<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-SG"
                       href="https://www.techradar.com/sg/feeds/tag/malware"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from TechRadar SG in Malware ]]></title>
                <link>https://www.techradar.com/sg/tag/malware</link>
        <description><![CDATA[ All the latest malware content from the TechRadar  SG team ]]></description>
                                    <lastBuildDate>Sat, 25 Jul 2026 14:20:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Experts claim to have found more weaknesses in Apple's Gatekeeper tool — but it doesn't seem too bothered ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-claim-to-have-found-more-weaknesses-in-apples-gatekeeper-tool-but-it-doesnt-seem-too-bothered</link>
                                                                            <description>
                            <![CDATA[ Gatekeeper doesn't blink when you archive a legitimate app and replace it with an evil doppelganger. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cigoAwt4EPwNFgf9LCcsXa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ctUFkwkvMxVyJJwJmZLPJ5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 25 Jul 2026 14:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ctUFkwkvMxVyJJwJmZLPJ5-1280-80.jpg">
                                                            <media:credit><![CDATA[Apple]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person using iPhone Mirroring on a MacBook Pro running macOS 27 Golden Gate.]]></media:description>                                                            <media:text><![CDATA[A person using iPhone Mirroring on a MacBook Pro running macOS 27 Golden Gate.]]></media:text>
                                <media:title type="plain"><![CDATA[A person using iPhone Mirroring on a MacBook Pro running macOS 27 Golden Gate.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ctUFkwkvMxVyJJwJmZLPJ5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers show Gatekeeper can be bypassed by replacing a previously run legitimate macOS app with malware</strong></li><li><strong>Attack requires prior user‑level code execution, then swaps in a malicious app that Gatekeeper won’t re‑verify</strong></li><li><strong>Apple dismissed the issue, saying locally rebuilt bundles fall outside Gatekeeper’s scope, leaving risk to social engineering</strong></li></ul><p>A pair of researchers claims to have found a way around Gatekeeper, a built-in macOS security feature that helps protect users from running malicious or untrusted software. However Apple doesn’t really see it that way and has seemingly decided not to pursue the issue further.</p><p>Gatekeeper’s modus operandi is rather simple - when a user downloads an app from outside the App Store, it verifies the product comes from an identified developer and is notarized by Apple. If it can’t verify it - it won’t allow it to run on the machine. </p><p>Now, security researchers Talal Haj Barky and Tommy Mysk claim that, as long as a legitimate app was run at least once on a macOS device, it can be replaced with a malicious version, and Gatekeeper won’t even blink its virtual eye.</p><h2 id="locally-built">Locally built</h2><p>That also means the attack is not that straightforward to pull off. The threat actor needs to have a way to execute user-level code (for example, a malicious app, a compromised software package installed through a package manager, or a prompt injection attack that tricks an AI agent).</p><p>Once that is obtained, they can archive a legitimate app, remove the original, then replace it with <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, and Gatekeeper will not try to re-authorize it. That malicious version can then trick the victim into compromising the device even further, since a certain level of trust was already established. </p><p>After reporting the issue to Apple, the company apparently just closed it. </p><p>"Apple doesn't consider this attack to be 'modifying' the signed executable," Mysk said. "Instead, Apple says that by archiving/restoring the app bundle, the proof-of-concept code overwrites the entire app bundle, making it locally built. Locally built app bundles are not covered by macOS guards. And this is why access to Keychain or TCC protected directories require system authorization prompts. And for users to accept those is a matter of social engineering attacks that Apple considers out of scope."</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/07/24/researchers-replace-downloaded-macos-apps-with-evil-twins-apple-shrugs/5277858" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Iran-linked group caught hiding surveillance tools in fake apps ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/vpn/vpn-privacy-security/iran-linked-group-caught-hiding-surveillance-tools-in-fake-apps</link>
                                                                            <description>
                            <![CDATA[ Researchers at Recorded Future found evidence that an Iran-linked group is spreading MarkiRAT spyware through fake VPN and media player apps promoted on social media, targeting Farsi speakers worldwide. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rcr4Mct7ErHSY84Lpy5fvW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/z8Ysj7MUYeyK822yMiTepP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 25 Jul 2026 06:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[VPN Privacy &amp; Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ monicajwrites@gmail.com (Monica J. White) ]]></author>                    <dc:creator><![CDATA[ Monica J. White ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/6AQ4y5nzk8kQ47Yp69GERj.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Monica is a journalist with over a decade of experience in covering technology.&lt;/p&gt;&lt;p&gt;She writes about the latest developments in computing, which means anything from computer chips made out of paper to cutting-edge desktop processors. Her coverage includes CPUs, GPUs, and everything else that goes into a PC or a laptop, but also peripherals.&lt;/p&gt;&lt;p&gt;GPUs are Monica’s main area of interest, and nothing thrills her quite like that time every couple of years when new graphics cards hit the market. She’s always keeping tabs on the latest from Nvidia, AMD, and Intel, including both the hardware and the software that powers our PCs.&lt;/p&gt;&lt;p&gt;As an avid gamer, her focus is always on the consumer and whether something works well and provides adequate value for the money. She believes that PC building can be intimidating, so her goal is to explain complex concepts in an approachable manner while still digging into the technical nitty-gritty we all love to learn more about.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/z8Ysj7MUYeyK822yMiTepP-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Malware kan ställa till med oreda]]></media:description>                                                            <media:text><![CDATA[A hand with a mobile phone and VPN application in front of the Iran flag]]></media:text>
                                <media:title type="plain"><![CDATA[A hand with a mobile phone and VPN application in front of the Iran flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/z8Ysj7MUYeyK822yMiTepP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Recorded Future found an Iran-linked group spreading spyware</strong></li><li><strong>The malware is delivered through fake VPN and media player apps</strong></li><li><strong>Researchers assess that most targets are Iranian users</strong></li></ul><p>A new report from <a href="https://www.recordedfuture.com/research/nexus-tag182-disseminates-markirat" target="_blank" rel="nofollow">Recorded Future's Insikt Group</a> describes a campaign that inverts the whole point of a privacy tool: fake VPN apps built specifically to spy on the people who install them.</p><p>Researchers have linked fresh infrastructure to an Iran-nexus threat cluster they track as TAG-182, which is using fake VPN and media player downloads to allegedly deliver a surveillance tool called MarkiRAT. The group is "highly likely" to be targeting Iranians living inside and outside the country, <a href="https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-ir-2026-0701.pdf" target="_blank" rel="nofollow">the report says</a>.</p><p>It's a blunt reminder that choosing one of the <a href="https://www.techradar.com/vpn/best-vpn" target="_blank" rel="nofollow">best VPN</a> services is a lot more secure than downloading free, unvetted tools.</p><h2 id="fake-apps-real-surveillance">Fake apps, real surveillance</h2><p>Insikt Group identified a cluster of attacker-controlled domains allegedly used to stage downloads of applications that appear nowhere on Google Play or Apple's App Store. </p><p>Two names stand out: Pis2ray VPN and a media player branded YESHICA, which was quietly renamed YESHICA YEPlayer in March 2026 after researchers publicly exposed the original.</p><p>According to researchers, if you download and run one of these files, you get MarkiRAT, a remote access Trojan. In plain terms, that is software that hands control of your device to somebody else. </p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr">A fake VPN app. A fake media player. Both delivering Iranian government surveillance #malware to targeted dissidents. Insikt Group has new research on TAG-182 and MarkiRAT:https://t.co/G7p9JO6peT#ThreatIntelligence #Cybersecurity pic.twitter.com/GwDyvGC99r<a href="https://twitter.com/cantworkitout/status/2072720755884695924">July 2, 2026</a></p></blockquote><div class="see-more__filter"></div></div><p>Analysts have documented it capturing screenshots and uploading them to attacker-run servers, while disguising itself under believable process names.</p><p>It also abuses BITS, the background service Windows uses to fetch updates, to pull down further files. Because that activity looks like ordinary system housekeeping rather than an attack, it tends to slip past routine cleanup.</p><p>MarkiRAT is not new. It has previously been used by Ferocious Kitten, a group <a href="https://securelist.com/ferocious-kitten-6-years-of-covert-surveillance-in-iran/102806/" target="_blank" rel="nofollow">Kaspersky</a> documented conducting years of covert surveillance against activists inside Iran. </p><p>Recorded Future stops short of attributing TAG-182 to any specific Iranian agency, but places it within a broader ecosystem of state-aligned surveillance groups.</p><h2 id="why-a-fake-vpn-makes-such-an-effective-lure">Why a fake VPN makes such an effective lure</h2><p>Distribution runs largely through social media. Insikt Group found Instagram posts promoting Pis2ray VPN in the weeks following street protests in Iran in late 2025, and again around the <a href="https://www.techradar.com/vpn/vpn-privacy-security/the-internet-is-not-connected-irans-88-day-blackout-begins-to-lift-but-traffic-remains-under-50-percent">country's prolonged internet shutdown</a>, which ended with partial restoration of access on 26 May 2026.</p><p>The people most desperate for a <a href="https://www.techradar.com/vpn/virtual-private-networks">virtual private network (VPN)</a> in a censored country are exactly the people most likely to install one from a social media link, because the official stores are often the very thing they cannot reach. </p><p>Recorded Future considers it almost certain that most targets are located in Iran or tied to anti-government movements in Europe and North America. TechRadar has covered <a href="https://www.techradar.com/vpn/vpn-privacy-security/beware-iran-linked-fake-vpn-apps-found-to-spy-on-android-users" target="_blank" rel="nofollow">previous Iran-linked fake VPN campaigns</a>, and this one seems to follow the same pattern with better infrastructure.</p><h2 id="how-to-stay-safe">How to stay safe</h2><p>Most readers will never be targeted by a state actor, but the underlying lesson travels. </p><p>Install VPN apps only from official stores, and check that the provider has a real, verifiable presence outside the app listing. </p><p>Treat any VPN promoted through an Instagram post, a Telegram channel, or a direct message as suspect, however polished it looks. </p><p>Star ratings are a weak signal, since fake reviews are cheap.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why you can’t buy security on the dark web ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/why-you-cant-buy-security-on-the-dark-web</link>
                                                                            <description>
                            <![CDATA[ Why buying, monitoring, or negotiating on the dark web often creates more risk than security. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wWnRmnUEZueLuNaGnKgaca</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 09:17:43 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Andrey Leskin ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:description>                                                            <media:text><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:text>
