<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-SG"
                       href="https://www.techradar.com/sg/feeds/tag/malware"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from TechRadar SG in Malware ]]></title>
                <link>https://www.techradar.com/sg/tag/malware</link>
        <description><![CDATA[ All the latest malware content from the TechRadar  SG team ]]></description>
                                    <lastBuildDate>Thu, 10 Sep 2026 01:05:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Experts build WeChat worm able to spread across millions of iPhone and Android devices via phone calls ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Calif researchers found a zero‑click WeChat VoIP flaw enabling account takeover via calls</strong></li><li><strong>“WeWorm” spreads through ringing calls; victims need not answer to be compromised</strong></li><li><strong>Tencent patched in Android 8.0.77 and iOS 8.0.76; no exploitation seen in the wild</strong></li></ul><p>Security researchers have found a flaw in WeChat which allows malicious actors to take over people’s accounts on both Android and iOS devices - but what makes this flaw stand out is the fact that it’s a zero-click bug - victims need not do a thing to be compromised.</p><p>WeChat is a “super-app”, allegedly used by roughly 1.4 billion people, and is especially popular in China. It started as a communications app, letting users send messages, and make voice and video calls, and has evolved to function as a social network, allowing users to share photos and videos, as well as a payment app through which users can transfer money, pay for things, order food, book taxis, and even access government and business services.</p><p>Security researchers from Calif have now <a href="https://calif.io/research/weworm" target="_blank" rel="nofollow">disclosed</a> finding a ‘memory corruption’ issue in WeChat's VoIP stack. For now, they decided not to share the technical details, and to instead demonstrate the flaw “at an upcoming conference.” To that end, they built a worm called WeWorm, capable of taking over target WeChat accounts and spread through phone calls made via the app. </p><h2 id="a-phone-call-would-suffice">A phone call would suffice</h2><p>In practice, it works remarkably simple: an attacker uses WeChat to call a person they have in their contacts list (this is a prerequisite). They can use both an Android and an iOS device, and can call anyone, regardless of the model or the OS they’re using. As soon as the phone starts ringing, WeWorm gets to work, “worming” its way into the victim’s device.</p><p>The victim does not even need to answer the phone - having it ring is enough. If they answer, they’ll hear nothing but silence, yet the worm will continue operating. If they decline the call, the attack stops, but this is hardly a mitigation - the attacker can simply call again while the victim is asleep (or otherwise away from their device).</p><p>Within a few seconds, the attacker will have access to the victim’s WeChat account, including their messages, contacts list, and virtually anything else found in the app. What makes this bug particularly worrisome on the surface is the fact that WeChat can be used to transfer money and pay for things, but WeChat Pay has additional authentication and risk controls designed to prevent that from happening. </p><p>The good news is that there is no evidence of this flaw being exploited in the wild. The bad news is that this is not the first zero-click flaw found in modern-day smartphones, and most likely will not be the last one.</p><h2 id="tencent-39-s-response">Tencent's response</h2><p>Calif said it responsibly disclosed its findings to WeChat’s parent company Tencent, who came back with a patch. Versions 8.0.77 for Android and 8.0.76 for iOS have apparently solved the problem, although </p><p>Tencent did not list any details in its patch notes, simply saying the version brought “bug fixes”, but in a statement shared with <a href="https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html" target="_blank"><em>The Hacker News</em></a>, it said the exploit has been “mitigated for all users”, and that it was applied server-side - users need not install anything, aside from the patch. </p><p>It’s also worth mentioning that WeChat has apps for HarmonyOS, Windows, Mac, and Linux. However, it would appear that Calif did not test those, and Tencent did not include them in its patch. The researchers did say that they would be looking into this same flaw in other products, too: </p><p>“This specific WeChat bug is one instance of the many unconventional attack surfaces that are present across many messaging apps,” they said. “We're conducting more of this research across other apps and attack surfaces, while working with app developers on attack surface reduction. This may take an industry-wide effort, since some of it depends on the platform owners. Once that work is further along, we'll share our progress, including the technical details of this WeChat bug.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/experts-build-wechat-worm-able-to-spread-across-millions-of-iphone-and-android-devices-via-phone-calls</link>
                                                                            <description>
                            <![CDATA[ Your phone rings, and you're infected - with all of your contacts and messages exposed. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">L2NUxfetWUexVX4yvWWxJe</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2yHEj7RR9QpUSvzcPym7Vf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Sep 2026 01:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2yHEj7RR9QpUSvzcPym7Vf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Angry man shouting at mobile phone while sitting at a desk]]></media:description>                                                            <media:text><![CDATA[Angry man shouting at mobile phone while sitting at a desk]]></media:text>
                                <media:title type="plain"><![CDATA[Angry man shouting at mobile phone while sitting at a desk]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2yHEj7RR9QpUSvzcPym7Vf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Calif researchers found a zero‑click WeChat VoIP flaw enabling account takeover via calls</strong></li><li><strong>“WeWorm” spreads through ringing calls; victims need not answer to be compromised</strong></li><li><strong>Tencent patched in Android 8.0.77 and iOS 8.0.76; no exploitation seen in the wild</strong></li></ul><p>Security researchers have found a flaw in WeChat which allows malicious actors to take over people’s accounts on both Android and iOS devices - but what makes this flaw stand out is the fact that it’s a zero-click bug - victims need not do a thing to be compromised.</p><p>WeChat is a “super-app”, allegedly used by roughly 1.4 billion people, and is especially popular in China. It started as a communications app, letting users send messages, and make voice and video calls, and has evolved to function as a social network, allowing users to share photos and videos, as well as a payment app through which users can transfer money, pay for things, order food, book taxis, and even access government and business services.</p><p>Security researchers from Calif have now <a href="https://calif.io/research/weworm" target="_blank" rel="nofollow">disclosed</a> finding a ‘memory corruption’ issue in WeChat's VoIP stack. For now, they decided not to share the technical details, and to instead demonstrate the flaw “at an upcoming conference.” To that end, they built a worm called WeWorm, capable of taking over target WeChat accounts and spread through phone calls made via the app. </p><h2 id="a-phone-call-would-suffice">A phone call would suffice</h2><p>In practice, it works remarkably simple: an attacker uses WeChat to call a person they have in their contacts list (this is a prerequisite). They can use both an Android and an iOS device, and can call anyone, regardless of the model or the OS they’re using. As soon as the phone starts ringing, WeWorm gets to work, “worming” its way into the victim’s device.</p><p>The victim does not even need to answer the phone - having it ring is enough. If they answer, they’ll hear nothing but silence, yet the worm will continue operating. If they decline the call, the attack stops, but this is hardly a mitigation - the attacker can simply call again while the victim is asleep (or otherwise away from their device).</p><p>Within a few seconds, the attacker will have access to the victim’s WeChat account, including their messages, contacts list, and virtually anything else found in the app. What makes this bug particularly worrisome on the surface is the fact that WeChat can be used to transfer money and pay for things, but WeChat Pay has additional authentication and risk controls designed to prevent that from happening. </p><p>The good news is that there is no evidence of this flaw being exploited in the wild. The bad news is that this is not the first zero-click flaw found in modern-day smartphones, and most likely will not be the last one.</p><h2 id="tencent-39-s-response">Tencent's response</h2><p>Calif said it responsibly disclosed its findings to WeChat’s parent company Tencent, who came back with a patch. Versions 8.0.77 for Android and 8.0.76 for iOS have apparently solved the problem, although </p><p>Tencent did not list any details in its patch notes, simply saying the version brought “bug fixes”, but in a statement shared with <a href="https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html" target="_blank"><em>The Hacker News</em></a>, it said the exploit has been “mitigated for all users”, and that it was applied server-side - users need not install anything, aside from the patch. </p><p>It’s also worth mentioning that WeChat has apps for HarmonyOS, Windows, Mac, and Linux. However, it would appear that Calif did not test those, and Tencent did not include them in its patch. The researchers did say that they would be looking into this same flaw in other products, too: </p><p>“This specific WeChat bug is one instance of the many unconventional attack surfaces that are present across many messaging apps,” they said. “We're conducting more of this research across other apps and attack surfaces, while working with app developers on attack surface reduction. This may take an industry-wide effort, since some of it depends on the platform owners. Once that work is further along, we'll share our progress, including the technical details of this WeChat bug.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NordVPN warns AI is making scams more personal and devastating than ever ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>NordVPN blocked over 5 million malware attempts in January alone</strong></li><li><strong>99% of phishing attacks impersonate just 300 brands</strong></li><li><strong>AI tools and fraud kits mean attackers no longer need advanced skills</strong></li></ul><p>We are well past the days when a cyberattack meant mass-mailing a poorly spelled virus. In 2026, cybercriminals are heavily leveraging generative AI to make their scams highly personal, industrializing fraud on a massive scale.</p><p>That is the stark warning from the <a href="https://a-us.storyblok.com/f/1001711/x/e393e7f999/nordvpn-consumer-cybersecurity-report.pdf" target="_blank" rel="nofollow">Consumer Cybersecurity Report: Dismantling the Evolving Threat Landscape,</a> published today by <a href="https://www.techradar.com/reviews/nordvpn">NordVPN</a>. Analyzing threat intelligence data from the first half of the year, the prominent cybersecurity and <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> provider uncovered that the most exploited vulnerability right now isn't outdated software; it is human trust.</p><p>Armed with unrestricted AI models and ready-to-use fraud kits, scammers have drastically lowered the entry barrier for digital crime. The focus has decisively shifted from complex technical exploits to highly targeted campaigns that weaponize greed, urgency, and our faith in familiar brands.</p><p>"Bad actors are weaponizing our natural instinct to believe what we see and hear," says Marijus Briedis, CTO at NordVPN, warning that these attacks no longer require advanced skills or significant resources. "Anyone with an internet connection can launch them." </p><p>It's in this context that "A single human error is now more likely than ever and likely to be more devastating than ever," Briedis added.</p><div class="product"><a data-dimension112="c4a21476-ac5f-11f1-abc2-45d92d361fe4" data-action="Deal Block" data-label="NordVPN &ndash; the best VPN overall NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We&rsquo;re confident that virtually anyone can sign up for NordVPN and get what they need from it. It&rsquo;s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee. NordVPN" data-dimension48="NordVPN &ndash; the best VPN overall NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We&rsquo;re confident that virtually anyone can sign up for NordVPN and get what they need from it. It&rsquo;s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee. NordVPN" href="http://go.nordvpn.net/aff_c?offer_id=564&aff_id=3013&url_id=10992" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="x3Zrr6LPF4qKNzdXj4H4t6" name="NordVPN deal image.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/x3Zrr6LPF4qKNzdXj4H4t6.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong></strong><a href="http://go.nordvpn.net/aff_c?offer_id=564&aff_id=3013&url_id=10992" target="_blank" rel="nofollow" data-dimension112="c4a21476-ac5f-11f1-abc2-45d92d361fe4" data-action="Deal Block" data-label="NordVPN &ndash; the best VPN overall NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We&rsquo;re confident that virtually anyone can sign up for NordVPN and get what they need from it. It&rsquo;s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee. NordVPN" data-dimension48="NordVPN &ndash; the best VPN overall NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We&rsquo;re confident that virtually anyone can sign up for NordVPN and get what they need from it. It&rsquo;s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee. NordVPN" data-dimension25=""><strong>NordVPN</strong> <strong>– the best VPN overall</strong></a> <br>NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We’re confident that virtually anyone can sign up for NordVPN and get what they need from it. It’s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.</p><p>Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee.<a class="view-deal button" href="http://go.nordvpn.net/aff_c?offer_id=564&aff_id=3013&url_id=10992" target="_blank" rel="nofollow" data-dimension112="c4a21476-ac5f-11f1-abc2-45d92d361fe4" data-action="Deal Block" data-label="NordVPN &ndash; the best VPN overall NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We&rsquo;re confident that virtually anyone can sign up for NordVPN and get what they need from it. It&rsquo;s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee. NordVPN" data-dimension48="NordVPN &ndash; the best VPN overall NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We&rsquo;re confident that virtually anyone can sign up for NordVPN and get what they need from it. It&rsquo;s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee. NordVPN" data-dimension25="">View Deal</a></p></div><h2 id="the-numbers-behind-the-threat">The numbers behind the threat</h2><p>NordVPN analyzes 12 million unique URLs daily, <strong>blocking an average of 130,000 malicious pages every 24 hours</strong> before they can reach a user — a critical defense mechanism as <a href="https://www.techradar.com/vpn/vpn-services/nordvpns-antivirus-tool-blocks-94-percent-of-phishing-sites-in-latest-independent-test">NordVPN’s antivirus tool continues to block</a> massive volumes of malicious sites.</p><p><a href="https://www.techradar.com/news/what-is-malware-and-how-dangerous-is-it"><strong>Malware</strong></a><strong> remains the single largest threat by volume</strong>. January 2026 saw a massive peak of over 5 million blocked attempts as attackers preyed on post-holiday shoppers. Most of these were <a href="https://www.techradar.com/pro/infostealers-on-the-rise-the-latest-concern-for-organizational-defenses">infostealers</a> aiming to grab saved login credentials. </p><p>The <strong>US</strong> was the hardest hit with 4.89 million attempts across the first half of the year, followed by the<strong> UK</strong> (2 million) and <strong>Germany </strong>(1.32 million).</p><p><a href="https://www.techradar.com/news/what-is-phishing-and-how-dangerous-is-it"><strong>Phishing</strong></a><strong> is equally rampant</strong>. NordVPN blocked over 4.4 million phishing attempts in the first half of the year, noting that 99% of these attacks impersonate a narrow list of just 300 brands, often disguised as <a href="https://www.techradar.com/vpn/vpn-privacy-security/looking-for-a-job-it-could-be-a-scam-nordvpn-uncovers-phishing-campaign-impersonating-top-brands-recruiters"><u>fake job recruiter campaigns</u></a>. </p><p><strong>Microsoft </strong>was the most impersonated company (16.12%), followed by <strong>Roblox </strong>(12.32%), <strong>Google</strong> (9.94%), and <strong>Netflix</strong> (5.99%). Adding to the danger, attackers frequently exploit the trusted .com domain, which accounts for 43.2% of all intercepted scams.</p><a href="https://x.wayin.com/display/container/dc/efe848be-588a-4e20-8711-6e02de64b315/details"><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1200px;"><p class="vanilla-image-block" style="padding-top:26.17%;"><img id="Z7QHFc4GHoMhdps5XmntoC" name="LNT-masthead" alt="Leave No Trace logo" src="https://cdn.mos.cms.futurecdn.net/Z7QHFc4GHoMhdps5XmntoC.png" mos="" align="middle" fullscreen="" width="1200" height="314" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure></a><p><strong>NEW</strong>: <a href="https://x.wayin.com/display/container/dc/efe848be-588a-4e20-8711-6e02de64b315/details" target="_blank" rel="nofollow"><strong>Leave No Trace</strong></a> — A weekly newsletter on digital privacy and online surveillance.</p><p>Leave No Trace investigates the companies and governments putting our digital freedom at risk — and the people fighting back.</p><p>📩 <a href="https://x.wayin.com/display/container/dc/efe848be-588a-4e20-8711-6e02de64b315/details">Subscribe now</a> to get every edition delivered to your inbox every Friday, launching this September.</p><h2 id="hijacked-sessions-and-the-dark-web">Hijacked sessions and the Dark Web</h2><p>While users are increasingly wary of downloading <a href="https://www.techradar.com/vpn/vpn-privacy-security/one-install-and-the-phone-is-no-longer-yours-nordvpn-warns-of-fake-ryanair-emirates-qatar-airways-apps-used-to-spread-malware">fake apps</a> or clicking shady links hidden in <a href="https://www.techradar.com/vpn/vpn-privacy-security/hundreds-of-thousands-at-risk-as-nordvpn-uncovers-sophisticated-adware-campaign-hidden-in-50-000-pirate-sites">pirate sites</a>, attackers are finding stealthier ways in. </p><p>Between January 1 and May 26, 2026, a staggering <strong>94 billion cookies were exposed online</strong>. Of these, 1.2 billion were active session cookies, which cybercriminals can use to hijack accounts without needing a password, often completely bypassing multi-factor authentication (MFA).</p><p>Once data is stolen, it is swiftly commodified. Using its <a href="https://www.techradar.com/pro/nordstellar-launches-dark-web-monitoring-tool-to-help-businesses-stay-safe">Dark Web Monitoring</a> tools, NordVPN identified <strong>8.4 million compromised accounts in just 90 days</strong>. </p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1255px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="mJhHtV57uA5Y5RZwHu8CKn" name="NordVPN dark web market" alt="Man looking at phone surrounded by price tags relating to his personal data" src="https://cdn.mos.cms.futurecdn.net/mJhHtV57uA5Y5RZwHu8CKn.jpg" mos="" align="middle" fullscreen="" width="1255" height="706" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: NordVPN)</span></figcaption></figure><p>Frighteningly, over 47% of the exchanged data involved physical addresses and full names, allowing attackers to weave digital and real-world identifiers together into comprehensive victim profiles.</p><p>Telephony isn't safe, either. Between the service's launch and June 16, NordVPN blocked nearly 29,000 scam calls and issued spam warnings to over 525,000 users.</p><h2 id="how-to-stay-safe">How to stay safe</h2><p>Because technical barriers for criminals are lower than ever, defensive strategies must evolve. NordVPN's report stresses that consumer protection now requires a <strong>mix of both technological defenses and behavioral resilience</strong>.</p><p>Alongside using security tools like a <a href="https://www.techradar.com/vpn/virtual-private-networks">virtual private network (VPN)</a> and <a href="https://www.techradar.com/best/best-antivirus">antivirus </a>software, users must cultivate a healthy skepticism. If a message, email, or website demands urgent action or offers something too good to be true, pause and verify. </p><p>In the age of AI-driven fraud, a moment of hesitation is your best line of defense.</p><div data-widget-type="review" data-model-name="NordVPN"></div> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/vpn/vpn-services/nordvpn-warns-ai-is-making-scams-more-personal-and-devastating-than-ever</link>
                                                                            <description>
                            <![CDATA[ NordVPN's first flagship Consumer Cybersecurity Report reveals how AI is industrializing fraud and bypassing technical defenses by targeting the human element. Here is what you need to know to stay safe. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uKXtnfRerxC4F8ymZ3wHzc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/U76sZeRd6fS2fKt5RqBYPL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 09 Sep 2026 15:18:50 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[VPN Services]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DXDNjzRkphApxN8f5SooCA.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rene Millman is a seasoned technology journalist whose work has appeared in The Guardian, the Financial Times, Computer Weekly, and IT Pro. With over two decades of experience as a reporter and editor, he specializes in making complex topics like cybersecurity, VPNs, and enterprise software accessible and engaging. &lt;/p&gt;&lt;p&gt;His writing is backed by years of market analysis, allowing him to deliver news and features with an expert’s understanding of the industry.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/U76sZeRd6fS2fKt5RqBYPL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Big letters AI in pink in front of pink and blue strands of light suggesting a digital explosion]]></media:description>                                                            <media:text><![CDATA[Big letters AI in pink in front of pink and blue strands of light suggesting a digital explosion]]></media:text>
                                <media:title type="plain"><![CDATA[Big letters AI in pink in front of pink and blue strands of light suggesting a digital explosion]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/U76sZeRd6fS2fKt5RqBYPL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>NordVPN blocked over 5 million malware attempts in January alone</strong></li><li><strong>99% of phishing attacks impersonate just 300 brands</strong></li><li><strong>AI tools and fraud kits mean attackers no longer need advanced skills</strong></li></ul><p>We are well past the days when a cyberattack meant mass-mailing a poorly spelled virus. In 2026, cybercriminals are heavily leveraging generative AI to make their scams highly personal, industrializing fraud on a massive scale.</p><p>That is the stark warning from the <a href="https://a-us.storyblok.com/f/1001711/x/e393e7f999/nordvpn-consumer-cybersecurity-report.pdf" target="_blank" rel="nofollow">Consumer Cybersecurity Report: Dismantling the Evolving Threat Landscape,</a> published today by <a href="https://www.techradar.com/reviews/nordvpn">NordVPN</a>. Analyzing threat intelligence data from the first half of the year, the prominent cybersecurity and <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> provider uncovered that the most exploited vulnerability right now isn't outdated software; it is human trust.</p><p>Armed with unrestricted AI models and ready-to-use fraud kits, scammers have drastically lowered the entry barrier for digital crime. The focus has decisively shifted from complex technical exploits to highly targeted campaigns that weaponize greed, urgency, and our faith in familiar brands.</p><p>"Bad actors are weaponizing our natural instinct to believe what we see and hear," says Marijus Briedis, CTO at NordVPN, warning that these attacks no longer require advanced skills or significant resources. "Anyone with an internet connection can launch them." </p><p>It's in this context that "A single human error is now more likely than ever and likely to be more devastating than ever," Briedis added.</p><div class="product"><a data-dimension112="c4a21476-ac5f-11f1-abc2-45d92d361fe4" data-action="Deal Block" data-label="NordVPN &ndash; the best VPN overall NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We&rsquo;re confident that virtually anyone can sign up for NordVPN and get what they need from it. It&rsquo;s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee. NordVPN" data-dimension48="NordVPN &ndash; the best VPN overall NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We&rsquo;re confident that virtually anyone can sign up for NordVPN and get what they need from it. It&rsquo;s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee. NordVPN" href="http://go.nordvpn.net/aff_c?offer_id=564&aff_id=3013&url_id=10992" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="x3Zrr6LPF4qKNzdXj4H4t6" name="NordVPN deal image.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/x3Zrr6LPF4qKNzdXj4H4t6.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong></strong><a href="http://go.nordvpn.net/aff_c?offer_id=564&aff_id=3013&url_id=10992" target="_blank" rel="nofollow" data-dimension112="c4a21476-ac5f-11f1-abc2-45d92d361fe4" data-action="Deal Block" data-label="NordVPN &ndash; the best VPN overall NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We&rsquo;re confident that virtually anyone can sign up for NordVPN and get what they need from it. It&rsquo;s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee. NordVPN" data-dimension48="NordVPN &ndash; the best VPN overall NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We&rsquo;re confident that virtually anyone can sign up for NordVPN and get what they need from it. It&rsquo;s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee. NordVPN" data-dimension25=""><strong>NordVPN</strong> <strong>– the best VPN overall</strong></a> <br>NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We’re confident that virtually anyone can sign up for NordVPN and get what they need from it. It’s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.</p><p>Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee.<a class="view-deal button" href="http://go.nordvpn.net/aff_c?offer_id=564&aff_id=3013&url_id=10992" target="_blank" rel="nofollow" data-dimension112="c4a21476-ac5f-11f1-abc2-45d92d361fe4" data-action="Deal Block" data-label="NordVPN &ndash; the best VPN overall NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We&rsquo;re confident that virtually anyone can sign up for NordVPN and get what they need from it. It&rsquo;s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee. NordVPN" data-dimension48="NordVPN &ndash; the best VPN overall NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We&rsquo;re confident that virtually anyone can sign up for NordVPN and get what they need from it. It&rsquo;s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee. NordVPN" data-dimension25="">View Deal</a></p></div><h2 id="the-numbers-behind-the-threat">The numbers behind the threat</h2><p>NordVPN analyzes 12 million unique URLs daily, <strong>blocking an average of 130,000 malicious pages every 24 hours</strong> before they can reach a user — a critical defense mechanism as <a href="https://www.techradar.com/vpn/vpn-services/nordvpns-antivirus-tool-blocks-94-percent-of-phishing-sites-in-latest-independent-test">NordVPN’s antivirus tool continues to block</a> massive volumes of malicious sites.</p><p><a href="https://www.techradar.com/news/what-is-malware-and-how-dangerous-is-it"><strong>Malware</strong></a><strong> remains the single largest threat by volume</strong>. January 2026 saw a massive peak of over 5 million blocked attempts as attackers preyed on post-holiday shoppers. Most of these were <a href="https://www.techradar.com/pro/infostealers-on-the-rise-the-latest-concern-for-organizational-defenses">infostealers</a> aiming to grab saved login credentials. </p><p>The <strong>US</strong> was the hardest hit with 4.89 million attempts across the first half of the year, followed by the<strong> UK</strong> (2 million) and <strong>Germany </strong>(1.32 million).</p><p><a href="https://www.techradar.com/news/what-is-phishing-and-how-dangerous-is-it"><strong>Phishing</strong></a><strong> is equally rampant</strong>. NordVPN blocked over 4.4 million phishing attempts in the first half of the year, noting that 99% of these attacks impersonate a narrow list of just 300 brands, often disguised as <a href="https://www.techradar.com/vpn/vpn-privacy-security/looking-for-a-job-it-could-be-a-scam-nordvpn-uncovers-phishing-campaign-impersonating-top-brands-recruiters"><u>fake job recruiter campaigns</u></a>. </p><p><strong>Microsoft </strong>was the most impersonated company (16.12%), followed by <strong>Roblox </strong>(12.32%), <strong>Google</strong> (9.94%), and <strong>Netflix</strong> (5.99%). Adding to the danger, attackers frequently exploit the trusted .com domain, which accounts for 43.2% of all intercepted scams.</p><a href="https://x.wayin.com/display/container/dc/efe848be-588a-4e20-8711-6e02de64b315/details"><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1200px;"><p class="vanilla-image-block" style="padding-top:26.17%;"><img id="Z7QHFc4GHoMhdps5XmntoC" name="LNT-masthead" alt="Leave No Trace logo" src="https://cdn.mos.cms.futurecdn.net/Z7QHFc4GHoMhdps5XmntoC.png" mos="" align="middle" fullscreen="" width="1200" height="314" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure></a><p><strong>NEW</strong>: <a href="https://x.wayin.com/display/container/dc/efe848be-588a-4e20-8711-6e02de64b315/details" target="_blank" rel="nofollow"><strong>Leave No Trace</strong></a> — A weekly newsletter on digital privacy and online surveillance.</p><p>Leave No Trace investigates the companies and governments putting our digital freedom at risk — and the people fighting back.</p><p>📩 <a href="https://x.wayin.com/display/container/dc/efe848be-588a-4e20-8711-6e02de64b315/details">Subscribe now</a> to get every edition delivered to your inbox every Friday, launching this September.</p><h2 id="hijacked-sessions-and-the-dark-web">Hijacked sessions and the Dark Web</h2><p>While users are increasingly wary of downloading <a href="https://www.techradar.com/vpn/vpn-privacy-security/one-install-and-the-phone-is-no-longer-yours-nordvpn-warns-of-fake-ryanair-emirates-qatar-airways-apps-used-to-spread-malware">fake apps</a> or clicking shady links hidden in <a href="https://www.techradar.com/vpn/vpn-privacy-security/hundreds-of-thousands-at-risk-as-nordvpn-uncovers-sophisticated-adware-campaign-hidden-in-50-000-pirate-sites">pirate sites</a>, attackers are finding stealthier ways in. </p><p>Between January 1 and May 26, 2026, a staggering <strong>94 billion cookies were exposed online</strong>. Of these, 1.2 billion were active session cookies, which cybercriminals can use to hijack accounts without needing a password, often completely bypassing multi-factor authentication (MFA).</p><p>Once data is stolen, it is swiftly commodified. Using its <a href="https://www.techradar.com/pro/nordstellar-launches-dark-web-monitoring-tool-to-help-businesses-stay-safe">Dark Web Monitoring</a> tools, NordVPN identified <strong>8.4 million compromised accounts in just 90 days</strong>. </p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1255px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="mJhHtV57uA5Y5RZwHu8CKn" name="NordVPN dark web market" alt="Man looking at phone surrounded by price tags relating to his personal data" src="https://cdn.mos.cms.futurecdn.net/mJhHtV57uA5Y5RZwHu8CKn.jpg" mos="" align="middle" fullscreen="" width="1255" height="706" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: NordVPN)</span></figcaption></figure><p>Frighteningly, over 47% of the exchanged data involved physical addresses and full names, allowing attackers to weave digital and real-world identifiers together into comprehensive victim profiles.</p><p>Telephony isn't safe, either. Between the service's launch and June 16, NordVPN blocked nearly 29,000 scam calls and issued spam warnings to over 525,000 users.</p><h2 id="how-to-stay-safe">How to stay safe</h2><p>Because technical barriers for criminals are lower than ever, defensive strategies must evolve. NordVPN's report stresses that consumer protection now requires a <strong>mix of both technological defenses and behavioral resilience</strong>.</p><p>Alongside using security tools like a <a href="https://www.techradar.com/vpn/virtual-private-networks">virtual private network (VPN)</a> and <a href="https://www.techradar.com/best/best-antivirus">antivirus </a>software, users must cultivate a healthy skepticism. If a message, email, or website demands urgent action or offers something too good to be true, pause and verify. </p><p>In the age of AI-driven fraud, a moment of hesitation is your best line of defense.</p><div data-widget-type="review" data-model-name="NordVPN"></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cisco routers are being turned into surveillance vantage points to hoover up data on trusted networks — and it's all thanks to this new malware ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Sygnia reports China‑linked Fire Ant expanding beyond virtualization to routers, TACACS, and Linux hosts</strong></li><li><strong>Compromised routers act as operational platforms</strong></li><li><strong>Campaign aims at “target behind the target,” leveraging trust relationships for broader espionage reach</strong></li></ul><p>Fire Ant, a China-nexus cyberespionage group, is no longer targeting just virtualization platforms, it’s also going for routers, authentication systems, and Linux management hosts. This is according to cybersecurity researchers Sygnia, who recently saw the group target Cisco IOS XR Routers. </p><p>Once they compromise a <a href="https://www.techradar.com/news/networking/routers-storage/best-router-9-top-wireless-routers-on-test-1090523" target="_blank">router</a>, they don’t just use it to move around the network, the researchers explained. Instead, they turn them into full-blown operational platforms, collecting traffic, establishing connections, manipulating command output, and even suppressing logging so that they fly under the defenders’ radars. </p><p>For authentication systems, Fire Ant was seen taking aim at TACACS servers. Admins use them to authenticate when accessing network hardware, and crooks use them to harvest valuable credentials and weaken the reliability of audit logs, as well. Finally, Sygnia says Fire Ant also targets Linux management hosts. The researchers saw multiple persistent implants and backdoors, including a custom SSH backdoor and a piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> spoofing legitimate software. </p><h2 id="target-behind-the-target">Target behind the target</h2><p>The goal of the campaign seems to be to establish a foothold that allows crooks to reach other environments. Sygnia describes it as a “target behind the target” scenario: </p><p>“This reinforces the “target behind the target” concept introduced earlier in this report. Fire Ant’s interest in the compromised organization should be understood not only as an attempt to compromise a single environment, but as an effort to control infrastructure that may enable visibility, collection, and potential access beyond the immediate victim. The strategic value lies in the trust relationships the organization maintains with connected environments,” Sygnia explained.</p><p>Very little is known about Fire Ant, besides the fact that it was first observed in 2025. Some researchers claim it has significant overlaps with a threat actor tracked as UNC3886, a Chinese espionage group previously observed by Google. However, there are also significant differences which make attribution inconclusive.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/chinese-fire-ant-hackers-turn-cisco-routers-into-spying-platforms/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/cisco-routers-are-being-turned-into-surveillance-vantage-points-to-hoover-up-data-on-trusted-networks-and-its-all-thanks-to-this-new-malware</link>
                                                                            <description>
                            <![CDATA[ Fire Ant is now targeting routers, authentication servers, and Linux management hosts, using them as stepping stones. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ktXPBkae4A3uwRF8jyucDd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EEXAxCUDKAq3frELz3rVYY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Sep 2026 19:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/EEXAxCUDKAq3frELz3rVYY-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all wearing black with hoods pulled up over their heads. You cannot see their faces. The hacker in the foreground sits with an open laptop in front of them. The background, behind the hackers, is a Chinese flag]]></media:description>                                                            <media:text><![CDATA[A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all wearing black with hoods pulled up over their heads. You cannot see their faces. The hacker in the foreground sits with an open laptop in front of them. The background, behind the hackers, is a Chinese flag]]></media:text>
                                <media:title type="plain"><![CDATA[A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all wearing black with hoods pulled up over their heads. You cannot see their faces. The hacker in the foreground sits with an open laptop in front of them. The background, behind the hackers, is a Chinese flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EEXAxCUDKAq3frELz3rVYY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Sygnia reports China‑linked Fire Ant expanding beyond virtualization to routers, TACACS, and Linux hosts</strong></li><li><strong>Compromised routers act as operational platforms</strong></li><li><strong>Campaign aims at “target behind the target,” leveraging trust relationships for broader espionage reach</strong></li></ul><p>Fire Ant, a China-nexus cyberespionage group, is no longer targeting just virtualization platforms, it’s also going for routers, authentication systems, and Linux management hosts. This is according to cybersecurity researchers Sygnia, who recently saw the group target Cisco IOS XR Routers. </p><p>Once they compromise a <a href="https://www.techradar.com/news/networking/routers-storage/best-router-9-top-wireless-routers-on-test-1090523" target="_blank">router</a>, they don’t just use it to move around the network, the researchers explained. Instead, they turn them into full-blown operational platforms, collecting traffic, establishing connections, manipulating command output, and even suppressing logging so that they fly under the defenders’ radars. </p><p>For authentication systems, Fire Ant was seen taking aim at TACACS servers. Admins use them to authenticate when accessing network hardware, and crooks use them to harvest valuable credentials and weaken the reliability of audit logs, as well. Finally, Sygnia says Fire Ant also targets Linux management hosts. The researchers saw multiple persistent implants and backdoors, including a custom SSH backdoor and a piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> spoofing legitimate software. </p><h2 id="target-behind-the-target">Target behind the target</h2><p>The goal of the campaign seems to be to establish a foothold that allows crooks to reach other environments. Sygnia describes it as a “target behind the target” scenario: </p><p>“This reinforces the “target behind the target” concept introduced earlier in this report. Fire Ant’s interest in the compromised organization should be understood not only as an attempt to compromise a single environment, but as an effort to control infrastructure that may enable visibility, collection, and potential access beyond the immediate victim. The strategic value lies in the trust relationships the organization maintains with connected environments,” Sygnia explained.</p><p>Very little is known about Fire Ant, besides the fact that it was first observed in 2025. Some researchers claim it has significant overlaps with a threat actor tracked as UNC3886, a Chinese espionage group previously observed by Google. However, there are also significant differences which make attribution inconclusive.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/chinese-fire-ant-hackers-turn-cisco-routers-into-spying-platforms/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Top AI tools including Claude, Codex, and Hermes installed suspicious code inside corporate networks ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Researchers found unclaimed llms.txt references on 120 domains, exploitable by cybercriminals</strong></li><li><strong>AI agents could install malware if they execute hallucinated or outdated documentation commands</strong></li><li><strong>Fixes: clean documentation and restrict AI agents from treating docs as executable instructions</strong></li></ul><p>Cybercriminals are able to now abuse hallucinated, outdated, and outright incorrect website documentation to deliver malware to unsuspecting victims through <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agents</a>, new research has claimed.</p><p>An increasing number of websites now contain two documents: llms.txt, and llms-full.txt. These are conventions that allow AI agents to properly read the contents of the websites. If an AI agent is looking to install software or add code to a project, they can search through these documents across the web until they find a fitting solution.</p><p>Researcher <a href="https://medium.com/@alonhertz1/data-became-code-we-ran-code-inside-fortune-500s-using-files-they-published-for-ai-agents-0cd67ffbbffc" target="_blank">Alon Hertz</a> analyzed 6,214 live domains belonging to defense contractors, Fortune 500 organizations, as well as big tech. On these domains he  found 8,265 of these .txt files and among them 120 (all on a different site) pointing to one or more code packages and domain names that weren’t registered at all.</p><h2 id="claiming-packages-and-domains">Claiming packages and domains</h2><p>There can be a myriad of reasons why they’re not registered. It can be due to human error, renamed or abandoned packages, copy/paste errors, or hallucinated documentation.</p><p>Now, for the purpose of the experiment, Hertz registered some of these unclaimed names and hosted packages that would phone home when installed. It took less than an hour for a Fortune 500 company to start pinging, and the numbers soon grew to “a few dozen more”. </p><p>This means that if the researchers can do it, so can cybercriminals. In theory, a cybercriminal could find these unclaimed packages and register <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>. If an AI agent has permission to execute shell/package-manager commands and stumbles upon this documentation, it can end up infecting the device. </p><p>Claude, OpenAI’s Codex, and Nous Research’s Hermes were all “guilty”, the researchers said. </p><p>To fix the vulnerability, two things need to happen. First, companies need to clean up their documentation and make sure it’s not pointing towards non-existent or malicious content. Second, AI agents need to stop treating documentation as executable instructions. Since the latter most likely isn’t happening any time soon, the immediate answer would probably lie in the former. In the meantime, organizations using AI for coding should consider the risks when granting AI agents permission to execute commands. </p><p><em>Via </em><a href="https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/" target="_blank"><em>Ars Technica</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/top-ai-tools-including-claude-codex-and-hermes-installed-suspicious-code-inside-corporate-networks</link>
                                                                            <description>
                            <![CDATA[ There is a new class of "squatting" risks emerging right in front of us and it involves llms.txt and llms-full.txt documentation. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">o8w4UpaZjEpWmoRVVffXRV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Thi6y93AMWrCXJAEiHDQbL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sun, 30 Aug 2026 12:05:00 +0000</pubDate>                                                                                                                                <updated>Mon, 31 Aug 2026 08:59:17 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Thi6y93AMWrCXJAEiHDQbL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot in front of a digital screen, touching some of the symbols with its outstretched finger]]></media:description>                                                            <media:text><![CDATA[A robot in front of a digital screen, touching some of the symbols with its outstretched finger]]></media:text>
                                <media:title type="plain"><![CDATA[A robot in front of a digital screen, touching some of the symbols with its outstretched finger]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Thi6y93AMWrCXJAEiHDQbL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers found unclaimed llms.txt references on 120 domains, exploitable by cybercriminals</strong></li><li><strong>AI agents could install malware if they execute hallucinated or outdated documentation commands</strong></li><li><strong>Fixes: clean documentation and restrict AI agents from treating docs as executable instructions</strong></li></ul><p>Cybercriminals are able to now abuse hallucinated, outdated, and outright incorrect website documentation to deliver malware to unsuspecting victims through <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agents</a>, new research has claimed.</p><p>An increasing number of websites now contain two documents: llms.txt, and llms-full.txt. These are conventions that allow AI agents to properly read the contents of the websites. If an AI agent is looking to install software or add code to a project, they can search through these documents across the web until they find a fitting solution.</p><p>Researcher <a href="https://medium.com/@alonhertz1/data-became-code-we-ran-code-inside-fortune-500s-using-files-they-published-for-ai-agents-0cd67ffbbffc" target="_blank">Alon Hertz</a> analyzed 6,214 live domains belonging to defense contractors, Fortune 500 organizations, as well as big tech. On these domains he  found 8,265 of these .txt files and among them 120 (all on a different site) pointing to one or more code packages and domain names that weren’t registered at all.</p><h2 id="claiming-packages-and-domains">Claiming packages and domains</h2><p>There can be a myriad of reasons why they’re not registered. It can be due to human error, renamed or abandoned packages, copy/paste errors, or hallucinated documentation.</p><p>Now, for the purpose of the experiment, Hertz registered some of these unclaimed names and hosted packages that would phone home when installed. It took less than an hour for a Fortune 500 company to start pinging, and the numbers soon grew to “a few dozen more”. </p><p>This means that if the researchers can do it, so can cybercriminals. In theory, a cybercriminal could find these unclaimed packages and register <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>. If an AI agent has permission to execute shell/package-manager commands and stumbles upon this documentation, it can end up infecting the device. </p><p>Claude, OpenAI’s Codex, and Nous Research’s Hermes were all “guilty”, the researchers said. </p><p>To fix the vulnerability, two things need to happen. First, companies need to clean up their documentation and make sure it’s not pointing towards non-existent or malicious content. Second, AI agents need to stop treating documentation as executable instructions. Since the latter most likely isn’t happening any time soon, the immediate answer would probably lie in the former. In the meantime, organizations using AI for coding should consider the risks when granting AI agents permission to execute commands. </p><p><em>Via </em><a href="https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/" target="_blank"><em>Ars Technica</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New Windows malware lays dormant until a custom command activates it like a sleeper agent ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Researcher Dominik Reichel found </strong><em><strong>SLEEPWALKER</strong></em><strong>, a silent malware implant disguised as ESET’s agent</strong></li><li><strong>It contains no malicious code, activates only after receiving crafted network signals</strong></li><li><strong>Likely a nation‑state project targeting specific victims; no active campaigns confirmed yet</strong></li></ul><p>Security researchers discovered a new and rather unusual piece of malware. </p><p>Most malware come with a built-in, pre-defined set of tools and features: system fingerprinting, network mapping, data exfiltration, keylogging, screenshots, tapping into the camera and microphone. When they infect a machine, they first try to phone home using the device’s internet connection and await instructions on which of the features to use.</p><p>But security researcher Dominik Reichel found something entirely different: a piece of malware not having any of the above, designed to remain almost completely silent until being “woken up”. He named it SLEEPWALKER.</p><h2 id="no-active-campaigns">No active campaigns</h2><p>This implant has no malicious code, and therefore nothing that would get flagged by security software. It hides in plain sight, masquerading as a legitimate Windows component for ESET’s Management Agent. This allows it to run from within a trusted app, instead of being a standalone program that could invite scrutiny. </p><p>SLEEPWALKER listens to network traffic for a specially crafted signal, waking up only when it is received. That signal also “teaches” the malware what it can do - schedule different activities, communicate with other systems, receive additional programs, and even execute code. </p><p>The <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> was submitted to VirusTotal sometime last year, Reichel said. It was not found in any active campaigns, and there are no confirmed victims, industries, countries, or organizations associated with the sample. Reichel also stressed that it’s unknown how the malware initially entered the reporter’s environment, who runs it, and what additional tools may have accompanied it. </p><p>He also said that the code is somewhat “rough around the edges”. Despite its unusual design, it comes with several weaknesses, which might suggest that SLEEPWALKER was a work in progress. He doesn’t know if there are newer variants in the wild, though.</p><p>Still, given the nature of the malware, Reichel doesn’t think it was built for indiscriminate attacks. Instead, it was most likely designed by nation-states with specific targets in mind.</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/08/24/you-dont-want-this-sleepwalker-backdoor-on-your-windows-machine/5292021" target="_blank"><em>The Register</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/new-windows-malware-lays-dormant-until-a-custom-command-activates-it-like-a-sleeper-agent</link>
                                                                            <description>
                            <![CDATA[ No one knows who built it and to what end. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Fdw3eEQBjziJB7YRTFX8FK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Aug 2026 16:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:description>                                                            <media:text><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:text>
                                <media:title type="plain"><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researcher Dominik Reichel found </strong><em><strong>SLEEPWALKER</strong></em><strong>, a silent malware implant disguised as ESET’s agent</strong></li><li><strong>It contains no malicious code, activates only after receiving crafted network signals</strong></li><li><strong>Likely a nation‑state project targeting specific victims; no active campaigns confirmed yet</strong></li></ul><p>Security researchers discovered a new and rather unusual piece of malware. </p><p>Most malware come with a built-in, pre-defined set of tools and features: system fingerprinting, network mapping, data exfiltration, keylogging, screenshots, tapping into the camera and microphone. When they infect a machine, they first try to phone home using the device’s internet connection and await instructions on which of the features to use.</p><p>But security researcher Dominik Reichel found something entirely different: a piece of malware not having any of the above, designed to remain almost completely silent until being “woken up”. He named it SLEEPWALKER.</p><h2 id="no-active-campaigns">No active campaigns</h2><p>This implant has no malicious code, and therefore nothing that would get flagged by security software. It hides in plain sight, masquerading as a legitimate Windows component for ESET’s Management Agent. This allows it to run from within a trusted app, instead of being a standalone program that could invite scrutiny. </p><p>SLEEPWALKER listens to network traffic for a specially crafted signal, waking up only when it is received. That signal also “teaches” the malware what it can do - schedule different activities, communicate with other systems, receive additional programs, and even execute code. </p><p>The <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> was submitted to VirusTotal sometime last year, Reichel said. It was not found in any active campaigns, and there are no confirmed victims, industries, countries, or organizations associated with the sample. Reichel also stressed that it’s unknown how the malware initially entered the reporter’s environment, who runs it, and what additional tools may have accompanied it. </p><p>He also said that the code is somewhat “rough around the edges”. Despite its unusual design, it comes with several weaknesses, which might suggest that SLEEPWALKER was a work in progress. He doesn’t know if there are newer variants in the wild, though.</p><p>Still, given the nature of the malware, Reichel doesn’t think it was built for indiscriminate attacks. Instead, it was most likely designed by nation-states with specific targets in mind.</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/08/24/you-dont-want-this-sleepwalker-backdoor-on-your-windows-machine/5292021" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Android car systems abused by hackers to launch new malware that pulls devices into a hidden proxy network ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Kaspersky found Android malware abusing DoFun car head units via TWCore updates</strong></li><li><strong>Multi‑stage attack installs loaders and reverse proxy, aiming to build a botnet of connected cars</strong></li><li><strong>Campaign attributed to MoYu Group; DoFun patched vulnerabilities after disclosure</strong></li></ul><p>We’ve seen botnets comprising cameras and DVRs, we’ve even seen botnets comprising smart fridges and digital frames, but we’ve never seen botnets comprising automobile <a href="https://www.techradar.com/vehicle-tech/hybrid-electric-vehicles/the-9-best-android-automotive-apps-to-upgrade-your-driving-experience-in-2025" target="_blank">infotainment systems</a>. First time for everything.</p><p>Earlier this week, security researchers Kaspersky warned about finding a brand new Android malware targeting the car’s head unit. The victim seems to be a Chinese manufacturer called DoFun. Head units from this manufacturer, built on Android, are running an app for analytics and software updates called TWCore.</p><p>According to Kaspersky, the attackers abused TWCore’s update mechanisms, instructing it to download a malicious APK. This <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> is then placed in the app’s cache directory and installed by the legitimate com.tw.core package. </p><div class="product"><a data-dimension112="5f96957a-a129-11f1-b672-5dafbaca92e3" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="5f96957a-a129-11f1-b672-5dafbaca92e3" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="5f96957a-a129-11f1-b672-5dafbaca92e3" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="no-active-campaigns-2">No active campaigns</h2><p>The researchers said this was a multi-stage attack. In the first stage, a tiny dropper with no user interface gets deployed. It decrypts embedded data, and extracts the information it needs for stage two. In the next stage, the loader contacts the attackers’ server and gets instructions about stage 3, which can be different things, from deploying additional malware, to running the “zhima” reverse proxy.</p><p>Despite its multifunctional nature, Kaspersky believes that the true goal of the campaign is to assimilate the cars into a botnet. Some cars come with a SIM slot and are connected to the internet 24/7. It is probably not an exaggeration to say that cars just might be the perfect devices for a malicious botnet. </p><p>Kaspersky attributed the campaign to MoYu Group, a threat actor known for building malicious botnets based on Android devices. In the past, this group was observed building the BadBox botnet out of Android smartphones, tablets, streaming devices, and other internet-connected hardware.</p><p>The researchers notified DoFun of their findings, and the vulnerability was quickly fixed: "We notified the vendor about the distribution scheme, and they subsequently reported fixing the security issues," the researchers said.</p><p><em>Via </em><a href="https://therecord.media/android-botnet-china-hackers" target="_blank"><em>The Record</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/android-car-systems-abused-by-hackers-to-launch-new-malware-that-pulls-devices-into-a-hidden-proxy-network</link>
                                                                            <description>
                            <![CDATA[ Crooks found a flaw in an analytics app and used it to deploy malware to cars' infotainment systems. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vn9vGmB7jKSvxynTXdzJ4N</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/huHCuSUqR6aadH7TQgGRs7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Aug 2026 13:10:07 +0000</pubDate>                                                                                                                                <updated>Wed, 26 Aug 2026 08:37:29 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/huHCuSUqR6aadH7TQgGRs7-1280-80.jpg">
                                                            <media:credit><![CDATA[Why Kei, Unsplash]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A man driving a car in the evening.]]></media:description>                                                            <media:text><![CDATA[A man driving a car in the evening.]]></media:text>
                                <media:title type="plain"><![CDATA[A man driving a car in the evening.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/huHCuSUqR6aadH7TQgGRs7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Kaspersky found Android malware abusing DoFun car head units via TWCore updates</strong></li><li><strong>Multi‑stage attack installs loaders and reverse proxy, aiming to build a botnet of connected cars</strong></li><li><strong>Campaign attributed to MoYu Group; DoFun patched vulnerabilities after disclosure</strong></li></ul><p>We’ve seen botnets comprising cameras and DVRs, we’ve even seen botnets comprising smart fridges and digital frames, but we’ve never seen botnets comprising automobile <a href="https://www.techradar.com/vehicle-tech/hybrid-electric-vehicles/the-9-best-android-automotive-apps-to-upgrade-your-driving-experience-in-2025" target="_blank">infotainment systems</a>. First time for everything.</p><p>Earlier this week, security researchers Kaspersky warned about finding a brand new Android malware targeting the car’s head unit. The victim seems to be a Chinese manufacturer called DoFun. Head units from this manufacturer, built on Android, are running an app for analytics and software updates called TWCore.</p><p>According to Kaspersky, the attackers abused TWCore’s update mechanisms, instructing it to download a malicious APK. This <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> is then placed in the app’s cache directory and installed by the legitimate com.tw.core package. </p><div class="product"><a data-dimension112="5f96957a-a129-11f1-b672-5dafbaca92e3" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="5f96957a-a129-11f1-b672-5dafbaca92e3" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="5f96957a-a129-11f1-b672-5dafbaca92e3" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="no-active-campaigns-2">No active campaigns</h2><p>The researchers said this was a multi-stage attack. In the first stage, a tiny dropper with no user interface gets deployed. It decrypts embedded data, and extracts the information it needs for stage two. In the next stage, the loader contacts the attackers’ server and gets instructions about stage 3, which can be different things, from deploying additional malware, to running the “zhima” reverse proxy.</p><p>Despite its multifunctional nature, Kaspersky believes that the true goal of the campaign is to assimilate the cars into a botnet. Some cars come with a SIM slot and are connected to the internet 24/7. It is probably not an exaggeration to say that cars just might be the perfect devices for a malicious botnet. </p><p>Kaspersky attributed the campaign to MoYu Group, a threat actor known for building malicious botnets based on Android devices. In the past, this group was observed building the BadBox botnet out of Android smartphones, tablets, streaming devices, and other internet-connected hardware.</p><p>The researchers notified DoFun of their findings, and the vulnerability was quickly fixed: "We notified the vendor about the distribution scheme, and they subsequently reported fixing the security issues," the researchers said.</p><p><em>Via </em><a href="https://therecord.media/android-botnet-china-hackers" target="_blank"><em>The Record</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New malware targets Microsoft Teams users by posing as your company's IT helpdesk ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Expel researchers warn of SynkLoader backdoor spread via fake IT help desk Teams messages</strong></li><li><strong>Malware modules include PhishLocker (fake login screen harvesting OS passwords) and Interactive Shell for remote control</strong></li><li><strong>Defenses: distrust unsolicited Teams DMs, verify with IT before installing apps, and train staff against social engineering</strong></li></ul><p>For roughly a month now, cybercriminals have been targeting organizations with a new backdoor malware called SynkLoader.</p><p>According to security researchers Expel, the attack starts with social engineering. Victims would get a Microsoft Teams message from a person claiming to be from the company’s IT help desk. They would tell the victim their computer is having an issue, and that they need to install a “PowerShell Cleaner”. This fake program is nothing more than a malicious framework, hosted on Microsoft Azure to increase its trustworthiness.</p><p>The <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> itself comes with a number of different modules, giving the attacker a range of features, from harvesting system information, to creating a reverse proxy. Two particularly worrying modules are called PhishLocker and Interactive Shell. The former creates a convincing, yet fake, Windows lock screen, which can harvest the user’s OS login password.</p><div class="product"><a data-dimension112="84719642-a129-11f1-a59c-dfe13294a7ef" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="84719642-a129-11f1-a59c-dfe13294a7ef" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="84719642-a129-11f1-a59c-dfe13294a7ef" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="this-is-not-sickkids-39-first-attack">This is not SickKids' first attack</h2><p>BleepingComputer argues that with this password the attackers could “access corporate environments from the infected device, bypassing IP allow-list restrictions”. Those with a sharper eye might spot the ruse, as a simple Alt + Tab shows that the login screen is nothing more than a “full-screen borderless GUI application”.</p><p>The other module - Interactive Shell, allows threat actors to remotely execute PowerShell commands and receive the output, which essentially grants them full control over the infected device. </p><p>The full list of Indicators of Compromise (IoC) can be found on <a href="https://expel.com/blog/synkloader-when-you-throw-in-everything-but-the-kitchen-sink/" target="_blank" rel="nofollow">this link</a>. To defend against these types of attacks, target companies should instruct their employees not to trust unsolicited Teams messages at face value, and not to install any applications without double-checking (calling) with their IT department first.</p><p>Alongside phone calls, Microsoft Teams is one of the most-used channels for initial contact and compromise. Also, employees remain the weakest link in every company’s cybersecurity chain, unwillingly granting attackers access or sharing login credentials.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/new-synkloader-malware-pushed-in-microsoft-teams-phishing-campaign/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/new-malware-targets-microsoft-teams-users-by-posing-as-your-companys-it-helpdesk</link>
                                                                            <description>
                            <![CDATA[ Victims are being told to install a fake cleaner software which is nothing more than a backdoor framework. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gDENeCKMs9WruAKu7UsWj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7DtE9RCVmUtmH2FAfvxsvM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 24 Aug 2026 17:15:00 +0000</pubDate>                                                                                                                                <updated>Wed, 26 Aug 2026 08:38:31 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7DtE9RCVmUtmH2FAfvxsvM-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:description>                                                            <media:text><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:text>
                                <media:title type="plain"><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7DtE9RCVmUtmH2FAfvxsvM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Expel researchers warn of SynkLoader backdoor spread via fake IT help desk Teams messages</strong></li><li><strong>Malware modules include PhishLocker (fake login screen harvesting OS passwords) and Interactive Shell for remote control</strong></li><li><strong>Defenses: distrust unsolicited Teams DMs, verify with IT before installing apps, and train staff against social engineering</strong></li></ul><p>For roughly a month now, cybercriminals have been targeting organizations with a new backdoor malware called SynkLoader.</p><p>According to security researchers Expel, the attack starts with social engineering. Victims would get a Microsoft Teams message from a person claiming to be from the company’s IT help desk. They would tell the victim their computer is having an issue, and that they need to install a “PowerShell Cleaner”. This fake program is nothing more than a malicious framework, hosted on Microsoft Azure to increase its trustworthiness.</p><p>The <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> itself comes with a number of different modules, giving the attacker a range of features, from harvesting system information, to creating a reverse proxy. Two particularly worrying modules are called PhishLocker and Interactive Shell. The former creates a convincing, yet fake, Windows lock screen, which can harvest the user’s OS login password.</p><div class="product"><a data-dimension112="84719642-a129-11f1-a59c-dfe13294a7ef" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="84719642-a129-11f1-a59c-dfe13294a7ef" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="84719642-a129-11f1-a59c-dfe13294a7ef" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="this-is-not-sickkids-39-first-attack">This is not SickKids' first attack</h2><p>BleepingComputer argues that with this password the attackers could “access corporate environments from the infected device, bypassing IP allow-list restrictions”. Those with a sharper eye might spot the ruse, as a simple Alt + Tab shows that the login screen is nothing more than a “full-screen borderless GUI application”.</p><p>The other module - Interactive Shell, allows threat actors to remotely execute PowerShell commands and receive the output, which essentially grants them full control over the infected device. </p><p>The full list of Indicators of Compromise (IoC) can be found on <a href="https://expel.com/blog/synkloader-when-you-throw-in-everything-but-the-kitchen-sink/" target="_blank" rel="nofollow">this link</a>. To defend against these types of attacks, target companies should instruct their employees not to trust unsolicited Teams messages at face value, and not to install any applications without double-checking (calling) with their IT department first.</p><p>Alongside phone calls, Microsoft Teams is one of the most-used channels for initial contact and compromise. Also, employees remain the weakest link in every company’s cybersecurity chain, unwillingly granting attackers access or sharing login credentials.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/new-synkloader-malware-pushed-in-microsoft-teams-phishing-campaign/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This Android banking trojan uses a fake VPN prompt to silence Google's defenses ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Researchers found banking malware requests VPN permissions to block Google Play and Play Protect on infected Android phones</strong></li><li><strong>ToxicPanda 2.0 bypasses security to install hidden payloads, targeting 349 banking and crypto apps across 16 countries </strong></li><li><strong>The malware can even seize shell-level control of a device</strong></li></ul><p>Security researchers have flagged a new twist in Android banking malware: a trojan that turns your phone's own VPN feature against you. </p><p>A <a href="https://zimperium.com/blog/the-toxicpanda-never-sleeps-toxicpanda-2.0-prepares-its-next-strike-on-mobile" target="_blank" rel="nofollow">report from mobile security firm Zimperium</a> details how ToxicPanda 2.0 abuses VPN permissions to shut down Google's built-in protections before it strikes.</p><p>The tactic is effective because it hides in plain sight. Plenty of legitimate apps ask for VPN access, and even the <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> apps rely on the same underlying permission to route your traffic. ToxicPanda copies that request, but uses the access to cut your phone off from Google Play instead.</p><p>Once Google Play Protect can no longer reach the device, the <a href="https://www.techradar.com/news/what-is-malware-and-how-dangerous-is-it">malware</a> has a clear runway to install its payload and begin harvesting your data.</p><h2 id="how-toxicpanda-uses-vpn-permissions-to-blind-google-play">How ToxicPanda uses VPN permissions to blind Google Play</h2><p>ToxicPanda operates as a "dropper," an app that smuggles in a second, hidden program. According to Zimperium researchers, the malware first shows a fake installation screen and prompts the victim to grant VPN permissions. That request looks routine, so many users tap "allow" without a second thought.</p><p>Granting it lets ToxicPanda create a local network interface that sits between the phone and the internet, giving the malware control over all traffic passing through the device. It immediately uses that control to block communication with Google Play and Google Play Services.</p><p>Cutting off this connection lets the malware interfere with app verifications, updates, and Play Protect, the security layer that would normally flag or remove a harmful app. With Google effectively blindfolded, ToxicPanda decrypts a payload hidden in its own files, installs it, and then asks for Accessibility Service permissions to dig deeper.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:512px;"><p class="vanilla-image-block" style="padding-top:70.12%;"><img id="8Ne52JFZZ7mzAM8PtByEdh" name="unnamed" alt="Screenshots from a malware app" src="https://cdn.mos.cms.futurecdn.net/8Ne52JFZZ7mzAM8PtByEdh.png" mos="" align="middle" fullscreen="" width="512" height="359" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Zimperium)</span></figcaption></figure><p>This release is a major escalation from the <a href="https://www.techradar.com/pro/security/dangerous-android-banking-malware-looks-to-trick-victims-with-fake-money-transfers">previous ToxicPanda iteration</a>. </p><p>As Zimperium says, ToxicPanda 2.0 now supports 167 remote commands. It can also overlay fake login screens on 349 banking, e-wallet, and crypto apps across 16 countries, up from just 16 apps previously. A separate module harvests PINs from more than 140 financial apps using invisible overlays that capture your taps.</p><p>The trojan can also spoof your Android lock screen to steal your PIN, pattern, or password, and it abuses Android's Wireless Debugging (ADB) feature to gain shell-level access and grant itself permissions without prompts.</p><p>ToxicPanda first appeared in 2024, targeting European banks. Other similar malware such as <a href="https://www.techradar.com/pro/security/hundreds-of-android-banking-and-crypto-apps-hit-by-dangerous-new-rokarolla-malware">Rokarolla, has also hit hundreds of banking and crypto apps</a> in recent months.</p><h2 id="how-to-stay-safe-2">How to stay safe</h2><p>The strongest defense is to keep the malware off your phone in the first place. </p><p>Only install apps from the official Google Play Store, and avoid sideloading APK files from links, ads, or third-party sites. Be aware that dangerous <a href="https://www.techradar.com/vpn/vpn-privacy-security/apple-and-google-are-hosting-hundreds-of-dangerous-vpn-links-here-is-why-your-device-is-at-risk">VPN links have even slipped into official app stores</a>, so treat any surprise VPN prompt with suspicion.</p><p>A legitimate VPN remains a valuable privacy tool, but this campaign is a reminder that the permission itself is powerful, so grant it only to apps you genuinely trust.</p><div data-widget-type="multimodelreview" data-model-name="NordVPN,Surfshark,Proton VPN" data-widget-title="Today's best VPN deals"></div> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/vpn/vpn-privacy-security/this-android-banking-trojan-uses-a-fake-vpn-prompt-to-silence-googles-defenses</link>
