after Microsoft published its August Patch Tuesday cumulative update in order to maximize the hurt.</p><p>The newest flaw is called ShieldBreak, and is described as a local escalation of privilege vulnerability that allows threat actors to gain SYSTEM-level privileges on vulnerable systems. Speaking of vulnerable systems, the list is rather long because it includes all versions of Windows 11, including those with the latest security patches. </p><p>“The PoC was tested in the latest version of windows 11 25h2 (+Canary channel) and windows server 2025, the PoC also have a 100% success rate,” Nightmare Eclipse <a href="https://git.projectnightcrawler.dev/NightmareEclipse/ShieldBreak/src/branch/main/ShieldBreak.cpp" target="_blank" rel="nofollow">said</a> on their GitHub account. “Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well.”</p><h2 id="a-bypass-for-the-rogueplanet-fix">A bypass for the RoguePlanet fix</h2><p>The mysterious attacker also said that the bug was actually a bypass for the patch Microsoft issued to fix their earlier work, called RoguePlanet.</p><p>“Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass,” the GitHub read entry.</p><p>Microsoft, on the other hand, responded in pure enterprise fashion, sharing a boilerplate statement that it was “investigating” and that it “supports coordinated <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">vulnerability</a> disclosure”. </p><p>In response to an enquiry by <a href="https://www.theregister.com/cyber-crime/2026/08/12/microsoft-vendetta-hacker-has-a-new-zero-day-that-gives-system-privileges-on-fully-patched-windows/5286889" target="_blank"><em>The Register</em></a>, a company spokesperson said Microsoft "is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims."</p><p>"Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible,” the statement reads. “Importantly, we support coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public."</p><h2 id="a-hacker-on-a-mission">A hacker on a mission</h2><p>Together with ShieldBreak, the number of disclosed Windows vulnerabilities and exploits now counts 10. Nightmare Eclipse’s campaign began in April 2026, when they demonstrated BlueHammer, a Windows Defender local privilege-escalation flaw that gives low-privileged users SYSTEM-level access. The researcher claimed BlueHammer, now tracked as CVE-2026-33825, was previously reported to Microsoft, but the company allegedly mishandled the disclosure. </p><p>Just before publishing the work, they <a href="https://arstechnica.com/security/2026/06/locked-in-heated-rivalry-with-researcher-microsoft-fixes-0-day-they-disclosed/" target="_blank" rel="nofollow">said</a> “someone violated our agreement and left me homeless with nothing. They knew this will happen and they still stabbed me in the back anyways, this is their decision not mine.”</p><p>At first, Microsoft took a tough stance, calling the public release “<a href="https://therecord.media/microsoft-says-it-will-not-pursue-security-researchers-disclosure" target="_blank">never justifiable</a>” and even warning that it might pursue legal cases against people who put customers at risk.</p><p>The community interpreted this statement as a threat of legal action against Nightmare Eclipse, which triggered a backlash. Microsoft later backed away, saying “to be clear about our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research.”</p><p>In the meantime, Nightmare Eclipse (also known as Chaotic Eclipse) went on a full-blown rampage. They released RedSun and UnDefend (both targeting Defender), YellowKey (a BitLocker bypass), GreenPlasma (a CTFMON-based privilege-escalation flaw), MiniPlasma (a regression of a vulnerability Microsoft had originally fixed in 2020), RoguePlanet (another Defender privilege-escalation bug), GreatXML (a BitLocker/Windows Recovery Environment bypass), LegacyHive (a Windows User Profile Service privilege-escalation flaw), and now ShieldBreak. </p><p>BlueHammer was fixed in April, RedSun and UnDefend in May, and YellowKey, GreenPlasma, and MiniPlasma, in June. RoguePlanet was patched in July, while LegacyHive, GreatXML, and ShieldBreak, remain unpatched. </p><p>It is also worth mentioning that not all of Nightmare Eclipse’s releases were equally complete or reproducible by third parties. For GreenPlasma, independent researchers said it contained the vulnerability but turning it into a reliable working exploit required significant additional technical work. Some of the early Defender exploits were also apparently difficult to reproduce, mostly because they relied on delicate race conditions and very specific sequences of Windows components. </p><p>ShieldBreak, however, seems to be more dangerous in that respect. Speaking to <em>The Register</em>, security researcher Kevin Beaumont confirmed it as working: “I've tried it, it works on latest Windows 11,” he told the publication. </p><p>He also said that while ShieldBreak was described as a bypass for the RoguePlanet fix, the two flaws actually operated quite differently. </p><p>“RoguePlanet was a filesystem race condition vuln that uses virtual disks and NT native file manipulation to trick quarantine process into overwriting system files,” Beaumont explained. “ShieldBreak user-mode callback hook to change file contents during a Defender cloud-hydration scan via cfapi (Cloud Filter API).”</p><p>No one knows how much ammunition Nightmare Eclipse still has, but we will certainly be paying attention to them in the hours after next month’s Patch Tuesday, as well. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/microsofts-nemesis-returns-nightmare-eclipse-is-back-with-a-new-zero-day-which-could-be-bad-news-for-windows-users</link>
                                                                            <description>
                            <![CDATA[ This is the tenth zero-day the disgruntled researcher disclosed, and yet another released soon after a Patch Tuesday. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Y9Ed8CXdbTCPjPE5PcQuC6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iGi8rqmXBTK3ZPbi4ExzfW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 16:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iGi8rqmXBTK3ZPbi4ExzfW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Är du ute efter bästa VPN för Windows 10 och Windwos 11? Här är våra favoriter just nu.]]></media:description>                                                            <media:text><![CDATA[Fingertip pressing keyboard key with Windows logo on it]]></media:text>
                                <media:title type="plain"><![CDATA[Fingertip pressing keyboard key with Windows logo on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iGi8rqmXBTK3ZPbi4ExzfW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Nightmare Eclipse discloses ShieldBreak, a new Windows privilege‑escalation zero‑day</strong></li><li><strong>Flaw bypasses a recent patch and works on fully updated Windows 11 systems</strong></li><li><strong>Researcher’s ongoing exploit spree leaves multiple Windows vulnerabilities still unpatched</strong></li></ul><p>Nightmare Eclipse has struck again! The notorious zero-day researcher with a Microsoft grudge disclosed its latest vulnerability, and just as in previous instances, they picked their timing and released their research hours after Microsoft published its August Patch Tuesday cumulative update in order to maximize the hurt.</p><p>The newest flaw is called ShieldBreak, and is described as a local escalation of privilege vulnerability that allows threat actors to gain SYSTEM-level privileges on vulnerable systems. Speaking of vulnerable systems, the list is rather long because it includes all versions of Windows 11, including those with the latest security patches. </p><p>“The PoC was tested in the latest version of windows 11 25h2 (+Canary channel) and windows server 2025, the PoC also have a 100% success rate,” Nightmare Eclipse <a href="https://git.projectnightcrawler.dev/NightmareEclipse/ShieldBreak/src/branch/main/ShieldBreak.cpp" target="_blank" rel="nofollow">said</a> on their GitHub account. “Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well.”</p><h2 id="a-bypass-for-the-rogueplanet-fix">A bypass for the RoguePlanet fix</h2><p>The mysterious attacker also said that the bug was actually a bypass for the patch Microsoft issued to fix their earlier work, called RoguePlanet.</p><p>“Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass,” the GitHub read entry.</p><p>Microsoft, on the other hand, responded in pure enterprise fashion, sharing a boilerplate statement that it was “investigating” and that it “supports coordinated <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">vulnerability</a> disclosure”. </p><p>In response to an enquiry by <a href="https://www.theregister.com/cyber-crime/2026/08/12/microsoft-vendetta-hacker-has-a-new-zero-day-that-gives-system-privileges-on-fully-patched-windows/5286889" target="_blank"><em>The Register</em></a>, a company spokesperson said Microsoft "is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims."</p><p>"Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible,” the statement reads. “Importantly, we support coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public."</p><h2 id="a-hacker-on-a-mission">A hacker on a mission</h2><p>Together with ShieldBreak, the number of disclosed Windows vulnerabilities and exploits now counts 10. Nightmare Eclipse’s campaign began in April 2026, when they demonstrated BlueHammer, a Windows Defender local privilege-escalation flaw that gives low-privileged users SYSTEM-level access. The researcher claimed BlueHammer, now tracked as CVE-2026-33825, was previously reported to Microsoft, but the company allegedly mishandled the disclosure. </p><p>Just before publishing the work, they <a href="https://arstechnica.com/security/2026/06/locked-in-heated-rivalry-with-researcher-microsoft-fixes-0-day-they-disclosed/" target="_blank" rel="nofollow">said</a> “someone violated our agreement and left me homeless with nothing. They knew this will happen and they still stabbed me in the back anyways, this is their decision not mine.”</p><p>At first, Microsoft took a tough stance, calling the public release “<a href="https://therecord.media/microsoft-says-it-will-not-pursue-security-researchers-disclosure" target="_blank">never justifiable</a>” and even warning that it might pursue legal cases against people who put customers at risk.</p><p>The community interpreted this statement as a threat of legal action against Nightmare Eclipse, which triggered a backlash. Microsoft later backed away, saying “to be clear about our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research.”</p><p>In the meantime, Nightmare Eclipse (also known as Chaotic Eclipse) went on a full-blown rampage. They released RedSun and UnDefend (both targeting Defender), YellowKey (a BitLocker bypass), GreenPlasma (a CTFMON-based privilege-escalation flaw), MiniPlasma (a regression of a vulnerability Microsoft had originally fixed in 2020), RoguePlanet (another Defender privilege-escalation bug), GreatXML (a BitLocker/Windows Recovery Environment bypass), LegacyHive (a Windows User Profile Service privilege-escalation flaw), and now ShieldBreak. </p><p>BlueHammer was fixed in April, RedSun and UnDefend in May, and YellowKey, GreenPlasma, and MiniPlasma, in June. RoguePlanet was patched in July, while LegacyHive, GreatXML, and ShieldBreak, remain unpatched. </p><p>It is also worth mentioning that not all of Nightmare Eclipse’s releases were equally complete or reproducible by third parties. For GreenPlasma, independent researchers said it contained the vulnerability but turning it into a reliable working exploit required significant additional technical work. Some of the early Defender exploits were also apparently difficult to reproduce, mostly because they relied on delicate race conditions and very specific sequences of Windows components. </p><p>ShieldBreak, however, seems to be more dangerous in that respect. Speaking to <em>The Register</em>, security researcher Kevin Beaumont confirmed it as working: “I've tried it, it works on latest Windows 11,” he told the publication. </p><p>He also said that while ShieldBreak was described as a bypass for the RoguePlanet fix, the two flaws actually operated quite differently. </p><p>“RoguePlanet was a filesystem race condition vuln that uses virtual disks and NT native file manipulation to trick quarantine process into overwriting system files,” Beaumont explained. “ShieldBreak user-mode callback hook to change file contents during a Defender cloud-hydration scan via cfapi (Cloud Filter API).”</p><p>No one knows how much ammunition Nightmare Eclipse still has, but we will certainly be paying attention to them in the hours after next month’s Patch Tuesday, as well. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Android users targeted by new WindRelay malware which can clone contactless cards in just 13 minutes ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>WindRelay campaign used vishing plus custom malware to turn phones into POS skimmers</strong></li><li><strong>Victims installed personalized RATs and NFC malware, enabling real‑time card theft</strong></li><li><strong>Attacks were highly targeted across Eastern Europe, with only a few individuals hit</strong></li></ul><p>Hackers are turning people’s smartphones into malicious <a href="https://www.techradar.com/news/the-best-pos-system" target="_blank">Point of Sale</a> (POS) devices and stealing their money directly from their payment cards, experts have warned. </p><p>Security researchers Group-IB spotted multiple such attacks across Eastern Europe, and named the campaign <a href="https://www.group-ib.com/blog/windrelay-nfc-spynote-rat-combo-fraud/" target="_blank">WindRelay</a>, after the custom-built malware used during the attacks.</p><p>The report notes this is a highly sophisticated, custom-tailored attack designed specifically for the victim. It starts with some form of reconnaissance, in which the attackers learn their victim’s identity, phone number, and likely other details. Although the researchers don’t discuss it, it is quite possible that the attackers obtained (or purchased) the data from unrelated data breaches and leaks.</p><h2 id="vishing-and-malware">Vishing and malware</h2><p>After learning a little bit about their target, the attackers get to work. They first prepare a remote access trojan (RAT) named SpyNote. They personalize the label with the victim’s own name (instead of it being a generic or impersonated brand), to build trust with their victim:</p><p>“Such tactics are more effective at weakening a victim’s natural defenses and suspicions,” the researchers noted in the report. “It removes the one cue people are trained to check before installing something unfamiliar — a strange or generic app name — right at the moment they’re most likely to hesitate.”</p><p>Then, they call the victim on the phone and introduce themselves as employees of their target’s bank. They claim the victim has a problem with their bank card, and instruct them to deploy SpyNote through the device’s package installer (the standard way to sideload apps outside an official app store).</p><p>SpyNote is a classic RAT that the attackers then use to deploy stage-two malware themselves. In this next step, they personally (as opposed to having the victim do it) install WindRelay, custom near-field communication (NFC) malware designed to capture contactless payment card data in real-time, when a card is tapped against the phone. </p><p>In other words, the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> turns the smartphone into a POS, and when a victim taps their card against it, the information is relayed to an attacker’s terminal. </p><h2 id="vishing-malware">Vishing + malware</h2><p>Vishing + malware combo is nothing new. We’ve seen it deployed numerous times before, and ShinyHunters are probably the shiniest example of the practice (pun definitely intended). Over the last couple of years, ShinyHunters have been calling their victims on the phone, impersonating the IT department, and getting their victims to log in via fake login portals which relay the credentials to the attackers.</p><p>They then use the credentials to access their victims’ SaaS products, exfiltrate as much sensitive data as possible, and then demand ransom in exchange for deleting the stolen files.</p><p>This new campaign, however, is a testament to the technique’s evolution. While ShinyHunters’ operatives only stay on the phone call until the victim logs in, these crooks remain on the line for as long as it takes. Group-IB says the average call lasts around 13 minutes, and by that moment, the victim will have installed both SpyNote and WindRelay, and has tapped their bank card against the phone, making unwanted payments.</p><p>In at least one case, the attackers successfully applied for a loan at the victim’s bank, stealing not only the money they had on their account, but also money they would have earned in the future.</p><p>The identity of the attackers is unknown at the time. We also don’t know exactly how many victims there were, but given the highly personalized nature of the attack, it’s safe to assume that there were only a handful.</p><p>Group-IB says it observed attacks in Czechia, Slovakia, and Slovenia, suggesting a threat actor focused primarily on Eastern European victims. The researchers also said they identified 23 samples uploaded to VirusTotal between November 2025 and July 2026, meaning the campaign was active for approximately seven months, targeting 23 individuals. </p><p>“The samples mimic various institutions from the targeted countries and contain text in the language of each targeted country,” the researchers said. “Some samples contain personalized UI elements and labels, such as the name of the victim, similar to the personalized RAT. This suggests the threat actor behind these campaigns most likely has the capability to dynamically build malicious applications tailored to individual victims.”</p><p>Group-IB says users should treat personalized app labels as a red flag and should apply extra friction to loan applications. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/android-users-targeted-by-new-windrelay-malware-which-can-clone-contactless-cards-in-just-13-minutes</link>
                                                                            <description>
                            <![CDATA[ Crooks are calling victims on the phone and installing POS malware on their smartphones. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">shwHxntyNEjscciJEjL9Li</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5kMrDAjQJGcdHytVASFjn5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 15:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5kMrDAjQJGcdHytVASFjn5-1280-80.jpg">
                                                            <media:credit><![CDATA[Rapeepong Puttakumwong via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Person pays using POS hardware card reader]]></media:description>                                                            <media:text><![CDATA[Person pays using POS hardware card reader]]></media:text>
                                <media:title type="plain"><![CDATA[Person pays using POS hardware card reader]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5kMrDAjQJGcdHytVASFjn5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>WindRelay campaign used vishing plus custom malware to turn phones into POS skimmers</strong></li><li><strong>Victims installed personalized RATs and NFC malware, enabling real‑time card theft</strong></li><li><strong>Attacks were highly targeted across Eastern Europe, with only a few individuals hit</strong></li></ul><p>Hackers are turning people’s smartphones into malicious <a href="https://www.techradar.com/news/the-best-pos-system" target="_blank">Point of Sale</a> (POS) devices and stealing their money directly from their payment cards, experts have warned. </p><p>Security researchers Group-IB spotted multiple such attacks across Eastern Europe, and named the campaign <a href="https://www.group-ib.com/blog/windrelay-nfc-spynote-rat-combo-fraud/" target="_blank">WindRelay</a>, after the custom-built malware used during the attacks.</p><p>The report notes this is a highly sophisticated, custom-tailored attack designed specifically for the victim. It starts with some form of reconnaissance, in which the attackers learn their victim’s identity, phone number, and likely other details. Although the researchers don’t discuss it, it is quite possible that the attackers obtained (or purchased) the data from unrelated data breaches and leaks.</p><h2 id="vishing-and-malware">Vishing and malware</h2><p>After learning a little bit about their target, the attackers get to work. They first prepare a remote access trojan (RAT) named SpyNote. They personalize the label with the victim’s own name (instead of it being a generic or impersonated brand), to build trust with their victim:</p><p>“Such tactics are more effective at weakening a victim’s natural defenses and suspicions,” the researchers noted in the report. “It removes the one cue people are trained to check before installing something unfamiliar — a strange or generic app name — right at the moment they’re most likely to hesitate.”</p><p>Then, they call the victim on the phone and introduce themselves as employees of their target’s bank. They claim the victim has a problem with their bank card, and instruct them to deploy SpyNote through the device’s package installer (the standard way to sideload apps outside an official app store).</p><p>SpyNote is a classic RAT that the attackers then use to deploy stage-two malware themselves. In this next step, they personally (as opposed to having the victim do it) install WindRelay, custom near-field communication (NFC) malware designed to capture contactless payment card data in real-time, when a card is tapped against the phone. </p><p>In other words, the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> turns the smartphone into a POS, and when a victim taps their card against it, the information is relayed to an attacker’s terminal. </p><h2 id="vishing-malware">Vishing + malware</h2><p>Vishing + malware combo is nothing new. We’ve seen it deployed numerous times before, and ShinyHunters are probably the shiniest example of the practice (pun definitely intended). Over the last couple of years, ShinyHunters have been calling their victims on the phone, impersonating the IT department, and getting their victims to log in via fake login portals which relay the credentials to the attackers.</p><p>They then use the credentials to access their victims’ SaaS products, exfiltrate as much sensitive data as possible, and then demand ransom in exchange for deleting the stolen files.</p><p>This new campaign, however, is a testament to the technique’s evolution. While ShinyHunters’ operatives only stay on the phone call until the victim logs in, these crooks remain on the line for as long as it takes. Group-IB says the average call lasts around 13 minutes, and by that moment, the victim will have installed both SpyNote and WindRelay, and has tapped their bank card against the phone, making unwanted payments.</p><p>In at least one case, the attackers successfully applied for a loan at the victim’s bank, stealing not only the money they had on their account, but also money they would have earned in the future.</p><p>The identity of the attackers is unknown at the time. We also don’t know exactly how many victims there were, but given the highly personalized nature of the attack, it’s safe to assume that there were only a handful.</p><p>Group-IB says it observed attacks in Czechia, Slovakia, and Slovenia, suggesting a threat actor focused primarily on Eastern European victims. The researchers also said they identified 23 samples uploaded to VirusTotal between November 2025 and July 2026, meaning the campaign was active for approximately seven months, targeting 23 individuals. </p><p>“The samples mimic various institutions from the targeted countries and contain text in the language of each targeted country,” the researchers said. “Some samples contain personalized UI elements and labels, such as the name of the victim, similar to the personalized RAT. This suggests the threat actor behind these campaigns most likely has the capability to dynamically build malicious applications tailored to individual victims.”