                                <media:title type="plain"><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Data leaks and corporate breaches have become routine. In many cases, stolen credentials, <a href="https://www.techradar.com/best/best-database-software">databases</a>, or attack tools eventually appear on the dark web, where they are traded and reused in future attacks.</p><p>This raises a question for <a href="https://www.techradar.com/best/best-small-business-website-builders">businesses</a>: if stolen corporate data ends up on the dark web, does it make sense to engage with this environment directly — by buying information, paying for services, or negotiating with attackers? </p><p>The short answer is no.</p><p>Not because the dark web doesn’t matter — quite the opposite: it is a core part of today’s cybercriminal <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>. The problem is that doing business with the dark web rarely reduces the immediate risks and systematically strengthens the very market that creates threats.</p><h2 id="the-nature-of-the-dark-web">The nature of the dark web</h2><p>The dark web — often used interchangeably with the term darknet — refers to parts of the internet intentionally hidden from search engines and accessible only through tools such as Tor or I2P.</p><p>It is not a single network but a collection of platforms and communities gated by encryption, nonstandard protocols, or restricted access. While some resources are relatively neutral, others are directly tied to criminal activity. From a cybersecurity perspective, the dark web matters primarily as a mature cybercrime marketplace.  </p><p>Technically, many platforms resemble early internet forums. Functionally, however, they operate much like B2B marketplaces — except the products include stolen data, compromised accounts, <a href="https://www.techradar.com/best/best-malware-removal">malware</a>, exploit kits, and attack services.</p><h2 id="the-economics-of-cybercrime">The economics of cybercrime</h2><p>A key function of the dark web is simplifying the monetization of cybercrime. More importantly, it enables specialization and the formation of complex supply chains.  </p><p>Instead of building operations end-to-end, cybercriminals now focus on specific roles: some identify vulnerabilities and gain initial access, others develop and distribute malware, while others specialize in monetization through data sales, extortion, or attacks-for-hire.</p><p>This division of labor has created a full-fledged cybercrime economy. Attackers no longer need advanced expertise or their own infrastructure — they can purchase the necessary tools and services, lowering the barrier to entry and increasing the scale of attacks.</p><p>A clear example is the Ransomware-as-a-Service (RaaS) model, where core groups develop malware and manage negotiations, while affiliates carry out attacks for a share of the ransom. This model has enabled large-scale incidents such as the 2021 Colonial Pipeline attack, which disrupted fuel supplies across the U.S. East Coast and resulted in a $4.4 million payment.</p><h2 id="dark-web-intelligence-and-false-signals">Dark web intelligence and false signals</h2><p>As the dark web evolved into a cybercrime marketplace, businesses naturally became interested in monitoring it for early warning signals.</p><p>In practice, this approach works only partially. The problem with dark web intelligence is that it comes from an environment with virtually no reliable verification mechanisms.</p><p>Like any anonymous and unregulated market, the dark web contains a significant amount of noise, manipulation, and outright fraud. Listings may be outdated, fabricated, or recycled from old leaks, while reputation signals can be artificially inflated. </p><p>The problem becomes even more pronounced when monitoring is outsourced to third-party vendors. Weak or unverifiable signals can easily be exaggerated, misinterpreted, or presented as evidence of major threats.</p><p>As a result, dark web monitoring rarely provides the level of certainty businesses expect. At best, it can highlight a potential issue that still requires verification.</p><h2 id="never-pay-cybercriminals">Never pay cybercriminals</h2><p>Direct engagement with the dark web is even more problematic — whether through ransom payments, purchasing leaked data, or hiring anonymous actors to test infrastructure.</p><p>The most obvious issue is that paying cybercriminals offers no guarantees. Attackers may simply demand another payment or leak the data anyway.</p><p>Uber learned this in 2016 after paying attackers $100,000 following a breach affecting 57 million users, only for the incident to become public later and trigger regulatory fallout.</p><p>A similar pattern appeared in the 2017 breach of HBO, when attackers stole 1.5 TB of Game of Thrones-related data, including unreleased episodes and internal <a href="https://www.techradar.com/best/best-cloud-document-storage">documents</a>. HBO reportedly transferred $250,000, but the material leaked anyway.</p><p>The broader problem, however, is structural: every payment flowing into the dark web economy directly finances its further growth. The more businesses participate in that market, the stronger the incentives for attackers to discover vulnerabilities, compromise systems, and scale operations.</p><h2 id="common-mistakes-when-dealing-with-the-dark-web">Common mistakes when dealing with the dark web</h2><p>When dealing with the dark web, organizations tend to repeat the same mistakes regardless of industry or size.</p><p>Trying to pay their way out of the problem. Companies often approach ransomware or leaks as negotiation problems. In reality, paying a ransom guarantees neither recovery nor safety. According to a 2021 study by Cybereason, 80% of organizations that paid ransoms were attacked again, often by the same groups.</p><p>Treating dark web monitoring as insurance. Monitoring services are often marketed as proactive protection. In reality, if company data appears for sale on the dark web, the compromise has already happened. Monitoring can provide signals, but it cannot replace actual <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> controls.</p><p>Hiring dark web hackers to test infrastructure. Unlike legitimate penetration testing, anonymous dark web “audits” offer no accountability, verification, or compliance guarantees. Even worse, the hired hacker may establish unauthorized access and later resell it.</p><p>Panicking after seeing the company name on the dark web. Many leaks and listings are outdated, recycled, or entirely fabricated. Without proper verification, rushed decisions can worsen the situation.</p><p>Delegating the entire issue to “dark web specialists.” Many companies delegate dark web monitoring to external vendors without the ability to independently assess the quality of the results. This creates a dangerous information asymmetry and increases dependence on unverifiable claims. </p><h2 id="what-businesses-should-do-instead">What businesses should do instead</h2><p>Dark web intelligence can be useful as one additional source of signals, but it requires cautious interpretation and independent validation. Treating it as a reliable source of truth — or outsourcing the entire function without oversight — is risky.</p><p>More importantly, businesses should avoid directly financing criminal ecosystems through payments or participation in underground markets.</p><p>Cyber resilience is built internally. Rather than attempting to “buy security” on the dark web, organizations should invest in systematic defense: resilient architecture, vulnerability <a href="https://www.techradar.com/best/it-management-tools">management</a>, monitoring, incident response, and technologies capable of mitigating attacks while maintaining continuity of critical services.</p><p><em></em><a href="https://www.techradar.com/best/secure-file-transfer-solutions"><em>We've featured the best secure file sharing.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why operational technology risk still slips past the boardroom ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/why-operational-technology-risk-still-slips-past-the-boardroom</link>
                                                                            <description>
                            <![CDATA[ Boards need to start treating OT cyber risk as an issue of business continuity. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">EcvSXqhDCyZJkkoKy33aYY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 09:04:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Louise Bulman ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg">
                                                            <media:credit><![CDATA[sarayut Thaneerat/ via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:description>                                                            <media:text><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:text>
                                <media:title type="plain"><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Across the UK, <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> incidents have become a familiar feature of the business landscape. </p><p>Disruptions affecting manufacturing and logistics over the past year have underlined how exposed organizations can be when physical operations are connected and digitalized. </p><p>Despite this growing awareness, boardroom conversations on cyber risk still tend to center on corporate IT and not operational technology (OT).</p><p>That focus leaves a significant gap. Operational technology, the systems that run factories, manage supply chains and underpin essential services, is now a primary target for attackers. When these environments are compromised, the consequences extend far beyond lost <a href="https://www.techradar.com/pro/best-data-removal-services-of-year">data</a>, affecting safety, revenue and in some cases an organization's ability to operate at all.</p><p>For many boards, this is less a question of indifference and more one of framing. Cyber risk is still commonly understood through an IT lens, shaped by experiences  with data breaches or <a href="https://www.techradar.com/best/best-malware-removal">malware</a> attacks that take down websites or enterprise IT systems. Operational disruption behaves differently in both scale and impact, and it demands a different level of governance attention.</p><h2 id="why-ot-risk-is-routinely-underestimated">Why OT risk is routinely underestimated</h2><p>Much of today’s operational <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> was designed long before connectivity and remote access became standard. These systems were engineered for reliability and safety, not for defense against hostile actors. As they have become more connected and digitalized, exposure has increased without always being matched by equivalent <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> practices.</p><p>The result is that many of the most serious business risks now sit within operational environments that boards rarely examine in detail. This creates a structural blind spot. While IT incidents are often measured in hours or days, failures in OT environments can take longer to mitigate while halting production, disrupting critical services and generating losses that compound rapidly over time.</p><p>Boards tend to engage more effectively when risk is grounded in tangible business terms. Understanding what a facility produces in a day, or what a week-long shutdown would mean for customers and partners, brings operational risk into sharper focus. Without that context, OT security can remain abstract and under-prioritized.</p><h2 id="when-cyber-incidents-stop-operations">When cyber incidents stop operations</h2><p>Recent incidents have shown how quickly cybersecurity events can escalate into operational crises. Last year, a leading British automotive brand publicly confirmed a cyber incident that led to a precautionary shutdown of systems. Manufacturing and retail operations were halted for weeks and disruptions rippled through suppliers, logistics partners and dealerships </p><p>Similar lessons can be drawn from cyber incidents affecting the UK’s water sector, where attackers targeted environments connected to the operational systems that control treatment and distribution. Beginning in 2024, multiple incidents reached systems close enough to operational control to raise concerns about safe operation. </p><p>Taken together, these examples point to board-level issues beyond preventing down time or service outages. They are also about maintaining operational continuity, understanding how quickly localized disruptions can cascade across an organization, and factoring in safety concerns and reputational risk. </p><h2 id="a-risk-landscape-shaped-by-geopolitics">A risk landscape shaped by geopolitics</h2><p>Operational technology risk is increasingly shaped by global forces. Geopolitical tension, trade restrictions and supply chain uncertainty now influence how organizations plan and prioritize security investment. </p><p>At the same time, governments are raising expectations around resilience and incident reporting, particularly in sectors linked to national infrastructure. Boards are therefore required to consider regulatory and geopolitical pressures alongside technical risk, adding another layer of complexity to cyber governance.</p><h2 id="bringing-direction-and-discipline-to-governance">Bringing direction and discipline to governance</h2><p>Stronger oversight depends on education and structure. Boards should expect cyber leaders to explain operational risk in clear business terms and to reference recognized best practice. Focusing on a prioritized and manageable set of critical controls that deliver the greatest risk reduction provides a practical foundation without overwhelming the organization.</p><p>Governance cadence is just as important as control selection. Regular, structured engagement with senior management create space to track how security investment supports operational resilience and wider business outcomes. Treating cyber risk as a standing governance issue, rather than an occasional update, reinforces accountability and sustained attention.</p><p>Clear prioritization models can further support decision-making. Categorizing actions into those that must happen now, those that can follow next and those that should not be pursued helps align technical, operational and financial perspectives. A shared language of priority reduces ambiguity and supports more consistent execution across sites.</p><h2 id="a-leadership-obligation">A leadership obligation</h2><p>Operational technology security can no longer be treated as a technical niche. It has become a leadership responsibility shaped by operational dependence, external pressure and increasingly capable adversaries. Boards that recognize this shift are better positioned to protect continuity, revenue and trust.</p><p>Looking ahead, resilient organizations will be led by teams that engage directly with the realities of their industrial environments. Asking sharper questions, demanding clearer insight and ensuring governance structures keep pace with operational risk remain among the most effective safeguards leaders can provide.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>We've ranked and reviewed the best antivirus software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Watch out - that Microsoft Calendar invite dated 2050 could be hiding stolen files and worse ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/watch-out-that-microsoft-calendar-invite-dated-2050-could-be-hiding-stolen-files-and-worse</link>
                                                                            <description>
                            <![CDATA[ Check your calendars for entries far into the future - especially if you're an Israeli entity. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LjgKxK7hkjXzxZoDby7Pxa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NK6WMQwJZAmbq9SfRREf2f-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jul 2026 16:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NK6WMQwJZAmbq9SfRREf2f-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images / Westend61]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Top view of woman holding smartphone and tablet with calendar on desk]]></media:description>                                                            <media:text><![CDATA[Top view of woman holding smartphone and tablet with calendar on desk]]></media:text>