                                                                            <description>
                            <![CDATA[ ToxicPanda 2.0 abuses Android VPN permissions to block Google Play Protect before stealing banking PINs. Here is how the malware works and how to stay safe. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hKCedBzhxScKDmmt9CYZFF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tEhgdM2MKoCYRwV4Ch3awa-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 24 Aug 2026 15:27:41 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[VPN Privacy & Security]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                                                                <author><![CDATA[ monicajwrites@gmail.com (Monica J. White) ]]></author>                    <dc:creator><![CDATA[ Monica J. White ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/6AQ4y5nzk8kQ47Yp69GERj.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Monica is a journalist with over a decade of experience in covering technology.&lt;/p&gt;&lt;p&gt;She writes about the latest developments in computing, which means anything from computer chips made out of paper to cutting-edge desktop processors. Her coverage includes CPUs, GPUs, and everything else that goes into a PC or a laptop, but also peripherals.&lt;/p&gt;&lt;p&gt;GPUs are Monica’s main area of interest, and nothing thrills her quite like that time every couple of years when new graphics cards hit the market. She’s always keeping tabs on the latest from Nvidia, AMD, and Intel, including both the hardware and the software that powers our PCs.&lt;/p&gt;&lt;p&gt;As an avid gamer, her focus is always on the consumer and whether something works well and provides adequate value for the money. She believes that PC building can be intimidating, so her goal is to explain complex concepts in an approachable manner while still digging into the technical nitty-gritty we all love to learn more about.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tEhgdM2MKoCYRwV4Ch3awa-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image Credit: Flickr]]></media:description>                                                            <media:text><![CDATA[malware]]></media:text>
                                <media:title type="plain"><![CDATA[malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tEhgdM2MKoCYRwV4Ch3awa-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers found banking malware requests VPN permissions to block Google Play and Play Protect on infected Android phones</strong></li><li><strong>ToxicPanda 2.0 bypasses security to install hidden payloads, targeting 349 banking and crypto apps across 16 countries </strong></li><li><strong>The malware can even seize shell-level control of a device</strong></li></ul><p>Security researchers have flagged a new twist in Android banking malware: a trojan that turns your phone's own VPN feature against you. </p><p>A <a href="https://zimperium.com/blog/the-toxicpanda-never-sleeps-toxicpanda-2.0-prepares-its-next-strike-on-mobile" target="_blank" rel="nofollow">report from mobile security firm Zimperium</a> details how ToxicPanda 2.0 abuses VPN permissions to shut down Google's built-in protections before it strikes.</p><p>The tactic is effective because it hides in plain sight. Plenty of legitimate apps ask for VPN access, and even the <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> apps rely on the same underlying permission to route your traffic. ToxicPanda copies that request, but uses the access to cut your phone off from Google Play instead.</p><p>Once Google Play Protect can no longer reach the device, the <a href="https://www.techradar.com/news/what-is-malware-and-how-dangerous-is-it">malware</a> has a clear runway to install its payload and begin harvesting your data.</p><h2 id="how-toxicpanda-uses-vpn-permissions-to-blind-google-play">How ToxicPanda uses VPN permissions to blind Google Play</h2><p>ToxicPanda operates as a "dropper," an app that smuggles in a second, hidden program. According to Zimperium researchers, the malware first shows a fake installation screen and prompts the victim to grant VPN permissions. That request looks routine, so many users tap "allow" without a second thought.</p><p>Granting it lets ToxicPanda create a local network interface that sits between the phone and the internet, giving the malware control over all traffic passing through the device. It immediately uses that control to block communication with Google Play and Google Play Services.</p><p>Cutting off this connection lets the malware interfere with app verifications, updates, and Play Protect, the security layer that would normally flag or remove a harmful app. With Google effectively blindfolded, ToxicPanda decrypts a payload hidden in its own files, installs it, and then asks for Accessibility Service permissions to dig deeper.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:512px;"><p class="vanilla-image-block" style="padding-top:70.12%;"><img id="8Ne52JFZZ7mzAM8PtByEdh" name="unnamed" alt="Screenshots from a malware app" src="https://cdn.mos.cms.futurecdn.net/8Ne52JFZZ7mzAM8PtByEdh.png" mos="" align="middle" fullscreen="" width="512" height="359" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Zimperium)</span></figcaption></figure><p>This release is a major escalation from the <a href="https://www.techradar.com/pro/security/dangerous-android-banking-malware-looks-to-trick-victims-with-fake-money-transfers">previous ToxicPanda iteration</a>. </p><p>As Zimperium says, ToxicPanda 2.0 now supports 167 remote commands. It can also overlay fake login screens on 349 banking, e-wallet, and crypto apps across 16 countries, up from just 16 apps previously. A separate module harvests PINs from more than 140 financial apps using invisible overlays that capture your taps.</p><p>The trojan can also spoof your Android lock screen to steal your PIN, pattern, or password, and it abuses Android's Wireless Debugging (ADB) feature to gain shell-level access and grant itself permissions without prompts.</p><p>ToxicPanda first appeared in 2024, targeting European banks. Other similar malware such as <a href="https://www.techradar.com/pro/security/hundreds-of-android-banking-and-crypto-apps-hit-by-dangerous-new-rokarolla-malware">Rokarolla, has also hit hundreds of banking and crypto apps</a> in recent months.</p><h2 id="how-to-stay-safe-2">How to stay safe</h2><p>The strongest defense is to keep the malware off your phone in the first place. </p><p>Only install apps from the official Google Play Store, and avoid sideloading APK files from links, ads, or third-party sites. Be aware that dangerous <a href="https://www.techradar.com/vpn/vpn-privacy-security/apple-and-google-are-hosting-hundreds-of-dangerous-vpn-links-here-is-why-your-device-is-at-risk">VPN links have even slipped into official app stores</a>, so treat any surprise VPN prompt with suspicion.</p><p>A legitimate VPN remains a valuable privacy tool, but this campaign is a reminder that the permission itself is powerful, so grant it only to apps you genuinely trust.</p><div data-widget-type="multimodelreview" data-model-name="NordVPN,Surfshark,Proton VPN" data-widget-title="Today's best VPN deals"></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'One install, and the phone is no longer yours' — NordVPN warns of fake Ryanair, Emirates, Qatar Airways apps used to spread malware ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>NordVPN found a malware campaign impersonating 65 brands</strong></li><li><strong>It tricks victims into clicking on messages requesting urgent action</strong></li><li><strong>If you use an Android phone, it’s worth checking your apps</strong></li></ul><p>Summer is still in full swing with many people out enjoying their holidays. Unfortunately, cybercriminals never stop trying to steal money by tricking people into believing they are on trustworthy websites or using legitimate apps — especially when our attention is more likely to wander. </p><p>That’s what <a href="https://www.techradar.com/reviews/nordvpn">NordVPN</a>, the pinnacle of the <a href="https://www.techradar.com/vpn/best-vpn">best VPNs</a>, recently investigated, issuing an alert urging caution over a widespread and sophisticated malware campaign targeting Android users through highly convincing phishing schemes. </p><p>The <a href="https://www.techradar.com/news/what-is-malware-and-how-dangerous-is-it">malware</a> is posing as over 65 well-known brands, including Ryanair, Emirates, and Qatar Airways, as well as tax authorities, registry offices, and social security systems that lure you into downloading their apps. </p><p>The dangerous trojan tracks your messages and logins, spies on you through your camera, records your voice, and bypasses two-factor authentication before ultimately draining your bank account.</p><p>The campaign has targeted users in Southeast Asia, Latin America, and Africa.</p><div class="product"><a data-dimension112="1eaf25e6-9fc5-11f1-8408-f73760c3f82f" data-action="Deal Block" data-label="NordVPN &ndash; the best VPN overall NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We&rsquo;re confident that virtually anyone can sign up for NordVPN and get what they need from it. It&rsquo;s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee. NordVPN" data-dimension48="NordVPN &ndash; the best VPN overall NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We&rsquo;re confident that virtually anyone can sign up for NordVPN and get what they need from it. It&rsquo;s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee. NordVPN" href="http://go.nordvpn.net/aff_c?offer_id=564&aff_id=3013&url_id=10992" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="x3Zrr6LPF4qKNzdXj4H4t6" name="NordVPN deal image.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/x3Zrr6LPF4qKNzdXj4H4t6.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong></strong><a href="http://go.nordvpn.net/aff_c?offer_id=564&aff_id=3013&url_id=10992" target="_blank" rel="nofollow" data-dimension112="1eaf25e6-9fc5-11f1-8408-f73760c3f82f" data-action="Deal Block" data-label="NordVPN &ndash; the best VPN overall NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We&rsquo;re confident that virtually anyone can sign up for NordVPN and get what they need from it. It&rsquo;s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee. NordVPN" data-dimension48="NordVPN &ndash; the best VPN overall NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We&rsquo;re confident that virtually anyone can sign up for NordVPN and get what they need from it. It&rsquo;s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee. NordVPN" data-dimension25=""><strong>NordVPN</strong> <strong>– the best VPN overall</strong></a> <br>NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We’re confident that virtually anyone can sign up for NordVPN and get what they need from it. It’s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.</p><p>Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee.<a class="view-deal button" href="http://go.nordvpn.net/aff_c?offer_id=564&aff_id=3013&url_id=10992" target="_blank" rel="nofollow" data-dimension112="1eaf25e6-9fc5-11f1-8408-f73760c3f82f" data-action="Deal Block" data-label="NordVPN &ndash; the best VPN overall NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We&rsquo;re confident that virtually anyone can sign up for NordVPN and get what they need from it. It&rsquo;s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee. NordVPN" data-dimension48="NordVPN &ndash; the best VPN overall NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We&rsquo;re confident that virtually anyone can sign up for NordVPN and get what they need from it. It&rsquo;s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee. NordVPN" data-dimension25="">View Deal</a></p></div><h2 id="what-the-research-found">What the research found</h2><p>NordVPN spent the last 12 months investigating the malware campaign — including its infrastructure and impersonation targets — analysing malware clusters and mapping more than 100 domains linked to the campaign. </p><p>It discovered that the campaign tricks users into installing an app that grants full access to their Android phones or computers by impersonating highly trustworthy companies — brands people are accustomed to providing their personal data without questioning it.</p><p>Victims are lured by a variety of requests via SMS, WhatsApp, or social media that look totally innocuous, like a job opening at an airline, a cheap flight, or a tax refund.</p><p>Once installed, the Trojan runs quietly in the background and stays active even if the phone is restarted, accessing your messages and call logs, capturing the screen, recording audio, and accessing the camera. </p><p>Attackers can even log into the victim's banking app and approve transactions themselves by using SMS interception to steal your money, as most banks implement two-factor authentication through one-time codes sent by text. </p><p>Marijus Briedis, chief technology officer at NordVPN, says: "One install, and the phone is no longer yours. The attacker sees your screen, reads your SMS codes, and empties your accounts from the inside."</p><p>Trusted brands are <a href="https://www.techradar.com/pro/security/who-are-the-most-spoofed-brands-in-phishing-scams-to-be-honest-you-can-probably-guess-most-of-them">often the most spoofed brands in phishing scams, </a>alongside other malware 'tricks' to gain trust, such as <a href="https://www.techradar.com/pro/security/this-creates-a-misleading-impression-of-safety-experts-warn-of-hackers-hijacking-legitimate-news-websites-and-reviews-to-drum-up-publicity">multi-platform PR campaigns</a> promoting malware as legitimate software, or even Chrome extensions <a href="http://www.techradar.com/vpn/vpn-services/hundreds-of-fake-chrome-vpn-extensions-impersonating-nordvpn-proton-and-more-caught-hijacking-your-traffic">impersonating VPNs</a>. </p><p>However, unlike many opportunistic phishing attempts, these attacks have been particularly hard to spot, featuring extremely accurate replicas of legitimate websites, meticulously copied and professionally translated. </p><h2 id="how-to-stay-safe-3">How to stay safe</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:3972px;"><p class="vanilla-image-block" style="padding-top:56.27%;"><img id="YQaVTQE6JAfu6bvPgwmd5U" name="shutterstock_1454959559.jpg" alt="Phone malware" src="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U.jpg" mos="" align="middle" fullscreen="" width="3972" height="2235" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Briedis advises Android users to be very careful <strong>not to install apps from links received via text message</strong>. "Real airlines, banks and government bodies distribute apps through Google Play, not SMS or WhatsApp," he stresses. </p><p>As with other <a href="https://www.techradar.com/computing/cyber-security/ai-impersonation-scams-are-sky-rocketing-in-2025-security-experts-warn-heres-how-to-stay-safe">AI impersonating scams</a>, users should <strong>treat any urgent request as a warning sign</strong>: whenever there is mention of a refund or an account being blocked, check the source carefully before clicking on anything or taking any action.</p><p><strong>Checking that a website is legitimate</strong> and does not operate from domains ending in .cc, .lol, .xyz, .mom, or .pw will be a clear safety indicator.</p><p>Furthermore, <strong>do not rely on 'the padlock icon'</strong>: an HTTPS connection merely indicates that the connection is encrypted, not that the site is genuine.</p><p>If you suspect that a suspicious app is already on your phone, <strong>disconnect your phone</strong> from the internet, <strong>uninstall the app</strong>, <strong>change your password</strong> from another device, and<strong> contact your bank</strong>: this will ensure you’re back in the clear.</p><p>And remember that if even the <a href="https://www.techradar.com/vpn/vpn-services/surfshark-warns-personal-devices-are-a-wide-open-door-as-uk-prime-minister-falls-for-impersonation-scam">current UK Prime Minister</a> can be a scam target, perhaps you should remain vigilant too.</p><div data-widget-type="review" data-model-name="NordVPN"></div> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/vpn/vpn-privacy-security/one-install-and-the-phone-is-no-longer-yours-nordvpn-warns-of-fake-ryanair-emirates-qatar-airways-apps-used-to-spread-malware</link>
                                                                            <description>
                            <![CDATA[ NordVPN urges caution online over a banking Trojan masquerading as more than 65 reputable brands. Here’s how to protect your phone. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">g3NJFZKAd3ZzHVFzoQHFU7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VX6FoHeTsueFCVN6BdgJA3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 24 Aug 2026 14:08:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[VPN Privacy & Security]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                                                                                    <dc:creator><![CDATA[ Silvia Iacovcich ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/e3cAo9wuAWurJxj5eRkg8M.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Silvia Iacovcich is a tech journalist with over five years of experience in the field, including AI, cybersecurity, and fintech. She has written for various publications focusing on the evolving regulatory landscape of AI, digital behavior, web3, and blockchain, as well as social media privacy and security regulations. &lt;/p&gt;&lt;p&gt;Silvia is fluent in Italian, French, Spanish, and Portuguese, and also knows a little Russian. Outside of work, she reads a lot (not just tech books, although many are) and enjoys hiking, running, and trying new types of beers.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VX6FoHeTsueFCVN6BdgJA3-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Person using a phone, holding their credit card and looking puzzled over whether something might be a scam]]></media:description>                                                            <media:text><![CDATA[Person using a phone, holding their credit card and looking puzzled over whether something might be a scam]]></media:text>
                                <media:title type="plain"><![CDATA[Person using a phone, holding their credit card and looking puzzled over whether something might be a scam]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VX6FoHeTsueFCVN6BdgJA3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>NordVPN found a malware campaign impersonating 65 brands</strong></li><li><strong>It tricks victims into clicking on messages requesting urgent action</strong></li><li><strong>If you use an Android phone, it’s worth checking your apps</strong></li></ul><p>Summer is still in full swing with many people out enjoying their holidays. Unfortunately, cybercriminals never stop trying to steal money by tricking people into believing they are on trustworthy websites or using legitimate apps — especially when our attention is more likely to wander. </p><p>That’s what <a href="https://www.techradar.com/reviews/nordvpn">NordVPN</a>, the pinnacle of the <a href="https://www.techradar.com/vpn/best-vpn">best VPNs</a>, recently investigated, issuing an alert urging caution over a widespread and sophisticated malware campaign targeting Android users through highly convincing phishing schemes. </p><p>The <a href="https://www.techradar.com/news/what-is-malware-and-how-dangerous-is-it">malware</a> is posing as over 65 well-known brands, including Ryanair, Emirates, and Qatar Airways, as well as tax authorities, registry offices, and social security systems that lure you into downloading their apps. </p><p>The dangerous trojan tracks your messages and logins, spies on you through your camera, records your voice, and bypasses two-factor authentication before ultimately draining your bank account.</p><p>The campaign has targeted users in Southeast Asia, Latin America, and Africa.</p><div class="product"><a data-dimension112="1eaf25e6-9fc5-11f1-8408-f73760c3f82f" data-action="Deal Block" data-label="NordVPN &ndash; the best VPN overall NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We&rsquo;re confident that virtually anyone can sign up for NordVPN and get what they need from it. It&rsquo;s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee. NordVPN" data-dimension48="NordVPN &ndash; the best VPN overall NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We&rsquo;re confident that virtually anyone can sign up for NordVPN and get what they need from it. It&rsquo;s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee. NordVPN" href="http://go.nordvpn.net/aff_c?offer_id=564&aff_id=3013&url_id=10992" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="x3Zrr6LPF4qKNzdXj4H4t6" name="NordVPN deal image.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/x3Zrr6LPF4qKNzdXj4H4t6.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong></strong><a href="http://go.nordvpn.net/aff_c?offer_id=564&aff_id=3013&url_id=10992" target="_blank" rel="nofollow" data-dimension112="1eaf25e6-9fc5-11f1-8408-f73760c3f82f" data-action="Deal Block" data-label="NordVPN &ndash; the best VPN overall NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We&rsquo;re confident that virtually anyone can sign up for NordVPN and get what they need from it. It&rsquo;s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee. NordVPN" data-dimension48="NordVPN &ndash; the best VPN overall NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We&rsquo;re confident that virtually anyone can sign up for NordVPN and get what they need from it. It&rsquo;s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee. NordVPN" data-dimension25=""><strong>NordVPN</strong> <strong>– the best VPN overall</strong></a> <br>NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We’re confident that virtually anyone can sign up for NordVPN and get what they need from it. It’s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.</p><p>Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee.<a class="view-deal button" href="http://go.nordvpn.net/aff_c?offer_id=564&aff_id=3013&url_id=10992" target="_blank" rel="nofollow" data-dimension112="1eaf25e6-9fc5-11f1-8408-f73760c3f82f" data-action="Deal Block" data-label="NordVPN &ndash; the best VPN overall NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We&rsquo;re confident that virtually anyone can sign up for NordVPN and get what they need from it. It&rsquo;s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee. NordVPN" data-dimension48="NordVPN &ndash; the best VPN overall NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We&rsquo;re confident that virtually anyone can sign up for NordVPN and get what they need from it. It&rsquo;s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee. NordVPN" data-dimension25="">View Deal</a></p></div><h2 id="what-the-research-found">What the research found</h2><p>NordVPN spent the last 12 months investigating the malware campaign — including its infrastructure and impersonation targets — analysing malware clusters and mapping more than 100 domains linked to the campaign. </p><p>It discovered that the campaign tricks users into installing an app that grants full access to their Android phones or computers by impersonating highly trustworthy companies — brands people are accustomed to providing their personal data without questioning it.</p><p>Victims are lured by a variety of requests via SMS, WhatsApp, or social media that look totally innocuous, like a job opening at an airline, a cheap flight, or a tax refund.</p><p>Once installed, the Trojan runs quietly in the background and stays active even if the phone is restarted, accessing your messages and call logs, capturing the screen, recording audio, and accessing the camera. </p><p>Attackers can even log into the victim's banking app and approve transactions themselves by using SMS interception to steal your money, as most banks implement two-factor authentication through one-time codes sent by text. </p><p>Marijus Briedis, chief technology officer at NordVPN, says: "One install, and the phone is no longer yours. The attacker sees your screen, reads your SMS codes, and empties your accounts from the inside."</p><p>Trusted brands are <a href="https://www.techradar.com/pro/security/who-are-the-most-spoofed-brands-in-phishing-scams-to-be-honest-you-can-probably-guess-most-of-them">often the most spoofed brands in phishing scams, </a>alongside other malware 'tricks' to gain trust, such as <a href="https://www.techradar.com/pro/security/this-creates-a-misleading-impression-of-safety-experts-warn-of-hackers-hijacking-legitimate-news-websites-and-reviews-to-drum-up-publicity">multi-platform PR campaigns</a> promoting malware as legitimate software, or even Chrome extensions <a href="http://www.techradar.com/vpn/vpn-services/hundreds-of-fake-chrome-vpn-extensions-impersonating-nordvpn-proton-and-more-caught-hijacking-your-traffic">impersonating VPNs</a>. </p><p>However, unlike many opportunistic phishing attempts, these attacks have been particularly hard to spot, featuring extremely accurate replicas of legitimate websites, meticulously copied and professionally translated. </p><h2 id="how-to-stay-safe-3">How to stay safe</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:3972px;"><p class="vanilla-image-block" style="padding-top:56.27%;"><img id="YQaVTQE6JAfu6bvPgwmd5U" name="shutterstock_1454959559.jpg" alt="Phone malware" src="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U.jpg" mos="" align="middle" fullscreen="" width="3972" height="2235" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Briedis advises Android users to be very careful <strong>not to install apps from links received via text message</strong>. "Real airlines, banks and government bodies distribute apps through Google Play, not SMS or WhatsApp," he stresses. </p><p>As with other <a href="https://www.techradar.com/computing/cyber-security/ai-impersonation-scams-are-sky-rocketing-in-2025-security-experts-warn-heres-how-to-stay-safe">AI impersonating scams</a>, users should <strong>treat any urgent request as a warning sign</strong>: whenever there is mention of a refund or an account being blocked, check the source carefully before clicking on anything or taking any action.</p><p><strong>Checking that a website is legitimate</strong> and does not operate from domains ending in .cc, .lol, .xyz, .mom, or .pw will be a clear safety indicator.</p><p>Furthermore, <strong>do not rely on 'the padlock icon'</strong>: an HTTPS connection merely indicates that the connection is encrypted, not that the site is genuine.</p><p>If you suspect that a suspicious app is already on your phone, <strong>disconnect your phone</strong> from the internet, <strong>uninstall the app</strong>, <strong>change your password</strong> from another device, and<strong> contact your bank</strong>: this will ensure you’re back in the clear.</p><p>And remember that if even the <a href="https://www.techradar.com/vpn/vpn-services/surfshark-warns-personal-devices-are-a-wide-open-door-as-uk-prime-minister-falls-for-impersonation-scam">current UK Prime Minister</a> can be a scam target, perhaps you should remain vigilant too.</p><div data-widget-type="review" data-model-name="NordVPN"></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The ascent of autonomous attacks and the race to contain them ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Cyber risk is now a board room issue, and we have seen clear examples of this in the UK. The 2025 Jaguar Land Rover attack left the carmaker with a £485m loss, swallowing up the £398m profit it had generated just 12 months before.</p><p>Production lines were halted for more than a month as the company shut down parts of its network, showing how quickly a cyber incident can affect <a href="https://www.techradar.com/best/best-small-business-software">business</a> performance, operational continuity and the wider supply chain. </p><p>Now, businesses are facing a fresh type of threat made possible by AI – the autonomous attack. Attackers can already automate parts of target research, initial access and <a href="https://www.techradar.com/best/best-malware-removal">malware</a> development, with any manual effort shrinking rapidly. </p><p>Simultaneously, the trust layer people rely on is eroding with the spread of AI-generated content and deepfakes. It’s a race to tackle the autonomous attack, but how do organizations formulate an effective response?</p><h2 id="ai-in-a-cyber-attacker-s-armory">AI in a cyber-attacker’s armory</h2><p>AI-driven automated technologies are strengthening a cyber-attacker’s armory. Prior to leveraging <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a>, bad actors often had to commit time and resources to researching a target company before planning an attack.</p><p>Timing was critical, and a perpetrator had to manually coordinate and initiate an attack at a specific time and could simply forget. AI doesn’t - and the rise of attack-as-a-service tools is making it possible to successfully breach organizations quickly and accurately.</p><p>Guardrails are starting to be put up around established generative AI tools, such as ChatGPT and Claude, in an effort to prevent this kind of misuse. But hackers are finding workarounds.</p><p>Rather than relying on readily available large language models (LLMs), they are deploying their own small language models (SLMs) on local devices, often on something as basic as a Raspberry Pi computer. From there, they can escalate attacks while hiding in the shadows. </p><h2 id="the-threat-to-businesses-of-all-sizes">The threat to businesses of all sizes</h2><p>The rise of automated attacks also means that <a href="https://www.techradar.com/best/best-business-cloud-storage-service">businesses</a> of all sizes are likely to be identified by automated technology as having exploitable vulnerabilities. Small and medium-sized businesses would previously have been off the radar as attacks relied on a bad actor’s knowledge of their existence.</p><p>However, AI can now scan and process vast numbers of organizations at speed, potentially leaving smaller firms, which are less likely to have robust cyber controls in place, more exposed. And even more so among smaller businesses, defenses are typically more fragmented and less organized than AI-driven attacks.</p><p>In other words, with AI by their side, attackers can coordinate and scale far better and much more quickly than most businesses can defend. </p><p>Autonomous attacks also make third-party and supply chain risk much harder to manage. Business networks can create access to <a href="https://www.techradar.com/best/best-data-recovery-software">data</a>, systems or operational processes. When attackers can automate reconnaissance and scale attacks across thousands of organizations, weaker suppliers may become an attractive route into larger businesses.</p><p>This is a particular concern because third-party risk management has often relied on annual questionnaires, point-in-time assessments and contractual assurances, but these approaches are no longer enough on their own. A supplier may have recently exposed a service, suffered a breach, changed its access privileges or failed to patch a critical vulnerability.</p><p>Businesses therefore need to move towards continuous, automated monitoring of supplier <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> posture. </p><p>Regulations such as NIS2 have also increased the focus on supply chain security for organizations operating in, or selling into, the EU. There is also a growing expectation from ICO and the FCA that boards can demonstrate cyber resilience.</p><h2 id="automation-and-the-rise-of-specific-attack-types">Automation and the rise of specific attack types</h2><p>Jadepuffer illustrates how AI is beginning to transform established attack types. Disclosed by Sysdig in July 2026, it was assessed as the first documented end-to-end LLM-driven extortion operation, with an AI agent conducting reconnaissance, harvesting credentials, moving between systems, destroying data and adapting when individual actions failed.</p><p>While none of the techniques were especially new in isolation, the significance was the way the AI connected them into a complete, adaptive attack.</p><p>Social engineering techniques, such as bad actors posing as trusted individuals, are becoming much more convincing in their approach. Fluent, grammatically correct messages and the professional tone and style of CEO communications can now be fully replicated on <a href="https://www.techradar.com/news/best-email-provider">emails</a>, SMS and even WhatsApp.</p><p>AI can even manage the entire conversation thread, including dynamically adapting responses to a target’s replies, with it possible to run simultaneous, tailored campaigns.</p><p>Vendor email compromise, where criminals impersonate suppliers, intercept genuine payment conversations or use compromised vendor accounts to request changes to bank details, directly links social engineering to third-party risk. </p><p>Taking a step back, the initial harvesting process of personal data for social engineering attacks can be streamlined. AI can automatically scrape data from public sources such as Companies House and social media to quickly provide the names of specific people, their roles and relationships. </p><h2 id="when-trust-and-identity-come-under-attack">When trust and identity come under attack</h2><p>Even on video conferencing calls, it’s becoming increasingly difficult to tell if the person you’re speaking to is real due to the increasing accuracy of deepfakes. As an example, it’s often now necessary to ask a suspected deepfake to do something it wasn’t programmed to do, such as raise a hand, to check if the person in question is real. But even that test is gradually being circumvented by new technology. </p><p>Organizations need stronger out-of-band verification protocols for high-value or unusual requests. A pre-agreed code word via a separate channel might be needed to ensure trust and security.</p><p><a href="https://www.techradar.com/best/best-identity-theft-protection">Identity</a> security is becoming a key area of defense as autonomous attacks become more advanced. Credential stuffing at scale, session cookie harvesting, MFA fatigue attacks and vishing attempts designed to bypass multi-factor authentication are all increasing. AI can make these attacks more efficient by identifying likely targets, generating convincing scripts and adapting to the victim's responses in real time. </p><p>This is why identity and access management should be treated as a critical control. Organizations need to know who has access to what, whether that access is still needed, which accounts are privileged and how quickly unusual behavior can be detected. </p><h2 id="fighting-ai-with-ai">Fighting AI with AI</h2><p>AI-driven autonomous attacks might be heightening the risk, but AI can also be used defensively. A good example of this is to run an automated risk analysis of an organization and highlight where security tools and the basics, such as malware protection, are out of date or missing.</p><p>With those fundamentals in place, AI can then underpin continuous monitoring of the critical systems, rather than periodic checks. Businesses should be identifying and focusing on protecting the “crown jewels” – that might be the top 10 most critical assets, such as payroll or a banking system, and target AI-led efforts on protecting them. </p><p>Joined-up visibility is then crucial. Businesses need to know who has access to those critical assets, the <a href="https://www.techradar.com/news/best-endpoint-security-software">endpoint</a> and network activity related to them and gain the ability to correlate any incidents quickly so the response to an AI-driven attack can be as swift as possible.</p><p>A combination of AI-powered technology, backed by human expertise, can provide proactive threat hunting to actively search for, investigate and remediate dangers, even if they are autonomous in origin.</p><h2 id="organizations-aren-t-powerless-in-the-fight">Organizations aren’t powerless in the fight</h2><p>The rise of autonomous attacks marks a new phase in cyber risk. For many businesses, particularly smaller ones, the challenge is preparing for attacks that can move much faster than traditional defenses. But organizations aren’t powerless in the fight. </p><p>Effective responses start with getting the basics right, from access controls to visibility across critical assets, to moving from periodic checks to continuous monitoring and faster detection with AI.</p><p>However, technology alone won’t be enough. Human expertise can interpret risk and make informed decisions under pressure to ensure resilience, even as the AI-driven autonomy threat moves to the next level.</p><p><em></em><a href="https://www.techradar.com/best/firewall"><em>We've featured the best firewall software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/the-ascent-of-autonomous-attacks-and-the-race-to-contain-them</link>
                                                                            <description>
                            <![CDATA[ Autonomous AI attacks are accelerating, forcing businesses to rethink cyber defense, identity and resilience. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m9Lu7apzNuBGXWiAhYqBn4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UjSNcAZ5SebctebKAMQNVF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 24 Aug 2026 10:06:15 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ian Bowell ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UjSNcAZ5SebctebKAMQNVF-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity ensures data protection on internet. Data encryption, firewall, encrypted network, VPN, secure access and authentication defend against malware, hacking, cyber crime and digital threat]]></media:description>                                                            <media:text><![CDATA[Cybersecurity ensures data protection on internet. Data encryption, firewall, encrypted network, VPN, secure access and authentication defend against malware, hacking, cyber crime and digital threat]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity ensures data protection on internet. Data encryption, firewall, encrypted network, VPN, secure access and authentication defend against malware, hacking, cyber crime and digital threat]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UjSNcAZ5SebctebKAMQNVF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber risk is now a board room issue, and we have seen clear examples of this in the UK. The 2025 Jaguar Land Rover attack left the carmaker with a £485m loss, swallowing up the £398m profit it had generated just 12 months before.</p><p>Production lines were halted for more than a month as the company shut down parts of its network, showing how quickly a cyber incident can affect <a href="https://www.techradar.com/best/best-small-business-software">business</a> performance, operational continuity and the wider supply chain. </p><p>Now, businesses are facing a fresh type of threat made possible by AI – the autonomous attack. Attackers can already automate parts of target research, initial access and <a href="https://www.techradar.com/best/best-malware-removal">malware</a> development, with any manual effort shrinking rapidly. </p><p>Simultaneously, the trust layer people rely on is eroding with the spread of AI-generated content and deepfakes. It’s a race to tackle the autonomous attack, but how do organizations formulate an effective response?</p><h2 id="ai-in-a-cyber-attacker-s-armory">AI in a cyber-attacker’s armory</h2><p>AI-driven automated technologies are strengthening a cyber-attacker’s armory. Prior to leveraging <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a>, bad actors often had to commit time and resources to researching a target company before planning an attack.</p><p>Timing was critical, and a perpetrator had to manually coordinate and initiate an attack at a specific time and could simply forget. AI doesn’t - and the rise of attack-as-a-service tools is making it possible to successfully breach organizations quickly and accurately.</p><p>Guardrails are starting to be put up around established generative AI tools, such as ChatGPT and Claude, in an effort to prevent this kind of misuse. But hackers are finding workarounds.</p><p>Rather than relying on readily available large language models (LLMs), they are deploying their own small language models (SLMs) on local devices, often on something as basic as a Raspberry Pi computer. From there, they can escalate attacks while hiding in the shadows. </p><h2 id="the-threat-to-businesses-of-all-sizes">The threat to businesses of all sizes</h2><p>The rise of automated attacks also means that <a href="https://www.techradar.com/best/best-business-cloud-storage-service">businesses</a> of all sizes are likely to be identified by automated technology as having exploitable vulnerabilities. Small and medium-sized businesses would previously have been off the radar as attacks relied on a bad actor’s knowledge of their existence.</p><p>However, AI can now scan and process vast numbers of organizations at speed, potentially leaving smaller firms, which are less likely to have robust cyber controls in place, more exposed. And even more so among smaller businesses, defenses are typically more fragmented and less organized than AI-driven attacks.</p><p>In other words, with AI by their side, attackers can coordinate and scale far better and much more quickly than most businesses can defend. </p><p>Autonomous attacks also make third-party and supply chain risk much harder to manage. Business networks can create access to <a href="https://www.techradar.com/best/best-data-recovery-software">data</a>, systems or operational processes. When attackers can automate reconnaissance and scale attacks across thousands of organizations, weaker suppliers may become an attractive route into larger businesses.</p><p>This is a particular concern because third-party risk management has often relied on annual questionnaires, point-in-time assessments and contractual assurances, but these approaches are no longer enough on their own. A supplier may have recently exposed a service, suffered a breach, changed its access privileges or failed to patch a critical vulnerability.</p><p>Businesses therefore need to move towards continuous, automated monitoring of supplier <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> posture. </p><p>Regulations such as NIS2 have also increased the focus on supply chain security for organizations operating in, or selling into, the EU. There is also a growing expectation from ICO and the FCA that boards can demonstrate cyber resilience.</p><h2 id="automation-and-the-rise-of-specific-attack-types">Automation and the rise of specific attack types</h2><p>Jadepuffer illustrates how AI is beginning to transform established attack types. Disclosed by Sysdig in July 2026, it was assessed as the first documented end-to-end LLM-driven extortion operation, with an AI agent conducting reconnaissance, harvesting credentials, moving between systems, destroying data and adapting when individual actions failed.</p><p>While none of the techniques were especially new in isolation, the significance was the way the AI connected them into a complete, adaptive attack.</p><p>Social engineering techniques, such as bad actors posing as trusted individuals, are becoming much more convincing in their approach. Fluent, grammatically correct messages and the professional tone and style of CEO communications can now be fully replicated on <a href="https://www.techradar.com/news/best-email-provider">emails</a>, SMS and even WhatsApp.</p><p>AI can even manage the entire conversation thread, including dynamically adapting responses to a target’s replies, with it possible to run simultaneous, tailored campaigns.</p><p>Vendor email compromise, where criminals impersonate suppliers, intercept genuine payment conversations or use compromised vendor accounts to request changes to bank details, directly links social engineering to third-party risk. </p><p>Taking a step back, the initial harvesting process of personal data for social engineering attacks can be streamlined. AI can automatically scrape data from public sources such as Companies House and social media to quickly provide the names of specific people, their roles and relationships. </p><h2 id="when-trust-and-identity-come-under-attack">When trust and identity come under attack</h2><p>Even on video conferencing calls, it’s becoming increasingly difficult to tell if the person you’re speaking to is real due to the increasing accuracy of deepfakes. As an example, it’s often now necessary to ask a suspected deepfake to do something it wasn’t programmed to do, such as raise a hand, to check if the person in question is real. But even that test is gradually being circumvented by new technology. </p><p>Organizations need stronger out-of-band verification protocols for high-value or unusual requests. A pre-agreed code word via a separate channel might be needed to ensure trust and security.</p><p><a href="https://www.techradar.com/best/best-identity-theft-protection">Identity</a> security is becoming a key area of defense as autonomous attacks become more advanced. Credential stuffing at scale, session cookie harvesting, MFA fatigue attacks and vishing attempts designed to bypass multi-factor authentication are all increasing. AI can make these attacks more efficient by identifying likely targets, generating convincing scripts and adapting to the victim's responses in real time. </p><p>This is why identity and access management should be treated as a critical control. Organizations need to know who has access to what, whether that access is still needed, which accounts are privileged and how quickly unusual behavior can be detected. </p><h2 id="fighting-ai-with-ai">Fighting AI with AI</h2><p>AI-driven autonomous attacks might be heightening the risk, but AI can also be used defensively. A good example of this is to run an automated risk analysis of an organization and highlight where security tools and the basics, such as malware protection, are out of date or missing.</p><p>With those fundamentals in place, AI can then underpin continuous monitoring of the critical systems, rather than periodic checks. Businesses should be identifying and focusing on protecting the “crown jewels” – that might be the top 10 most critical assets, such as payroll or a banking system, and target AI-led efforts on protecting them. </p><p>Joined-up visibility is then crucial. Businesses need to know who has access to those critical assets, the <a href="https://www.techradar.com/news/best-endpoint-security-software">endpoint</a> and network activity related to them and gain the ability to correlate any incidents quickly so the response to an AI-driven attack can be as swift as possible.</p><p>A combination of AI-powered technology, backed by human expertise, can provide proactive threat hunting to actively search for, investigate and remediate dangers, even if they are autonomous in origin.</p><h2 id="organizations-aren-t-powerless-in-the-fight">Organizations aren’t powerless in the fight</h2><p>The rise of autonomous attacks marks a new phase in cyber risk. For many businesses, particularly smaller ones, the challenge is preparing for attacks that can move much faster than traditional defenses. But organizations aren’t powerless in the fight. </p><p>Effective responses start with getting the basics right, from access controls to visibility across critical assets, to moving from periodic checks to continuous monitoring and faster detection with AI.</p><p>However, technology alone won’t be enough. Human expertise can interpret risk and make informed decisions under pressure to ensure resilience, even as the AI-driven autonomy threat moves to the next level.</p><p><em></em><a href="https://www.techradar.com/best/firewall"><em>We've featured the best firewall software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This new malware can use Google passkeys even after a victim resets their password ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>iAuthFlow v2 sold on Russian forums lets attackers persist in email accounts  </strong></li><li><strong>Tool phishes logins, then secretly creates attacker‑controlled passkeys for lasting access  </strong></li><li><strong>Defenses include auditing passkeys, OAuth tokens, mail rules, and removing rogue methods</strong></li></ul><p>Security researchers have discovered a new <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> toolkit which allows threat actors to log back into compromised email accounts even after the password was changed and all sessions terminated.</p><p>iAuthFlow v2 is currently being sold on Russian dark web forums for north of $10,000, a new <a href="https://abnormal.ai/blog/iauthflow-v2-phishing-google-passkeys" target="_blank" rel="nofollow">report</a> from cybersecurity experts from Abnormal said, as they obtained a copy of iAuthFlow v2 for analysis.</p><p>The malware primarily works as a phishing tool, trying to trick users into logging into either Google, Microsoft, iCloud, or LinkedIn. As soon as they do that, they relay the login credentials to the attackers, who log into the accounts on their end, as well - before the tool displays a “processing” page for a few seconds while, in the background, it sets up a new passkey. </p><h2 id="how-to-defend-against-iauthflow-v2">How to defend against iAuthFlow v2</h2><p>A passkey is an alternative means of authentication that is often touted as the “<a href="https://www.techradar.com/best/password-manager" target="_blank">password</a> killer”. It uses cryptographic keys stored on a device, allowing users to sign in with a fingerprint, face scan, or device PIN. </p><p>Because the secret key never leaves the device, it is resistant to phishing. However, if the threat actor is able to generate a key of their own, on the device they own, access is basically guaranteed. </p><p>The ad for the toolkit also comes with a video demo, showing how it works. In the demo, iAuthFlow v2 created the passkey six seconds after authentication. </p><p>However, generating a passkey is not that straightforward of a process and it could encounter hiccups, Abnormal hints, saying that Google, for example, might require further identity verification before allowing the change.</p><p>Usually, when a threat actor compromises an <a href="https://www.techradar.com/news/best-email-provider" target="_blank">email account</a>, terminating all sessions and changing the password is usually enough.</p><p>In this case, however, users should do a lot more: review the account for signs of compromise, including unauthorized passkeys or security keys, malicious Gmail filters and forwarding rules, recovery and delegated access changes, and unauthorized applications, Abnormal suggests.</p><p>They should also revoke relevant OAuth tokens and grants, investigate available sign-in, mail-rule, 2-Step Verification, passkey and OAuth audit events, and finally, make sure any attacker-enrolled authentication methods are removed.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/this-new-malware-can-use-google-passkeys-even-after-a-victim-resets-their-password</link>
                                                                            <description>
                            <![CDATA[ A newly discovered toolkit can deeply compromise Gmail, Microsoft, Apple, and LinkedIn accounts ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XL5nrccyjA7YTcv5HwxC9C</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QGZS7tno9wMKaY7FVBDSNE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 21 Aug 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QGZS7tno9wMKaY7FVBDSNE-1280-80.jpg">
                                                            <media:credit><![CDATA[Ascannio / Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Gmail app listing]]></media:description>                                                            <media:text><![CDATA[Gmail app listing]]></media:text>
                                <media:title type="plain"><![CDATA[Gmail app listing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QGZS7tno9wMKaY7FVBDSNE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>iAuthFlow v2 sold on Russian forums lets attackers persist in email accounts  </strong></li><li><strong>Tool phishes logins, then secretly creates attacker‑controlled passkeys for lasting access  </strong></li><li><strong>Defenses include auditing passkeys, OAuth tokens, mail rules, and removing rogue methods</strong></li></ul><p>Security researchers have discovered a new <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> toolkit which allows threat actors to log back into compromised email accounts even after the password was changed and all sessions terminated.</p><p>iAuthFlow v2 is currently being sold on Russian dark web forums for north of $10,000, a new <a href="https://abnormal.ai/blog/iauthflow-v2-phishing-google-passkeys" target="_blank" rel="nofollow">report</a> from cybersecurity experts from Abnormal said, as they obtained a copy of iAuthFlow v2 for analysis.</p><p>The malware primarily works as a phishing tool, trying to trick users into logging into either Google, Microsoft, iCloud, or LinkedIn. As soon as they do that, they relay the login credentials to the attackers, who log into the accounts on their end, as well - before the tool displays a “processing” page for a few seconds while, in the background, it sets up a new passkey. </p><h2 id="how-to-defend-against-iauthflow-v2">How to defend against iAuthFlow v2</h2><p>A passkey is an alternative means of authentication that is often touted as the “<a href="https://www.techradar.com/best/password-manager" target="_blank">password</a> killer”. It uses cryptographic keys stored on a device, allowing users to sign in with a fingerprint, face scan, or device PIN. </p><p>Because the secret key never leaves the device, it is resistant to phishing. However, if the threat actor is able to generate a key of their own, on the device they own, access is basically guaranteed. </p><p>The ad for the toolkit also comes with a video demo, showing how it works. In the demo, iAuthFlow v2 created the passkey six seconds after authentication. </p><p>However, generating a passkey is not that straightforward of a process and it could encounter hiccups, Abnormal hints, saying that Google, for example, might require further identity verification before allowing the change.</p><p>Usually, when a threat actor compromises an <a href="https://www.techradar.com/news/best-email-provider" target="_blank">email account</a>, terminating all sessions and changing the password is usually enough.</p><p>In this case, however, users should do a lot more: review the account for signs of compromise, including unauthorized passkeys or security keys, malicious Gmail filters and forwarding rules, recovery and delegated access changes, and unauthorized applications, Abnormal suggests.</p><p>They should also revoke relevant OAuth tokens and grants, investigate available sign-in, mail-rule, 2-Step Verification, passkey and OAuth audit events, and finally, make sure any attacker-enrolled authentication methods are removed.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security experts targeted by fake crypto conference in scam to hand over details ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Huntress spotted a ClickFix campaign targeting security pros via fake conference invites  </strong></li><li><strong>Victims tricked into pasting code that installs AMOS infostealer on macOS </strong></li><li><strong>If lured, isolate systems, reset credentials, rotate secrets, and review cryptocurrency wallets</strong></li></ul><p>Cybercriminals are targeting security professionals with a highly tailored ClickFix campaign in an attempt to get their computers infected with infostealer <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, experts have warned.</p><p>An active campaign against people who have attended, or have a history of attending, various cybersecurity conferences such as Black Hat, or DEF CON has been detetced by security researchers <a href="https://www.huntress.com/blog/defcon-phishing-google-doc-malware" target="_blank">Huntress</a>, who were targets themselves. </p><p>The attack starts on X, where the threat actor uses a fake account to interact with people visiting and sharing content from these conferences. After establishing rapport, they move into DMs, claiming they’re organizing a conference of their own, and sharing a Google Docs file containing “more info” with the victim. </p><h2 id="follow-up-attack">Follow-up attack</h2><p>Here is where the attackersy go for the ClickFix attack. The document comes with a vertical sidebar, apparently as a security feature that keeps the contents of the file encrypted. The victim is given a decryption code to enter, but it returns an error and offers a solution - to bring up the Terminal and copy/paste a piece of code.</p><p>From here, it’s the usual ClickFix practice: the victim ends up downloading and running AMOS, a notorious Mac infostealer capable of grabbing browser information, cookies, keychain data, cryptocurrency wallet information, Telegram files, and more. The Windows variant did not work when Huntress tried to analyze it, but it’s safe to assume the end goal is the same.</p><p>Huntress also found that this is not where the attack ends. If the victim does not install the infostealer, the threat actor will follow up with a different document, this time pretending to be for Dropbox and working only with the desktop app. Of course, the download button leads straight back to the infostealer.</p><p>The researchers shared a full list of Indicators of Compromise (IoC) which can be found on this link. They also advised anyone who interacted with this kind of lure to isolate the system from the network, collect relevant forensic evidence, and “consider reimaging the system”. </p><p>“Assume that credentials on the system have been compromised”, they said. “Revoke active sessions, reset passwords, and rotate API keys or any other secrets that may reside on the system. Review cryptocurrency wallets as well, if present.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/security-experts-targeted-by-fake-crypto-conference-in-scam-to-hand-over-details</link>
                                                                            <description>
                            <![CDATA[ Cybersecurity pros attending conferences are being targeted with AMOS and other infostealers, experts warn. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4WM98xrduycbkQfG5f5Wdh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 21 Aug 2026 13:20:22 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:description>                                                            <media:text><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:text>
                                <media:title type="plain"><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Huntress spotted a ClickFix campaign targeting security pros via fake conference invites  </strong></li><li><strong>Victims tricked into pasting code that installs AMOS infostealer on macOS </strong></li><li><strong>If lured, isolate systems, reset credentials, rotate secrets, and review cryptocurrency wallets</strong></li></ul><p>Cybercriminals are targeting security professionals with a highly tailored ClickFix campaign in an attempt to get their computers infected with infostealer <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, experts have warned.</p><p>An active campaign against people who have attended, or have a history of attending, various cybersecurity conferences such as Black Hat, or DEF CON has been detetced by security researchers <a href="https://www.huntress.com/blog/defcon-phishing-google-doc-malware" target="_blank">Huntress</a>, who were targets themselves. </p><p>The attack starts on X, where the threat actor uses a fake account to interact with people visiting and sharing content from these conferences. After establishing rapport, they move into DMs, claiming they’re organizing a conference of their own, and sharing a Google Docs file containing “more info” with the victim. </p><h2 id="follow-up-attack">Follow-up attack</h2><p>Here is where the attackersy go for the ClickFix attack. The document comes with a vertical sidebar, apparently as a security feature that keeps the contents of the file encrypted. The victim is given a decryption code to enter, but it returns an error and offers a solution - to bring up the Terminal and copy/paste a piece of code.</p><p>From here, it’s the usual ClickFix practice: the victim ends up downloading and running AMOS, a notorious Mac infostealer capable of grabbing browser information, cookies, keychain data, cryptocurrency wallet information, Telegram files, and more. The Windows variant did not work when Huntress tried to analyze it, but it’s safe to assume the end goal is the same.</p><p>Huntress also found that this is not where the attack ends. If the victim does not install the infostealer, the threat actor will follow up with a different document, this time pretending to be for Dropbox and working only with the desktop app. Of course, the download button leads straight back to the infostealer.</p><p>The researchers shared a full list of Indicators of Compromise (IoC) which can be found on this link. They also advised anyone who interacted with this kind of lure to isolate the system from the network, collect relevant forensic evidence, and “consider reimaging the system”. </p><p>“Assume that credentials on the system have been compromised”, they said. “Revoke active sessions, reset passwords, and rotate API keys or any other secrets that may reside on the system. Review cryptocurrency wallets as well, if present.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Rethinking secure file transfer for a cross-domain world ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The UK's National Cyber Security Centre recently issued a blunt warning to government and industry alike, warning that many systems are now connected "in ways their designers never anticipated", built on protocols never intended to withstand the sophistication of today's attackers.</p><p>That warning applies to all organizations relying on cross-domain processes to move data between environments with different security levels, and especially to complex cyber-physical systems where data flows between standard IT and operational technology (OT) assets.</p><p><a href="https://www.techradar.com/best/best-ways-to-transfer-files-online">File transfer</a> is one of these fundamental processes but remains one of the most often overlooked.</p><p>Every <a href="https://www.techradar.com/best/best-billing-and-invoicing-software">invoice</a> sent to a supplier, every firmware update pushed to a factory floor, every report shared with a regulator is data crossing between systems with different levels of trust.</p><p>For years, file transfer security has been treated as a solved problem. Enterprises were happy to encrypt the channel, confirm delivery, and move on. That approach made sense when systems were simpler, and threats moved more slowly. However, it no longer reflects reality.</p><h2 id="why-perimeter-based-trust-no-longer-holds">Why perimeter-based trust no longer holds</h2><p>Most file transfer platforms were never built with security as the primary goal. They were built to move data reliably between systems, encrypt the connection, confirm that a file arrived, and log that the job was done. Whether the file itself was safe was rarely part of the equation.</p><p>That gap provides a consistent way for cyber attackers to gain a foothold in their targets' systems. A file transfer platform sits between organizations by design, trusted by both sides precisely because it's meant to be routine infrastructure.</p><p>The traditional Managed File Transfer (MFT) model is built to automate file delivery, not to defend against attack. As such, it leaves the process exposed to a familiar set of threats, from man-in-the-middle interception and credential theft to <a href="https://www.techradar.com/best/best-malware-removal">malware</a> covertly embedded in an otherwise ordinary file. Attackers don't need to break the platform itself, only to exploit the assumption that whatever moves through it can be trusted.</p><p>As we've seen with incidents like 2023's MoveIT supply chain cyberattack and last year's SharePoint breach, a single vulnerability in a widely used transfer tool can give attackers access to thousands of organizations at once, simply because every one of them assumed the platform itself could be trusted.</p><p>That assumption is exactly what attackers are counting on. Securing the channel a file travels through was never the same as securing the file.</p><h2 id="the-shrinking-window-to-respond">The shrinking window to respond</h2><p>File security has always been a blind spot, but it's become much more critical in recent years as the attack lifecycle continues to accelerate. Newly disclosed vulnerabilities are now routinely exploited within 48 hours of becoming public, leaving little room for <a href="https://www.techradar.com/best/best-patch-management-tools">patch management</a> by organizations to prepare, or even notice before they're targeted.</p><p>Detection, by contrast, still moves comparatively slowly. Breaches involving file-based attacks can go unnoticed for months, giving an intruder ample time to move laterally, extract data, or embed themselves further into connected systems before anyone realizes something is wrong.</p><p>It's not simply that attackers are fast, but that most organizations still treat file movement as something to review after the fact rather than control at the point of entry. By the time a malicious file is identified, the damage has often already been done.</p><p>This is why proactive, layered controls around every file entering or leaving the business matter more than ever. Waiting to react is not a viable strategy.</p><h2 id="establishing-continuous-file-verification">Establishing continuous file verification </h2><p>Closing this gap means shifting towards a security-first MFT process, where every file, user, and workflow is treated as a potential point of exposure rather than assumed safe by default.</p><p>Prevention is by design, rather than protection bolted on afterwards as with most traditional MFT models. And that starts with looking inside the file, not just authenticating the channel it arrives through.</p><p>Deep content inspection examines the file's actual structure, identifying hidden or malicious elements that a simple scan would miss. Alongside this, automated vulnerability detection and malware prevention should apply to every file by default, not as an optional extra reserved for high-risk transfers. Even the most innocuous file can now serve as a powerful attack vector – in fact, threat actors are counting on it.</p><p>Likewise, savvier attackers are actively designing payloads to evade detection, so standard processes need <a href="https://www.techradar.com/best/best-backup-software">backup</a>. Potentially malicious files need to be tested in a safe, isolated environment where their behavior can be observed before they ever reach a live system. This kind of sandboxing catches clues missed by reputation checks and static scanning, revealing intent rather than simply checking for known signatures.</p><p>A Content Disarm and Reconstruction (CDR) process is a valuable addition here, deconstructing files and sanitizing them by removing any active content without harming function.</p><p>However, none of this works as a single checkpoint. Each of these controls needs to feed into a continuous process, where a file is validated at every stage of its journey rather than cleared once and trusted from that point on. These capabilities should also be paired with constant monitoring and detailed audit visibility, so that if something does slip through, organizations know exactly what moved, where it went, and what it touched.</p><p>As a result, organizations can reliably build confidence in data as it crosses between environments, rather than assuming that confidence once and carrying it forward unchecked.</p><h2 id="closing-the-loop-on-trust">Closing the loop on trust</h2><p>The NCSC's warning and guidance on cross-domain systems point to the same conclusion: security built on fixed boundaries can no longer keep pace with how data actually moves.</p><p>File transfer is where that principle emerges most often in daily practice. Trust that was once given on principle must now be earned at every crossing. That shift, more than any single tool, is what will define resilient file transfer going forward.</p><p><em></em><a href="https://www.techradar.com/news/best-internet-security-suites"><em>We've reviewed, rated, and ranked the best internet security suites for PCs, Macs and mobile devices</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/rethinking-secure-file-transfer-for-a-cross-domain-world</link>
                                                                            <description>
                            <![CDATA[ Modern organizations need layered controls to secure data moving across increasingly trusted environments. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">CodgKHfXNXGc5UD3vjMc5E</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/snacLhKPDncvV3JtXYyw7M-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Aug 2026 14:23:54 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ James Neilson ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/snacLhKPDncvV3JtXYyw7M-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A portion of the globe with dotted lights criss-crossing the image connecting the countries]]></media:description>                                                            <media:text><![CDATA[A portion of the globe with dotted lights criss-crossing the image connecting the countries]]></media:text>