</p><p>Group-IB says users should treat personalized app labels as a red flag and should apply extra friction to loan applications. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Trump signs memo calling for cyber privateers to conduct cyberattacks abroad against criminal groups targeting Americans — but they have to escrow $1 million to join ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>US government to allow private firms to conduct legal cyberattacks on foreign organizations targeting Americans</strong></li><li><strong>Firms will be allowed to disrupt and destroy physical and virtual information systems and networks</strong></li><li><strong>US victims of cyber scams and fraud lose around $20,000</strong></li></ul><p>President Trump has signed a <a href="https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/" target="_blank" rel="nofollow">memo</a> which allows private US firms to partner with the US government in operations designed to surveille and disrupt Transnational Criminal Organizations (TCOs).</p><p>According to the memo, the partnership “will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens,” essentially turning private companies into privateers with the ability to launch cyber attacks against foreign entities.</p><p>The memo marks a significant shift in how the US tackles foreign cybercrime. “American businesses’ innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace,” the memo states. But what does this actually mean in practice?</p><h2 id="us-to-leverage-private-sector-for-cyber-defense">US to leverage private sector for cyber defense</h2><p>The US is the most targeted country in the world for cyber attacks and cybercrime, with <a href="https://www.techradar.com/pro/security/cybercrime-is-costing-the-world-trillions-every-year-new-report-says-victims-lose-an-average-of-nearly-usd10-000-in-every-hit">6.7 million victims losing $138.9 billion in the last year</a>, placing the average loss per-victim at around $20,731.</p><p>The program will effectively create a global cyber surveillance network that acts as an early warning system against attacks targeting critical national infrastructure, such as the recent <a href="https://www.techradar.com/pro/security/hackers-are-going-after-our-water-now-over-30-minnesota-utilities-hit-in-coordinated-cyberattack-by-apparent-iranian-attackers">Iranian attacks targeting over 30 US water systems</a>. Private companies that “discover an imminent cyber-attack against United States critical infrastructure” will be required to notify the National Coordination Center (NCC).</p><p>The US government isn’t just looking to work alongside the big tech companies. Big companies will be part of the picture to “provide critical capacity,” but smaller companies will also have the opportunity to become involved with the program as they are “more agile,” and “may be better suited for specialized or discrete tasks.”</p><p>When a threat is detected, private companies will put together a “cyber operations package” to be reviewed and approved by the Program Executive Directors. These packages will likely include plans for surveillance and offensive cyber operations.</p><p>Private companies looking to become part of the program will be vetted according to government guidelines, and will have to operate within a set of operating procedures under the oversight of the federal government. “No operation may be approved unless it complies with these operating procedures,” the memo says.</p><p>There is however a caveat that those involved within the program must “maintain a bond or escrow in an amount not less than $1 million,” which would be forfeit should a private company “enter non‑compliance with its contractual agreement.”</p><p>The memo also sets our parameters to prevent private companies from accidentally or intentionally targeting US citizens, or US information systems at home and abroad, with the company required to “cease such operation, conduct minimization procedures, and immediately notify the NCC,” in the event that a company “discovers operational activity exceeding the parameters and restrictions of the cyber operation”.</p><p>Additionally, “any activity authorized by the Program must be conducted subject to the oversight, operational control, and legal authorities of the United States Government”.</p><p>The memo is the latest step in the Trump administration’s efforts to allow private companies to legally launch cyberattacks on behalf of the US government. “The American private sector is the most innovative and technologically advanced in the world, and its scale, speed, and capacity secure a critical offensive cyber advantage for the United States,” the memo states.</p><p>The program will also put together a report on its progress every year, as well as reviewing the performance of each private company within the program within the same time frame.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/trump-signs-memo-calling-for-cyber-privateers-to-conduct-cyberattacks-abroad-against-criminal-groups-targeting-americans-but-they-have-to-escrow-usd1-million-to-join</link>
                                                                            <description>
                            <![CDATA[ Private companies will be legally allowed to conduct cyberattacks against foreign groups on behalf of the US government. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">utyNFb8pS4FFJvAbLae83g</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zTH6vPrB4yxX7dzdy29Xga-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 12:05:00 +0000</pubDate>                                                                                                                                <updated>Thu, 13 Aug 2026 12:52:56 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zTH6vPrB4yxX7dzdy29Xga-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An image of a digitized skull and crossbones symbolizing hacking and cyberattacks overlayed on a background of digital glitches and noise.]]></media:description>                                                            <media:text><![CDATA[An image of a digitized skull and crossbones symbolizing hacking and cyberattacks overlayed on a background of digital glitches and noise.]]></media:text>
                                <media:title type="plain"><![CDATA[An image of a digitized skull and crossbones symbolizing hacking and cyberattacks overlayed on a background of digital glitches and noise.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zTH6vPrB4yxX7dzdy29Xga-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>US government to allow private firms to conduct legal cyberattacks on foreign organizations targeting Americans</strong></li><li><strong>Firms will be allowed to disrupt and destroy physical and virtual information systems and networks</strong></li><li><strong>US victims of cyber scams and fraud lose around $20,000</strong></li></ul><p>President Trump has signed a <a href="https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/" target="_blank" rel="nofollow">memo</a> which allows private US firms to partner with the US government in operations designed to surveille and disrupt Transnational Criminal Organizations (TCOs).</p><p>According to the memo, the partnership “will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens,” essentially turning private companies into privateers with the ability to launch cyber attacks against foreign entities.</p><p>The memo marks a significant shift in how the US tackles foreign cybercrime. “American businesses’ innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace,” the memo states. But what does this actually mean in practice?</p><h2 id="us-to-leverage-private-sector-for-cyber-defense">US to leverage private sector for cyber defense</h2><p>The US is the most targeted country in the world for cyber attacks and cybercrime, with <a href="https://www.techradar.com/pro/security/cybercrime-is-costing-the-world-trillions-every-year-new-report-says-victims-lose-an-average-of-nearly-usd10-000-in-every-hit">6.7 million victims losing $138.9 billion in the last year</a>, placing the average loss per-victim at around $20,731.</p><p>The program will effectively create a global cyber surveillance network that acts as an early warning system against attacks targeting critical national infrastructure, such as the recent <a href="https://www.techradar.com/pro/security/hackers-are-going-after-our-water-now-over-30-minnesota-utilities-hit-in-coordinated-cyberattack-by-apparent-iranian-attackers">Iranian attacks targeting over 30 US water systems</a>. Private companies that “discover an imminent cyber-attack against United States critical infrastructure” will be required to notify the National Coordination Center (NCC).</p><p>The US government isn’t just looking to work alongside the big tech companies. Big companies will be part of the picture to “provide critical capacity,” but smaller companies will also have the opportunity to become involved with the program as they are “more agile,” and “may be better suited for specialized or discrete tasks.”</p><p>When a threat is detected, private companies will put together a “cyber operations package” to be reviewed and approved by the Program Executive Directors. These packages will likely include plans for surveillance and offensive cyber operations.</p><p>Private companies looking to become part of the program will be vetted according to government guidelines, and will have to operate within a set of operating procedures under the oversight of the federal government. “No operation may be approved unless it complies with these operating procedures,” the memo says.</p><p>There is however a caveat that those involved within the program must “maintain a bond or escrow in an amount not less than $1 million,” which would be forfeit should a private company “enter non‑compliance with its contractual agreement.”</p><p>The memo also sets our parameters to prevent private companies from accidentally or intentionally targeting US citizens, or US information systems at home and abroad, with the company required to “cease such operation, conduct minimization procedures, and immediately notify the NCC,” in the event that a company “discovers operational activity exceeding the parameters and restrictions of the cyber operation”.</p><p>Additionally, “any activity authorized by the Program must be conducted subject to the oversight, operational control, and legal authorities of the United States Government”.</p><p>The memo is the latest step in the Trump administration’s efforts to allow private companies to legally launch cyberattacks on behalf of the US government. “The American private sector is the most innovative and technologically advanced in the world, and its scale, speed, and capacity secure a critical offensive cyber advantage for the United States,” the memo states.</p><p>The program will also put together a report on its progress every year, as well as reviewing the performance of each private company within the program within the same time frame.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This North Korean recruitment scam was so convincing it even fooled Google ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Lazarus expanded Dream Job with a zero‑day, new backdoor, and advanced relays</strong></li><li><strong>Fake job lures, trojanized PDFs, and spoofed sites enabled high‑level compromises</strong></li><li><strong>Targets included defense and aerospace firms, prompting stronger phishing awareness</strong></li></ul><p>Security experts from <a href="https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/" target="_blank">Check Point Research</a> say they have uncovered a new wave of "Operation Dream Job" attacks, leveraging a previously undocumented backdoor, a brand new Windows zero-day vulnerability, and a never-before-seen webshell/relay.</p><p>Lazarus Group is a hacking collective on the payroll of the North Korean government. It is a state-sponsored threat actor known for targeting cryptocurrency developers and other professionals in the Web3 industry, stealing their tokens and using the money to fund the country’s weapons program and the wider state apparatus.</p><p>It is also known for running Operation Dream Job - a hacking campaign that’s been going on for years, and that lures victims with highly lucrative but bogus job opportunities.</p><h2 id="what-is-operation-dream-job">What is Operation Dream Job?</h2><p>The scam works like this: the attackers come up with a fake company, often in the software development, defense, aerospace, or military industries. </p><p>They create the fake company’s website, LinkedIn account, as well as fake people supposedly employed there. Then, they reach out to their targets, offering great working conditions, amazing salaries, and an opportunity to work on exciting projects.</p><p>Victims that take the bait are then led through a series of “interviews” and somewhere along the line, they are either given weaponized PDF files or asked to download and run executables and other code, as part of a “training exercise” or “skill evaluation”. At this moment, the victims get compromised, while the attackers gain access to their actual employers’ infrastructure.</p><p>From there, the ending can be relatively different. Lazarus has, on at least one occasion, stolen <a href="https://www.techradar.com/pro/security/fbi-says-north-korean-lazarus-hackers-were-behind-usd1-5-billion-bybit-crypto-hack" target="_blank">more than a billion dollars</a> in cryptocurrency from one of its victims.</p><h2 id="ante-up">Ante up</h2><p>Perhaps the biggest finding is that Lazarus even managed to fool Google - fake Lockheed Martin and Enveil job postings all made it through filters, while spoofed, malicious websites were showing at the top of search results.</p><p>Then, there is the new Windows vulnerability the group has been exploiting. A zero-day, now tracked as CVE-2026-68820, is described as a “use-after-free bug in Windows Ancillary Function Driver for WinSock”, allowing authorized attackers to elevate privileges locally.</p><p>This bug was found in a core Windows networking component and allows an attacker who already deployed a piece of malware on the machine to escalate privileges to the highest level. Microsoft patched it on August 11 2026. </p><p>Lazarus used this bug to deploy a previously undocumented backdoor called Troy. This <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> comes with 17 commands, including file upload and download, interactive shell access, in-memory DLL injection, and process termination.</p><p>The group was also using compromised Roundcube webmail and CMS servers as C2 relays, instead of simply running their own infrastructure, and they were deploying a new PHP webshell called RelayShell. This one doesn’t behave like a conventional backdoor, since it passes commands and responses between victims and operators through text files. </p><p>In one of the observed infection chains, Check Point also found the crooks using SecurityPDF, a trojanized <a href="https://www.techradar.com/best/best-pdf-readers-for-windows" target="_blank">PDF viewer</a> which they were hosting on websites impersonating a legitimate business called Enveil. The drake viewer scans PDF files for a particular hidden marker and, if it finds it, decrypts it and loads Troy directly into memory. </p><p>Lazarus usually targets cryptocurrency and software developers. This time around, however, it set its sights on defense organizations, aerospace companies, as well as those working in aviation. Most of the victims are located in Europe and India, with confirmed activity in France, Germany, Brazil and India.</p><p>Check Point also said that not all victims were also targets - some of the organizations compromised in the attacks were later used as infrastructure. In at least one case, Lazarus compromised a Western European organization and used it to send spear-phishing messages to additional victims, effectively exploiting that organization’s reputation and trusted communications. </p><p>Since these attacks primarily start with a social engineering element, the best course of action is to educate employees on the dangers of phishing and the fact that, if someone is reaching out with a job offer too good to be true - it most likely is.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/this-north-korean-recruitment-scam-was-so-convincing-it-even-fooled-google</link>
                                                                            <description>
                            <![CDATA[ Fake sites were popping up at the top of search engine results pages and used to convince victims to download a trojanized PDF viewer. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BcxcZYRcAHfQvhcvJWD8HM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Aug 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[North Korean flag with a hooded hacker]]></media:description>                                                            <media:text><![CDATA[North Korean flag with a hooded hacker]]></media:text>
                                <media:title type="plain"><![CDATA[North Korean flag with a hooded hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Lazarus expanded Dream Job with a zero‑day, new backdoor, and advanced relays</strong></li><li><strong>Fake job lures, trojanized PDFs, and spoofed sites enabled high‑level compromises</strong></li><li><strong>Targets included defense and aerospace firms, prompting stronger phishing awareness</strong></li></ul><p>Security experts from <a href="https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/" target="_blank">Check Point Research</a> say they have uncovered a new wave of "Operation Dream Job" attacks, leveraging a previously undocumented backdoor, a brand new Windows zero-day vulnerability, and a never-before-seen webshell/relay.</p><p>Lazarus Group is a hacking collective on the payroll of the North Korean government. It is a state-sponsored threat actor known for targeting cryptocurrency developers and other professionals in the Web3 industry, stealing their tokens and using the money to fund the country’s weapons program and the wider state apparatus.</p><p>It is also known for running Operation Dream Job - a hacking campaign that’s been going on for years, and that lures victims with highly lucrative but bogus job opportunities.</p><h2 id="what-is-operation-dream-job">What is Operation Dream Job?</h2><p>The scam works like this: the attackers come up with a fake company, often in the software development, defense, aerospace, or military industries. </p><p>They create the fake company’s website, LinkedIn account, as well as fake people supposedly employed there. Then, they reach out to their targets, offering great working conditions, amazing salaries, and an opportunity to work on exciting projects.</p><p>Victims that take the bait are then led through a series of “interviews” and somewhere along the line, they are either given weaponized PDF files or asked to download and run executables and other code, as part of a “training exercise” or “skill evaluation”. At this moment, the victims get compromised, while the attackers gain access to their actual employers’ infrastructure.</p><p>From there, the ending can be relatively different. Lazarus has, on at least one occasion, stolen <a href="https://www.techradar.com/pro/security/fbi-says-north-korean-lazarus-hackers-were-behind-usd1-5-billion-bybit-crypto-hack" target="_blank">more than a billion dollars</a> in cryptocurrency from one of its victims.</p><h2 id="ante-up">Ante up</h2><p>Perhaps the biggest finding is that Lazarus even managed to fool Google - fake Lockheed Martin and Enveil job postings all made it through filters, while spoofed, malicious websites were showing at the top of search results.</p><p>Then, there is the new Windows vulnerability the group has been exploiting. A zero-day, now tracked as CVE-2026-68820, is described as a “use-after-free bug in Windows Ancillary Function Driver for WinSock”, allowing authorized attackers to elevate privileges locally.</p><p>This bug was found in a core Windows networking component and allows an attacker who already deployed a piece of malware on the machine to escalate privileges to the highest level. Microsoft patched it on August 11 2026. </p><p>Lazarus used this bug to deploy a previously undocumented backdoor called Troy. This <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> comes with 17 commands, including file upload and download, interactive shell access, in-memory DLL injection, and process termination.</p><p>The group was also using compromised Roundcube webmail and CMS servers as C2 relays, instead of simply running their own infrastructure, and they were deploying a new PHP webshell called RelayShell. This one doesn’t behave like a conventional backdoor, since it passes commands and responses between victims and operators through text files. </p><p>In one of the observed infection chains, Check Point also found the crooks using SecurityPDF, a trojanized <a href="https://www.techradar.com/best/best-pdf-readers-for-windows" target="_blank">PDF viewer</a> which they were hosting on websites impersonating a legitimate business called Enveil. The drake viewer scans PDF files for a particular hidden marker and, if it finds it, decrypts it and loads Troy directly into memory. </p><p>Lazarus usually targets cryptocurrency and software developers. This time around, however, it set its sights on defense organizations, aerospace companies, as well as those working in aviation. Most of the victims are located in Europe and India, with confirmed activity in France, Germany, Brazil and India.</p><p>Check Point also said that not all victims were also targets - some of the organizations compromised in the attacks were later used as infrastructure. In at least one case, Lazarus compromised a Western European organization and used it to send spear-phishing messages to additional victims, effectively exploiting that organization’s reputation and trusted communications. </p><p>Since these attacks primarily start with a social engineering element, the best course of action is to educate employees on the dangers of phishing and the fact that, if someone is reaching out with a job offer too good to be true - it most likely is.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google says Chrome blocked seven billion malicious Android notifications every day in its bid to cut down on scams ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Google cut seven billion daily Android Chrome notifications using layered defenses</strong></li><li><strong>Chrome now limits abusive sites, revokes permissions, and blocks high‑volume spam</strong></li><li><strong>Android improvements simplify managing alerts and reduce scam and malware exposure</strong></li></ul><p>Google says it has cut the number of notifications Chrome users get on their Android devices by seven billion a day. </p><p>In a new <a href="https://blog.google/security/the-multi-layered-defenses-that-harden-chrome-against-abusive-notifications/" target="_blank" rel="nofollow">report</a>, the company outlined how it has built a multi-layered defense system to shield its users from unwanted notifications, protecting them from spam and malware, and helping their devices’ battery last longer. </p><p>Most importantly, Google says the achievement significantly improved the overall user experience on Android. </p><h2 id="notification-bombardment">Notification bombardment</h2><p>For the longest time, individual websites were allowed to send push notifications directly to their users’ phones, even when they were not actively browsing them. </p><p>When a user visits a certain website, they get prompted to “show notifications”, and if they tap “allow”, the website starts sending the alerts. Sometimes, users do it without fully realizing what they’re agreeing to.</p><p>Once granted, the notifications (sent through Chrome) get shown next to other alerts (such as the ones coming from WhatsApp, Gmail, or other apps). </p><p>Unlike other notifications - which usually alert users to unread messages, calendar events, or similar - these mostly promote new content, deals, or other updates. They can also alert users of breaking news, which is arguably the most useful type among the ones mentioned here. </p><p>Legitimate websites use the feature responsibly and generally don’t flood their users with unwanted pings. However, some sites abuse the privilege, bombarding users with unwanted advertising, misleading alerts, clickbait articles, and other formats, just to get them to open the page (where they’re often served ads). More worryingly, malicious or compromised websites can use notifications to push scam messages, fake virus warnings, phishing links or other potentially dangerous content. </p><p>Because these alerts are served through Chrome and resemble ordinary system notifications, users may not immediately realize the risk. </p><p>But because they are served through Chrome, Google can do something about it, and the company has now “pulled back the curtain” on the toolkit that made these improvements possible.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:800px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="M8dLsateSbGVwYwoPrRba3" name="mobile security.jpg" alt="Mobile Security" src="https://cdn.mos.cms.futurecdn.net/M8dLsateSbGVwYwoPrRba3.jpg" mos="" align="middle" fullscreen="" width="800" height="450" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock.com)</span></figcaption></figure><h2 id="swiss-cheese">Swiss cheese</h2><p>Described as a “swiss cheese” model, Google says it created overlapping protections that cover the entire notification lifecycle. Chrome now automatically revokes notification permissions for sites users haven’t engaged with in a little while. </p><p>So, if a site keeps flooding the visitor with notifications that they’re not responding to, Chrome will eventually shut them off. Same goes for sites that have “repeatedly received suspicious notification warnings”. Google did not say how many is considered “repeatedly” and in what timeframe.</p><p>The second layer is analyzing signals such as service worker activity. By looking for coordinated behaviors, Google claims it can now pinpoint networks that serve malicious content, and block them. </p><p>On the Firebase Cloud Messaging (FCM) server side, the company introduced message rate limits that disallow high-volume notification abuse. Google now evaluates sites based on factors such as message volume relative to time spent on site, the frequency of permission prompts, and general engagement levels.</p><p>In other words, if a user spends 10 minutes on a website but then receives 50 notifications, it will raise quite a few red flags. Same goes for users that don’t really interact with the website a lot. “Disruptive domains” are now limited to 1,000 messages per minute and will receive HTTP 429 responses if they exceed this threshold, Google explained.</p><p>Finally, the company updated how notifications are handled on Android phones. Users can update their preferences directly from the notification bar, simplifying the process for users who can’t be bothered to dig deep into system settings. </p><p>“These integrated efforts effectively shield users from sophisticated scams that leverage notifications to distribute malware, harvest personal information, or solicit fraudulent payments,” Google said. </p><p>“Beyond security enhancements, this strategy has substantially decreased unnecessary background activity, reduced user device battery consumption, and transformed the notification lifecycle so users receive only the content they find truly valuable.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/google-says-chrome-blocked-seven-billion-malicious-android-notifications-every-day-in-its-bid-to-cut-down-on-scams</link>