                                <media:title type="plain"><![CDATA[Top view of woman holding smartphone and tablet with calendar on desk]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NK6WMQwJZAmbq9SfRREf2f-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Group‑IB discovers HollowGraph malware targeting Israeli entities, exfiltrating files via Microsoft Graph API</strong></li><li><strong>Operators hide instructions in future calendar entries, then attach encrypted stolen data to events</strong></li><li><strong>At least 12 systems were compromised; overlaps with Lyceum noted but attribution remains low‑confidence</strong></li></ul><p>Cybercriminals have found a way to communicate with the malware installed on victim devices through compromised Microsoft Calendar apps, experts have warned.</p><p>Security researchers at Group-IB have <a href="https://www.group-ib.com/blog/hollowgraph-microsoft-365/" target="_blank" rel="nofollow">detailed</a> a newly discovered piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> called HollowGraph designed to exfiltrate sensitive files from compromised devices.</p><p>What makes the malware stand out is the way it communicates with its operators. The best way to spot hidden malware is to monitor the traffic flowing in and out of a device, which is why cybercriminals try their best to hide this traffic, or blend it with another, legitimate one. In that respect, HollowGraph is unique because it abuses Microsoft Graph API and a compromised Microsoft 365 mailbox calendar.</p><h2 id="a-dozen-victims">A dozen victims</h2><p>After landing on a device and compromising the Microsoft 365 account, HollowGraph uses that account’s permissions to access Microsoft Graph. Operators create calendar entries containing instructions and place them far into the future (in the year 2050) to avoid being spotted. After acting on the instructions and harvesting valuable information, the malware exfiltrates it through the same channel.</p><p>Instead of uploading files to a suspicious server, HollowGraph attaches encrypted stolen data to calendar events and sends it through Microsoft Graph. For defenders, all of this traffic seems legitimate and usually flies under their radars. </p><p>So far, all of the victims are Israeli entities, Group-IB said. The researchers identified at least 12 compromised systems, three of which were still actively communicating with the attackers’ infrastructure during the investigation.</p><p>The researchers did not attribute the attack to any known threat actor, but hinted at a potential. They identified technical similarities in command structures and plugin mechanisms between HollowGraph’s framework, Cavern, and a .NET backdoor used by Lyceum (an Iranian-nexus threat actor associated with OilRig). However, Group-IB explicitly emphasizes that these overlaps are not distinct enough, so they assess this link with low confidence.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'macOS users may face real, sophisticated threats that require neither exploits nor any elevated access to succeed': ClickLock Stealer tries to trick Apple users into revealing their passwords ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/macos-users-may-face-real-sophisticated-threats-that-require-neither-exploits-nor-any-elevated-access-to-succeed-clicklock-stealer-tries-to-trick-apple-users-into-revealing-their-passwords</link>
                                                                            <description>
                            <![CDATA[ ClickLock bores its victims into complying and then steals all sorts of data. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rTfuMcJQcWwgFKNJxEtbqi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[hacker hands at work with  interface around]]></media:description>                                                            <media:text><![CDATA[hacker hands at work with  interface around]]></media:text>
                                <media:title type="plain"><![CDATA[hacker hands at work with  interface around]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Group‑IB uncovers ClickLock, a new macOS‑focused infostealer using aggressive social engineering by spamming password prompts and terminating key apps every 210ms until victims comply</strong></li><li><strong>Once credentials are obtained, it exfiltrates browser data, crypto wallets, password manager entries, FTP configs, and device info via Telegram Bot API</strong></li><li><strong>Active since May 2026, spotted in 33 countries (mostly Europe), distributed via ClickFix campaigns, and initially undetected by security vendors until recently</strong></li></ul><p>Security researchers from Group-IB have uncovered a new infostealer targeting primarily macOS users in Europe.</p><p>Dubbed <a href="https://www.group-ib.com/blog/clicklock-stealer-macos-malware/" target="_blank">ClickLock</a>, it is more of an annoying social engineering mechanism rather than a full-blown malware variant, constantly popping up a login prompt on the victim’s device, until they finally comply and share the credentials. </p><p>Every 210 milliseconds it terminates key apps on the device (Finder, Dock, TErminal, etc.), essentially making it useless. At the same time, it keeps prompting a password dialog on the screen, making sure the victim can do nothing but provide the credentials.</p><h2 id="targeting-europeans">Targeting Europeans</h2><p>The loop is set to continue for more than three straight days, or until the victim folds. </p><p>After getting the keys to the kingdom, the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> gets to work and starts exfiltrating valuable information.</p><p>This includes data from key <a href="https://www.techradar.com/best/browser" target="_blank">browsers</a> (Chrome, Firefox, Brave, and others), saved logins, cookies, autofill data, and other browser information, data linked to cryptocurrency wallets and extensions, encrypted wallet vault material that can be cracked off-site, data from <a href="https://www.techradar.com/best/password-manager" target="_blank">password managers</a>, cached cryptocurrency addresses across EVM, Bitcoin, Solana, TRON, TON, and Stacks, shell histories, FileZilla FTP configuration and recent-server data, and basic device information.Everything is then packaged into a .ZIP archive and exfiltrated via a Telegram Bot API.</p><p>Group-IB says the campaign has been active since at least May 2026, so it’s been active for a few months now. A researcher submitted a variant to VirusTotal in early June, but it remained undetected by all security vendors until recently, Group-IB says.</p><p>So far, it has been spotted in 33 countries, more than half of which are in Europe, it was also added. The malware is most likely being distributed via a ClickFix social engineering campaign, and has not been tied to any particular threat actor. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Russian hacker turns Gemini CLI into a hacking agent, creates small-scale botnet ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/russian-hacker-turns-gemini-cli-into-a-hacking-agent-creates-small-scale-botnet</link>
                                                                            <description>
                            <![CDATA[ The hacker told the AI he was an authorized pentester - and the AI believed him. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2aLD452X3VLZeF4n8MnsB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PRCsQfoXPXi2t4jsGwWr6L-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jul 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PRCsQfoXPXi2t4jsGwWr6L-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A human shakes a robot&#039;s hand in front of blue concentric circles]]></media:description>                                                            <media:text><![CDATA[A human shakes a robot&#039;s hand in front of blue concentric circles]]></media:text>
                                <media:title type="plain"><![CDATA[A human shakes a robot&#039;s hand in front of blue concentric circles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PRCsQfoXPXi2t4jsGwWr6L-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Russian hacker “bandcampro” used Google’s Gemini CLI to control an eight‑device botnet at a dental clinic</strong></li><li><strong>The attacker tricked the AI by posing as a pen tester, directing it to migrate C2 infrastructure, troubleshoot connectivity, and prepare payload bundles</strong></li><li><strong>The AI assisted with daily operations like password guessing and WordPress access, highlighting risks of misuse when threat actors co‑opt AI tools</strong></li></ul><p>A Russian hacker and his AI companion were able to successfully control a miniature, eight-system botnet, with the hacker giving instructions in conversational language, and the AI doing his bidding, experts have found.</p><p>Analyzing 200 session logs obtained from the Russian-speaking threat actor known as “bandcampro”, cybersecurity researchers Trend Micro saw the hacker use Google’s Gemini CLI, an open source AI command-line tool that lets developers interact with Google's <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">Gemini AI</a> models directly from a terminal. </p><p>Scouring through a month’s worth of session logs (between April 21 and May 19 2026), the researchers discovered that the attacker tricked the AI by telling it they were an “authorized pen tester”. While the AI mostly complied with their nefarious overlord, they refused the orders on at least one occasion.</p><h2 id="gone-in-six-minutes">Gone in six minutes</h2><p>Trend Micro found the hacker controlled eight devices belonging to a dental clinic and sought to access their access their OpenDental database.</p><p>Using the AI, bandcampro did a number of things, starting with migrating the botnet to a new C2 infrastructure. He gave the AI a skill file with the full architecture description, standard operating procedures, infection one-liner, persistence commands, and troubleshooting steps.</p><p>He then told it to “study the C2 migration”, which had the AI process the guide and prepare all the code and necessary steps. It took the tool around six minutes to get the job done. </p><p>"The AI read the migration guide, then prepared a migration bundle, a small archive of server code, payloads, and the skill file. It then unpacked the bundle, launched the C&C server on a VPS, and brought up the Cloudflare tunnel," Trend Micro says.</p><p>Bandcampro then used the AI to troubleshoot connectivity issues, as well as for various daily operations, such as guessing passwords, generating plausible variants of existing passwords for WordPress portals, and more.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/google-gemini-cli-abused-as-a-hacking-agent-malware-botnet-operator/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hundreds of GitHub repos found posing as real software to push malware ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/hundreds-of-github-repos-found-posing-as-real-software-to-push-malware</link>
                                                                            <description>
                            <![CDATA[ Russian hackers are trying to sneak infostealers onto people's devices to grab passwords, crypto, and more. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dxoB3qPWwHz8vExitx7Zed</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jul 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phone malware]]></media:description>                                                            <media:text><![CDATA[Phone malware]]></media:text>
                                <media:title type="plain"><![CDATA[Phone malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>ArcticWolf uncovered 292 malicious GitHub repositories spoofing legitimate tools and products, delivering a new BoryptGrab infostealer variant</strong></li><li><strong>Malware steals from 19 browsers, 32 crypto wallets, messaging apps, Steam, and Windows Credential Manager, and uniquely bypasses Chrome’s App‑Bound Encryption via code injection</strong></li><li><strong>Most repos have been removed, but some remain active; GitHub’s popularity makes it a prime target, underscoring the need to vet code before use</strong></li></ul><p>Russian actors have reportedly created hundreds of malicious GitHub repositories masquerading as legitimate software but acting as a dangerous infostealer. </p><p>Cybersecurity researchers ArcticWolf discovered the campaign after finding their own products spoofed as part of the attack.</p><p>In total, the researchers found 292 fake repositories, spoofing things like security products, developer tools, macOS utilities, games, and more. Each repository contained a README file with the download URL.</p><h2 id="obviously-malicious">Obviously malicious</h2><p>Victims who download the program get a variant of the BoryptGrab infostealer family that grabs data from 19 browsers (<a href="https://www.techradar.com/best/password-manager" target="_blank">passwords</a>, cookies, payment information), 32 cryptocurrency wallets, Telegram, Discord, and Steam sessions, credentials for Meta’s Max, data from Windows Credential Manager, and more. It can also exfiltrate files from Desktop and Documents, and grab screenshots.</p><p>While most of the features can be found in other BoryptGrab variants, this one is unique in a sense that it can bypass Chrome’s App-Bound Encryption through direct code injection into the browser process.</p><p>While it hasn’t been specifically said that the threat actors are Russian, the compressed data is later sent to a Russia-based command-and-control (C2) infrastructure.</p><p>What’s also worth mentioning is that the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> is not designed to last. It has no anti-analysis layer, and doesn’t even try to hide itself in any specific manner. It does not establish persistence and simply tries to grab as much sensitive data as it can on the first attempt.</p><p>The attack, which seems to have started in the final days of June, is almost thwarted now, since most of the malicious repositories have been removed from GitHub. Citing “researchers”, <a href="https://www.bleepingcomputer.com/news/security/nearly-300-github-repos-pose-as-legit-software-to-push-malware/" target="_blank"><em>BleepingComputer</em></a> reported that several dozen still remain active, though. </p><p>Because of its importance and popularity in the open-source community, GitHub is currently one of the most targeted platforms on the internet, which is why it’s important to double-check and vet every piece of code before it’s applied to a project.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How parked domains became a cybercrime goldmine ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/how-parked-domains-became-a-cybercrime-goldmine</link>
                                                                            <description>
                            <![CDATA[ Forgotten by security teams, parked domains have quietly become cybercrime's most lucrative hiding place. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TMRpjDCenLo2Y8LXXvpcxE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jul 2026 13:37:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dr. Renée Burton ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phone malware]]></media:description>                                                            <media:text><![CDATA[Phone malware]]></media:text>