                                <media:title type="plain"><![CDATA[A portion of the globe with dotted lights criss-crossing the image connecting the countries]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/snacLhKPDncvV3JtXYyw7M-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK's National Cyber Security Centre recently issued a blunt warning to government and industry alike, warning that many systems are now connected "in ways their designers never anticipated", built on protocols never intended to withstand the sophistication of today's attackers.</p><p>That warning applies to all organizations relying on cross-domain processes to move data between environments with different security levels, and especially to complex cyber-physical systems where data flows between standard IT and operational technology (OT) assets.</p><p><a href="https://www.techradar.com/best/best-ways-to-transfer-files-online">File transfer</a> is one of these fundamental processes but remains one of the most often overlooked.</p><p>Every <a href="https://www.techradar.com/best/best-billing-and-invoicing-software">invoice</a> sent to a supplier, every firmware update pushed to a factory floor, every report shared with a regulator is data crossing between systems with different levels of trust.</p><p>For years, file transfer security has been treated as a solved problem. Enterprises were happy to encrypt the channel, confirm delivery, and move on. That approach made sense when systems were simpler, and threats moved more slowly. However, it no longer reflects reality.</p><h2 id="why-perimeter-based-trust-no-longer-holds">Why perimeter-based trust no longer holds</h2><p>Most file transfer platforms were never built with security as the primary goal. They were built to move data reliably between systems, encrypt the connection, confirm that a file arrived, and log that the job was done. Whether the file itself was safe was rarely part of the equation.</p><p>That gap provides a consistent way for cyber attackers to gain a foothold in their targets' systems. A file transfer platform sits between organizations by design, trusted by both sides precisely because it's meant to be routine infrastructure.</p><p>The traditional Managed File Transfer (MFT) model is built to automate file delivery, not to defend against attack. As such, it leaves the process exposed to a familiar set of threats, from man-in-the-middle interception and credential theft to <a href="https://www.techradar.com/best/best-malware-removal">malware</a> covertly embedded in an otherwise ordinary file. Attackers don't need to break the platform itself, only to exploit the assumption that whatever moves through it can be trusted.</p><p>As we've seen with incidents like 2023's MoveIT supply chain cyberattack and last year's SharePoint breach, a single vulnerability in a widely used transfer tool can give attackers access to thousands of organizations at once, simply because every one of them assumed the platform itself could be trusted.</p><p>That assumption is exactly what attackers are counting on. Securing the channel a file travels through was never the same as securing the file.</p><h2 id="the-shrinking-window-to-respond">The shrinking window to respond</h2><p>File security has always been a blind spot, but it's become much more critical in recent years as the attack lifecycle continues to accelerate. Newly disclosed vulnerabilities are now routinely exploited within 48 hours of becoming public, leaving little room for <a href="https://www.techradar.com/best/best-patch-management-tools">patch management</a> by organizations to prepare, or even notice before they're targeted.</p><p>Detection, by contrast, still moves comparatively slowly. Breaches involving file-based attacks can go unnoticed for months, giving an intruder ample time to move laterally, extract data, or embed themselves further into connected systems before anyone realizes something is wrong.</p><p>It's not simply that attackers are fast, but that most organizations still treat file movement as something to review after the fact rather than control at the point of entry. By the time a malicious file is identified, the damage has often already been done.</p><p>This is why proactive, layered controls around every file entering or leaving the business matter more than ever. Waiting to react is not a viable strategy.</p><h2 id="establishing-continuous-file-verification">Establishing continuous file verification </h2><p>Closing this gap means shifting towards a security-first MFT process, where every file, user, and workflow is treated as a potential point of exposure rather than assumed safe by default.</p><p>Prevention is by design, rather than protection bolted on afterwards as with most traditional MFT models. And that starts with looking inside the file, not just authenticating the channel it arrives through.</p><p>Deep content inspection examines the file's actual structure, identifying hidden or malicious elements that a simple scan would miss. Alongside this, automated vulnerability detection and malware prevention should apply to every file by default, not as an optional extra reserved for high-risk transfers. Even the most innocuous file can now serve as a powerful attack vector – in fact, threat actors are counting on it.</p><p>Likewise, savvier attackers are actively designing payloads to evade detection, so standard processes need <a href="https://www.techradar.com/best/best-backup-software">backup</a>. Potentially malicious files need to be tested in a safe, isolated environment where their behavior can be observed before they ever reach a live system. This kind of sandboxing catches clues missed by reputation checks and static scanning, revealing intent rather than simply checking for known signatures.</p><p>A Content Disarm and Reconstruction (CDR) process is a valuable addition here, deconstructing files and sanitizing them by removing any active content without harming function.</p><p>However, none of this works as a single checkpoint. Each of these controls needs to feed into a continuous process, where a file is validated at every stage of its journey rather than cleared once and trusted from that point on. These capabilities should also be paired with constant monitoring and detailed audit visibility, so that if something does slip through, organizations know exactly what moved, where it went, and what it touched.</p><p>As a result, organizations can reliably build confidence in data as it crosses between environments, rather than assuming that confidence once and carrying it forward unchecked.</p><h2 id="closing-the-loop-on-trust">Closing the loop on trust</h2><p>The NCSC's warning and guidance on cross-domain systems point to the same conclusion: security built on fixed boundaries can no longer keep pace with how data actually moves.</p><p>File transfer is where that principle emerges most often in daily practice. Trust that was once given on principle must now be earned at every crossing. That shift, more than any single tool, is what will define resilient file transfer going forward.</p><p><em></em><a href="https://www.techradar.com/news/best-internet-security-suites"><em>We've reviewed, rated, and ranked the best internet security suites for PCs, Macs and mobile devices</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ghosts in the machine: AI malware shows why it is time to extend Zero Trust to code ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Software security was built around human development. </p><p>People wrote, reviewed and deployed code. Now machines are taking over.  </p><p>In a recent paper, Anthropic reports that more than 80% of the code merged into its production codebase is authored by their <a href="https://www.techradar.com/best/best-ai-tools">AI</a> model, Claude. </p><p>The same capabilities that make <a href="https://www.techradar.com/best/sites-for-hiring-developers">developers</a> more productive are changing the economics of cyberattacks. </p><p>While adversaries still define the objective, machines can generate the payloads, test variants, adapt code to different environments and repeat the process at a velocity that security programs can’t match.</p><h2 id="speed-is-marginalizing-security-controls">Speed is Marginalizing Security Controls</h2><p>Most enterprise software security workflows assume there is time for review. <a href="https://www.techradar.com/pro/software-services/best-no-code-platforms">Code</a> is written, scanned, tested, approved and deployed. If something suspicious happens later, security teams investigate and respond.</p><p>That model breaks down when <a href="https://www.techradar.com/best/best-open-source-software">software</a> moves from prompt to execution in minutes.</p><p>AI-generated code can become a script, dependency, <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a> job or infrastructure change almost immediately. While development agents can modify files, resolve packages and run commands. </p><p>Human reviewers are no longer in the loop.</p><p>Attackers can use the same mechanics to generate exploits, test evasion techniques and adjust payload behavior for different targets. This creates more variation with fewer stable indicators for defenders to recognize.</p><p>While AI-assisted analysis can improve triage, it still often produces probability, not policy. At machine speed, “probably suspicious” is not good enough.</p><h2 id="machines-change-the-attack-model">Machines Change The Attack Model</h2><p>Human attackers are not disappearing. But more of the attack chain is becoming machine-executed.</p><p>AI can automate reconnaissance, accelerate vulnerability discovery, generate exploit code, rewrite payloads and adapt command sequences to the target environment. But most defensive measures are designed around human constraints: reused infrastructure, shortcuts and trackable patterns. These don’t apply to machine attacks.</p><p>A machine-generated payload may not match a known signature or have an established reputation. It may be created, used briefly and discarded. But AI <a href="https://www.techradar.com/best/best-malware-removal">malware</a> must still interact with the target environment to achieve its objective. Its behavior cannot conceal its intent, since it must access resources and change the environment in ways that advance the attack. </p><p>What malicious code is capable of doing is the more durable security signal.</p><h2 id="security-needs-to-ask-a-different-question">Security Needs to Ask A Different Question</h2><p>Software supply chain security has improved, but much of it still validates the artifact’s properties before execution rather than governing execution itself.</p><p>SBOMs, signing and provenance give security teams greater confidence in a code's composition, origin and build history. But knowing where software came from does not reveal what it will do when it runs.</p><p>Software can pass each of those checks and still create risk. Even an artifact produced through a legitimate build process may violate policy at runtime, while an AI-generated script may complete its intended task in a way that exposes data or systems. As a result, a clean dependency list is not proof of safe behavior.</p><h2 id="post-execution-detection-is-too-late">Post-Execution Detection Is Too Late</h2><p>Detection and response remain essential, but they intervene after risk has entered the environment. By the time suspicious behavior is visible, software may have accessed secrets, changed system state, opened network connections or created persistence. </p><p>AI compresses that window. Code can be generated, modified and deployed faster than humans can review it. Waiting for post-execution evidence gives attackers too much room to operate.</p><p>We need to shift the decision point left. Instead of asking, “Can we contain this software if it behaves badly?” the question should be, “Should this behavior be permitted to execute in the first place?”</p><p>That does not mean replacing existing controls, but rather changing where the decisive security gate sits.</p><h2 id="zero-trust-for-code">Zero Trust for Code</h2><p>Zero Trust changed enterprise security by rejecting implicit trust. Users, devices, sessions and access requests are not trusted simply because they appear familiar. They must be verified against policy.</p><p>Software execution needs the same level of verification.</p><p>Code should not be trusted solely because it came from a known repository, was signed by a recognized publisher, passed through a build pipeline or has not been seen exhibiting malicious behavior before. Those are useful indicators, but they are not conclusive.</p><p>Zero Trust for Code addresses this problem. Before software runs, its expected behavior should be evaluated against policy. If the behavior is acceptable, execution can proceed. If not, the artifact should be blocked, restricted, isolated or escalated for review.</p><p>Organizations can start by mapping every path through which code enters the environment or executes with meaningful privilege. This includes formal development channels such as repositories, open-source packages, containers and CI/CD pipelines, as well as email attachments, downloaded files, macros, browser extensions, endpoint installers, third-party integrations and scripts introduced through AI or automation tools. </p><p>Then identify where those paths rely on inherited trust. If execution is allowed because software came from an approved source, was signed, passed through a build process or has no malicious history, the control is incomplete. Behavior still has to be evaluated before the artifact is allowed to run.</p><p>As AI takes on more of the work of creating legitimate and malicious code, enterprises can no longer assume that code which clears existing checks should be allowed to run. Execution must become a deliberate security decision.</p><p><em></em><a href="https://www.techradar.com/news/best-internet-security-suites"><em>We've listed the best internet security suites for PCs, Macs and mobile devices</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/ghosts-in-the-machine-ai-malware-shows-why-it-is-time-to-extend-zero-trust-to-code</link>
                                                                            <description>
                            <![CDATA[ AI-generated malware is outpacing human-centered security controls, find out how enterprises can fight back. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">x7wbtdtY98HrDXmeoU79w</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Aug 2026 10:41:24 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ken Ammon ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:description>                                                            <media:text><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:text>
                                <media:title type="plain"><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Software security was built around human development. </p><p>People wrote, reviewed and deployed code. Now machines are taking over.  </p><p>In a recent paper, Anthropic reports that more than 80% of the code merged into its production codebase is authored by their <a href="https://www.techradar.com/best/best-ai-tools">AI</a> model, Claude. </p><p>The same capabilities that make <a href="https://www.techradar.com/best/sites-for-hiring-developers">developers</a> more productive are changing the economics of cyberattacks. </p><p>While adversaries still define the objective, machines can generate the payloads, test variants, adapt code to different environments and repeat the process at a velocity that security programs can’t match.</p><h2 id="speed-is-marginalizing-security-controls">Speed is Marginalizing Security Controls</h2><p>Most enterprise software security workflows assume there is time for review. <a href="https://www.techradar.com/pro/software-services/best-no-code-platforms">Code</a> is written, scanned, tested, approved and deployed. If something suspicious happens later, security teams investigate and respond.</p><p>That model breaks down when <a href="https://www.techradar.com/best/best-open-source-software">software</a> moves from prompt to execution in minutes.</p><p>AI-generated code can become a script, dependency, <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a> job or infrastructure change almost immediately. While development agents can modify files, resolve packages and run commands. </p><p>Human reviewers are no longer in the loop.</p><p>Attackers can use the same mechanics to generate exploits, test evasion techniques and adjust payload behavior for different targets. This creates more variation with fewer stable indicators for defenders to recognize.</p><p>While AI-assisted analysis can improve triage, it still often produces probability, not policy. At machine speed, “probably suspicious” is not good enough.</p><h2 id="machines-change-the-attack-model">Machines Change The Attack Model</h2><p>Human attackers are not disappearing. But more of the attack chain is becoming machine-executed.</p><p>AI can automate reconnaissance, accelerate vulnerability discovery, generate exploit code, rewrite payloads and adapt command sequences to the target environment. But most defensive measures are designed around human constraints: reused infrastructure, shortcuts and trackable patterns. These don’t apply to machine attacks.</p><p>A machine-generated payload may not match a known signature or have an established reputation. It may be created, used briefly and discarded. But AI <a href="https://www.techradar.com/best/best-malware-removal">malware</a> must still interact with the target environment to achieve its objective. Its behavior cannot conceal its intent, since it must access resources and change the environment in ways that advance the attack. </p><p>What malicious code is capable of doing is the more durable security signal.</p><h2 id="security-needs-to-ask-a-different-question">Security Needs to Ask A Different Question</h2><p>Software supply chain security has improved, but much of it still validates the artifact’s properties before execution rather than governing execution itself.</p><p>SBOMs, signing and provenance give security teams greater confidence in a code's composition, origin and build history. But knowing where software came from does not reveal what it will do when it runs.</p><p>Software can pass each of those checks and still create risk. Even an artifact produced through a legitimate build process may violate policy at runtime, while an AI-generated script may complete its intended task in a way that exposes data or systems. As a result, a clean dependency list is not proof of safe behavior.</p><h2 id="post-execution-detection-is-too-late">Post-Execution Detection Is Too Late</h2><p>Detection and response remain essential, but they intervene after risk has entered the environment. By the time suspicious behavior is visible, software may have accessed secrets, changed system state, opened network connections or created persistence. </p><p>AI compresses that window. Code can be generated, modified and deployed faster than humans can review it. Waiting for post-execution evidence gives attackers too much room to operate.</p><p>We need to shift the decision point left. Instead of asking, “Can we contain this software if it behaves badly?” the question should be, “Should this behavior be permitted to execute in the first place?”</p><p>That does not mean replacing existing controls, but rather changing where the decisive security gate sits.</p><h2 id="zero-trust-for-code">Zero Trust for Code</h2><p>Zero Trust changed enterprise security by rejecting implicit trust. Users, devices, sessions and access requests are not trusted simply because they appear familiar. They must be verified against policy.</p><p>Software execution needs the same level of verification.</p><p>Code should not be trusted solely because it came from a known repository, was signed by a recognized publisher, passed through a build pipeline or has not been seen exhibiting malicious behavior before. Those are useful indicators, but they are not conclusive.</p><p>Zero Trust for Code addresses this problem. Before software runs, its expected behavior should be evaluated against policy. If the behavior is acceptable, execution can proceed. If not, the artifact should be blocked, restricted, isolated or escalated for review.</p><p>Organizations can start by mapping every path through which code enters the environment or executes with meaningful privilege. This includes formal development channels such as repositories, open-source packages, containers and CI/CD pipelines, as well as email attachments, downloaded files, macros, browser extensions, endpoint installers, third-party integrations and scripts introduced through AI or automation tools. </p><p>Then identify where those paths rely on inherited trust. If execution is allowed because software came from an approved source, was signed, passed through a build process or has no malicious history, the control is incomplete. Behavior still has to be evaluated before the artifact is allowed to run.</p><p>As AI takes on more of the work of creating legitimate and malicious code, enterprises can no longer assume that code which clears existing checks should be allowed to run. Execution must become a deliberate security decision.</p><p><em></em><a href="https://www.techradar.com/news/best-internet-security-suites"><em>We've listed the best internet security suites for PCs, Macs and mobile devices</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hundreds of fake Chrome VPN extensions impersonating NordVPN, Proton, and more caught hijacking your traffic ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Socket's Threat Research Team found 737 fake VPN and proxy extensions on the Chrome Web Store, with more than 75,000 combined installs</strong></li><li><strong>The add-ons pose as trusted names like Proton VPN and NordVPN while routing your entire browser session through proxies run by one operator</strong></li><li><strong>Hundreds are still live, so it's worth checking your browser now and removing anything suspicious</strong></li></ul><p>A new investigation has exposed a huge cluster of counterfeit VPN extensions that promise privacy while rerouting your traffic.</p><p><a href="https://socket.dev/blog/chrome-vpn-extension-impersonation" target="_blank" rel="nofollow">Socket's Threat Research Team</a> said it identified 737 free VPN and proxy extensions published across at least 40 Chrome Web Store developer accounts. More than 27o of these impersonate 66 of the <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> services and privacy brands, including big names like <a href="https://www.techradar.com/reviews/nordvpn">NordVPN</a> and <a href="https://www.techradar.com/reviews/protonvpn">Proton VPN</a>. </p><p>Between them, the extensions racked up more than 75,000 installs, mostly among Russian-speaking users hunting for ways to reach blocked services.</p><p>If you use Chrome and rely on a browser add-on to stay private, it's worth making sure the one you installed is a genuine product from a real provider rather than one of these lookalikes.</p><h2 id="what-the-researchers-found">What the researchers found</h2><p>Socket's team traced the whole network back to a single Russian VPN subscription business trading as Myxa VPN. </p><p>The researchers linked the extensions using a shared analytics account, clustered domain registrations, common hosting, and leaked Windows build paths pointing to one project folder. The free extensions appear to act as a funnel, nudging users toward a paid subscription.</p><p>Some of the paid promises were pure fiction. Socket says the premium tiers advertised servers in countries like Japan, Singapore, and Australia, but when it tested 200 premium hostnames across 40 domains, none returned an A record, meaning those servers simply did not exist.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/2087321016624439534"><p lang="en" dir="ltr">Socket’s Threat Research Team found 737 Chrome VPN extensions in one campaign. 274 impersonated trusted brands, while 520 routed all browser traffic through shared infrastructure.The campaign’s paid plan listed 200 server hostnames. Not one resolved.https://t.co/Nwz02e3ncb<a href="https://twitter.com/cantworkitout/status/2087321016624439534">August 11, 2026</a></p></blockquote></figure><div class="see-more__filter"></div></div><p>The core trick is the same across nearly every extension. Once you press Connect, everything you browse gets pushed through a server the operator controls, with no per-site exceptions.</p><p>It adds no <a href="https://www.techradar.com/vpn/what-is-encryption">encryption</a>, so it isn't doing the protective work a real VPN would. Worse, 104 extensions resolved their proxy addresses through Cloudflare or Google DNS-over-HTTPS and handed Chrome a raw IP, a technique that makes the operator's servers harder to block or spot.</p><h2 id="why-fake-vpn-are-dangerous-and-how-to-stay-safe">Why fake VPN are dangerous, and how to stay safe</h2><p>Sitting in the middle of your traffic gives the operator a clear view. Socket says the setup lets whoever runs the proxy observe the websites you visit, TLS SNI metadata, your source <a href="https://www.techradar.com/pro/what-is-an-ip-address">IP address,</a> and any data sent over unencrypted HTTP. That means anything you type into a non-HTTPS page, including logins, could be exposed.</p><p>Socket doesn't know whether this data has actually been collected or misused, but the fact that it can be is the problem. It's the same pattern behind earlier warnings about <a href="https://www.techradar.com/vpn/vpn-privacy-security/fake-proton-vpn-extensions-slip-into-chrome-web-store-heres-how-to-stay-safe">fake VPN extensions in the Chrome Web Store</a> and <a href="https://www.techradar.com/vpn/vpn-privacy-security/google-issues-security-alert-your-vpn-app-could-be-spyware-in-disguise">Google's own alerts about spyware posing as VPN apps</a>.</p><p>Google has already acted, but not completely. By the time Socket collected its data, 221 of the 737 extensions had been removed, while 516 remained listed, so the threat hasn't fully gone away.</p><p>If you think you installed one, the advice from Socket is straightforward. Remove the extension immediately, then check that Chrome's proxy configuration has returned to normal and change any credentials you entered on non-HTTPS sites while it was active. You can review your proxy settings by heading to your browser settings and searching for "proxy."</p><div data-widget-type="multimodelreview" data-model-name="NordVPN,Surfshark,Proton VPN" data-widget-title="Today's best VPN deals"></div> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/vpn/vpn-services/hundreds-of-fake-chrome-vpn-extensions-impersonating-nordvpn-proton-and-more-caught-hijacking-your-traffic</link>
                                                                            <description>
                            <![CDATA[ Socket's Threat Research Team uncovered 737 fake Chrome VPN extensions impersonating major brands and rerouting browser traffic through their own proxies. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8MLogZ68m4QzZc2nM4Hy2o</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZfhFwGtGeLFq7LEuTgCMbD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Aug 2026 16:23:01 +0000</pubDate>                                                                                                                                <updated>Fri, 14 Aug 2026 16:27:52 +0000</updated>
                                                                                                                                            <category><![CDATA[VPN Privacy & Security]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                                                                <author><![CDATA[ monicajwrites@gmail.com (Monica J. White) ]]></author>                    <dc:creator><![CDATA[ Monica J. White ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/6AQ4y5nzk8kQ47Yp69GERj.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Monica is a journalist with over a decade of experience in covering technology.&lt;/p&gt;&lt;p&gt;She writes about the latest developments in computing, which means anything from computer chips made out of paper to cutting-edge desktop processors. Her coverage includes CPUs, GPUs, and everything else that goes into a PC or a laptop, but also peripherals.&lt;/p&gt;&lt;p&gt;GPUs are Monica’s main area of interest, and nothing thrills her quite like that time every couple of years when new graphics cards hit the market. She’s always keeping tabs on the latest from Nvidia, AMD, and Intel, including both the hardware and the software that powers our PCs.&lt;/p&gt;&lt;p&gt;As an avid gamer, her focus is always on the consumer and whether something works well and provides adequate value for the money. She believes that PC building can be intimidating, so her goal is to explain complex concepts in an approachable manner while still digging into the technical nitty-gritty we all love to learn more about.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZfhFwGtGeLFq7LEuTgCMbD-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / Ink Drop]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Silhouette of a hand holding a padlock infront of the google chrome logo]]></media:description>                                                            <media:text><![CDATA[Silhouette of a hand holding a padlock infront of the google chrome logo]]></media:text>
                                <media:title type="plain"><![CDATA[Silhouette of a hand holding a padlock infront of the google chrome logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZfhFwGtGeLFq7LEuTgCMbD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Socket's Threat Research Team found 737 fake VPN and proxy extensions on the Chrome Web Store, with more than 75,000 combined installs</strong></li><li><strong>The add-ons pose as trusted names like Proton VPN and NordVPN while routing your entire browser session through proxies run by one operator</strong></li><li><strong>Hundreds are still live, so it's worth checking your browser now and removing anything suspicious</strong></li></ul><p>A new investigation has exposed a huge cluster of counterfeit VPN extensions that promise privacy while rerouting your traffic.</p><p><a href="https://socket.dev/blog/chrome-vpn-extension-impersonation" target="_blank" rel="nofollow">Socket's Threat Research Team</a> said it identified 737 free VPN and proxy extensions published across at least 40 Chrome Web Store developer accounts. More than 27o of these impersonate 66 of the <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> services and privacy brands, including big names like <a href="https://www.techradar.com/reviews/nordvpn">NordVPN</a> and <a href="https://www.techradar.com/reviews/protonvpn">Proton VPN</a>. </p><p>Between them, the extensions racked up more than 75,000 installs, mostly among Russian-speaking users hunting for ways to reach blocked services.</p><p>If you use Chrome and rely on a browser add-on to stay private, it's worth making sure the one you installed is a genuine product from a real provider rather than one of these lookalikes.</p><h2 id="what-the-researchers-found">What the researchers found</h2><p>Socket's team traced the whole network back to a single Russian VPN subscription business trading as Myxa VPN. </p><p>The researchers linked the extensions using a shared analytics account, clustered domain registrations, common hosting, and leaked Windows build paths pointing to one project folder. The free extensions appear to act as a funnel, nudging users toward a paid subscription.</p><p>Some of the paid promises were pure fiction. Socket says the premium tiers advertised servers in countries like Japan, Singapore, and Australia, but when it tested 200 premium hostnames across 40 domains, none returned an A record, meaning those servers simply did not exist.</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/2087321016624439534"><p lang="en" dir="ltr">Socket’s Threat Research Team found 737 Chrome VPN extensions in one campaign. 274 impersonated trusted brands, while 520 routed all browser traffic through shared infrastructure.The campaign’s paid plan listed 200 server hostnames. Not one resolved.https://t.co/Nwz02e3ncb<a href="https://twitter.com/cantworkitout/status/2087321016624439534">August 11, 2026</a></p></blockquote></figure><div class="see-more__filter"></div></div><p>The core trick is the same across nearly every extension. Once you press Connect, everything you browse gets pushed through a server the operator controls, with no per-site exceptions.</p><p>It adds no <a href="https://www.techradar.com/vpn/what-is-encryption">encryption</a>, so it isn't doing the protective work a real VPN would. Worse, 104 extensions resolved their proxy addresses through Cloudflare or Google DNS-over-HTTPS and handed Chrome a raw IP, a technique that makes the operator's servers harder to block or spot.</p><h2 id="why-fake-vpn-are-dangerous-and-how-to-stay-safe">Why fake VPN are dangerous, and how to stay safe</h2><p>Sitting in the middle of your traffic gives the operator a clear view. Socket says the setup lets whoever runs the proxy observe the websites you visit, TLS SNI metadata, your source <a href="https://www.techradar.com/pro/what-is-an-ip-address">IP address,</a> and any data sent over unencrypted HTTP. That means anything you type into a non-HTTPS page, including logins, could be exposed.</p><p>Socket doesn't know whether this data has actually been collected or misused, but the fact that it can be is the problem. It's the same pattern behind earlier warnings about <a href="https://www.techradar.com/vpn/vpn-privacy-security/fake-proton-vpn-extensions-slip-into-chrome-web-store-heres-how-to-stay-safe">fake VPN extensions in the Chrome Web Store</a> and <a href="https://www.techradar.com/vpn/vpn-privacy-security/google-issues-security-alert-your-vpn-app-could-be-spyware-in-disguise">Google's own alerts about spyware posing as VPN apps</a>.</p><p>Google has already acted, but not completely. By the time Socket collected its data, 221 of the 737 extensions had been removed, while 516 remained listed, so the threat hasn't fully gone away.</p><p>If you think you installed one, the advice from Socket is straightforward. Remove the extension immediately, then check that Chrome's proxy configuration has returned to normal and change any credentials you entered on non-HTTPS sites while it was active. You can review your proxy settings by heading to your browser settings and searching for "proxy."</p><div data-widget-type="multimodelreview" data-model-name="NordVPN,Surfshark,Proton VPN" data-widget-title="Today's best VPN deals"></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Android users targeted by new WindRelay malware which can clone contactless cards in just 13 minutes ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>WindRelay campaign used vishing plus custom malware to turn phones into POS skimmers</strong></li><li><strong>Victims installed personalized RATs and NFC malware, enabling real‑time card theft</strong></li><li><strong>Attacks were highly targeted across Eastern Europe, with only a few individuals hit</strong></li></ul><p>Hackers are turning people’s smartphones into malicious <a href="https://www.techradar.com/news/the-best-pos-system" target="_blank">Point of Sale</a> (POS) devices and stealing their money directly from their payment cards, experts have warned. </p><p>Security researchers Group-IB spotted multiple such attacks across Eastern Europe, and named the campaign <a href="https://www.group-ib.com/blog/windrelay-nfc-spynote-rat-combo-fraud/" target="_blank">WindRelay</a>, after the custom-built malware used during the attacks.</p><p>The report notes this is a highly sophisticated, custom-tailored attack designed specifically for the victim. It starts with some form of reconnaissance, in which the attackers learn their victim’s identity, phone number, and likely other details. Although the researchers don’t discuss it, it is quite possible that the attackers obtained (or purchased) the data from unrelated data breaches and leaks.</p><h2 id="vishing-and-malware">Vishing and malware</h2><p>After learning a little bit about their target, the attackers get to work. They first prepare a remote access trojan (RAT) named SpyNote. They personalize the label with the victim’s own name (instead of it being a generic or impersonated brand), to build trust with their victim:</p><p>“Such tactics are more effective at weakening a victim’s natural defenses and suspicions,” the researchers noted in the report. “It removes the one cue people are trained to check before installing something unfamiliar — a strange or generic app name — right at the moment they’re most likely to hesitate.”</p><p>Then, they call the victim on the phone and introduce themselves as employees of their target’s bank. They claim the victim has a problem with their bank card, and instruct them to deploy SpyNote through the device’s package installer (the standard way to sideload apps outside an official app store).</p><p>SpyNote is a classic RAT that the attackers then use to deploy stage-two malware themselves. In this next step, they personally (as opposed to having the victim do it) install WindRelay, custom near-field communication (NFC) malware designed to capture contactless payment card data in real-time, when a card is tapped against the phone. </p><p>In other words, the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> turns the smartphone into a POS, and when a victim taps their card against it, the information is relayed to an attacker’s terminal. </p><h2 id="vishing-malware">Vishing + malware</h2><p>Vishing + malware combo is nothing new. We’ve seen it deployed numerous times before, and ShinyHunters are probably the shiniest example of the practice (pun definitely intended). Over the last couple of years, ShinyHunters have been calling their victims on the phone, impersonating the IT department, and getting their victims to log in via fake login portals which relay the credentials to the attackers.</p><p>They then use the credentials to access their victims’ SaaS products, exfiltrate as much sensitive data as possible, and then demand ransom in exchange for deleting the stolen files.</p><p>This new campaign, however, is a testament to the technique’s evolution. While ShinyHunters’ operatives only stay on the phone call until the victim logs in, these crooks remain on the line for as long as it takes. Group-IB says the average call lasts around 13 minutes, and by that moment, the victim will have installed both SpyNote and WindRelay, and has tapped their bank card against the phone, making unwanted payments.</p><p>In at least one case, the attackers successfully applied for a loan at the victim’s bank, stealing not only the money they had on their account, but also money they would have earned in the future.</p><p>The identity of the attackers is unknown at the time. We also don’t know exactly how many victims there were, but given the highly personalized nature of the attack, it’s safe to assume that there were only a handful.</p><p>Group-IB says it observed attacks in Czechia, Slovakia, and Slovenia, suggesting a threat actor focused primarily on Eastern European victims. The researchers also said they identified 23 samples uploaded to VirusTotal between November 2025 and July 2026, meaning the campaign was active for approximately seven months, targeting 23 individuals. </p><p>“The samples mimic various institutions from the targeted countries and contain text in the language of each targeted country,” the researchers said. “Some samples contain personalized UI elements and labels, such as the name of the victim, similar to the personalized RAT. This suggests the threat actor behind these campaigns most likely has the capability to dynamically build malicious applications tailored to individual victims.”</p><p>Group-IB says users should treat personalized app labels as a red flag and should apply extra friction to loan applications. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/android-users-targeted-by-new-windrelay-malware-which-can-clone-contactless-cards-in-just-13-minutes</link>
                                                                            <description>
                            <![CDATA[ Crooks are calling victims on the phone and installing POS malware on their smartphones. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">shwHxntyNEjscciJEjL9Li</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5kMrDAjQJGcdHytVASFjn5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 15:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5kMrDAjQJGcdHytVASFjn5-1280-80.jpg">
                                                            <media:credit><![CDATA[Rapeepong Puttakumwong via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Person pays using POS hardware card reader]]></media:description>                                                            <media:text><![CDATA[Person pays using POS hardware card reader]]></media:text>
                                <media:title type="plain"><![CDATA[Person pays using POS hardware card reader]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5kMrDAjQJGcdHytVASFjn5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>WindRelay campaign used vishing plus custom malware to turn phones into POS skimmers</strong></li><li><strong>Victims installed personalized RATs and NFC malware, enabling real‑time card theft</strong></li><li><strong>Attacks were highly targeted across Eastern Europe, with only a few individuals hit</strong></li></ul><p>Hackers are turning people’s smartphones into malicious <a href="https://www.techradar.com/news/the-best-pos-system" target="_blank">Point of Sale</a> (POS) devices and stealing their money directly from their payment cards, experts have warned. </p><p>Security researchers Group-IB spotted multiple such attacks across Eastern Europe, and named the campaign <a href="https://www.group-ib.com/blog/windrelay-nfc-spynote-rat-combo-fraud/" target="_blank">WindRelay</a>, after the custom-built malware used during the attacks.</p><p>The report notes this is a highly sophisticated, custom-tailored attack designed specifically for the victim. It starts with some form of reconnaissance, in which the attackers learn their victim’s identity, phone number, and likely other details. Although the researchers don’t discuss it, it is quite possible that the attackers obtained (or purchased) the data from unrelated data breaches and leaks.</p><h2 id="vishing-and-malware">Vishing and malware</h2><p>After learning a little bit about their target, the attackers get to work. They first prepare a remote access trojan (RAT) named SpyNote. They personalize the label with the victim’s own name (instead of it being a generic or impersonated brand), to build trust with their victim:</p><p>“Such tactics are more effective at weakening a victim’s natural defenses and suspicions,” the researchers noted in the report. “It removes the one cue people are trained to check before installing something unfamiliar — a strange or generic app name — right at the moment they’re most likely to hesitate.”</p><p>Then, they call the victim on the phone and introduce themselves as employees of their target’s bank. They claim the victim has a problem with their bank card, and instruct them to deploy SpyNote through the device’s package installer (the standard way to sideload apps outside an official app store).</p><p>SpyNote is a classic RAT that the attackers then use to deploy stage-two malware themselves. In this next step, they personally (as opposed to having the victim do it) install WindRelay, custom near-field communication (NFC) malware designed to capture contactless payment card data in real-time, when a card is tapped against the phone. </p><p>In other words, the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> turns the smartphone into a POS, and when a victim taps their card against it, the information is relayed to an attacker’s terminal. </p><h2 id="vishing-malware">Vishing + malware</h2><p>Vishing + malware combo is nothing new. We’ve seen it deployed numerous times before, and ShinyHunters are probably the shiniest example of the practice (pun definitely intended). Over the last couple of years, ShinyHunters have been calling their victims on the phone, impersonating the IT department, and getting their victims to log in via fake login portals which relay the credentials to the attackers.</p><p>They then use the credentials to access their victims’ SaaS products, exfiltrate as much sensitive data as possible, and then demand ransom in exchange for deleting the stolen files.</p><p>This new campaign, however, is a testament to the technique’s evolution. While ShinyHunters’ operatives only stay on the phone call until the victim logs in, these crooks remain on the line for as long as it takes. Group-IB says the average call lasts around 13 minutes, and by that moment, the victim will have installed both SpyNote and WindRelay, and has tapped their bank card against the phone, making unwanted payments.</p><p>In at least one case, the attackers successfully applied for a loan at the victim’s bank, stealing not only the money they had on their account, but also money they would have earned in the future.</p><p>The identity of the attackers is unknown at the time. We also don’t know exactly how many victims there were, but given the highly personalized nature of the attack, it’s safe to assume that there were only a handful.</p><p>Group-IB says it observed attacks in Czechia, Slovakia, and Slovenia, suggesting a threat actor focused primarily on Eastern European victims. The researchers also said they identified 23 samples uploaded to VirusTotal between November 2025 and July 2026, meaning the campaign was active for approximately seven months, targeting 23 individuals. </p><p>“The samples mimic various institutions from the targeted countries and contain text in the language of each targeted country,” the researchers said. “Some samples contain personalized UI elements and labels, such as the name of the victim, similar to the personalized RAT. This suggests the threat actor behind these campaigns most likely has the capability to dynamically build malicious applications tailored to individual victims.”</p><p>Group-IB says users should treat personalized app labels as a red flag and should apply extra friction to loan applications. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Windows users face six times more malware than Mac owners, Surfshark reveals — but 'Macs are safer' is only half true ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Surfshark recorded nearly 6 times as many malware detections on Windows</strong></li><li><strong>While trojans mostly target Windows devices, phishing lands harder on Mac</strong></li><li><strong>A "Macs are safe" mindset may leave users more at risk of social engineering</strong></li></ul><p>New data from <a href="https://surfshark.com/research/chart/malware-detections-windows-vs-macos">Surfshark</a> shows a stark split in how malware finds its targets: Windows users are hit at nearly six times the rate of macOS users.</p><p>The headline number is eye-catching, but the full story is more interesting. While Windows soaks up the vast majority of traditional <a href="https://www.techradar.com/news/what-is-malware-and-how-dangerous-is-it">malware</a>, Mac users face a very different kind of threat, one that a locked-down operating system does little to stop: <a href="https://www.techradar.com/news/everything-you-need-to-know-about-phishing">phishing</a>.</p><p><a href="https://www.techradar.com/best/best-antivirus">Antivirus </a>software paired with one of the <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> services remains a sensible layer of defence, whatever you run, but <a href="https://bit.ly/3SAbtut" target="_blank" rel="nofollow">Surfshark's findings</a> are a useful reminder that while risks change depending on the platform, they never disappear.</p><div class="product"><a data-dimension112="ff4c4aa2-9660-11f1-89b4-1f3684d9c300" data-action="Deal Block" data-label="Surfshark &ndash; the best cheap VPNSurfshark is a fast, easy-to-use VPN that seriously beats the competition when it comes to subscription pricing. Its two-year Starter plan works out at $2.49 a month (plus tax), but we think Surfshark One is the best value plan as it adds an antivirus, data breach monitor, and alternative ID tool starting from the equivalent of  $2.79 a month. Surfshark – the best cheap VPN" data-dimension48="Surfshark &ndash; the best cheap VPNSurfshark is a fast, easy-to-use VPN that seriously beats the competition when it comes to subscription pricing. Its two-year Starter plan works out at $2.49 a month (plus tax), but we think Surfshark One is the best value plan as it adds an antivirus, data breach monitor, and alternative ID tool starting from the equivalent of  $2.79 a month. Surfshark – the best cheap VPN" href="https://get.surfshark.net/aff_c?offer_id=1030&aff_id=1691&url_id=2561" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="pSwRio45uPDhdN5egHcYF" name="Surfshark deal image.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/pSwRio45uPDhdN5egHcYF.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong></strong><a href="http://get.surfshark.net/aff_c?offer_id=61&aff_id=1691" target="_blank" rel="nofollow" data-dimension112="ff4c4aa2-9660-11f1-89b4-1f3684d9c300" data-action="Deal Block" data-label="Surfshark &ndash; the best cheap VPNSurfshark is a fast, easy-to-use VPN that seriously beats the competition when it comes to subscription pricing. Its two-year Starter plan works out at $2.49 a month (plus tax), but we think Surfshark One is the best value plan as it adds an antivirus, data breach monitor, and alternative ID tool starting from the equivalent of  $2.79 a month. Surfshark – the best cheap VPN" data-dimension48="Surfshark &ndash; the best cheap VPNSurfshark is a fast, easy-to-use VPN that seriously beats the competition when it comes to subscription pricing. Its two-year Starter plan works out at $2.49 a month (plus tax), but we think Surfshark One is the best value plan as it adds an antivirus, data breach monitor, and alternative ID tool starting from the equivalent of  $2.79 a month. Surfshark – the best cheap VPN" data-dimension25=""><strong>Surfshark – the best cheap VPN</strong></a><strong></strong><br>Surfshark is a fast, easy-to-use VPN that seriously beats the competition when it comes to subscription pricing. Its two-year Starter plan works out at $2.49 a month<strong> </strong>(plus tax), but we think Surfshark One is the best value plan as it adds an antivirus, data breach monitor, and alternative ID tool starting from the equivalent of  $2.79 a month. <a class="view-deal button" href="https://get.surfshark.net/aff_c?offer_id=1030&aff_id=1691&url_id=2561" target="_blank" rel="nofollow" data-dimension112="ff4c4aa2-9660-11f1-89b4-1f3684d9c300" data-action="Deal Block" data-label="Surfshark &ndash; the best cheap VPNSurfshark is a fast, easy-to-use VPN that seriously beats the competition when it comes to subscription pricing. Its two-year Starter plan works out at $2.49 a month (plus tax), but we think Surfshark One is the best value plan as it adds an antivirus, data breach monitor, and alternative ID tool starting from the equivalent of  $2.79 a month. Surfshark – the best cheap VPN" data-dimension48="Surfshark &ndash; the best cheap VPNSurfshark is a fast, easy-to-use VPN that seriously beats the competition when it comes to subscription pricing. Its two-year Starter plan works out at $2.49 a month (plus tax), but we think Surfshark One is the best value plan as it adds an antivirus, data breach monitor, and alternative ID tool starting from the equivalent of  $2.79 a month. Surfshark – the best cheap VPN" data-dimension25="">View Deal</a></p></div><h2 id="the-six-times-gap-by-the-numbers">The six-times gap, by the numbers</h2><p>Surfshark analysed 391,305 malware detections logged by its antivirus between 1 January and 31 July 2026. Windows devices made up 66% of the active user base but accounted for a striking 92% of all detections, while macOS users represented 34% of the base yet just 8% of threats. </p><p>That works out to nearly six Windows detections for every one on a Mac.</p><p>"Windows' popularity has always made it the biggest target for cybercriminals," said Gabrielė Sinkevičiūtė, Head of Product at Surfshark, pointing to the scale of malware built around Windows' dominant market share, along with differences in how each platform handles third-party software and permissions.</p><p><a href="https://bit.ly/3TK4q2N" target="_blank" rel="nofollow">Surfshark's equivalent research</a> from last year yielded similar results, so the trend appears to be consistent.</p><h2 id="trojans-dominate-windows-while-phishing-surges-on-mac">Trojans dominate Windows, while phishing surges on Mac</h2><a href="https://bit.ly/3SAbtut"><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1172px;"><p class="vanilla-image-block" style="padding-top:68.17%;"><img id="xj4Tb5sFYs2sBwDTnEdTUW" name="unnamed (1)" alt="Surfshark's graph showing its Antivirus malware detection data on Windows and macOS (August 2026)" src="https://cdn.mos.cms.futurecdn.net/xj4Tb5sFYs2sBwDTnEdTUW.png" mos="" align="middle" fullscreen="" width="1172" height="799" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="caption-text">Surfshark's new Antiscam hub combines a number of its existing features into one easily navigated location </span><span class="credit" itemprop="copyrightHolder">(Image credit: Surfshark)</span></figcaption></figure></a><p>The threat mix differs sharply by platform. Trojans (malicious software hiding inside safe programs) were the top danger on Windows at 46% of detections, versus 25% on macOS, while riskware (legitimate software that can pose security threats) sat at 19% and 17% respectively. Viruses were level at 9% on both, and adware (software that puts unwanted ads on your device) trailed at 4% on Windows and 3% on Mac.</p><p><a href="https://www.techradar.com/news/everything-you-need-to-know-about-phishing">Phishing</a> is where Mac users lose ground. It ranked third on macOS at 15% of detections, but only sixth on Windows at 3%. Because phishing exploits trust rather than software flaws, a hardened operating system offers little protection, and Surfshark argues a false sense of security can make Mac owners slower to question a suspicious message.</p><p>Other research backs this up. <a href="https://www.microsoft.com/en-us/security/blog/2026/02/02/infostealers-without-borders-macos-python-stealers-and-platform-abuse/" target="_blank" rel="nofollow">Microsoft reported</a> in early 2026 that infostealer campaigns are expanding beyond Windows onto macOS using social-engineering tricks such as ClickFix prompts and fake installers, and <a href="https://www.malwarebytes.com/blog/mobile/2025/02/macs-targeted-by-info-stealers-in-new-era-of-cyberthreats" target="_blank" rel="nofollow">Malwarebytes</a> has tracked Mac infostealers becoming a mainstream threat rather than a rarity. TechRadar has likewise reported that <a href="https://www.techradar.com/pro/the-mythical-security-status-of-macos-is-no-more-report-finds-apple-devices-fare-the-worst-when-it-comes-to-full-takeover-risks">the "mythical" security status of macOS is fading</a>.</p><h2 id="how-to-stay-safe-4">How to stay safe</h2><p>The core advice is the same on both platforms: treat unexpected links, attachments and login prompts with suspicion, keep your operating system and apps patched, and only install software from official sources. </p><p>Never paste a command into Terminal or PowerShell because a website told you to, as that single step drives many recent Mac infections.</p><p>Running reputable antivirus software helps on either system, but the biggest fix for Mac users may be a change in attitude. Dropping the assumption that Apple hardware is inherently immune is the first real step toward not becoming the softer target.</p><div data-widget-type="review" data-model-name="Surfshark"></div> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/vpn/vpn-services/windows-users-face-six-times-more-malware-than-mac-owners-surfshark-reveals-but-macs-are-safer-is-only-half-true</link>
                                                                            <description>
                            <![CDATA[ New Surfshark data shows Windows users hit nearly six times more malware than Mac users, but Mac owners face a bigger phishing risk thanks to a false sense of security. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">EgEUaTKec78PM3a9oqtBSo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8wom7TXsEex7ExUd8LhF2n-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 09:14:22 +0000</pubDate>                                                                                                                                <updated>Thu, 13 Aug 2026 09:16:05 +0000</updated>
                                                                                                                                            <category><![CDATA[VPN Services]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                                                                <author><![CDATA[ monicajwrites@gmail.com (Monica J. White) ]]></author>                    <dc:creator><![CDATA[ Monica J. White ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/6AQ4y5nzk8kQ47Yp69GERj.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Monica is a journalist with over a decade of experience in covering technology.&lt;/p&gt;&lt;p&gt;She writes about the latest developments in computing, which means anything from computer chips made out of paper to cutting-edge desktop processors. Her coverage includes CPUs, GPUs, and everything else that goes into a PC or a laptop, but also peripherals.&lt;/p&gt;&lt;p&gt;GPUs are Monica’s main area of interest, and nothing thrills her quite like that time every couple of years when new graphics cards hit the market. She’s always keeping tabs on the latest from Nvidia, AMD, and Intel, including both the hardware and the software that powers our PCs.&lt;/p&gt;&lt;p&gt;As an avid gamer, her focus is always on the consumer and whether something works well and provides adequate value for the money. She believes that PC building can be intimidating, so her goal is to explain complex concepts in an approachable manner while still digging into the technical nitty-gritty we all love to learn more about.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8wom7TXsEex7ExUd8LhF2n-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.]]></media:description>                                                            <media:text><![CDATA[A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.]]></media:text>
                                <media:title type="plain"><![CDATA[A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8wom7TXsEex7ExUd8LhF2n-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Surfshark recorded nearly 6 times as many malware detections on Windows</strong></li><li><strong>While trojans mostly target Windows devices, phishing lands harder on Mac</strong></li><li><strong>A "Macs are safe" mindset may leave users more at risk of social engineering</strong></li></ul><p>New data from <a href="https://surfshark.com/research/chart/malware-detections-windows-vs-macos">Surfshark</a> shows a stark split in how malware finds its targets: Windows users are hit at nearly six times the rate of macOS users.</p><p>The headline number is eye-catching, but the full story is more interesting. While Windows soaks up the vast majority of traditional <a href="https://www.techradar.com/news/what-is-malware-and-how-dangerous-is-it">malware</a>, Mac users face a very different kind of threat, one that a locked-down operating system does little to stop: <a href="https://www.techradar.com/news/everything-you-need-to-know-about-phishing">phishing</a>.</p><p><a href="https://www.techradar.com/best/best-antivirus">Antivirus </a>software paired with one of the <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> services remains a sensible layer of defence, whatever you run, but <a href="https://bit.ly/3SAbtut" target="_blank" rel="nofollow">Surfshark's findings</a> are a useful reminder that while risks change depending on the platform, they never disappear.</p><div class="product"><a data-dimension112="ff4c4aa2-9660-11f1-89b4-1f3684d9c300" data-action="Deal Block" data-label="Surfshark &ndash; the best cheap VPNSurfshark is a fast, easy-to-use VPN that seriously beats the competition when it comes to subscription pricing. Its two-year Starter plan works out at $2.49 a month (plus tax), but we think Surfshark One is the best value plan as it adds an antivirus, data breach monitor, and alternative ID tool starting from the equivalent of  $2.79 a month. Surfshark – the best cheap VPN" data-dimension48="Surfshark &ndash; the best cheap VPNSurfshark is a fast, easy-to-use VPN that seriously beats the competition when it comes to subscription pricing. Its two-year Starter plan works out at $2.49 a month (plus tax), but we think Surfshark One is the best value plan as it adds an antivirus, data breach monitor, and alternative ID tool starting from the equivalent of  $2.79 a month. Surfshark – the best cheap VPN" href="https://get.surfshark.net/aff_c?offer_id=1030&aff_id=1691&url_id=2561" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="pSwRio45uPDhdN5egHcYF" name="Surfshark deal image.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/pSwRio45uPDhdN5egHcYF.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong></strong><a href="http://get.surfshark.net/aff_c?offer_id=61&aff_id=1691" target="_blank" rel="nofollow" data-dimension112="ff4c4aa2-9660-11f1-89b4-1f3684d9c300" data-action="Deal Block" data-label="Surfshark &ndash; the best cheap VPNSurfshark is a fast, easy-to-use VPN that seriously beats the competition when it comes to subscription pricing. Its two-year Starter plan works out at $2.49 a month (plus tax), but we think Surfshark One is the best value plan as it adds an antivirus, data breach monitor, and alternative ID tool starting from the equivalent of  $2.79 a month. Surfshark – the best cheap VPN" data-dimension48="Surfshark &ndash; the best cheap VPNSurfshark is a fast, easy-to-use VPN that seriously beats the competition when it comes to subscription pricing. Its two-year Starter plan works out at $2.49 a month (plus tax), but we think Surfshark One is the best value plan as it adds an antivirus, data breach monitor, and alternative ID tool starting from the equivalent of  $2.79 a month. Surfshark – the best cheap VPN" data-dimension25=""><strong>Surfshark – the best cheap VPN</strong></a><strong></strong><br>Surfshark is a fast, easy-to-use VPN that seriously beats the competition when it comes to subscription pricing. Its two-year Starter plan works out at $2.49 a month<strong> </strong>(plus tax), but we think Surfshark One is the best value plan as it adds an antivirus, data breach monitor, and alternative ID tool starting from the equivalent of  $2.79 a month. <a class="view-deal button" href="https://get.surfshark.net/aff_c?offer_id=1030&aff_id=1691&url_id=2561" target="_blank" rel="nofollow" data-dimension112="ff4c4aa2-9660-11f1-89b4-1f3684d9c300" data-action="Deal Block" data-label="Surfshark &ndash; the best cheap VPNSurfshark is a fast, easy-to-use VPN that seriously beats the competition when it comes to subscription pricing. Its two-year Starter plan works out at $2.49 a month (plus tax), but we think Surfshark One is the best value plan as it adds an antivirus, data breach monitor, and alternative ID tool starting from the equivalent of  $2.79 a month. Surfshark – the best cheap VPN" data-dimension48="Surfshark &ndash; the best cheap VPNSurfshark is a fast, easy-to-use VPN that seriously beats the competition when it comes to subscription pricing. Its two-year Starter plan works out at $2.49 a month (plus tax), but we think Surfshark One is the best value plan as it adds an antivirus, data breach monitor, and alternative ID tool starting from the equivalent of  $2.79 a month. Surfshark – the best cheap VPN" data-dimension25="">View Deal</a></p></div><h2 id="the-six-times-gap-by-the-numbers">The six-times gap, by the numbers</h2><p>Surfshark analysed 391,305 malware detections logged by its antivirus between 1 January and 31 July 2026. Windows devices made up 66% of the active user base but accounted for a striking 92% of all detections, while macOS users represented 34% of the base yet just 8% of threats. </p><p>That works out to nearly six Windows detections for every one on a Mac.</p><p>"Windows' popularity has always made it the biggest target for cybercriminals," said Gabrielė Sinkevičiūtė, Head of Product at Surfshark, pointing to the scale of malware built around Windows' dominant market share, along with differences in how each platform handles third-party software and permissions.</p><p><a href="https://bit.ly/3TK4q2N" target="_blank" rel="nofollow">Surfshark's equivalent research</a> from last year yielded similar results, so the trend appears to be consistent.</p><h2 id="trojans-dominate-windows-while-phishing-surges-on-mac">Trojans dominate Windows, while phishing surges on Mac</h2><a href="https://bit.ly/3SAbtut"><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1172px;"><p class="vanilla-image-block" style="padding-top:68.17%;"><img id="xj4Tb5sFYs2sBwDTnEdTUW" name="unnamed (1)" alt="Surfshark's graph showing its Antivirus malware detection data on Windows and macOS (August 2026)" src="https://cdn.mos.cms.futurecdn.net/xj4Tb5sFYs2sBwDTnEdTUW.png" mos="" align="middle" fullscreen="" width="1172" height="799" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="caption-text">Surfshark's new Antiscam hub combines a number of its existing features into one easily navigated location </span><span class="credit" itemprop="copyrightHolder">(Image credit: Surfshark)</span></figcaption></figure></a><p>The threat mix differs sharply by platform. Trojans (malicious software hiding inside safe programs) were the top danger on Windows at 46% of detections, versus 25% on macOS, while riskware (legitimate software that can pose security threats) sat at 19% and 17% respectively. Viruses were level at 9% on both, and adware (software that puts unwanted ads on your device) trailed at 4% on Windows and 3% on Mac.</p><p><a href="https://www.techradar.com/news/everything-you-need-to-know-about-phishing">Phishing</a> is where Mac users lose ground. It ranked third on macOS at 15% of detections, but only sixth on Windows at 3%. Because phishing exploits trust rather than software flaws, a hardened operating system offers little protection, and Surfshark argues a false sense of security can make Mac owners slower to question a suspicious message.</p><p>Other research backs this up. <a href="https://www.microsoft.com/en-us/security/blog/2026/02/02/infostealers-without-borders-macos-python-stealers-and-platform-abuse/" target="_blank" rel="nofollow">Microsoft reported</a> in early 2026 that infostealer campaigns are expanding beyond Windows onto macOS using social-engineering tricks such as ClickFix prompts and fake installers, and <a href="https://www.malwarebytes.com/blog/mobile/2025/02/macs-targeted-by-info-stealers-in-new-era-of-cyberthreats" target="_blank" rel="nofollow">Malwarebytes</a> has tracked Mac infostealers becoming a mainstream threat rather than a rarity. TechRadar has likewise reported that <a href="https://www.techradar.com/pro/the-mythical-security-status-of-macos-is-no-more-report-finds-apple-devices-fare-the-worst-when-it-comes-to-full-takeover-risks">the "mythical" security status of macOS is fading</a>.</p><h2 id="how-to-stay-safe-4">How to stay safe</h2><p>The core advice is the same on both platforms: treat unexpected links, attachments and login prompts with suspicion, keep your operating system and apps patched, and only install software from official sources. </p><p>Never paste a command into Terminal or PowerShell because a website told you to, as that single step drives many recent Mac infections.</p><p>Running reputable antivirus software helps on either system, but the biggest fix for Mac users may be a change in attitude. Dropping the assumption that Apple hardware is inherently immune is the first real step toward not becoming the softer target.</p><div data-widget-type="review" data-model-name="Surfshark"></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why AI is accelerating old cyber risks, not creating new ones ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The integration of <a href="https://www.techradar.com/pro/best-ai-chatbot-for-business">artificial intelligence</a> (AI) into everyday work and life has prompted businesses and regulatory bodies to take action. AI is a force introducing entirely new categories of threat, making heightened cyber resilience essential. However, amidst the panic to get in front of this, it should be noted that not all the hype is entirely accurate. </p><p>The underlying vulnerabilities organizations face today are largely the same ones they faced five or ten years ago: unpatched systems, weak <a href="https://www.techradar.com/best/best-identity-theft-protection">identity</a> controls, excessive privileges, insecure third-party integrations.</p><p>In some cases, these weaknesses have existed for some time, and most likely, will continue to exist because the first fundamental constraint of computer science is that the removal of all vulnerabilities is impossible. Therefore, no amount of tooling or budget will ever make any business 100% secure. Equally, that doesn’t mean improvements should simply be dismissed - especially in the age of AI.</p><h2 id="speed-not-novelty">Speed, not novelty</h2><p>While not introducing anything inherently new, there is still some cause for concern surrounding AI. The nature of existing weaknesses remains the same. However, AI does significantly change the speed and scale at which they can be identified and exploited. Tasks that once required time, skill, and persistence can now be automated, accelerated, and in some cases delegated.</p><p>The barrier to entry has been lowered for less sophisticated actors to operate with greater efficiency and success.</p><p>We are already seeing early signs of this shift. Elements of the attack lifecycle can be automated, be that reconnaissance or lateral movement. Nation-state actors have begun experimenting with using these systems to coordinate multi-stage operations, and we’ve recently seen a fully autonomous attack take place, without any human supervision.</p><p>At the same time, more familiar techniques are being enhanced rather than replaced. <a href="https://www.techradar.com/best/best-malware-removal">Malware</a> can be generated or iterated more quickly to evade detection. Social engineering has become more convincing through deepfakes, and phishing campaigns have become easier to scale. </p><p>None of this represents a fundamentally new playbook, simply the acceleration of an existing one. </p><h2 id="the-distraction-problem">The distraction problem</h2><p>The distinction between novelty and speed matters because it shapes how organizations respond. If AI is treated as a novel and exceptional threat, it encourages a reactive mindset. <a href="https://www.techradar.com/news/best-internet-security-suites">Security</a> teams are pushed towards finding “AI-specific” solutions, often at the expense of addressing longstanding gaps in their environment. In practice, those gaps still remain the most reliable entry points for attackers.</p><p>The risk that the current level of attention on AI creates, is a form of strategic distraction. Boards and executives are rightly asking questions about AI risk, but those conversations can become detached from the basics. Patch management programs remain inconsistent. Asset inventories are incomplete. Third-party exposure is poorly understood. Identity and access management remains fragmented across systems. </p><p>These are the same issues that security professionals were tackling before the advent of AI and the technology does not take them off the board. If anything, these become more consequential as the speed of exploitation increases. </p><h2 id="the-right-response">The right response</h2><p>It is worth being clear about the limits of control. No organization will ever be 100% secure. There will always be unknown vulnerabilities, many of which the new frontier models will be able to fish out.</p><p>However, the idea that AI introduces risk that can be entirely “solved” is misleading. Even if advanced models identify previously unknown weaknesses, the response remains the same as it has always been: prioritize, remediate and reduce exposure over time.</p><p>For defenders, matching this increased tempo requires a combination of discipline and adaptation. Established practices such as red teaming and tabletop exercises need to evolve to incorporate AI-enabled scenarios. Incident response teams need to be prepared to handle new forms of evidence, including those generated or manipulated by AI systems.</p><p>In addition, training programs need to reflect the growing sophistication of social engineering, particularly where deepfakes and voice cloning is concerned. </p><p>AI-driven detection and response capabilities can play an important role, particularly in identifying patterns at scale. But they are not a substitute for secure-by-design principles, robust access controls, or a clear understanding of where critical <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> resides. Therefore, organizations should observe caution about over-rotating towards new tools without addressing foundational weaknesses.</p><p>The expansion of the attack surface through enterprise AI adoption adds another layer of complexity. Threat actors are already targeting AI workflows directly, exploiting vulnerabilities in <a href="https://www.techradar.com/best/best-antivirus">software</a> development environments, and using techniques such as prompt injection to manipulate system behavior.</p><p>In some cases, malicious instructions can be embedded within otherwise benign content, triggering unintended actions when processed by an AI system. </p><p>Again, these developments are best understood as extensions of familiar concepts. Input validation, supply chain risk, and data integrity have always been central to security. AI introduces new contexts in which these issues manifest, but not entirely new categories of risk.</p><p>From a governance perspective, this reinforces the need for clarity rather than novelty. Boards should be focused on defining risk tolerance, ensuring accountability, and maintaining visibility over how AI is used within the organization.</p><p>This includes integrating AI considerations into existing risk frameworks rather than treating them as a separate domain. Legal, technical, and communications teams need to be aligned, particularly in scenarios involving misinformation or synthetic media, where response speed is critical. </p><h2 id="what-matters-now">What matters now</h2><p>There is value in the current focus on cyber risk. Increased attention at the board level can drive investment and accountability in ways that were previously difficult to achieve. But that attention needs to be directed towards the right problems. Treating AI as an entirely new threat risks misallocating resources and overlooking the vulnerabilities that are already present.</p><p>AI will continue to evolve and so will the ways in which it is used by both attackers and defenders. In cyber security, progress is often less about discovering new answers and more about applying existing ones with greeted consistency and speed.</p><p>The organizations that navigate this shift most effectively will be those that remain grounded in a clear understanding of what has and has not changed.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/why-ai-is-accelerating-old-cyber-risks-not-creating-new-ones</link>