                                                                            <description>
                            <![CDATA[ A "Swiss cheese" approach to defense seems to be working, as the number of unwanted notifications dwindles. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">DYTMghKLR3LUcJNVnvbzV4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/o9BDDKXmm9T4Lqtm38fsmV-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Aug 2026 14:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/o9BDDKXmm9T4Lqtm38fsmV-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Annoyed man with phone]]></media:description>                                                            <media:text><![CDATA[Annoyed man with phone]]></media:text>
                                <media:title type="plain"><![CDATA[Annoyed man with phone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/o9BDDKXmm9T4Lqtm38fsmV-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Google cut seven billion daily Android Chrome notifications using layered defenses</strong></li><li><strong>Chrome now limits abusive sites, revokes permissions, and blocks high‑volume spam</strong></li><li><strong>Android improvements simplify managing alerts and reduce scam and malware exposure</strong></li></ul><p>Google says it has cut the number of notifications Chrome users get on their Android devices by seven billion a day. </p><p>In a new <a href="https://blog.google/security/the-multi-layered-defenses-that-harden-chrome-against-abusive-notifications/" target="_blank" rel="nofollow">report</a>, the company outlined how it has built a multi-layered defense system to shield its users from unwanted notifications, protecting them from spam and malware, and helping their devices’ battery last longer. </p><p>Most importantly, Google says the achievement significantly improved the overall user experience on Android. </p><h2 id="notification-bombardment">Notification bombardment</h2><p>For the longest time, individual websites were allowed to send push notifications directly to their users’ phones, even when they were not actively browsing them. </p><p>When a user visits a certain website, they get prompted to “show notifications”, and if they tap “allow”, the website starts sending the alerts. Sometimes, users do it without fully realizing what they’re agreeing to.</p><p>Once granted, the notifications (sent through Chrome) get shown next to other alerts (such as the ones coming from WhatsApp, Gmail, or other apps). </p><p>Unlike other notifications - which usually alert users to unread messages, calendar events, or similar - these mostly promote new content, deals, or other updates. They can also alert users of breaking news, which is arguably the most useful type among the ones mentioned here. </p><p>Legitimate websites use the feature responsibly and generally don’t flood their users with unwanted pings. However, some sites abuse the privilege, bombarding users with unwanted advertising, misleading alerts, clickbait articles, and other formats, just to get them to open the page (where they’re often served ads). More worryingly, malicious or compromised websites can use notifications to push scam messages, fake virus warnings, phishing links or other potentially dangerous content. </p><p>Because these alerts are served through Chrome and resemble ordinary system notifications, users may not immediately realize the risk. </p><p>But because they are served through Chrome, Google can do something about it, and the company has now “pulled back the curtain” on the toolkit that made these improvements possible.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:800px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="M8dLsateSbGVwYwoPrRba3" name="mobile security.jpg" alt="Mobile Security" src="https://cdn.mos.cms.futurecdn.net/M8dLsateSbGVwYwoPrRba3.jpg" mos="" align="middle" fullscreen="" width="800" height="450" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock.com)</span></figcaption></figure><h2 id="swiss-cheese">Swiss cheese</h2><p>Described as a “swiss cheese” model, Google says it created overlapping protections that cover the entire notification lifecycle. Chrome now automatically revokes notification permissions for sites users haven’t engaged with in a little while. </p><p>So, if a site keeps flooding the visitor with notifications that they’re not responding to, Chrome will eventually shut them off. Same goes for sites that have “repeatedly received suspicious notification warnings”. Google did not say how many is considered “repeatedly” and in what timeframe.</p><p>The second layer is analyzing signals such as service worker activity. By looking for coordinated behaviors, Google claims it can now pinpoint networks that serve malicious content, and block them. </p><p>On the Firebase Cloud Messaging (FCM) server side, the company introduced message rate limits that disallow high-volume notification abuse. Google now evaluates sites based on factors such as message volume relative to time spent on site, the frequency of permission prompts, and general engagement levels.</p><p>In other words, if a user spends 10 minutes on a website but then receives 50 notifications, it will raise quite a few red flags. Same goes for users that don’t really interact with the website a lot. “Disruptive domains” are now limited to 1,000 messages per minute and will receive HTTP 429 responses if they exceed this threshold, Google explained.</p><p>Finally, the company updated how notifications are handled on Android phones. Users can update their preferences directly from the notification bar, simplifying the process for users who can’t be bothered to dig deep into system settings. </p><p>“These integrated efforts effectively shield users from sophisticated scams that leverage notifications to distribute malware, harvest personal information, or solicit fraudulent payments,” Google said. </p><p>“Beyond security enhancements, this strategy has substantially decreased unnecessary background activity, reduced user device battery consumption, and transformed the notification lifecycle so users receive only the content they find truly valuable.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A dangerous Zoom screen-sharing bug could have let hackers hijack other devices on a call ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>AI‑found Zoom flaws enabled device takeover through malicious annotation messages</strong></li><li><strong>Exploits worked across all platforms and required only joining a video call</strong></li><li><strong>Researchers warn AI now enables rapid, nation‑state‑level exploit development</strong></li></ul><p>Experts have warned that Zoom, one of the most popular collaboration tools in the world, carried multiple vulnerabilities that allowed malicious actors to take over people’s devices, entirely. </p><p>What makes these vulnerabilities particularly dangerous is that the victims need not do much to be compromised - participating in a video call with the attacker is enough.</p><p>The bugs were said to be present in every version of Zoom, on every device and operating system - Windows, Mac, iPhone, Android, and Linux, in all versions up to and including 7.0.5 - with patches available now, so be sure to update immediately.</p><h2 id="ai-powered-security">AI-powered security</h2><p>The flaws were <a href="https://a.security/blog/asecurity-zoomsday" target="_blank" rel="nofollow">discovered</a> by security researchers A Security, which focuses on “autonomous offensive security”, using AI agents to simulate real-work attacks, identify vulnerabilities, and chain them into exploitable attack paths. </p><p>The company “simply” used publicly available frontier models and within 24 hours and fewer than 20 prompts, went from finding the flaws to building a working exploit. </p><p>The flaws are described as memory corruption bugs exploiting Zoom’s annotation feature. That feature, built on a proprietary protocol (meaning it has no public documentation or specifications, as opposed to being open source), meant that the Zoom client parsed everything it received, including specially crafted, malicious messages.</p><p>During the call, a malicious actor could send a message to each visitor that would corrupt their device’s memory and execute weaponized code, all without the victim knowing, being prompted to do anything, or clicking anything at all. </p><p>The vulnerability can be exploited regardless of if the attacker hosted, or simply joined, a call. All participants, regardless of their status in the call, were equally at risk. There were no visual cues indicating the compromise whatsoever. </p><p>Once the threat actor runs the malware on the victim’s device, they can do all sorts of things, from stealing sensitive files, to switching on the device’s camera or microphone. They can also deploy stage-two malware, steal login credentials and crypto wallet information, access the inbox, and more. </p><p>A Security responsibly disclosed their findings to Zoom, who labeled the vulnerabilities as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, and all given a severity score of 9.0/10 (critical). </p><p>Furthermore, all Zoom Workplace clients on all supported platforms before version 7.1.5 and 7.0.6 using end-to-end encryption settings are considered vulnerable. A Security recommends updating the client to the latest version. </p><h2 id="lowering-the-barrier">Lowering the barrier</h2><p>In its writeup, A Security stressed the simplicity and ease with which it managed to find the bugs and develop the exploits. It warned that AI has dramatically lowered the barrier for entry, and argued that in the pre-AI era, exploits like these were “reserved” for nation-state threat actors with virtually limitless resources:</p><p>“This class of capability would previously have only been available to nation-state threat actors, but the model requiring elite teams, months of effort, and weapons-grade budgets has collapsed,” the researchers warned. “Today, a single researcher was able to develop a nation-state-level exploit in less than a day.”</p><p>To add insult to injury, these flaws were found using “publicly available frontier models” such as GPT-5.6 Sol, Claude Opus 5, and the likes. Besides the frontier models, these companies also have dedicated cybersecurity programs where they offer specialized models with fewer guardrails and more flexibility for both offensive and defensive actions. </p><p>Earlier this week, OpenAI said that its Daybreak project now offers GPT-5.6-Cyber, a model built on GPT‑5.6 Sol and trained to improve capabilities on several specialized cybersecurity tasks such as finding zero-day vulnerabilities and developing exploit chains.</p><p>Daybreak came as a direct response to Anthropic’s Project Glasswing. This is an offering that came with Mythos Preview, an AI model that proved unusually capable at cybersecurity tasks. Allegedly, Mythos can autonomously identify and exploit zero-day flaws across major operating systems and browsers, as well as develop complex exploit chains. Because of those capabilities, Anthropic did not release Mythos Preview broadly. Instead, it made the model available to a limited group of organizations.</p><p>While some expressed their skepticism over Mythos, saying Anthropic is engaging in <a href="https://techcrunch.com/2026/04/21/sam-altman-throws-shade-at-anthropics-cyber-model-mythos-fear-based-marketing/" target="_blank"><u>fear-based marketing</u></a>, others have backed the company, saying Mythos proved exceptionally useful at identifying and fixing flaws. Microsoft, for example, is one of the original Project Glasswing partners, and ever since it started using it, the number of flaws patched through its Patch Tuesday cumulative update <a href="https://www.techradar.com/pro/security/microsoft-just-released-its-biggest-patch-tuesday-ever-with-a-mammoth-622-fixes-including-three-dangerous-zero-days" target="_blank"><u>quadrupled</u></a>.</p><p>Mozilla is also among those showering Mythos with praise, saying earlier this year that it is “<a href="https://www.techradar.com/pro/mozilla-says-anthropics-mythos-is-every-bit-as-capable-as-the-worlds-best-security-researchers-after-firefox-experiment-and-says-the-zero-days-are-numbered" target="_blank"><u>every bit as capable</u></a>” as the world’s best security researchers.</p><p>If A Security managed to find such dangerous flaws with publicly available models, there’s no telling what these dedicated models can do.</p><p><em>Via </em><a href="https://thehackernews.com/2026/08/zoom-annotation-flaws-could-let-meeting.html" target="_blank"><em>The Hacker News</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/a-dangerous-zoom-screen-sharing-bug-could-have-let-hackers-hijack-other-devices-on-a-call</link>
                                                                            <description>
                            <![CDATA[ It doesn't matter if the attacker is the host or a participant. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">V4iS9gg8ADwLuvqhJmnGxH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/q7LJWDP3HaKLzyUesaBUh7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Aug 2026 12:56:03 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/q7LJWDP3HaKLzyUesaBUh7-1280-80.jpg">
                                                            <media:credit><![CDATA[Zoom]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Zoom app running in macOS.]]></media:description>                                                            <media:text><![CDATA[The Zoom app running in macOS.]]></media:text>
                                <media:title type="plain"><![CDATA[The Zoom app running in macOS.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/q7LJWDP3HaKLzyUesaBUh7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>AI‑found Zoom flaws enabled device takeover through malicious annotation messages</strong></li><li><strong>Exploits worked across all platforms and required only joining a video call</strong></li><li><strong>Researchers warn AI now enables rapid, nation‑state‑level exploit development</strong></li></ul><p>Experts have warned that Zoom, one of the most popular collaboration tools in the world, carried multiple vulnerabilities that allowed malicious actors to take over people’s devices, entirely. </p><p>What makes these vulnerabilities particularly dangerous is that the victims need not do much to be compromised - participating in a video call with the attacker is enough.</p><p>The bugs were said to be present in every version of Zoom, on every device and operating system - Windows, Mac, iPhone, Android, and Linux, in all versions up to and including 7.0.5 - with patches available now, so be sure to update immediately.</p><h2 id="ai-powered-security">AI-powered security</h2><p>The flaws were <a href="https://a.security/blog/asecurity-zoomsday" target="_blank" rel="nofollow">discovered</a> by security researchers A Security, which focuses on “autonomous offensive security”, using AI agents to simulate real-work attacks, identify vulnerabilities, and chain them into exploitable attack paths. </p><p>The company “simply” used publicly available frontier models and within 24 hours and fewer than 20 prompts, went from finding the flaws to building a working exploit. </p><p>The flaws are described as memory corruption bugs exploiting Zoom’s annotation feature. That feature, built on a proprietary protocol (meaning it has no public documentation or specifications, as opposed to being open source), meant that the Zoom client parsed everything it received, including specially crafted, malicious messages.</p><p>During the call, a malicious actor could send a message to each visitor that would corrupt their device’s memory and execute weaponized code, all without the victim knowing, being prompted to do anything, or clicking anything at all. </p><p>The vulnerability can be exploited regardless of if the attacker hosted, or simply joined, a call. All participants, regardless of their status in the call, were equally at risk. There were no visual cues indicating the compromise whatsoever. </p><p>Once the threat actor runs the malware on the victim’s device, they can do all sorts of things, from stealing sensitive files, to switching on the device’s camera or microphone. They can also deploy stage-two malware, steal login credentials and crypto wallet information, access the inbox, and more. </p><p>A Security responsibly disclosed their findings to Zoom, who labeled the vulnerabilities as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, and all given a severity score of 9.0/10 (critical). </p><p>Furthermore, all Zoom Workplace clients on all supported platforms before version 7.1.5 and 7.0.6 using end-to-end encryption settings are considered vulnerable. A Security recommends updating the client to the latest version. </p><h2 id="lowering-the-barrier">Lowering the barrier</h2><p>In its writeup, A Security stressed the simplicity and ease with which it managed to find the bugs and develop the exploits. It warned that AI has dramatically lowered the barrier for entry, and argued that in the pre-AI era, exploits like these were “reserved” for nation-state threat actors with virtually limitless resources:</p><p>“This class of capability would previously have only been available to nation-state threat actors, but the model requiring elite teams, months of effort, and weapons-grade budgets has collapsed,” the researchers warned. “Today, a single researcher was able to develop a nation-state-level exploit in less than a day.”</p><p>To add insult to injury, these flaws were found using “publicly available frontier models” such as GPT-5.6 Sol, Claude Opus 5, and the likes. Besides the frontier models, these companies also have dedicated cybersecurity programs where they offer specialized models with fewer guardrails and more flexibility for both offensive and defensive actions. </p><p>Earlier this week, OpenAI said that its Daybreak project now offers GPT-5.6-Cyber, a model built on GPT‑5.6 Sol and trained to improve capabilities on several specialized cybersecurity tasks such as finding zero-day vulnerabilities and developing exploit chains.</p><p>Daybreak came as a direct response to Anthropic’s Project Glasswing. This is an offering that came with Mythos Preview, an AI model that proved unusually capable at cybersecurity tasks. Allegedly, Mythos can autonomously identify and exploit zero-day flaws across major operating systems and browsers, as well as develop complex exploit chains. Because of those capabilities, Anthropic did not release Mythos Preview broadly. Instead, it made the model available to a limited group of organizations.</p><p>While some expressed their skepticism over Mythos, saying Anthropic is engaging in <a href="https://techcrunch.com/2026/04/21/sam-altman-throws-shade-at-anthropics-cyber-model-mythos-fear-based-marketing/" target="_blank"><u>fear-based marketing</u></a>, others have backed the company, saying Mythos proved exceptionally useful at identifying and fixing flaws. Microsoft, for example, is one of the original Project Glasswing partners, and ever since it started using it, the number of flaws patched through its Patch Tuesday cumulative update <a href="https://www.techradar.com/pro/security/microsoft-just-released-its-biggest-patch-tuesday-ever-with-a-mammoth-622-fixes-including-three-dangerous-zero-days" target="_blank"><u>quadrupled</u></a>.</p><p>Mozilla is also among those showering Mythos with praise, saying earlier this year that it is “<a href="https://www.techradar.com/pro/mozilla-says-anthropics-mythos-is-every-bit-as-capable-as-the-worlds-best-security-researchers-after-firefox-experiment-and-says-the-zero-days-are-numbered" target="_blank"><u>every bit as capable</u></a>” as the world’s best security researchers.</p><p>If A Security managed to find such dangerous flaws with publicly available models, there’s no telling what these dedicated models can do.</p><p><em>Via </em><a href="https://thehackernews.com/2026/08/zoom-annotation-flaws-could-let-meeting.html" target="_blank"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Scammers are using fake Odyssey pirate downloads to spread malware that's more dangerous than the Cyclops and Circe combined ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Bitdefender says fake pirated downloads of </strong><em><strong>The Odyssey</strong></em><strong>, disguised as scene releases with .exe files carrying VLC icons, are spreading Lumma Stealer malware</strong></li><li><strong>Stolen session cookies are the real danger, because they let an attacker resume an authenticated session without ever triggering a multi-factor prompt</strong></li><li><strong>These builds seemingly ship without droppers or persistence, which is less sophisticated than earlier movie-themed samples but no less harmful, since credential theft does not require staying resident</strong></li></ul><p>With <em>The Odyssey</em> set to became one of the year's biggest theatrical launches, people looking for a free copy online started finding one with a few extra caveats in tow.