                                <media:title type="plain"><![CDATA[Phone malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Every day, millions of people type a web address into their browser, usually in a flurry of rapid keystrokes, and arrive exactly where they intended. </p><p>However, a small but significant number of people don’t. </p><p>They might miss a letter, type an extra letter in their haste, or get some letters mixed up. Instead of hitting linkedin[.]com, they hit linkdein[.]com. Those mistakes gave way to one of the internet’s least glamorous destinations – the parked domain.   </p><p>Most internet users have encountered them at some point, even if they didn't know what they were looking at. Typically, a parked domain would just be a sparse, messy page filled with adverts and a search bar with very little else. </p><p>They existed because someone, somewhere, recognized that in the early days of the internet a percentage of users would inevitably mistype a popular website – so they registered the most similar-looking <a href="https://www.techradar.com/news/best-domain-registrars">domain names</a> for themselves in a move known as “typosquatting” and earned advertising revenue from the resulting traffic. </p><p>If just 0.1% of the millions of people accessing amazon[.]com accidentally went to the amazn[.]com domain they’d bought, that’s still a worthwhile payday. It was a mundane corner of the digital economy, built on convenience, coincidence, and the occasional typo.</p><p>History can be a harsh teacher, but it can also sow complacency. In 2026, a lot of security teams still regard parked domains as little more than lazy digital billboards – inconvenient and annoying, but not a meaningful security concern. </p><p>However, the <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> surrounding parked domains has evolved considerably from the amateurish, pop-up-ridden advertising pages of the early internet. What was once a simple case of opportunistic domain monetization now sits inside a far more complex ecosystem of advertisers, brokers, and traffic distribution networks. </p><p>In many cases, a user's accidental visit no longer ends on a parked page at all. Instead, it triggers a journey through a chain of intermediaries operating largely out of sight. Somewhere along that journey, legitimate advertising can give way to fraud, scams, and <a href="https://www.techradar.com/best/best-malware-removal">malware</a> distribution. </p><p>In other words, one of the web's most familiar and overlooked mechanisms has become one of the most lucrative and insidious vehicles for cybercrime. </p><h2 id="from-mistype-to-malware">From Mistype to Malware </h2><p>The transformation of parked domains from digital curiosities into <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> risks has been subtle, and that’s one of the reasons it’s so dangerous. For decades, the model followed the same patterns – a user would land on a parked domain, see a collection of banners, click on something accidental or otherwise, and generate a small amount of revenue for the domain owner. </p><p>It was cynical, but at least it was transparent because users could at least see where they had ended up and decide for themselves what to do next – usually just close the tab and go where they meant to. The only real danger here came from the occasional misleading or malicious ad rather than the mechanics of the domain itself. </p><p>Today things are different. Changes within the online advertising industry, including tighter policies around traditional domain monetization, have encouraged cybercriminals and fraudsters to try new approaches to keep the train of monetization moving. </p><p>Increasingly, users who arrive at a parked domain don't encounter a parked page at all. Instead, they’re immediately redirected elsewhere through a process known as “zero-click advertising”, sometimes referred to as direct search. </p><p>What appears to be a simple typo can trigger a rapid auction in which a user's visit is bought, sold, and passed between multiple advertising partners before they ever see a destination website. Most of this activity unfolds in fractions of a second and entirely beyond the user's view, and while many of those transactions remain legitimate, the sheer complexity of the ecosystem creates opportunities for abuse. </p><p>Somewhere within that chain, traffic can be acquired by actors whose interests extend far beyond advertising revenue, opening the door to scams, malware, fraudulent software, and a host of other malicious outcomes. </p><h2 id="the-malvertising-economy">The Malvertising Economy</h2><p>One of the reasons parked domain abuse is still underestimated and difficult to pin down is that the attack path rarely follows a straight line. When most people imagine a cyberattack, they picture a malicious website waiting at the end of a link, ready to ensnare an unsuspecting user. </p><p>But in this case, by the time a user reaches the content they're ultimately shown, their traffic may have already passed through a maze of advertising exchanges, brokers, redirectors, and cloaking services. </p><p>Each participant sees only a fragment of the overall journey, making it remarkably difficult for the “good guys” to determine which “bad guys” are responsible for what. It’s a little like trying to investigate a crime scene where the evidence constantly rearranges itself.</p><p>The cowardly threat actors involved in this type of cybercrime exploit this ambiguity. They use sophisticated cloaking techniques which allow them to examine visitors before deciding which content to serve up – where are they based? What kind of browser are they using? What operating system is their device running? </p><p>A <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> researcher in California might see a harmless landing page, while a finance broker in London might be served up a credential harvesting scam. This selective delivery makes malicious activity harder to detect and even harder to reproduce. </p><p>What’s worse, parked domain abuse is rarely aimed at a specific industry or organization. The actors deploying parked domains are usually financially motivated, and their primary interest is in acquiring traffic, so they’re not going to discriminate. </p><p>Once they’ve ensnared a victim, they become a commodity moving through an invisible marketplace where every click has value and every redirection creates another opportunity for exploitation.</p><h2 id="the-blind-spot-in-traditional-security">The blind spot in traditional security</h2><p>So where does all of this leave defenders? Parked domain abuse doesn’t behave like a conventional cyber threat. While security teams are used to investigating suspicious websites, malicious files, or compromised accounts that leave a relatively obvious trail, parked domain campaigns are different because the underlying traffic distribution is constantly changing. </p><p>The same typo domain can send one user down an entirely different path than the next. By the time an analyst attempts to recreate what a victim experienced, the route may no longer exist and any “evidence” has effectively evaporated. How do they defend against something they can't see or recreate?</p><p>One thing is guaranteed – regardless of how many redirects, intermediaries, cloaking systems, or advertising platforms sit between the initial typo and the final destination, every step in the journey depends on the <a href="https://www.techradar.com/news/best-dns-server">domain name system (DNS)</a>. Often described as the internet's address book, DNS is responsible for translating domain names into the destinations users ultimately reach. </p><p>Put simply, each lookup leaves behind a breadcrumb that helps reveal relationships that would otherwise remain hidden, and that visibility has allowed researchers investigating typosquatted versions of well-known domains to follow the trail beyond the initial deception. Patterns start to emerge between seemingly unrelated cases of malware, involving the same parking providers, cloaking services, and traffic distribution infrastructure. </p><p>By examining historical DNS records and mapping the relationships between domains over time, it has become possible to connect incidents that appear to be unrelated and expose the networks operating behind them. Instead of playing “whack a mole” and chasing surface level domains, DNS mapping has allowed defenders to target the entire machine. </p><p>The greatest danger posed by parked domains isn't the typo itself, but the assumption that the infrastructure behind that typo is benign. For years, parked domains occupied a strange corner of the internet, largely ignored by security teams and rarely considered worthy of serious scrutiny. </p><p>But today, they offer cybercriminals something far more valuable than advertising revenue – access to legitimate systems, trusted business models, and vast streams of user traffic that can be manipulated and monetized at scale. </p><p>As threat actors continue to refine their use of cloaking, traffic distribution, and advertising networks, the distinction between legitimate online activity and malicious activity will become increasingly difficult to spot from the outside.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>Protect yourself against malware with the best antivirus software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts get Google, Microsoft to pull trusted ModHeader with 1.6 million installs after finding it could harvest all kinds of data ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-get-google-microsoft-to-pull-trusted-modheader-with-1-6-million-installs-after-finding-it-could-harvest-all-kinds-of-data</link>
                                                                            <description>
                            <![CDATA[ Visited domains were being exfiltrated to a third-party server, seemingly under a Chinese actor's control. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wBogsTgqZ6B4E5RonumGgf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/97XMVxvuGbBvxfxdd8VJqH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Jul 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/97XMVxvuGbBvxfxdd8VJqH-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Chrome, Edge, Safari, and Firefox browser apps on a mobile phone]]></media:description>                                                            <media:text><![CDATA[Chrome, Edge, Safari, and Firefox browser apps on a mobile phone]]></media:text>
                                <media:title type="plain"><![CDATA[Chrome, Edge, Safari, and Firefox browser apps on a mobile phone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/97XMVxvuGbBvxfxdd8VJqH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Stripe OLT found ModHeader v7.0.18 carried a hidden spyware SDK, exfiltrating visited domains daily to a Chinese‑owned server and acting as adware</strong></li><li><strong>The extension had 1.6M downloads across Chrome and Edge before being pulled but installed endpoints remain at risk</strong></li><li><strong>Researchers urge defenders to identify and remove existing installations, as removal from stores does not automatically remediate compromised devices</strong></li></ul><p>ModHeader, a trusted Chrome and Edge browser extension with more than 1.6 million downloads, was found to be malicious, apparently sending sensitive data to a Chinese-owned server, and has since been pulled on both repositories. </p><p>Security researchers Stripe OLT revealed the news in a new <a href="https://stripeolt.com/knowledge-hub/threat-research/chrome-extension-hidden-data-exfiltration-900k-users/" target="_blank">report</a>, outlining how a ModHeader build v7.0.18 carried a hidden <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">spyware</a> SDK. </p><p>As per Stripe OLT, the spyware collects domains users visit, encrypts the data with AES-GCP, and then sends it - once a day - to a remote server. The collector was found inactive by default, but the required code, encryption key, and upload schedule were all already embedded in the extension.</p><h2 id="links-to-chinese-actors">Links to Chinese actors</h2><p>Researchers found no command-and-control functionality, which means the server only receives the stolen data and cannot communicate back. The extension also worked as an adware, displaying ads and opening advertising tabs on updates, including on enterprise-managed devices.</p><p>The researchers attributed the attack, albeit with low confidence, to a Chinese-speaking threat actor. The exfiltration domain routes emails through Lark, which is a suite common with Chinese-speaking teams, it was said. They also found Chinese strings in the code, and said that the listing ships a Simplified Chinese locale. </p><p>ModHeader is a Chrome and Edge <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> extension that allows users to modify HTTP request and response headers sent between their browser and websites. Developers and security researchers use it to test APIs, troubleshoot applications, and simulate different environments. It has around 900,000 users on Chrome, and another 700,000 on Edge. </p><p>According to <a href="https://thehackernews.com/2026/07/google-and-microsoft-pull-modheader.html" target="_blank"><em>The Hacker News</em></a>, Microsoft pulled the tool from its repository on June 3 2026, followed by Google a week later, on July 10. </p><p>“Following our disclosure, Google has removed the extension from the Chrome Web Store,” Stripe OLT concluded. “We welcome this action, but removal from the store does not automatically remediate endpoints where the extension was already installed, so defenders should continue to identify and remove existing installations.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This new macOS infostealer poses as an Apple crash reporting tool to try and steal all your valuable data ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/this-new-macos-infostealer-poses-as-an-apple-crash-reporting-tool-to-try-and-steal-all-your-valuable-data</link>
                                                                            <description>
                            <![CDATA[ Researchers found a new piece of macOS malware grabbing passwords, crypto data, and more. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SbwjYKP7zxrLGTEJgE6gNe</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ctJuqMRzZN6mdeA4UPgdTd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Jul 2026 14:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ctJuqMRzZN6mdeA4UPgdTd-1280-80.jpg">