                                                                            <description>
                            <![CDATA[ AI is changing cyber threats, but core security principles still determine organizational resilience. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nK4aRi3GqqpfroE4X3Ryg3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Aug 2026 10:27:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ed Williams, LevelBlue ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg">
                                                            <media:credit><![CDATA[Blue Planet Studio/Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:description>                                                            <media:text><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:text>
                                <media:title type="plain"><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The integration of <a href="https://www.techradar.com/pro/best-ai-chatbot-for-business">artificial intelligence</a> (AI) into everyday work and life has prompted businesses and regulatory bodies to take action. AI is a force introducing entirely new categories of threat, making heightened cyber resilience essential. However, amidst the panic to get in front of this, it should be noted that not all the hype is entirely accurate. </p><p>The underlying vulnerabilities organizations face today are largely the same ones they faced five or ten years ago: unpatched systems, weak <a href="https://www.techradar.com/best/best-identity-theft-protection">identity</a> controls, excessive privileges, insecure third-party integrations.</p><p>In some cases, these weaknesses have existed for some time, and most likely, will continue to exist because the first fundamental constraint of computer science is that the removal of all vulnerabilities is impossible. Therefore, no amount of tooling or budget will ever make any business 100% secure. Equally, that doesn’t mean improvements should simply be dismissed - especially in the age of AI.</p><h2 id="speed-not-novelty">Speed, not novelty</h2><p>While not introducing anything inherently new, there is still some cause for concern surrounding AI. The nature of existing weaknesses remains the same. However, AI does significantly change the speed and scale at which they can be identified and exploited. Tasks that once required time, skill, and persistence can now be automated, accelerated, and in some cases delegated.</p><p>The barrier to entry has been lowered for less sophisticated actors to operate with greater efficiency and success.</p><p>We are already seeing early signs of this shift. Elements of the attack lifecycle can be automated, be that reconnaissance or lateral movement. Nation-state actors have begun experimenting with using these systems to coordinate multi-stage operations, and we’ve recently seen a fully autonomous attack take place, without any human supervision.</p><p>At the same time, more familiar techniques are being enhanced rather than replaced. <a href="https://www.techradar.com/best/best-malware-removal">Malware</a> can be generated or iterated more quickly to evade detection. Social engineering has become more convincing through deepfakes, and phishing campaigns have become easier to scale. </p><p>None of this represents a fundamentally new playbook, simply the acceleration of an existing one. </p><h2 id="the-distraction-problem">The distraction problem</h2><p>The distinction between novelty and speed matters because it shapes how organizations respond. If AI is treated as a novel and exceptional threat, it encourages a reactive mindset. <a href="https://www.techradar.com/news/best-internet-security-suites">Security</a> teams are pushed towards finding “AI-specific” solutions, often at the expense of addressing longstanding gaps in their environment. In practice, those gaps still remain the most reliable entry points for attackers.</p><p>The risk that the current level of attention on AI creates, is a form of strategic distraction. Boards and executives are rightly asking questions about AI risk, but those conversations can become detached from the basics. Patch management programs remain inconsistent. Asset inventories are incomplete. Third-party exposure is poorly understood. Identity and access management remains fragmented across systems. </p><p>These are the same issues that security professionals were tackling before the advent of AI and the technology does not take them off the board. If anything, these become more consequential as the speed of exploitation increases. </p><h2 id="the-right-response">The right response</h2><p>It is worth being clear about the limits of control. No organization will ever be 100% secure. There will always be unknown vulnerabilities, many of which the new frontier models will be able to fish out.</p><p>However, the idea that AI introduces risk that can be entirely “solved” is misleading. Even if advanced models identify previously unknown weaknesses, the response remains the same as it has always been: prioritize, remediate and reduce exposure over time.</p><p>For defenders, matching this increased tempo requires a combination of discipline and adaptation. Established practices such as red teaming and tabletop exercises need to evolve to incorporate AI-enabled scenarios. Incident response teams need to be prepared to handle new forms of evidence, including those generated or manipulated by AI systems.</p><p>In addition, training programs need to reflect the growing sophistication of social engineering, particularly where deepfakes and voice cloning is concerned. </p><p>AI-driven detection and response capabilities can play an important role, particularly in identifying patterns at scale. But they are not a substitute for secure-by-design principles, robust access controls, or a clear understanding of where critical <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> resides. Therefore, organizations should observe caution about over-rotating towards new tools without addressing foundational weaknesses.</p><p>The expansion of the attack surface through enterprise AI adoption adds another layer of complexity. Threat actors are already targeting AI workflows directly, exploiting vulnerabilities in <a href="https://www.techradar.com/best/best-antivirus">software</a> development environments, and using techniques such as prompt injection to manipulate system behavior.</p><p>In some cases, malicious instructions can be embedded within otherwise benign content, triggering unintended actions when processed by an AI system. </p><p>Again, these developments are best understood as extensions of familiar concepts. Input validation, supply chain risk, and data integrity have always been central to security. AI introduces new contexts in which these issues manifest, but not entirely new categories of risk.</p><p>From a governance perspective, this reinforces the need for clarity rather than novelty. Boards should be focused on defining risk tolerance, ensuring accountability, and maintaining visibility over how AI is used within the organization.</p><p>This includes integrating AI considerations into existing risk frameworks rather than treating them as a separate domain. Legal, technical, and communications teams need to be aligned, particularly in scenarios involving misinformation or synthetic media, where response speed is critical. </p><h2 id="what-matters-now">What matters now</h2><p>There is value in the current focus on cyber risk. Increased attention at the board level can drive investment and accountability in ways that were previously difficult to achieve. But that attention needs to be directed towards the right problems. Treating AI as an entirely new threat risks misallocating resources and overlooking the vulnerabilities that are already present.</p><p>AI will continue to evolve and so will the ways in which it is used by both attackers and defenders. In cyber security, progress is often less about discovering new answers and more about applying existing ones with greeted consistency and speed.</p><p>The organizations that navigate this shift most effectively will be those that remain grounded in a clear understanding of what has and has not changed.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cybersecurity’s identity crisis: why trust can no longer begin and end at login ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The image most organizations still have of a cyberattack is fundamentally outdated.</p><p>We tend to picture hackers battering down digital walls by exploiting software vulnerabilities or launching convoluted <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a> campaigns. Yet some of the most damaging breaches today involve something far less dramatic. </p><p>An attacker enters through the front door using valid credentials, passes authentication checks, and proceeds through the environment as if they are a completely legitimate employee.</p><p>Recent attacks targeting public sector organizations in the UK have once again demonstrated just how easy it is to get into an environment if you have the right credentials. </p><p>Earlier this year, hackers managed to breach systems used by the UK Foreign Office and local councils using stolen login credentials. </p><p>As compromised credentials become increasingly easy to buy and sell on the dark web, organizations face a different sort of challenge: determining whether the person behind a successful login is actually who they claim to be.</p><h2 id="authentication-is-no-longer-enough">Authentication is no longer enough</h2><p>For years, organizations viewed authentication as a decisive security event. A user entered the correct <a href="https://www.techradar.com/best/password-generator">password</a>, perhaps completed a multi-factor authentication challenge, and was granted access.</p><p>The problem is that attackers have, as ever, have found a way around.</p><p>Large-scale phishing campaigns, infostealer <a href="https://www.techradar.com/best/best-malware-removal">malware</a>, session hijacking techniques and credential harvesting operations have made legitimate account access easier to acquire than ever before. The UK's Cyber Security Breaches Survey 2025 found that phishing remains the most common cyber threat facing organizations, affecting 85% of businesses that experienced a breach or attack. </p><p>For many cybercriminals, phishing is simply the first step in a wider economy built around stolen identities. Once compromised, credentials and authentication tokens are routinely traded on dark web forums, giving attackers a ready-made route into trusted environments.</p><p>So why do we continue to treat a successful authentication as proof that a user can be permanently trusted?</p><p>In reality, authentication provides only a snapshot in time. It confirms that a user presented the correct credentials at a specific moment. It does not prove that the individual behind the keyboard remains the same person throughout their activity, nor does it account for changing risk factors once access has been granted.</p><h2 id="the-rise-of-continuous-trust">The rise of continuous trust</h2><p>The concept of Zero Trust isn’t a new principle, but it reflects a broader recognition that trust must be earned repeatedly, not granted indefinitely.</p><p>Continuous trust models assume that every request, transaction, and interaction carries some degree of risk. Instead of relying solely on login events, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> controls continuously assess whether behavior remains consistent with an individual's expected identity and context.</p><p>For example, an <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employee</a> logging in from their usual location during working hours may initially present low risk. However, if that same account suddenly begins accessing systems it has never touched before, or exhibiting behavior inconsistent with historical patterns, trust levels should automatically decrease.</p><p>The critical question is no longer "Did this user authenticate correctly?" but rather "Does this activity continue to make sense?"</p><h2 id="behavior-tells-a-story-that-credentials-cannot">Behavior tells a story that credentials cannot</h2><p>One of the most promising developments in modern <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> is the growing ability to analyze behavioral signals in real time.</p><p>Every user leaves behind a digital fingerprint through their actions. They access particular applications, work within predictable timeframes, interact with specific datasets, and follow recognizable workflows. Even small deviations can provide valuable indicators of potential compromise.</p><p>Machine learning and advanced analytics increasingly allow security teams to identify these anomalies at scale. The goal is not simply to detect malicious activity but to recognize when behavior no longer aligns with an established baseline.</p><p>This is particularly important because attackers who obtain legitimate credentials often attempt to blend into normal operations. They move carefully, avoid triggering conventional alerts, and exploit the fact that many security systems are designed to detect intrusion rather than impersonation.</p><p>Behavioral intelligence offers a much-needed layer of scrutiny that credentials alone cannot provide.</p><p>Importantly, this approach also helps reduce reliance on static indicators of compromise, many of which become obsolete quickly. </p><h2 id="why-identity-security-sits-at-the-heart-of-business-resilience">Why identity security sits at the heart of business resilience</h2><p>Identity-related attacks are increasingly becoming the biggest threat to business continuity. Modern organizations depend on interconnected digital infrastructures spanning employees, contractors, partners, suppliers, and customers. The compromise of a single trusted identity can create a pathway into multiple systems and services.</p><p>Security strategies should focus on limiting unnecessary privileges, continuously validating access rights, reducing identity sprawl, and establishing clear visibility across the entire identity ecosystem.</p><p>Just as importantly, organizations must recognize that identity is dynamic. Employees join, leave, change roles, gain new permissions, and interact with new applications constantly. Security controls need to evolve at the same pace.</p><p>The organizations most resilient to future threats will be those that understand identity as a living system rather than a static credential database.</p><h2 id="the-future-of-cybersecurity-starts-with-questioning-trust">The future of cybersecurity starts with questioning trust</h2><p>The next generation of cyberattacks will be defined by attackers blending in rather than breaking in. That shift demands a fundamental rethinking of cybersecurity from first principles.</p><p>In an environment where identities are constantly targeted, trust can no longer be binary. It cannot be granted once and forgotten. Instead, trust must become dynamic, measurable, and continuously verified.</p><p>The future belongs to organizations that recognize authentication as the start of a security conversation, not its conclusion.</p><p><a href="https://www.techradar.com/best/best-antivirus"><em>We've reviewed, rated, and ranked the best antivirus</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/cybersecuritys-identity-crisis-why-trust-can-no-longer-begin-and-end-at-login</link>
                                                                            <description>
                            <![CDATA[ Cyber threats no longer break in; they log in. Here's why organizations must rethink trust in the age of identity-based attacks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">P4P7Uqw39itJ9WdXNiJSB8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Aug 2026 06:49:25 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Vaibhav Dutta ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:description>                                                            <media:text><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:text>
                                <media:title type="plain"><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The image most organizations still have of a cyberattack is fundamentally outdated.</p><p>We tend to picture hackers battering down digital walls by exploiting software vulnerabilities or launching convoluted <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a> campaigns. Yet some of the most damaging breaches today involve something far less dramatic. </p><p>An attacker enters through the front door using valid credentials, passes authentication checks, and proceeds through the environment as if they are a completely legitimate employee.</p><p>Recent attacks targeting public sector organizations in the UK have once again demonstrated just how easy it is to get into an environment if you have the right credentials. </p><p>Earlier this year, hackers managed to breach systems used by the UK Foreign Office and local councils using stolen login credentials. </p><p>As compromised credentials become increasingly easy to buy and sell on the dark web, organizations face a different sort of challenge: determining whether the person behind a successful login is actually who they claim to be.</p><h2 id="authentication-is-no-longer-enough">Authentication is no longer enough</h2><p>For years, organizations viewed authentication as a decisive security event. A user entered the correct <a href="https://www.techradar.com/best/password-generator">password</a>, perhaps completed a multi-factor authentication challenge, and was granted access.</p><p>The problem is that attackers have, as ever, have found a way around.</p><p>Large-scale phishing campaigns, infostealer <a href="https://www.techradar.com/best/best-malware-removal">malware</a>, session hijacking techniques and credential harvesting operations have made legitimate account access easier to acquire than ever before. The UK's Cyber Security Breaches Survey 2025 found that phishing remains the most common cyber threat facing organizations, affecting 85% of businesses that experienced a breach or attack. </p><p>For many cybercriminals, phishing is simply the first step in a wider economy built around stolen identities. Once compromised, credentials and authentication tokens are routinely traded on dark web forums, giving attackers a ready-made route into trusted environments.</p><p>So why do we continue to treat a successful authentication as proof that a user can be permanently trusted?</p><p>In reality, authentication provides only a snapshot in time. It confirms that a user presented the correct credentials at a specific moment. It does not prove that the individual behind the keyboard remains the same person throughout their activity, nor does it account for changing risk factors once access has been granted.</p><h2 id="the-rise-of-continuous-trust">The rise of continuous trust</h2><p>The concept of Zero Trust isn’t a new principle, but it reflects a broader recognition that trust must be earned repeatedly, not granted indefinitely.</p><p>Continuous trust models assume that every request, transaction, and interaction carries some degree of risk. Instead of relying solely on login events, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> controls continuously assess whether behavior remains consistent with an individual's expected identity and context.</p><p>For example, an <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employee</a> logging in from their usual location during working hours may initially present low risk. However, if that same account suddenly begins accessing systems it has never touched before, or exhibiting behavior inconsistent with historical patterns, trust levels should automatically decrease.</p><p>The critical question is no longer "Did this user authenticate correctly?" but rather "Does this activity continue to make sense?"</p><h2 id="behavior-tells-a-story-that-credentials-cannot">Behavior tells a story that credentials cannot</h2><p>One of the most promising developments in modern <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> is the growing ability to analyze behavioral signals in real time.</p><p>Every user leaves behind a digital fingerprint through their actions. They access particular applications, work within predictable timeframes, interact with specific datasets, and follow recognizable workflows. Even small deviations can provide valuable indicators of potential compromise.</p><p>Machine learning and advanced analytics increasingly allow security teams to identify these anomalies at scale. The goal is not simply to detect malicious activity but to recognize when behavior no longer aligns with an established baseline.</p><p>This is particularly important because attackers who obtain legitimate credentials often attempt to blend into normal operations. They move carefully, avoid triggering conventional alerts, and exploit the fact that many security systems are designed to detect intrusion rather than impersonation.</p><p>Behavioral intelligence offers a much-needed layer of scrutiny that credentials alone cannot provide.</p><p>Importantly, this approach also helps reduce reliance on static indicators of compromise, many of which become obsolete quickly. </p><h2 id="why-identity-security-sits-at-the-heart-of-business-resilience">Why identity security sits at the heart of business resilience</h2><p>Identity-related attacks are increasingly becoming the biggest threat to business continuity. Modern organizations depend on interconnected digital infrastructures spanning employees, contractors, partners, suppliers, and customers. The compromise of a single trusted identity can create a pathway into multiple systems and services.</p><p>Security strategies should focus on limiting unnecessary privileges, continuously validating access rights, reducing identity sprawl, and establishing clear visibility across the entire identity ecosystem.</p><p>Just as importantly, organizations must recognize that identity is dynamic. Employees join, leave, change roles, gain new permissions, and interact with new applications constantly. Security controls need to evolve at the same pace.</p><p>The organizations most resilient to future threats will be those that understand identity as a living system rather than a static credential database.</p><h2 id="the-future-of-cybersecurity-starts-with-questioning-trust">The future of cybersecurity starts with questioning trust</h2><p>The next generation of cyberattacks will be defined by attackers blending in rather than breaking in. That shift demands a fundamental rethinking of cybersecurity from first principles.</p><p>In an environment where identities are constantly targeted, trust can no longer be binary. It cannot be granted once and forgotten. Instead, trust must become dynamic, measurable, and continuously verified.</p><p>The future belongs to organizations that recognize authentication as the start of a security conversation, not its conclusion.</p><p><a href="https://www.techradar.com/best/best-antivirus"><em>We've reviewed, rated, and ranked the best antivirus</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts warn North Korean hackers are increasingly using AI to build smarter and more devious cyberattacks ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Kimsuky used local AI tools to evade monitoring and enhance operations</strong></li><li><strong>Researchers observed extensive AI-driven capability building across the group’s infrastructure</strong></li><li><strong>Defenders urged behavior-based detection to spot evolving AI-enabled threats</strong></li></ul><p>North Korean hackers have found a way to use Generative Artificial Intelligence (GenAI) to supercharge their activities without tipping off the tool’s maintainers.</p><p>When people use AI tools like ChatGPT or Claude, their activities can be (at least to some extent) tracked and curbed - with OpenAI recently identifying and <a href="https://www.techradar.com/pro/security/openai-says-it-stopped-an-asian-scam-campaign-hijacking-chatgpt-to-lure-in-victims" target="_blank">terminating multiple ChatGPT accounts</a> used in phishing and human trafficking. </p><p>That is why Kimsuky - a known state-sponsored North Korean threat actor, used Ollama, GPT4All and Msty locally, allowing them to process documents without sending any sensitive information to outside AI services. </p><h2 id="consistent-process-of-capability-development">"Consistent process of capability development"</h2><p>The attacks were spotted by security researchers <a href="https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm" target="_blank" rel="nofollow">Genians</a> who “conducted months of tracking and log analysis on the infrastructure utilized as C2 in this campaign,” to identify the tools they used.</p><p>Aside from the three LLMs, they also used retrieval augmented generation (RAG) tools for document search, as well as AI agent development frameworks, text-to-speech software, and an AI-assisted coding tool called Cursor.</p><p>Using AI to write malicious code is not as simple as it sounds, due to various guardrails set up by the developers. As a result, AI in crime has been mostly limited to drafting phishing emails and crafting authentic-looking but malicious landing pages. However, Kimsuky has shown that AI in cybercrime continues to evolve and is becoming an ever-greater threat. </p><p>“What was observed in the threat actor's infrastructure was not merely evidence of several documents being created with AI, but a consistent process of capability development: establishing local LLM runtime environments, configuring RAG based on documents in the actor's possession, collecting AI agent development frameworks, and acquiring libraries for integration with external commercial AI services,” Genians concluded.</p><p>As a result, defenders must move from content-based assessment to behavior-based detection, the researchers warned, saying this should serve “as the fundamental premise of security recommendations.”</p><p>“In addition to indicator of compromise (IoC)-based detection, organizations should contextually correlate the sequence of anomalous activities following LNK execution, including PowerShell execution, persistence establishment, and external communications, to assess the overall threat level.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/experts-warn-north-korean-hackers-are-increasingly-using-ai-to-build-smarter-and-more-devious-cyberattacks</link>
                                                                            <description>
                            <![CDATA[ In cybercrime, AI is used for more than simply drafting phishing emails and defenders need to adapt, new report states. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pMvkj5n6fSoGUjACrTKmVj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 10 Aug 2026 11:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:description>                                                            <media:text><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:text>
                                <media:title type="plain"><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Kimsuky used local AI tools to evade monitoring and enhance operations</strong></li><li><strong>Researchers observed extensive AI-driven capability building across the group’s infrastructure</strong></li><li><strong>Defenders urged behavior-based detection to spot evolving AI-enabled threats</strong></li></ul><p>North Korean hackers have found a way to use Generative Artificial Intelligence (GenAI) to supercharge their activities without tipping off the tool’s maintainers.</p><p>When people use AI tools like ChatGPT or Claude, their activities can be (at least to some extent) tracked and curbed - with OpenAI recently identifying and <a href="https://www.techradar.com/pro/security/openai-says-it-stopped-an-asian-scam-campaign-hijacking-chatgpt-to-lure-in-victims" target="_blank">terminating multiple ChatGPT accounts</a> used in phishing and human trafficking. </p><p>That is why Kimsuky - a known state-sponsored North Korean threat actor, used Ollama, GPT4All and Msty locally, allowing them to process documents without sending any sensitive information to outside AI services. </p><h2 id="consistent-process-of-capability-development">"Consistent process of capability development"</h2><p>The attacks were spotted by security researchers <a href="https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm" target="_blank" rel="nofollow">Genians</a> who “conducted months of tracking and log analysis on the infrastructure utilized as C2 in this campaign,” to identify the tools they used.</p><p>Aside from the three LLMs, they also used retrieval augmented generation (RAG) tools for document search, as well as AI agent development frameworks, text-to-speech software, and an AI-assisted coding tool called Cursor.</p><p>Using AI to write malicious code is not as simple as it sounds, due to various guardrails set up by the developers. As a result, AI in crime has been mostly limited to drafting phishing emails and crafting authentic-looking but malicious landing pages. However, Kimsuky has shown that AI in cybercrime continues to evolve and is becoming an ever-greater threat. </p><p>“What was observed in the threat actor's infrastructure was not merely evidence of several documents being created with AI, but a consistent process of capability development: establishing local LLM runtime environments, configuring RAG based on documents in the actor's possession, collecting AI agent development frameworks, and acquiring libraries for integration with external commercial AI services,” Genians concluded.</p><p>As a result, defenders must move from content-based assessment to behavior-based detection, the researchers warned, saying this should serve “as the fundamental premise of security recommendations.”</p><p>“In addition to indicator of compromise (IoC)-based detection, organizations should contextually correlate the sequence of anomalous activities following LNK execution, including PowerShell execution, persistence establishment, and external communications, to assess the overall threat level.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts warn malicious AI skills are hitting more victims than ever — with one family amassing 1.7 million downloads ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Attackers cloned AI skills, later adding malicious code to steal credentials</strong></li><li><strong>Zenity Labs found millions of installs and dozens of dangerous skill variants</strong></li><li><strong>Vercel and Microsoft removed malicious skills, but manual removal is still required</strong></li></ul><p>AI skills, instructions that teach AI agents how to do certain tasks and thus extend their capabilities, are increasingly being used in supply chain attacks, researchers have found.</p><p>Security experts at Zenity Labs uncovered a credential-stealing campaign on skills.sh, a public registry (essentially an app store) for AI agent skills. In the registry, belonging to Vercel (a cloud platform for web applications), threat actors were cloning existing skills, creating typosquatted lookalikes which, at first, did nothing malicious.</p><p>However, after a little time had past, and the skills amassed a solid download count, the attackers introduced malicious code instructing the <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agents</a> to, among other things, exfiltrate SSH keys, cloud credentials, Git and package manager tokens, Kubernetes and Docker configurations, database credentials, infrastructure-as-code credentials, environment files and service account files. The agents were then told to package the stolen information with host metadata and send it to the attackers. </p><h2 id="dozens-of-malicious-skills">Dozens of malicious skills</h2><p>While Zenity Labs could not say exactly how many people fell victim to this attack, they did stress that a single skill family amassed more than 1.7 million aggregate installs (not unique users). </p><p>And that is just one skill family, in a sea of malicious skills. The researchers also said they found “dozens” of additional skills exhibiting either malicious or dangerous behavior. Almost a third (30%) of identified dangerous skills abused Claude Code and OpenClaw to drop malware to their targets, as well. Also, Zenity found “hundreds” of reserved and empty package names that were being kept for future attacks. </p><p>These findings show how quickly cybercriminals adapt, and how creative they can get when it comes to abusing new tech. In essence, this campaign is an AI spin on a software supply-chain attack, being similar in spirit to incidents where attackers compromise an existing trusted package or repository, and later push a malicious update. </p><p>Following responsible disclosure, Vercel and Microsoft removed the identified skills, but Zenity warns that those who installed them before won’t be safe until they remove them from their systems manually.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/experts-warn-malicious-ai-skills-are-hitting-more-victims-than-ever-with-one-family-amassing-1-7-million-downloads</link>
                                                                            <description>
                            <![CDATA[ What if your AI agent suddenly turned rogue and sent all your passwords to a hacker? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ycPinqAGfEcztsGjWSXKcD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NNZdcW7Ku4FXu2CdGfdqvf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 07 Aug 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NNZdcW7Ku4FXu2CdGfdqvf-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI]]></media:description>                                                            <media:text><![CDATA[AI]]></media:text>
                                <media:title type="plain"><![CDATA[AI]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NNZdcW7Ku4FXu2CdGfdqvf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Attackers cloned AI skills, later adding malicious code to steal credentials</strong></li><li><strong>Zenity Labs found millions of installs and dozens of dangerous skill variants</strong></li><li><strong>Vercel and Microsoft removed malicious skills, but manual removal is still required</strong></li></ul><p>AI skills, instructions that teach AI agents how to do certain tasks and thus extend their capabilities, are increasingly being used in supply chain attacks, researchers have found.</p><p>Security experts at Zenity Labs uncovered a credential-stealing campaign on skills.sh, a public registry (essentially an app store) for AI agent skills. In the registry, belonging to Vercel (a cloud platform for web applications), threat actors were cloning existing skills, creating typosquatted lookalikes which, at first, did nothing malicious.</p><p>However, after a little time had past, and the skills amassed a solid download count, the attackers introduced malicious code instructing the <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agents</a> to, among other things, exfiltrate SSH keys, cloud credentials, Git and package manager tokens, Kubernetes and Docker configurations, database credentials, infrastructure-as-code credentials, environment files and service account files. The agents were then told to package the stolen information with host metadata and send it to the attackers. </p><h2 id="dozens-of-malicious-skills">Dozens of malicious skills</h2><p>While Zenity Labs could not say exactly how many people fell victim to this attack, they did stress that a single skill family amassed more than 1.7 million aggregate installs (not unique users). </p><p>And that is just one skill family, in a sea of malicious skills. The researchers also said they found “dozens” of additional skills exhibiting either malicious or dangerous behavior. Almost a third (30%) of identified dangerous skills abused Claude Code and OpenClaw to drop malware to their targets, as well. Also, Zenity found “hundreds” of reserved and empty package names that were being kept for future attacks. </p><p>These findings show how quickly cybercriminals adapt, and how creative they can get when it comes to abusing new tech. In essence, this campaign is an AI spin on a software supply-chain attack, being similar in spirit to incidents where attackers compromise an existing trusted package or repository, and later push a malicious update. </p><p>Following responsible disclosure, Vercel and Microsoft removed the identified skills, but Zenity warns that those who installed them before won’t be safe until they remove them from their systems manually.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers caught hijacking this Chinese Windows VPN's installers to spread malware ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Fortinet experts found malicious code in QuickFox VPN's Windows installer </strong></li><li><strong>The attack actively avoided personal gaming computers</strong></li><li><strong>QuickFox has since removed the malicious components from version 3.59.6</strong></li></ul><p>Cybersecurity researchers have uncovered a severe supply chain attack targeting QuickFox, a popular Chinese <a href="https://www.techradar.com/vpn/best-windows-10-vpn">Windows VPN</a> application. </p><p>According to a new <a href="https://www.fortinet.com/blog/threat-research/quickfox-supply-chain-attack-used-to-deploy-fdmtp-implant" target="_blank" rel="nofollow">report from Fortinet’s FortiGuard Labs</a>, attackers trojanized the software's installers for over a year to quietly deploy malicious backdoor implants onto users' machines.</p><p>As Fortinet's experts explain, QuickFox "is a VPN proxy and game accelerator typically employed by Chinese users to speed up access to Chinese-based resources, often to improve video game user experience<a href="https://www.fortinet.com/blog/threat-research/quickfox-supply-chain-attack-used-to-deploy-fdmtp-implant">.</a>" </p><p>However, experts found that malicious actors altered the application's underlying code to deliver a highly targeted <a href="https://www.techradar.com/news/what-is-malware-and-how-dangerous-is-it">malware</a> campaign. The threat actors modified an HTML file within the app's installer to automatically download and execute malicious JavaScript. </p><p>To avoid raising suspicion, this malicious code was pulled from a fake domain intentionally registered to mimic QuickFox’s legitimate infrastructure. Fortinet notes that the campaign had been active since at least August 2025, with QuickFox removing the malicious code with version 3.59.6. </p><p>TechRadar has not independently verified Fortinet's findings, but we have reached out to QuickFox for comment and will update this article if we receive a reply.</p><h2 id="a-highly-targeted-backdoor">A highly targeted backdoor</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1015px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="sdg89w5jqoix37UtxDByia" name="QuickFox" alt="QuickFox's app logo" src="https://cdn.mos.cms.futurecdn.net/sdg89w5jqoix37UtxDByia.png" mos="" align="middle" fullscreen="" width="1015" height="571" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: QuickFox)</span></figcaption></figure><p>The malware didn't infect everyone who downloaded the compromised VPN software. Instead, it used clever guardrails to filter out standard consumers. </p><p>If the malicious script detected Steam — the popular distribution service for online games — running on the victim's device, it immediately stopped the infection process to avoid personal gaming computers.</p><p>However, if it found tools used by developers, IT administrators, or cryptocurrency users, such as Visual Studio Code, Telegram, or various cryptocurrency wallets, it proceeded with the attack. This behavior suggests the hackers were explicitly hunting for high-value corporate environments and professionals rather than casual gamers.</p><p>When a target was deemed suitable, the script abused a legitimate Microsoft utility to secretly install the FDMTP implant and inject the malware. This persistent backdoor allowed attackers to collect sensitive system information, including <a href="https://www.techradar.com/pro/what-is-an-ip-address">IP addresses</a>, active processes, MAC addresses, and usernames. </p><p>Because FDMTP is highly modular, it also enabled the hackers to remotely download and execute additional malicious plugins, granting them long-term access to compromised machines.</p><p>While macOS builds contained the modified file, the infection process only executed on Windows endpoints. Android and iOS apps were completely unaffected.</p><h2 id="how-to-stay-safe-5">How to stay safe</h2><p>While Fortinet researchers have not confidently attributed the attack to a specific group, they noted significant technical crossovers with Twill Typhoon, a known threat actor.</p><p>The good news is that the threat now appears to be contained. According to the cybersecurity firm, "QuickFox has removed the described malicious components from their Windows installer from v3.59.6," following responsible disclosure.</p><p>If you have used QuickFox on a Windows machine over the last year, you should immediately update to the latest version directly from the vendor and run a full antivirus scan on your system. </p><p>Organizations are also advised to check their networks for any unusual activity or unrecognized file transfers originating from QuickFox installations.</p><div data-widget-type="multimodelreview" data-model-name="NordVPN,Surfshark,ExpressVPN,Proton VPN" data-widget-title="Today's best Windows VPN deals"></div> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/vpn/vpn-privacy-security/hackers-caught-hijacking-this-chinese-windows-vpns-installers-to-spread-malware</link>
                                                                            <description>
                            <![CDATA[ QuickFox VPN users might be at risk. Researchers discovered that attackers trojanized the software's Windows installer for over a year to deploy a persistent backdoor. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">EC4Uh9Tr46AmTmJdfYQ2RH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EEXAxCUDKAq3frELz3rVYY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Aug 2026 15:19:54 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[VPN Privacy & Security]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DXDNjzRkphApxN8f5SooCA.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rene Millman is a seasoned technology journalist whose work has appeared in The Guardian, the Financial Times, Computer Weekly, and IT Pro. With over two decades of experience as a reporter and editor, he specializes in making complex topics like cybersecurity, VPNs, and enterprise software accessible and engaging. &lt;/p&gt;&lt;p&gt;His writing is backed by years of market analysis, allowing him to deliver news and features with an expert’s understanding of the industry.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/EEXAxCUDKAq3frELz3rVYY-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A group of hackers all wearing black with hoods pulled up over their heads with an open laptop in front of them. The background is a Chinese flag]]></media:description>                                                            <media:text><![CDATA[A group of hackers all wearing black with hoods pulled up over their heads with an open laptop in front of them. The background is a Chinese flag]]></media:text>
                                <media:title type="plain"><![CDATA[A group of hackers all wearing black with hoods pulled up over their heads with an open laptop in front of them. The background is a Chinese flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EEXAxCUDKAq3frELz3rVYY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Fortinet experts found malicious code in QuickFox VPN's Windows installer </strong></li><li><strong>The attack actively avoided personal gaming computers</strong></li><li><strong>QuickFox has since removed the malicious components from version 3.59.6</strong></li></ul><p>Cybersecurity researchers have uncovered a severe supply chain attack targeting QuickFox, a popular Chinese <a href="https://www.techradar.com/vpn/best-windows-10-vpn">Windows VPN</a> application. </p><p>According to a new <a href="https://www.fortinet.com/blog/threat-research/quickfox-supply-chain-attack-used-to-deploy-fdmtp-implant" target="_blank" rel="nofollow">report from Fortinet’s FortiGuard Labs</a>, attackers trojanized the software's installers for over a year to quietly deploy malicious backdoor implants onto users' machines.</p><p>As Fortinet's experts explain, QuickFox "is a VPN proxy and game accelerator typically employed by Chinese users to speed up access to Chinese-based resources, often to improve video game user experience<a href="https://www.fortinet.com/blog/threat-research/quickfox-supply-chain-attack-used-to-deploy-fdmtp-implant">.</a>" </p><p>However, experts found that malicious actors altered the application's underlying code to deliver a highly targeted <a href="https://www.techradar.com/news/what-is-malware-and-how-dangerous-is-it">malware</a> campaign. The threat actors modified an HTML file within the app's installer to automatically download and execute malicious JavaScript. </p><p>To avoid raising suspicion, this malicious code was pulled from a fake domain intentionally registered to mimic QuickFox’s legitimate infrastructure. Fortinet notes that the campaign had been active since at least August 2025, with QuickFox removing the malicious code with version 3.59.6. </p><p>TechRadar has not independently verified Fortinet's findings, but we have reached out to QuickFox for comment and will update this article if we receive a reply.</p><h2 id="a-highly-targeted-backdoor">A highly targeted backdoor</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1015px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="sdg89w5jqoix37UtxDByia" name="QuickFox" alt="QuickFox's app logo" src="https://cdn.mos.cms.futurecdn.net/sdg89w5jqoix37UtxDByia.png" mos="" align="middle" fullscreen="" width="1015" height="571" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: QuickFox)</span></figcaption></figure><p>The malware didn't infect everyone who downloaded the compromised VPN software. Instead, it used clever guardrails to filter out standard consumers. </p><p>If the malicious script detected Steam — the popular distribution service for online games — running on the victim's device, it immediately stopped the infection process to avoid personal gaming computers.</p><p>However, if it found tools used by developers, IT administrators, or cryptocurrency users, such as Visual Studio Code, Telegram, or various cryptocurrency wallets, it proceeded with the attack. This behavior suggests the hackers were explicitly hunting for high-value corporate environments and professionals rather than casual gamers.</p><p>When a target was deemed suitable, the script abused a legitimate Microsoft utility to secretly install the FDMTP implant and inject the malware. This persistent backdoor allowed attackers to collect sensitive system information, including <a href="https://www.techradar.com/pro/what-is-an-ip-address">IP addresses</a>, active processes, MAC addresses, and usernames. </p><p>Because FDMTP is highly modular, it also enabled the hackers to remotely download and execute additional malicious plugins, granting them long-term access to compromised machines.</p><p>While macOS builds contained the modified file, the infection process only executed on Windows endpoints. Android and iOS apps were completely unaffected.</p><h2 id="how-to-stay-safe-5">How to stay safe</h2><p>While Fortinet researchers have not confidently attributed the attack to a specific group, they noted significant technical crossovers with Twill Typhoon, a known threat actor.</p><p>The good news is that the threat now appears to be contained. According to the cybersecurity firm, "QuickFox has removed the described malicious components from their Windows installer from v3.59.6," following responsible disclosure.</p><p>If you have used QuickFox on a Windows machine over the last year, you should immediately update to the latest version directly from the vendor and run a full antivirus scan on your system. </p><p>Organizations are also advised to check their networks for any unusual activity or unrecognized file transfers originating from QuickFox installations.</p><div data-widget-type="multimodelreview" data-model-name="NordVPN,Surfshark,ExpressVPN,Proton VPN" data-widget-title="Today's best Windows VPN deals"></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google Blogger locks out thousands of users after malware false positive ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Google’s automated systems mistakenly flagged hundreds of Blogger sites as malicious</strong></li><li><strong>Company admitted a bug caused false malware labels, promising a fix</strong></li><li><strong>Users advised to request reviews, avoid migrating content</strong></li></ul><p>Hundreds of Blogger websites were locked down, and some apparently deleted as well, after Google’s automated security systems erroneously flagged them as malicious.</p><p>A user posted a new message on Google’s forum saying the huge number of reports regarding locked blogs are all for the same reason - <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">Malware</a> and Similar Malicious Content. </p><p>The nature of the lockdown “suggests misclassification by automated systems”, the post reads, adding that the team has “already been notified of this issue.”</p><h2 id="aware-of-a-bug">Aware of a bug""</h2><p>Those affected will see a red padlock in their dashboard and a warning saying the blog was locked: </p><p>"This blog was removed for violating Blogger's Community Guidelines. If you wish to request a review of the blog, click 'Request Review' below," the notice reads. </p><p>At press time, the forum post had more than 500 “I have the same question” votes, and more than 200 replies. </p><p>In a statement given to <a href="https://www.bleepingcomputer.com/news/google/google-blogger-locks-hundreds-of-blogs-in-malware-false-positive/" target="_blank"><em>BleepingComputer</em></a>, Google said it was aware of a bug that falsely labeled many sites as malicious, and that it was working on a fix.</p><p>"We are aware of a bug that incorrectly flagged some Blogger-hosted sites as malware for less than a day. We are working on a fix to resolve the issue as quickly as possible," the company said.</p><p>To make matters even worse, Google said that if users don’t file an appeal, that their blogs can be permanently deleted. </p><p>Users are advised not to create new blogs and migrate content, since that is in violation with Google’s TOS. They are also advised against deleting their Blogger profile or service from their Google account, since this will irrevocably delete the blogs. They can, however, back up their blogs if they are afraid of losing the content. </p><p>The full extent of the issue is unknown, but according to <em>BleepingComputer</em>, the number of users on the platform exceeds 200,000.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/google-blogger-locks-out-thousands-of-users-after-malware-false-positive</link>
                                                                            <description>
                            <![CDATA[ Google is aware of the situation and is working on a fix, it confirms as hundreds of bloggers report issues with their websites. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iHgkAhkcGwXMPfwoTyxCQN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Zdi4C3sHApwN8TFE2Bnhk8-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Aug 2026 14:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/Zdi4C3sHApwN8TFE2Bnhk8-1280-80.png">
                                                            <media:credit><![CDATA[WebLove.PL / Google Support]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Blogger]]></media:description>                                                            <media:text><![CDATA[Blogger]]></media:text>
                                <media:title type="plain"><![CDATA[Blogger]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Zdi4C3sHApwN8TFE2Bnhk8-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Google’s automated systems mistakenly flagged hundreds of Blogger sites as malicious</strong></li><li><strong>Company admitted a bug caused false malware labels, promising a fix</strong></li><li><strong>Users advised to request reviews, avoid migrating content</strong></li></ul><p>Hundreds of Blogger websites were locked down, and some apparently deleted as well, after Google’s automated security systems erroneously flagged them as malicious.</p><p>A user posted a new message on Google’s forum saying the huge number of reports regarding locked blogs are all for the same reason - <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">Malware</a> and Similar Malicious Content. </p><p>The nature of the lockdown “suggests misclassification by automated systems”, the post reads, adding that the team has “already been notified of this issue.”</p><h2 id="aware-of-a-bug">Aware of a bug""</h2><p>Those affected will see a red padlock in their dashboard and a warning saying the blog was locked: </p><p>"This blog was removed for violating Blogger's Community Guidelines. If you wish to request a review of the blog, click 'Request Review' below," the notice reads. </p><p>At press time, the forum post had more than 500 “I have the same question” votes, and more than 200 replies. </p><p>In a statement given to <a href="https://www.bleepingcomputer.com/news/google/google-blogger-locks-hundreds-of-blogs-in-malware-false-positive/" target="_blank"><em>BleepingComputer</em></a>, Google said it was aware of a bug that falsely labeled many sites as malicious, and that it was working on a fix.</p><p>"We are aware of a bug that incorrectly flagged some Blogger-hosted sites as malware for less than a day. We are working on a fix to resolve the issue as quickly as possible," the company said.</p><p>To make matters even worse, Google said that if users don’t file an appeal, that their blogs can be permanently deleted. </p><p>Users are advised not to create new blogs and migrate content, since that is in violation with Google’s TOS. They are also advised against deleting their Blogger profile or service from their Google account, since this will irrevocably delete the blogs. They can, however, back up their blogs if they are afraid of losing the content. </p><p>The full extent of the issue is unknown, but according to <em>BleepingComputer</em>, the number of users on the platform exceeds 200,000.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How open-source malware is re-targeting UK supply chains ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Open-source <a href="https://www.techradar.com/best/best-malware-removal">malware</a> has changed shape. </p><p>What once focused on noisy cryptomining has moved toward something far more valuable: access. </p><p>Our recent data shows attackers are increasingly targeting credentials and secrets embedded in software dependencies, with UK organizations firmly in scope.</p><p>This shift marks a move away from opportunistic abuse toward deliberate supply-chain compromise. Instead of draining compute cycles, attackers are positioning themselves inside build pipelines and developer workflows. </p><p>The goal is persistence, not disruption. </p><p>For organizations that rely heavily on <a href="https://www.techradar.com/best/best-open-source-software">open source software</a>, this fundamentally changes both the threat model and the potential impact.</p><p>This is what “shift left” actually means in 2026: controlling what enters the build, not just detecting what runs in production.</p><h2 id="why-credential-theft-has-overtaken-cryptomining">Why credential theft has overtaken cryptomining</h2><p>More than half of malicious open-source packages now focus on stealing credentials and secrets, overtaking cryptomining as the dominant threat type. The reason is straightforward. Credentials offer lasting value. They provide persistent access, broader reach across environments, and a lower risk of detection than resource abuse. A stolen token or API key can unlock entire systems, not just a single machine.</p><p>Cryptomining, by contrast, is easy to spot and quick to shut down. It consumes resources and triggers alerts. Credential theft blends in and can be executed in seconds. It exploits the trust placed on developer workflows to operate in a safe environment. </p><p>For attackers looking to maximize return while minimizing exposure, this approach maximizes returns whilst doing away with the risk of being discovered.</p><p>The implication is clear: protecting runtime infrastructure is no longer enough. The <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> boundary now starts at dependency intake and at the developer environment.</p><h2 id="multi-stage-malware-becomes-the-norm">Multi-stage malware becomes the norm</h2><p>Modern open-source malware is rarely single-purpose. Our analysis shows dropper and loader behavior increasing by nearly 2,900 percent year over year in Q1 2025, signaling a shift toward engineered, multi-stage attacks. </p><p>Around 77 percent of malicious packages distributed through open source ecosystems now combine multiple threat types. Droppers appear in nearly all observed cases, while secret exfiltration features in close to two-thirds.</p><p>These packages are designed to evolve after installation, pulling in additional payloads or changing behavior over time. This reflects industrialized campaigns rather than opportunistic experimentation. Attackers are investing in resilience, stealth, and scale.</p><p>For defenders, this means signature-based thinking is outdated. If malware is modular and adaptive, controls must focus on provenance, behavior, and prevention before execution. Again, this is what “shift left” actually means: securing the build graph itself, not just the workloads it produces.</p><h2 id="supply-chains-under-direct-pressure">Supply chains under direct pressure</h2><p>The widespread use of open source, particularly within the <a href="https://www.techradar.com/best/best-online-courses-to-learn-javascript">JavaScript</a> ecosystem, creates systemic exposure. Modern applications routinely depend on hundreds of direct and transitive npm packages. That density of reuse creates efficiency, but also amplifies upstream risk.</p><p>Recent activity linked to the Lazarus group illustrates the threat. More than 200 malicious packages were identified, almost all concentrated in npm. When a single ecosystem underpins financial services platforms, government services, and critical national <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>, concentration risk becomes a strategic issue.</p><p>A compromised dependency does not stay isolated. It propagates through shared frameworks, internal libraries, and CI pipelines. In sectors built on speed and reuse, upstream compromise quickly becomes downstream impact. This is why dependency governance is no longer just a developer hygiene issue; it is a board-level supply-chain concern.</p><h2 id="automation-turns-one-package-into-thousands-of-compromises">Automation turns one package into thousands of compromises</h2><p>Today’s malware increasingly targets CI/CD pipelines and developer workflows optimized for <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a>. When a compromised dependency enters a build, it can quietly extract API keys, certificates, and access tokens without triggering runtime alerts. Automation does the rest.</p><p>What starts as a single poisoned package can spread across hundreds or thousands of builds. The very systems designed to accelerate delivery now accelerate compromise.</p><p>The practical takeaway is uncomfortable but necessary: if build systems are automated, security controls must be automated at the same level. Manual review cannot scale against automated distribution.</p><h2 id="ai-coding-assistants-and-the-hallucination-problem">AI coding assistants and the hallucination problem</h2><p><a href="https://www.techradar.com/best/best-ai-tools">AI</a>-assisted development introduces an additional layer of risk. Studies and testing have shown that large language models can, in a meaningful percentage of cases, suggest packages or functions that do not exist. Developers under time pressure may attempt to install or rely on these hallucinated dependencies, unknowingly expanding the attack surface.</p><p>Hallucinated package names, fabricated examples, and unsafe dependency suggestions can quietly undermine supply-chain integrity. Attackers are already exploiting naming conventions and trust models to seed packages that appear legitimate to both humans and machines.</p><p>Each hallucination creates rework, friction, and lost <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a>. Much of this waste could be reduced if AI systems were grounded in authoritative, real-time package intelligence rather than pattern prediction alone.</p><p>Our recent research reinforces this point. The company found that smaller AI models augmented with live package intelligence significantly outperformed larger standalone models when handling dependency upgrades and package selection tasks. The findings suggest that real-time ecosystem context matters more than model size alone when developers are making security-sensitive decisions. It also helps smaller models are 70x cheaper compared to frontier models.</p><p>This has direct implications for software supply-chain defense. If AI coding assistants recommend dependencies without verifying package provenance, maintenance status, or ecosystem trust signals, they risk accelerating the spread of malicious or hallucinated packages into production environments.</p><p>In practice, secure AI-assisted development will depend less on increasingly large models and more on whether those models are connected to authoritative, continuously updated software intelligence.</p><p>Here too, the lesson is upstream control. Guardrails must sit at the point of dependency selection, not after the code ships.</p><h2 id="why-defenders-are-falling-behind">Why defenders are falling behind</h2><p>Many UK security controls remain focused on detecting threats after code is deployed. Attackers have moved upstream. They target the build process, the dependency graph, and the trust relationships developers rely on.</p><p>This mismatch leaves organizations well prepared for runtime incidents but exposed during development. As long as defenders assume malware announces itself loudly, supply-chain compromise will continue to slip through unnoticed.</p><p>“Shift left” is often treated as a slogan. In practice, it means enforcing policy before installation, validating provenance before execution, and blocking malicious packages before they enter the graph.</p><h2 id="stealing-the-keys-not-the-cycles">Stealing the keys, not the cycles</h2><p>Open-source malware has evolved from stealing compute to stealing access. Credentials unlock ecosystems, not just machines. For UK organisations, this makes supply-chain security a strategic concern rather than a technical afterthought.</p><p>Preventing malicious code from entering the build is now more effective than responding after deployment. The quiet shift from coins to credentials has already happened. The question is whether defenses will adapt quickly enough to match it.</p><p>If it isn’t automated, it won’t scale.</p><h2 id="what-organizations-should-prioritize-now">What organizations should prioritize now</h2><p>To respond effectively, UK organisations should focus on a small number of structural controls:</p><p>●      Gate dependency intake with automated policy enforcement before packages enter CI/CD.</p><p>●      Continuously monitor for secret exposure within build environments and revoke compromised credentials rapidly.</p><p>●      Enforce provenance and integrity verification for open-source components, including transitive dependencies.</p><p>●      Ground AI coding tools in authoritative package intelligence to prevent hallucinated or malicious dependency suggestions.</p><p>None of these measures eliminate risk. But together, they realign defenses with where attackers are actually operating: upstream, automated, and inside the supply chain.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>We've ranked and reviewed the best antivirus software available.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/how-open-source-malware-is-re-targeting-uk-supply-chains</link>
                                                                            <description>
                            <![CDATA[ Open-source malware has changed shape. What once focused on noisy cryptomining has moved toward something far more valuable: access. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">K7kRczCJ8xu5ULpbPps76b</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Aug 2026 09:13:55 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ilkka Turunen ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phone malware]]></media:description>                                                            <media:text><![CDATA[Phone malware]]></media:text>
                                <media:title type="plain"><![CDATA[Phone malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Open-source <a href="https://www.techradar.com/best/best-malware-removal">malware</a> has changed shape. </p><p>What once focused on noisy cryptomining has moved toward something far more valuable: access. </p><p>Our recent data shows attackers are increasingly targeting credentials and secrets embedded in software dependencies, with UK organizations firmly in scope.</p><p>This shift marks a move away from opportunistic abuse toward deliberate supply-chain compromise. Instead of draining compute cycles, attackers are positioning themselves inside build pipelines and developer workflows. </p><p>The goal is persistence, not disruption. </p><p>For organizations that rely heavily on <a href="https://www.techradar.com/best/best-open-source-software">open source software</a>, this fundamentally changes both the threat model and the potential impact.</p><p>This is what “shift left” actually means in 2026: controlling what enters the build, not just detecting what runs in production.</p><h2 id="why-credential-theft-has-overtaken-cryptomining">Why credential theft has overtaken cryptomining</h2><p>More than half of malicious open-source packages now focus on stealing credentials and secrets, overtaking cryptomining as the dominant threat type. The reason is straightforward. Credentials offer lasting value. They provide persistent access, broader reach across environments, and a lower risk of detection than resource abuse. A stolen token or API key can unlock entire systems, not just a single machine.</p><p>Cryptomining, by contrast, is easy to spot and quick to shut down. It consumes resources and triggers alerts. Credential theft blends in and can be executed in seconds. It exploits the trust placed on developer workflows to operate in a safe environment. </p><p>For attackers looking to maximize return while minimizing exposure, this approach maximizes returns whilst doing away with the risk of being discovered.</p><p>The implication is clear: protecting runtime infrastructure is no longer enough. The <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> boundary now starts at dependency intake and at the developer environment.</p><h2 id="multi-stage-malware-becomes-the-norm">Multi-stage malware becomes the norm</h2><p>Modern open-source malware is rarely single-purpose. Our analysis shows dropper and loader behavior increasing by nearly 2,900 percent year over year in Q1 2025, signaling a shift toward engineered, multi-stage attacks. </p><p>Around 77 percent of malicious packages distributed through open source ecosystems now combine multiple threat types. Droppers appear in nearly all observed cases, while secret exfiltration features in close to two-thirds.</p><p>These packages are designed to evolve after installation, pulling in additional payloads or changing behavior over time. This reflects industrialized campaigns rather than opportunistic experimentation. Attackers are investing in resilience, stealth, and scale.</p><p>For defenders, this means signature-based thinking is outdated. If malware is modular and adaptive, controls must focus on provenance, behavior, and prevention before execution. Again, this is what “shift left” actually means: securing the build graph itself, not just the workloads it produces.</p><h2 id="supply-chains-under-direct-pressure">Supply chains under direct pressure</h2><p>The widespread use of open source, particularly within the <a href="https://www.techradar.com/best/best-online-courses-to-learn-javascript">JavaScript</a> ecosystem, creates systemic exposure. Modern applications routinely depend on hundreds of direct and transitive npm packages. That density of reuse creates efficiency, but also amplifies upstream risk.</p><p>Recent activity linked to the Lazarus group illustrates the threat. More than 200 malicious packages were identified, almost all concentrated in npm. When a single ecosystem underpins financial services platforms, government services, and critical national <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>, concentration risk becomes a strategic issue.</p><p>A compromised dependency does not stay isolated. It propagates through shared frameworks, internal libraries, and CI pipelines. In sectors built on speed and reuse, upstream compromise quickly becomes downstream impact. This is why dependency governance is no longer just a developer hygiene issue; it is a board-level supply-chain concern.</p><h2 id="automation-turns-one-package-into-thousands-of-compromises">Automation turns one package into thousands of compromises</h2><p>Today’s malware increasingly targets CI/CD pipelines and developer workflows optimized for <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a>. When a compromised dependency enters a build, it can quietly extract API keys, certificates, and access tokens without triggering runtime alerts. Automation does the rest.</p><p>What starts as a single poisoned package can spread across hundreds or thousands of builds. The very systems designed to accelerate delivery now accelerate compromise.</p><p>The practical takeaway is uncomfortable but necessary: if build systems are automated, security controls must be automated at the same level. Manual review cannot scale against automated distribution.</p><h2 id="ai-coding-assistants-and-the-hallucination-problem">AI coding assistants and the hallucination problem</h2><p><a href="https://www.techradar.com/best/best-ai-tools">AI</a>-assisted development introduces an additional layer of risk. Studies and testing have shown that large language models can, in a meaningful percentage of cases, suggest packages or functions that do not exist. Developers under time pressure may attempt to install or rely on these hallucinated dependencies, unknowingly expanding the attack surface.</p><p>Hallucinated package names, fabricated examples, and unsafe dependency suggestions can quietly undermine supply-chain integrity. Attackers are already exploiting naming conventions and trust models to seed packages that appear legitimate to both humans and machines.</p><p>Each hallucination creates rework, friction, and lost <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a>. Much of this waste could be reduced if AI systems were grounded in authoritative, real-time package intelligence rather than pattern prediction alone.</p><p>Our recent research reinforces this point. The company found that smaller AI models augmented with live package intelligence significantly outperformed larger standalone models when handling dependency upgrades and package selection tasks. The findings suggest that real-time ecosystem context matters more than model size alone when developers are making security-sensitive decisions. It also helps smaller models are 70x cheaper compared to frontier models.</p><p>This has direct implications for software supply-chain defense. If AI coding assistants recommend dependencies without verifying package provenance, maintenance status, or ecosystem trust signals, they risk accelerating the spread of malicious or hallucinated packages into production environments.</p><p>In practice, secure AI-assisted development will depend less on increasingly large models and more on whether those models are connected to authoritative, continuously updated software intelligence.</p><p>Here too, the lesson is upstream control. Guardrails must sit at the point of dependency selection, not after the code ships.</p><h2 id="why-defenders-are-falling-behind">Why defenders are falling behind</h2><p>Many UK security controls remain focused on detecting threats after code is deployed. Attackers have moved upstream. They target the build process, the dependency graph, and the trust relationships developers rely on.</p><p>This mismatch leaves organizations well prepared for runtime incidents but exposed during development. As long as defenders assume malware announces itself loudly, supply-chain compromise will continue to slip through unnoticed.</p><p>“Shift left” is often treated as a slogan. In practice, it means enforcing policy before installation, validating provenance before execution, and blocking malicious packages before they enter the graph.</p><h2 id="stealing-the-keys-not-the-cycles">Stealing the keys, not the cycles</h2><p>Open-source malware has evolved from stealing compute to stealing access. Credentials unlock ecosystems, not just machines. For UK organisations, this makes supply-chain security a strategic concern rather than a technical afterthought.</p><p>Preventing malicious code from entering the build is now more effective than responding after deployment. The quiet shift from coins to credentials has already happened. The question is whether defenses will adapt quickly enough to match it.</p><p>If it isn’t automated, it won’t scale.</p><h2 id="what-organizations-should-prioritize-now">What organizations should prioritize now</h2><p>To respond effectively, UK organisations should focus on a small number of structural controls:</p><p>●      Gate dependency intake with automated policy enforcement before packages enter CI/CD.</p><p>●      Continuously monitor for secret exposure within build environments and revoke compromised credentials rapidly.</p><p>●      Enforce provenance and integrity verification for open-source components, including transitive dependencies.</p><p>●      Ground AI coding tools in authoritative package intelligence to prevent hallucinated or malicious dependency suggestions.</p><p>None of these measures eliminate risk. But together, they realign defenses with where attackers are actually operating: upstream, automated, and inside the supply chain.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>We've ranked and reviewed the best antivirus software available.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New ChainDrop worm poisons over 1,300 npm packages, Keyv and Cacheable among those hit ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Aikido researchers uncovers ChainDrop, a Shai‑Hulud variant infecting 1,300+ npm packages with an infostealer</strong></li><li><strong>Attackers compromised GitHub accounts tied to popular libraries (Keyv, Cacheable, flat‑cache, file‑entry‑cache) and pushed tainted releases with 2B monthly downloads</strong></li><li><strong>Malware exfiltrates developer/cloud credentials and secrets to a public GitHub repo; admins should treat affected systems as compromised even after removal</strong></li></ul><p>Another Shai-Hulud variant has been discovered in the wild, infecting more than 1,300 npm packages with an infostealer.</p><p>Security researchers Aikido <a href="https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack" target="_blank" rel="nofollow">reported</a> finding “at least 868 packages (across 1381 versions) that have been compromised by the worm.”</p><p>Shai-Hulud is a self-propagating supply chain <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> that targets software developers by compromising open-source packages and CI/CD pipelines. It steals credentials, API keys, and access tokens and then uses those stolen secrets to publish additional malicious packages.</p><h2 id="what-to-do-in-case-of-an-infection">What to do in case of an infection</h2><p>In May 2026, actors claiming to be associated with the TeamPCP group publicly released the <a href="https://www.techradar.com/pro/security/self-replicating-shai-hulud-infects-147-npm-packages-with-over-2-million-downloads-per-week" target="_blank">Shai-Hulud</a> worm's source code, saying they were “open sourcing the carnage” and inviting other threat actors to adopt and modify the code. Since then, there were multiple copycat campaigns and variants, including this one which Aikido dubbed ‘ChainDrop’.</p><p>Aikido said the attackers compromised the GitHub account of the person maintaining Keyv and Cacheable, widely used open source JavaScript libraries for caching data in Node.js applications. From there, they were able to move into other popular utilities such as flat-cache and file-entry-cache, as well as packages associated with organizations such as Deliveroo, Ornikar, OneReach, Picsart, Qlik, and ServiceTitan.</p><p>The malware was pushed directly into the projects’ main branches, and then generated additional package releases. The compromised packages have a combined 2 billion monthly downloads. </p><p>Aikido says the infostealer grabs developer and cloud credentials, encrypts them, and then sends them to a public GitHub repository called “Shai-Hulud: Here We Go Again.”</p><p>It also steals local configuration files, GitHub PATs, workflow tokens, and other ghp_, gho_, and ghs_ tokens, certain npm tokens, GitHub Actions secrets, AWS credentials, Kubernetes secrets, and more. </p><p>The researchers are saying system admins who installed a tainted package should treat their developer workstation or CI/CD runner as compromised, even if they removed the package. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/new-chaindrop-worm-poisons-over-1-300-npm-packages-keyv-and-cacheable-among-those-hit</link>