</p><p>What they were actually downloading, according to <a href="https://www.bitdefender.com/en-us/blog/hotforsecurity/the-odyssey-piracy-lumma-stealer" target="_blank">Bitdefender</a>, was Lumma Stealer, a prominent infostealer that operates as a Malware-as-a-Service (MaaS).</p><p>The company's researchers say its security products blocked users from downloading and running malicious files disguised as the film, circulating under names designed to look like scene releases: "the odyssey 2026 1080p webrip-lama.exe" is one of three examples published, alongside variants dressed as 2160p HD and H. 264 rips. </p><h2 id="a-regular-occurrence-for-pirates">A regular occurrence for pirates</h2><p>The threat is a well-worn playbook rather than a new one, as Bitdefender documented a near-identical campaign in 2025 built around <em>Mission: Impossible – The Final Reckoning</em>, distributing the same malware family through torrent sites using files dressed as movie releases. The blockbuster changes; the delivery does not.</p><p>The most useful detail in the report is also the least dramatic, and it explains why a file extension that should be a screaming red flag frequently is not: Windows does not show file extensions by default.</p><p>Unless a user has enabled that option in Explorer settings, the ".exe" at the end of a filename is simply invisible. Attackers pair that with a custom icon, commonly one lifted from VLC Media Player or a generic video file, so what appears on screen is a VLC icon and a filename that reads like a movie rip. There is nothing visible to distinguish it from the thing the user was actually looking for.</p><p>Bitdefender's point about social engineering follows from that, and it is a sharp one: almost none is required here. Someone hunting for a leaked copy of a film still in theaters has already accepted that they will be dealing with odd filenames, unofficial sources, and compressed archives. An executable claiming to be a video player or installer is not an uncommon sight in the world of piracy, where such practices are rife.</p><p>Lumma, also tracked as LummaC2, is a Russian-developed information stealer sold as a service, with affiliates paying somewhere between $250 and $1,000 a month for access. Upon execution, it harvests browser passwords, authentication cookies, saved payment information, cryptocurrency wallet data, autofill data, and remote desktop credentials.</p><p>It has often been highlighted as one of the most prolific MaaS options out there and has had <a href="https://www.techradar.com/pro/security/microsoft-takes-legal-action-against-lumma-stealer-after-400-000-devices-infected" target="_blank">Microsoft, the DOJ, and the FBI act directly against it</a> in the past, but has managed to stay alive since, evolving into a more stealthy entity.</p><p>Bitdefender notes that the samples in this campaign arrive without droppers and without persistence mechanisms. </p><p>Previous movie-themed Lumma builds carried more machinery, including delayed execution when security software was detected and encrypted payload delivery through AutoIt scripts. The approach here differs considerably: the attackers appear content with whatever they can collect at execution time and do not attempt to hold the machine afterward.</p><p>Prevention in this case simply involves avoiding the download of pirated films from channels that, as a rule of thumb, do not implement many, if any, security measures to keep infostealers out. </p><p>For those seeking a broader solution, enabling file extensions in Windows Explorer is the way to go. It takes seconds, it is off by default, and it removes the specific blind spot this particular campaign depends on.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/scammers-are-using-fake-odyssey-pirate-downloads-to-spread-malware-thats-more-dangerous-than-the-cyclops-and-circe-combined</link>
                                                                            <description>
                            <![CDATA[ Fake downloads of The Odyssey are delivering Lumma Stealer, and the stolen session cookies walk straight past your two-factor authentication ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xoShk7grh9qqbbQ4g5pjNT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/U6UNG2aaqj47hstBqBLsGd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Aug 2026 18:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/U6UNG2aaqj47hstBqBLsGd-1280-80.jpg">
                                                            <media:credit><![CDATA[Universal Studios]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Matt Damon&#039;s Odysseus looking over his left shoulder with some ships in the background in The Odyssey]]></media:description>                                                            <media:text><![CDATA[Matt Damon&#039;s Odysseus looking over his left shoulder with some ships in the background in The Odyssey]]></media:text>
                                <media:title type="plain"><![CDATA[Matt Damon&#039;s Odysseus looking over his left shoulder with some ships in the background in The Odyssey]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/U6UNG2aaqj47hstBqBLsGd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Bitdefender says fake pirated downloads of </strong><em><strong>The Odyssey</strong></em><strong>, disguised as scene releases with .exe files carrying VLC icons, are spreading Lumma Stealer malware</strong></li><li><strong>Stolen session cookies are the real danger, because they let an attacker resume an authenticated session without ever triggering a multi-factor prompt</strong></li><li><strong>These builds seemingly ship without droppers or persistence, which is less sophisticated than earlier movie-themed samples but no less harmful, since credential theft does not require staying resident</strong></li></ul><p>With <em>The Odyssey</em> set to became one of the year's biggest theatrical launches, people looking for a free copy online started finding one with a few extra caveats in tow.</p><p>What they were actually downloading, according to <a href="https://www.bitdefender.com/en-us/blog/hotforsecurity/the-odyssey-piracy-lumma-stealer" target="_blank">Bitdefender</a>, was Lumma Stealer, a prominent infostealer that operates as a Malware-as-a-Service (MaaS).</p><p>The company's researchers say its security products blocked users from downloading and running malicious files disguised as the film, circulating under names designed to look like scene releases: "the odyssey 2026 1080p webrip-lama.exe" is one of three examples published, alongside variants dressed as 2160p HD and H. 264 rips. </p><h2 id="a-regular-occurrence-for-pirates">A regular occurrence for pirates</h2><p>The threat is a well-worn playbook rather than a new one, as Bitdefender documented a near-identical campaign in 2025 built around <em>Mission: Impossible – The Final Reckoning</em>, distributing the same malware family through torrent sites using files dressed as movie releases. The blockbuster changes; the delivery does not.</p><p>The most useful detail in the report is also the least dramatic, and it explains why a file extension that should be a screaming red flag frequently is not: Windows does not show file extensions by default.</p><p>Unless a user has enabled that option in Explorer settings, the ".exe" at the end of a filename is simply invisible. Attackers pair that with a custom icon, commonly one lifted from VLC Media Player or a generic video file, so what appears on screen is a VLC icon and a filename that reads like a movie rip. There is nothing visible to distinguish it from the thing the user was actually looking for.</p><p>Bitdefender's point about social engineering follows from that, and it is a sharp one: almost none is required here. Someone hunting for a leaked copy of a film still in theaters has already accepted that they will be dealing with odd filenames, unofficial sources, and compressed archives. An executable claiming to be a video player or installer is not an uncommon sight in the world of piracy, where such practices are rife.</p><p>Lumma, also tracked as LummaC2, is a Russian-developed information stealer sold as a service, with affiliates paying somewhere between $250 and $1,000 a month for access. Upon execution, it harvests browser passwords, authentication cookies, saved payment information, cryptocurrency wallet data, autofill data, and remote desktop credentials.</p><p>It has often been highlighted as one of the most prolific MaaS options out there and has had <a href="https://www.techradar.com/pro/security/microsoft-takes-legal-action-against-lumma-stealer-after-400-000-devices-infected" target="_blank">Microsoft, the DOJ, and the FBI act directly against it</a> in the past, but has managed to stay alive since, evolving into a more stealthy entity.</p><p>Bitdefender notes that the samples in this campaign arrive without droppers and without persistence mechanisms. </p><p>Previous movie-themed Lumma builds carried more machinery, including delayed execution when security software was detected and encrypted payload delivery through AutoIt scripts. The approach here differs considerably: the attackers appear content with whatever they can collect at execution time and do not attempt to hold the machine afterward.</p><p>Prevention in this case simply involves avoiding the download of pirated films from channels that, as a rule of thumb, do not implement many, if any, security measures to keep infostealers out. </p><p>For those seeking a broader solution, enabling file extensions in Windows Explorer is the way to go. It takes seconds, it is off by default, and it removes the specific blind spot this particular campaign depends on.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI extends 'Daybreak' security project and reveals new cyber model — but for approved users only ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>OpenAI expands Daybreak with Blue and Red tiers for defensive cyber work</strong></li><li><strong>New GPT‑5.6‑Cyber model offers high compliance for authorized vulnerability research</strong></li><li><strong>Access remains restricted due to dual‑use risks and reduced safeguard operation</strong></li></ul><p>OpenAI has <a href="https://openai.com/index/expanding-daybreak-as-the-cyber-defense-window-narrows/" target="_blank" rel="nofollow">announced</a> two new tiers for its Daybreak dedicated cybersecurity project, each offering a different model with different levels of compliance. It also used the opportunity to introduce a new security-focused AI model, as well.</p><p>Hackers and criminals are increasingly abusing AI to improve and speed up the creation of phishing emails and malicious code, and with the introduction of <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agents</a>, they’ve also used it to automate entire attack processes. The AI community responded by placing strong guardrails, making sure their models do not comply with requests to build malware, or hack other companies.</p><p>These guardrails ended up being a two-edged sword, because as they slowed down attackers, they also slowed down the defenders.</p><h2 id="what-is-daybreak">What is Daybreak?</h2><p>To give the cybersecurity community the upper edge, companies like OpenAI started creating <a href="https://www.techradar.com/pro/security/openai-reveals-daybreak-its-attempt-to-topple-anthropic-mythos" target="_blank">dedicated cybersecurity initiatives</a> that provide a vetted list of companies state-of-the-art models, free of guardrails. The company also provided them with pre-trained AI agents, as well as access to a pool of shared knowledge.</p><p>Initially launched in June 2026, Daybreak originally included GPT.5-5-Cyber (a model optimized for security work), Codex Security (an agent that can analyze codebases, identify vulnerabilities, validate findings, and help develop patches), Patch the Planet (an initiative with Trail of Bits to find and fix vulnerabilities in open-source software), Daybreak Cyber Partner Program (lets approved cybersecurity companies such as Cloudflare or Cisco integrate OpenAI's cyber capabilities into their own products and services), and Trusted Access for Cyber (the governance/access system for organizations doing authorized cybersecurity work with these capabilities).</p><p>Now, OpenAI has expanded Daybreak with two access tiers, Daybreak Blue, and Daybreak Red.</p><p>The company says Daybreak Blue is “the recommended starting point for most defenders, supporting vulnerability discovery, secure code review, malware analysis, incident response, and patch validation. Companies opting for this tier can expect access to frontier general-purpose models, including GPT‑5.6 Sol, whose safeguards have been tailored to authorized defensive security work.</p><p>Daybreak Red, on the other hand, provides access to OpenAI’s “purpose-trained cybersecurity models for authorized vulnerability research, exploit validation, and security testing.” This tier offers the brand new GPT‑5.6‑Cyber, built on GPT‑5.6 Sol and trained to improve capabilities on several specialized cybersecurity tasks such as finding zero-day vulnerabilities and developing exploit chains.</p><p>This model is also more compliant and less likely to refuse certain higher-risk, dual-use cyber tasks.</p><h2 id="complying-with-dangerous-requests">Complying with "dangerous" requests</h2><p>Request compliance is the name of the game here. OpenAI says the new model addresses feedback from security researchers who “encountered persistent refusals with the earlier model.” General-purpose GPT-5.6 Sol, for example, will comply with just 1.5% of the requests usually given by cyber-defenders working on codebase analysis or vulnerability identification. This percentage increases to 2.0% with Daybreak Blue access. </p><p>GPT-5.6-Cyber, on the other hand, completes 95.0% of requests, OpenAI says, up from 57.3% of the previous model, GPT-5.5-Cyber. We weren’t able to independently verify these claims, though. </p><p>While it doesn’t outright say it, OpenAI considers these models relatively dangerous to use, which is why they’re locked behind the Daybreak Cyber Partner Program. However, the program is now expanding, allowing these companies to embed the models behind their own products, managed services, or cybersecurity engagements, and offer them to clients of their own. </p><p>Those who wish to be a part of the program directly can do so by applying to join online now.</p><p>“Models running with reduced safeguards carry risks beyond standard model usage, whether from misuse or misalignment. Despite these risks, we believe that democratizing access to frontier intelligence for defenders is crucial to accelerating and automating cyber defense,” OpenAI said.</p><p>“Daybreak Blue and Daybreak Red access are available for approved individuals⁠ and organizations conducting authorized work. We control access through identity verification, account security, monitoring, approved-use restrictions, and legal attestations.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/openai-extends-daybreak-security-project-and-reveals-new-cyber-model-but-for-approved-users-only</link>
                                                                            <description>
                            <![CDATA[ Daybreak now offers two different models that come with varying degrees of compliance. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">AjWZELXMsLjAfnbdxFTR4P</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gN6Qsf7QSmrmYwtYPr47HY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Aug 2026 13:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gN6Qsf7QSmrmYwtYPr47HY-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[OpenAI logo on smartphone, reflected on main screen]]></media:description>                                                            <media:text><![CDATA[OpenAI logo on smartphone, reflected on main screen]]></media:text>
                                <media:title type="plain"><![CDATA[OpenAI logo on smartphone, reflected on main screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gN6Qsf7QSmrmYwtYPr47HY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>OpenAI expands Daybreak with Blue and Red tiers for defensive cyber work</strong></li><li><strong>New GPT‑5.6‑Cyber model offers high compliance for authorized vulnerability research</strong></li><li><strong>Access remains restricted due to dual‑use risks and reduced safeguard operation</strong></li></ul><p>OpenAI has <a href="https://openai.com/index/expanding-daybreak-as-the-cyber-defense-window-narrows/" target="_blank" rel="nofollow">announced</a> two new tiers for its Daybreak dedicated cybersecurity project, each offering a different model with different levels of compliance. It also used the opportunity to introduce a new security-focused AI model, as well.</p><p>Hackers and criminals are increasingly abusing AI to improve and speed up the creation of phishing emails and malicious code, and with the introduction of <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agents</a>, they’ve also used it to automate entire attack processes. The AI community responded by placing strong guardrails, making sure their models do not comply with requests to build malware, or hack other companies.</p><p>These guardrails ended up being a two-edged sword, because as they slowed down attackers, they also slowed down the defenders.</p><h2 id="what-is-daybreak">What is Daybreak?</h2><p>To give the cybersecurity community the upper edge, companies like OpenAI started creating <a href="https://www.techradar.com/pro/security/openai-reveals-daybreak-its-attempt-to-topple-anthropic-mythos" target="_blank">dedicated cybersecurity initiatives</a> that provide a vetted list of companies state-of-the-art models, free of guardrails. The company also provided them with pre-trained AI agents, as well as access to a pool of shared knowledge.</p><p>Initially launched in June 2026, Daybreak originally included GPT.5-5-Cyber (a model optimized for security work), Codex Security (an agent that can analyze codebases, identify vulnerabilities, validate findings, and help develop patches), Patch the Planet (an initiative with Trail of Bits to find and fix vulnerabilities in open-source software), Daybreak Cyber Partner Program (lets approved cybersecurity companies such as Cloudflare or Cisco integrate OpenAI's cyber capabilities into their own products and services), and Trusted Access for Cyber (the governance/access system for organizations doing authorized cybersecurity work with these capabilities).</p><p>Now, OpenAI has expanded Daybreak with two access tiers, Daybreak Blue, and Daybreak Red.</p><p>The company says Daybreak Blue is “the recommended starting point for most defenders, supporting vulnerability discovery, secure code review, malware analysis, incident response, and patch validation. Companies opting for this tier can expect access to frontier general-purpose models, including GPT‑5.6 Sol, whose safeguards have been tailored to authorized defensive security work.</p><p>Daybreak Red, on the other hand, provides access to OpenAI’s “purpose-trained cybersecurity models for authorized vulnerability research, exploit validation, and security testing.” This tier offers the brand new GPT‑5.6‑Cyber, built on GPT‑5.6 Sol and trained to improve capabilities on several specialized cybersecurity tasks such as finding zero-day vulnerabilities and developing exploit chains.</p><p>This model is also more compliant and less likely to refuse certain higher-risk, dual-use cyber tasks.</p><h2 id="complying-with-dangerous-requests">Complying with "dangerous" requests</h2><p>Request compliance is the name of the game here. OpenAI says the new model addresses feedback from security researchers who “encountered persistent refusals with the earlier model.” General-purpose GPT-5.6 Sol, for example, will comply with just 1.5% of the requests usually given by cyber-defenders working on codebase analysis or vulnerability identification. This percentage increases to 2.0% with Daybreak Blue access. </p><p>GPT-5.6-Cyber, on the other hand, completes 95.0% of requests, OpenAI says, up from 57.3% of the previous model, GPT-5.5-Cyber. We weren’t able to independently verify these claims, though. </p><p>While it doesn’t outright say it, OpenAI considers these models relatively dangerous to use, which is why they’re locked behind the Daybreak Cyber Partner Program. However, the program is now expanding, allowing these companies to embed the models behind their own products, managed services, or cybersecurity engagements, and offer them to clients of their own. </p><p>Those who wish to be a part of the program directly can do so by applying to join online now.</p><p>“Models running with reduced safeguards carry risks beyond standard model usage, whether from misuse or misalignment. Despite these risks, we believe that democratizing access to frontier intelligence for defenders is crucial to accelerating and automating cyber defense,” OpenAI said.</p><p>“Daybreak Blue and Daybreak Red access are available for approved individuals⁠ and organizations conducting authorized work. We control access through identity verification, account security, monitoring, approved-use restrictions, and legal attestations.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The CEVA Logistics data breach is having major knock-on effects across Europe - here's what we know ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>CEVA Logistics hack disrupted European warehouses and exposed some customer data</strong></li><li><strong>Retailers and Valve reported compromised delivery information and service delays</strong></li><li><strong>Clients warned of targeted scams while awaiting fuller incident details from CEVA</strong></li></ul><p>CEVA Logistics, one of the biggest shipping and logistics companies in the world, has suffered a major cyberattack, the effects of which are trickling down to many of its clients. </p><p>The details of the hack itself, however, are not yet publicly available and what little information is out there came from the affected clients themselves.</p><p>CEVA has not yet issued an official statement, or filed a report with the regulators, but confirmed to <a href="https://techcrunch.com/2026/08/10/a-data-breach-at-shipping-giant-ceva-logistics-is-rippling-across-banks-retailers-steam-gamers-and-beyond/" target="_blank"><em>TechCrunch</em></a> that the attack most likely started on July 29, 2026, and affected at least eight warehouses across Europe.</p><h2 id="technical-details-missing-affected-customers-step-forward">Technical details missing, affected customers step forward</h2><p>CEVA Logistics is a global logistics and supply-chain company and a wholly owned subsidiary of CMA CGM, a French shipping giant. It provides freight forwarding, contract logistics, warehousing and transportation services to thousands of customers, including major companies in the consumer and retail, automotive, industrial and aerospace sectors. </p><p>The company operates in more than 170 countries around the world and last year it generated $18.3 billion in gross revenue, so it is a major player and a key target for attackers.</p><p>The details about the incident itself are scarce right now. We don’t know how the crooks broke in (via a successful social engineering attack, or by abusing a software vulnerability, for example), how much data they stole, or if they demanded a ransom payment in exchange for deleting the stolen goods. From one of the victims, though, we have learned that some data was most likely compromised.</p><p>When the effects of a cyberattack spill into the physical realm (as is the case here with eight affected warehouses) we can speculate the attack was either <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a>, or disruptive <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>. Companies shut down parts of their IT infrastructure only when there is no other way to clear an infection or remove malicious outsiders.</p><p>In the meantime, a small number of CEVA’s customers confirmed suffering an attack and losing sensitive data. </p><p>Among them is Bol, a Dutch online retail company, which said the incident affected two systems used for processing orders from one of its fulfillment</p><p>“No bol systems were affected,” it said. “However, data of customers whose orders were processed via this location may have been viewed or copied.”</p><p>Bol also said restoring operations at one of CEVA’s locations was taking longer than anticipated. As a result, the assortment stored at the affected location was taken offline, and the products were unavailable for sale. Also, Bol is currently unable to receive goods from suppliers and sales partners at that location.</p><p>A similar announcement was given by De Bijenkorf, another Dutch luxury retailer, who said that order processing, returns, and refunds, might take longer, but stressed that its stores remained open. It also said that some customer data may have been compromised, including names, contact details, online orders data and, in some cases, VAT numbers. Payment information, bank account numbers (IBANs), credit card information, usernames, or passwords, were not compromised, it was confirmed. </p><h2 id="valve-steps-forward">Valve steps forward</h2><p>Retail giants aside, PC gaming powerhouse Valve also notified its customers about the incident. It said CEVA ships Steam hardware to its European customers and as such, receives specific delivery-related information from Steam. </p><p>This information, which CEVA retains for up to 90 days after the order, was most likely compromised. It includes names, street addresses, phone numbers, email addresses, and the type and price of ordered products.</p><p>Valve warned its customers to expect fake messages, either via email, SMS, or phone, that might mention recent hardware orders. </p><p>“They may quote your address back to you to prove they're genuine. They may ask you to confirm a delivery, pay a small customs or redelivery fee, or sign in somewhere to “verify” your order. Treat all of them as fake,” Valve warned. The company also stressed that customer accounts are safe and that users need not do anything to secure them.</p><p>Other details are missing, not just for the general public, but for the affected CEVA clients, as well. Valve said it was “pressing” the company for the full scope of what was taken and how, and added that it is notifying the relevant authorities, as well. </p><p>A spokesperson of the Dutch data protection authority, Mark Schenkel, told <em>TechCrunch</em> the agency so far received 10 incident reports. Given the size of CEVA, it’s safe to assume there will be others.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/the-ceva-logistics-data-breach-is-having-major-knock-on-effects-across-europe-heres-what-we-know</link>