                                                            <media:credit><![CDATA[Herry Sucahya on Unsplash]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The menu bar running in macOS.]]></media:description>                                                            <media:text><![CDATA[The menu bar running in macOS.]]></media:text>
                                <media:title type="plain"><![CDATA[The menu bar running in macOS.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ctJuqMRzZN6mdeA4UPgdTd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Jamf researchers uncover “CrashStealer,” a notarized macOS infostealer disguised as Apple’s CrashReporter</strong></li><li><strong>Distributed via a fake site called “Werkbit Setup”, it bypasses Gatekeeper, installs a LaunchAgent</strong></li><li><strong>It then uses a fake password prompt to unlock Keychain, exfiltrating credentials, cookies, files, and data from 80 crypto wallets and 14 password managers</strong></li></ul><p>A new macOS infostealer has been spotted in the wild, masquerading as an Apple crash reporting tool, experts have warned.</p><p>Called CrashStealer, this C++ infostealer was designed to nab login credentials, keychain information, as well as data related to more than 80 cryptocurrency wallets.</p><p>Cybersecurity researchers Jamf published an in-depth <a href="https://www.jamf.com/blog/crashstealer-macos-infostealer-analysis/" target="_blank">report</a> on the malware, noting CrashStealer is most likely distributed via a fake software site that was only registered recently.</p><h2 id="unlocking-keychain">Unlocking Keychain</h2><p>Victims who land on the site (either via a social media recommendation or search engine results) need to know the PIN code before initiating the download. This was most likely done to avoid analyst scrutiny, as well as to increase perceived credibility and a sense of exclusivity.</p><p>Usually, apps downloaded from third-party sources are scanned by Gatekeeper, Apple’s built-in security system. However, Jamf says that this payload is delivered via a signed and Apple-notarized installer and distributed as a disk image named “Werkbit Setup”, which allowed it to bypass Gatekeeper without any warnings.</p><p>Those that download and run the program will get a binary named ‘CrashReporter.app’, which will create a LaunchAgent (‘com.apple.crashreporter.helper’), and will see a fake macOS password prompt.</p><p>That prompt unlocks the user’s Keychain where most of their secrets are stored (passwords, private cryptographic keys, and more) and then exfiltrates all information to a third-party server. </p><p>Besides Keychain data, the CrashReporter <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> also pulls browser credentials and cookies from most browsers, data from 80 cryptocurrency wallet extensions, 14 <a href="https://www.techradar.com/best/password-manager" target="_blank">password managers</a>, locally stored files, and more. </p><p>Jamf said CrashReporter overlaps, to some extent, with other known infostealers (AMOS, for example), but is still unique enough given its client-side encryption mechanism, as well as the native C++ implementation.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Five reasons switching from IP VPN to SD WAN will help you build an AI-ready network ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/five-reasons-switching-from-ip-vpn-to-sd-wan-will-help-you-build-an-ai-ready-network</link>
                                                                            <description>
                            <![CDATA[ The scale, speed and complexity of modern cloud and AI workloads demand SD WAN. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KBrWATibJQLupbVHbsHQCH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MuH6FdnCJqsnobznT3LSEM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Jul 2026 10:21:45 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Laura Farina ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MuH6FdnCJqsnobznT3LSEM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A digital representation of the globe in blue]]></media:description>                                                            <media:text><![CDATA[A digital representation of the globe in blue]]></media:text>
                                <media:title type="plain"><![CDATA[A digital representation of the globe in blue]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MuH6FdnCJqsnobznT3LSEM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In the early 2000s, IP <a href="https://www.techradar.com/vpn/best-vpn-for-business">VPN</a> was the enterprise networking technology of choice for IT leaders. </p><p>MySpace was the go-to social network, we used Skype for video calls, we listened to music on our new MP3 players and the Nokia 1100 was the most popular mobile handset. </p><p>It feels like a different era entirely, yet many businesses are still running on legacy networks that were perfect for their needs back then but are now holding them back. </p><p>By today’s terms, networks were built for low levels of traffic. Cisco estimates global IP traffic levels were around 175 petabytes per month in 2001. Compare that to today’s figure, which is around 522,000 petabytes per month, or approximately 3000 times higher than 2001 levels, and you can understand why 87% of businesses in an Accenture study believe their legacy network is compromising their ability to advance on cloud, data and AI and digital transformation. </p><p>Untangling and replacing the complex web of enterprise networks built up over years is an unavoidable and costly necessity. It’s a bit like replacing the windows in your home - you know you’ll improve <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>, stormproof your home and cut energy costs by upgrading, but the process feels like a hassle. </p><p>Today, IT leaders aren’t just ‘replacing the windows’ by modernizing outdated networks; they’re going further and building high capacity, low latency, secure architectures designed to withstand the explosive demands of <a href="https://www.techradar.com/best/best-ai-tools">AI</a>.</p><h2 id="making-the-move-to-sd-wan">Making the move to SD WAN</h2><p>Millions of businesses are switching from IP VPN to Software-Defined Wide Area Networks, or SD WAN. Strong market growth is forecast in SD WAN, with one market forecast anticipating SD WAN CAGR of almost 40% (38.9%) from 2023 to 2030. </p><p>This growth is being driven by multiple factors including a shift to cloud-native architectures; a change in workplace practices and rise in remote working environments; and strong demand for network architectures that can manage current and future AI-related applications and services.  </p><p>SD WAN is faster, more cost effective and more secure, with built in <a href="https://www.techradar.com/best/ztna-solutions">zero trust</a> protection. It’s purpose built for distributed users and for managing cloud, AI workloads, data flows, and SaaS traffic. </p><p>But, to be truly AI ready, <a href="https://www.techradar.com/best/best-infrastructure-management-service">IT infrastructure</a> must be software driven, and this is where SD WAN excels: it gives your business the security, flexibility, and reliability needed to operate confidently in an AI driven future. Here are five ways switching to SD WAN will help you build an AI-ready network:</p><h2 id="1-built-for-ai-scale-performance">1.Built for AI-scale performance</h2><p>High-bandwidth, low latency SD WANs are critical for the delivery of AI workloads, particularly as businesses move towards AI inference. They provide fast access to <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud services</a> and dynamic bandwidth allocation as they monitor network conditions and reroute over the best available path. </p><p>For example, imagine a drive-through restaurant that uses an AI voice to take and relay orders or a supermarket that uses an AI model to scan shelves in its store, to detect gaps in stock, alert staff and predict which items will run out next. A high-performance, low latency network is essential here to guarantee a seamless <a href="https://www.techradar.com/best/cx-tools">customer experience</a>. </p><p>SD WAN’s application-aware routing levels this up even further, prioritizing AI traffic and deprioritizing the transfer of, for example, bulk file transfers or back-ups. </p><h2 id="2-security-that-matches-today-s-threat-landscape">2.Security that matches today’s threat landscape</h2><p>The global cyber attack surface has expanded dramatically. AI now plays a dual role, enabling more sophisticated attacks while also powering new, advanced defense capabilities. Traditional IP VPNs offer traffic <a href="https://www.techradar.com/best/best-encryption-software">encryption</a> but lack native security features. In contrast, SD WAN is built to protect modern networks from today’s high volume, highly sophisticated cyber threats:</p><p>- Zero trust access protects users, devices and applications</p><p>- Traffic is encrypted end to end, so that all data between sites, platforms and applications is secure</p><p>- Threat prevention at the edge protects core infrastructure from threats, with features such as intrusion detection and prevention, <a href="https://www.techradar.com/best/best-malware-removal">malware</a> scanning and <a href="https://www.techradar.com/news/best-dns-server">DNS</a> security</p><p>- Automated real-time security updates with threat intelligence pushed globally within minutes</p><h2 id="3-cloud-connectivity-without-compromise">3.Cloud connectivity without compromise</h2><p>SD WANs provide direct, optimized access to major cloud environments, such as Microsoft Azure, <a href="https://www.techradar.com/news/aws">AWS</a>, and Google Cloud, by using automated secure tunnels and intelligent path selection. </p><p>This ensures cloud and AI services run with lower latency, higher performance, and more reliable connectivity. Also important to note is that SD WANs provide high levels of autonomy and <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a>, so it’s easy to make changes quickly and easily as businesses navigate dynamic market conditions. </p><h2 id="4-data-insights-that-power-automation">4.Data insights that power automation </h2><p>SD WAN captures real-time data including latency, packet loss and application usage patterns – data which can be fed into AI-based network monitoring, automation and predictive <a href="https://www.techradar.com/best/best-maintenance-management-software">maintenance management</a> tools, so that networks become self-optimizing, self-healing and proactively secure.</p><h2 id="5-a-foundation-ready-for-sase-and-zero-trust">5.A foundation ready for SASE and Zero Trust</h2><p>When combined with Secure Access Service Edge (SASE), SD WAN creates a single, secure, high performance network foundation that’s built to drive AI opportunities while protecting against cyber risks with integrated security solutions including zero trust, secure web gateways and cloud firewalls. </p><p>SASE is a cloud based networking and security framework that combines SD WAN with integrated security services (like Zero Trust, secure web gateways, and cloud firewalls) into a single unified architecture. It’s the gold standard of AI-ready architecture.</p><p>As enterprises accelerate toward an AI driven future, the networks that once served them well are now becoming a barrier to progress. SD WAN offers a clear path forward: a software defined, secure, high performance foundation built to handle the scale, speed and complexity of modern cloud and AI workloads. </p><p>By making the shift now, businesses can replace aging infrastructure with an agile, intelligent network that not only supports today’s demands but unlocks the full potential of tomorrow’s AI innovation.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>We've ranked and reviewed the best antivirus software available</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p><h2 id=""></h2>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Japan's largest taxi operator Nihon Kotsu hit by cyberattack which forces systems to be shut down ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/japans-largest-taxi-operator-nihon-kotsu-hit-by-cyberattack-which-forces-systems-to-be-shut-down</link>
                                                                            <description>
                            <![CDATA[ Nihon Kotsu suffers malware attack, but there's no evidence of data exfiltration yet. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5vBZ3jEmoQgQq6pxgNJU6X</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JFKDCP2HdEKqSGJCkLNprB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Jul 2026 09:24:11 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JFKDCP2HdEKqSGJCkLNprB-1280-80.jpg">
                                                            <media:credit><![CDATA[Forcepint]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[IA y ciberseguridad]]></media:description>                                                            <media:text><![CDATA[IA y ciberseguridad]]></media:text>
                                <media:title type="plain"><![CDATA[IA y ciberseguridad]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JFKDCP2HdEKqSGJCkLNprB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Japan’s largest taxi operator confirms July 11 malware attack forcing shutdowns of its IT systems and disrupted dispatch and reservation services</strong></li><li><strong>Nihon Kotsu isolated networks, notified authorities, and brought in third‑party experts; customers were advised to use alternative taxi apps during the outage</strong></li><li><strong>No data leaks have been confirmed, but Nihon Kotsu warned it may disclose and notify affected parties if evidence of personal information exposure emerges</strong></li></ul><p>Japan’s largest taxi operator, Nihon Kotsu, hasconfirmed suffering a cyberattack which forced it to temporarily shut down parts of its IT infrastructure.</p><p>In a statement published on the company’s Japanese website, Nihon Kotsu said the attack took place in the early morning of July 11 - on a Saturday, when unnamed threat actors infected its devices with malware.</p><p>“We have recently discovered that our internal systems have been subjected to unauthorized external access (<a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware infection</a>),” the machine-translated statement reads. “We deeply apologize for the great inconvenience and concern caused to our customers, business partners, and all related parties due to this incident.”</p><h2 id="services-unavailable">Services unavailable</h2><p>As soon as it spotted the intrusion, Nihon Kotsu did what most companies do - shut down its network to prevent further damage, notified relevant law enforcement and data protection authorities, and brought in third-party experts to assess the damages and assist with the repairs.</p><p>The shutdown means some customer-facing services are unavailable: “As a result, the hire car web order and reservation management system, taxi dispatch service by phone, and some internal systems are temporarily unavailable,” the company said. </p><p>It advised its customers to use a different taxi app, which allows users to choose a taxi service to their liking. </p><p>So far, there is no evidence of any data exfiltration, or leaks to the dark web. However, the company did leave it as a possibility. </p><p>“At this time, no information leakage has been confirmed, but if any leakage or possibility of personal information of customers or related parties is newly discovered, we will promptly make official announcements and contact the affected parties individually in accordance with laws and regulations,” the company concluded.</p><p>Nihon Kotsu is Japan’s largest taxi operator, employing more than 18,000 people and running a fleet of more than 8,500 taxis and more than 2,000 chauffeur vehicles.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/japans-largest-taxi-operator-shuts-systems-after-cyberattack/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The new rules of software supply chain security: visibility, vigilance, validation ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/the-new-rules-of-software-supply-chain-security-visibility-vigilance-validation</link>