                                                                            <description>
                            <![CDATA[ Another Shai-Hulud variant hits npm packages, worming its way into hundreds of packages. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">RckCeYHbHTFv2D4CzixxRm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Aug 2026 11:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:description>                                                            <media:text><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:text>
                                <media:title type="plain"><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Aikido researchers uncovers ChainDrop, a Shai‑Hulud variant infecting 1,300+ npm packages with an infostealer</strong></li><li><strong>Attackers compromised GitHub accounts tied to popular libraries (Keyv, Cacheable, flat‑cache, file‑entry‑cache) and pushed tainted releases with 2B monthly downloads</strong></li><li><strong>Malware exfiltrates developer/cloud credentials and secrets to a public GitHub repo; admins should treat affected systems as compromised even after removal</strong></li></ul><p>Another Shai-Hulud variant has been discovered in the wild, infecting more than 1,300 npm packages with an infostealer.</p><p>Security researchers Aikido <a href="https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack" target="_blank" rel="nofollow">reported</a> finding “at least 868 packages (across 1381 versions) that have been compromised by the worm.”</p><p>Shai-Hulud is a self-propagating supply chain <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> that targets software developers by compromising open-source packages and CI/CD pipelines. It steals credentials, API keys, and access tokens and then uses those stolen secrets to publish additional malicious packages.</p><h2 id="what-to-do-in-case-of-an-infection">What to do in case of an infection</h2><p>In May 2026, actors claiming to be associated with the TeamPCP group publicly released the <a href="https://www.techradar.com/pro/security/self-replicating-shai-hulud-infects-147-npm-packages-with-over-2-million-downloads-per-week" target="_blank">Shai-Hulud</a> worm's source code, saying they were “open sourcing the carnage” and inviting other threat actors to adopt and modify the code. Since then, there were multiple copycat campaigns and variants, including this one which Aikido dubbed ‘ChainDrop’.</p><p>Aikido said the attackers compromised the GitHub account of the person maintaining Keyv and Cacheable, widely used open source JavaScript libraries for caching data in Node.js applications. From there, they were able to move into other popular utilities such as flat-cache and file-entry-cache, as well as packages associated with organizations such as Deliveroo, Ornikar, OneReach, Picsart, Qlik, and ServiceTitan.</p><p>The malware was pushed directly into the projects’ main branches, and then generated additional package releases. The compromised packages have a combined 2 billion monthly downloads. </p><p>Aikido says the infostealer grabs developer and cloud credentials, encrypts them, and then sends them to a public GitHub repository called “Shai-Hulud: Here We Go Again.”</p><p>It also steals local configuration files, GitHub PATs, workflow tokens, and other ghp_, gho_, and ghs_ tokens, certain npm tokens, GitHub Actions secrets, AWS credentials, Kubernetes secrets, and more. </p><p>The researchers are saying system admins who installed a tainted package should treat their developer workstation or CI/CD runner as compromised, even if they removed the package. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New malware disguised as popular Roblox cheat tool could give hackers full control of your PC — including the webcam ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Bitdefender reported Roblox players lured by a fake “undetected” Xeno Executor mod spreading malware</strong></li><li><strong>Infection chain delivers a Java‑based RAT and infostealer stealing browser data, online accounts, payment info, and crypto wallets</strong></li><li><strong>Malware also enables surveillance and remote control; campaign peaked in March 2026 and remains active against Roblox’s 82M players</strong></li></ul><p>Cybercriminals are targeting Roblox players with an infostealer and a Remote Access Trojan (RAT) malware that grants them full control over compromised computers, experts have warned.</p><p>Roblox is an online gaming platform, virtual universe, and game creation system where users play millions of games and user-generated mods. Among the mods is Xeno Executor, a utility that allows players to run scripts that automate certain actions or run custom code. Some players use Xeno Executor to run cheats, too.</p><p>Since it’s an unofficial script, Roblox does not allow it and blocks it whenever a new version is released. Now, security researchers Bitdefender have <a href="https://www.bitdefender.com/en-us/blog/labs/fake-xeno-roblox-discord-executor" target="_blank">reported</a> finding an “undetected” version being promoted on various gaming forums, Discord communities, and similar.</p><h2 id="cornflake-and-cocoshell">CornFlake and CocoShell</h2><p>This version is advertised as “invisible” to Roblox’s anti-cheat systems, but in reality, all it does is trigger an infection chain that ends in a Java-based RAT and information stealer. </p><p>The <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> grabs browser data such as passwords and cookies from some of the most popular browsers (Chrome, Edge, Brave, Opera, Vivaldi), as well as online accounts and payment data (Discord, Roblox, Minecraft, Microsoft Store tokens, and more). </p><p>It also steals cryptocurrency wallet data, particularly targeting the Exodus Wallet. </p><p>As for surveillance, it can log keys, track mouse movements, grab screenshots, stream whatever is on the desktop, and access the webcam. The crooks are also granted file upload and download, PowerShell command execution, and more. </p><p>The campaign was kicked off at the start of the year, reaching its peak in March, it was said. It has now stabilized and is still going relatively strong. </p><p>We don’t know exactly how many players fell victim to this campaign, but Roblox is an incredibly popular platform, so it is possible the campaign was rather successful, too.</p><p>According to <a href="https://activeplayer.io/roblox/" target="_blank" rel="nofollow"><u>Activeplayer</u></a>, Roblox currently has more than 82 million active players.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/new-malware-disguised-as-popular-roblox-cheat-tool-could-give-hackers-full-control-of-your-pc-including-the-webcam</link>
                                                                            <description>
                            <![CDATA[ A new "invisible" Xeno Executor is actually a highly capable RAT and a potent infostealer. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bdewFffvWfEHEGEL8NkXC4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/d7fHZ9ema8LcBAtrUaK7Ji-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Aug 2026 18:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/d7fHZ9ema8LcBAtrUaK7Ji-1280-80.png">
                                                            <media:credit><![CDATA[Roblox]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Screenshot of Roblox&#039;s new Kids and Select accounts]]></media:description>                                                            <media:text><![CDATA[Screenshot of Roblox&#039;s new Kids and Select accounts]]></media:text>
                                <media:title type="plain"><![CDATA[Screenshot of Roblox&#039;s new Kids and Select accounts]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/d7fHZ9ema8LcBAtrUaK7Ji-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Bitdefender reported Roblox players lured by a fake “undetected” Xeno Executor mod spreading malware</strong></li><li><strong>Infection chain delivers a Java‑based RAT and infostealer stealing browser data, online accounts, payment info, and crypto wallets</strong></li><li><strong>Malware also enables surveillance and remote control; campaign peaked in March 2026 and remains active against Roblox’s 82M players</strong></li></ul><p>Cybercriminals are targeting Roblox players with an infostealer and a Remote Access Trojan (RAT) malware that grants them full control over compromised computers, experts have warned.</p><p>Roblox is an online gaming platform, virtual universe, and game creation system where users play millions of games and user-generated mods. Among the mods is Xeno Executor, a utility that allows players to run scripts that automate certain actions or run custom code. Some players use Xeno Executor to run cheats, too.</p><p>Since it’s an unofficial script, Roblox does not allow it and blocks it whenever a new version is released. Now, security researchers Bitdefender have <a href="https://www.bitdefender.com/en-us/blog/labs/fake-xeno-roblox-discord-executor" target="_blank">reported</a> finding an “undetected” version being promoted on various gaming forums, Discord communities, and similar.</p><h2 id="cornflake-and-cocoshell">CornFlake and CocoShell</h2><p>This version is advertised as “invisible” to Roblox’s anti-cheat systems, but in reality, all it does is trigger an infection chain that ends in a Java-based RAT and information stealer. </p><p>The <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> grabs browser data such as passwords and cookies from some of the most popular browsers (Chrome, Edge, Brave, Opera, Vivaldi), as well as online accounts and payment data (Discord, Roblox, Minecraft, Microsoft Store tokens, and more). </p><p>It also steals cryptocurrency wallet data, particularly targeting the Exodus Wallet. </p><p>As for surveillance, it can log keys, track mouse movements, grab screenshots, stream whatever is on the desktop, and access the webcam. The crooks are also granted file upload and download, PowerShell command execution, and more. </p><p>The campaign was kicked off at the start of the year, reaching its peak in March, it was said. It has now stabilized and is still going relatively strong. </p><p>We don’t know exactly how many players fell victim to this campaign, but Roblox is an incredibly popular platform, so it is possible the campaign was rather successful, too.</p><p>According to <a href="https://activeplayer.io/roblox/" target="_blank" rel="nofollow"><u>Activeplayer</u></a>, Roblox currently has more than 82 million active players.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts reveal Google Password Manager can be hijacked to let hackers steal passkeys and gain access to all your secrets ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Palo Alto Networks’ Unit 42 detailed three Google passkey exploits</strong></li><li><strong>Attacks require prior malware infection; methods ranged from impersonating victims to stealing the master secret protecting synced passkeys</strong></li><li><strong>Google implemented fixes after disclosure, with some services (e.g., eBay) patching vulnerabilities directly</strong></li></ul><p>Security researchers from Palo Alto Networks’ Unit 42 have found three ways to exploit Google’s passkey system and log into people’s PIN- or biometrics-protected accounts. </p><p>They named these ways ‘Pass-ta-key’, ‘Silver Pass-ta-key’, and ‘Golden Pass-ta-key’, each being progressively more dangerous than the previous one. </p><p>While it sounds mighty dangerous, there are major caveats to the exploit, and some of the holes have been plugged already.</p><h2 id="trusting-the-wrong-device">Trusting the wrong device</h2><p>The biggest caveat is that the victim’s device needs to be infected with malware beforehand. Malware can do all sorts of things, from stealing session cookies to exfiltrating sensitive data, so if a device is tainted with malware, it’s already in trouble.</p><p>Still, Unit 42’s findings were important enough to warrant a fix from Google.</p><p>In the first technique, the attackers pretend to be the victim. By using malware, they can “ask” Google to log into a passkey-protected account as if it was the victim themselves. Usually, the service being logged into would require a PIN or a fingerprint to confirm the authenticity of the request, but in this scenario, that wasn’t the case.</p><p>The method doesn’t work everywhere, though. Unit 42 could not replicate the attack on GitHub, but they succeeded on eBay. The latter later fixed the problem. </p><p>In the second attack, Unit 42 managed to make Google “trust” the threat actor’s device, meaning the victim’s computer was no longer necessary. </p><p>In the third attack, the researchers managed to steal the “master key”. </p><p><a href="https://www.techradar.com/best/password-manager" target="_blank">Google Password Manager</a> syncs the passkeys between devices, and to do that, it uses a master secret that protects all of the synced passkeys. The researchers found that, under certain circumstances, malware can grab this master secret while Chrome is temporarily using it, unlocking all of the synced passkeys, copying them to another computer, and being able to use them at a later date. </p><p>The researchers disclosed their findings with Google before publication, and some fixes were already implemented. Google is yet to comment on the findings and confirm that all of the flaws were addressed. </p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys/" target="_blank">BleepingComputer</a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/experts-reveal-google-password-manager-can-be-hijacked-to-let-hackers-steal-passkeys-and-gain-access-to-all-your-secrets</link>
                                                                            <description>
                            <![CDATA[ Three Pass-ta-key techniques allowed security researchers to work around biometrics-protected locks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bUumiq3YYstdbhKhfwc7fL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qGbky6N99QiLtik8fjzcUL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Aug 2026 15:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qGbky6N99QiLtik8fjzcUL-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / Blue Andy]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Circuit board and shield icon, Hardware security, computer data protection and electronic technology concept,]]></media:description>                                                            <media:text><![CDATA[Circuit board and shield icon, Hardware security, computer data protection and electronic technology concept,]]></media:text>
                                <media:title type="plain"><![CDATA[Circuit board and shield icon, Hardware security, computer data protection and electronic technology concept,]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qGbky6N99QiLtik8fjzcUL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Palo Alto Networks’ Unit 42 detailed three Google passkey exploits</strong></li><li><strong>Attacks require prior malware infection; methods ranged from impersonating victims to stealing the master secret protecting synced passkeys</strong></li><li><strong>Google implemented fixes after disclosure, with some services (e.g., eBay) patching vulnerabilities directly</strong></li></ul><p>Security researchers from Palo Alto Networks’ Unit 42 have found three ways to exploit Google’s passkey system and log into people’s PIN- or biometrics-protected accounts. </p><p>They named these ways ‘Pass-ta-key’, ‘Silver Pass-ta-key’, and ‘Golden Pass-ta-key’, each being progressively more dangerous than the previous one. </p><p>While it sounds mighty dangerous, there are major caveats to the exploit, and some of the holes have been plugged already.</p><h2 id="trusting-the-wrong-device">Trusting the wrong device</h2><p>The biggest caveat is that the victim’s device needs to be infected with malware beforehand. Malware can do all sorts of things, from stealing session cookies to exfiltrating sensitive data, so if a device is tainted with malware, it’s already in trouble.</p><p>Still, Unit 42’s findings were important enough to warrant a fix from Google.</p><p>In the first technique, the attackers pretend to be the victim. By using malware, they can “ask” Google to log into a passkey-protected account as if it was the victim themselves. Usually, the service being logged into would require a PIN or a fingerprint to confirm the authenticity of the request, but in this scenario, that wasn’t the case.</p><p>The method doesn’t work everywhere, though. Unit 42 could not replicate the attack on GitHub, but they succeeded on eBay. The latter later fixed the problem. </p><p>In the second attack, Unit 42 managed to make Google “trust” the threat actor’s device, meaning the victim’s computer was no longer necessary. </p><p>In the third attack, the researchers managed to steal the “master key”. </p><p><a href="https://www.techradar.com/best/password-manager" target="_blank">Google Password Manager</a> syncs the passkeys between devices, and to do that, it uses a master secret that protects all of the synced passkeys. The researchers found that, under certain circumstances, malware can grab this master secret while Chrome is temporarily using it, unlocking all of the synced passkeys, copying them to another computer, and being able to use them at a later date. </p><p>The researchers disclosed their findings with Google before publication, and some fixes were already implemented. Google is yet to comment on the findings and confirm that all of the flaws were addressed. </p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys/" target="_blank">BleepingComputer</a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI and regulation are reshaping the future of building security ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Criminals used to rely on lock-picking tools and crowbars to break into buildings. Today’s attackers can cause just as much damage and disruption by using phishing links, <a href="https://www.techradar.com/best/best-malware-removal">malware</a> and sophisticated digital exploits to target products, systems and networks.</p><p>The truth is, today’s security challenge isn’t just physical – or cyber – but both. And keeping one step ahead of criminals is a full-time occupation. For those people tasked with researching and developing the latest products, it sometimes means using unconventional tactics, such as using professional lock pickers to test the security and resilience of new products.  </p><p>While modern locks are still based on mechanical engineering, they are more advanced than they look. Improvements in design, materials, and manufacturing mean they are stronger, more reliable, and harder to tamper with. But there’s more to locks than just <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>.</p><p>Some systems can even use the motion of turning a key to generate a small amount of electrical energy, which provides energy to power extra functions without wiring or batteries. This means they are not just standalone locks but can also be used as part of wider digital access systems.</p><p>Used extensively in buildings such as offices, hotels, hospitals and other critical infrastructure, these modern digital access solutions can also connect to cloud-based platforms to manage who can enter buildings and restricted areas. </p><h2 id="bridging-physical-and-digital-security">Bridging physical and digital security</h2><p>However, digital systems have their own security risks, which means security teams need to anticipate and defend against a wide range of risks – from attempts to breach access platforms to phishing attacks – as well as other tactics designed to exploit human behavior.</p><p>This explains why some security personnel have to adopt a ‘hacker’s mindset’ to keep systems safe. And that means continuously testing, probing, and strengthening systems to identify vulnerabilities.</p><p>But what is becoming increasingly clear is that physical and digital security systems can no longer be treated as separate entities. </p><p>Many security solutions today employ both mechanical and digital technology, which means that resilience – the kind of resilience that keeps <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> centers safe, for example – depends on understanding how risks move across systems, people and environments.</p><h2 id="embedding-resilience-into-design">Embedding resilience into design</h2><p>That means continuously designing and testing products against existing real-world threats while also anticipating what might be around the corner. That includes building security into every stage of development, especially as technology evolves.   </p><p>For instance, great strides have been made recently in terms of biometric <a href="https://www.techradar.com/best/best-authenticator-apps">authentication</a>, including facial recognition and fingerprint scanning. Similarly, <a href="https://www.techradar.com/best/best-android-phones">smartphones</a> are increasingly being used to secure credentials for mobile-based access control systems.</p><p>Work is also currently underway to use artificial intelligence (AI) to analyze data in real time to identify unusual entry times, identify multiple failed authentication attempts, or spot any other anomalies that might suggest someone is trying to gain entry illegally. </p><p>Using <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> in a positive way is important because it is also the source of some of the newest and, therefore, most unpredictable challenges. For example, there are now autonomous AI threat chains that can discover and exploit vulnerabilities unilaterally, moving from reconnaissance to exfiltration in record time without any need for human oversight.</p><p>The danger posed by cyber criminals has also become more complex due to the growing interconnectivity of digital products and services. In many ways, a world where all hardware and software are interconnected is an efficient and convenient one.</p><p>But it is also one where, if bad actors gain access to a single element, they may be able to compromise the whole network.</p><h2 id="the-importance-of-regulation-and-compliance">The importance of regulation and compliance</h2><p>This is something that the European Union (EU) is actively addressing. For instance, the European Union’s (EU) NIS2 Directive relates to cybersecurity protecting network and information systems and significantly broadens both the scope and the obligations for compliance.</p><p>It also takes an “all-hazard” approach to security, which means protecting not just digital networks and systems, but also the physical environments in which they operate.</p><p>Similarly, the EU’s Cyber Resilience Act is designed to ensure that all digital products are safe from cyber threats. </p><p>Its goal is to ensure that connected devices and software are built, updated, and maintained with security in mind, helping protect users in an increasingly connected world.</p><p>And by introducing clearer requirements and standards, the CRA will help consumers and organizations identify products with strong security features and configure them more securely from the outset.</p><p>In both cases, not only is it incumbent on vendors to meet or exceed these rules and regulations, but also to keep customers, the wider industry, and other stakeholders informed about developments. </p><p>Not only must businesses contend with the usual challenges from phishing and malware, but the rapid growth of AI has introduced a new and unpredictable dimension to keeping out online criminals. Security – both physical and cyber – has never been more critical than it is today. </p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/ai-and-regulation-are-reshaping-the-future-of-building-security</link>
                                                                            <description>
                            <![CDATA[ Physical and digital security systems can no longer be treated as separate entities. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">PhaeDPPiRasLRCpz46RbMS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UjSNcAZ5SebctebKAMQNVF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 27 Jul 2026 09:08:45 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kelly Gill ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UjSNcAZ5SebctebKAMQNVF-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity ensures data protection on internet. Data encryption, firewall, encrypted network, VPN, secure access and authentication defend against malware, hacking, cyber crime and digital threat]]></media:description>                                                            <media:text><![CDATA[Cybersecurity ensures data protection on internet. Data encryption, firewall, encrypted network, VPN, secure access and authentication defend against malware, hacking, cyber crime and digital threat]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity ensures data protection on internet. Data encryption, firewall, encrypted network, VPN, secure access and authentication defend against malware, hacking, cyber crime and digital threat]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UjSNcAZ5SebctebKAMQNVF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Criminals used to rely on lock-picking tools and crowbars to break into buildings. Today’s attackers can cause just as much damage and disruption by using phishing links, <a href="https://www.techradar.com/best/best-malware-removal">malware</a> and sophisticated digital exploits to target products, systems and networks.</p><p>The truth is, today’s security challenge isn’t just physical – or cyber – but both. And keeping one step ahead of criminals is a full-time occupation. For those people tasked with researching and developing the latest products, it sometimes means using unconventional tactics, such as using professional lock pickers to test the security and resilience of new products.  </p><p>While modern locks are still based on mechanical engineering, they are more advanced than they look. Improvements in design, materials, and manufacturing mean they are stronger, more reliable, and harder to tamper with. But there’s more to locks than just <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>.</p><p>Some systems can even use the motion of turning a key to generate a small amount of electrical energy, which provides energy to power extra functions without wiring or batteries. This means they are not just standalone locks but can also be used as part of wider digital access systems.</p><p>Used extensively in buildings such as offices, hotels, hospitals and other critical infrastructure, these modern digital access solutions can also connect to cloud-based platforms to manage who can enter buildings and restricted areas. </p><h2 id="bridging-physical-and-digital-security">Bridging physical and digital security</h2><p>However, digital systems have their own security risks, which means security teams need to anticipate and defend against a wide range of risks – from attempts to breach access platforms to phishing attacks – as well as other tactics designed to exploit human behavior.</p><p>This explains why some security personnel have to adopt a ‘hacker’s mindset’ to keep systems safe. And that means continuously testing, probing, and strengthening systems to identify vulnerabilities.</p><p>But what is becoming increasingly clear is that physical and digital security systems can no longer be treated as separate entities. </p><p>Many security solutions today employ both mechanical and digital technology, which means that resilience – the kind of resilience that keeps <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> centers safe, for example – depends on understanding how risks move across systems, people and environments.</p><h2 id="embedding-resilience-into-design">Embedding resilience into design</h2><p>That means continuously designing and testing products against existing real-world threats while also anticipating what might be around the corner. That includes building security into every stage of development, especially as technology evolves.   </p><p>For instance, great strides have been made recently in terms of biometric <a href="https://www.techradar.com/best/best-authenticator-apps">authentication</a>, including facial recognition and fingerprint scanning. Similarly, <a href="https://www.techradar.com/best/best-android-phones">smartphones</a> are increasingly being used to secure credentials for mobile-based access control systems.</p><p>Work is also currently underway to use artificial intelligence (AI) to analyze data in real time to identify unusual entry times, identify multiple failed authentication attempts, or spot any other anomalies that might suggest someone is trying to gain entry illegally. </p><p>Using <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> in a positive way is important because it is also the source of some of the newest and, therefore, most unpredictable challenges. For example, there are now autonomous AI threat chains that can discover and exploit vulnerabilities unilaterally, moving from reconnaissance to exfiltration in record time without any need for human oversight.</p><p>The danger posed by cyber criminals has also become more complex due to the growing interconnectivity of digital products and services. In many ways, a world where all hardware and software are interconnected is an efficient and convenient one.</p><p>But it is also one where, if bad actors gain access to a single element, they may be able to compromise the whole network.</p><h2 id="the-importance-of-regulation-and-compliance">The importance of regulation and compliance</h2><p>This is something that the European Union (EU) is actively addressing. For instance, the European Union’s (EU) NIS2 Directive relates to cybersecurity protecting network and information systems and significantly broadens both the scope and the obligations for compliance.</p><p>It also takes an “all-hazard” approach to security, which means protecting not just digital networks and systems, but also the physical environments in which they operate.</p><p>Similarly, the EU’s Cyber Resilience Act is designed to ensure that all digital products are safe from cyber threats. </p><p>Its goal is to ensure that connected devices and software are built, updated, and maintained with security in mind, helping protect users in an increasingly connected world.</p><p>And by introducing clearer requirements and standards, the CRA will help consumers and organizations identify products with strong security features and configure them more securely from the outset.</p><p>In both cases, not only is it incumbent on vendors to meet or exceed these rules and regulations, but also to keep customers, the wider industry, and other stakeholders informed about developments. </p><p>Not only must businesses contend with the usual challenges from phishing and malware, but the rapid growth of AI has introduced a new and unpredictable dimension to keeping out online criminals. Security – both physical and cyber – has never been more critical than it is today. </p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts claim to have found more weaknesses in Apple's Gatekeeper tool — but it doesn't seem too bothered ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Researchers show Gatekeeper can be bypassed by replacing a previously run legitimate macOS app with malware</strong></li><li><strong>Attack requires prior user‑level code execution, then swaps in a malicious app that Gatekeeper won’t re‑verify</strong></li><li><strong>Apple dismissed the issue, saying locally rebuilt bundles fall outside Gatekeeper’s scope, leaving risk to social engineering</strong></li></ul><p>A pair of researchers claims to have found a way around Gatekeeper, a built-in macOS security feature that helps protect users from running malicious or untrusted software. However Apple doesn’t really see it that way and has seemingly decided not to pursue the issue further.</p><p>Gatekeeper’s modus operandi is rather simple - when a user downloads an app from outside the App Store, it verifies the product comes from an identified developer and is notarized by Apple. If it can’t verify it - it won’t allow it to run on the machine. </p><p>Now, security researchers Talal Haj Barky and Tommy Mysk claim that, as long as a legitimate app was run at least once on a macOS device, it can be replaced with a malicious version, and Gatekeeper won’t even blink its virtual eye.</p><h2 id="locally-built">Locally built</h2><p>That also means the attack is not that straightforward to pull off. The threat actor needs to have a way to execute user-level code (for example, a malicious app, a compromised software package installed through a package manager, or a prompt injection attack that tricks an AI agent).</p><p>Once that is obtained, they can archive a legitimate app, remove the original, then replace it with <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, and Gatekeeper will not try to re-authorize it. That malicious version can then trick the victim into compromising the device even further, since a certain level of trust was already established. </p><p>After reporting the issue to Apple, the company apparently just closed it. </p><p>"Apple doesn't consider this attack to be 'modifying' the signed executable," Mysk said. "Instead, Apple says that by archiving/restoring the app bundle, the proof-of-concept code overwrites the entire app bundle, making it locally built. Locally built app bundles are not covered by macOS guards. And this is why access to Keychain or TCC protected directories require system authorization prompts. And for users to accept those is a matter of social engineering attacks that Apple considers out of scope."</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/07/24/researchers-replace-downloaded-macos-apps-with-evil-twins-apple-shrugs/5277858" target="_blank"><em>The Register</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/experts-claim-to-have-found-more-weaknesses-in-apples-gatekeeper-tool-but-it-doesnt-seem-too-bothered</link>
                                                                            <description>
                            <![CDATA[ Gatekeeper doesn't blink when you archive a legitimate app and replace it with an evil doppelganger. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cigoAwt4EPwNFgf9LCcsXa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ctUFkwkvMxVyJJwJmZLPJ5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 25 Jul 2026 14:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ctUFkwkvMxVyJJwJmZLPJ5-1280-80.jpg">
                                                            <media:credit><![CDATA[Apple]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person using iPhone Mirroring on a MacBook Pro running macOS 27 Golden Gate.]]></media:description>                                                            <media:text><![CDATA[A person using iPhone Mirroring on a MacBook Pro running macOS 27 Golden Gate.]]></media:text>
                                <media:title type="plain"><![CDATA[A person using iPhone Mirroring on a MacBook Pro running macOS 27 Golden Gate.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ctUFkwkvMxVyJJwJmZLPJ5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers show Gatekeeper can be bypassed by replacing a previously run legitimate macOS app with malware</strong></li><li><strong>Attack requires prior user‑level code execution, then swaps in a malicious app that Gatekeeper won’t re‑verify</strong></li><li><strong>Apple dismissed the issue, saying locally rebuilt bundles fall outside Gatekeeper’s scope, leaving risk to social engineering</strong></li></ul><p>A pair of researchers claims to have found a way around Gatekeeper, a built-in macOS security feature that helps protect users from running malicious or untrusted software. However Apple doesn’t really see it that way and has seemingly decided not to pursue the issue further.</p><p>Gatekeeper’s modus operandi is rather simple - when a user downloads an app from outside the App Store, it verifies the product comes from an identified developer and is notarized by Apple. If it can’t verify it - it won’t allow it to run on the machine. </p><p>Now, security researchers Talal Haj Barky and Tommy Mysk claim that, as long as a legitimate app was run at least once on a macOS device, it can be replaced with a malicious version, and Gatekeeper won’t even blink its virtual eye.</p><h2 id="locally-built">Locally built</h2><p>That also means the attack is not that straightforward to pull off. The threat actor needs to have a way to execute user-level code (for example, a malicious app, a compromised software package installed through a package manager, or a prompt injection attack that tricks an AI agent).</p><p>Once that is obtained, they can archive a legitimate app, remove the original, then replace it with <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, and Gatekeeper will not try to re-authorize it. That malicious version can then trick the victim into compromising the device even further, since a certain level of trust was already established. </p><p>After reporting the issue to Apple, the company apparently just closed it. </p><p>"Apple doesn't consider this attack to be 'modifying' the signed executable," Mysk said. "Instead, Apple says that by archiving/restoring the app bundle, the proof-of-concept code overwrites the entire app bundle, making it locally built. Locally built app bundles are not covered by macOS guards. And this is why access to Keychain or TCC protected directories require system authorization prompts. And for users to accept those is a matter of social engineering attacks that Apple considers out of scope."</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/07/24/researchers-replace-downloaded-macos-apps-with-evil-twins-apple-shrugs/5277858" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Iran-linked group caught hiding surveillance tools in fake apps ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Recorded Future found an Iran-linked group spreading spyware</strong></li><li><strong>The malware is delivered through fake VPN and media player apps</strong></li><li><strong>Researchers assess that most targets are Iranian users</strong></li></ul><p>A new report from <a href="https://www.recordedfuture.com/research/nexus-tag182-disseminates-markirat" target="_blank" rel="nofollow">Recorded Future's Insikt Group</a> describes a campaign that inverts the whole point of a privacy tool: fake VPN apps built specifically to spy on the people who install them.</p><p>Researchers have linked fresh infrastructure to an Iran-nexus threat cluster they track as TAG-182, which is using fake VPN and media player downloads to allegedly deliver a surveillance tool called MarkiRAT. The group is "highly likely" to be targeting Iranians living inside and outside the country, <a href="https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-ir-2026-0701.pdf" target="_blank" rel="nofollow">the report says</a>.</p><p>It's a blunt reminder that choosing one of the <a href="https://www.techradar.com/vpn/best-vpn" target="_blank" rel="nofollow">best VPN</a> services is a lot more secure than downloading free, unvetted tools.</p><h2 id="fake-apps-real-surveillance">Fake apps, real surveillance</h2><p>Insikt Group identified a cluster of attacker-controlled domains allegedly used to stage downloads of applications that appear nowhere on Google Play or Apple's App Store. </p><p>Two names stand out: Pis2ray VPN and a media player branded YESHICA, which was quietly renamed YESHICA YEPlayer in March 2026 after researchers publicly exposed the original.</p><p>According to researchers, if you download and run one of these files, you get MarkiRAT, a remote access Trojan. In plain terms, that is software that hands control of your device to somebody else. </p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/2072720755884695924"><p lang="en" dir="ltr">A fake VPN app. A fake media player. Both delivering Iranian government surveillance #malware to targeted dissidents. Insikt Group has new research on TAG-182 and MarkiRAT:https://t.co/G7p9JO6peT#ThreatIntelligence #Cybersecurity pic.twitter.com/GwDyvGC99r<a href="https://twitter.com/cantworkitout/status/2072720755884695924">July 2, 2026</a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Analysts have documented it capturing screenshots and uploading them to attacker-run servers, while disguising itself under believable process names.</p><p>It also abuses BITS, the background service Windows uses to fetch updates, to pull down further files. Because that activity looks like ordinary system housekeeping rather than an attack, it tends to slip past routine cleanup.</p><p>MarkiRAT is not new. It has previously been used by Ferocious Kitten, a group <a href="https://securelist.com/ferocious-kitten-6-years-of-covert-surveillance-in-iran/102806/" target="_blank" rel="nofollow">Kaspersky</a> documented conducting years of covert surveillance against activists inside Iran. </p><p>Recorded Future stops short of attributing TAG-182 to any specific Iranian agency, but places it within a broader ecosystem of state-aligned surveillance groups.</p><div data-widget-type="multimodelreview" data-model-name="NordVPN,Surfshark,Proton VPN" data-widget-title="Today's best VPN deals"></div><h2 id="why-a-fake-vpn-makes-such-an-effective-lure">Why a fake VPN makes such an effective lure</h2><p>Distribution runs largely through social media. Insikt Group found Instagram posts promoting Pis2ray VPN in the weeks following street protests in Iran in late 2025, and again around the <a href="https://www.techradar.com/vpn/vpn-privacy-security/the-internet-is-not-connected-irans-88-day-blackout-begins-to-lift-but-traffic-remains-under-50-percent">country's prolonged internet shutdown</a>, which ended with partial restoration of access on 26 May 2026.</p><p>The people most desperate for a <a href="https://www.techradar.com/vpn/virtual-private-networks">virtual private network (VPN)</a> in a censored country are exactly the people most likely to install one from a social media link, because the official stores are often the very thing they cannot reach. </p><p>Recorded Future considers it almost certain that most targets are located in Iran or tied to anti-government movements in Europe and North America. TechRadar has covered <a href="https://www.techradar.com/vpn/vpn-privacy-security/beware-iran-linked-fake-vpn-apps-found-to-spy-on-android-users" target="_blank" rel="nofollow">previous Iran-linked fake VPN campaigns</a>, and this one seems to follow the same pattern with better infrastructure.</p><h2 id="how-to-stay-safe-6">How to stay safe</h2><p>Most readers will never be targeted by a state actor, but the underlying lesson travels. </p><p>Install VPN apps only from official stores, and check that the provider has a real, verifiable presence outside the app listing. </p><p>Treat any VPN promoted through an Instagram post, a Telegram channel, or a direct message as suspect, however polished it looks. </p><p>Star ratings are a weak signal, since fake reviews are cheap.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/vpn/vpn-privacy-security/iran-linked-group-caught-hiding-surveillance-tools-in-fake-apps</link>
                                                                            <description>
                            <![CDATA[ Researchers at Recorded Future found evidence that an Iran-linked group is spreading MarkiRAT spyware through fake VPN and media player apps promoted on social media, targeting Farsi speakers worldwide. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rcr4Mct7ErHSY84Lpy5fvW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/z8Ysj7MUYeyK822yMiTepP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 25 Jul 2026 06:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[VPN Privacy & Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ monicajwrites@gmail.com (Monica J. White) ]]></author>                    <dc:creator><![CDATA[ Monica J. White ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/6AQ4y5nzk8kQ47Yp69GERj.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Monica is a journalist with over a decade of experience in covering technology.&lt;/p&gt;&lt;p&gt;She writes about the latest developments in computing, which means anything from computer chips made out of paper to cutting-edge desktop processors. Her coverage includes CPUs, GPUs, and everything else that goes into a PC or a laptop, but also peripherals.&lt;/p&gt;&lt;p&gt;GPUs are Monica’s main area of interest, and nothing thrills her quite like that time every couple of years when new graphics cards hit the market. She’s always keeping tabs on the latest from Nvidia, AMD, and Intel, including both the hardware and the software that powers our PCs.&lt;/p&gt;&lt;p&gt;As an avid gamer, her focus is always on the consumer and whether something works well and provides adequate value for the money. She believes that PC building can be intimidating, so her goal is to explain complex concepts in an approachable manner while still digging into the technical nitty-gritty we all love to learn more about.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/z8Ysj7MUYeyK822yMiTepP-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Malware kan ställa till med oreda]]></media:description>                                                            <media:text><![CDATA[A hand with a mobile phone and VPN application in front of the Iran flag]]></media:text>
                                <media:title type="plain"><![CDATA[A hand with a mobile phone and VPN application in front of the Iran flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/z8Ysj7MUYeyK822yMiTepP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Recorded Future found an Iran-linked group spreading spyware</strong></li><li><strong>The malware is delivered through fake VPN and media player apps</strong></li><li><strong>Researchers assess that most targets are Iranian users</strong></li></ul><p>A new report from <a href="https://www.recordedfuture.com/research/nexus-tag182-disseminates-markirat" target="_blank" rel="nofollow">Recorded Future's Insikt Group</a> describes a campaign that inverts the whole point of a privacy tool: fake VPN apps built specifically to spy on the people who install them.</p><p>Researchers have linked fresh infrastructure to an Iran-nexus threat cluster they track as TAG-182, which is using fake VPN and media player downloads to allegedly deliver a surveillance tool called MarkiRAT. The group is "highly likely" to be targeting Iranians living inside and outside the country, <a href="https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-ir-2026-0701.pdf" target="_blank" rel="nofollow">the report says</a>.</p><p>It's a blunt reminder that choosing one of the <a href="https://www.techradar.com/vpn/best-vpn" target="_blank" rel="nofollow">best VPN</a> services is a lot more secure than downloading free, unvetted tools.</p><h2 id="fake-apps-real-surveillance">Fake apps, real surveillance</h2><p>Insikt Group identified a cluster of attacker-controlled domains allegedly used to stage downloads of applications that appear nowhere on Google Play or Apple's App Store. </p><p>Two names stand out: Pis2ray VPN and a media player branded YESHICA, which was quietly renamed YESHICA YEPlayer in March 2026 after researchers publicly exposed the original.</p><p>According to researchers, if you download and run one of these files, you get MarkiRAT, a remote access Trojan. In plain terms, that is software that hands control of your device to somebody else. </p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/2072720755884695924"><p lang="en" dir="ltr">A fake VPN app. A fake media player. Both delivering Iranian government surveillance #malware to targeted dissidents. Insikt Group has new research on TAG-182 and MarkiRAT:https://t.co/G7p9JO6peT#ThreatIntelligence #Cybersecurity pic.twitter.com/GwDyvGC99r<a href="https://twitter.com/cantworkitout/status/2072720755884695924">July 2, 2026</a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Analysts have documented it capturing screenshots and uploading them to attacker-run servers, while disguising itself under believable process names.</p><p>It also abuses BITS, the background service Windows uses to fetch updates, to pull down further files. Because that activity looks like ordinary system housekeeping rather than an attack, it tends to slip past routine cleanup.</p><p>MarkiRAT is not new. It has previously been used by Ferocious Kitten, a group <a href="https://securelist.com/ferocious-kitten-6-years-of-covert-surveillance-in-iran/102806/" target="_blank" rel="nofollow">Kaspersky</a> documented conducting years of covert surveillance against activists inside Iran. </p><p>Recorded Future stops short of attributing TAG-182 to any specific Iranian agency, but places it within a broader ecosystem of state-aligned surveillance groups.</p><div data-widget-type="multimodelreview" data-model-name="NordVPN,Surfshark,Proton VPN" data-widget-title="Today's best VPN deals"></div><h2 id="why-a-fake-vpn-makes-such-an-effective-lure">Why a fake VPN makes such an effective lure</h2><p>Distribution runs largely through social media. Insikt Group found Instagram posts promoting Pis2ray VPN in the weeks following street protests in Iran in late 2025, and again around the <a href="https://www.techradar.com/vpn/vpn-privacy-security/the-internet-is-not-connected-irans-88-day-blackout-begins-to-lift-but-traffic-remains-under-50-percent">country's prolonged internet shutdown</a>, which ended with partial restoration of access on 26 May 2026.</p><p>The people most desperate for a <a href="https://www.techradar.com/vpn/virtual-private-networks">virtual private network (VPN)</a> in a censored country are exactly the people most likely to install one from a social media link, because the official stores are often the very thing they cannot reach. </p><p>Recorded Future considers it almost certain that most targets are located in Iran or tied to anti-government movements in Europe and North America. TechRadar has covered <a href="https://www.techradar.com/vpn/vpn-privacy-security/beware-iran-linked-fake-vpn-apps-found-to-spy-on-android-users" target="_blank" rel="nofollow">previous Iran-linked fake VPN campaigns</a>, and this one seems to follow the same pattern with better infrastructure.</p><h2 id="how-to-stay-safe-6">How to stay safe</h2><p>Most readers will never be targeted by a state actor, but the underlying lesson travels. </p><p>Install VPN apps only from official stores, and check that the provider has a real, verifiable presence outside the app listing. </p><p>Treat any VPN promoted through an Instagram post, a Telegram channel, or a direct message as suspect, however polished it looks. </p><p>Star ratings are a weak signal, since fake reviews are cheap.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why you can’t buy security on the dark web ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Data leaks and corporate breaches have become routine. In many cases, stolen credentials, <a href="https://www.techradar.com/best/best-database-software">databases</a>, or attack tools eventually appear on the dark web, where they are traded and reused in future attacks.</p><p>This raises a question for <a href="https://www.techradar.com/best/best-small-business-website-builders">businesses</a>: if stolen corporate data ends up on the dark web, does it make sense to engage with this environment directly — by buying information, paying for services, or negotiating with attackers? </p><p>The short answer is no.</p><p>Not because the dark web doesn’t matter — quite the opposite: it is a core part of today’s cybercriminal <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>. The problem is that doing business with the dark web rarely reduces the immediate risks and systematically strengthens the very market that creates threats.</p><h2 id="the-nature-of-the-dark-web">The nature of the dark web</h2><p>The dark web — often used interchangeably with the term darknet — refers to parts of the internet intentionally hidden from search engines and accessible only through tools such as Tor or I2P.</p><p>It is not a single network but a collection of platforms and communities gated by encryption, nonstandard protocols, or restricted access. While some resources are relatively neutral, others are directly tied to criminal activity. From a cybersecurity perspective, the dark web matters primarily as a mature cybercrime marketplace.  </p><p>Technically, many platforms resemble early internet forums. Functionally, however, they operate much like B2B marketplaces — except the products include stolen data, compromised accounts, <a href="https://www.techradar.com/best/best-malware-removal">malware</a>, exploit kits, and attack services.</p><h2 id="the-economics-of-cybercrime">The economics of cybercrime</h2><p>A key function of the dark web is simplifying the monetization of cybercrime. More importantly, it enables specialization and the formation of complex supply chains.  </p><p>Instead of building operations end-to-end, cybercriminals now focus on specific roles: some identify vulnerabilities and gain initial access, others develop and distribute malware, while others specialize in monetization through data sales, extortion, or attacks-for-hire.</p><p>This division of labor has created a full-fledged cybercrime economy. Attackers no longer need advanced expertise or their own infrastructure — they can purchase the necessary tools and services, lowering the barrier to entry and increasing the scale of attacks.</p><p>A clear example is the Ransomware-as-a-Service (RaaS) model, where core groups develop malware and manage negotiations, while affiliates carry out attacks for a share of the ransom. This model has enabled large-scale incidents such as the 2021 Colonial Pipeline attack, which disrupted fuel supplies across the U.S. East Coast and resulted in a $4.4 million payment.</p><h2 id="dark-web-intelligence-and-false-signals">Dark web intelligence and false signals</h2><p>As the dark web evolved into a cybercrime marketplace, businesses naturally became interested in monitoring it for early warning signals.</p><p>In practice, this approach works only partially. The problem with dark web intelligence is that it comes from an environment with virtually no reliable verification mechanisms.</p><p>Like any anonymous and unregulated market, the dark web contains a significant amount of noise, manipulation, and outright fraud. Listings may be outdated, fabricated, or recycled from old leaks, while reputation signals can be artificially inflated. </p><p>The problem becomes even more pronounced when monitoring is outsourced to third-party vendors. Weak or unverifiable signals can easily be exaggerated, misinterpreted, or presented as evidence of major threats.</p><p>As a result, dark web monitoring rarely provides the level of certainty businesses expect. At best, it can highlight a potential issue that still requires verification.</p><h2 id="never-pay-cybercriminals">Never pay cybercriminals</h2><p>Direct engagement with the dark web is even more problematic — whether through ransom payments, purchasing leaked data, or hiring anonymous actors to test infrastructure.</p><p>The most obvious issue is that paying cybercriminals offers no guarantees. Attackers may simply demand another payment or leak the data anyway.</p><p>Uber learned this in 2016 after paying attackers $100,000 following a breach affecting 57 million users, only for the incident to become public later and trigger regulatory fallout.</p><p>A similar pattern appeared in the 2017 breach of HBO, when attackers stole 1.5 TB of Game of Thrones-related data, including unreleased episodes and internal <a href="https://www.techradar.com/best/best-cloud-document-storage">documents</a>. HBO reportedly transferred $250,000, but the material leaked anyway.</p><p>The broader problem, however, is structural: every payment flowing into the dark web economy directly finances its further growth. The more businesses participate in that market, the stronger the incentives for attackers to discover vulnerabilities, compromise systems, and scale operations.</p><h2 id="common-mistakes-when-dealing-with-the-dark-web">Common mistakes when dealing with the dark web</h2><p>When dealing with the dark web, organizations tend to repeat the same mistakes regardless of industry or size.</p><p>Trying to pay their way out of the problem. Companies often approach ransomware or leaks as negotiation problems. In reality, paying a ransom guarantees neither recovery nor safety. According to a 2021 study by Cybereason, 80% of organizations that paid ransoms were attacked again, often by the same groups.</p><p>Treating dark web monitoring as insurance. Monitoring services are often marketed as proactive protection. In reality, if company data appears for sale on the dark web, the compromise has already happened. Monitoring can provide signals, but it cannot replace actual <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> controls.</p><p>Hiring dark web hackers to test infrastructure. Unlike legitimate penetration testing, anonymous dark web “audits” offer no accountability, verification, or compliance guarantees. Even worse, the hired hacker may establish unauthorized access and later resell it.</p><p>Panicking after seeing the company name on the dark web. Many leaks and listings are outdated, recycled, or entirely fabricated. Without proper verification, rushed decisions can worsen the situation.</p><p>Delegating the entire issue to “dark web specialists.” Many companies delegate dark web monitoring to external vendors without the ability to independently assess the quality of the results. This creates a dangerous information asymmetry and increases dependence on unverifiable claims. </p><h2 id="what-businesses-should-do-instead">What businesses should do instead</h2><p>Dark web intelligence can be useful as one additional source of signals, but it requires cautious interpretation and independent validation. Treating it as a reliable source of truth — or outsourcing the entire function without oversight — is risky.</p><p>More importantly, businesses should avoid directly financing criminal ecosystems through payments or participation in underground markets.</p><p>Cyber resilience is built internally. Rather than attempting to “buy security” on the dark web, organizations should invest in systematic defense: resilient architecture, vulnerability <a href="https://www.techradar.com/best/it-management-tools">management</a>, monitoring, incident response, and technologies capable of mitigating attacks while maintaining continuity of critical services.</p><p><em></em><a href="https://www.techradar.com/best/secure-file-transfer-solutions"><em>We've featured the best secure file sharing.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/why-you-cant-buy-security-on-the-dark-web</link>
                                                                            <description>
                            <![CDATA[ Why buying, monitoring, or negotiating on the dark web often creates more risk than security. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wWnRmnUEZueLuNaGnKgaca</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 09:17:43 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Andrey Leskin ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:description>                                                            <media:text><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:text>
                                <media:title type="plain"><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Data leaks and corporate breaches have become routine. In many cases, stolen credentials, <a href="https://www.techradar.com/best/best-database-software">databases</a>, or attack tools eventually appear on the dark web, where they are traded and reused in future attacks.</p><p>This raises a question for <a href="https://www.techradar.com/best/best-small-business-website-builders">businesses</a>: if stolen corporate data ends up on the dark web, does it make sense to engage with this environment directly — by buying information, paying for services, or negotiating with attackers? </p><p>The short answer is no.</p><p>Not because the dark web doesn’t matter — quite the opposite: it is a core part of today’s cybercriminal <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>. The problem is that doing business with the dark web rarely reduces the immediate risks and systematically strengthens the very market that creates threats.</p><h2 id="the-nature-of-the-dark-web">The nature of the dark web</h2><p>The dark web — often used interchangeably with the term darknet — refers to parts of the internet intentionally hidden from search engines and accessible only through tools such as Tor or I2P.</p><p>It is not a single network but a collection of platforms and communities gated by encryption, nonstandard protocols, or restricted access. While some resources are relatively neutral, others are directly tied to criminal activity. From a cybersecurity perspective, the dark web matters primarily as a mature cybercrime marketplace.  </p><p>Technically, many platforms resemble early internet forums. Functionally, however, they operate much like B2B marketplaces — except the products include stolen data, compromised accounts, <a href="https://www.techradar.com/best/best-malware-removal">malware</a>, exploit kits, and attack services.</p><h2 id="the-economics-of-cybercrime">The economics of cybercrime</h2><p>A key function of the dark web is simplifying the monetization of cybercrime. More importantly, it enables specialization and the formation of complex supply chains.  </p><p>Instead of building operations end-to-end, cybercriminals now focus on specific roles: some identify vulnerabilities and gain initial access, others develop and distribute malware, while others specialize in monetization through data sales, extortion, or attacks-for-hire.</p><p>This division of labor has created a full-fledged cybercrime economy. Attackers no longer need advanced expertise or their own infrastructure — they can purchase the necessary tools and services, lowering the barrier to entry and increasing the scale of attacks.</p><p>A clear example is the Ransomware-as-a-Service (RaaS) model, where core groups develop malware and manage negotiations, while affiliates carry out attacks for a share of the ransom. This model has enabled large-scale incidents such as the 2021 Colonial Pipeline attack, which disrupted fuel supplies across the U.S. East Coast and resulted in a $4.4 million payment.</p><h2 id="dark-web-intelligence-and-false-signals">Dark web intelligence and false signals</h2><p>As the dark web evolved into a cybercrime marketplace, businesses naturally became interested in monitoring it for early warning signals.</p><p>In practice, this approach works only partially. The problem with dark web intelligence is that it comes from an environment with virtually no reliable verification mechanisms.</p><p>Like any anonymous and unregulated market, the dark web contains a significant amount of noise, manipulation, and outright fraud. Listings may be outdated, fabricated, or recycled from old leaks, while reputation signals can be artificially inflated. </p><p>The problem becomes even more pronounced when monitoring is outsourced to third-party vendors. Weak or unverifiable signals can easily be exaggerated, misinterpreted, or presented as evidence of major threats.</p><p>As a result, dark web monitoring rarely provides the level of certainty businesses expect. At best, it can highlight a potential issue that still requires verification.</p><h2 id="never-pay-cybercriminals">Never pay cybercriminals</h2><p>Direct engagement with the dark web is even more problematic — whether through ransom payments, purchasing leaked data, or hiring anonymous actors to test infrastructure.</p><p>The most obvious issue is that paying cybercriminals offers no guarantees. Attackers may simply demand another payment or leak the data anyway.</p><p>Uber learned this in 2016 after paying attackers $100,000 following a breach affecting 57 million users, only for the incident to become public later and trigger regulatory fallout.</p><p>A similar pattern appeared in the 2017 breach of HBO, when attackers stole 1.5 TB of Game of Thrones-related data, including unreleased episodes and internal <a href="https://www.techradar.com/best/best-cloud-document-storage">documents</a>. HBO reportedly transferred $250,000, but the material leaked anyway.</p><p>The broader problem, however, is structural: every payment flowing into the dark web economy directly finances its further growth. The more businesses participate in that market, the stronger the incentives for attackers to discover vulnerabilities, compromise systems, and scale operations.</p><h2 id="common-mistakes-when-dealing-with-the-dark-web">Common mistakes when dealing with the dark web</h2><p>When dealing with the dark web, organizations tend to repeat the same mistakes regardless of industry or size.</p><p>Trying to pay their way out of the problem. Companies often approach ransomware or leaks as negotiation problems. In reality, paying a ransom guarantees neither recovery nor safety. According to a 2021 study by Cybereason, 80% of organizations that paid ransoms were attacked again, often by the same groups.</p><p>Treating dark web monitoring as insurance. Monitoring services are often marketed as proactive protection. In reality, if company data appears for sale on the dark web, the compromise has already happened. Monitoring can provide signals, but it cannot replace actual <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> controls.</p><p>Hiring dark web hackers to test infrastructure. Unlike legitimate penetration testing, anonymous dark web “audits” offer no accountability, verification, or compliance guarantees. Even worse, the hired hacker may establish unauthorized access and later resell it.</p><p>Panicking after seeing the company name on the dark web. Many leaks and listings are outdated, recycled, or entirely fabricated. Without proper verification, rushed decisions can worsen the situation.</p><p>Delegating the entire issue to “dark web specialists.” Many companies delegate dark web monitoring to external vendors without the ability to independently assess the quality of the results. This creates a dangerous information asymmetry and increases dependence on unverifiable claims. </p><h2 id="what-businesses-should-do-instead">What businesses should do instead</h2><p>Dark web intelligence can be useful as one additional source of signals, but it requires cautious interpretation and independent validation. Treating it as a reliable source of truth — or outsourcing the entire function without oversight — is risky.</p><p>More importantly, businesses should avoid directly financing criminal ecosystems through payments or participation in underground markets.</p><p>Cyber resilience is built internally. Rather than attempting to “buy security” on the dark web, organizations should invest in systematic defense: resilient architecture, vulnerability <a href="https://www.techradar.com/best/it-management-tools">management</a>, monitoring, incident response, and technologies capable of mitigating attacks while maintaining continuity of critical services.</p><p><em></em><a href="https://www.techradar.com/best/secure-file-transfer-solutions"><em>We've featured the best secure file sharing.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why operational technology risk still slips past the boardroom ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Across the UK, <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> incidents have become a familiar feature of the business landscape. </p><p>Disruptions affecting manufacturing and logistics over the past year have underlined how exposed organizations can be when physical operations are connected and digitalized. </p><p>Despite this growing awareness, boardroom conversations on cyber risk still tend to center on corporate IT and not operational technology (OT).</p><p>That focus leaves a significant gap. Operational technology, the systems that run factories, manage supply chains and underpin essential services, is now a primary target for attackers. When these environments are compromised, the consequences extend far beyond lost <a href="https://www.techradar.com/pro/best-data-removal-services-of-year">data</a>, affecting safety, revenue and in some cases an organization's ability to operate at all.</p><p>For many boards, this is less a question of indifference and more one of framing. Cyber risk is still commonly understood through an IT lens, shaped by experiences  with data breaches or <a href="https://www.techradar.com/best/best-malware-removal">malware</a> attacks that take down websites or enterprise IT systems. Operational disruption behaves differently in both scale and impact, and it demands a different level of governance attention.</p><h2 id="why-ot-risk-is-routinely-underestimated">Why OT risk is routinely underestimated</h2><p>Much of today’s operational <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> was designed long before connectivity and remote access became standard. These systems were engineered for reliability and safety, not for defense against hostile actors. As they have become more connected and digitalized, exposure has increased without always being matched by equivalent <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> practices.</p><p>The result is that many of the most serious business risks now sit within operational environments that boards rarely examine in detail. This creates a structural blind spot. While IT incidents are often measured in hours or days, failures in OT environments can take longer to mitigate while halting production, disrupting critical services and generating losses that compound rapidly over time.</p><p>Boards tend to engage more effectively when risk is grounded in tangible business terms. Understanding what a facility produces in a day, or what a week-long shutdown would mean for customers and partners, brings operational risk into sharper focus. Without that context, OT security can remain abstract and under-prioritized.</p><h2 id="when-cyber-incidents-stop-operations">When cyber incidents stop operations</h2><p>Recent incidents have shown how quickly cybersecurity events can escalate into operational crises. Last year, a leading British automotive brand publicly confirmed a cyber incident that led to a precautionary shutdown of systems. Manufacturing and retail operations were halted for weeks and disruptions rippled through suppliers, logistics partners and dealerships </p><p>Similar lessons can be drawn from cyber incidents affecting the UK’s water sector, where attackers targeted environments connected to the operational systems that control treatment and distribution. Beginning in 2024, multiple incidents reached systems close enough to operational control to raise concerns about safe operation. </p><p>Taken together, these examples point to board-level issues beyond preventing down time or service outages. They are also about maintaining operational continuity, understanding how quickly localized disruptions can cascade across an organization, and factoring in safety concerns and reputational risk. </p><h2 id="a-risk-landscape-shaped-by-geopolitics">A risk landscape shaped by geopolitics</h2><p>Operational technology risk is increasingly shaped by global forces. Geopolitical tension, trade restrictions and supply chain uncertainty now influence how organizations plan and prioritize security investment. </p><p>At the same time, governments are raising expectations around resilience and incident reporting, particularly in sectors linked to national infrastructure. Boards are therefore required to consider regulatory and geopolitical pressures alongside technical risk, adding another layer of complexity to cyber governance.</p><h2 id="bringing-direction-and-discipline-to-governance">Bringing direction and discipline to governance</h2><p>Stronger oversight depends on education and structure. Boards should expect cyber leaders to explain operational risk in clear business terms and to reference recognized best practice. Focusing on a prioritized and manageable set of critical controls that deliver the greatest risk reduction provides a practical foundation without overwhelming the organization.</p><p>Governance cadence is just as important as control selection. Regular, structured engagement with senior management create space to track how security investment supports operational resilience and wider business outcomes. Treating cyber risk as a standing governance issue, rather than an occasional update, reinforces accountability and sustained attention.</p><p>Clear prioritization models can further support decision-making. Categorizing actions into those that must happen now, those that can follow next and those that should not be pursued helps align technical, operational and financial perspectives. A shared language of priority reduces ambiguity and supports more consistent execution across sites.</p><h2 id="a-leadership-obligation">A leadership obligation</h2><p>Operational technology security can no longer be treated as a technical niche. It has become a leadership responsibility shaped by operational dependence, external pressure and increasingly capable adversaries. Boards that recognize this shift are better positioned to protect continuity, revenue and trust.</p><p>Looking ahead, resilient organizations will be led by teams that engage directly with the realities of their industrial environments. Asking sharper questions, demanding clearer insight and ensuring governance structures keep pace with operational risk remain among the most effective safeguards leaders can provide.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>We've ranked and reviewed the best antivirus software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/why-operational-technology-risk-still-slips-past-the-boardroom</link>