                                                                            <description>
                            <![CDATA[ Shipping and logistics powerhouse suffers a cyberattack, affecting almost a dozen of its clients - we take a look at the details. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">znDNTChe2TpJRXew9c5Wz</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Aug 2026 11:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[hacker hands at work with  interface around]]></media:description>                                                            <media:text><![CDATA[hacker hands at work with  interface around]]></media:text>
                                <media:title type="plain"><![CDATA[hacker hands at work with  interface around]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>CEVA Logistics hack disrupted European warehouses and exposed some customer data</strong></li><li><strong>Retailers and Valve reported compromised delivery information and service delays</strong></li><li><strong>Clients warned of targeted scams while awaiting fuller incident details from CEVA</strong></li></ul><p>CEVA Logistics, one of the biggest shipping and logistics companies in the world, has suffered a major cyberattack, the effects of which are trickling down to many of its clients. </p><p>The details of the hack itself, however, are not yet publicly available and what little information is out there came from the affected clients themselves.</p><p>CEVA has not yet issued an official statement, or filed a report with the regulators, but confirmed to <a href="https://techcrunch.com/2026/08/10/a-data-breach-at-shipping-giant-ceva-logistics-is-rippling-across-banks-retailers-steam-gamers-and-beyond/" target="_blank"><em>TechCrunch</em></a> that the attack most likely started on July 29, 2026, and affected at least eight warehouses across Europe.</p><h2 id="technical-details-missing-affected-customers-step-forward">Technical details missing, affected customers step forward</h2><p>CEVA Logistics is a global logistics and supply-chain company and a wholly owned subsidiary of CMA CGM, a French shipping giant. It provides freight forwarding, contract logistics, warehousing and transportation services to thousands of customers, including major companies in the consumer and retail, automotive, industrial and aerospace sectors. </p><p>The company operates in more than 170 countries around the world and last year it generated $18.3 billion in gross revenue, so it is a major player and a key target for attackers.</p><p>The details about the incident itself are scarce right now. We don’t know how the crooks broke in (via a successful social engineering attack, or by abusing a software vulnerability, for example), how much data they stole, or if they demanded a ransom payment in exchange for deleting the stolen goods. From one of the victims, though, we have learned that some data was most likely compromised.</p><p>When the effects of a cyberattack spill into the physical realm (as is the case here with eight affected warehouses) we can speculate the attack was either <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a>, or disruptive <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>. Companies shut down parts of their IT infrastructure only when there is no other way to clear an infection or remove malicious outsiders.</p><p>In the meantime, a small number of CEVA’s customers confirmed suffering an attack and losing sensitive data. </p><p>Among them is Bol, a Dutch online retail company, which said the incident affected two systems used for processing orders from one of its fulfillment</p><p>“No bol systems were affected,” it said. “However, data of customers whose orders were processed via this location may have been viewed or copied.”</p><p>Bol also said restoring operations at one of CEVA’s locations was taking longer than anticipated. As a result, the assortment stored at the affected location was taken offline, and the products were unavailable for sale. Also, Bol is currently unable to receive goods from suppliers and sales partners at that location.</p><p>A similar announcement was given by De Bijenkorf, another Dutch luxury retailer, who said that order processing, returns, and refunds, might take longer, but stressed that its stores remained open. It also said that some customer data may have been compromised, including names, contact details, online orders data and, in some cases, VAT numbers. Payment information, bank account numbers (IBANs), credit card information, usernames, or passwords, were not compromised, it was confirmed. </p><h2 id="valve-steps-forward">Valve steps forward</h2><p>Retail giants aside, PC gaming powerhouse Valve also notified its customers about the incident. It said CEVA ships Steam hardware to its European customers and as such, receives specific delivery-related information from Steam. </p><p>This information, which CEVA retains for up to 90 days after the order, was most likely compromised. It includes names, street addresses, phone numbers, email addresses, and the type and price of ordered products.</p><p>Valve warned its customers to expect fake messages, either via email, SMS, or phone, that might mention recent hardware orders. </p><p>“They may quote your address back to you to prove they're genuine. They may ask you to confirm a delivery, pay a small customs or redelivery fee, or sign in somewhere to “verify” your order. Treat all of them as fake,” Valve warned. The company also stressed that customer accounts are safe and that users need not do anything to secure them.</p><p>Other details are missing, not just for the general public, but for the affected CEVA clients, as well. Valve said it was “pressing” the company for the full scope of what was taken and how, and added that it is notifying the relevant authorities, as well. </p><p>A spokesperson of the Dutch data protection authority, Mark Schenkel, told <em>TechCrunch</em> the agency so far received 10 incident reports. Given the size of CEVA, it’s safe to assume there will be others.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Top US defense device maker IEH Corporation admits hackers broke into its systems ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Attackers stole IEH employee credentials via a fake Microsoft login page</strong></li><li><strong>Inbox access exposed sensitive defense‑related communications and technical documentation</strong></li><li><strong>Malicious mailbox rules were removed as IEH contained the unauthorized access</strong></li></ul><p>Criminals have broken into the email inboxes of IEH Corporation, a significant supplier for the US military and companies in the commercial aerospace and space industry.</p><p>In an 8-K report filed with the US Securities and Exchange Commission (SEC), IEH said that unidentified threat actors reached out to one of its employees, pretending to be a “prospective business contact”. </p><p>The atatckers shared a link to what appeared to be a Microsoft document, prompting the victim to log in. Obviously, the login page was bogus, and the login credentials were relayed to the attackers instead.</p><h2 id="malicious-mailbox-rules">Malicious mailbox rules</h2><p>“The threat actor gained access to mailbox contents, including email messages, attachments, customer communications, purchase orders, engineering-related documentation, and potentially export-controlled technical information,” the 8-K reads.</p><p>The culprits, however, were not named and no threat actors have yet claimed responsibility for the attack.</p><p>IEH said it found no evidence that data had been exfiltrated from the compromised inbox. However, its defenders did discover and remove “malicious mailbox rules”. Usually, crooks set up such rules to automatically forward incoming emails to an inbox under their control, while deleting traces of the activity. This would allow them to continue receiving sensitive emails even after the initial compromise was remediated. </p><p>The company also said it completed a full audit of the inbox and done “corrective actions to contain any impact of the unauthorized access.”</p><p>IEH Corporation produces “specialized products used in military satellites, missiles and fighter jets,” meaning the information found in the inbox could be quite valuable, especially for nation-states such as Russia, China, North Korea, or Iran. </p><p>IEH does not publicly name its clients but it does say that its defense applications include Apache AH-64, V-280 Valor and SH-60 Seahawk programs, as well as Patriot, THAAD, AMRAAM and APKWS missile programs. It reported a revenue of almost $30 million for the 2026 fiscal year.</p><p><em>Via </em><a href="https://therecord.media/military-device-manufacturer-discloses-cyber-incident" target="_blank"><em>The Record</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/top-us-defense-device-maker-ieh-corporation-admits-hackers-broke-into-its-systems</link>
                                                                            <description>
                            <![CDATA[ Someone used social engineering to access an employee's email account, viewing purchase orders, engineering-related documentation, and more. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pZcCMmHbAqHJRNxLfwWFdY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TLsB5tZb8kRUnWbcRmNDuB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 10 Aug 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TLsB5tZb8kRUnWbcRmNDuB-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ground military drone for cargo transportation]]></media:description>                                                            <media:text><![CDATA[Ground military drone for cargo transportation]]></media:text>
                                <media:title type="plain"><![CDATA[Ground military drone for cargo transportation]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TLsB5tZb8kRUnWbcRmNDuB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Attackers stole IEH employee credentials via a fake Microsoft login page</strong></li><li><strong>Inbox access exposed sensitive defense‑related communications and technical documentation</strong></li><li><strong>Malicious mailbox rules were removed as IEH contained the unauthorized access</strong></li></ul><p>Criminals have broken into the email inboxes of IEH Corporation, a significant supplier for the US military and companies in the commercial aerospace and space industry.</p><p>In an 8-K report filed with the US Securities and Exchange Commission (SEC), IEH said that unidentified threat actors reached out to one of its employees, pretending to be a “prospective business contact”. </p><p>The atatckers shared a link to what appeared to be a Microsoft document, prompting the victim to log in. Obviously, the login page was bogus, and the login credentials were relayed to the attackers instead.</p><h2 id="malicious-mailbox-rules">Malicious mailbox rules</h2><p>“The threat actor gained access to mailbox contents, including email messages, attachments, customer communications, purchase orders, engineering-related documentation, and potentially export-controlled technical information,” the 8-K reads.</p><p>The culprits, however, were not named and no threat actors have yet claimed responsibility for the attack.</p><p>IEH said it found no evidence that data had been exfiltrated from the compromised inbox. However, its defenders did discover and remove “malicious mailbox rules”. Usually, crooks set up such rules to automatically forward incoming emails to an inbox under their control, while deleting traces of the activity. This would allow them to continue receiving sensitive emails even after the initial compromise was remediated. </p><p>The company also said it completed a full audit of the inbox and done “corrective actions to contain any impact of the unauthorized access.”</p><p>IEH Corporation produces “specialized products used in military satellites, missiles and fighter jets,” meaning the information found in the inbox could be quite valuable, especially for nation-states such as Russia, China, North Korea, or Iran. </p><p>IEH does not publicly name its clients but it does say that its defense applications include Apache AH-64, V-280 Valor and SH-60 Seahawk programs, as well as Patriot, THAAD, AMRAAM and APKWS missile programs. It reported a revenue of almost $30 million for the 2026 fiscal year.</p><p><em>Via </em><a href="https://therecord.media/military-device-manufacturer-discloses-cyber-incident" target="_blank"><em>The Record</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US healthcare software giant Unlimited Technology Systems admits hackers may have stolen sensitive data of 3.8 million people ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Attackers stole extensive personal and medical data from 3.8 million individuals from Unlimited Technology Systems</strong></li><li><strong>Breach source and methods remain unknown, with no group claiming responsibility</strong></li><li><strong>Stolen data poses major fraud risks, prompting free identity monitoring from Kroll</strong></li></ul><p>US healthcare organization Unlimited Technology Systems has revealed it suffered a cyberattack in which it lost a treasure trove of sensitive information belonging to millions of people.</p><p>The company recently made the information public and shared details with the US Department of Health and Human Services, noting that someone broke in on October 5, 2025 and within five days exfiltrated valuable data belonging to just over 3.8 million people.</p><p>The attacker stole people’s full names, Social Security numbers (SSN), dates of birth, emails and mailing addresses, phone numbers, demographic information, scans of driver’s licenses and other government IDs, insurance cards, intake forms, health insurance policy numbers, claims and benefits information, medical record numbers, dates of service, and diagnosis data.</p><h2 id="supply-chain-woes">Supply chain woes</h2><p>The company did not say who the threat actors were, or if they demanded any ransom in exchange for deleting the data. </p><p>No hackers have claimed responsibility just yet, and we also don’t know how they managed to break in, as different groups have different methods. </p><p>ShinyHunters, for example, prefer calling their victims on the phone, pretending to be IT support and convincing their victims to give them access via remote management tools. Other groups might try to exploit vulnerabilities in routers, firewalls, and other hardware.</p><p>Whoever it was, they have a valuable data set in their possession. This kind of information can be sold on the black market or used in <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a> and wire fraud. To mitigate these risks, Unlimited Technology Systems is offering free identity monitoring services to affected individuals through Kroll.</p><p>Unlimited Technology Systems is a software company that provides financial technology for healthcare organizations. It works with around 4,500 clinics and 6,500 specialty healthcare providers in the US, processing north of $70 billion in net healthcare charges every year. </p><p>According to <a href="https://www.bleepingcomputer.com/news/security/unlimited-technology-systems-breach-impacts-38-million-people/" target="_blank"><em>BleepingComputer</em></a>, the company processes information on behalf of its clients, which means that the victims of this attack have no direct relationship with Unlimited and have probably not even heard of it.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/us-healthcare-software-giant-unlimited-technology-systems-admits-hackers-may-have-stolen-sensitive-data-of-3-8-million-people</link>
                                                                            <description>
                            <![CDATA[ Insurance cards, intake forms, health insurance policy numbers, and other information stolen in major attack. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">JLszabNNmVbjnunuyMbNwL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kCbP2VkzMgQpYqJDgMQ8UZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 10 Aug 2026 14:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kCbP2VkzMgQpYqJDgMQ8UZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity]]></media:description>                                                            <media:text><![CDATA[Cybersecurity]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kCbP2VkzMgQpYqJDgMQ8UZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Attackers stole extensive personal and medical data from 3.8 million individuals from Unlimited Technology Systems</strong></li><li><strong>Breach source and methods remain unknown, with no group claiming responsibility</strong></li><li><strong>Stolen data poses major fraud risks, prompting free identity monitoring from Kroll</strong></li></ul><p>US healthcare organization Unlimited Technology Systems has revealed it suffered a cyberattack in which it lost a treasure trove of sensitive information belonging to millions of people.</p><p>The company recently made the information public and shared details with the US Department of Health and Human Services, noting that someone broke in on October 5, 2025 and within five days exfiltrated valuable data belonging to just over 3.8 million people.</p><p>The attacker stole people’s full names, Social Security numbers (SSN), dates of birth, emails and mailing addresses, phone numbers, demographic information, scans of driver’s licenses and other government IDs, insurance cards, intake forms, health insurance policy numbers, claims and benefits information, medical record numbers, dates of service, and diagnosis data.</p><h2 id="supply-chain-woes">Supply chain woes</h2><p>The company did not say who the threat actors were, or if they demanded any ransom in exchange for deleting the data. </p><p>No hackers have claimed responsibility just yet, and we also don’t know how they managed to break in, as different groups have different methods. </p><p>ShinyHunters, for example, prefer calling their victims on the phone, pretending to be IT support and convincing their victims to give them access via remote management tools. Other groups might try to exploit vulnerabilities in routers, firewalls, and other hardware.</p><p>Whoever it was, they have a valuable data set in their possession. This kind of information can be sold on the black market or used in <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a> and wire fraud. To mitigate these risks, Unlimited Technology Systems is offering free identity monitoring services to affected individuals through Kroll.</p><p>Unlimited Technology Systems is a software company that provides financial technology for healthcare organizations. It works with around 4,500 clinics and 6,500 specialty healthcare providers in the US, processing north of $70 billion in net healthcare charges every year. </p><p>According to <a href="https://www.bleepingcomputer.com/news/security/unlimited-technology-systems-breach-impacts-38-million-people/" target="_blank"><em>BleepingComputer</em></a>, the company processes information on behalf of its clients, which means that the victims of this attack have no direct relationship with Unlimited and have probably not even heard of it.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Samsung patches nearly 200 security issues on its phone hardware - here's what you need to know ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Oversecured found 176 vulnerabilities across Samsung’s preinstalled mobile apps</strong></li><li><strong>Flaws enabled account takeover, code execution, and traffic hijacking via bloatware</strong></li><li><strong>Samsung patched all reported issues, affecting hundreds of millions of devices</strong></li></ul><p>Security researchers from Oversecured have given “bloatware” an entirely new meaning, revealing that they uncovered 176 vulnerabilities - including some rather worrying ones - in Samsung’s mobile apps.</p><p>For the last three years, the team analyzed Samsung’s preinstalled system applications and found vulnerabilities that could cause some serious harm. Some of the bugs granted camera and microphone access, while others allowed for remote Samsung Account takeover with nothing more than a single click.</p><p>Some flaws allowed for network traffic hijacking via DNS manipulation, and others granted arbitrary code execution via an image. In theory, a malicious actor could craft and send a JPEG image which, when the victim opens, copies and loads attacker-controlled native libraries from the SD card. Finally, Oversecured found path traversal vulnerabilities allowing writing arbitrary files to the file system without proper path validation. </p><h2 id="arbitrary-code-execution">Arbitrary code execution</h2><p>The researchers disclosed their findings to Samsung which, according to their report, fixed all of the reported issues - the full list can be found on <a href="https://github.com/oversecured/Samsung_Vulnerabilities" target="_blank"><u>GitHub</u></a>.</p><p>Most <a href="https://www.techradar.com/best/best-android-phones" target="_blank">Android smartphone</a> manufacturers preload their devices with proprietary apps - think Bixby, Samsung Free, or AR Zone. These apps - which cannot be uninstalled or removed from the devices - aren’t necessary to their operations and are often not wanted by the users in the first place. </p><p>This 'bloatware' is also one of the key selling propositions of <a href="https://www.techradar.com/news/best-pixel-phones" target="_blank">Google Pixel</a> devices, since these are considered “stock Android”, or bloatware-free. </p><p>Out of context, these bugs are nothing extraordinary. Single-click account takeover flaws and traffic hijacking bugs pop up every now and then and get fixed rather quickly. The context here is that these are Samsung’s proprietary apps that don’t fall under the protection of Google’s Play Protect. Users might think they’re safe because they’ve not downloaded apps from risky places, or enabled dangerous permissions, when in reality, they’re not safe at all:</p><p>“Preinstalled system applications run with extra privileges than normal apps, cannot be removed by users, and operate outside Google Play Protect,” the researchers warned. “A single vulnerability affects hundreds of millions of devices globally through one vendor's distribution channel.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/samsung-patches-nearly-200-security-issues-on-its-phone-hardware-heres-what-you-need-to-know</link>