                                                                            <description>
                            <![CDATA[ Software supply chain security is fast becoming a business-critical priority. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">c8Dxf5VhTRoXfkMpwcVx5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Jul 2026 08:56:46 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jon France ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:description>                                                            <media:text><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:text>
                                <media:title type="plain"><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The global digital economy runs on a thriving ecosystem of third-party vendors, enabling organizations to scale and innovate faster than they possibly could do on their own. </p><p>This digital ecosystem is teeming with software suppliers, not just <a href="https://www.techradar.com/best/best-small-business-software">business software</a> that you can buy but also a vast array of software libraries that are embedded in third-party products. </p><p>Speed, however, can sometimes be the enemy of risk, as many organizations have not adequately validated whether these third-party technologies are sufficiently safeguarded against cyber threats and other digital risk. </p><p>So, while software is a great enabler, it also brings risk, given that it often is built with frameworks and libraries that are not known or well supported. </p><p>Consider that companies employ an average of 106 SaaS apps within their IT environments , and the picture becomes quite clear: software supply chain security is a serious concern. </p><p>It’s no wonder that half (51%) of participants in the latest Supply Chain Risk Survey ranked software vulnerabilities in supplier products as the most disruptive <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> threat to their organization’s supply chain, behind only data breaches (64%) and <a href="https://www.techradar.com/best/best-malware-removal">malware</a> or <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a> (52%).</p><p>An ever-changing attack surface that comprises <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud services</a>, micro-services, APIs, SaaS platforms, third‑party services and now AI agents has expanded well beyond what once was an understood perimeter before widespread digital transformation took hold. </p><p>How secure is your own extended digital ecosystem? If this question makes your heart race, then take a closer look at three key considerations for addressing software supply chain security.</p><h2 id="1-visibility-determine-what-s-actually-in-your-multi-layered-supply-chain">1. Visibility: Determine what’s actually in your multi-layered supply chain</h2><p>Since the software supply chain is part of a vast, interconnected digital ecosystem, organizations likely do not have full visibility of what and who make up their third-party providers. Recent high-profile incidents have signaled just how fragile supply chains can be. </p><p>Assuring business continuity requires organizations to scrutinize partners before placing such deep trust in them. That effort starts with knowing who is in your interconnected digital ecosystem before you can start to manage the risk. </p><p>Understanding risk across a supply chain is conceptually easy, but it is practically difficult. While clearly outlining security parameters and requirements in supplier contracts is a great starting point, it is not enough, as contracting is generally a point-in-time activity and should be paired with monitoring. You must be able to see and measure <a href="https://www.techradar.com/best/best-software-asset-management-tools">software assets</a> so you can better manage them. </p><p>After all, you can’t protect what you can’t see, and many businesses still don’t have a complete, accurate asset inventory, meaning that their vulnerability exposure is incomplete. If you don’t know what systems, apps, devices and libraries are in your environment, vulnerability management is supposition, inference and guesswork. </p><p>It is crucial to understand what your suppliers are doing both upstream and who you supply downstream, because their decisions are now part of your organization’s own risk profile. Software often presents the biggest blind spots in asset management, thanks in large part to a lack transparency in software build and dependencies, shadow IT, shadow AI and unmanaged endpoints. </p><p>An organization's exposure is tied directly to the security posture of every supplier they rely on. Attackers know this, increasingly targeting upstream or downstream partners. You can secure your own environment perfectly and still be vulnerable through others’ oversight. Tools that can profile, quantify and score risk across the supply chain, therefore, are essential, as is tooling that monitors for unusual activity.</p><h2 id="2-vigilance-prioritize-the-security-of-ai-integrations-across-your-software-supply-chain">2. Vigilance: Prioritize the security of AI integrations across your software supply chain</h2><p>Threats can lurk anywhere and everywhere across your supply chain. But there’s a new kid in town: AI. The software supply chain has expanded to include the unique risks of AI ecosystem, such as reliance on external foundational models and highly connected agents. </p><p>This escalating integration of <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> makes the multi-faceted software supply chain even more of a concern. Cybersecurity professionals who participated in the latest Cybersecurity Workforce Study  revealed a troubling AI-related security event their organization experienced in that prior year: data poisoning (cited by 11%). </p><p>Data poisoning happens when bad actors intentionally insert corrupted, misleading or malicious data into the training dataset of a machine-learning model. Even a small amount of poisoned data can change the model’s behavior, in turn resulting in misclassifications, degraded accuracy or malicious outcomes. So suddenly that seemingly helpful <a href="https://www.techradar.com/pro/best-ai-chatbot-for-business">ChatBot</a> that is embedded in your <a href="https://www.techradar.com/best/the-best-crm-software">CRM</a>, <a href="https://www.techradar.com/best/cms">CMS</a> or other purpose-driven enterprise software may not be so friendly after all!</p><p>Indeed, organizations simply have little / no control over the software that suppliers are using, making it much more difficult to ensure vulnerabilities are identified before widespread rollout, as well as supported and patched once deployed, but they do have control over scrutinizing suppliers. </p><p>Therefore, the people on your <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> team and the processes they follow matter more than ever. Technology accelerates both sides of the fight, so your real advantage comes from having skilled practitioners who understand how AI changes your risk profile, attack surface and can put the right controls in place to compensate. </p><p>Cybersecurity professionals who specialize in software supply chain security can quantify the risk of model poisoning / steering, prompt injection and model inversion, and assess the inherent bias of pre-trained open-source models, protecting the integrity of software and services from upstream vulnerabilities. Such a holistic approach ensures that every component, from third-party libraries to the training data itself, meets the organization’s security and ethical standards.</p><p>In addition, reviewing and evaluating vendor agreements is an important task for cybersecurity teams and stakeholders. Think of these disciplined actions as a necessary stress-test meant to identify and address weaknesses and changing needs. A good contract with clear deliverables and expectations is part of a cybersecurity defensive strategy alongside your people and your defense technologies and ongoing monitoring of systems and services.</p><h2 id="3-validation-adopt-skills-frameworks-and-codes-of-practice-for-software-supply-chain-security">3. Validation: Adopt skills frameworks and codes of practice for software supply chain security</h2><p>No organization must stand up against the heightened threat of software supply chain security alone. Take advantage of existing guidance such as the U.K.’s Software Security Code of Practice to follow when you’re trying to batten the software hatches at your own organization. </p><p>Not only does this code support software vendors as they adopt secure software lifecycle development practices; it also supports software customers in mitigating the likelihood and impact of software supply chain attacks.</p><p>In addition to following code and other guidance frameworks, organizations can look to skills frameworks and vendor-neutral certifications to validate that their cybersecurity professionals demonstrate certain skills needed to build and strengthen supply chain security and resilience. </p><p>Skills development in the disciplines of governance, risk and compliance (GRC), secure software development and AI skills better enable cybersecurity and risk professionals to make informed decisions regarding software supply chain security and risk management. </p><h2 id="from-complexity-to-better-security">From complexity to better security</h2><p>Supply chains are complex, longer than you think and multidimensional. Organizations must place much greater focus on stress-testing the resilience of software suppliers and continuously evaluating exposure. </p><p>This approach goes well beyond being careful about what software makes it all the way to procurement. The potentially more damaging layer to address in the macro supply chain involves the embedded software and integrated AI tools that other suppliers are using.</p><p>The question is not whether your digital supply chain will face disruption. It's whether you have the visibility, vigilance and validation to operate when it does. That’s resilience: the north star of software supply chain security. Without question, transparency has to run through supply chains instead of just sitting inside organizations.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've rounded up the best endpoint protection software suites</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Vibe coded threats shift again — hackers are using AI chatbots to write malware using natural language ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/vibe-coded-threats-shift-again-hackers-are-using-ai-chatbots-to-write-malware-using-natural-language</link>
                                                                            <description>
                            <![CDATA[ How do you spot an attack when signatures and behaviors can no longer be used? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7FaiGdV8mykwMcDLSkT3n9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/G8QNviZt3KrDbfWVANJrNM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 13 Jul 2026 15:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/G8QNviZt3KrDbfWVANJrNM-1280-80.jpg">
                                                            <media:credit><![CDATA[Elchinator from Pixabay ]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[malware]]></media:description>                                                            <media:text><![CDATA[malware]]></media:text>
                                <media:title type="plain"><![CDATA[malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/G8QNviZt3KrDbfWVANJrNM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Huntress analyzed AI‑generated malware “Untitled1.ps1,” a noisy custom AD enumeration tool likely built by low‑skilled attackers using generative AI</strong></li><li><strong>Attackers paired it with s5cmd for rapid data exfiltration and SharpShares.exe for share enumeration before being detected and removed</strong></li><li><strong>Report warns AI “vibe coding” lowers barriers for cybercrime, producing unique payloads that evade signature‑based defenses, requiring behavioral analytics to catch attack lifecycles</strong></li></ul><p>“Unsophisticated” cybercriminals can now easily write malicious code using Artificial Intelligence (AI) and run devastating data breach attacks with speed, forcing defenders to rethink their strategies, researchers have claimed. </p><p>Security experts Huntress thoroughly investigating a piece of AI-written <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, and <a href="https://www.huntress.com/blog/ai-coded-malware-vibe-coding-active-directory" target="_blank">explained</a> how the bespoke, AI-generated payload was a “highly aggressive, noisy, custom-built AD enumeration tool.”</p><p>Since cybercriminals are generally careful not to make too much noise and to try and do their bidding without raising any alarms, the researchers hint this was the work of a low-skilled attacker.</p><h2 id="significant-challenge">Significant challenge</h2><p>The malware, labeled Untitled1.ps1, was designed to map the Active Directory environment and apparently, it did its job well. In the next step, the crooks deployed a legitimate high-speed command-line tool for Amazon S3 operations called s5cmd which, according to Huntress, is often used for data exfiltration.</p><p>Before being spotted and kicked out, the attackers also deployed a known enumeration tool called SharpShares.exe, filtering common administrative shares while hunting for further user-accessible data repositories. </p><p>The move from off-the-shelf frameworks to custom, bespoke AI tools is a “significant challenge” for the defenders, Huntress warns. </p><p>“Historically, AVs and EDR platforms have relied heavily on file hashes and static string signatures,” they say. “Vibe-coded scripts are inherently unique. Untitled1.ps1 has never existed before and will likely never be compiled in this exact configuration again.”</p><p>As a result, defenders must focus on the “fundamental behaviors of the attack lifecycle.” AI can change the code syntax, they’re saying, but cannot change the underlying mechanics of <a href="https://www.techradar.com/pro/best-active-directory-documentation-tool-of-year" target="_blank">Active Directory</a> enumeration. </p><p>“Vibe coding lowers the barrier to entry for cybercrime, allowing unsophisticated actors to generate highly capable, evasive tooling on the fly,” the researchers concluded. “While the code itself may be messy, over-engineered, and filled with AI hallmarks like left-behind comments, the threat it poses is very real. To combat this, defenders must abandon rigid, signature-based thinking and embrace behavioral analytics to catch the underlying actions that no LLM can hide.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft discovers new multi-malware package 'GigaWiper' capable of deploying wipers and ransomware ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/microsoft-discovers-new-multi-malware-package-gigawiper-capable-of-deploying-wipers-and-ransomware</link>