                                                                            <description>
                            <![CDATA[ Boards need to start treating OT cyber risk as an issue of business continuity. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">EcvSXqhDCyZJkkoKy33aYY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 09:04:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Louise Bulman ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg">
                                                            <media:credit><![CDATA[sarayut Thaneerat/ via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:description>                                                            <media:text><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:text>
                                <media:title type="plain"><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Across the UK, <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> incidents have become a familiar feature of the business landscape. </p><p>Disruptions affecting manufacturing and logistics over the past year have underlined how exposed organizations can be when physical operations are connected and digitalized. </p><p>Despite this growing awareness, boardroom conversations on cyber risk still tend to center on corporate IT and not operational technology (OT).</p><p>That focus leaves a significant gap. Operational technology, the systems that run factories, manage supply chains and underpin essential services, is now a primary target for attackers. When these environments are compromised, the consequences extend far beyond lost <a href="https://www.techradar.com/pro/best-data-removal-services-of-year">data</a>, affecting safety, revenue and in some cases an organization's ability to operate at all.</p><p>For many boards, this is less a question of indifference and more one of framing. Cyber risk is still commonly understood through an IT lens, shaped by experiences  with data breaches or <a href="https://www.techradar.com/best/best-malware-removal">malware</a> attacks that take down websites or enterprise IT systems. Operational disruption behaves differently in both scale and impact, and it demands a different level of governance attention.</p><h2 id="why-ot-risk-is-routinely-underestimated">Why OT risk is routinely underestimated</h2><p>Much of today’s operational <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> was designed long before connectivity and remote access became standard. These systems were engineered for reliability and safety, not for defense against hostile actors. As they have become more connected and digitalized, exposure has increased without always being matched by equivalent <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> practices.</p><p>The result is that many of the most serious business risks now sit within operational environments that boards rarely examine in detail. This creates a structural blind spot. While IT incidents are often measured in hours or days, failures in OT environments can take longer to mitigate while halting production, disrupting critical services and generating losses that compound rapidly over time.</p><p>Boards tend to engage more effectively when risk is grounded in tangible business terms. Understanding what a facility produces in a day, or what a week-long shutdown would mean for customers and partners, brings operational risk into sharper focus. Without that context, OT security can remain abstract and under-prioritized.</p><h2 id="when-cyber-incidents-stop-operations">When cyber incidents stop operations</h2><p>Recent incidents have shown how quickly cybersecurity events can escalate into operational crises. Last year, a leading British automotive brand publicly confirmed a cyber incident that led to a precautionary shutdown of systems. Manufacturing and retail operations were halted for weeks and disruptions rippled through suppliers, logistics partners and dealerships </p><p>Similar lessons can be drawn from cyber incidents affecting the UK’s water sector, where attackers targeted environments connected to the operational systems that control treatment and distribution. Beginning in 2024, multiple incidents reached systems close enough to operational control to raise concerns about safe operation. </p><p>Taken together, these examples point to board-level issues beyond preventing down time or service outages. They are also about maintaining operational continuity, understanding how quickly localized disruptions can cascade across an organization, and factoring in safety concerns and reputational risk. </p><h2 id="a-risk-landscape-shaped-by-geopolitics">A risk landscape shaped by geopolitics</h2><p>Operational technology risk is increasingly shaped by global forces. Geopolitical tension, trade restrictions and supply chain uncertainty now influence how organizations plan and prioritize security investment. </p><p>At the same time, governments are raising expectations around resilience and incident reporting, particularly in sectors linked to national infrastructure. Boards are therefore required to consider regulatory and geopolitical pressures alongside technical risk, adding another layer of complexity to cyber governance.</p><h2 id="bringing-direction-and-discipline-to-governance">Bringing direction and discipline to governance</h2><p>Stronger oversight depends on education and structure. Boards should expect cyber leaders to explain operational risk in clear business terms and to reference recognized best practice. Focusing on a prioritized and manageable set of critical controls that deliver the greatest risk reduction provides a practical foundation without overwhelming the organization.</p><p>Governance cadence is just as important as control selection. Regular, structured engagement with senior management create space to track how security investment supports operational resilience and wider business outcomes. Treating cyber risk as a standing governance issue, rather than an occasional update, reinforces accountability and sustained attention.</p><p>Clear prioritization models can further support decision-making. Categorizing actions into those that must happen now, those that can follow next and those that should not be pursued helps align technical, operational and financial perspectives. A shared language of priority reduces ambiguity and supports more consistent execution across sites.</p><h2 id="a-leadership-obligation">A leadership obligation</h2><p>Operational technology security can no longer be treated as a technical niche. It has become a leadership responsibility shaped by operational dependence, external pressure and increasingly capable adversaries. Boards that recognize this shift are better positioned to protect continuity, revenue and trust.</p><p>Looking ahead, resilient organizations will be led by teams that engage directly with the realities of their industrial environments. Asking sharper questions, demanding clearer insight and ensuring governance structures keep pace with operational risk remain among the most effective safeguards leaders can provide.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>We've ranked and reviewed the best antivirus software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Watch out - that Microsoft Calendar invite dated 2050 could be hiding stolen files and worse ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Group‑IB discovers HollowGraph malware targeting Israeli entities, exfiltrating files via Microsoft Graph API</strong></li><li><strong>Operators hide instructions in future calendar entries, then attach encrypted stolen data to events</strong></li><li><strong>At least 12 systems were compromised; overlaps with Lyceum noted but attribution remains low‑confidence</strong></li></ul><p>Cybercriminals have found a way to communicate with the malware installed on victim devices through compromised Microsoft Calendar apps, experts have warned.</p><p>Security researchers at Group-IB have <a href="https://www.group-ib.com/blog/hollowgraph-microsoft-365/" target="_blank" rel="nofollow">detailed</a> a newly discovered piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> called HollowGraph designed to exfiltrate sensitive files from compromised devices.</p><p>What makes the malware stand out is the way it communicates with its operators. The best way to spot hidden malware is to monitor the traffic flowing in and out of a device, which is why cybercriminals try their best to hide this traffic, or blend it with another, legitimate one. In that respect, HollowGraph is unique because it abuses Microsoft Graph API and a compromised Microsoft 365 mailbox calendar.</p><h2 id="a-dozen-victims">A dozen victims</h2><p>After landing on a device and compromising the Microsoft 365 account, HollowGraph uses that account’s permissions to access Microsoft Graph. Operators create calendar entries containing instructions and place them far into the future (in the year 2050) to avoid being spotted. After acting on the instructions and harvesting valuable information, the malware exfiltrates it through the same channel.</p><p>Instead of uploading files to a suspicious server, HollowGraph attaches encrypted stolen data to calendar events and sends it through Microsoft Graph. For defenders, all of this traffic seems legitimate and usually flies under their radars. </p><p>So far, all of the victims are Israeli entities, Group-IB said. The researchers identified at least 12 compromised systems, three of which were still actively communicating with the attackers’ infrastructure during the investigation.</p><p>The researchers did not attribute the attack to any known threat actor, but hinted at a potential. They identified technical similarities in command structures and plugin mechanisms between HollowGraph’s framework, Cavern, and a .NET backdoor used by Lyceum (an Iranian-nexus threat actor associated with OilRig). However, Group-IB explicitly emphasizes that these overlaps are not distinct enough, so they assess this link with low confidence.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/watch-out-that-microsoft-calendar-invite-dated-2050-could-be-hiding-stolen-files-and-worse</link>
                                                                            <description>
                            <![CDATA[ Check your calendars for entries far into the future - especially if you're an Israeli entity. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LjgKxK7hkjXzxZoDby7Pxa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NK6WMQwJZAmbq9SfRREf2f-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jul 2026 16:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NK6WMQwJZAmbq9SfRREf2f-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images / Westend61]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Top view of woman holding smartphone and tablet with calendar on desk]]></media:description>                                                            <media:text><![CDATA[Top view of woman holding smartphone and tablet with calendar on desk]]></media:text>
                                <media:title type="plain"><![CDATA[Top view of woman holding smartphone and tablet with calendar on desk]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NK6WMQwJZAmbq9SfRREf2f-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Group‑IB discovers HollowGraph malware targeting Israeli entities, exfiltrating files via Microsoft Graph API</strong></li><li><strong>Operators hide instructions in future calendar entries, then attach encrypted stolen data to events</strong></li><li><strong>At least 12 systems were compromised; overlaps with Lyceum noted but attribution remains low‑confidence</strong></li></ul><p>Cybercriminals have found a way to communicate with the malware installed on victim devices through compromised Microsoft Calendar apps, experts have warned.</p><p>Security researchers at Group-IB have <a href="https://www.group-ib.com/blog/hollowgraph-microsoft-365/" target="_blank" rel="nofollow">detailed</a> a newly discovered piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> called HollowGraph designed to exfiltrate sensitive files from compromised devices.</p><p>What makes the malware stand out is the way it communicates with its operators. The best way to spot hidden malware is to monitor the traffic flowing in and out of a device, which is why cybercriminals try their best to hide this traffic, or blend it with another, legitimate one. In that respect, HollowGraph is unique because it abuses Microsoft Graph API and a compromised Microsoft 365 mailbox calendar.</p><h2 id="a-dozen-victims">A dozen victims</h2><p>After landing on a device and compromising the Microsoft 365 account, HollowGraph uses that account’s permissions to access Microsoft Graph. Operators create calendar entries containing instructions and place them far into the future (in the year 2050) to avoid being spotted. After acting on the instructions and harvesting valuable information, the malware exfiltrates it through the same channel.</p><p>Instead of uploading files to a suspicious server, HollowGraph attaches encrypted stolen data to calendar events and sends it through Microsoft Graph. For defenders, all of this traffic seems legitimate and usually flies under their radars. </p><p>So far, all of the victims are Israeli entities, Group-IB said. The researchers identified at least 12 compromised systems, three of which were still actively communicating with the attackers’ infrastructure during the investigation.</p><p>The researchers did not attribute the attack to any known threat actor, but hinted at a potential. They identified technical similarities in command structures and plugin mechanisms between HollowGraph’s framework, Cavern, and a .NET backdoor used by Lyceum (an Iranian-nexus threat actor associated with OilRig). However, Group-IB explicitly emphasizes that these overlaps are not distinct enough, so they assess this link with low confidence.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'macOS users may face real, sophisticated threats that require neither exploits nor any elevated access to succeed': ClickLock Stealer tries to trick Apple users into revealing their passwords ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Group‑IB uncovers ClickLock, a new macOS‑focused infostealer using aggressive social engineering by spamming password prompts and terminating key apps every 210ms until victims comply</strong></li><li><strong>Once credentials are obtained, it exfiltrates browser data, crypto wallets, password manager entries, FTP configs, and device info via Telegram Bot API</strong></li><li><strong>Active since May 2026, spotted in 33 countries (mostly Europe), distributed via ClickFix campaigns, and initially undetected by security vendors until recently</strong></li></ul><p>Security researchers from Group-IB have uncovered a new infostealer targeting primarily macOS users in Europe.</p><p>Dubbed <a href="https://www.group-ib.com/blog/clicklock-stealer-macos-malware/" target="_blank">ClickLock</a>, it is more of an annoying social engineering mechanism rather than a full-blown malware variant, constantly popping up a login prompt on the victim’s device, until they finally comply and share the credentials. </p><p>Every 210 milliseconds it terminates key apps on the device (Finder, Dock, TErminal, etc.), essentially making it useless. At the same time, it keeps prompting a password dialog on the screen, making sure the victim can do nothing but provide the credentials.</p><h2 id="targeting-europeans">Targeting Europeans</h2><p>The loop is set to continue for more than three straight days, or until the victim folds. </p><p>After getting the keys to the kingdom, the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> gets to work and starts exfiltrating valuable information.</p><p>This includes data from key <a href="https://www.techradar.com/best/browser" target="_blank">browsers</a> (Chrome, Firefox, Brave, and others), saved logins, cookies, autofill data, and other browser information, data linked to cryptocurrency wallets and extensions, encrypted wallet vault material that can be cracked off-site, data from <a href="https://www.techradar.com/best/password-manager" target="_blank">password managers</a>, cached cryptocurrency addresses across EVM, Bitcoin, Solana, TRON, TON, and Stacks, shell histories, FileZilla FTP configuration and recent-server data, and basic device information.Everything is then packaged into a .ZIP archive and exfiltrated via a Telegram Bot API.</p><p>Group-IB says the campaign has been active since at least May 2026, so it’s been active for a few months now. A researcher submitted a variant to VirusTotal in early June, but it remained undetected by all security vendors until recently, Group-IB says.</p><p>So far, it has been spotted in 33 countries, more than half of which are in Europe, it was also added. The malware is most likely being distributed via a ClickFix social engineering campaign, and has not been tied to any particular threat actor. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/macos-users-may-face-real-sophisticated-threats-that-require-neither-exploits-nor-any-elevated-access-to-succeed-clicklock-stealer-tries-to-trick-apple-users-into-revealing-their-passwords</link>
                                                                            <description>
                            <![CDATA[ ClickLock bores its victims into complying and then steals all sorts of data. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rTfuMcJQcWwgFKNJxEtbqi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[hacker hands at work with  interface around]]></media:description>                                                            <media:text><![CDATA[hacker hands at work with  interface around]]></media:text>
                                <media:title type="plain"><![CDATA[hacker hands at work with  interface around]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Group‑IB uncovers ClickLock, a new macOS‑focused infostealer using aggressive social engineering by spamming password prompts and terminating key apps every 210ms until victims comply</strong></li><li><strong>Once credentials are obtained, it exfiltrates browser data, crypto wallets, password manager entries, FTP configs, and device info via Telegram Bot API</strong></li><li><strong>Active since May 2026, spotted in 33 countries (mostly Europe), distributed via ClickFix campaigns, and initially undetected by security vendors until recently</strong></li></ul><p>Security researchers from Group-IB have uncovered a new infostealer targeting primarily macOS users in Europe.</p><p>Dubbed <a href="https://www.group-ib.com/blog/clicklock-stealer-macos-malware/" target="_blank">ClickLock</a>, it is more of an annoying social engineering mechanism rather than a full-blown malware variant, constantly popping up a login prompt on the victim’s device, until they finally comply and share the credentials. </p><p>Every 210 milliseconds it terminates key apps on the device (Finder, Dock, TErminal, etc.), essentially making it useless. At the same time, it keeps prompting a password dialog on the screen, making sure the victim can do nothing but provide the credentials.</p><h2 id="targeting-europeans">Targeting Europeans</h2><p>The loop is set to continue for more than three straight days, or until the victim folds. </p><p>After getting the keys to the kingdom, the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> gets to work and starts exfiltrating valuable information.</p><p>This includes data from key <a href="https://www.techradar.com/best/browser" target="_blank">browsers</a> (Chrome, Firefox, Brave, and others), saved logins, cookies, autofill data, and other browser information, data linked to cryptocurrency wallets and extensions, encrypted wallet vault material that can be cracked off-site, data from <a href="https://www.techradar.com/best/password-manager" target="_blank">password managers</a>, cached cryptocurrency addresses across EVM, Bitcoin, Solana, TRON, TON, and Stacks, shell histories, FileZilla FTP configuration and recent-server data, and basic device information.Everything is then packaged into a .ZIP archive and exfiltrated via a Telegram Bot API.</p><p>Group-IB says the campaign has been active since at least May 2026, so it’s been active for a few months now. A researcher submitted a variant to VirusTotal in early June, but it remained undetected by all security vendors until recently, Group-IB says.</p><p>So far, it has been spotted in 33 countries, more than half of which are in Europe, it was also added. The malware is most likely being distributed via a ClickFix social engineering campaign, and has not been tied to any particular threat actor. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Russian hacker turns Gemini CLI into a hacking agent, creates small-scale botnet ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Russian hacker “bandcampro” used Google’s Gemini CLI to control an eight‑device botnet at a dental clinic</strong></li><li><strong>The attacker tricked the AI by posing as a pen tester, directing it to migrate C2 infrastructure, troubleshoot connectivity, and prepare payload bundles</strong></li><li><strong>The AI assisted with daily operations like password guessing and WordPress access, highlighting risks of misuse when threat actors co‑opt AI tools</strong></li></ul><p>A Russian hacker and his AI companion were able to successfully control a miniature, eight-system botnet, with the hacker giving instructions in conversational language, and the AI doing his bidding, experts have found.</p><p>Analyzing 200 session logs obtained from the Russian-speaking threat actor known as “bandcampro”, cybersecurity researchers Trend Micro saw the hacker use Google’s Gemini CLI, an open source AI command-line tool that lets developers interact with Google's <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">Gemini AI</a> models directly from a terminal. </p><p>Scouring through a month’s worth of session logs (between April 21 and May 19 2026), the researchers discovered that the attacker tricked the AI by telling it they were an “authorized pen tester”. While the AI mostly complied with their nefarious overlord, they refused the orders on at least one occasion.</p><h2 id="gone-in-six-minutes">Gone in six minutes</h2><p>Trend Micro found the hacker controlled eight devices belonging to a dental clinic and sought to access their access their OpenDental database.</p><p>Using the AI, bandcampro did a number of things, starting with migrating the botnet to a new C2 infrastructure. He gave the AI a skill file with the full architecture description, standard operating procedures, infection one-liner, persistence commands, and troubleshooting steps.</p><p>He then told it to “study the C2 migration”, which had the AI process the guide and prepare all the code and necessary steps. It took the tool around six minutes to get the job done. </p><p>"The AI read the migration guide, then prepared a migration bundle, a small archive of server code, payloads, and the skill file. It then unpacked the bundle, launched the C&C server on a VPS, and brought up the Cloudflare tunnel," Trend Micro says.</p><p>Bandcampro then used the AI to troubleshoot connectivity issues, as well as for various daily operations, such as guessing passwords, generating plausible variants of existing passwords for WordPress portals, and more.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/google-gemini-cli-abused-as-a-hacking-agent-malware-botnet-operator/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/russian-hacker-turns-gemini-cli-into-a-hacking-agent-creates-small-scale-botnet</link>
                                                                            <description>
                            <![CDATA[ The hacker told the AI he was an authorized pentester - and the AI believed him. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2aLD452X3VLZeF4n8MnsB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PRCsQfoXPXi2t4jsGwWr6L-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jul 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PRCsQfoXPXi2t4jsGwWr6L-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A human shakes a robot&#039;s hand in front of blue concentric circles]]></media:description>                                                            <media:text><![CDATA[A human shakes a robot&#039;s hand in front of blue concentric circles]]></media:text>
                                <media:title type="plain"><![CDATA[A human shakes a robot&#039;s hand in front of blue concentric circles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PRCsQfoXPXi2t4jsGwWr6L-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Russian hacker “bandcampro” used Google’s Gemini CLI to control an eight‑device botnet at a dental clinic</strong></li><li><strong>The attacker tricked the AI by posing as a pen tester, directing it to migrate C2 infrastructure, troubleshoot connectivity, and prepare payload bundles</strong></li><li><strong>The AI assisted with daily operations like password guessing and WordPress access, highlighting risks of misuse when threat actors co‑opt AI tools</strong></li></ul><p>A Russian hacker and his AI companion were able to successfully control a miniature, eight-system botnet, with the hacker giving instructions in conversational language, and the AI doing his bidding, experts have found.</p><p>Analyzing 200 session logs obtained from the Russian-speaking threat actor known as “bandcampro”, cybersecurity researchers Trend Micro saw the hacker use Google’s Gemini CLI, an open source AI command-line tool that lets developers interact with Google's <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">Gemini AI</a> models directly from a terminal. </p><p>Scouring through a month’s worth of session logs (between April 21 and May 19 2026), the researchers discovered that the attacker tricked the AI by telling it they were an “authorized pen tester”. While the AI mostly complied with their nefarious overlord, they refused the orders on at least one occasion.</p><h2 id="gone-in-six-minutes">Gone in six minutes</h2><p>Trend Micro found the hacker controlled eight devices belonging to a dental clinic and sought to access their access their OpenDental database.</p><p>Using the AI, bandcampro did a number of things, starting with migrating the botnet to a new C2 infrastructure. He gave the AI a skill file with the full architecture description, standard operating procedures, infection one-liner, persistence commands, and troubleshooting steps.</p><p>He then told it to “study the C2 migration”, which had the AI process the guide and prepare all the code and necessary steps. It took the tool around six minutes to get the job done. </p><p>"The AI read the migration guide, then prepared a migration bundle, a small archive of server code, payloads, and the skill file. It then unpacked the bundle, launched the C&C server on a VPS, and brought up the Cloudflare tunnel," Trend Micro says.</p><p>Bandcampro then used the AI to troubleshoot connectivity issues, as well as for various daily operations, such as guessing passwords, generating plausible variants of existing passwords for WordPress portals, and more.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/google-gemini-cli-abused-as-a-hacking-agent-malware-botnet-operator/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hundreds of GitHub repos found posing as real software to push malware ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>ArcticWolf uncovered 292 malicious GitHub repositories spoofing legitimate tools and products, delivering a new BoryptGrab infostealer variant</strong></li><li><strong>Malware steals from 19 browsers, 32 crypto wallets, messaging apps, Steam, and Windows Credential Manager, and uniquely bypasses Chrome’s App‑Bound Encryption via code injection</strong></li><li><strong>Most repos have been removed, but some remain active; GitHub’s popularity makes it a prime target, underscoring the need to vet code before use</strong></li></ul><p>Russian actors have reportedly created hundreds of malicious GitHub repositories masquerading as legitimate software but acting as a dangerous infostealer. </p><p>Cybersecurity researchers ArcticWolf discovered the campaign after finding their own products spoofed as part of the attack.</p><p>In total, the researchers found 292 fake repositories, spoofing things like security products, developer tools, macOS utilities, games, and more. Each repository contained a README file with the download URL.</p><h2 id="obviously-malicious">Obviously malicious</h2><p>Victims who download the program get a variant of the BoryptGrab infostealer family that grabs data from 19 browsers (<a href="https://www.techradar.com/best/password-manager" target="_blank">passwords</a>, cookies, payment information), 32 cryptocurrency wallets, Telegram, Discord, and Steam sessions, credentials for Meta’s Max, data from Windows Credential Manager, and more. It can also exfiltrate files from Desktop and Documents, and grab screenshots.</p><p>While most of the features can be found in other BoryptGrab variants, this one is unique in a sense that it can bypass Chrome’s App-Bound Encryption through direct code injection into the browser process.</p><p>While it hasn’t been specifically said that the threat actors are Russian, the compressed data is later sent to a Russia-based command-and-control (C2) infrastructure.</p><p>What’s also worth mentioning is that the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> is not designed to last. It has no anti-analysis layer, and doesn’t even try to hide itself in any specific manner. It does not establish persistence and simply tries to grab as much sensitive data as it can on the first attempt.</p><p>The attack, which seems to have started in the final days of June, is almost thwarted now, since most of the malicious repositories have been removed from GitHub. Citing “researchers”, <a href="https://www.bleepingcomputer.com/news/security/nearly-300-github-repos-pose-as-legit-software-to-push-malware/" target="_blank"><em>BleepingComputer</em></a> reported that several dozen still remain active, though. </p><p>Because of its importance and popularity in the open-source community, GitHub is currently one of the most targeted platforms on the internet, which is why it’s important to double-check and vet every piece of code before it’s applied to a project.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/hundreds-of-github-repos-found-posing-as-real-software-to-push-malware</link>
                                                                            <description>
                            <![CDATA[ Russian hackers are trying to sneak infostealers onto people's devices to grab passwords, crypto, and more. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dxoB3qPWwHz8vExitx7Zed</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jul 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phone malware]]></media:description>                                                            <media:text><![CDATA[Phone malware]]></media:text>
                                <media:title type="plain"><![CDATA[Phone malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>ArcticWolf uncovered 292 malicious GitHub repositories spoofing legitimate tools and products, delivering a new BoryptGrab infostealer variant</strong></li><li><strong>Malware steals from 19 browsers, 32 crypto wallets, messaging apps, Steam, and Windows Credential Manager, and uniquely bypasses Chrome’s App‑Bound Encryption via code injection</strong></li><li><strong>Most repos have been removed, but some remain active; GitHub’s popularity makes it a prime target, underscoring the need to vet code before use</strong></li></ul><p>Russian actors have reportedly created hundreds of malicious GitHub repositories masquerading as legitimate software but acting as a dangerous infostealer. </p><p>Cybersecurity researchers ArcticWolf discovered the campaign after finding their own products spoofed as part of the attack.</p><p>In total, the researchers found 292 fake repositories, spoofing things like security products, developer tools, macOS utilities, games, and more. Each repository contained a README file with the download URL.</p><h2 id="obviously-malicious">Obviously malicious</h2><p>Victims who download the program get a variant of the BoryptGrab infostealer family that grabs data from 19 browsers (<a href="https://www.techradar.com/best/password-manager" target="_blank">passwords</a>, cookies, payment information), 32 cryptocurrency wallets, Telegram, Discord, and Steam sessions, credentials for Meta’s Max, data from Windows Credential Manager, and more. It can also exfiltrate files from Desktop and Documents, and grab screenshots.</p><p>While most of the features can be found in other BoryptGrab variants, this one is unique in a sense that it can bypass Chrome’s App-Bound Encryption through direct code injection into the browser process.</p><p>While it hasn’t been specifically said that the threat actors are Russian, the compressed data is later sent to a Russia-based command-and-control (C2) infrastructure.</p><p>What’s also worth mentioning is that the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> is not designed to last. It has no anti-analysis layer, and doesn’t even try to hide itself in any specific manner. It does not establish persistence and simply tries to grab as much sensitive data as it can on the first attempt.</p><p>The attack, which seems to have started in the final days of June, is almost thwarted now, since most of the malicious repositories have been removed from GitHub. Citing “researchers”, <a href="https://www.bleepingcomputer.com/news/security/nearly-300-github-repos-pose-as-legit-software-to-push-malware/" target="_blank"><em>BleepingComputer</em></a> reported that several dozen still remain active, though. </p><p>Because of its importance and popularity in the open-source community, GitHub is currently one of the most targeted platforms on the internet, which is why it’s important to double-check and vet every piece of code before it’s applied to a project.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How parked domains became a cybercrime goldmine ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Every day, millions of people type a web address into their browser, usually in a flurry of rapid keystrokes, and arrive exactly where they intended. </p><p>However, a small but significant number of people don’t. </p><p>They might miss a letter, type an extra letter in their haste, or get some letters mixed up. Instead of hitting linkedin[.]com, they hit linkdein[.]com. Those mistakes gave way to one of the internet’s least glamorous destinations – the parked domain.   </p><p>Most internet users have encountered them at some point, even if they didn't know what they were looking at. Typically, a parked domain would just be a sparse, messy page filled with adverts and a search bar with very little else. </p><p>They existed because someone, somewhere, recognized that in the early days of the internet a percentage of users would inevitably mistype a popular website – so they registered the most similar-looking <a href="https://www.techradar.com/news/best-domain-registrars">domain names</a> for themselves in a move known as “typosquatting” and earned advertising revenue from the resulting traffic. </p><p>If just 0.1% of the millions of people accessing amazon[.]com accidentally went to the amazn[.]com domain they’d bought, that’s still a worthwhile payday. It was a mundane corner of the digital economy, built on convenience, coincidence, and the occasional typo.</p><p>History can be a harsh teacher, but it can also sow complacency. In 2026, a lot of security teams still regard parked domains as little more than lazy digital billboards – inconvenient and annoying, but not a meaningful security concern. </p><p>However, the <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> surrounding parked domains has evolved considerably from the amateurish, pop-up-ridden advertising pages of the early internet. What was once a simple case of opportunistic domain monetization now sits inside a far more complex ecosystem of advertisers, brokers, and traffic distribution networks. </p><p>In many cases, a user's accidental visit no longer ends on a parked page at all. Instead, it triggers a journey through a chain of intermediaries operating largely out of sight. Somewhere along that journey, legitimate advertising can give way to fraud, scams, and <a href="https://www.techradar.com/best/best-malware-removal">malware</a> distribution. </p><p>In other words, one of the web's most familiar and overlooked mechanisms has become one of the most lucrative and insidious vehicles for cybercrime. </p><h2 id="from-mistype-to-malware">From Mistype to Malware </h2><p>The transformation of parked domains from digital curiosities into <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> risks has been subtle, and that’s one of the reasons it’s so dangerous. For decades, the model followed the same patterns – a user would land on a parked domain, see a collection of banners, click on something accidental or otherwise, and generate a small amount of revenue for the domain owner. </p><p>It was cynical, but at least it was transparent because users could at least see where they had ended up and decide for themselves what to do next – usually just close the tab and go where they meant to. The only real danger here came from the occasional misleading or malicious ad rather than the mechanics of the domain itself. </p><p>Today things are different. Changes within the online advertising industry, including tighter policies around traditional domain monetization, have encouraged cybercriminals and fraudsters to try new approaches to keep the train of monetization moving. </p><p>Increasingly, users who arrive at a parked domain don't encounter a parked page at all. Instead, they’re immediately redirected elsewhere through a process known as “zero-click advertising”, sometimes referred to as direct search. </p><p>What appears to be a simple typo can trigger a rapid auction in which a user's visit is bought, sold, and passed between multiple advertising partners before they ever see a destination website. Most of this activity unfolds in fractions of a second and entirely beyond the user's view, and while many of those transactions remain legitimate, the sheer complexity of the ecosystem creates opportunities for abuse. </p><p>Somewhere within that chain, traffic can be acquired by actors whose interests extend far beyond advertising revenue, opening the door to scams, malware, fraudulent software, and a host of other malicious outcomes. </p><h2 id="the-malvertising-economy">The Malvertising Economy</h2><p>One of the reasons parked domain abuse is still underestimated and difficult to pin down is that the attack path rarely follows a straight line. When most people imagine a cyberattack, they picture a malicious website waiting at the end of a link, ready to ensnare an unsuspecting user. </p><p>But in this case, by the time a user reaches the content they're ultimately shown, their traffic may have already passed through a maze of advertising exchanges, brokers, redirectors, and cloaking services. </p><p>Each participant sees only a fragment of the overall journey, making it remarkably difficult for the “good guys” to determine which “bad guys” are responsible for what. It’s a little like trying to investigate a crime scene where the evidence constantly rearranges itself.</p><p>The cowardly threat actors involved in this type of cybercrime exploit this ambiguity. They use sophisticated cloaking techniques which allow them to examine visitors before deciding which content to serve up – where are they based? What kind of browser are they using? What operating system is their device running? </p><p>A <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> researcher in California might see a harmless landing page, while a finance broker in London might be served up a credential harvesting scam. This selective delivery makes malicious activity harder to detect and even harder to reproduce. </p><p>What’s worse, parked domain abuse is rarely aimed at a specific industry or organization. The actors deploying parked domains are usually financially motivated, and their primary interest is in acquiring traffic, so they’re not going to discriminate. </p><p>Once they’ve ensnared a victim, they become a commodity moving through an invisible marketplace where every click has value and every redirection creates another opportunity for exploitation.</p><h2 id="the-blind-spot-in-traditional-security">The blind spot in traditional security</h2><p>So where does all of this leave defenders? Parked domain abuse doesn’t behave like a conventional cyber threat. While security teams are used to investigating suspicious websites, malicious files, or compromised accounts that leave a relatively obvious trail, parked domain campaigns are different because the underlying traffic distribution is constantly changing. </p><p>The same typo domain can send one user down an entirely different path than the next. By the time an analyst attempts to recreate what a victim experienced, the route may no longer exist and any “evidence” has effectively evaporated. How do they defend against something they can't see or recreate?</p><p>One thing is guaranteed – regardless of how many redirects, intermediaries, cloaking systems, or advertising platforms sit between the initial typo and the final destination, every step in the journey depends on the <a href="https://www.techradar.com/news/best-dns-server">domain name system (DNS)</a>. Often described as the internet's address book, DNS is responsible for translating domain names into the destinations users ultimately reach. </p><p>Put simply, each lookup leaves behind a breadcrumb that helps reveal relationships that would otherwise remain hidden, and that visibility has allowed researchers investigating typosquatted versions of well-known domains to follow the trail beyond the initial deception. Patterns start to emerge between seemingly unrelated cases of malware, involving the same parking providers, cloaking services, and traffic distribution infrastructure. </p><p>By examining historical DNS records and mapping the relationships between domains over time, it has become possible to connect incidents that appear to be unrelated and expose the networks operating behind them. Instead of playing “whack a mole” and chasing surface level domains, DNS mapping has allowed defenders to target the entire machine. </p><p>The greatest danger posed by parked domains isn't the typo itself, but the assumption that the infrastructure behind that typo is benign. For years, parked domains occupied a strange corner of the internet, largely ignored by security teams and rarely considered worthy of serious scrutiny. </p><p>But today, they offer cybercriminals something far more valuable than advertising revenue – access to legitimate systems, trusted business models, and vast streams of user traffic that can be manipulated and monetized at scale. </p><p>As threat actors continue to refine their use of cloaking, traffic distribution, and advertising networks, the distinction between legitimate online activity and malicious activity will become increasingly difficult to spot from the outside.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>Protect yourself against malware with the best antivirus software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/how-parked-domains-became-a-cybercrime-goldmine</link>
                                                                            <description>
                            <![CDATA[ Forgotten by security teams, parked domains have quietly become cybercrime's most lucrative hiding place. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TMRpjDCenLo2Y8LXXvpcxE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jul 2026 13:37:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dr. Renée Burton ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phone malware]]></media:description>                                                            <media:text><![CDATA[Phone malware]]></media:text>
                                <media:title type="plain"><![CDATA[Phone malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Every day, millions of people type a web address into their browser, usually in a flurry of rapid keystrokes, and arrive exactly where they intended. </p><p>However, a small but significant number of people don’t. </p><p>They might miss a letter, type an extra letter in their haste, or get some letters mixed up. Instead of hitting linkedin[.]com, they hit linkdein[.]com. Those mistakes gave way to one of the internet’s least glamorous destinations – the parked domain.   </p><p>Most internet users have encountered them at some point, even if they didn't know what they were looking at. Typically, a parked domain would just be a sparse, messy page filled with adverts and a search bar with very little else. </p><p>They existed because someone, somewhere, recognized that in the early days of the internet a percentage of users would inevitably mistype a popular website – so they registered the most similar-looking <a href="https://www.techradar.com/news/best-domain-registrars">domain names</a> for themselves in a move known as “typosquatting” and earned advertising revenue from the resulting traffic. </p><p>If just 0.1% of the millions of people accessing amazon[.]com accidentally went to the amazn[.]com domain they’d bought, that’s still a worthwhile payday. It was a mundane corner of the digital economy, built on convenience, coincidence, and the occasional typo.</p><p>History can be a harsh teacher, but it can also sow complacency. In 2026, a lot of security teams still regard parked domains as little more than lazy digital billboards – inconvenient and annoying, but not a meaningful security concern. </p><p>However, the <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> surrounding parked domains has evolved considerably from the amateurish, pop-up-ridden advertising pages of the early internet. What was once a simple case of opportunistic domain monetization now sits inside a far more complex ecosystem of advertisers, brokers, and traffic distribution networks. </p><p>In many cases, a user's accidental visit no longer ends on a parked page at all. Instead, it triggers a journey through a chain of intermediaries operating largely out of sight. Somewhere along that journey, legitimate advertising can give way to fraud, scams, and <a href="https://www.techradar.com/best/best-malware-removal">malware</a> distribution. </p><p>In other words, one of the web's most familiar and overlooked mechanisms has become one of the most lucrative and insidious vehicles for cybercrime. </p><h2 id="from-mistype-to-malware">From Mistype to Malware </h2><p>The transformation of parked domains from digital curiosities into <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> risks has been subtle, and that’s one of the reasons it’s so dangerous. For decades, the model followed the same patterns – a user would land on a parked domain, see a collection of banners, click on something accidental or otherwise, and generate a small amount of revenue for the domain owner. </p><p>It was cynical, but at least it was transparent because users could at least see where they had ended up and decide for themselves what to do next – usually just close the tab and go where they meant to. The only real danger here came from the occasional misleading or malicious ad rather than the mechanics of the domain itself. </p><p>Today things are different. Changes within the online advertising industry, including tighter policies around traditional domain monetization, have encouraged cybercriminals and fraudsters to try new approaches to keep the train of monetization moving. </p><p>Increasingly, users who arrive at a parked domain don't encounter a parked page at all. Instead, they’re immediately redirected elsewhere through a process known as “zero-click advertising”, sometimes referred to as direct search. </p><p>What appears to be a simple typo can trigger a rapid auction in which a user's visit is bought, sold, and passed between multiple advertising partners before they ever see a destination website. Most of this activity unfolds in fractions of a second and entirely beyond the user's view, and while many of those transactions remain legitimate, the sheer complexity of the ecosystem creates opportunities for abuse. </p><p>Somewhere within that chain, traffic can be acquired by actors whose interests extend far beyond advertising revenue, opening the door to scams, malware, fraudulent software, and a host of other malicious outcomes. </p><h2 id="the-malvertising-economy">The Malvertising Economy</h2><p>One of the reasons parked domain abuse is still underestimated and difficult to pin down is that the attack path rarely follows a straight line. When most people imagine a cyberattack, they picture a malicious website waiting at the end of a link, ready to ensnare an unsuspecting user. </p><p>But in this case, by the time a user reaches the content they're ultimately shown, their traffic may have already passed through a maze of advertising exchanges, brokers, redirectors, and cloaking services. </p><p>Each participant sees only a fragment of the overall journey, making it remarkably difficult for the “good guys” to determine which “bad guys” are responsible for what. It’s a little like trying to investigate a crime scene where the evidence constantly rearranges itself.</p><p>The cowardly threat actors involved in this type of cybercrime exploit this ambiguity. They use sophisticated cloaking techniques which allow them to examine visitors before deciding which content to serve up – where are they based? What kind of browser are they using? What operating system is their device running? </p><p>A <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> researcher in California might see a harmless landing page, while a finance broker in London might be served up a credential harvesting scam. This selective delivery makes malicious activity harder to detect and even harder to reproduce. </p><p>What’s worse, parked domain abuse is rarely aimed at a specific industry or organization. The actors deploying parked domains are usually financially motivated, and their primary interest is in acquiring traffic, so they’re not going to discriminate. </p><p>Once they’ve ensnared a victim, they become a commodity moving through an invisible marketplace where every click has value and every redirection creates another opportunity for exploitation.</p><h2 id="the-blind-spot-in-traditional-security">The blind spot in traditional security</h2><p>So where does all of this leave defenders? Parked domain abuse doesn’t behave like a conventional cyber threat. While security teams are used to investigating suspicious websites, malicious files, or compromised accounts that leave a relatively obvious trail, parked domain campaigns are different because the underlying traffic distribution is constantly changing. </p><p>The same typo domain can send one user down an entirely different path than the next. By the time an analyst attempts to recreate what a victim experienced, the route may no longer exist and any “evidence” has effectively evaporated. How do they defend against something they can't see or recreate?</p><p>One thing is guaranteed – regardless of how many redirects, intermediaries, cloaking systems, or advertising platforms sit between the initial typo and the final destination, every step in the journey depends on the <a href="https://www.techradar.com/news/best-dns-server">domain name system (DNS)</a>. Often described as the internet's address book, DNS is responsible for translating domain names into the destinations users ultimately reach. </p><p>Put simply, each lookup leaves behind a breadcrumb that helps reveal relationships that would otherwise remain hidden, and that visibility has allowed researchers investigating typosquatted versions of well-known domains to follow the trail beyond the initial deception. Patterns start to emerge between seemingly unrelated cases of malware, involving the same parking providers, cloaking services, and traffic distribution infrastructure. </p><p>By examining historical DNS records and mapping the relationships between domains over time, it has become possible to connect incidents that appear to be unrelated and expose the networks operating behind them. Instead of playing “whack a mole” and chasing surface level domains, DNS mapping has allowed defenders to target the entire machine. </p><p>The greatest danger posed by parked domains isn't the typo itself, but the assumption that the infrastructure behind that typo is benign. For years, parked domains occupied a strange corner of the internet, largely ignored by security teams and rarely considered worthy of serious scrutiny. </p><p>But today, they offer cybercriminals something far more valuable than advertising revenue – access to legitimate systems, trusted business models, and vast streams of user traffic that can be manipulated and monetized at scale. </p><p>As threat actors continue to refine their use of cloaking, traffic distribution, and advertising networks, the distinction between legitimate online activity and malicious activity will become increasingly difficult to spot from the outside.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>Protect yourself against malware with the best antivirus software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts get Google, Microsoft to pull trusted ModHeader with 1.6 million installs after finding it could harvest all kinds of data ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Stripe OLT found ModHeader v7.0.18 carried a hidden spyware SDK, exfiltrating visited domains daily to a Chinese‑owned server and acting as adware</strong></li><li><strong>The extension had 1.6M downloads across Chrome and Edge before being pulled but installed endpoints remain at risk</strong></li><li><strong>Researchers urge defenders to identify and remove existing installations, as removal from stores does not automatically remediate compromised devices</strong></li></ul><p>ModHeader, a trusted Chrome and Edge browser extension with more than 1.6 million downloads, was found to be malicious, apparently sending sensitive data to a Chinese-owned server, and has since been pulled on both repositories. </p><p>Security researchers Stripe OLT revealed the news in a new <a href="https://stripeolt.com/knowledge-hub/threat-research/chrome-extension-hidden-data-exfiltration-900k-users/" target="_blank">report</a>, outlining how a ModHeader build v7.0.18 carried a hidden <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">spyware</a> SDK. </p><p>As per Stripe OLT, the spyware collects domains users visit, encrypts the data with AES-GCP, and then sends it - once a day - to a remote server. The collector was found inactive by default, but the required code, encryption key, and upload schedule were all already embedded in the extension.</p><h2 id="links-to-chinese-actors">Links to Chinese actors</h2><p>Researchers found no command-and-control functionality, which means the server only receives the stolen data and cannot communicate back. The extension also worked as an adware, displaying ads and opening advertising tabs on updates, including on enterprise-managed devices.</p><p>The researchers attributed the attack, albeit with low confidence, to a Chinese-speaking threat actor. The exfiltration domain routes emails through Lark, which is a suite common with Chinese-speaking teams, it was said. They also found Chinese strings in the code, and said that the listing ships a Simplified Chinese locale. </p><p>ModHeader is a Chrome and Edge <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> extension that allows users to modify HTTP request and response headers sent between their browser and websites. Developers and security researchers use it to test APIs, troubleshoot applications, and simulate different environments. It has around 900,000 users on Chrome, and another 700,000 on Edge. </p><p>According to <a href="https://thehackernews.com/2026/07/google-and-microsoft-pull-modheader.html" target="_blank"><em>The Hacker News</em></a>, Microsoft pulled the tool from its repository on June 3 2026, followed by Google a week later, on July 10. </p><p>“Following our disclosure, Google has removed the extension from the Chrome Web Store,” Stripe OLT concluded. “We welcome this action, but removal from the store does not automatically remediate endpoints where the extension was already installed, so defenders should continue to identify and remove existing installations.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/experts-get-google-microsoft-to-pull-trusted-modheader-with-1-6-million-installs-after-finding-it-could-harvest-all-kinds-of-data</link>
                                                                            <description>
                            <![CDATA[ Visited domains were being exfiltrated to a third-party server, seemingly under a Chinese actor's control. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wBogsTgqZ6B4E5RonumGgf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/97XMVxvuGbBvxfxdd8VJqH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Jul 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/97XMVxvuGbBvxfxdd8VJqH-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Chrome, Edge, Safari, and Firefox browser apps on a mobile phone]]></media:description>                                                            <media:text><![CDATA[Chrome, Edge, Safari, and Firefox browser apps on a mobile phone]]></media:text>
                                <media:title type="plain"><![CDATA[Chrome, Edge, Safari, and Firefox browser apps on a mobile phone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/97XMVxvuGbBvxfxdd8VJqH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Stripe OLT found ModHeader v7.0.18 carried a hidden spyware SDK, exfiltrating visited domains daily to a Chinese‑owned server and acting as adware</strong></li><li><strong>The extension had 1.6M downloads across Chrome and Edge before being pulled but installed endpoints remain at risk</strong></li><li><strong>Researchers urge defenders to identify and remove existing installations, as removal from stores does not automatically remediate compromised devices</strong></li></ul><p>ModHeader, a trusted Chrome and Edge browser extension with more than 1.6 million downloads, was found to be malicious, apparently sending sensitive data to a Chinese-owned server, and has since been pulled on both repositories. </p><p>Security researchers Stripe OLT revealed the news in a new <a href="https://stripeolt.com/knowledge-hub/threat-research/chrome-extension-hidden-data-exfiltration-900k-users/" target="_blank">report</a>, outlining how a ModHeader build v7.0.18 carried a hidden <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">spyware</a> SDK. </p><p>As per Stripe OLT, the spyware collects domains users visit, encrypts the data with AES-GCP, and then sends it - once a day - to a remote server. The collector was found inactive by default, but the required code, encryption key, and upload schedule were all already embedded in the extension.</p><h2 id="links-to-chinese-actors">Links to Chinese actors</h2><p>Researchers found no command-and-control functionality, which means the server only receives the stolen data and cannot communicate back. The extension also worked as an adware, displaying ads and opening advertising tabs on updates, including on enterprise-managed devices.</p><p>The researchers attributed the attack, albeit with low confidence, to a Chinese-speaking threat actor. The exfiltration domain routes emails through Lark, which is a suite common with Chinese-speaking teams, it was said. They also found Chinese strings in the code, and said that the listing ships a Simplified Chinese locale. </p><p>ModHeader is a Chrome and Edge <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> extension that allows users to modify HTTP request and response headers sent between their browser and websites. Developers and security researchers use it to test APIs, troubleshoot applications, and simulate different environments. It has around 900,000 users on Chrome, and another 700,000 on Edge. </p><p>According to <a href="https://thehackernews.com/2026/07/google-and-microsoft-pull-modheader.html" target="_blank"><em>The Hacker News</em></a>, Microsoft pulled the tool from its repository on June 3 2026, followed by Google a week later, on July 10. </p><p>“Following our disclosure, Google has removed the extension from the Chrome Web Store,” Stripe OLT concluded. “We welcome this action, but removal from the store does not automatically remediate endpoints where the extension was already installed, so defenders should continue to identify and remove existing installations.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This new macOS infostealer poses as an Apple crash reporting tool to try and steal all your valuable data ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Jamf researchers uncover “CrashStealer,” a notarized macOS infostealer disguised as Apple’s CrashReporter</strong></li><li><strong>Distributed via a fake site called “Werkbit Setup”, it bypasses Gatekeeper, installs a LaunchAgent</strong></li><li><strong>It then uses a fake password prompt to unlock Keychain, exfiltrating credentials, cookies, files, and data from 80 crypto wallets and 14 password managers</strong></li></ul><p>A new macOS infostealer has been spotted in the wild, masquerading as an Apple crash reporting tool, experts have warned.</p><p>Called CrashStealer, this C++ infostealer was designed to nab login credentials, keychain information, as well as data related to more than 80 cryptocurrency wallets.</p><p>Cybersecurity researchers Jamf published an in-depth <a href="https://www.jamf.com/blog/crashstealer-macos-infostealer-analysis/" target="_blank">report</a> on the malware, noting CrashStealer is most likely distributed via a fake software site that was only registered recently.</p><h2 id="unlocking-keychain">Unlocking Keychain</h2><p>Victims who land on the site (either via a social media recommendation or search engine results) need to know the PIN code before initiating the download. This was most likely done to avoid analyst scrutiny, as well as to increase perceived credibility and a sense of exclusivity.</p><p>Usually, apps downloaded from third-party sources are scanned by Gatekeeper, Apple’s built-in security system. However, Jamf says that this payload is delivered via a signed and Apple-notarized installer and distributed as a disk image named “Werkbit Setup”, which allowed it to bypass Gatekeeper without any warnings.</p><p>Those that download and run the program will get a binary named ‘CrashReporter.app’, which will create a LaunchAgent (‘com.apple.crashreporter.helper’), and will see a fake macOS password prompt.</p><p>That prompt unlocks the user’s Keychain where most of their secrets are stored (passwords, private cryptographic keys, and more) and then exfiltrates all information to a third-party server. </p><p>Besides Keychain data, the CrashReporter <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> also pulls browser credentials and cookies from most browsers, data from 80 cryptocurrency wallet extensions, 14 <a href="https://www.techradar.com/best/password-manager" target="_blank">password managers</a>, locally stored files, and more. </p><p>Jamf said CrashReporter overlaps, to some extent, with other known infostealers (AMOS, for example), but is still unique enough given its client-side encryption mechanism, as well as the native C++ implementation.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/this-new-macos-infostealer-poses-as-an-apple-crash-reporting-tool-to-try-and-steal-all-your-valuable-data</link>
                                                                            <description>
                            <![CDATA[ Researchers found a new piece of macOS malware grabbing passwords, crypto data, and more. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SbwjYKP7zxrLGTEJgE6gNe</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ctJuqMRzZN6mdeA4UPgdTd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Jul 2026 14:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ctJuqMRzZN6mdeA4UPgdTd-1280-80.jpg">
                                                            <media:credit><![CDATA[Herry Sucahya on Unsplash]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The menu bar running in macOS.]]></media:description>                                                            <media:text><![CDATA[The menu bar running in macOS.]]></media:text>
                                <media:title type="plain"><![CDATA[The menu bar running in macOS.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ctJuqMRzZN6mdeA4UPgdTd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Jamf researchers uncover “CrashStealer,” a notarized macOS infostealer disguised as Apple’s CrashReporter</strong></li><li><strong>Distributed via a fake site called “Werkbit Setup”, it bypasses Gatekeeper, installs a LaunchAgent</strong></li><li><strong>It then uses a fake password prompt to unlock Keychain, exfiltrating credentials, cookies, files, and data from 80 crypto wallets and 14 password managers</strong></li></ul><p>A new macOS infostealer has been spotted in the wild, masquerading as an Apple crash reporting tool, experts have warned.</p><p>Called CrashStealer, this C++ infostealer was designed to nab login credentials, keychain information, as well as data related to more than 80 cryptocurrency wallets.</p><p>Cybersecurity researchers Jamf published an in-depth <a href="https://www.jamf.com/blog/crashstealer-macos-infostealer-analysis/" target="_blank">report</a> on the malware, noting CrashStealer is most likely distributed via a fake software site that was only registered recently.</p><h2 id="unlocking-keychain">Unlocking Keychain</h2><p>Victims who land on the site (either via a social media recommendation or search engine results) need to know the PIN code before initiating the download. This was most likely done to avoid analyst scrutiny, as well as to increase perceived credibility and a sense of exclusivity.</p><p>Usually, apps downloaded from third-party sources are scanned by Gatekeeper, Apple’s built-in security system. However, Jamf says that this payload is delivered via a signed and Apple-notarized installer and distributed as a disk image named “Werkbit Setup”, which allowed it to bypass Gatekeeper without any warnings.</p><p>Those that download and run the program will get a binary named ‘CrashReporter.app’, which will create a LaunchAgent (‘com.apple.crashreporter.helper’), and will see a fake macOS password prompt.</p><p>That prompt unlocks the user’s Keychain where most of their secrets are stored (passwords, private cryptographic keys, and more) and then exfiltrates all information to a third-party server. </p><p>Besides Keychain data, the CrashReporter <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> also pulls browser credentials and cookies from most browsers, data from 80 cryptocurrency wallet extensions, 14 <a href="https://www.techradar.com/best/password-manager" target="_blank">password managers</a>, locally stored files, and more. </p><p>Jamf said CrashReporter overlaps, to some extent, with other known infostealers (AMOS, for example), but is still unique enough given its client-side encryption mechanism, as well as the native C++ implementation.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Five reasons switching from IP VPN to SD WAN will help you build an AI-ready network ]]></title>