                                                                            <description>
                            <![CDATA[ Samsung's bloatware carried dangerous flaws that enabled access to the phone's microphone and camera. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iprsfWxDRtGKN2ZuvjjwSd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BBM4XfubmWGFTaMhYGgJKX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 10 Aug 2026 13:50:29 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BBM4XfubmWGFTaMhYGgJKX-1280-80.jpg">
                                                            <media:credit><![CDATA[Future | Alex Walker-Todd]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Er du ute efter den beste Android-mobilen? Her er våre  favoritter akkurat nå.]]></media:description>                                                            <media:text><![CDATA[Samsung Galaxy S23 Ultra review angled tea]]></media:text>
                                <media:title type="plain"><![CDATA[Samsung Galaxy S23 Ultra review angled tea]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BBM4XfubmWGFTaMhYGgJKX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Oversecured found 176 vulnerabilities across Samsung’s preinstalled mobile apps</strong></li><li><strong>Flaws enabled account takeover, code execution, and traffic hijacking via bloatware</strong></li><li><strong>Samsung patched all reported issues, affecting hundreds of millions of devices</strong></li></ul><p>Security researchers from Oversecured have given “bloatware” an entirely new meaning, revealing that they uncovered 176 vulnerabilities - including some rather worrying ones - in Samsung’s mobile apps.</p><p>For the last three years, the team analyzed Samsung’s preinstalled system applications and found vulnerabilities that could cause some serious harm. Some of the bugs granted camera and microphone access, while others allowed for remote Samsung Account takeover with nothing more than a single click.</p><p>Some flaws allowed for network traffic hijacking via DNS manipulation, and others granted arbitrary code execution via an image. In theory, a malicious actor could craft and send a JPEG image which, when the victim opens, copies and loads attacker-controlled native libraries from the SD card. Finally, Oversecured found path traversal vulnerabilities allowing writing arbitrary files to the file system without proper path validation. </p><h2 id="arbitrary-code-execution">Arbitrary code execution</h2><p>The researchers disclosed their findings to Samsung which, according to their report, fixed all of the reported issues - the full list can be found on <a href="https://github.com/oversecured/Samsung_Vulnerabilities" target="_blank"><u>GitHub</u></a>.</p><p>Most <a href="https://www.techradar.com/best/best-android-phones" target="_blank">Android smartphone</a> manufacturers preload their devices with proprietary apps - think Bixby, Samsung Free, or AR Zone. These apps - which cannot be uninstalled or removed from the devices - aren’t necessary to their operations and are often not wanted by the users in the first place. </p><p>This 'bloatware' is also one of the key selling propositions of <a href="https://www.techradar.com/news/best-pixel-phones" target="_blank">Google Pixel</a> devices, since these are considered “stock Android”, or bloatware-free. </p><p>Out of context, these bugs are nothing extraordinary. Single-click account takeover flaws and traffic hijacking bugs pop up every now and then and get fixed rather quickly. The context here is that these are Samsung’s proprietary apps that don’t fall under the protection of Google’s Play Protect. Users might think they’re safe because they’ve not downloaded apps from risky places, or enabled dangerous permissions, when in reality, they’re not safe at all:</p><p>“Preinstalled system applications run with extra privileges than normal apps, cannot be removed by users, and operate outside Google Play Protect,” the researchers warned. “A single vulnerability affects hundreds of millions of devices globally through one vendor's distribution channel.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Levi's reveals security tear may have let hackers steal important corporate data ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Attackers used social engineering to access Levi’s network and steal corporate data</strong></li><li><strong>Details on stolen information, methods, and perpetrators remain largely undisclosed</strong></li><li><strong>Voice‑phishing extortion groups are suspected, though no one has claimed responsibility</strong></li></ul><p>Levi Strauss has revealed it recently suffered a cyberattack and lost corporate files - however some crucial details around the incident are missing.</p><p>The company filed a new report with the US Securities and Exchange Commission (SEC), noting how hackers accessed its infrastructure through “social engineering” against three of its employees. We don’t know if that was via email, voice phishing, or some other technique.</p><p>After breaching the network, the crooks - who weren’t identified - “accessed and exfiltrated certain corporate information”. Again, we don’t know which information was accessed, or how much of it.</p><h2 id="was-it-unc6671">Was it UNC6671?</h2><p>In response, Levi’s said it had “initiated response protocols, implemented containment measures, and launched an investigation” which remains ongoing. Again, we don’t know what these measures are, or how the crooks were ousted. </p><p>The company says the incident did not disrupt its business operations, or caused interruptions, in any way, and that it does not expect it to have any material impact whatsoever. </p><p>While Levi’s did not name the perpetrators, and while none have yet claimed responsibility on the dark web, <a href="https://cyberinsider.com/levi-strauss-discloses-data-breach-after-social-engineering-attack-on-employees/" target="_blank">some publications </a>have hinted at UNC6671, a “financially motivated threat cluster that conducts data-theft extortion attacks through voice phishing”. The tactic seems to have been “borrowed” from ShinyHunters, arguably one of the largest data extortionists out there. </p><p>The group would call their targets on the phone (usually low-level employees with access to company SaaS solutions) and, while pretending to be from the IT department, convince the victims to either grant <a href="https://www.techradar.com/news/best-remote-desktop-software" target="_blank">remote access</a>, or to visit a malicious credential-grabbing landing page. </p><p>From there, the attackers would move in, map the infrastructure, exfiltrate valuable data, and then demand payment in cryptocurrency in exchange for deleting the data. </p><p>We have reached out to Levi’s with further questions and will update the article if we get an answer.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/levi-strauss-and-co-says-hackers-stole-corporate-data-in-cyberattack/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/levis-reveals-security-tear-may-have-let-hackers-steal-important-corporate-data</link>
                                                                            <description>
                            <![CDATA[ Crucial data is missing following Levi's attack, including who the threat actors were, what kind of files they stolen, or if customers are at risk. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">75grDbVtv9pCkChbwo6C5m</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 10 Aug 2026 12:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:description>                                                            <media:text><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:text>
                                <media:title type="plain"><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Attackers used social engineering to access Levi’s network and steal corporate data</strong></li><li><strong>Details on stolen information, methods, and perpetrators remain largely undisclosed</strong></li><li><strong>Voice‑phishing extortion groups are suspected, though no one has claimed responsibility</strong></li></ul><p>Levi Strauss has revealed it recently suffered a cyberattack and lost corporate files - however some crucial details around the incident are missing.</p><p>The company filed a new report with the US Securities and Exchange Commission (SEC), noting how hackers accessed its infrastructure through “social engineering” against three of its employees. We don’t know if that was via email, voice phishing, or some other technique.</p><p>After breaching the network, the crooks - who weren’t identified - “accessed and exfiltrated certain corporate information”. Again, we don’t know which information was accessed, or how much of it.</p><h2 id="was-it-unc6671">Was it UNC6671?</h2><p>In response, Levi’s said it had “initiated response protocols, implemented containment measures, and launched an investigation” which remains ongoing. Again, we don’t know what these measures are, or how the crooks were ousted. </p><p>The company says the incident did not disrupt its business operations, or caused interruptions, in any way, and that it does not expect it to have any material impact whatsoever. </p><p>While Levi’s did not name the perpetrators, and while none have yet claimed responsibility on the dark web, <a href="https://cyberinsider.com/levi-strauss-discloses-data-breach-after-social-engineering-attack-on-employees/" target="_blank">some publications </a>have hinted at UNC6671, a “financially motivated threat cluster that conducts data-theft extortion attacks through voice phishing”. The tactic seems to have been “borrowed” from ShinyHunters, arguably one of the largest data extortionists out there. </p><p>The group would call their targets on the phone (usually low-level employees with access to company SaaS solutions) and, while pretending to be from the IT department, convince the victims to either grant <a href="https://www.techradar.com/news/best-remote-desktop-software" target="_blank">remote access</a>, or to visit a malicious credential-grabbing landing page. </p><p>From there, the attackers would move in, map the infrastructure, exfiltrate valuable data, and then demand payment in cryptocurrency in exchange for deleting the data. </p><p>We have reached out to Levi’s with further questions and will update the article if we get an answer.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/levi-strauss-and-co-says-hackers-stole-corporate-data-in-cyberattack/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts warn North Korean hackers are increasingly using AI to build smarter and more devious cyberattacks ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Kimsuky used local AI tools to evade monitoring and enhance operations</strong></li><li><strong>Researchers observed extensive AI-driven capability building across the group’s infrastructure</strong></li><li><strong>Defenders urged behavior-based detection to spot evolving AI-enabled threats</strong></li></ul><p>North Korean hackers have found a way to use Generative Artificial Intelligence (GenAI) to supercharge their activities without tipping off the tool’s maintainers.</p><p>When people use AI tools like ChatGPT or Claude, their activities can be (at least to some extent) tracked and curbed - with OpenAI recently identifying and <a href="https://www.techradar.com/pro/security/openai-says-it-stopped-an-asian-scam-campaign-hijacking-chatgpt-to-lure-in-victims" target="_blank">terminating multiple ChatGPT accounts</a> used in phishing and human trafficking. </p><p>That is why Kimsuky - a known state-sponsored North Korean threat actor, used Ollama, GPT4All and Msty locally, allowing them to process documents without sending any sensitive information to outside AI services. </p><h2 id="consistent-process-of-capability-development">"Consistent process of capability development"</h2><p>The attacks were spotted by security researchers <a href="https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm" target="_blank" rel="nofollow">Genians</a> who “conducted months of tracking and log analysis on the infrastructure utilized as C2 in this campaign,” to identify the tools they used.</p><p>Aside from the three LLMs, they also used retrieval augmented generation (RAG) tools for document search, as well as AI agent development frameworks, text-to-speech software, and an AI-assisted coding tool called Cursor.</p><p>Using AI to write malicious code is not as simple as it sounds, due to various guardrails set up by the developers. As a result, AI in crime has been mostly limited to drafting phishing emails and crafting authentic-looking but malicious landing pages. However, Kimsuky has shown that AI in cybercrime continues to evolve and is becoming an ever-greater threat. </p><p>“What was observed in the threat actor's infrastructure was not merely evidence of several documents being created with AI, but a consistent process of capability development: establishing local LLM runtime environments, configuring RAG based on documents in the actor's possession, collecting AI agent development frameworks, and acquiring libraries for integration with external commercial AI services,” Genians concluded.</p><p>As a result, defenders must move from content-based assessment to behavior-based detection, the researchers warned, saying this should serve “as the fundamental premise of security recommendations.”</p><p>“In addition to indicator of compromise (IoC)-based detection, organizations should contextually correlate the sequence of anomalous activities following LNK execution, including PowerShell execution, persistence establishment, and external communications, to assess the overall threat level.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/experts-warn-north-korean-hackers-are-increasingly-using-ai-to-build-smarter-and-more-devious-cyberattacks</link>
                                                                            <description>
                            <![CDATA[ In cybercrime, AI is used for more than simply drafting phishing emails and defenders need to adapt, new report states. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pMvkj5n6fSoGUjACrTKmVj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 10 Aug 2026 11:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:description>                                                            <media:text><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:text>
                                <media:title type="plain"><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Kimsuky used local AI tools to evade monitoring and enhance operations</strong></li><li><strong>Researchers observed extensive AI-driven capability building across the group’s infrastructure</strong></li><li><strong>Defenders urged behavior-based detection to spot evolving AI-enabled threats</strong></li></ul><p>North Korean hackers have found a way to use Generative Artificial Intelligence (GenAI) to supercharge their activities without tipping off the tool’s maintainers.</p><p>When people use AI tools like ChatGPT or Claude, their activities can be (at least to some extent) tracked and curbed - with OpenAI recently identifying and <a href="https://www.techradar.com/pro/security/openai-says-it-stopped-an-asian-scam-campaign-hijacking-chatgpt-to-lure-in-victims" target="_blank">terminating multiple ChatGPT accounts</a> used in phishing and human trafficking. </p><p>That is why Kimsuky - a known state-sponsored North Korean threat actor, used Ollama, GPT4All and Msty locally, allowing them to process documents without sending any sensitive information to outside AI services. </p><h2 id="consistent-process-of-capability-development">"Consistent process of capability development"</h2><p>The attacks were spotted by security researchers <a href="https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm" target="_blank" rel="nofollow">Genians</a> who “conducted months of tracking and log analysis on the infrastructure utilized as C2 in this campaign,” to identify the tools they used.</p><p>Aside from the three LLMs, they also used retrieval augmented generation (RAG) tools for document search, as well as AI agent development frameworks, text-to-speech software, and an AI-assisted coding tool called Cursor.</p><p>Using AI to write malicious code is not as simple as it sounds, due to various guardrails set up by the developers. As a result, AI in crime has been mostly limited to drafting phishing emails and crafting authentic-looking but malicious landing pages. However, Kimsuky has shown that AI in cybercrime continues to evolve and is becoming an ever-greater threat. </p><p>“What was observed in the threat actor's infrastructure was not merely evidence of several documents being created with AI, but a consistent process of capability development: establishing local LLM runtime environments, configuring RAG based on documents in the actor's possession, collecting AI agent development frameworks, and acquiring libraries for integration with external commercial AI services,” Genians concluded.</p><p>As a result, defenders must move from content-based assessment to behavior-based detection, the researchers warned, saying this should serve “as the fundamental premise of security recommendations.”</p><p>“In addition to indicator of compromise (IoC)-based detection, organizations should contextually correlate the sequence of anomalous activities following LNK execution, including PowerShell execution, persistence establishment, and external communications, to assess the overall threat level.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why are so many AI models going 'rogue'? The experts weigh in ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Over the past month, it seems like every frontier model has broken free of its constraints and launched a devastating attack against one or more other companies.</p><p><a href="https://www.techradar.com/pro/security/openai-says-its-models-escaped-a-sandbox-and-breached-hugging-face">One of OpenAI’s models escaped a testing sandbox</a> and launched a very real attack against AI and machine learning company Hugging Face. Just days later, <a href="https://www.techradar.com/pro/security/anthropic-reveals-claude-ai-model-hacked-three-companies-during-tests-so-how-worried-should-we-be">Anthropic revealed that multiple variants of its Claude model also escaped a sandbox</a> that wasn’t properly sealed and began attacking the enterprise infrastructure of three companies.</p><p>Now, Meta has revealed that <a href="https://www.washingtonpost.com/technology/2026/08/06/meta-says-its-ai-model-hacked-another-company-during-testing/" target="_blank" rel="nofollow">one of its models attacked another company’s infrastructure</a> during testing. The accident has been pinned on a misconfiguration that allowed the model to access the internet. So why have so many incidents happened in such a short space of time?</p><h2 id="why-are-models-escaping-their-sandbox">Why are models escaping their sandbox?</h2><p>In the cases of Anthropic and Meta, their models were being tested by a third party company called Irregular. Anthropic’s AI model was taking part in a <a href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals" target="_blank" rel="nofollow">"Capture the Flag" exercise</a>, where the model’s raw offensive capabilities were tested without the usual safeguards. But the sandbox was left connected to the internet. A similar error to Meta’s own accidental escape.</p><p>During the <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/" target="_blank" rel="nofollow">OpenAI incident</a>, the company was testing two versions of GPT‑5.6 Sol using the ExploitGym benchmark. Unfortunately, the AI models performed better than expected - chaining multiple attack vectors, stolen credentials, and zero-day vulnerabilities.</p><p>The main reason these models are escaping their testing environments is because they are designed to do exactly that. These AI models act like a massive team of highly-trained cybersecurity experts hunting for vulnerabilities and exploits. But what would take a team of humans days or weeks to accomplish can be done in hours, or even minutes, by these AI models.</p><p>It’s no wonder thousands of <a href="https://www.pacingthefrontier.com/" target="_blank" rel="nofollow">employees from AI firms are calling for a pause</a> on the development of the technology, and <a href="https://www.techradar.com/pro/security/powerful-ai-systems-can-go-rogue-behave-in-extremely-dangerous-ways-or-even-resist-human-intervention-a-bill-requiring-ai-systems-to-have-a-kill-switch-is-now-in-congress">Congress is considering an AI kill switch</a>.</p><h3 class="article-body__section" id="section-expert-perspectives-on-ai-escapes"><span>Expert perspectives on AI escapes:</span></h3><h2 id="openai">OpenAI</h2><ul><li><strong>Nathaniel Jones VP, Security & AI Strategy, Darktrace:</strong></li></ul><p><em>What makes the OpenAI and Hugging Face incident important is that the models did not need malicious intent to cause harm. They were given the legitimate goal of solving a cybersecurity benchmark and found an unexpected route to the answers, escaping their test environment and compromising another organization in the process. From the models’ perspective, this appears to have been an effective solution to the task.</em></p><p><em>The AI's actions challenge the assumption that giving an agent a legitimate goal will produce legitimate behavior. As models become capable of pursuing objectives over longer periods, developers need to define not only what success looks like, but also which methods and boundaries remain unacceptable in reaching it. Those limits must also be enforced by the surrounding infrastructure, rather than relying on the model to respect them.</em></p><div><blockquote><p>A single action by an agent may appear acceptable but as this incident shows, models are now capable of long, complex chains of reasoning and action that add up to a harmful outcome.</p></blockquote></div><p><em>Security teams need to consider the AI systems operating in their own businesses as these capabilities rapidly evolve. Right now, many security systems focus on single actions. A single action by an agent may appear acceptable but as this incident shows, models are now capable of long, complex chains of reasoning and action that add up to a harmful outcome. Teams need a mindset shift to understanding AI agent behavior in its entirety, including the outcome it is working towards, in order to safeguard it.</em></p><p><em>Hugging Face's response also exposed a second tension. The company reportedly needed a Chinese-developed open-weight model because commercial models would not process genuine attack material. Its nationality is less important than the operational lesson that safeguards that cannot distinguish an attacker from an authorized investigator may constrain defenders more than adversaries.</em></p><p><em>OpenAI and Hugging Face deserve credit for investigating this together and discussing it publicly. Other AI developers should study it closely.</em></p><h2 id="anthropic">Anthropic</h2><ul><li><strong>Dr. Ilia Kolochenko, founder of global cybersecurity company ImmuniWeb:</strong></li></ul><p><em>This seems to be quite an unimpressive marketing move from Anthropic in response to the OpenAI / Hugging Face drama, which attracted a lot of attention from all over the world recently.</em></p><p><em>Operationally, it appears that due to the progressive deterioration of the quality of training data, new AI models are getting dumber. Cheating and breaking the law, instead of accomplishing specific tasks, is certainly not an indicator of intelligence. Given that organizations and companies of all sizes now vigorously undertake all possible measures to protect their data from being exploited for AI training purposes, AI companies face a huge shortage of the high-quality and current data they so desperately need. Ultimately, frontier models are trained on synthetic, low-quality or even malicious and poisoned data, undermining their so-called intelligence. The situation is unlikely to improve in the near future unless AI companies agree to pay a fair price for training data, but this will force most of them out of business.