                                                                            <description>
                            <![CDATA[ One wiper can destroy a computer in different ways, but it can also spy on users. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6JU6gwuxmJ5p8jKNCQnPq5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Jul 2026 16:50:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[hacker hands at work with  interface around]]></media:description>                                                            <media:text><![CDATA[hacker hands at work with  interface around]]></media:text>
                                <media:title type="plain"><![CDATA[hacker hands at work with  interface around]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft warns of “GigaWiper,” a destructive malware attributed to Iranian group CyberAv3ngers that combines multiple variants into one</strong></li><li><strong>It can wipe drives, encrypt files with a fake ransomware extension, or overwrite Windows partitions, while also spying via screenshots, VNC sessions, and system data theft</strong></li><li><strong>The malware hides under fake OneDrive tasks and registry keys, showing both espionage and sabotage capabilities with no recovery path for victims’ data</strong></li></ul><p>Microsoft is warning about a new piece of malware called GigaWiper, which can spy on people’s computers and then destroy them entirely, in different ways.</p><p>It was built by mashing different <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> variants into one, and it seems to be the work of Iranian state-sponsored threat actors called CyberAv3ngers. The hackers also took a little cheeky dig at Microsoft, through the malware’s obfuscation mechanism.</p><p>As Microsoft <a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="nofollow">explained</a>, GigaWiper can overwrite the physical drive and wipe the partition table, destroying the contents of the disk directly. It can also encrypt all files on the drive, add a .candy extension, and change the desktop wallpaper to show a warning. This ransomware approach does not share a ransom note, and does not generate a decryption key, so there is nothing to pay, and no way to decrypt the files - they are gone for good, just giving victims false hope.</p><h2 id="spying-on-the-victims">Spying on the victims</h2><p>Finally, the third method goes straight for the Windows drive, overwriting it multiple times with different data patterns. </p><p>Besides bricking the disk, GigaWiper can also spy on its victims by grabbing screenshots, recording the screen, or opening a VNC session to either stream someone else’s work, or allow the attackers to use the mouse and keyboard. The malware can also extract system data, manage programs and services, modify the registry, and more. </p><p>But the cheekiest feature is how it hides. It schedules a task called OneDrive Update and tracks itself in a registry key called OneDrive\Environment. Perhaps the attackers assumed no one really pays attention to <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">OneDrive</a>, and thus the malware could stay out of sight for longer. </p><p>Speaking of the attackers, Microsoft does not name them, but most of the components mashed together to form GigaWiper were previously attributed to CyberAv3ngers, a group linked to Iran's Islamic Revolutionary Guard Corps.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This malicious Google Notes extension just wants to sneakily steal all your crypto ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/this-malicious-google-notes-extension-just-wants-to-sneakily-steal-all-your-crypto</link>
                                                                            <description>
                            <![CDATA[ Another clipboard jacker was found in the wild, on the prowl for people's crypto. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TgqEFku9ZNa9fNUkZbYTj9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VnoVVXTmAmxSBYBe4LUwVW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Jul 2026 11:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VnoVVXTmAmxSBYBe4LUwVW-1280-80.jpg">
                                                            <media:credit><![CDATA[vjkombajn/Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image credit: Pixabay/vjkombajn]]></media:description>                                                            <media:text><![CDATA[Cryptocurrencies]]></media:text>
                                <media:title type="plain"><![CDATA[Cryptocurrencies]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VnoVVXTmAmxSBYBe4LUwVW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>McAfee flags “Silent Swap,” a malicious Chromium extension disguised as Google Notes that secretly hijacks crypto transactions</strong></li><li><strong>It works as a clipboard jacker, swapping copied wallet addresses with attacker‑controlled ones so victims unknowingly send funds to criminals</strong></li><li><strong>Researchers advise always cross‑checking full wallet strings before sending, as attackers can craft lookalike addresses differing only in a few characters</strong></li></ul><p>Researchers have found yet another extension for Chromium-based browsers that is designed solely to steal people’s hard-earned cryptocurrency.</p><p>A <a href="https://www.mcafee.com/blogs/other-blogs/mcafee-labs/crypto-clipper-wallet-swapping-browser-extension-malware/" target="_blank" rel="nofollow">report</a> from McAfee has sounded the alarm on Silent Swap, a piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> hiding inside a benign-looking Google Notes extension.</p><p>Victims who stumble upon and download it (most likely through phishing, social engineering, or shady forums and websites), will get an extension that, on the surface, works as intended. It shows a small window where the victim can type a note and save it. They can color-code the notes and search through saved ones. However, this was only made to hide the program’s true intentions, which are to steal cryptocurrency.</p><h2 id="hijacking-the-clipboard">Hijacking the clipboard</h2><p>Silent Swap works like a typical clipboard jacker. It monitors the clipboard for strings that look like a <a href="https://www.techradar.com/news/best-bitcoin-wallets" target="_blank">crypto wallet</a> - seemingly random strings of 26 to 42 alphanumeric characters. </p><p>When it spots one, it replaces it with a different one belonging to the attacker, so when the victim pastes the address into the wallet to send the funds, they are actually sending them to the address belonging to the attackers.</p><p>This works because crypto wallets are almost impossible to memorize, and too risky to type in from a piece of paper or a different document, forcing users to rely on copying and pasting. </p><p>Once the victim sends the funds, they are almost certainly irretrievably gone. Only if the funds are being sent from a centralized exchange (like Coinbase, for example), and if the victim spots the attack fast enough, can they ask the exchange’s support to freeze the transaction. In all other cases, once the money is sent, it’s gone.</p><p>The best way to defend against these attacks is to cross-reference the strings before hitting send. Some people would only check the first and last few characters, but security researchers don’t recommend it, because some clipboard jackers can generate addresses that only differ in a few characters.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How AI is taking IoT security to the next level ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/how-ai-is-taking-iot-security-to-the-next-level</link>
                                                                            <description>
                            <![CDATA[ AI is redefining how organizations protect and manage connected devices. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BwU5d5Knz43h6RHYPL7LC3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/euoWA3SymQA2cKKjmF37W4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Jul 2026 10:28:27 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Iain Davidson ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/euoWA3SymQA2cKKjmF37W4-1280-80.jpg">
                                                            <media:credit><![CDATA[The Register]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wi-Fi]]></media:description>                                                            <media:text><![CDATA[Wi-Fi]]></media:text>
                                <media:title type="plain"><![CDATA[Wi-Fi]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/euoWA3SymQA2cKKjmF37W4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The IoT and <a href="https://www.techradar.com/best/best-ai-tools">AI</a> are a likely partnership: IoT generates and captures data, often in large volume, AI is ideally placed to analyze it. </p><p>Combined, AIoT presents new opportunities, so much so that Transforma Insights forecasts no fewer than 9.1 billion AIoT connections at the end of 2033, a more than six-fold increase in 10 years. </p><p></p><p>The potential for AI in the IoT is far-reaching, and one standout application is enhanced security.</p><h2 id="the-security-risk-to-the-iot">The security risk to the IoT </h2><p>All connected devices are under growing levels of threat, but the IoT is particularly targeted. According to Beaming’s cyberthreat report into UK businesses, IoT devices were most frequently attacked in 2024. They are attractive targets for the data they exchange and their potential to be compromised. </p><p>The devices are often unmanned and generally sit outside corporate <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> perimeters. They may be in remote spots, where they could be subject to unauthorized physical access attempts, and often remain in place for long periods of time. Many, such as the IoT devices used in energy, transport, utilities and retail, transfer sensitive data of high value. </p><p>Businesses need confidence that data collected through the IoT—both real-time and historical—comes from secure and trusted sources, not least when it comes to developing and training AI models. In this, the IoT works with digital twins, which are digital representations of physical objects or systems. </p><p>The IoT enables the seamless flow of real-world data between the physical and the digital, while the digital twin’s attributes provide the features for AI modelling. Historical data collected through IoT is then used to train and refine the AI model. </p><h2 id="how-ai-is-helping-secure-the-iot">How AI is helping secure the IoT</h2><p>AI applies its <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a> and analytical capabilities to many tasks and priorities. It is making inroads into cybersecurity, something that has not gone unnoticed. Last year, the IEEE revealed almost half of the global technology leaders it surveyed (47%) expect vulnerability identification and attack prevention to be a top use of AI in 2026. </p><p>That may be some comfort to enterprises and connectivity and solutions providers grappling with the problem of protecting IoT devices and applications. This challenge is compounded by the fact that attackers are increasingly using AI themselves to automate phishing, accelerate reconnaissance and develop adaptive <a href="https://www.techradar.com/best/best-malware-removal">malware</a> that evades traditional detection. However, it is more comforting still, that AI is already making a difference in the IoT, redefining how organizations protect their devices. </p><p>AI-powered anomaly and threat detection (ATD) is helping security teams identify threats like suspicious network traffic and botnet activity faster and improving resilience across large-scale IoT environments, something enterprises must strive for. </p><p>In the recent past, the focus on the IoT was arguably getting devices online. That is no longer the challenge; the test now is keeping them operational: compliance readiness and the flexibility to adapt to ever-evolving commercial and technological changes. It also means maintaining resilience. </p><p>IoT security must follow a clear defend against, detect and react approach to swiftly counter attacks. No one or two of these three measures are enough without the others. </p><h2 id="how-ai-improves-iot-visibility-and-incident-response">How AI improves IoT visibility and incident response</h2><p>AI-powered ATD detects anomalous behavior, such as remote code execution, abnormal port connection or a suspicious IP. These could indicate the beginnings of a cyberattack on an IoT device. It analyses the anomaly and can identify the attack type, be it distributed denial of service (<a href="https://www.techradar.com/news/best-ddos-protection">DDoS</a>), man-in-the-middle (MiTM) or an attempted device takeover. </p><p>ATD can then trigger direct action, if business rules dictate an automated response. This could take the form of threat isolation or referring the incident for full review. </p><h2 id="anomaly-and-threat-detection-protects-over-one-million-devices">Anomaly and threat detection protects over one million devices</h2><p>ATD runs entirely in the mobile core network infrastructure, rather than through software agents on a device, so it can be retrofitted to existing systems.</p><p>Enterprises that have identified IP backdoors and Mirai botnet infections within hours. </p><p>With IP backdoors, ATD detects unusual outbound connections, or traffic, to suspicious IPs. Such backdoors may allow remote control or data exfiltration, both of which leave identifiable behavioral traces.