                                                                                                <dc:content><![CDATA[ <p>In the early 2000s, IP <a href="https://www.techradar.com/vpn/best-vpn-for-business">VPN</a> was the enterprise networking technology of choice for IT leaders. </p><p>MySpace was the go-to social network, we used Skype for video calls, we listened to music on our new MP3 players and the Nokia 1100 was the most popular mobile handset. </p><p>It feels like a different era entirely, yet many businesses are still running on legacy networks that were perfect for their needs back then but are now holding them back. </p><p>By today’s terms, networks were built for low levels of traffic. Cisco estimates global IP traffic levels were around 175 petabytes per month in 2001. Compare that to today’s figure, which is around 522,000 petabytes per month, or approximately 3000 times higher than 2001 levels, and you can understand why 87% of businesses in an Accenture study believe their legacy network is compromising their ability to advance on cloud, data and AI and digital transformation. </p><p>Untangling and replacing the complex web of enterprise networks built up over years is an unavoidable and costly necessity. It’s a bit like replacing the windows in your home - you know you’ll improve <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>, stormproof your home and cut energy costs by upgrading, but the process feels like a hassle. </p><p>Today, IT leaders aren’t just ‘replacing the windows’ by modernizing outdated networks; they’re going further and building high capacity, low latency, secure architectures designed to withstand the explosive demands of <a href="https://www.techradar.com/best/best-ai-tools">AI</a>.</p><h2 id="making-the-move-to-sd-wan">Making the move to SD WAN</h2><p>Millions of businesses are switching from IP VPN to Software-Defined Wide Area Networks, or SD WAN. Strong market growth is forecast in SD WAN, with one market forecast anticipating SD WAN CAGR of almost 40% (38.9%) from 2023 to 2030. </p><p>This growth is being driven by multiple factors including a shift to cloud-native architectures; a change in workplace practices and rise in remote working environments; and strong demand for network architectures that can manage current and future AI-related applications and services.  </p><p>SD WAN is faster, more cost effective and more secure, with built in <a href="https://www.techradar.com/best/ztna-solutions">zero trust</a> protection. It’s purpose built for distributed users and for managing cloud, AI workloads, data flows, and SaaS traffic. </p><p>But, to be truly AI ready, <a href="https://www.techradar.com/best/best-infrastructure-management-service">IT infrastructure</a> must be software driven, and this is where SD WAN excels: it gives your business the security, flexibility, and reliability needed to operate confidently in an AI driven future. Here are five ways switching to SD WAN will help you build an AI-ready network:</p><h2 id="1-built-for-ai-scale-performance">1.Built for AI-scale performance</h2><p>High-bandwidth, low latency SD WANs are critical for the delivery of AI workloads, particularly as businesses move towards AI inference. They provide fast access to <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud services</a> and dynamic bandwidth allocation as they monitor network conditions and reroute over the best available path. </p><p>For example, imagine a drive-through restaurant that uses an AI voice to take and relay orders or a supermarket that uses an AI model to scan shelves in its store, to detect gaps in stock, alert staff and predict which items will run out next. A high-performance, low latency network is essential here to guarantee a seamless <a href="https://www.techradar.com/best/cx-tools">customer experience</a>. </p><p>SD WAN’s application-aware routing levels this up even further, prioritizing AI traffic and deprioritizing the transfer of, for example, bulk file transfers or back-ups. </p><h2 id="2-security-that-matches-today-s-threat-landscape">2.Security that matches today’s threat landscape</h2><p>The global cyber attack surface has expanded dramatically. AI now plays a dual role, enabling more sophisticated attacks while also powering new, advanced defense capabilities. Traditional IP VPNs offer traffic <a href="https://www.techradar.com/best/best-encryption-software">encryption</a> but lack native security features. In contrast, SD WAN is built to protect modern networks from today’s high volume, highly sophisticated cyber threats:</p><p>- Zero trust access protects users, devices and applications</p><p>- Traffic is encrypted end to end, so that all data between sites, platforms and applications is secure</p><p>- Threat prevention at the edge protects core infrastructure from threats, with features such as intrusion detection and prevention, <a href="https://www.techradar.com/best/best-malware-removal">malware</a> scanning and <a href="https://www.techradar.com/news/best-dns-server">DNS</a> security</p><p>- Automated real-time security updates with threat intelligence pushed globally within minutes</p><h2 id="3-cloud-connectivity-without-compromise">3.Cloud connectivity without compromise</h2><p>SD WANs provide direct, optimized access to major cloud environments, such as Microsoft Azure, <a href="https://www.techradar.com/news/aws">AWS</a>, and Google Cloud, by using automated secure tunnels and intelligent path selection. </p><p>This ensures cloud and AI services run with lower latency, higher performance, and more reliable connectivity. Also important to note is that SD WANs provide high levels of autonomy and <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a>, so it’s easy to make changes quickly and easily as businesses navigate dynamic market conditions. </p><h2 id="4-data-insights-that-power-automation">4.Data insights that power automation </h2><p>SD WAN captures real-time data including latency, packet loss and application usage patterns – data which can be fed into AI-based network monitoring, automation and predictive <a href="https://www.techradar.com/best/best-maintenance-management-software">maintenance management</a> tools, so that networks become self-optimizing, self-healing and proactively secure.</p><h2 id="5-a-foundation-ready-for-sase-and-zero-trust">5.A foundation ready for SASE and Zero Trust</h2><p>When combined with Secure Access Service Edge (SASE), SD WAN creates a single, secure, high performance network foundation that’s built to drive AI opportunities while protecting against cyber risks with integrated security solutions including zero trust, secure web gateways and cloud firewalls. </p><p>SASE is a cloud based networking and security framework that combines SD WAN with integrated security services (like Zero Trust, secure web gateways, and cloud firewalls) into a single unified architecture. It’s the gold standard of AI-ready architecture.</p><p>As enterprises accelerate toward an AI driven future, the networks that once served them well are now becoming a barrier to progress. SD WAN offers a clear path forward: a software defined, secure, high performance foundation built to handle the scale, speed and complexity of modern cloud and AI workloads. </p><p>By making the shift now, businesses can replace aging infrastructure with an agile, intelligent network that not only supports today’s demands but unlocks the full potential of tomorrow’s AI innovation.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>We've ranked and reviewed the best antivirus software available</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p><h2 id=""></h2> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/five-reasons-switching-from-ip-vpn-to-sd-wan-will-help-you-build-an-ai-ready-network</link>
                                                                            <description>
                            <![CDATA[ The scale, speed and complexity of modern cloud and AI workloads demand SD WAN. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KBrWATibJQLupbVHbsHQCH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MuH6FdnCJqsnobznT3LSEM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Jul 2026 10:21:45 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Laura Farina ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MuH6FdnCJqsnobznT3LSEM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A digital representation of the globe in blue]]></media:description>                                                            <media:text><![CDATA[A digital representation of the globe in blue]]></media:text>
                                <media:title type="plain"><![CDATA[A digital representation of the globe in blue]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MuH6FdnCJqsnobznT3LSEM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In the early 2000s, IP <a href="https://www.techradar.com/vpn/best-vpn-for-business">VPN</a> was the enterprise networking technology of choice for IT leaders. </p><p>MySpace was the go-to social network, we used Skype for video calls, we listened to music on our new MP3 players and the Nokia 1100 was the most popular mobile handset. </p><p>It feels like a different era entirely, yet many businesses are still running on legacy networks that were perfect for their needs back then but are now holding them back. </p><p>By today’s terms, networks were built for low levels of traffic. Cisco estimates global IP traffic levels were around 175 petabytes per month in 2001. Compare that to today’s figure, which is around 522,000 petabytes per month, or approximately 3000 times higher than 2001 levels, and you can understand why 87% of businesses in an Accenture study believe their legacy network is compromising their ability to advance on cloud, data and AI and digital transformation. </p><p>Untangling and replacing the complex web of enterprise networks built up over years is an unavoidable and costly necessity. It’s a bit like replacing the windows in your home - you know you’ll improve <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>, stormproof your home and cut energy costs by upgrading, but the process feels like a hassle. </p><p>Today, IT leaders aren’t just ‘replacing the windows’ by modernizing outdated networks; they’re going further and building high capacity, low latency, secure architectures designed to withstand the explosive demands of <a href="https://www.techradar.com/best/best-ai-tools">AI</a>.</p><h2 id="making-the-move-to-sd-wan">Making the move to SD WAN</h2><p>Millions of businesses are switching from IP VPN to Software-Defined Wide Area Networks, or SD WAN. Strong market growth is forecast in SD WAN, with one market forecast anticipating SD WAN CAGR of almost 40% (38.9%) from 2023 to 2030. </p><p>This growth is being driven by multiple factors including a shift to cloud-native architectures; a change in workplace practices and rise in remote working environments; and strong demand for network architectures that can manage current and future AI-related applications and services.  </p><p>SD WAN is faster, more cost effective and more secure, with built in <a href="https://www.techradar.com/best/ztna-solutions">zero trust</a> protection. It’s purpose built for distributed users and for managing cloud, AI workloads, data flows, and SaaS traffic. </p><p>But, to be truly AI ready, <a href="https://www.techradar.com/best/best-infrastructure-management-service">IT infrastructure</a> must be software driven, and this is where SD WAN excels: it gives your business the security, flexibility, and reliability needed to operate confidently in an AI driven future. Here are five ways switching to SD WAN will help you build an AI-ready network:</p><h2 id="1-built-for-ai-scale-performance">1.Built for AI-scale performance</h2><p>High-bandwidth, low latency SD WANs are critical for the delivery of AI workloads, particularly as businesses move towards AI inference. They provide fast access to <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud services</a> and dynamic bandwidth allocation as they monitor network conditions and reroute over the best available path. </p><p>For example, imagine a drive-through restaurant that uses an AI voice to take and relay orders or a supermarket that uses an AI model to scan shelves in its store, to detect gaps in stock, alert staff and predict which items will run out next. A high-performance, low latency network is essential here to guarantee a seamless <a href="https://www.techradar.com/best/cx-tools">customer experience</a>. </p><p>SD WAN’s application-aware routing levels this up even further, prioritizing AI traffic and deprioritizing the transfer of, for example, bulk file transfers or back-ups. </p><h2 id="2-security-that-matches-today-s-threat-landscape">2.Security that matches today’s threat landscape</h2><p>The global cyber attack surface has expanded dramatically. AI now plays a dual role, enabling more sophisticated attacks while also powering new, advanced defense capabilities. Traditional IP VPNs offer traffic <a href="https://www.techradar.com/best/best-encryption-software">encryption</a> but lack native security features. In contrast, SD WAN is built to protect modern networks from today’s high volume, highly sophisticated cyber threats:</p><p>- Zero trust access protects users, devices and applications</p><p>- Traffic is encrypted end to end, so that all data between sites, platforms and applications is secure</p><p>- Threat prevention at the edge protects core infrastructure from threats, with features such as intrusion detection and prevention, <a href="https://www.techradar.com/best/best-malware-removal">malware</a> scanning and <a href="https://www.techradar.com/news/best-dns-server">DNS</a> security</p><p>- Automated real-time security updates with threat intelligence pushed globally within minutes</p><h2 id="3-cloud-connectivity-without-compromise">3.Cloud connectivity without compromise</h2><p>SD WANs provide direct, optimized access to major cloud environments, such as Microsoft Azure, <a href="https://www.techradar.com/news/aws">AWS</a>, and Google Cloud, by using automated secure tunnels and intelligent path selection. </p><p>This ensures cloud and AI services run with lower latency, higher performance, and more reliable connectivity. Also important to note is that SD WANs provide high levels of autonomy and <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a>, so it’s easy to make changes quickly and easily as businesses navigate dynamic market conditions. </p><h2 id="4-data-insights-that-power-automation">4.Data insights that power automation </h2><p>SD WAN captures real-time data including latency, packet loss and application usage patterns – data which can be fed into AI-based network monitoring, automation and predictive <a href="https://www.techradar.com/best/best-maintenance-management-software">maintenance management</a> tools, so that networks become self-optimizing, self-healing and proactively secure.</p><h2 id="5-a-foundation-ready-for-sase-and-zero-trust">5.A foundation ready for SASE and Zero Trust</h2><p>When combined with Secure Access Service Edge (SASE), SD WAN creates a single, secure, high performance network foundation that’s built to drive AI opportunities while protecting against cyber risks with integrated security solutions including zero trust, secure web gateways and cloud firewalls. </p><p>SASE is a cloud based networking and security framework that combines SD WAN with integrated security services (like Zero Trust, secure web gateways, and cloud firewalls) into a single unified architecture. It’s the gold standard of AI-ready architecture.</p><p>As enterprises accelerate toward an AI driven future, the networks that once served them well are now becoming a barrier to progress. SD WAN offers a clear path forward: a software defined, secure, high performance foundation built to handle the scale, speed and complexity of modern cloud and AI workloads. </p><p>By making the shift now, businesses can replace aging infrastructure with an agile, intelligent network that not only supports today’s demands but unlocks the full potential of tomorrow’s AI innovation.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>We've ranked and reviewed the best antivirus software available</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p><h2 id=""></h2>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Japan's largest taxi operator Nihon Kotsu hit by cyberattack which forces systems to be shut down ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Japan’s largest taxi operator confirms July 11 malware attack forcing shutdowns of its IT systems and disrupted dispatch and reservation services</strong></li><li><strong>Nihon Kotsu isolated networks, notified authorities, and brought in third‑party experts; customers were advised to use alternative taxi apps during the outage</strong></li><li><strong>No data leaks have been confirmed, but Nihon Kotsu warned it may disclose and notify affected parties if evidence of personal information exposure emerges</strong></li></ul><p>Japan’s largest taxi operator, Nihon Kotsu, hasconfirmed suffering a cyberattack which forced it to temporarily shut down parts of its IT infrastructure.</p><p>In a statement published on the company’s Japanese website, Nihon Kotsu said the attack took place in the early morning of July 11 - on a Saturday, when unnamed threat actors infected its devices with malware.</p><p>“We have recently discovered that our internal systems have been subjected to unauthorized external access (<a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware infection</a>),” the machine-translated statement reads. “We deeply apologize for the great inconvenience and concern caused to our customers, business partners, and all related parties due to this incident.”</p><h2 id="services-unavailable">Services unavailable</h2><p>As soon as it spotted the intrusion, Nihon Kotsu did what most companies do - shut down its network to prevent further damage, notified relevant law enforcement and data protection authorities, and brought in third-party experts to assess the damages and assist with the repairs.</p><p>The shutdown means some customer-facing services are unavailable: “As a result, the hire car web order and reservation management system, taxi dispatch service by phone, and some internal systems are temporarily unavailable,” the company said. </p><p>It advised its customers to use a different taxi app, which allows users to choose a taxi service to their liking. </p><p>So far, there is no evidence of any data exfiltration, or leaks to the dark web. However, the company did leave it as a possibility. </p><p>“At this time, no information leakage has been confirmed, but if any leakage or possibility of personal information of customers or related parties is newly discovered, we will promptly make official announcements and contact the affected parties individually in accordance with laws and regulations,” the company concluded.</p><p>Nihon Kotsu is Japan’s largest taxi operator, employing more than 18,000 people and running a fleet of more than 8,500 taxis and more than 2,000 chauffeur vehicles.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/japans-largest-taxi-operator-shuts-systems-after-cyberattack/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/japans-largest-taxi-operator-nihon-kotsu-hit-by-cyberattack-which-forces-systems-to-be-shut-down</link>
                                                                            <description>
                            <![CDATA[ Nihon Kotsu suffers malware attack, but there's no evidence of data exfiltration yet. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5vBZ3jEmoQgQq6pxgNJU6X</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JFKDCP2HdEKqSGJCkLNprB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Jul 2026 09:24:11 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JFKDCP2HdEKqSGJCkLNprB-1280-80.jpg">
                                                            <media:credit><![CDATA[Forcepint]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[IA y ciberseguridad]]></media:description>                                                            <media:text><![CDATA[IA y ciberseguridad]]></media:text>
                                <media:title type="plain"><![CDATA[IA y ciberseguridad]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JFKDCP2HdEKqSGJCkLNprB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Japan’s largest taxi operator confirms July 11 malware attack forcing shutdowns of its IT systems and disrupted dispatch and reservation services</strong></li><li><strong>Nihon Kotsu isolated networks, notified authorities, and brought in third‑party experts; customers were advised to use alternative taxi apps during the outage</strong></li><li><strong>No data leaks have been confirmed, but Nihon Kotsu warned it may disclose and notify affected parties if evidence of personal information exposure emerges</strong></li></ul><p>Japan’s largest taxi operator, Nihon Kotsu, hasconfirmed suffering a cyberattack which forced it to temporarily shut down parts of its IT infrastructure.</p><p>In a statement published on the company’s Japanese website, Nihon Kotsu said the attack took place in the early morning of July 11 - on a Saturday, when unnamed threat actors infected its devices with malware.</p><p>“We have recently discovered that our internal systems have been subjected to unauthorized external access (<a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware infection</a>),” the machine-translated statement reads. “We deeply apologize for the great inconvenience and concern caused to our customers, business partners, and all related parties due to this incident.”</p><h2 id="services-unavailable">Services unavailable</h2><p>As soon as it spotted the intrusion, Nihon Kotsu did what most companies do - shut down its network to prevent further damage, notified relevant law enforcement and data protection authorities, and brought in third-party experts to assess the damages and assist with the repairs.</p><p>The shutdown means some customer-facing services are unavailable: “As a result, the hire car web order and reservation management system, taxi dispatch service by phone, and some internal systems are temporarily unavailable,” the company said. </p><p>It advised its customers to use a different taxi app, which allows users to choose a taxi service to their liking. </p><p>So far, there is no evidence of any data exfiltration, or leaks to the dark web. However, the company did leave it as a possibility. </p><p>“At this time, no information leakage has been confirmed, but if any leakage or possibility of personal information of customers or related parties is newly discovered, we will promptly make official announcements and contact the affected parties individually in accordance with laws and regulations,” the company concluded.</p><p>Nihon Kotsu is Japan’s largest taxi operator, employing more than 18,000 people and running a fleet of more than 8,500 taxis and more than 2,000 chauffeur vehicles.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/japans-largest-taxi-operator-shuts-systems-after-cyberattack/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The new rules of software supply chain security: visibility, vigilance, validation ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The global digital economy runs on a thriving ecosystem of third-party vendors, enabling organizations to scale and innovate faster than they possibly could do on their own. </p><p>This digital ecosystem is teeming with software suppliers, not just <a href="https://www.techradar.com/best/best-small-business-software">business software</a> that you can buy but also a vast array of software libraries that are embedded in third-party products. </p><p>Speed, however, can sometimes be the enemy of risk, as many organizations have not adequately validated whether these third-party technologies are sufficiently safeguarded against cyber threats and other digital risk. </p><p>So, while software is a great enabler, it also brings risk, given that it often is built with frameworks and libraries that are not known or well supported. </p><p>Consider that companies employ an average of 106 SaaS apps within their IT environments , and the picture becomes quite clear: software supply chain security is a serious concern. </p><p>It’s no wonder that half (51%) of participants in the latest Supply Chain Risk Survey ranked software vulnerabilities in supplier products as the most disruptive <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> threat to their organization’s supply chain, behind only data breaches (64%) and <a href="https://www.techradar.com/best/best-malware-removal">malware</a> or <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a> (52%).</p><p>An ever-changing attack surface that comprises <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud services</a>, micro-services, APIs, SaaS platforms, third‑party services and now AI agents has expanded well beyond what once was an understood perimeter before widespread digital transformation took hold. </p><p>How secure is your own extended digital ecosystem? If this question makes your heart race, then take a closer look at three key considerations for addressing software supply chain security.</p><h2 id="1-visibility-determine-what-s-actually-in-your-multi-layered-supply-chain">1. Visibility: Determine what’s actually in your multi-layered supply chain</h2><p>Since the software supply chain is part of a vast, interconnected digital ecosystem, organizations likely do not have full visibility of what and who make up their third-party providers. Recent high-profile incidents have signaled just how fragile supply chains can be. </p><p>Assuring business continuity requires organizations to scrutinize partners before placing such deep trust in them. That effort starts with knowing who is in your interconnected digital ecosystem before you can start to manage the risk. </p><p>Understanding risk across a supply chain is conceptually easy, but it is practically difficult. While clearly outlining security parameters and requirements in supplier contracts is a great starting point, it is not enough, as contracting is generally a point-in-time activity and should be paired with monitoring. You must be able to see and measure <a href="https://www.techradar.com/best/best-software-asset-management-tools">software assets</a> so you can better manage them. </p><p>After all, you can’t protect what you can’t see, and many businesses still don’t have a complete, accurate asset inventory, meaning that their vulnerability exposure is incomplete. If you don’t know what systems, apps, devices and libraries are in your environment, vulnerability management is supposition, inference and guesswork. </p><p>It is crucial to understand what your suppliers are doing both upstream and who you supply downstream, because their decisions are now part of your organization’s own risk profile. Software often presents the biggest blind spots in asset management, thanks in large part to a lack transparency in software build and dependencies, shadow IT, shadow AI and unmanaged endpoints. </p><p>An organization's exposure is tied directly to the security posture of every supplier they rely on. Attackers know this, increasingly targeting upstream or downstream partners. You can secure your own environment perfectly and still be vulnerable through others’ oversight. Tools that can profile, quantify and score risk across the supply chain, therefore, are essential, as is tooling that monitors for unusual activity.</p><h2 id="2-vigilance-prioritize-the-security-of-ai-integrations-across-your-software-supply-chain">2. Vigilance: Prioritize the security of AI integrations across your software supply chain</h2><p>Threats can lurk anywhere and everywhere across your supply chain. But there’s a new kid in town: AI. The software supply chain has expanded to include the unique risks of AI ecosystem, such as reliance on external foundational models and highly connected agents. </p><p>This escalating integration of <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> makes the multi-faceted software supply chain even more of a concern. Cybersecurity professionals who participated in the latest Cybersecurity Workforce Study  revealed a troubling AI-related security event their organization experienced in that prior year: data poisoning (cited by 11%). </p><p>Data poisoning happens when bad actors intentionally insert corrupted, misleading or malicious data into the training dataset of a machine-learning model. Even a small amount of poisoned data can change the model’s behavior, in turn resulting in misclassifications, degraded accuracy or malicious outcomes. So suddenly that seemingly helpful <a href="https://www.techradar.com/pro/best-ai-chatbot-for-business">ChatBot</a> that is embedded in your <a href="https://www.techradar.com/best/the-best-crm-software">CRM</a>, <a href="https://www.techradar.com/best/cms">CMS</a> or other purpose-driven enterprise software may not be so friendly after all!</p><p>Indeed, organizations simply have little / no control over the software that suppliers are using, making it much more difficult to ensure vulnerabilities are identified before widespread rollout, as well as supported and patched once deployed, but they do have control over scrutinizing suppliers. </p><p>Therefore, the people on your <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> team and the processes they follow matter more than ever. Technology accelerates both sides of the fight, so your real advantage comes from having skilled practitioners who understand how AI changes your risk profile, attack surface and can put the right controls in place to compensate. </p><p>Cybersecurity professionals who specialize in software supply chain security can quantify the risk of model poisoning / steering, prompt injection and model inversion, and assess the inherent bias of pre-trained open-source models, protecting the integrity of software and services from upstream vulnerabilities. Such a holistic approach ensures that every component, from third-party libraries to the training data itself, meets the organization’s security and ethical standards.</p><p>In addition, reviewing and evaluating vendor agreements is an important task for cybersecurity teams and stakeholders. Think of these disciplined actions as a necessary stress-test meant to identify and address weaknesses and changing needs. A good contract with clear deliverables and expectations is part of a cybersecurity defensive strategy alongside your people and your defense technologies and ongoing monitoring of systems and services.</p><h2 id="3-validation-adopt-skills-frameworks-and-codes-of-practice-for-software-supply-chain-security">3. Validation: Adopt skills frameworks and codes of practice for software supply chain security</h2><p>No organization must stand up against the heightened threat of software supply chain security alone. Take advantage of existing guidance such as the U.K.’s Software Security Code of Practice to follow when you’re trying to batten the software hatches at your own organization. </p><p>Not only does this code support software vendors as they adopt secure software lifecycle development practices; it also supports software customers in mitigating the likelihood and impact of software supply chain attacks.</p><p>In addition to following code and other guidance frameworks, organizations can look to skills frameworks and vendor-neutral certifications to validate that their cybersecurity professionals demonstrate certain skills needed to build and strengthen supply chain security and resilience. </p><p>Skills development in the disciplines of governance, risk and compliance (GRC), secure software development and AI skills better enable cybersecurity and risk professionals to make informed decisions regarding software supply chain security and risk management. </p><h2 id="from-complexity-to-better-security">From complexity to better security</h2><p>Supply chains are complex, longer than you think and multidimensional. Organizations must place much greater focus on stress-testing the resilience of software suppliers and continuously evaluating exposure. </p><p>This approach goes well beyond being careful about what software makes it all the way to procurement. The potentially more damaging layer to address in the macro supply chain involves the embedded software and integrated AI tools that other suppliers are using.</p><p>The question is not whether your digital supply chain will face disruption. It's whether you have the visibility, vigilance and validation to operate when it does. That’s resilience: the north star of software supply chain security. Without question, transparency has to run through supply chains instead of just sitting inside organizations.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've rounded up the best endpoint protection software suites</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/the-new-rules-of-software-supply-chain-security-visibility-vigilance-validation</link>
                                                                            <description>
                            <![CDATA[ Software supply chain security is fast becoming a business-critical priority. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">c8Dxf5VhTRoXfkMpwcVx5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Jul 2026 08:56:46 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jon France ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:description>                                                            <media:text><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:text>
                                <media:title type="plain"><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The global digital economy runs on a thriving ecosystem of third-party vendors, enabling organizations to scale and innovate faster than they possibly could do on their own. </p><p>This digital ecosystem is teeming with software suppliers, not just <a href="https://www.techradar.com/best/best-small-business-software">business software</a> that you can buy but also a vast array of software libraries that are embedded in third-party products. </p><p>Speed, however, can sometimes be the enemy of risk, as many organizations have not adequately validated whether these third-party technologies are sufficiently safeguarded against cyber threats and other digital risk. </p><p>So, while software is a great enabler, it also brings risk, given that it often is built with frameworks and libraries that are not known or well supported. </p><p>Consider that companies employ an average of 106 SaaS apps within their IT environments , and the picture becomes quite clear: software supply chain security is a serious concern. </p><p>It’s no wonder that half (51%) of participants in the latest Supply Chain Risk Survey ranked software vulnerabilities in supplier products as the most disruptive <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> threat to their organization’s supply chain, behind only data breaches (64%) and <a href="https://www.techradar.com/best/best-malware-removal">malware</a> or <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a> (52%).</p><p>An ever-changing attack surface that comprises <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud services</a>, micro-services, APIs, SaaS platforms, third‑party services and now AI agents has expanded well beyond what once was an understood perimeter before widespread digital transformation took hold. </p><p>How secure is your own extended digital ecosystem? If this question makes your heart race, then take a closer look at three key considerations for addressing software supply chain security.</p><h2 id="1-visibility-determine-what-s-actually-in-your-multi-layered-supply-chain">1. Visibility: Determine what’s actually in your multi-layered supply chain</h2><p>Since the software supply chain is part of a vast, interconnected digital ecosystem, organizations likely do not have full visibility of what and who make up their third-party providers. Recent high-profile incidents have signaled just how fragile supply chains can be. </p><p>Assuring business continuity requires organizations to scrutinize partners before placing such deep trust in them. That effort starts with knowing who is in your interconnected digital ecosystem before you can start to manage the risk. </p><p>Understanding risk across a supply chain is conceptually easy, but it is practically difficult. While clearly outlining security parameters and requirements in supplier contracts is a great starting point, it is not enough, as contracting is generally a point-in-time activity and should be paired with monitoring. You must be able to see and measure <a href="https://www.techradar.com/best/best-software-asset-management-tools">software assets</a> so you can better manage them. </p><p>After all, you can’t protect what you can’t see, and many businesses still don’t have a complete, accurate asset inventory, meaning that their vulnerability exposure is incomplete. If you don’t know what systems, apps, devices and libraries are in your environment, vulnerability management is supposition, inference and guesswork. </p><p>It is crucial to understand what your suppliers are doing both upstream and who you supply downstream, because their decisions are now part of your organization’s own risk profile. Software often presents the biggest blind spots in asset management, thanks in large part to a lack transparency in software build and dependencies, shadow IT, shadow AI and unmanaged endpoints. </p><p>An organization's exposure is tied directly to the security posture of every supplier they rely on. Attackers know this, increasingly targeting upstream or downstream partners. You can secure your own environment perfectly and still be vulnerable through others’ oversight. Tools that can profile, quantify and score risk across the supply chain, therefore, are essential, as is tooling that monitors for unusual activity.</p><h2 id="2-vigilance-prioritize-the-security-of-ai-integrations-across-your-software-supply-chain">2. Vigilance: Prioritize the security of AI integrations across your software supply chain</h2><p>Threats can lurk anywhere and everywhere across your supply chain. But there’s a new kid in town: AI. The software supply chain has expanded to include the unique risks of AI ecosystem, such as reliance on external foundational models and highly connected agents. </p><p>This escalating integration of <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> makes the multi-faceted software supply chain even more of a concern. Cybersecurity professionals who participated in the latest Cybersecurity Workforce Study  revealed a troubling AI-related security event their organization experienced in that prior year: data poisoning (cited by 11%). </p><p>Data poisoning happens when bad actors intentionally insert corrupted, misleading or malicious data into the training dataset of a machine-learning model. Even a small amount of poisoned data can change the model’s behavior, in turn resulting in misclassifications, degraded accuracy or malicious outcomes. So suddenly that seemingly helpful <a href="https://www.techradar.com/pro/best-ai-chatbot-for-business">ChatBot</a> that is embedded in your <a href="https://www.techradar.com/best/the-best-crm-software">CRM</a>, <a href="https://www.techradar.com/best/cms">CMS</a> or other purpose-driven enterprise software may not be so friendly after all!</p><p>Indeed, organizations simply have little / no control over the software that suppliers are using, making it much more difficult to ensure vulnerabilities are identified before widespread rollout, as well as supported and patched once deployed, but they do have control over scrutinizing suppliers. </p><p>Therefore, the people on your <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> team and the processes they follow matter more than ever. Technology accelerates both sides of the fight, so your real advantage comes from having skilled practitioners who understand how AI changes your risk profile, attack surface and can put the right controls in place to compensate. </p><p>Cybersecurity professionals who specialize in software supply chain security can quantify the risk of model poisoning / steering, prompt injection and model inversion, and assess the inherent bias of pre-trained open-source models, protecting the integrity of software and services from upstream vulnerabilities. Such a holistic approach ensures that every component, from third-party libraries to the training data itself, meets the organization’s security and ethical standards.</p><p>In addition, reviewing and evaluating vendor agreements is an important task for cybersecurity teams and stakeholders. Think of these disciplined actions as a necessary stress-test meant to identify and address weaknesses and changing needs. A good contract with clear deliverables and expectations is part of a cybersecurity defensive strategy alongside your people and your defense technologies and ongoing monitoring of systems and services.</p><h2 id="3-validation-adopt-skills-frameworks-and-codes-of-practice-for-software-supply-chain-security">3. Validation: Adopt skills frameworks and codes of practice for software supply chain security</h2><p>No organization must stand up against the heightened threat of software supply chain security alone. Take advantage of existing guidance such as the U.K.’s Software Security Code of Practice to follow when you’re trying to batten the software hatches at your own organization. </p><p>Not only does this code support software vendors as they adopt secure software lifecycle development practices; it also supports software customers in mitigating the likelihood and impact of software supply chain attacks.</p><p>In addition to following code and other guidance frameworks, organizations can look to skills frameworks and vendor-neutral certifications to validate that their cybersecurity professionals demonstrate certain skills needed to build and strengthen supply chain security and resilience. </p><p>Skills development in the disciplines of governance, risk and compliance (GRC), secure software development and AI skills better enable cybersecurity and risk professionals to make informed decisions regarding software supply chain security and risk management. </p><h2 id="from-complexity-to-better-security">From complexity to better security</h2><p>Supply chains are complex, longer than you think and multidimensional. Organizations must place much greater focus on stress-testing the resilience of software suppliers and continuously evaluating exposure. </p><p>This approach goes well beyond being careful about what software makes it all the way to procurement. The potentially more damaging layer to address in the macro supply chain involves the embedded software and integrated AI tools that other suppliers are using.</p><p>The question is not whether your digital supply chain will face disruption. It's whether you have the visibility, vigilance and validation to operate when it does. That’s resilience: the north star of software supply chain security. Without question, transparency has to run through supply chains instead of just sitting inside organizations.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've rounded up the best endpoint protection software suites</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Vibe coded threats shift again — hackers are using AI chatbots to write malware using natural language ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Huntress analyzed AI‑generated malware “Untitled1.ps1,” a noisy custom AD enumeration tool likely built by low‑skilled attackers using generative AI</strong></li><li><strong>Attackers paired it with s5cmd for rapid data exfiltration and SharpShares.exe for share enumeration before being detected and removed</strong></li><li><strong>Report warns AI “vibe coding” lowers barriers for cybercrime, producing unique payloads that evade signature‑based defenses, requiring behavioral analytics to catch attack lifecycles</strong></li></ul><p>“Unsophisticated” cybercriminals can now easily write malicious code using Artificial Intelligence (AI) and run devastating data breach attacks with speed, forcing defenders to rethink their strategies, researchers have claimed. </p><p>Security experts Huntress thoroughly investigating a piece of AI-written <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, and <a href="https://www.huntress.com/blog/ai-coded-malware-vibe-coding-active-directory" target="_blank">explained</a> how the bespoke, AI-generated payload was a “highly aggressive, noisy, custom-built AD enumeration tool.”</p><p>Since cybercriminals are generally careful not to make too much noise and to try and do their bidding without raising any alarms, the researchers hint this was the work of a low-skilled attacker.</p><h2 id="significant-challenge">Significant challenge</h2><p>The malware, labeled Untitled1.ps1, was designed to map the Active Directory environment and apparently, it did its job well. In the next step, the crooks deployed a legitimate high-speed command-line tool for Amazon S3 operations called s5cmd which, according to Huntress, is often used for data exfiltration.</p><p>Before being spotted and kicked out, the attackers also deployed a known enumeration tool called SharpShares.exe, filtering common administrative shares while hunting for further user-accessible data repositories. </p><p>The move from off-the-shelf frameworks to custom, bespoke AI tools is a “significant challenge” for the defenders, Huntress warns. </p><p>“Historically, AVs and EDR platforms have relied heavily on file hashes and static string signatures,” they say. “Vibe-coded scripts are inherently unique. Untitled1.ps1 has never existed before and will likely never be compiled in this exact configuration again.”</p><p>As a result, defenders must focus on the “fundamental behaviors of the attack lifecycle.” AI can change the code syntax, they’re saying, but cannot change the underlying mechanics of <a href="https://www.techradar.com/pro/best-active-directory-documentation-tool-of-year" target="_blank">Active Directory</a> enumeration. </p><p>“Vibe coding lowers the barrier to entry for cybercrime, allowing unsophisticated actors to generate highly capable, evasive tooling on the fly,” the researchers concluded. “While the code itself may be messy, over-engineered, and filled with AI hallmarks like left-behind comments, the threat it poses is very real. To combat this, defenders must abandon rigid, signature-based thinking and embrace behavioral analytics to catch the underlying actions that no LLM can hide.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/vibe-coded-threats-shift-again-hackers-are-using-ai-chatbots-to-write-malware-using-natural-language</link>
                                                                            <description>
                            <![CDATA[ How do you spot an attack when signatures and behaviors can no longer be used? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7FaiGdV8mykwMcDLSkT3n9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/G8QNviZt3KrDbfWVANJrNM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 13 Jul 2026 15:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/G8QNviZt3KrDbfWVANJrNM-1280-80.jpg">
                                                            <media:credit><![CDATA[Elchinator from Pixabay ]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[malware]]></media:description>                                                            <media:text><![CDATA[malware]]></media:text>
                                <media:title type="plain"><![CDATA[malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/G8QNviZt3KrDbfWVANJrNM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Huntress analyzed AI‑generated malware “Untitled1.ps1,” a noisy custom AD enumeration tool likely built by low‑skilled attackers using generative AI</strong></li><li><strong>Attackers paired it with s5cmd for rapid data exfiltration and SharpShares.exe for share enumeration before being detected and removed</strong></li><li><strong>Report warns AI “vibe coding” lowers barriers for cybercrime, producing unique payloads that evade signature‑based defenses, requiring behavioral analytics to catch attack lifecycles</strong></li></ul><p>“Unsophisticated” cybercriminals can now easily write malicious code using Artificial Intelligence (AI) and run devastating data breach attacks with speed, forcing defenders to rethink their strategies, researchers have claimed. </p><p>Security experts Huntress thoroughly investigating a piece of AI-written <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, and <a href="https://www.huntress.com/blog/ai-coded-malware-vibe-coding-active-directory" target="_blank">explained</a> how the bespoke, AI-generated payload was a “highly aggressive, noisy, custom-built AD enumeration tool.”</p><p>Since cybercriminals are generally careful not to make too much noise and to try and do their bidding without raising any alarms, the researchers hint this was the work of a low-skilled attacker.</p><h2 id="significant-challenge">Significant challenge</h2><p>The malware, labeled Untitled1.ps1, was designed to map the Active Directory environment and apparently, it did its job well. In the next step, the crooks deployed a legitimate high-speed command-line tool for Amazon S3 operations called s5cmd which, according to Huntress, is often used for data exfiltration.</p><p>Before being spotted and kicked out, the attackers also deployed a known enumeration tool called SharpShares.exe, filtering common administrative shares while hunting for further user-accessible data repositories. </p><p>The move from off-the-shelf frameworks to custom, bespoke AI tools is a “significant challenge” for the defenders, Huntress warns. </p><p>“Historically, AVs and EDR platforms have relied heavily on file hashes and static string signatures,” they say. “Vibe-coded scripts are inherently unique. Untitled1.ps1 has never existed before and will likely never be compiled in this exact configuration again.”</p><p>As a result, defenders must focus on the “fundamental behaviors of the attack lifecycle.” AI can change the code syntax, they’re saying, but cannot change the underlying mechanics of <a href="https://www.techradar.com/pro/best-active-directory-documentation-tool-of-year" target="_blank">Active Directory</a> enumeration. </p><p>“Vibe coding lowers the barrier to entry for cybercrime, allowing unsophisticated actors to generate highly capable, evasive tooling on the fly,” the researchers concluded. “While the code itself may be messy, over-engineered, and filled with AI hallmarks like left-behind comments, the threat it poses is very real. To combat this, defenders must abandon rigid, signature-based thinking and embrace behavioral analytics to catch the underlying actions that no LLM can hide.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft discovers new multi-malware package 'GigaWiper' capable of deploying wipers and ransomware ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft warns of “GigaWiper,” a destructive malware attributed to Iranian group CyberAv3ngers that combines multiple variants into one</strong></li><li><strong>It can wipe drives, encrypt files with a fake ransomware extension, or overwrite Windows partitions, while also spying via screenshots, VNC sessions, and system data theft</strong></li><li><strong>The malware hides under fake OneDrive tasks and registry keys, showing both espionage and sabotage capabilities with no recovery path for victims’ data</strong></li></ul><p>Microsoft is warning about a new piece of malware called GigaWiper, which can spy on people’s computers and then destroy them entirely, in different ways.</p><p>It was built by mashing different <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> variants into one, and it seems to be the work of Iranian state-sponsored threat actors called CyberAv3ngers. The hackers also took a little cheeky dig at Microsoft, through the malware’s obfuscation mechanism.</p><p>As Microsoft <a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="nofollow">explained</a>, GigaWiper can overwrite the physical drive and wipe the partition table, destroying the contents of the disk directly. It can also encrypt all files on the drive, add a .candy extension, and change the desktop wallpaper to show a warning. This ransomware approach does not share a ransom note, and does not generate a decryption key, so there is nothing to pay, and no way to decrypt the files - they are gone for good, just giving victims false hope.</p><h2 id="spying-on-the-victims">Spying on the victims</h2><p>Finally, the third method goes straight for the Windows drive, overwriting it multiple times with different data patterns. </p><p>Besides bricking the disk, GigaWiper can also spy on its victims by grabbing screenshots, recording the screen, or opening a VNC session to either stream someone else’s work, or allow the attackers to use the mouse and keyboard. The malware can also extract system data, manage programs and services, modify the registry, and more. </p><p>But the cheekiest feature is how it hides. It schedules a task called OneDrive Update and tracks itself in a registry key called OneDrive\Environment. Perhaps the attackers assumed no one really pays attention to <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">OneDrive</a>, and thus the malware could stay out of sight for longer. </p><p>Speaking of the attackers, Microsoft does not name them, but most of the components mashed together to form GigaWiper were previously attributed to CyberAv3ngers, a group linked to Iran's Islamic Revolutionary Guard Corps.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/microsoft-discovers-new-multi-malware-package-gigawiper-capable-of-deploying-wipers-and-ransomware</link>
                                                                            <description>
                            <![CDATA[ One wiper can destroy a computer in different ways, but it can also spy on users. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6JU6gwuxmJ5p8jKNCQnPq5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Jul 2026 16:50:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[hacker hands at work with  interface around]]></media:description>                                                            <media:text><![CDATA[hacker hands at work with  interface around]]></media:text>
                                <media:title type="plain"><![CDATA[hacker hands at work with  interface around]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft warns of “GigaWiper,” a destructive malware attributed to Iranian group CyberAv3ngers that combines multiple variants into one</strong></li><li><strong>It can wipe drives, encrypt files with a fake ransomware extension, or overwrite Windows partitions, while also spying via screenshots, VNC sessions, and system data theft</strong></li><li><strong>The malware hides under fake OneDrive tasks and registry keys, showing both espionage and sabotage capabilities with no recovery path for victims’ data</strong></li></ul><p>Microsoft is warning about a new piece of malware called GigaWiper, which can spy on people’s computers and then destroy them entirely, in different ways.</p><p>It was built by mashing different <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> variants into one, and it seems to be the work of Iranian state-sponsored threat actors called CyberAv3ngers. The hackers also took a little cheeky dig at Microsoft, through the malware’s obfuscation mechanism.</p><p>As Microsoft <a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="nofollow">explained</a>, GigaWiper can overwrite the physical drive and wipe the partition table, destroying the contents of the disk directly. It can also encrypt all files on the drive, add a .candy extension, and change the desktop wallpaper to show a warning. This ransomware approach does not share a ransom note, and does not generate a decryption key, so there is nothing to pay, and no way to decrypt the files - they are gone for good, just giving victims false hope.</p><h2 id="spying-on-the-victims">Spying on the victims</h2><p>Finally, the third method goes straight for the Windows drive, overwriting it multiple times with different data patterns. </p><p>Besides bricking the disk, GigaWiper can also spy on its victims by grabbing screenshots, recording the screen, or opening a VNC session to either stream someone else’s work, or allow the attackers to use the mouse and keyboard. The malware can also extract system data, manage programs and services, modify the registry, and more. </p><p>But the cheekiest feature is how it hides. It schedules a task called OneDrive Update and tracks itself in a registry key called OneDrive\Environment. Perhaps the attackers assumed no one really pays attention to <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">OneDrive</a>, and thus the malware could stay out of sight for longer. </p><p>Speaking of the attackers, Microsoft does not name them, but most of the components mashed together to form GigaWiper were previously attributed to CyberAv3ngers, a group linked to Iran's Islamic Revolutionary Guard Corps.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This malicious Google Notes extension just wants to sneakily steal all your crypto ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>McAfee flags “Silent Swap,” a malicious Chromium extension disguised as Google Notes that secretly hijacks crypto transactions</strong></li><li><strong>It works as a clipboard jacker, swapping copied wallet addresses with attacker‑controlled ones so victims unknowingly send funds to criminals</strong></li><li><strong>Researchers advise always cross‑checking full wallet strings before sending, as attackers can craft lookalike addresses differing only in a few characters</strong></li></ul><p>Researchers have found yet another extension for Chromium-based browsers that is designed solely to steal people’s hard-earned cryptocurrency.</p><p>A <a href="https://www.mcafee.com/blogs/other-blogs/mcafee-labs/crypto-clipper-wallet-swapping-browser-extension-malware/" target="_blank" rel="nofollow">report</a> from McAfee has sounded the alarm on Silent Swap, a piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> hiding inside a benign-looking Google Notes extension.</p><p>Victims who stumble upon and download it (most likely through phishing, social engineering, or shady forums and websites), will get an extension that, on the surface, works as intended. It shows a small window where the victim can type a note and save it. They can color-code the notes and search through saved ones. However, this was only made to hide the program’s true intentions, which are to steal cryptocurrency.</p><h2 id="hijacking-the-clipboard">Hijacking the clipboard</h2><p>Silent Swap works like a typical clipboard jacker. It monitors the clipboard for strings that look like a <a href="https://www.techradar.com/news/best-bitcoin-wallets" target="_blank">crypto wallet</a> - seemingly random strings of 26 to 42 alphanumeric characters. </p><p>When it spots one, it replaces it with a different one belonging to the attacker, so when the victim pastes the address into the wallet to send the funds, they are actually sending them to the address belonging to the attackers.</p><p>This works because crypto wallets are almost impossible to memorize, and too risky to type in from a piece of paper or a different document, forcing users to rely on copying and pasting. </p><p>Once the victim sends the funds, they are almost certainly irretrievably gone. Only if the funds are being sent from a centralized exchange (like Coinbase, for example), and if the victim spots the attack fast enough, can they ask the exchange’s support to freeze the transaction. In all other cases, once the money is sent, it’s gone.</p><p>The best way to defend against these attacks is to cross-reference the strings before hitting send. Some people would only check the first and last few characters, but security researchers don’t recommend it, because some clipboard jackers can generate addresses that only differ in a few characters.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/this-malicious-google-notes-extension-just-wants-to-sneakily-steal-all-your-crypto</link>
                                                                            <description>
                            <![CDATA[ Another clipboard jacker was found in the wild, on the prowl for people's crypto. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TgqEFku9ZNa9fNUkZbYTj9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VnoVVXTmAmxSBYBe4LUwVW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Jul 2026 11:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VnoVVXTmAmxSBYBe4LUwVW-1280-80.jpg">
                                                            <media:credit><![CDATA[vjkombajn/Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image credit: Pixabay/vjkombajn]]></media:description>                                                            <media:text><![CDATA[Cryptocurrencies]]></media:text>
                                <media:title type="plain"><![CDATA[Cryptocurrencies]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VnoVVXTmAmxSBYBe4LUwVW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>McAfee flags “Silent Swap,” a malicious Chromium extension disguised as Google Notes that secretly hijacks crypto transactions</strong></li><li><strong>It works as a clipboard jacker, swapping copied wallet addresses with attacker‑controlled ones so victims unknowingly send funds to criminals</strong></li><li><strong>Researchers advise always cross‑checking full wallet strings before sending, as attackers can craft lookalike addresses differing only in a few characters</strong></li></ul><p>Researchers have found yet another extension for Chromium-based browsers that is designed solely to steal people’s hard-earned cryptocurrency.</p><p>A <a href="https://www.mcafee.com/blogs/other-blogs/mcafee-labs/crypto-clipper-wallet-swapping-browser-extension-malware/" target="_blank" rel="nofollow">report</a> from McAfee has sounded the alarm on Silent Swap, a piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> hiding inside a benign-looking Google Notes extension.</p><p>Victims who stumble upon and download it (most likely through phishing, social engineering, or shady forums and websites), will get an extension that, on the surface, works as intended. It shows a small window where the victim can type a note and save it. They can color-code the notes and search through saved ones. However, this was only made to hide the program’s true intentions, which are to steal cryptocurrency.</p><h2 id="hijacking-the-clipboard">Hijacking the clipboard</h2><p>Silent Swap works like a typical clipboard jacker. It monitors the clipboard for strings that look like a <a href="https://www.techradar.com/news/best-bitcoin-wallets" target="_blank">crypto wallet</a> - seemingly random strings of 26 to 42 alphanumeric characters. </p><p>When it spots one, it replaces it with a different one belonging to the attacker, so when the victim pastes the address into the wallet to send the funds, they are actually sending them to the address belonging to the attackers.</p><p>This works because crypto wallets are almost impossible to memorize, and too risky to type in from a piece of paper or a different document, forcing users to rely on copying and pasting. </p><p>Once the victim sends the funds, they are almost certainly irretrievably gone. Only if the funds are being sent from a centralized exchange (like Coinbase, for example), and if the victim spots the attack fast enough, can they ask the exchange’s support to freeze the transaction. In all other cases, once the money is sent, it’s gone.</p><p>The best way to defend against these attacks is to cross-reference the strings before hitting send. Some people would only check the first and last few characters, but security researchers don’t recommend it, because some clipboard jackers can generate addresses that only differ in a few characters.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How AI is taking IoT security to the next level ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The IoT and <a href="https://www.techradar.com/best/best-ai-tools">AI</a> are a likely partnership: IoT generates and captures data, often in large volume, AI is ideally placed to analyze it. </p><p>Combined, AIoT presents new opportunities, so much so that Transforma Insights forecasts no fewer than 9.1 billion AIoT connections at the end of 2033, a more than six-fold increase in 10 years. </p><p></p><p>The potential for AI in the IoT is far-reaching, and one standout application is enhanced security.</p><h2 id="the-security-risk-to-the-iot">The security risk to the IoT </h2><p>All connected devices are under growing levels of threat, but the IoT is particularly targeted. According to Beaming’s cyberthreat report into UK businesses, IoT devices were most frequently attacked in 2024. They are attractive targets for the data they exchange and their potential to be compromised. </p><p>The devices are often unmanned and generally sit outside corporate <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> perimeters. They may be in remote spots, where they could be subject to unauthorized physical access attempts, and often remain in place for long periods of time. Many, such as the IoT devices used in energy, transport, utilities and retail, transfer sensitive data of high value. </p><p>Businesses need confidence that data collected through the IoT—both real-time and historical—comes from secure and trusted sources, not least when it comes to developing and training AI models. In this, the IoT works with digital twins, which are digital representations of physical objects or systems. </p><p>The IoT enables the seamless flow of real-world data between the physical and the digital, while the digital twin’s attributes provide the features for AI modelling. Historical data collected through IoT is then used to train and refine the AI model. </p><h2 id="how-ai-is-helping-secure-the-iot">How AI is helping secure the IoT</h2><p>AI applies its <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a> and analytical capabilities to many tasks and priorities. It is making inroads into cybersecurity, something that has not gone unnoticed. Last year, the IEEE revealed almost half of the global technology leaders it surveyed (47%) expect vulnerability identification and attack prevention to be a top use of AI in 2026. </p><p>That may be some comfort to enterprises and connectivity and solutions providers grappling with the problem of protecting IoT devices and applications. This challenge is compounded by the fact that attackers are increasingly using AI themselves to automate phishing, accelerate reconnaissance and develop adaptive <a href="https://www.techradar.com/best/best-malware-removal">malware</a> that evades traditional detection. However, it is more comforting still, that AI is already making a difference in the IoT, redefining how organizations protect their devices. </p><p>AI-powered anomaly and threat detection (ATD) is helping security teams identify threats like suspicious network traffic and botnet activity faster and improving resilience across large-scale IoT environments, something enterprises must strive for. </p><p>In the recent past, the focus on the IoT was arguably getting devices online. That is no longer the challenge; the test now is keeping them operational: compliance readiness and the flexibility to adapt to ever-evolving commercial and technological changes. It also means maintaining resilience. </p><p>IoT security must follow a clear defend against, detect and react approach to swiftly counter attacks. No one or two of these three measures are enough without the others. </p><h2 id="how-ai-improves-iot-visibility-and-incident-response">How AI improves IoT visibility and incident response</h2><p>AI-powered ATD detects anomalous behavior, such as remote code execution, abnormal port connection or a suspicious IP. These could indicate the beginnings of a cyberattack on an IoT device. It analyses the anomaly and can identify the attack type, be it distributed denial of service (<a href="https://www.techradar.com/news/best-ddos-protection">DDoS</a>), man-in-the-middle (MiTM) or an attempted device takeover. </p><p>ATD can then trigger direct action, if business rules dictate an automated response. This could take the form of threat isolation or referring the incident for full review. </p><h2 id="anomaly-and-threat-detection-protects-over-one-million-devices">Anomaly and threat detection protects over one million devices</h2><p>ATD runs entirely in the mobile core network infrastructure, rather than through software agents on a device, so it can be retrofitted to existing systems.</p><p>Enterprises that have identified IP backdoors and Mirai botnet infections within hours. </p><p>With IP backdoors, ATD detects unusual outbound connections, or traffic, to suspicious IPs. Such backdoors may allow remote control or data exfiltration, both of which leave identifiable behavioral traces.</p><p>In the case of Mirai, anomalous behavior typically exhibits as spikes in outbound traffic, uncommon ports use, or repetitive scanning of external IPs. ATD can flag these irregularities in real time and trigger corrective actions, such as blocking or quarantining the device, blocking or throttling traffic or patching firmware.</p><h2 id="automation-and-analytics-can-shape-the-next-phase-of-iot-security">Automation and analytics can shape the next phase of IoT security</h2><p>There is a clear shift in IoT implementation and management. It is insufficient to plan for device deployment, sit back and gather the data. Without a strategy that accounts for the stresses, threats and changes that beset IoT estates, enterprises risk costly surprises like unplanned site visits and service disruptions. </p><p>AI, through automation and analytics, can shape the next phase of IoT security. Enterprises that detect, analyze and even automatically address, anomalous activity reduce the risk of cyberattack-related outages and inconvenient site visits to access devices. </p><p>Sending field technicians to maintain or repair devices can add significantly to total cost of ownership. Each truck roll, which incurs expenses for labor, fuel, vehicle wear and often missed <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a> opportunities, can add up to over $1000 per site visit. </p><p>IoT downtime, meanwhile disrupts operations and can have a catastrophic reputational, as well as financial, cost. </p><h2 id="how-to-balance-innovation-data-privacy-and-operational-control">How to balance innovation, data privacy and operational control</h2><p>Enterprises are, for the most part, keen to innovate through AI but have understandable questions about data privacy and operational control. </p><p>It is important to know what AI does, in all process integrations, to understand why it does it and to have control that prevents AI deviating from its purpose.</p><p>On data privacy, ATD isn’t installed on IoT devices. Only packet headers from device <a href="https://www.techradar.com/best/best-cloud-storage">cloud</a> communications are mirrored from the mobile core to the ATD engine, with threat levels and AI-driven insights relayed through a customer portal. </p><p>Operational control is maintained through the business rules that dictate how the ATD engine reacts. The option to refer an anomaly for review, for example, gives enterprises the flexibility to incorporate human oversight, under predetermined circumstances. </p><p>This is especially useful when you consider there can be genuine reasons why a SIM may increase or cease communication, that an incident reviewer will understand.</p><h2 id="ai-powered-iot-security">AI-powered IoT security </h2><p>AI is making a difference to the speed, efficiency and depth of response to cyberthreats. Automation and advanced analytics within IoT solutions’ security measures also help enterprises manage costs, by minimizing labor-intensive manual tasks and site visits, and reducing the risk of expensive cyberattack reparations. </p><p>For CISOs, CIOs, product and operations managers seeking to maximize IoT value and protect their enterprise IT domains from external threats, AI-powered ATD offers visibility and actionable insights to take IoT security to the next level.</p><p><a href="https://www.techradar.com/best/best-antivirus"><em>We've reviewed and ranked the best antivirus software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/how-ai-is-taking-iot-security-to-the-next-level</link>
                                                                            <description>
                            <![CDATA[ AI is redefining how organizations protect and manage connected devices. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BwU5d5Knz43h6RHYPL7LC3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/euoWA3SymQA2cKKjmF37W4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Jul 2026 10:28:27 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Iain Davidson ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/euoWA3SymQA2cKKjmF37W4-1280-80.jpg">
                                                            <media:credit><![CDATA[The Register]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wi-Fi]]></media:description>                                                            <media:text><![CDATA[Wi-Fi]]></media:text>