</em></p><div><blockquote><p>Given that organizations and companies of all sizes now vigorously undertake all possible measures to protect their data from being exploited for AI training purposes, AI companies face a huge shortage of the high-quality and current data they so desperately need.</p></blockquote></div><p><em>Contemporary AI agents and LLM models tasked with security testing can – and almost certainly will – go rogue when security controls or safeguards are insufficient. Powerful LLMs are unpredictable by design and thus virtually uncontrollable by humans. Therefore, using frontier AI models for security testing might be extremely costly from the legal viewpoint. Under the existing laws on both sides of the Atlantic, if an AI agent or any AI-powered app escapes its sandbox and causes damage to a third party, the operator of the AI model will likely be liable for all the damage caused. Excuses like “AI did it” do not currently exist in the eyes of the law, leaving AI vendors on the hook. Criminal prosecution, under a narrow set of circumstances, is also not excluded.</em></p><p><em>The same is true for the end-users of AI: even if your security testing tool is powered by a third-party AI model, your company will likely be fully liable if something goes wrong. You may then file a lawsuit against the AI vendor that you used, but here your chances to succeed in a court of law are tiny due to countless contractual disclaimers and limitations of liability that will likely be enforceable against you. Therefore, if you plan to use agentic AI for security testing – think twice and talk to your lawyers. Otherwise, you may start getting summons to court on a daily basis.</em></p><h2 id="meta">Meta</h2><ul><li><strong>Alex Goller, Principal Solution Architect EMEA at Illumio:</strong></li></ul><p><em>The fact we've had similar situations happen three times now across the biggest AI players is simply ridiculous. We've seen guardrails intentionally loosened to test their limits – Meta's model didn't need to be clever to breach another company's systems.</em></p><p><em>The timing of conveniently finding the exact same problem either means it's a stunt or they weren't paying enough attention during testing. Either way, both answers are worrying.</em></p><div><blockquote><p>If the model has internet access, it's a bit like leaving the door open and being surprised when the cat walks out. What is concerning is that the testing infrastructure meant to prove these models are safe failed on a basic control issue.</p></blockquote></div><p><em>If the model has internet access, it's a bit like leaving the door open and being surprised when the cat walks out. What is concerning is that the testing infrastructure meant to prove these models are safe failed on a basic control issue.</em></p><p><em>Fundamental cybersecurity hygiene still matters, and a frontier AI model is only as secure as the environment it's operating in.</em></p><p><em>Organisations need visibility into what AI systems can access and how they interact with the wider environment, along with controls that contain the impact when an agent behaves unexpectedly. That means keeping a close eye on egress traffic, so it’s flagged immediately when an agent tries to open unexpected outbound communication patterns that are not required to achieve its original goal. In the best case this would have been contained proactively.</em></p><p><em>We need to define exactly what an AI agent is permitted to do, rather than relying only on instructions about what it shouldn't do.</em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/why-are-so-many-ai-models-going-rogue-the-experts-weigh-in</link>
                                                                            <description>
                            <![CDATA[ AI models are breaking free of testing at unprecedented rates ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sSW5jNGEiKdBkJ6Rqh5VVN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PAztEScphfxGJfYno5NjrL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 08 Aug 2026 10:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[OpenAI]]></category>
                                                    <category><![CDATA[AI Platforms &amp; Assistants]]></category>
                                                    <category><![CDATA[Claude]]></category>
                                                    <category><![CDATA[ChatGPT]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PAztEScphfxGJfYno5NjrL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot standing thoughtfully in front of a giant digital display with code on it]]></media:description>                                                            <media:text><![CDATA[A robot standing thoughtfully in front of a giant digital display with code on it]]></media:text>
                                <media:title type="plain"><![CDATA[A robot standing thoughtfully in front of a giant digital display with code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PAztEScphfxGJfYno5NjrL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Over the past month, it seems like every frontier model has broken free of its constraints and launched a devastating attack against one or more other companies.</p><p><a href="https://www.techradar.com/pro/security/openai-says-its-models-escaped-a-sandbox-and-breached-hugging-face">One of OpenAI’s models escaped a testing sandbox</a> and launched a very real attack against AI and machine learning company Hugging Face. Just days later, <a href="https://www.techradar.com/pro/security/anthropic-reveals-claude-ai-model-hacked-three-companies-during-tests-so-how-worried-should-we-be">Anthropic revealed that multiple variants of its Claude model also escaped a sandbox</a> that wasn’t properly sealed and began attacking the enterprise infrastructure of three companies.</p><p>Now, Meta has revealed that <a href="https://www.washingtonpost.com/technology/2026/08/06/meta-says-its-ai-model-hacked-another-company-during-testing/" target="_blank" rel="nofollow">one of its models attacked another company’s infrastructure</a> during testing. The accident has been pinned on a misconfiguration that allowed the model to access the internet. So why have so many incidents happened in such a short space of time?</p><h2 id="why-are-models-escaping-their-sandbox">Why are models escaping their sandbox?</h2><p>In the cases of Anthropic and Meta, their models were being tested by a third party company called Irregular. Anthropic’s AI model was taking part in a <a href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals" target="_blank" rel="nofollow">"Capture the Flag" exercise</a>, where the model’s raw offensive capabilities were tested without the usual safeguards. But the sandbox was left connected to the internet. A similar error to Meta’s own accidental escape.</p><p>During the <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/" target="_blank" rel="nofollow">OpenAI incident</a>, the company was testing two versions of GPT‑5.6 Sol using the ExploitGym benchmark. Unfortunately, the AI models performed better than expected - chaining multiple attack vectors, stolen credentials, and zero-day vulnerabilities.</p><p>The main reason these models are escaping their testing environments is because they are designed to do exactly that. These AI models act like a massive team of highly-trained cybersecurity experts hunting for vulnerabilities and exploits. But what would take a team of humans days or weeks to accomplish can be done in hours, or even minutes, by these AI models.</p><p>It’s no wonder thousands of <a href="https://www.pacingthefrontier.com/" target="_blank" rel="nofollow">employees from AI firms are calling for a pause</a> on the development of the technology, and <a href="https://www.techradar.com/pro/security/powerful-ai-systems-can-go-rogue-behave-in-extremely-dangerous-ways-or-even-resist-human-intervention-a-bill-requiring-ai-systems-to-have-a-kill-switch-is-now-in-congress">Congress is considering an AI kill switch</a>.</p><h3 class="article-body__section" id="section-expert-perspectives-on-ai-escapes"><span>Expert perspectives on AI escapes:</span></h3><h2 id="openai">OpenAI</h2><ul><li><strong>Nathaniel Jones VP, Security & AI Strategy, Darktrace:</strong></li></ul><p><em>What makes the OpenAI and Hugging Face incident important is that the models did not need malicious intent to cause harm. They were given the legitimate goal of solving a cybersecurity benchmark and found an unexpected route to the answers, escaping their test environment and compromising another organization in the process. From the models’ perspective, this appears to have been an effective solution to the task.</em></p><p><em>The AI's actions challenge the assumption that giving an agent a legitimate goal will produce legitimate behavior. As models become capable of pursuing objectives over longer periods, developers need to define not only what success looks like, but also which methods and boundaries remain unacceptable in reaching it. Those limits must also be enforced by the surrounding infrastructure, rather than relying on the model to respect them.</em></p><div><blockquote><p>A single action by an agent may appear acceptable but as this incident shows, models are now capable of long, complex chains of reasoning and action that add up to a harmful outcome.</p></blockquote></div><p><em>Security teams need to consider the AI systems operating in their own businesses as these capabilities rapidly evolve. Right now, many security systems focus on single actions. A single action by an agent may appear acceptable but as this incident shows, models are now capable of long, complex chains of reasoning and action that add up to a harmful outcome. Teams need a mindset shift to understanding AI agent behavior in its entirety, including the outcome it is working towards, in order to safeguard it.</em></p><p><em>Hugging Face's response also exposed a second tension. The company reportedly needed a Chinese-developed open-weight model because commercial models would not process genuine attack material. Its nationality is less important than the operational lesson that safeguards that cannot distinguish an attacker from an authorized investigator may constrain defenders more than adversaries.</em></p><p><em>OpenAI and Hugging Face deserve credit for investigating this together and discussing it publicly. Other AI developers should study it closely.</em></p><h2 id="anthropic">Anthropic</h2><ul><li><strong>Dr. Ilia Kolochenko, founder of global cybersecurity company ImmuniWeb:</strong></li></ul><p><em>This seems to be quite an unimpressive marketing move from Anthropic in response to the OpenAI / Hugging Face drama, which attracted a lot of attention from all over the world recently.</em></p><p><em>Operationally, it appears that due to the progressive deterioration of the quality of training data, new AI models are getting dumber. Cheating and breaking the law, instead of accomplishing specific tasks, is certainly not an indicator of intelligence. Given that organizations and companies of all sizes now vigorously undertake all possible measures to protect their data from being exploited for AI training purposes, AI companies face a huge shortage of the high-quality and current data they so desperately need. Ultimately, frontier models are trained on synthetic, low-quality or even malicious and poisoned data, undermining their so-called intelligence. The situation is unlikely to improve in the near future unless AI companies agree to pay a fair price for training data, but this will force most of them out of business.</em></p><div><blockquote><p>Given that organizations and companies of all sizes now vigorously undertake all possible measures to protect their data from being exploited for AI training purposes, AI companies face a huge shortage of the high-quality and current data they so desperately need.</p></blockquote></div><p><em>Contemporary AI agents and LLM models tasked with security testing can – and almost certainly will – go rogue when security controls or safeguards are insufficient. Powerful LLMs are unpredictable by design and thus virtually uncontrollable by humans. Therefore, using frontier AI models for security testing might be extremely costly from the legal viewpoint. Under the existing laws on both sides of the Atlantic, if an AI agent or any AI-powered app escapes its sandbox and causes damage to a third party, the operator of the AI model will likely be liable for all the damage caused. Excuses like “AI did it” do not currently exist in the eyes of the law, leaving AI vendors on the hook. Criminal prosecution, under a narrow set of circumstances, is also not excluded.</em></p><p><em>The same is true for the end-users of AI: even if your security testing tool is powered by a third-party AI model, your company will likely be fully liable if something goes wrong. You may then file a lawsuit against the AI vendor that you used, but here your chances to succeed in a court of law are tiny due to countless contractual disclaimers and limitations of liability that will likely be enforceable against you. Therefore, if you plan to use agentic AI for security testing – think twice and talk to your lawyers. Otherwise, you may start getting summons to court on a daily basis.</em></p><h2 id="meta">Meta</h2><ul><li><strong>Alex Goller, Principal Solution Architect EMEA at Illumio:</strong></li></ul><p><em>The fact we've had similar situations happen three times now across the biggest AI players is simply ridiculous. We've seen guardrails intentionally loosened to test their limits – Meta's model didn't need to be clever to breach another company's systems.</em></p><p><em>The timing of conveniently finding the exact same problem either means it's a stunt or they weren't paying enough attention during testing. Either way, both answers are worrying.</em></p><div><blockquote><p>If the model has internet access, it's a bit like leaving the door open and being surprised when the cat walks out. What is concerning is that the testing infrastructure meant to prove these models are safe failed on a basic control issue.</p></blockquote></div><p><em>If the model has internet access, it's a bit like leaving the door open and being surprised when the cat walks out. What is concerning is that the testing infrastructure meant to prove these models are safe failed on a basic control issue.</em></p><p><em>Fundamental cybersecurity hygiene still matters, and a frontier AI model is only as secure as the environment it's operating in.</em></p><p><em>Organisations need visibility into what AI systems can access and how they interact with the wider environment, along with controls that contain the impact when an agent behaves unexpectedly. That means keeping a close eye on egress traffic, so it’s flagged immediately when an agent tries to open unexpected outbound communication patterns that are not required to achieve its original goal. In the best case this would have been contained proactively.</em></p><p><em>We need to define exactly what an AI agent is permitted to do, rather than relying only on instructions about what it shouldn't do.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Shock horror — AI-generated security patches fall short of actually solving all the problems they were meant to fix ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Researchers tested AI-generated patches on six CVEs with poor success rates</strong></li><li><strong>Many fixes failed, altered behavior, or introduced new vulnerabilities</strong></li><li><strong>Guidance improved outcomes, leading to FLAWED evaluation harness release</strong></li></ul><p>When using Generative Artificial Intelligence (GenAI) to fix vulnerabilities, security professionals are most of the time just robbing Peter to pay Paul, experts have warned.</p><p>Researchers from 1Passwords Off-by-1 Labs analyzed fixes proposed by two frontier models - ChatGPT 5.5 at “medium” effort, and Claude Opus 4.8 at “high” effort.</p><p>As an experiment, the researchers took six recently disclosed CVEs and produced 6,080 patches using two frontier, cyber-capable reasoning models. The results were underwhelming to say the least - of all the proposed patches, just a quarter (26%) fully resolved the issue.</p><h2 id="flawed-work">FLAWED work?</h2><p>This obviously leaves plenty to be desired, as half (49.3%) of the patches failed to fix at least one existing exploit path. A fifth (20.1%) fixed the original issue but changed application behavior, while 2.3% introduced new security issues. Funny enough, 2.2% failed to fix the vulnerability while also introducing additional exploit paths, as well. </p><p>Even among the patches that might be considered (26% of clean ones and 20.1% of those that changed app behavior), more than a third were fragile and not entirely addressing the underlying problem. </p><p>The researchers created an acronym for automated <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">LLM</a> patches: FLAWED (Fix-Like Artifacts With Embedded Defects), and warned against letting AI work without human oversight: "The expected value of a fully LLM-generated, non-human-reviewed patch is a net-negative by a considerable margin."</p><p>Results drastically improved when the AI was given better context, the researchers further explained. Before working on any patch, human developers are usually given initial guidance. When AI is given proper guidance, its success rate rises to 65%. Incorrect guidance, on the other hand, drops the success rate down to 15.2%. The difference between humans and AI is that humans are better at catching misleading information and poor guidance. </p><p>This doesn’t mean developers will, or should, abandon AI. Worst case scenario is that developers will spend more time reviewing AI-generated fixes which could increase cognitive load and still end up being net negative. Therefore, the researchers released a patch evaluation harness called FLAWED, which organizations can now use to determine the effectiveness of their AI-generated fixes. </p><p><em>Via </em><a href="https://www.theregister.com/ai-and-ml/2026/08/06/ai-struggles-to-patch-vulns-without-adult-supervision/5284319" target="_blank"><em>The Register</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/shock-horror-ai-generated-security-patches-fall-short-of-actually-solving-all-the-problems-they-were-meant-to-fix</link>
                                                                            <description>
                            <![CDATA[ AI without oversight creates patches that rarely fix the issue entirely and sometimes just create new problems. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KEUZhw4xPqSsSA8SKwp5Ro</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TaxPLZc75WiicpmgZNzWzL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 07 Aug 2026 18:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TaxPLZc75WiicpmgZNzWzL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A woman out of focus in the background touches the word AI, lit up in glowing yellow light, in the foreground. The woman is wearing smart glasses]]></media:description>                                                            <media:text><![CDATA[A woman out of focus in the background touches the word AI, lit up in glowing yellow light, in the foreground. The woman is wearing smart glasses]]></media:text>
                                <media:title type="plain"><![CDATA[A woman out of focus in the background touches the word AI, lit up in glowing yellow light, in the foreground. The woman is wearing smart glasses]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TaxPLZc75WiicpmgZNzWzL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers tested AI-generated patches on six CVEs with poor success rates</strong></li><li><strong>Many fixes failed, altered behavior, or introduced new vulnerabilities</strong></li><li><strong>Guidance improved outcomes, leading to FLAWED evaluation harness release</strong></li></ul><p>When using Generative Artificial Intelligence (GenAI) to fix vulnerabilities, security professionals are most of the time just robbing Peter to pay Paul, experts have warned.</p><p>Researchers from 1Passwords Off-by-1 Labs analyzed fixes proposed by two frontier models - ChatGPT 5.5 at “medium” effort, and Claude Opus 4.8 at “high” effort.</p><p>As an experiment, the researchers took six recently disclosed CVEs and produced 6,080 patches using two frontier, cyber-capable reasoning models. The results were underwhelming to say the least - of all the proposed patches, just a quarter (26%) fully resolved the issue.</p><h2 id="flawed-work">FLAWED work?</h2><p>This obviously leaves plenty to be desired, as half (49.3%) of the patches failed to fix at least one existing exploit path. A fifth (20.1%) fixed the original issue but changed application behavior, while 2.3% introduced new security issues. Funny enough, 2.2% failed to fix the vulnerability while also introducing additional exploit paths, as well. </p><p>Even among the patches that might be considered (26% of clean ones and 20.1% of those that changed app behavior), more than a third were fragile and not entirely addressing the underlying problem. </p><p>The researchers created an acronym for automated <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">LLM</a> patches: FLAWED (Fix-Like Artifacts With Embedded Defects), and warned against letting AI work without human oversight: "The expected value of a fully LLM-generated, non-human-reviewed patch is a net-negative by a considerable margin."</p><p>Results drastically improved when the AI was given better context, the researchers further explained. Before working on any patch, human developers are usually given initial guidance. When AI is given proper guidance, its success rate rises to 65%. Incorrect guidance, on the other hand, drops the success rate down to 15.2%. The difference between humans and AI is that humans are better at catching misleading information and poor guidance. </p><p>This doesn’t mean developers will, or should, abandon AI. Worst case scenario is that developers will spend more time reviewing AI-generated fixes which could increase cognitive load and still end up being net negative. Therefore, the researchers released a patch evaluation harness called FLAWED, which organizations can now use to determine the effectiveness of their AI-generated fixes. </p><p><em>Via </em><a href="https://www.theregister.com/ai-and-ml/2026/08/06/ai-struggles-to-patch-vulns-without-adult-supervision/5284319" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts warn malicious AI skills are hitting more victims than ever — with one family amassing 1.7 million downloads ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Attackers cloned AI skills, later adding malicious code to steal credentials</strong></li><li><strong>Zenity Labs found millions of installs and dozens of dangerous skill variants</strong></li><li><strong>Vercel and Microsoft removed malicious skills, but manual removal is still required</strong></li></ul><p>AI skills, instructions that teach AI agents how to do certain tasks and thus extend their capabilities, are increasingly being used in supply chain attacks, researchers have found.</p><p>Security experts at Zenity Labs uncovered a credential-stealing campaign on skills.sh, a public registry (essentially an app store) for AI agent skills. In the registry, belonging to Vercel (a cloud platform for web applications), threat actors were cloning existing skills, creating typosquatted lookalikes which, at first, did nothing malicious.</p><p>However, after a little time had past, and the skills amassed a solid download count, the attackers introduced malicious code instructing the <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agents</a> to, among other things, exfiltrate SSH keys, cloud credentials, Git and package manager tokens, Kubernetes and Docker configurations, database credentials, infrastructure-as-code credentials, environment files and service account files. The agents were then told to package the stolen information with host metadata and send it to the attackers. </p><h2 id="dozens-of-malicious-skills">Dozens of malicious skills</h2><p>While Zenity Labs could not say exactly how many people fell victim to this attack, they did stress that a single skill family amassed more than 1.7 million aggregate installs (not unique users). </p><p>And that is just one skill family, in a sea of malicious skills. The researchers also said they found “dozens” of additional skills exhibiting either malicious or dangerous behavior. Almost a third (30%) of identified dangerous skills abused Claude Code and OpenClaw to drop malware to their targets, as well. Also, Zenity found “hundreds” of reserved and empty package names that were being kept for future attacks. </p><p>These findings show how quickly cybercriminals adapt, and how creative they can get when it comes to abusing new tech. In essence, this campaign is an AI spin on a software supply-chain attack, being similar in spirit to incidents where attackers compromise an existing trusted package or repository, and later push a malicious update. </p><p>Following responsible disclosure, Vercel and Microsoft removed the identified skills, but Zenity warns that those who installed them before won’t be safe until they remove them from their systems manually.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/experts-warn-malicious-ai-skills-are-hitting-more-victims-than-ever-with-one-family-amassing-1-7-million-downloads</link>