                                <media:title type="plain"><![CDATA[Wi-Fi]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/euoWA3SymQA2cKKjmF37W4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The IoT and <a href="https://www.techradar.com/best/best-ai-tools">AI</a> are a likely partnership: IoT generates and captures data, often in large volume, AI is ideally placed to analyze it. </p><p>Combined, AIoT presents new opportunities, so much so that Transforma Insights forecasts no fewer than 9.1 billion AIoT connections at the end of 2033, a more than six-fold increase in 10 years. </p><p></p><p>The potential for AI in the IoT is far-reaching, and one standout application is enhanced security.</p><h2 id="the-security-risk-to-the-iot">The security risk to the IoT </h2><p>All connected devices are under growing levels of threat, but the IoT is particularly targeted. According to Beaming’s cyberthreat report into UK businesses, IoT devices were most frequently attacked in 2024. They are attractive targets for the data they exchange and their potential to be compromised. </p><p>The devices are often unmanned and generally sit outside corporate <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> perimeters. They may be in remote spots, where they could be subject to unauthorized physical access attempts, and often remain in place for long periods of time. Many, such as the IoT devices used in energy, transport, utilities and retail, transfer sensitive data of high value. </p><p>Businesses need confidence that data collected through the IoT—both real-time and historical—comes from secure and trusted sources, not least when it comes to developing and training AI models. In this, the IoT works with digital twins, which are digital representations of physical objects or systems. </p><p>The IoT enables the seamless flow of real-world data between the physical and the digital, while the digital twin’s attributes provide the features for AI modelling. Historical data collected through IoT is then used to train and refine the AI model. </p><h2 id="how-ai-is-helping-secure-the-iot">How AI is helping secure the IoT</h2><p>AI applies its <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a> and analytical capabilities to many tasks and priorities. It is making inroads into cybersecurity, something that has not gone unnoticed. Last year, the IEEE revealed almost half of the global technology leaders it surveyed (47%) expect vulnerability identification and attack prevention to be a top use of AI in 2026. </p><p>That may be some comfort to enterprises and connectivity and solutions providers grappling with the problem of protecting IoT devices and applications. This challenge is compounded by the fact that attackers are increasingly using AI themselves to automate phishing, accelerate reconnaissance and develop adaptive <a href="https://www.techradar.com/best/best-malware-removal">malware</a> that evades traditional detection. However, it is more comforting still, that AI is already making a difference in the IoT, redefining how organizations protect their devices. </p><p>AI-powered anomaly and threat detection (ATD) is helping security teams identify threats like suspicious network traffic and botnet activity faster and improving resilience across large-scale IoT environments, something enterprises must strive for. </p><p>In the recent past, the focus on the IoT was arguably getting devices online. That is no longer the challenge; the test now is keeping them operational: compliance readiness and the flexibility to adapt to ever-evolving commercial and technological changes. It also means maintaining resilience. </p><p>IoT security must follow a clear defend against, detect and react approach to swiftly counter attacks. No one or two of these three measures are enough without the others. </p><h2 id="how-ai-improves-iot-visibility-and-incident-response">How AI improves IoT visibility and incident response</h2><p>AI-powered ATD detects anomalous behavior, such as remote code execution, abnormal port connection or a suspicious IP. These could indicate the beginnings of a cyberattack on an IoT device. It analyses the anomaly and can identify the attack type, be it distributed denial of service (<a href="https://www.techradar.com/news/best-ddos-protection">DDoS</a>), man-in-the-middle (MiTM) or an attempted device takeover. </p><p>ATD can then trigger direct action, if business rules dictate an automated response. This could take the form of threat isolation or referring the incident for full review. </p><h2 id="anomaly-and-threat-detection-protects-over-one-million-devices">Anomaly and threat detection protects over one million devices</h2><p>ATD runs entirely in the mobile core network infrastructure, rather than through software agents on a device, so it can be retrofitted to existing systems.</p><p>Enterprises that have identified IP backdoors and Mirai botnet infections within hours. </p><p>With IP backdoors, ATD detects unusual outbound connections, or traffic, to suspicious IPs. Such backdoors may allow remote control or data exfiltration, both of which leave identifiable behavioral traces.</p><p>In the case of Mirai, anomalous behavior typically exhibits as spikes in outbound traffic, uncommon ports use, or repetitive scanning of external IPs. ATD can flag these irregularities in real time and trigger corrective actions, such as blocking or quarantining the device, blocking or throttling traffic or patching firmware.</p><h2 id="automation-and-analytics-can-shape-the-next-phase-of-iot-security">Automation and analytics can shape the next phase of IoT security</h2><p>There is a clear shift in IoT implementation and management. It is insufficient to plan for device deployment, sit back and gather the data. Without a strategy that accounts for the stresses, threats and changes that beset IoT estates, enterprises risk costly surprises like unplanned site visits and service disruptions. </p><p>AI, through automation and analytics, can shape the next phase of IoT security. Enterprises that detect, analyze and even automatically address, anomalous activity reduce the risk of cyberattack-related outages and inconvenient site visits to access devices. </p><p>Sending field technicians to maintain or repair devices can add significantly to total cost of ownership. Each truck roll, which incurs expenses for labor, fuel, vehicle wear and often missed <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a> opportunities, can add up to over $1000 per site visit. </p><p>IoT downtime, meanwhile disrupts operations and can have a catastrophic reputational, as well as financial, cost. </p><h2 id="how-to-balance-innovation-data-privacy-and-operational-control">How to balance innovation, data privacy and operational control</h2><p>Enterprises are, for the most part, keen to innovate through AI but have understandable questions about data privacy and operational control. </p><p>It is important to know what AI does, in all process integrations, to understand why it does it and to have control that prevents AI deviating from its purpose.</p><p>On data privacy, ATD isn’t installed on IoT devices. Only packet headers from device <a href="https://www.techradar.com/best/best-cloud-storage">cloud</a> communications are mirrored from the mobile core to the ATD engine, with threat levels and AI-driven insights relayed through a customer portal. </p><p>Operational control is maintained through the business rules that dictate how the ATD engine reacts. The option to refer an anomaly for review, for example, gives enterprises the flexibility to incorporate human oversight, under predetermined circumstances. </p><p>This is especially useful when you consider there can be genuine reasons why a SIM may increase or cease communication, that an incident reviewer will understand.</p><h2 id="ai-powered-iot-security">AI-powered IoT security </h2><p>AI is making a difference to the speed, efficiency and depth of response to cyberthreats. Automation and advanced analytics within IoT solutions’ security measures also help enterprises manage costs, by minimizing labor-intensive manual tasks and site visits, and reducing the risk of expensive cyberattack reparations. </p><p>For CISOs, CIOs, product and operations managers seeking to maximize IoT value and protect their enterprise IT domains from external threats, AI-powered ATD offers visibility and actionable insights to take IoT security to the next level.</p><p><a href="https://www.techradar.com/best/best-antivirus"><em>We've reviewed and ranked the best antivirus software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ MacPaw Moonlock antivirus review ]]></title>
                                                                                                <dc:content><![CDATA[ <p>MacPaw has spent years building a reputation as one of the most design-conscious developers in the Mac ecosystem. Its flagship product, <a href="https://www.techradar.com/reviews/cleanmymac-x-for-mac-review" target="_blank">CleanMyMac</a>, has long included a malware removal module powered by Moonlock's engine. In October 2025, the Kyiv-based company spun that security technology into a standalone product: Moonlock, a full-featured antivirus app that goes well beyond a simple scanner.</p><p>Rather than leading with threat counts and detection percentages, Moonlock frames itself as security software that treats users like adults, explaining what malware is, why it matters, and what to do next, instead of firing off opaque alerts. The marketing centers on a 'care, not scare' approach, essentially promising to educate you rather than just bombarding you with red-text alerts.</p><p>While many live in the mythical belief that Macs are immune to viruses, <a href="https://moonlock.com/2025-macos-threat-report" target="_blank">MacPaw's own research</a> reports that 66 percent of Mac users encountered at least one cyber threat last year, with a 67% increase in registered macOS backdoor variants in 2025. The research shows a key message: macOS is not immune, are users are being targeted more frequently than ever.</p><h3 class="article-body__section" id="section-plans-and-pricing"><span>Plans and pricing</span></h3><p>Moonlock starts at $54 per year for a single Mac, with licenses available for 2, 5, or more than 10 devices per subscription. Monthly billing and one-time lifetime license options are also available for those who prefer not to commit to an annual cycle.</p><p>Discounts of up to 67 percent are advertised on multi-year plans, which is worth exploring if you intend to stick with the product long term.</p><p>New users get a seven-day free trial, though a credit card is required to start. That is a common enough practice, but it does mean you will need to remember to cancel if the product does not suit you. To soften the blow of that annual fee, Moonlock offers a 30-day money-back guarantee, which is a considerably more generous safety net than the case-by-case refund process offered by some competitors.</p><p>Current Setapp subscribers get access to Moonlock at no additional charge, which may be the most compelling value proposition for those already in MacPaw's subscription ecosystem. At $54 per year for a single device, standalone pricing lands considerably higher than ClamXAV's three-Mac Home plan at $29.95, a gap worth weighing if budget is a primary concern.</p><h3 class="article-body__section" id="section-features"><span>Features</span></h3><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2624px;"><p class="vanilla-image-block" style="padding-top:63.41%;"><img id="5KepRLD9rYrfaLqHs4edTZ" name="moonlock-scan" alt="A screenshot of a MacPaw Moonlock scan" src="https://cdn.mos.cms.futurecdn.net/5KepRLD9rYrfaLqHs4edTZ.jpg" mos="" align="middle" fullscreen="" width="2624" height="1664" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Moonlock)</span></figcaption></figure><p>Moonlock is organized into six sections: Home, Malware Scanner, VPN, Network Inspector, System Protection, and Security Advisor. That framework reflects a deliberate decision to bundle a security suite rather than deliver a focused antivirus, giving the product a notably broader footprint than Mac-only rivals like ClamXAV.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2624px;"><p class="vanilla-image-block" style="padding-top:66.31%;"><img id="Z7hkDirscjtHPz8KP3X67Q" name="moonlock-malware-scanner" alt="A screenshot of the MacPaw Moonlock malware scanner in action" src="https://cdn.mos.cms.futurecdn.net/Z7hkDirscjtHPz8KP3X67Q.jpg" mos="" align="middle" fullscreen="" width="2624" height="1740" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Moonlock)</span></figcaption></figure><p>Real-time protection runs continuously in the background, monitoring file activity, app behavior, and Mail attachments even when the main application window is closed. The Malware Scanner supports on-demand and scheduled scans, with built-in quarantine and removal tools. Detected threats are accompanied by plain-language explanations rather than raw file paths and specialized terms.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2624px;"><p class="vanilla-image-block" style="padding-top:66.31%;"><img id="ZTwnWuF8rVzcFgSx7DrkdU" name="moonlock-vpn" alt="A screenshot of the MacPaw Moonlock VPN in action" src="https://cdn.mos.cms.futurecdn.net/ZTwnWuF8rVzcFgSx7DrkdU.jpg" mos="" align="middle" fullscreen="" width="2624" height="1740" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Moonlock)</span></figcaption></figure><p>The bundled VPN is a simplified version of MacPaw's ClearVPN, covering around 60 server locations across more than 45 countries. Independent testing found no DNS or WebRTC leaks, and MacPaw maintains a no-logging policy. Speed retention is strong, holding around 82 percent of baseline download speeds on transatlantic connections and up to 96 percent on closer servers.</p><p>Network Inspector adds a country-level connection blocker, permitting users to block outbound traffic to specific regions. System Protection audits macOS's own built-in security settings and walks you through any gaps. Finally, Security Advisor provides a checklist for basic digital hygiene, including practical guidance on habits such as two-factor authentication and app permissions. AI assists with malware classification on the backend, helping the team update threat databases before new strains reach your device.</p><h3 class="article-body__section" id="section-privacy-and-security"><span>Privacy and Security</span></h3><p>From a top level perspective, Moonlock was tested by the third-party laboratory AV-Test in September 2025 and earned it's AV-Test certification. It scored a 5.5/6 in Protection, 4.5/6 in Performance, and a full 6/6 for Usability (which I'll dive into in the next section).</p><p>As for the credibility of the underlying research arm, Moonlock Lab has made several notable contributions to the antivirus landscape, being the first to identify PyStealer on VirusTotal, and the lab has also been cited by the SANS Institute for discovering new variants of the Atomic macOS infostealer.</p><p>Regarding privacy, the VPN operates under a strict zero-logs policy, and all data is processed locally. MacPaw publishes a Trust Center at security.macpaw.com describing its data-handling practices, certifications, and security standards, which is a nice change in transparency from many other antivirus providers.</p><p>The one caveat worth noting is that Moonlock is a recent standalone launch. While the underlying engine has been in use in CleanMyMac for some time, the app itself has a limited history as an independently tested product. But it is worth noting that in the time since the last time AV-Test handled Moonlock, MacPaw have likely taken steps to improve protection and performance.</p><h3 class="article-body__section" id="section-interface-and-in-use"><span>Interface and in use</span></h3><p>The interface is highly polished, modern, and immediately legible, with a two-panel home dashboard that separates tasks on the left from status information on the right. Everything is where you would expect it to be, and the visual hierarchy makes it easy to tell at a glance whether your Mac is protected. </p><p>Instead of a generic 'Threat Resolved' notification, Moonlock tells you what was found, why it poses a risk, and what your options are. I found I was the one to make the final call on whether to remove a flagged item, which sidesteps the infuriating experience of automated deletion that occasionally catches legitimate software.</p><p>The system requirements make it suitable for older devices too, requiring macOS 13 or later and 515MB of disk space. The app runs quickly and, in day-to-day use, does not noticeably drag on performance. Installation requires a MacPaw account, which adds a step that competitors like ClamXAV skip entirely for home users, but the tradeoff is a unified login for managing licenses and accessing support.</p><p>Ultimately, Moonlock is a great option for those looking for an accessible and easily navigable Mac antivirus that doesn't bombard you with any overly-technical language, and performs as though you are the one in control.</p><h3 class="article-body__section" id="section-support"><span>Support</span></h3><p>Moonlock support runs on MacPaw's established infrastructure, with a dedicated knowledge base that covers installation, configuration, and troubleshooting, and those with questions can submit immediate inquiries through the support portal. In-app feedback is also available via the Help menu.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2624px;"><p class="vanilla-image-block" style="padding-top:63.41%;"><img id="Poe8caHraKyHPdShHYkJug" name="moonlock-security-advisor" alt="A screenshot of the Moonlock security advisor in action" src="https://cdn.mos.cms.futurecdn.net/Poe8caHraKyHPdShHYkJug.jpg" mos="" align="middle" fullscreen="" width="2624" height="1664" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Moonlock)</span></figcaption></figure><p>As with many Mac-focused security products, live chat or phone support does not appear to be offered as a standard option. For most home users, the knowledge base and email channel will be sufficient. Teams with more complicated environments should verify support response times before committing, particularly given that Moonlock is a relatively new standalone product and the support documentation is still maturing.</p><h3 class="article-body__section" id="section-the-competition"><span>The competition</span></h3><p>ClamXAV is the most direct rival in the Mac-exclusive antivirus space. At $29.95 per year for three devices, it is considerably cheaper than Moonlock's $54 single-device starting price, and it also holds a perfect AV-Test score compared to Moonlock's test results. It does not include a VPN, network inspection, or the polished onboarding experience Moonlock offers, but for those who want focused antivirus protection at a lower cost, it is a strong option.</p><p><a href="https://www.techradar.com/pro/intego-mac-internet-security-x9-review" target="_blank">Intego Mac Internet Security X9</a> sits at a comparable price point and includes a network monitor, with a longer track record in independent third-party testing. Bitdefender Total Security and Norton AntiVirus Plus both offer wider platform coverage and larger feature sets, making them better fits for households with mixed Windows and Mac devices.</p><p>Those who are already subscribed to CleanMyMac should also note that its built-in malware-scanning module, powered by the same Moonlock engine, continues to function independently. Therefore the question is whether the full Moonlock standalone app adds enough to justify an additional subscription or an upgrade in spending.</p><h2 id="final-verdict">Final verdict</h2><p>Moonlock is one of the most carefully designed security apps I've encountered in the Mac ecosystem. Its interface is excellent, its feature set is broader than most Mac-specific alternatives, and the research team behind it is doing genuinely credible original work. The 30-day money-back guarantee is also a nice addition, despite the need to enter your payment details first.</p><p>At $54 per year for a single Mac, it costs nearly twice as much as ClamXAV's three-device plan. The added value of the bundled VPN and Network Inspector goes some way toward justifying that gap, but those who already have a VPN solution elsewhere may not find the extras compelling enough. Setapp subscribers, on the other hand, get all of this for free as part of a subscription they likely already value.</p><p>For long-standing CleanMyMac users who already benefit from the embedded Moonlock engine, the standalone app offers greater depth, visibility, and control, but it's not a replacement for anything missing. It is a fuller version of the protection they have already been relying on, now with a VPN, richer reporting, and a proper home for the security features that were previously contained within a Mac cleaning utility.</p><p>For Mac users who want a single subscription that covers antivirus, VPN, network monitoring, and system security guidance, Moonlock makes a strong argument. Just go in aware of what you are paying for relative to the alternatives.</p><p><em>You might also be interested in our report on </em><a href="https://www.techradar.com/news/software/applications/30-best-mac-apps-for-just-about-everything-712511"><em>the best Mac apps of the year</em></a><em>.</em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/computing/macs/macpaw-moonlock-antivirus-review</link>
                                                                            <description>
                            <![CDATA[ Moonlock is a relatively new arrival to the Mac antivirus scene, but offers excellent usability and won't hinder the performance of older Macs. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VeqiGPVbAQdSwFCBLk4FdC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QM9hJkWMMHyFDBLSPEBhmG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 06 Jul 2026 13:32:19 +0000</pubDate>                                                                                                                                <updated>Mon, 06 Jul 2026 13:34:33 +0000</updated>
                                                                                                                                            <category><![CDATA[Macs]]></category>
                                                    <category><![CDATA[macOS]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Desktop PCs]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ bryan.wolfe@futurenet.com (Bryan M Wolfe) ]]></author>                    <dc:creator><![CDATA[ Bryan M Wolfe ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsbij4rP7NWfEAnN3HdV87.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                        <dc:contributor><![CDATA[ Benedict Collins ]]></dc:contributor>
                                                                    <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QM9hJkWMMHyFDBLSPEBhmG-1280-80.jpg">
                                                            <media:credit><![CDATA[Moonlock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A screenshot of the MacPaw Moonlock dashboard]]></media:description>                                                            <media:text><![CDATA[A screenshot of the MacPaw Moonlock dashboard]]></media:text>
                                <media:title type="plain"><![CDATA[A screenshot of the MacPaw Moonlock dashboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QM9hJkWMMHyFDBLSPEBhmG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>MacPaw has spent years building a reputation as one of the most design-conscious developers in the Mac ecosystem. Its flagship product, <a href="https://www.techradar.com/reviews/cleanmymac-x-for-mac-review" target="_blank">CleanMyMac</a>, has long included a malware removal module powered by Moonlock's engine. In October 2025, the Kyiv-based company spun that security technology into a standalone product: Moonlock, a full-featured antivirus app that goes well beyond a simple scanner.</p><p>Rather than leading with threat counts and detection percentages, Moonlock frames itself as security software that treats users like adults, explaining what malware is, why it matters, and what to do next, instead of firing off opaque alerts. The marketing centers on a 'care, not scare' approach, essentially promising to educate you rather than just bombarding you with red-text alerts.</p><p>While many live in the mythical belief that Macs are immune to viruses, <a href="https://moonlock.com/2025-macos-threat-report" target="_blank">MacPaw's own research</a> reports that 66 percent of Mac users encountered at least one cyber threat last year, with a 67% increase in registered macOS backdoor variants in 2025. The research shows a key message: macOS is not immune, are users are being targeted more frequently than ever.</p><h3 class="article-body__section" id="section-plans-and-pricing"><span>Plans and pricing</span></h3><p>Moonlock starts at $54 per year for a single Mac, with licenses available for 2, 5, or more than 10 devices per subscription. Monthly billing and one-time lifetime license options are also available for those who prefer not to commit to an annual cycle.</p><p>Discounts of up to 67 percent are advertised on multi-year plans, which is worth exploring if you intend to stick with the product long term.</p><p>New users get a seven-day free trial, though a credit card is required to start. That is a common enough practice, but it does mean you will need to remember to cancel if the product does not suit you. To soften the blow of that annual fee, Moonlock offers a 30-day money-back guarantee, which is a considerably more generous safety net than the case-by-case refund process offered by some competitors.</p><p>Current Setapp subscribers get access to Moonlock at no additional charge, which may be the most compelling value proposition for those already in MacPaw's subscription ecosystem. At $54 per year for a single device, standalone pricing lands considerably higher than ClamXAV's three-Mac Home plan at $29.95, a gap worth weighing if budget is a primary concern.</p><h3 class="article-body__section" id="section-features"><span>Features</span></h3><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2624px;"><p class="vanilla-image-block" style="padding-top:63.41%;"><img id="5KepRLD9rYrfaLqHs4edTZ" name="moonlock-scan" alt="A screenshot of a MacPaw Moonlock scan" src="https://cdn.mos.cms.futurecdn.net/5KepRLD9rYrfaLqHs4edTZ.jpg" mos="" align="middle" fullscreen="" width="2624" height="1664" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Moonlock)</span></figcaption></figure><p>Moonlock is organized into six sections: Home, Malware Scanner, VPN, Network Inspector, System Protection, and Security Advisor. That framework reflects a deliberate decision to bundle a security suite rather than deliver a focused antivirus, giving the product a notably broader footprint than Mac-only rivals like ClamXAV.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2624px;"><p class="vanilla-image-block" style="padding-top:66.31%;"><img id="Z7hkDirscjtHPz8KP3X67Q" name="moonlock-malware-scanner" alt="A screenshot of the MacPaw Moonlock malware scanner in action" src="https://cdn.mos.cms.futurecdn.net/Z7hkDirscjtHPz8KP3X67Q.jpg" mos="" align="middle" fullscreen="" width="2624" height="1740" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Moonlock)</span></figcaption></figure><p>Real-time protection runs continuously in the background, monitoring file activity, app behavior, and Mail attachments even when the main application window is closed. The Malware Scanner supports on-demand and scheduled scans, with built-in quarantine and removal tools. Detected threats are accompanied by plain-language explanations rather than raw file paths and specialized terms.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2624px;"><p class="vanilla-image-block" style="padding-top:66.31%;"><img id="ZTwnWuF8rVzcFgSx7DrkdU" name="moonlock-vpn" alt="A screenshot of the MacPaw Moonlock VPN in action" src="https://cdn.mos.cms.futurecdn.net/ZTwnWuF8rVzcFgSx7DrkdU.jpg" mos="" align="middle" fullscreen="" width="2624" height="1740" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Moonlock)</span></figcaption></figure><p>The bundled VPN is a simplified version of MacPaw's ClearVPN, covering around 60 server locations across more than 45 countries. Independent testing found no DNS or WebRTC leaks, and MacPaw maintains a no-logging policy. Speed retention is strong, holding around 82 percent of baseline download speeds on transatlantic connections and up to 96 percent on closer servers.</p><p>Network Inspector adds a country-level connection blocker, permitting users to block outbound traffic to specific regions. System Protection audits macOS's own built-in security settings and walks you through any gaps. Finally, Security Advisor provides a checklist for basic digital hygiene, including practical guidance on habits such as two-factor authentication and app permissions. AI assists with malware classification on the backend, helping the team update threat databases before new strains reach your device.</p><h3 class="article-body__section" id="section-privacy-and-security"><span>Privacy and Security</span></h3><p>From a top level perspective, Moonlock was tested by the third-party laboratory AV-Test in September 2025 and earned it's AV-Test certification. It scored a 5.5/6 in Protection, 4.5/6 in Performance, and a full 6/6 for Usability (which I'll dive into in the next section).</p><p>As for the credibility of the underlying research arm, Moonlock Lab has made several notable contributions to the antivirus landscape, being the first to identify PyStealer on VirusTotal, and the lab has also been cited by the SANS Institute for discovering new variants of the Atomic macOS infostealer.</p><p>Regarding privacy, the VPN operates under a strict zero-logs policy, and all data is processed locally. MacPaw publishes a Trust Center at security.macpaw.com describing its data-handling practices, certifications, and security standards, which is a nice change in transparency from many other antivirus providers.</p><p>The one caveat worth noting is that Moonlock is a recent standalone launch. While the underlying engine has been in use in CleanMyMac for some time, the app itself has a limited history as an independently tested product. But it is worth noting that in the time since the last time AV-Test handled Moonlock, MacPaw have likely taken steps to improve protection and performance.</p><h3 class="article-body__section" id="section-interface-and-in-use"><span>Interface and in use</span></h3><p>The interface is highly polished, modern, and immediately legible, with a two-panel home dashboard that separates tasks on the left from status information on the right. Everything is where you would expect it to be, and the visual hierarchy makes it easy to tell at a glance whether your Mac is protected. </p><p>Instead of a generic 'Threat Resolved' notification, Moonlock tells you what was found, why it poses a risk, and what your options are. I found I was the one to make the final call on whether to remove a flagged item, which sidesteps the infuriating experience of automated deletion that occasionally catches legitimate software.</p><p>The system requirements make it suitable for older devices too, requiring macOS 13 or later and 515MB of disk space. The app runs quickly and, in day-to-day use, does not noticeably drag on performance. Installation requires a MacPaw account, which adds a step that competitors like ClamXAV skip entirely for home users, but the tradeoff is a unified login for managing licenses and accessing support.</p><p>Ultimately, Moonlock is a great option for those looking for an accessible and easily navigable Mac antivirus that doesn't bombard you with any overly-technical language, and performs as though you are the one in control.</p><h3 class="article-body__section" id="section-support"><span>Support</span></h3><p>Moonlock support runs on MacPaw's established infrastructure, with a dedicated knowledge base that covers installation, configuration, and troubleshooting, and those with questions can submit immediate inquiries through the support portal. In-app feedback is also available via the Help menu.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2624px;"><p class="vanilla-image-block" style="padding-top:63.41%;"><img id="Poe8caHraKyHPdShHYkJug" name="moonlock-security-advisor" alt="A screenshot of the Moonlock security advisor in action" src="https://cdn.mos.cms.futurecdn.net/Poe8caHraKyHPdShHYkJug.jpg" mos="" align="middle" fullscreen="" width="2624" height="1664" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Moonlock)</span></figcaption></figure><p>As with many Mac-focused security products, live chat or phone support does not appear to be offered as a standard option. For most home users, the knowledge base and email channel will be sufficient. Teams with more complicated environments should verify support response times before committing, particularly given that Moonlock is a relatively new standalone product and the support documentation is still maturing.</p><h3 class="article-body__section" id="section-the-competition"><span>The competition</span></h3><p>ClamXAV is the most direct rival in the Mac-exclusive antivirus space. At $29.95 per year for three devices, it is considerably cheaper than Moonlock's $54 single-device starting price, and it also holds a perfect AV-Test score compared to Moonlock's test results. It does not include a VPN, network inspection, or the polished onboarding experience Moonlock offers, but for those who want focused antivirus protection at a lower cost, it is a strong option.</p><p><a href="https://www.techradar.com/pro/intego-mac-internet-security-x9-review" target="_blank">Intego Mac Internet Security X9</a> sits at a comparable price point and includes a network monitor, with a longer track record in independent third-party testing. Bitdefender Total Security and Norton AntiVirus Plus both offer wider platform coverage and larger feature sets, making them better fits for households with mixed Windows and Mac devices.</p><p>Those who are already subscribed to CleanMyMac should also note that its built-in malware-scanning module, powered by the same Moonlock engine, continues to function independently. Therefore the question is whether the full Moonlock standalone app adds enough to justify an additional subscription or an upgrade in spending.</p><h2 id="final-verdict">Final verdict</h2><p>Moonlock is one of the most carefully designed security apps I've encountered in the Mac ecosystem. Its interface is excellent, its feature set is broader than most Mac-specific alternatives, and the research team behind it is doing genuinely credible original work. The 30-day money-back guarantee is also a nice addition, despite the need to enter your payment details first.</p><p>At $54 per year for a single Mac, it costs nearly twice as much as ClamXAV's three-device plan. The added value of the bundled VPN and Network Inspector goes some way toward justifying that gap, but those who already have a VPN solution elsewhere may not find the extras compelling enough. Setapp subscribers, on the other hand, get all of this for free as part of a subscription they likely already value.</p><p>For long-standing CleanMyMac users who already benefit from the embedded Moonlock engine, the standalone app offers greater depth, visibility, and control, but it's not a replacement for anything missing. It is a fuller version of the protection they have already been relying on, now with a VPN, richer reporting, and a proper home for the security features that were previously contained within a Mac cleaning utility.</p><p>For Mac users who want a single subscription that covers antivirus, VPN, network monitoring, and system security guidance, Moonlock makes a strong argument. Just go in aware of what you are paying for relative to the alternatives.</p><p><em>You might also be interested in our report on </em><a href="https://www.techradar.com/news/software/applications/30-best-mac-apps-for-just-about-everything-712511"><em>the best Mac apps of the year</em></a><em>.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ We built a trillion-dollar security industry on top of an unprotected layer ]]></title>
                                                                                                <dc:content><![CDATA[ <p>For thirty years, the hardest part of a sophisticated cyberattack was the human labor behind it. Finding the vulnerability. Writing the exploit. Chaining the access. Staying quiet long enough to matter. </p><p>That work required teams, time, and tradecraft. It’s the reason nation-state operations looked different from criminal ones, and why most organizations could plan around the gap between them.</p><p>That gap is closing. </p><p>We are entering what I think of as the Mythos era, in which machines can do in minutes what used to take skilled human operators months. <a href="https://www.techradar.com/best/best-online-cyber-security-courses">Cybersecurity</a> defenses are improving, but the layer where final decisions are made, the human one, is now the easiest to exploit. </p><p>The advantage that protected most organizations, most of the time, is going with it. Precision at scale is no longer a contradiction. It’s a feature.</p><h2 id="the-human-stack-what-it-is-and-why-it-matters">The Human Stack: what it is and why it matters</h2><p>Most of the conversation about this shift has focused on what these systems do to vulnerabilities. That conversation is accurate, but incomplete. The harder problem is what machine-speed attacks do to the systems those vulnerabilities ultimately route through: systems that depend on human decisions.</p><p>That’s a layer most <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> programs don’t explicitly own. I call it the Human Stack, the point where every system finally comes down to a person deciding whether a wire transfer goes through, whether an email is trusted, or whether a voice on a phone call is real. We have spent a generation hardening everything above it, and almost nothing on the layer itself.</p><p>For most of cybersecurity's history, that was a tolerable bet. Attackers had to choose between going wide and crude, or narrow and precise. The Human Stack held because precision didn’t scale, and scale didn’t achieve precision.</p><p>That tradeoff is gone.</p><h2 id="what-the-next-wave-of-attacks-looks-like">What the next wave of attacks looks like</h2><p>The next wave won’t arrive as <a href="https://www.techradar.com/best/best-malware-removal">malware</a>. It’ll arrive as evidence. A voicemail that sounds exactly like the person it claims to be. A video call with a face you have known for ten years. An email thread that picks up a conversation you actually had, in the cadence you actually use, referencing a project that actually exists. The technical indicators will be clean, and the social indicators will be perfect. The only thing that will be wrong is the conclusion the human is being led to.</p><p>Last year, I spent time with the team behind Midnight in the War Room, a documentary premiering August 5 at Black Hat USA. It brings together over 50 experts, from global CISOs and military strategists to reformed hackers and victims of cyber conflict. The conversations were about something that has been happening for a long time and is about to be accelerated: the industrialization of social engineering, and the steady weaponization of the behavioral attack surface.</p><p>That surface doesn't stop at your perimeter. It extends through every vendor, managed service provider, and <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud services</a> administrator your business depends on. Your operations going offline may have nothing to do with your own people, and everything to do with someone three vendors deep making a decision under synthetic pressure.</p><h2 id="what-this-means-for-enterprises">What this means for enterprises</h2><p>For businesses, this isn’t theoretical. Financial risk is direct. We're already seeing fraudulent wire transfers, manipulated approval chains, and finance chiefs impersonated so convincingly that payments clear before anyone notices.</p><p>Operational disruption can come with no malware on your systems. The behavioral attack surface doesn't stop at your perimeter. It extends through every vendor, managed service provider, law firm, auditor, and cloud administrator your business depends on. </p><p>A compromised third party, manipulated through a perfectly constructed social engineering campaign, can take your operations offline without leaving a fingerprint anywhere near your network. Most organizations scrutinize their own security posture far more rigorously than the human decision-making environments of the third parties they rely on, leaving that exposure largely unmanaged. </p><p>Regulators and insurers are starting to ask harder questions about that exposure, and most organizations don't yet have good answers.</p><h2 id="the-shift-from-prevention-to-resilience">The shift from prevention to resilience</h2><p>There's a second shift that boards need to start preparing for, and it's bigger than any single control or technology. We're leaving the era in which security success is measured by attacks prevented. We're entering one in which the realistic measure is how quickly an organization recovers when belief fails.</p><p>Prevention still matters, and the investments organizations have made in it have been the right ones. But in a world where attacks will sometimes succeed because they're indistinguishable from legitimate activity, prevention alone is no longer a coherent strategy. Resilience is.</p><p>What resilience means at the human layer is different from what it means at the technical one. Technical resilience is about systems that fail gracefully and recover quickly. Human resilience is about decision-making environments that can absorb a successful deception, recognize it, and contain it before it compounds. Most organizations have invested in the first. Very few have invested in the second. That's the gap the next decade will judge us on.</p><h2 id="what-leaders-should-do">What leaders should do</h2><p>The security stack remains necessary, but this era exposes that even the best systems hand their hardest decisions to humans, and we haven't invested in that layer with the same rigor. Here’s where to start:</p><p><strong>Measure recovery, not just prevention</strong></p><p>When belief fails, how fast can your organization catch it, contain it, and get back up? That has to be designed into your operating model now, not figured out after an incident. </p><p><strong>Design for decision-making under deception</strong></p><p>Training people to spot phishing isn't sufficient when the phishing email is indistinguishable from a real one. Build institutional processes that don't rely on a single person making the right call under pressure.</p><p><strong>Treat people as operational infrastructure. </strong></p><p>Human judgment is a critical system. It needs redundancy and failure protocols, just like any other.</p><p><strong>Extend your security culture to your vendor ecosystem</strong></p><p>The behavioral attack surface runs through your entire supply chain. Your third-party risk program needs to account for the human layer, not just the technical one.</p><h2 id="the-window-is-closing">The window is closing</h2><p>Midnight in the War Room will make this visible in a way an op-ed cannot. </p><p>The Mythos era did not create this problem. It revealed it. The cost of exploiting human decision-making precisely was high enough to keep most attackers out. That barrier is collapsing now.</p><p>What comes next will not announce itself. It’ll arrive looking like someone you trust, asking for something that feels completely reasonable, right up until the moment it isn't.</p><p>The question is no longer whether your systems can withstand attack. It's whether your people are prepared to make decisions in a world where the evidence itself can no longer be trusted, and whether your organization is built to recover when those decisions go wrong.</p><p><em></em><a href="https://www.techradar.com/best/best-cloud-antivirus"><em>We've reviewed and ranked the best cloud antivirus</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/we-built-a-trillion-dollar-security-industry-on-top-of-an-unprotected-layer</link>
                                                                            <description>
                            <![CDATA[ As attackers increasingly exploit the 'human stack', organizations must shift from purely technical defenses to behavior-based resilience. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sMHxNdB4WmJWK3NYsDeq6N</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wV66hEbpJdAc4iPB7RwtkK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 06 Jul 2026 10:46:42 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sarah Gosler ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wV66hEbpJdAc4iPB7RwtkK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An exclamation mark inside a red warning triangle, surrounded by email symbols, superimposed on someone typing on a laptop]]></media:description>                                                            <media:text><![CDATA[An exclamation mark inside a red warning triangle, surrounded by email symbols, superimposed on someone typing on a laptop]]></media:text>
                                <media:title type="plain"><![CDATA[An exclamation mark inside a red warning triangle, surrounded by email symbols, superimposed on someone typing on a laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wV66hEbpJdAc4iPB7RwtkK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>For thirty years, the hardest part of a sophisticated cyberattack was the human labor behind it. Finding the vulnerability. Writing the exploit. Chaining the access. Staying quiet long enough to matter. </p><p>That work required teams, time, and tradecraft. It’s the reason nation-state operations looked different from criminal ones, and why most organizations could plan around the gap between them.</p><p>That gap is closing. </p><p>We are entering what I think of as the Mythos era, in which machines can do in minutes what used to take skilled human operators months. <a href="https://www.techradar.com/best/best-online-cyber-security-courses">Cybersecurity</a> defenses are improving, but the layer where final decisions are made, the human one, is now the easiest to exploit. </p><p>The advantage that protected most organizations, most of the time, is going with it. Precision at scale is no longer a contradiction. It’s a feature.</p><h2 id="the-human-stack-what-it-is-and-why-it-matters">The Human Stack: what it is and why it matters</h2><p>Most of the conversation about this shift has focused on what these systems do to vulnerabilities. That conversation is accurate, but incomplete. The harder problem is what machine-speed attacks do to the systems those vulnerabilities ultimately route through: systems that depend on human decisions.</p><p>That’s a layer most <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> programs don’t explicitly own. I call it the Human Stack, the point where every system finally comes down to a person deciding whether a wire transfer goes through, whether an email is trusted, or whether a voice on a phone call is real. We have spent a generation hardening everything above it, and almost nothing on the layer itself.</p><p>For most of cybersecurity's history, that was a tolerable bet. Attackers had to choose between going wide and crude, or narrow and precise. The Human Stack held because precision didn’t scale, and scale didn’t achieve precision.</p><p>That tradeoff is gone.</p><h2 id="what-the-next-wave-of-attacks-looks-like">What the next wave of attacks looks like</h2><p>The next wave won’t arrive as <a href="https://www.techradar.com/best/best-malware-removal">malware</a>. It’ll arrive as evidence. A voicemail that sounds exactly like the person it claims to be. A video call with a face you have known for ten years. An email thread that picks up a conversation you actually had, in the cadence you actually use, referencing a project that actually exists. The technical indicators will be clean, and the social indicators will be perfect. The only thing that will be wrong is the conclusion the human is being led to.</p><p>Last year, I spent time with the team behind Midnight in the War Room, a documentary premiering August 5 at Black Hat USA. It brings together over 50 experts, from global CISOs and military strategists to reformed hackers and victims of cyber conflict. The conversations were about something that has been happening for a long time and is about to be accelerated: the industrialization of social engineering, and the steady weaponization of the behavioral attack surface.</p><p>That surface doesn't stop at your perimeter. It extends through every vendor, managed service provider, and <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud services</a> administrator your business depends on. Your operations going offline may have nothing to do with your own people, and everything to do with someone three vendors deep making a decision under synthetic pressure.</p><h2 id="what-this-means-for-enterprises">What this means for enterprises</h2><p>For businesses, this isn’t theoretical. Financial risk is direct. We're already seeing fraudulent wire transfers, manipulated approval chains, and finance chiefs impersonated so convincingly that payments clear before anyone notices.</p><p>Operational disruption can come with no malware on your systems. The behavioral attack surface doesn't stop at your perimeter. It extends through every vendor, managed service provider, law firm, auditor, and cloud administrator your business depends on. </p><p>A compromised third party, manipulated through a perfectly constructed social engineering campaign, can take your operations offline without leaving a fingerprint anywhere near your network. Most organizations scrutinize their own security posture far more rigorously than the human decision-making environments of the third parties they rely on, leaving that exposure largely unmanaged. </p><p>Regulators and insurers are starting to ask harder questions about that exposure, and most organizations don't yet have good answers.</p><h2 id="the-shift-from-prevention-to-resilience">The shift from prevention to resilience</h2><p>There's a second shift that boards need to start preparing for, and it's bigger than any single control or technology. We're leaving the era in which security success is measured by attacks prevented. We're entering one in which the realistic measure is how quickly an organization recovers when belief fails.</p><p>Prevention still matters, and the investments organizations have made in it have been the right ones. But in a world where attacks will sometimes succeed because they're indistinguishable from legitimate activity, prevention alone is no longer a coherent strategy. Resilience is.</p><p>What resilience means at the human layer is different from what it means at the technical one. Technical resilience is about systems that fail gracefully and recover quickly. Human resilience is about decision-making environments that can absorb a successful deception, recognize it, and contain it before it compounds. Most organizations have invested in the first. Very few have invested in the second. That's the gap the next decade will judge us on.</p><h2 id="what-leaders-should-do">What leaders should do</h2><p>The security stack remains necessary, but this era exposes that even the best systems hand their hardest decisions to humans, and we haven't invested in that layer with the same rigor. Here’s where to start:</p><p><strong>Measure recovery, not just prevention</strong></p><p>When belief fails, how fast can your organization catch it, contain it, and get back up? That has to be designed into your operating model now, not figured out after an incident. </p><p><strong>Design for decision-making under deception</strong></p><p>Training people to spot phishing isn't sufficient when the phishing email is indistinguishable from a real one. Build institutional processes that don't rely on a single person making the right call under pressure.</p><p><strong>Treat people as operational infrastructure. </strong></p><p>Human judgment is a critical system. It needs redundancy and failure protocols, just like any other.</p><p><strong>Extend your security culture to your vendor ecosystem</strong></p><p>The behavioral attack surface runs through your entire supply chain. Your third-party risk program needs to account for the human layer, not just the technical one.</p><h2 id="the-window-is-closing">The window is closing</h2><p>Midnight in the War Room will make this visible in a way an op-ed cannot. </p><p>The Mythos era did not create this problem. It revealed it. The cost of exploiting human decision-making precisely was high enough to keep most attackers out. That barrier is collapsing now.</p><p>What comes next will not announce itself. It’ll arrive looking like someone you trust, asking for something that feels completely reasonable, right up until the moment it isn't.</p><p>The question is no longer whether your systems can withstand attack. It's whether your people are prepared to make decisions in a world where the evidence itself can no longer be trusted, and whether your organization is built to recover when those decisions go wrong.</p><p><em></em><a href="https://www.techradar.com/best/best-cloud-antivirus"><em>We've reviewed and ranked the best cloud antivirus</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ That free VPN Chrome and Firefox extension may be reading your clipboard every half a second, researchers warn ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Researchers found "VPN Go" extensions for Chrome and Firefox secretly harvesting copied text</strong></li><li><strong>The clipboard theft was not there at launch and arrived through a later update</strong></li><li><strong>Anything copied while the extension was active should now be treated as exposed</strong></li></ul><p>Security researchers at Socket found two browser extensions distributed under the "VPN Go: Free VPN" branding, one listed on the Chrome Web Store and one on Firefox Add-ons, to secretly harvest copied text. </p><p>Both present themselves as free VPN tools with working proxy features. Underneath, <a href="https://socket.dev/blog/chrome-and-firefox-extensions-free-vpns-add-clipboard-stealers" target="_blank" rel="nofollow">Socket says</a>, both also run a clipboard stealer that continuously watches copied text and sends it to infrastructure controlled by the attacker.</p><p>According to Socket, the clipboard theft was not present when the extensions first appeared. It was added later, through an ordinary-looking update, after the extensions had already built up a base of trusting users. That staged approach is exactly what makes this kind of threat so hard to spot, and why even a fairly cautious user can end up exposed.</p><p>For anyone weighing up a no-cost privacy tool, it is worth knowing that not every free option behaves like this, and the <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> services are tested precisely so you do not have to take this kind of gamble. But this case shows how thin the line can be between a useful free extension and a data-harvesting one.</p><h2 id="what-socket-s-research-uncovered">What Socket's research uncovered</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1213px;"><p class="vanilla-image-block" style="padding-top:56.22%;"><img id="7b3ucMmXHaTYWRvoZbT8T9" name="VPN Go" alt="VPN Go in Chrome Web Store" src="https://cdn.mos.cms.futurecdn.net/7b3ucMmXHaTYWRvoZbT8T9.png" mos="" align="middle" fullscreen="" width="1213" height="682" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Chrome)</span></figcaption></figure><p>Socket says the earliest analyzed builds behaved like ordinary proxy extensions, with no confirmed clipboard theft. </p><p>On <a href="https://www.techradar.com/reviews/google-chrome">Chrome</a>, that changed with version 1.1, when the extension added a script that reads the clipboard and ships those chunks off to a hardcoded address. The <a href="https://www.techradar.com/reviews/mozilla-firefox">Firefox</a> version followed the same path slightly later, moving the same theft loop into its background script.</p><p>Once active, the monitoring is relentless. The Chrome content script checks the clipboard roughly every half a second, according to Socket's analysis, while the Firefox build polls every 1.5 seconds. </p><p>Each newly copied value is tagged with a session identifier so it can be reassembled on the other end, then sent out over plain HTTP. All of this was happening while the two apps' privacy policies stated that the tools did not collect, store, or share user data and did not keep activity logs.</p><p>TechRadar has reached out to VPN Go for comment, but both email addresses bounced, and both extensions have since been pulled from their stores.</p><h2 id="why-clipboard-stealers-are-dangerous-for-users">Why clipboard stealers are dangerous for users</h2><p>The reason clipboard theft is so effective is that it abuses something completely routine. People copy and paste sensitive information all day, and it's not careless to do so. Password managers rely on exactly that: copying long, unique passwords into your accounts.</p><p>An extension that can silently read the clipboard has access to all of this information; it just has to wait for you to copy the right thing. If you have used either of the two extensions in question, you should treat any information you've copied during that time as exposed.</p><p>Researchers have repeatedly found free VPN extensions doing things their users never agreed to. Recent reporting has covered a <a href="https://www.techradar.com/vpn/vpn-privacy-security/this-free-chrome-vpn-extension-found-to-spy-on-its-100k-users-uninstall-it-now">free Chrome VPN extension caught taking screenshots</a> of every page its users visited, and a <a href="https://www.techradar.com/vpn/vpn-privacy-security/malicious-free-vpn-extension-makes-a-comeback">malicious free VPN extension that resurfaced</a> after being removed, returning in a more evasive form. </p><p>The pattern is consistent enough that it is worth treating any unknown free VPN extension with caution by default. That caution matters: TechRadar's own polling found that <a href="https://www.techradar.com/vpn/vpn-privacy-security/to-pay-or-not-to-pay-nearly-1-in-4-techradar-readers-say-they-use-free-vpns-despite-the-risks">nearly 1 in 4 readers use free VPNs</a> despite knowing the risks.</p><div data-widget-type="multimodelreview" data-model-name="NordVPN,Surfshark,Proton VPN" data-widget-title="Today's best VPN deals"></div><h2 id="how-to-stay-safe-7">How to stay safe</h2><p>If you want the protection a VPN offers without rolling the dice, stick to providers with a track record and independent testing behind them. </p><p>A reputable paid service, or one of the carefully vetted <a href="https://www.techradar.com/vpn/best-free-vpn">best free VPN</a> options, is a far safer bet than an unknown extension promising unlimited access for nothing. As the saying goes, when the product is free, there is a decent chance that you are the product.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/vpn/vpn-privacy-security/that-free-vpn-chrome-and-firefox-extension-may-be-reading-your-clipboard-every-half-a-second-researchers-warn</link>
                                                                            <description>
                            <![CDATA[ Researchers at Socket found two "VPN Go" browser extensions for Chrome and Firefox that posed as free VPNs while quietly stealing clipboard data through later updates. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">drttgaXd7xBrBjVNgZ6gbP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5pmsJs3KfnrtbsM98UsnG9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 01 Jul 2026 13:22:10 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[VPN Privacy & Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ monicajwrites@gmail.com (Monica J. White) ]]></author>                    <dc:creator><![CDATA[ Monica J. White ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/6AQ4y5nzk8kQ47Yp69GERj.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Monica is a journalist with over a decade of experience in covering technology.&lt;/p&gt;&lt;p&gt;She writes about the latest developments in computing, which means anything from computer chips made out of paper to cutting-edge desktop processors. Her coverage includes CPUs, GPUs, and everything else that goes into a PC or a laptop, but also peripherals.&lt;/p&gt;&lt;p&gt;GPUs are Monica’s main area of interest, and nothing thrills her quite like that time every couple of years when new graphics cards hit the market. She’s always keeping tabs on the latest from Nvidia, AMD, and Intel, including both the hardware and the software that powers our PCs.&lt;/p&gt;&lt;p&gt;As an avid gamer, her focus is always on the consumer and whether something works well and provides adequate value for the money. She believes that PC building can be intimidating, so her goal is to explain complex concepts in an approachable manner while still digging into the technical nitty-gritty we all love to learn more about.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5pmsJs3KfnrtbsM98UsnG9-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Malware kan ställa till med oreda]]></media:description>                                                            <media:text><![CDATA[Android phone malware]]></media:text>
                                <media:title type="plain"><![CDATA[Android phone malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5pmsJs3KfnrtbsM98UsnG9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers found "VPN Go" extensions for Chrome and Firefox secretly harvesting copied text</strong></li><li><strong>The clipboard theft was not there at launch and arrived through a later update</strong></li><li><strong>Anything copied while the extension was active should now be treated as exposed</strong></li></ul><p>Security researchers at Socket found two browser extensions distributed under the "VPN Go: Free VPN" branding, one listed on the Chrome Web Store and one on Firefox Add-ons, to secretly harvest copied text. </p><p>Both present themselves as free VPN tools with working proxy features. Underneath, <a href="https://socket.dev/blog/chrome-and-firefox-extensions-free-vpns-add-clipboard-stealers" target="_blank" rel="nofollow">Socket says</a>, both also run a clipboard stealer that continuously watches copied text and sends it to infrastructure controlled by the attacker.</p><p>According to Socket, the clipboard theft was not present when the extensions first appeared. It was added later, through an ordinary-looking update, after the extensions had already built up a base of trusting users. That staged approach is exactly what makes this kind of threat so hard to spot, and why even a fairly cautious user can end up exposed.</p><p>For anyone weighing up a no-cost privacy tool, it is worth knowing that not every free option behaves like this, and the <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> services are tested precisely so you do not have to take this kind of gamble. But this case shows how thin the line can be between a useful free extension and a data-harvesting one.</p><h2 id="what-socket-s-research-uncovered">What Socket's research uncovered</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1213px;"><p class="vanilla-image-block" style="padding-top:56.22%;"><img id="7b3ucMmXHaTYWRvoZbT8T9" name="VPN Go" alt="VPN Go in Chrome Web Store" src="https://cdn.mos.cms.futurecdn.net/7b3ucMmXHaTYWRvoZbT8T9.png" mos="" align="middle" fullscreen="" width="1213" height="682" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Chrome)</span></figcaption></figure><p>Socket says the earliest analyzed builds behaved like ordinary proxy extensions, with no confirmed clipboard theft. </p><p>On <a href="https://www.techradar.com/reviews/google-chrome">Chrome</a>, that changed with version 1.1, when the extension added a script that reads the clipboard and ships those chunks off to a hardcoded address. The <a href="https://www.techradar.com/reviews/mozilla-firefox">Firefox</a> version followed the same path slightly later, moving the same theft loop into its background script.</p><p>Once active, the monitoring is relentless. The Chrome content script checks the clipboard roughly every half a second, according to Socket's analysis, while the Firefox build polls every 1.5 seconds. </p><p>Each newly copied value is tagged with a session identifier so it can be reassembled on the other end, then sent out over plain HTTP. All of this was happening while the two apps' privacy policies stated that the tools did not collect, store, or share user data and did not keep activity logs.</p><p>TechRadar has reached out to VPN Go for comment, but both email addresses bounced, and both extensions have since been pulled from their stores.</p><h2 id="why-clipboard-stealers-are-dangerous-for-users">Why clipboard stealers are dangerous for users</h2><p>The reason clipboard theft is so effective is that it abuses something completely routine. People copy and paste sensitive information all day, and it's not careless to do so. Password managers rely on exactly that: copying long, unique passwords into your accounts.</p><p>An extension that can silently read the clipboard has access to all of this information; it just has to wait for you to copy the right thing. If you have used either of the two extensions in question, you should treat any information you've copied during that time as exposed.</p><p>Researchers have repeatedly found free VPN extensions doing things their users never agreed to. Recent reporting has covered a <a href="https://www.techradar.com/vpn/vpn-privacy-security/this-free-chrome-vpn-extension-found-to-spy-on-its-100k-users-uninstall-it-now">free Chrome VPN extension caught taking screenshots</a> of every page its users visited, and a <a href="https://www.techradar.com/vpn/vpn-privacy-security/malicious-free-vpn-extension-makes-a-comeback">malicious free VPN extension that resurfaced</a> after being removed, returning in a more evasive form. </p><p>The pattern is consistent enough that it is worth treating any unknown free VPN extension with caution by default. That caution matters: TechRadar's own polling found that <a href="https://www.techradar.com/vpn/vpn-privacy-security/to-pay-or-not-to-pay-nearly-1-in-4-techradar-readers-say-they-use-free-vpns-despite-the-risks">nearly 1 in 4 readers use free VPNs</a> despite knowing the risks.</p><div data-widget-type="multimodelreview" data-model-name="NordVPN,Surfshark,Proton VPN" data-widget-title="Today's best VPN deals"></div><h2 id="how-to-stay-safe-7">How to stay safe</h2><p>If you want the protection a VPN offers without rolling the dice, stick to providers with a track record and independent testing behind them. </p><p>A reputable paid service, or one of the carefully vetted <a href="https://www.techradar.com/vpn/best-free-vpn">best free VPN</a> options, is a far safer bet than an unknown extension promising unlimited access for nothing. As the saying goes, when the product is free, there is a decent chance that you are the product.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NAIC confirms data breach with ShinyHunters claiming 3.1TB of data stolen in Oracle zero-day attack ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>NAIC confirmed a cyberattack exploiting an Oracle PeopleSoft zero‑day, with ShinyHunters claiming theft of 3.1TB of data</strong></li><li><strong>Stolen cache allegedly includes insurer filings, credit rating files, AWS logs, configs, and PII; NAIC says only financial reports and technical data were taken</strong></li><li><strong>Incident spotted June 11, disclosed June 17; files leaked online suggest NAIC did not pay ransom, as ShinyHunters continues exploiting the zero‑day across 100+ organizations</strong></li></ul><p>The National Association of Insurance Commissioners (NAIC) confirmed suffering a cyberattack that resulted in the stolen data being leaked on the dark web. While the company did not name the group responsible, or mentioned the size of the stolen cache, the infamous ShinyHunters claimed responsibility and stated they snatched around 3.1TB of information.</p><p>In a security notice published on the NAIC website, it was explained that the attackers managed to exploit a <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">zero-day vulnerability</a> in Oracle PeopleSoft. This is an <a href="https://www.techradar.com/best/best-erp-software" target="_blank">enterprise resource planning</a> (ERP) software suite, designed to help businesses manage employees, finances, supply chains, and more. Citing Google Mandiant, Cybernews says ShinyHunters first started exploiting the zero-day on May 27, and managed to compromise more than 100 organizations and 300 individuals, before Oracle finally pushed an emergency update on June 10.</p><p>Among the victims, as we now know, is NAIC, whose PeopleSoft environment was compromised, and used to obtain credentials and move laterally to internal data storage locations. </p><h2 id="shinyhunters-step-forward">ShinyHunters step forward</h2><p>Based on NAIC’s investigation, the stolen information includes publicly available statutory financial reports, insurer investment credit rating data, and some technical information such as outdated logs and configuration files. There is no evidence that personal information, banking information, or payment data was accessed, it said.</p><p>NAIC spotted the attack on June 11 and immediately launched its incident response protocol, which includes notifying law enforcement, blocking malicious actors, and bringing in third-party security experts. The Commission disclosed the incident on June 17, a day before ShinyHunters went public. </p><p>The notorious ransomware gang claims to have taken more than 264,000 insurer regulatory filing documents, 2,000 customer and bulk orders containing personally identifiable information, some 45,000 files from major credit rating agencies, statutory annual and quarterly financial statements submitted by insurers, production AWS infrastructure logs, cloud configuration files, and workload automation data, and SQL scripts.</p><p>Since the files were seemingly leaked online, it’s safe to assume that NAIC did not (want to) pay the ransom demand.</p><p><em>Via </em><a href="https://cybernews.com/news/naic-breach-shinyhunters-3tb-insurance-systems-data/" target="_blank"><em>Cybernews</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/naic-confirms-data-breach-with-shinyhunters-claiming-3-1tb-of-data-stolen-in-oracle-zero-day-attack</link>
                                                                            <description>
                            <![CDATA[ Insurer regulatory filing documents, customer bulk orders, and more, stolen in a major zero-day supply chain attack ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rq7YhrojSragNBymdm8FYn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 26 Jun 2026 18:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[hacker hands at work with  interface around]]></media:description>                                                            <media:text><![CDATA[hacker hands at work with  interface around]]></media:text>
                                <media:title type="plain"><![CDATA[hacker hands at work with  interface around]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>NAIC confirmed a cyberattack exploiting an Oracle PeopleSoft zero‑day, with ShinyHunters claiming theft of 3.1TB of data</strong></li><li><strong>Stolen cache allegedly includes insurer filings, credit rating files, AWS logs, configs, and PII; NAIC says only financial reports and technical data were taken</strong></li><li><strong>Incident spotted June 11, disclosed June 17; files leaked online suggest NAIC did not pay ransom, as ShinyHunters continues exploiting the zero‑day across 100+ organizations</strong></li></ul><p>The National Association of Insurance Commissioners (NAIC) confirmed suffering a cyberattack that resulted in the stolen data being leaked on the dark web. While the company did not name the group responsible, or mentioned the size of the stolen cache, the infamous ShinyHunters claimed responsibility and stated they snatched around 3.1TB of information.</p><p>In a security notice published on the NAIC website, it was explained that the attackers managed to exploit a <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">zero-day vulnerability</a> in Oracle PeopleSoft. This is an <a href="https://www.techradar.com/best/best-erp-software" target="_blank">enterprise resource planning</a> (ERP) software suite, designed to help businesses manage employees, finances, supply chains, and more. Citing Google Mandiant, Cybernews says ShinyHunters first started exploiting the zero-day on May 27, and managed to compromise more than 100 organizations and 300 individuals, before Oracle finally pushed an emergency update on June 10.</p><p>Among the victims, as we now know, is NAIC, whose PeopleSoft environment was compromised, and used to obtain credentials and move laterally to internal data storage locations. </p><h2 id="shinyhunters-step-forward">ShinyHunters step forward</h2><p>Based on NAIC’s investigation, the stolen information includes publicly available statutory financial reports, insurer investment credit rating data, and some technical information such as outdated logs and configuration files. There is no evidence that personal information, banking information, or payment data was accessed, it said.</p><p>NAIC spotted the attack on June 11 and immediately launched its incident response protocol, which includes notifying law enforcement, blocking malicious actors, and bringing in third-party security experts. The Commission disclosed the incident on June 17, a day before ShinyHunters went public. </p><p>The notorious ransomware gang claims to have taken more than 264,000 insurer regulatory filing documents, 2,000 customer and bulk orders containing personally identifiable information, some 45,000 files from major credit rating agencies, statutory annual and quarterly financial statements submitted by insurers, production AWS infrastructure logs, cloud configuration files, and workload automation data, and SQL scripts.</p><p>Since the files were seemingly leaked online, it’s safe to assume that NAIC did not (want to) pay the ransom demand.</p><p><em>Via </em><a href="https://cybernews.com/news/naic-breach-shinyhunters-3tb-insurance-systems-data/" target="_blank"><em>Cybernews</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>