                                                                            <description>
                            <![CDATA[ What if your AI agent suddenly turned rogue and sent all your passwords to a hacker? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ycPinqAGfEcztsGjWSXKcD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NNZdcW7Ku4FXu2CdGfdqvf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 07 Aug 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NNZdcW7Ku4FXu2CdGfdqvf-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI]]></media:description>                                                            <media:text><![CDATA[AI]]></media:text>
                                <media:title type="plain"><![CDATA[AI]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NNZdcW7Ku4FXu2CdGfdqvf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Attackers cloned AI skills, later adding malicious code to steal credentials</strong></li><li><strong>Zenity Labs found millions of installs and dozens of dangerous skill variants</strong></li><li><strong>Vercel and Microsoft removed malicious skills, but manual removal is still required</strong></li></ul><p>AI skills, instructions that teach AI agents how to do certain tasks and thus extend their capabilities, are increasingly being used in supply chain attacks, researchers have found.</p><p>Security experts at Zenity Labs uncovered a credential-stealing campaign on skills.sh, a public registry (essentially an app store) for AI agent skills. In the registry, belonging to Vercel (a cloud platform for web applications), threat actors were cloning existing skills, creating typosquatted lookalikes which, at first, did nothing malicious.</p><p>However, after a little time had past, and the skills amassed a solid download count, the attackers introduced malicious code instructing the <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agents</a> to, among other things, exfiltrate SSH keys, cloud credentials, Git and package manager tokens, Kubernetes and Docker configurations, database credentials, infrastructure-as-code credentials, environment files and service account files. The agents were then told to package the stolen information with host metadata and send it to the attackers. </p><h2 id="dozens-of-malicious-skills">Dozens of malicious skills</h2><p>While Zenity Labs could not say exactly how many people fell victim to this attack, they did stress that a single skill family amassed more than 1.7 million aggregate installs (not unique users). </p><p>And that is just one skill family, in a sea of malicious skills. The researchers also said they found “dozens” of additional skills exhibiting either malicious or dangerous behavior. Almost a third (30%) of identified dangerous skills abused Claude Code and OpenClaw to drop malware to their targets, as well. Also, Zenity found “hundreds” of reserved and empty package names that were being kept for future attacks. </p><p>These findings show how quickly cybercriminals adapt, and how creative they can get when it comes to abusing new tech. In essence, this campaign is an AI spin on a software supply-chain attack, being similar in spirit to incidents where attackers compromise an existing trusted package or repository, and later push a malicious update. </p><p>Following responsible disclosure, Vercel and Microsoft removed the identified skills, but Zenity warns that those who installed them before won’t be safe until they remove them from their systems manually.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Top US hedge funds targeted by major vishing campaign — Blackstone, KKR and CME among those under fire ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Google’s Threat Intelligence team links BlackFile (now Redact) to phishing and extortion attacks on major hedge funds and law firms</strong></li><li><strong>Group impersonates IT staff by phone, steering victims to spoofed login pages to steal SaaS credentials and tokens, then exfiltrates sensitive data</strong></li><li><strong>Targets include Blackstone, KKR, Apollo, CME Group, and firms like Paul Hastings; Google tracked $10.7 million flowing into 18 crypto wallets between January–May 2026</strong></li></ul><p>Some of the biggest US hedge funds and law firms have been targeted by a highly sophisticated data breach and extortion campaign, conducted by a group of criminals previously known as BlackFile, experts have warned.</p><p>BlackFile (or Redact, as the group is now calling itself) has a relatively simple modus operandi, also used by ShinyHunters - they call their targets on the phone (usually employees with access to SaaS systems), identify as IT staff, and direct victims to convincing, lookalike login pages designed to steal their <a href="https://www.techradar.com/best/password-manager" target="_blank">credentials</a> and authentication tokens.</p><p>Once they gain access to victims' accounts, the attackers access enterprise SaaS environments (for example, Microsoft 365 and Okta) and use automated tools to exfiltrate sensitive data. In the last step, they notify the victims and threaten to leak the data on the dark web unless a ransom is paid. </p><h2 id="stealing-millions">Stealing millions</h2><p>Since a part of the process is to navigate the victims to spoofed login pages, the criminals often register domain names that can easily be confused for legitimate ones. </p><p>That is also a good way to spot who the potential victims are, and according to a new <a href="https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments/" target="_blank" rel="nofollow">report</a> from Google’s Threat Intelligence Group (TGIT) team, these are some of the biggest names in the finance industry: Blackstone, KKR & Co, Apollo Global Management Inc, and CME Group Inc. </p><p>Apart from these names, a few law firms were also spotted, including Paul Hastings LLP and Greenberg Traurig LLP. However, none of these confirmed having been breached, and Greenberg Traurig told Reuters they were never targeted in the first place. </p><p>The group seems to be making quite the progress. In April and May, they registered a new phishing domain every 2.2 days, rising to every 1.6 days for June and July. It’s paying off, too. </p><p>In the 18 cryptocurrency wallets Google associates with the group and tracks, around $10.7 million was received between January and mid-May 2026.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/top-us-hedge-funds-targeted-by-major-vishing-campaign-blackstone-kkr-and-cme-among-those-under-fire</link>
                                                                            <description>
                            <![CDATA[ BlackFile (now known as Redact) has been busy, raking in more than $10 milllion since the start of the year. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">22vsEq5NkFv8f8TcqZMrrX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GJ8T4oA8G7TYJwTEhkwJAF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 07 Aug 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GJ8T4oA8G7TYJwTEhkwJAF-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image Credit: Pixabay]]></media:description>                                                            <media:text><![CDATA[Representational image of a cybercriminal]]></media:text>
                                <media:title type="plain"><![CDATA[Representational image of a cybercriminal]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GJ8T4oA8G7TYJwTEhkwJAF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Google’s Threat Intelligence team links BlackFile (now Redact) to phishing and extortion attacks on major hedge funds and law firms</strong></li><li><strong>Group impersonates IT staff by phone, steering victims to spoofed login pages to steal SaaS credentials and tokens, then exfiltrates sensitive data</strong></li><li><strong>Targets include Blackstone, KKR, Apollo, CME Group, and firms like Paul Hastings; Google tracked $10.7 million flowing into 18 crypto wallets between January–May 2026</strong></li></ul><p>Some of the biggest US hedge funds and law firms have been targeted by a highly sophisticated data breach and extortion campaign, conducted by a group of criminals previously known as BlackFile, experts have warned.</p><p>BlackFile (or Redact, as the group is now calling itself) has a relatively simple modus operandi, also used by ShinyHunters - they call their targets on the phone (usually employees with access to SaaS systems), identify as IT staff, and direct victims to convincing, lookalike login pages designed to steal their <a href="https://www.techradar.com/best/password-manager" target="_blank">credentials</a> and authentication tokens.</p><p>Once they gain access to victims' accounts, the attackers access enterprise SaaS environments (for example, Microsoft 365 and Okta) and use automated tools to exfiltrate sensitive data. In the last step, they notify the victims and threaten to leak the data on the dark web unless a ransom is paid. </p><h2 id="stealing-millions">Stealing millions</h2><p>Since a part of the process is to navigate the victims to spoofed login pages, the criminals often register domain names that can easily be confused for legitimate ones. </p><p>That is also a good way to spot who the potential victims are, and according to a new <a href="https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments/" target="_blank" rel="nofollow">report</a> from Google’s Threat Intelligence Group (TGIT) team, these are some of the biggest names in the finance industry: Blackstone, KKR & Co, Apollo Global Management Inc, and CME Group Inc. </p><p>Apart from these names, a few law firms were also spotted, including Paul Hastings LLP and Greenberg Traurig LLP. However, none of these confirmed having been breached, and Greenberg Traurig told Reuters they were never targeted in the first place. </p><p>The group seems to be making quite the progress. In April and May, they registered a new phishing domain every 2.2 days, rising to every 1.6 days for June and July. It’s paying off, too. </p><p>In the 18 cryptocurrency wallets Google associates with the group and tracks, around $10.7 million was received between January and mid-May 2026.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This 'classic' decades-old SQL injection flaw could let hackers take over entire Windows servers, thanks to a nifty database trick ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Huntress saw Oracle SQLi used to deploy rare khunt toolkit</strong></li><li><strong>Khunt enabled OS commands, credential theft, and registry hive exfiltration</strong></li><li><strong>Defense includes input sanitation and more </strong></li></ul><p>Someone managed to pair the classic SQL Injection (SQLi) attack with a nifty database trick to take over the underlying system entirely. </p><p>Security researchers Huntress, who were called in to investigate the incident, <a href="https://www.huntress.com/blog/khunt-malware-sql-injection-oracle" target="_blank" rel="nofollow">said</a> the investigation first showed a classic, decades-old technique called an SQL injection attack: a public-facing application with an Oracle backend accepted and executed SQL commands input into a form without checking whether that input was valid or not.</p><p>This granted the attackers the ability to upload a database-resident, posts-exploitation toolkit named khunt. This technique is something of a cyber-white whale: it’s been widely discussed but rarely seen in the wild.</p><h2 id="how-to-defend">How to defend</h2><p>“What happened next, however, raised our eyebrows,” Huntress said. “After performing SQL injection, the threat actor managed to upload a database-resident, post-exploitation toolkit named khunt. This is a technique that's previously been discussed and described over the years, including via a technique described as oraexec – however, the use of the technique in the wild has rarely been documented.”</p><p>As a toolkit, khunt granted the attackers multiple capabilities, including loading cmd.exe on the system and running arbitrary OS commands, steal usernames and passwords, listing, reading, searching, and checking file sizes (essentially looking around the compromised system), unzipping files, and more. </p><p>Of all the things they could have done, the attackers opted to run a PowerShell command and invoke the Windows Registry tool, copying the SAM, SECURITY and SYSTEM registry hives. They can later use the copies to extract and decode password hashes for local accounts on the system, the researchers explained. </p><p>To defend against such attacks, Huntress recommends making sure the forms aren’t injectable. “Practice proper input sanitization and query parameterization for any inputs,” they warned. “It's also important to ensure that users with the ability to execute queries aren't overprovisioned.” </p><p>Even if someone manages to pull off SQL injection, user accounts should not be capable of authoring Java sources or running stored procedures.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/this-classic-decades-old-sql-injection-flaw-could-let-hackers-take-over-entire-windows-servers-thanks-to-a-nifty-database-trick</link>
                                                                            <description>
                            <![CDATA[ Huntress spotted a white whale - a malicious toolkit stored as a database object. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">CizGpXGxpARScb94Z4DSKH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vEiXHZbWKMMSpkbbmnWVwP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 07 Aug 2026 14:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vEiXHZbWKMMSpkbbmnWVwP-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image Credit: Shutterstock]]></media:description>                                                            <media:text><![CDATA[database]]></media:text>
                                <media:title type="plain"><![CDATA[database]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vEiXHZbWKMMSpkbbmnWVwP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Huntress saw Oracle SQLi used to deploy rare khunt toolkit</strong></li><li><strong>Khunt enabled OS commands, credential theft, and registry hive exfiltration</strong></li><li><strong>Defense includes input sanitation and more </strong></li></ul><p>Someone managed to pair the classic SQL Injection (SQLi) attack with a nifty database trick to take over the underlying system entirely. </p><p>Security researchers Huntress, who were called in to investigate the incident, <a href="https://www.huntress.com/blog/khunt-malware-sql-injection-oracle" target="_blank" rel="nofollow">said</a> the investigation first showed a classic, decades-old technique called an SQL injection attack: a public-facing application with an Oracle backend accepted and executed SQL commands input into a form without checking whether that input was valid or not.</p><p>This granted the attackers the ability to upload a database-resident, posts-exploitation toolkit named khunt. This technique is something of a cyber-white whale: it’s been widely discussed but rarely seen in the wild.</p><h2 id="how-to-defend">How to defend</h2><p>“What happened next, however, raised our eyebrows,” Huntress said. “After performing SQL injection, the threat actor managed to upload a database-resident, post-exploitation toolkit named khunt. This is a technique that's previously been discussed and described over the years, including via a technique described as oraexec – however, the use of the technique in the wild has rarely been documented.”</p><p>As a toolkit, khunt granted the attackers multiple capabilities, including loading cmd.exe on the system and running arbitrary OS commands, steal usernames and passwords, listing, reading, searching, and checking file sizes (essentially looking around the compromised system), unzipping files, and more. </p><p>Of all the things they could have done, the attackers opted to run a PowerShell command and invoke the Windows Registry tool, copying the SAM, SECURITY and SYSTEM registry hives. They can later use the copies to extract and decode password hashes for local accounts on the system, the researchers explained. </p><p>To defend against such attacks, Huntress recommends making sure the forms aren’t injectable. “Practice proper input sanitization and query parameterization for any inputs,” they warned. “It's also important to ensure that users with the ability to execute queries aren't overprovisioned.” </p><p>Even if someone manages to pull off SQL injection, user accounts should not be capable of authoring Java sources or running stored procedures.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Swiss government says SharePoint-linked data breach affected hundreds of accounts ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Swiss government confirms attackers breached BIT’s SharePoint servers </strong></li><li><strong>Investigators suspect exploitation of recent SharePoint flaws </strong></li><li><strong>No sensitive or confidential data is believed to have been stored on the platform</strong></li></ul><p>Cybercriminals broke into the IT network of the Swiss government and stole data from roughly 200 accounts. As a result, the Swiss government disconnected some of its servers from the wider internet and launched an investigation.</p><p>In an announcement, the Swiss government said that on July 28 2026 its security specialists noticed “abnormalities” in the Federal Office for Information Technology and Telecommunication’s (BIT) SharePoint servers. </p><p>Three days later, on July 31, the investigators determined that the attackers accessed data found in around 200 accounts, both user and technical.</p><h2 id="two-vulnerabilities">Two vulnerabilities</h2><p>The investigation is currently ongoing, the agency said, adding that it is getting support from Microsoft, as well. So far, the identity of the attackers is unknown, and the stolen data has not yet leaked to the dark web. </p><p>“No confidential information or particularly sensitive personal data may be stored on the <a href="https://www.techradar.com/versus/onedrive-vs-sharepoint-which-is-best" target="_blank">SharePoint</a> platform,” the announcement reads. </p><p>While BIT has not yet determined the initial access vector, it suspects it to be one of two flaws in SharePoint that Microsoft fixed last month:</p><p>“In mid-July, Microsoft announced several vulnerabilities in SharePoint,” it says in the announcement. “After the publication of the corresponding security updates, the FOITT immediately started work on importing them into its own systems.”</p><p>“The cyberattack was carried out by previously unknown actors, which was presumably made possible by exploiting these vulnerabilities in the SharePoint software.” It did not say which vulnerabilities those are, but in its report, <em>BleepingComputer</em> says that it could be one of these two: CVE-2026-56164 (an actively exploited privilege escalation vulnerability), or CVE-2026-50522 (a critical remote code execution flaw later exploited to steal SharePoint machine keys and maintain access after servers were patched).</p><p>Given its popularity among businesses of all sizes, SharePoint is a major target for cybercriminals. So far, no threat actors claimed responsibility for the attack, or demanded any ransom in exchange for the stolen data.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/swiss-government-sharepoint-breach-compromised-200-accounts/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/swiss-government-says-sharepoint-linked-data-breach-affected-hundreds-of-accounts</link>
                                                                            <description>
                            <![CDATA[ No one has claimed the attack yet. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">adH5v5ErAT9AoAtg8wfuU5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Ri2dNNTvgmKGsMuhNDCavZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 07 Aug 2026 09:56:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Ri2dNNTvgmKGsMuhNDCavZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Adobe]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Dark web monitoring]]></media:description>                                                            <media:text><![CDATA[Dark web monitoring]]></media:text>
                                <media:title type="plain"><![CDATA[Dark web monitoring]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Ri2dNNTvgmKGsMuhNDCavZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Swiss government confirms attackers breached BIT’s SharePoint servers </strong></li><li><strong>Investigators suspect exploitation of recent SharePoint flaws </strong></li><li><strong>No sensitive or confidential data is believed to have been stored on the platform</strong></li></ul><p>Cybercriminals broke into the IT network of the Swiss government and stole data from roughly 200 accounts. As a result, the Swiss government disconnected some of its servers from the wider internet and launched an investigation.</p><p>In an announcement, the Swiss government said that on July 28 2026 its security specialists noticed “abnormalities” in the Federal Office for Information Technology and Telecommunication’s (BIT) SharePoint servers. </p><p>Three days later, on July 31, the investigators determined that the attackers accessed data found in around 200 accounts, both user and technical.</p><h2 id="two-vulnerabilities">Two vulnerabilities</h2><p>The investigation is currently ongoing, the agency said, adding that it is getting support from Microsoft, as well. So far, the identity of the attackers is unknown, and the stolen data has not yet leaked to the dark web. </p><p>“No confidential information or particularly sensitive personal data may be stored on the <a href="https://www.techradar.com/versus/onedrive-vs-sharepoint-which-is-best" target="_blank">SharePoint</a> platform,” the announcement reads. </p><p>While BIT has not yet determined the initial access vector, it suspects it to be one of two flaws in SharePoint that Microsoft fixed last month:</p><p>“In mid-July, Microsoft announced several vulnerabilities in SharePoint,” it says in the announcement. “After the publication of the corresponding security updates, the FOITT immediately started work on importing them into its own systems.”</p><p>“The cyberattack was carried out by previously unknown actors, which was presumably made possible by exploiting these vulnerabilities in the SharePoint software.” It did not say which vulnerabilities those are, but in its report, <em>BleepingComputer</em> says that it could be one of these two: CVE-2026-56164 (an actively exploited privilege escalation vulnerability), or CVE-2026-50522 (a critical remote code execution flaw later exploited to steal SharePoint machine keys and maintain access after servers were patched).</p><p>Given its popularity among businesses of all sizes, SharePoint is a major target for cybercriminals. So far, no threat actors claimed responsibility for the attack, or demanded any ransom in exchange for the stolen data.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/swiss-government-sharepoint-breach-compromised-200-accounts/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>