</p><p>In the case of Mirai, anomalous behavior typically exhibits as spikes in outbound traffic, uncommon ports use, or repetitive scanning of external IPs. ATD can flag these irregularities in real time and trigger corrective actions, such as blocking or quarantining the device, blocking or throttling traffic or patching firmware.</p><h2 id="automation-and-analytics-can-shape-the-next-phase-of-iot-security">Automation and analytics can shape the next phase of IoT security</h2><p>There is a clear shift in IoT implementation and management. It is insufficient to plan for device deployment, sit back and gather the data. Without a strategy that accounts for the stresses, threats and changes that beset IoT estates, enterprises risk costly surprises like unplanned site visits and service disruptions. </p><p>AI, through automation and analytics, can shape the next phase of IoT security. Enterprises that detect, analyze and even automatically address, anomalous activity reduce the risk of cyberattack-related outages and inconvenient site visits to access devices. </p><p>Sending field technicians to maintain or repair devices can add significantly to total cost of ownership. Each truck roll, which incurs expenses for labor, fuel, vehicle wear and often missed <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a> opportunities, can add up to over $1000 per site visit. </p><p>IoT downtime, meanwhile disrupts operations and can have a catastrophic reputational, as well as financial, cost. </p><h2 id="how-to-balance-innovation-data-privacy-and-operational-control">How to balance innovation, data privacy and operational control</h2><p>Enterprises are, for the most part, keen to innovate through AI but have understandable questions about data privacy and operational control. </p><p>It is important to know what AI does, in all process integrations, to understand why it does it and to have control that prevents AI deviating from its purpose.</p><p>On data privacy, ATD isn’t installed on IoT devices. Only packet headers from device <a href="https://www.techradar.com/best/best-cloud-storage">cloud</a> communications are mirrored from the mobile core to the ATD engine, with threat levels and AI-driven insights relayed through a customer portal. </p><p>Operational control is maintained through the business rules that dictate how the ATD engine reacts. The option to refer an anomaly for review, for example, gives enterprises the flexibility to incorporate human oversight, under predetermined circumstances. </p><p>This is especially useful when you consider there can be genuine reasons why a SIM may increase or cease communication, that an incident reviewer will understand.</p><h2 id="ai-powered-iot-security">AI-powered IoT security </h2><p>AI is making a difference to the speed, efficiency and depth of response to cyberthreats. Automation and advanced analytics within IoT solutions’ security measures also help enterprises manage costs, by minimizing labor-intensive manual tasks and site visits, and reducing the risk of expensive cyberattack reparations. </p><p>For CISOs, CIOs, product and operations managers seeking to maximize IoT value and protect their enterprise IT domains from external threats, AI-powered ATD offers visibility and actionable insights to take IoT security to the next level.</p><p><a href="https://www.techradar.com/best/best-antivirus"><em>We've reviewed and ranked the best antivirus software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ MacPaw Moonlock antivirus review ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/computing/macs/macpaw-moonlock-antivirus-review</link>
                                                                            <description>
                            <![CDATA[ Moonlock is a relatively new arrival to the Mac antivirus scene, but offers excellent usability and won't hinder the performance of older Macs. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VeqiGPVbAQdSwFCBLk4FdC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QM9hJkWMMHyFDBLSPEBhmG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 06 Jul 2026 13:32:19 +0000</pubDate>                                                                                                                                <updated>Mon, 06 Jul 2026 13:34:33 +0000</updated>
                                                                                                                                            <category><![CDATA[Macs]]></category>
                                                    <category><![CDATA[macOS]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Desktop PCs]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ bryan.wolfe@futurenet.com (Bryan M Wolfe) ]]></author>                    <dc:creator><![CDATA[ Bryan M Wolfe ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsbij4rP7NWfEAnN3HdV87.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                        <dc:contributor><![CDATA[ Benedict Collins ]]></dc:contributor>
                                                                    <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QM9hJkWMMHyFDBLSPEBhmG-1280-80.jpg">
                                                            <media:credit><![CDATA[Moonlock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A screenshot of the MacPaw Moonlock dashboard]]></media:description>                                                            <media:text><![CDATA[A screenshot of the MacPaw Moonlock dashboard]]></media:text>
                                <media:title type="plain"><![CDATA[A screenshot of the MacPaw Moonlock dashboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QM9hJkWMMHyFDBLSPEBhmG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>MacPaw has spent years building a reputation as one of the most design-conscious developers in the Mac ecosystem. Its flagship product, <a href="https://www.techradar.com/reviews/cleanmymac-x-for-mac-review" target="_blank">CleanMyMac</a>, has long included a malware removal module powered by Moonlock's engine. In October 2025, the Kyiv-based company spun that security technology into a standalone product: Moonlock, a full-featured antivirus app that goes well beyond a simple scanner.</p><p>Rather than leading with threat counts and detection percentages, Moonlock frames itself as security software that treats users like adults, explaining what malware is, why it matters, and what to do next, instead of firing off opaque alerts. The marketing centers on a 'care, not scare' approach, essentially promising to educate you rather than just bombarding you with red-text alerts.</p><p>While many live in the mythical belief that Macs are immune to viruses, <a href="https://moonlock.com/2025-macos-threat-report" target="_blank">MacPaw's own research</a> reports that 66 percent of Mac users encountered at least one cyber threat last year, with a 67% increase in registered macOS backdoor variants in 2025. The research shows a key message: macOS is not immune, are users are being targeted more frequently than ever.</p><h3 class="article-body__section" id="section-plans-and-pricing"><span>Plans and pricing</span></h3><p>Moonlock starts at $54 per year for a single Mac, with licenses available for 2, 5, or more than 10 devices per subscription. Monthly billing and one-time lifetime license options are also available for those who prefer not to commit to an annual cycle.</p><p>Discounts of up to 67 percent are advertised on multi-year plans, which is worth exploring if you intend to stick with the product long term.</p><p>New users get a seven-day free trial, though a credit card is required to start. That is a common enough practice, but it does mean you will need to remember to cancel if the product does not suit you. To soften the blow of that annual fee, Moonlock offers a 30-day money-back guarantee, which is a considerably more generous safety net than the case-by-case refund process offered by some competitors.</p><p>Current Setapp subscribers get access to Moonlock at no additional charge, which may be the most compelling value proposition for those already in MacPaw's subscription ecosystem. At $54 per year for a single device, standalone pricing lands considerably higher than ClamXAV's three-Mac Home plan at $29.95, a gap worth weighing if budget is a primary concern.</p><h3 class="article-body__section" id="section-features"><span>Features</span></h3><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2624px;"><p class="vanilla-image-block" style="padding-top:63.41%;"><img id="5KepRLD9rYrfaLqHs4edTZ" name="moonlock-scan" alt="A screenshot of a MacPaw Moonlock scan" src="https://cdn.mos.cms.futurecdn.net/5KepRLD9rYrfaLqHs4edTZ.jpg" mos="" align="middle" fullscreen="" width="2624" height="1664" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Moonlock)</span></figcaption></figure><p>Moonlock is organized into six sections: Home, Malware Scanner, VPN, Network Inspector, System Protection, and Security Advisor. That framework reflects a deliberate decision to bundle a security suite rather than deliver a focused antivirus, giving the product a notably broader footprint than Mac-only rivals like ClamXAV.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2624px;"><p class="vanilla-image-block" style="padding-top:66.31%;"><img id="Z7hkDirscjtHPz8KP3X67Q" name="moonlock-malware-scanner" alt="A screenshot of the MacPaw Moonlock malware scanner in action" src="https://cdn.mos.cms.futurecdn.net/Z7hkDirscjtHPz8KP3X67Q.jpg" mos="" align="middle" fullscreen="" width="2624" height="1740" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Moonlock)</span></figcaption></figure><p>Real-time protection runs continuously in the background, monitoring file activity, app behavior, and Mail attachments even when the main application window is closed. The Malware Scanner supports on-demand and scheduled scans, with built-in quarantine and removal tools. Detected threats are accompanied by plain-language explanations rather than raw file paths and specialized terms.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2624px;"><p class="vanilla-image-block" style="padding-top:66.31%;"><img id="ZTwnWuF8rVzcFgSx7DrkdU" name="moonlock-vpn" alt="A screenshot of the MacPaw Moonlock VPN in action" src="https://cdn.mos.cms.futurecdn.net/ZTwnWuF8rVzcFgSx7DrkdU.jpg" mos="" align="middle" fullscreen="" width="2624" height="1740" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Moonlock)</span></figcaption></figure><p>The bundled VPN is a simplified version of MacPaw's ClearVPN, covering around 60 server locations across more than 45 countries. Independent testing found no DNS or WebRTC leaks, and MacPaw maintains a no-logging policy. Speed retention is strong, holding around 82 percent of baseline download speeds on transatlantic connections and up to 96 percent on closer servers.</p><p>Network Inspector adds a country-level connection blocker, permitting users to block outbound traffic to specific regions. System Protection audits macOS's own built-in security settings and walks you through any gaps. Finally, Security Advisor provides a checklist for basic digital hygiene, including practical guidance on habits such as two-factor authentication and app permissions. AI assists with malware classification on the backend, helping the team update threat databases before new strains reach your device.</p><h3 class="article-body__section" id="section-privacy-and-security"><span>Privacy and Security</span></h3><p>From a top level perspective, Moonlock was tested by the third-party laboratory AV-Test in September 2025 and earned it's AV-Test certification. It scored a 5.5/6 in Protection, 4.5/6 in Performance, and a full 6/6 for Usability (which I'll dive into in the next section).</p><p>As for the credibility of the underlying research arm, Moonlock Lab has made several notable contributions to the antivirus landscape, being the first to identify PyStealer on VirusTotal, and the lab has also been cited by the SANS Institute for discovering new variants of the Atomic macOS infostealer.</p><p>Regarding privacy, the VPN operates under a strict zero-logs policy, and all data is processed locally. MacPaw publishes a Trust Center at security.macpaw.com describing its data-handling practices, certifications, and security standards, which is a nice change in transparency from many other antivirus providers.</p><p>The one caveat worth noting is that Moonlock is a recent standalone launch. While the underlying engine has been in use in CleanMyMac for some time, the app itself has a limited history as an independently tested product. But it is worth noting that in the time since the last time AV-Test handled Moonlock, MacPaw have likely taken steps to improve protection and performance.</p><h3 class="article-body__section" id="section-interface-and-in-use"><span>Interface and in use</span></h3><p>The interface is highly polished, modern, and immediately legible, with a two-panel home dashboard that separates tasks on the left from status information on the right. Everything is where you would expect it to be, and the visual hierarchy makes it easy to tell at a glance whether your Mac is protected. </p><p>Instead of a generic 'Threat Resolved' notification, Moonlock tells you what was found, why it poses a risk, and what your options are. I found I was the one to make the final call on whether to remove a flagged item, which sidesteps the infuriating experience of automated deletion that occasionally catches legitimate software.</p><p>The system requirements make it suitable for older devices too, requiring macOS 13 or later and 515MB of disk space. The app runs quickly and, in day-to-day use, does not noticeably drag on performance. Installation requires a MacPaw account, which adds a step that competitors like ClamXAV skip entirely for home users, but the tradeoff is a unified login for managing licenses and accessing support.</p><p>Ultimately, Moonlock is a great option for those looking for an accessible and easily navigable Mac antivirus that doesn't bombard you with any overly-technical language, and performs as though you are the one in control.</p><h3 class="article-body__section" id="section-support"><span>Support</span></h3><p>Moonlock support runs on MacPaw's established infrastructure, with a dedicated knowledge base that covers installation, configuration, and troubleshooting, and those with questions can submit immediate inquiries through the support portal. In-app feedback is also available via the Help menu.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2624px;"><p class="vanilla-image-block" style="padding-top:63.41%;"><img id="Poe8caHraKyHPdShHYkJug" name="moonlock-security-advisor" alt="A screenshot of the Moonlock security advisor in action" src="https://cdn.mos.cms.futurecdn.net/Poe8caHraKyHPdShHYkJug.jpg" mos="" align="middle" fullscreen="" width="2624" height="1664" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Moonlock)</span></figcaption></figure><p>As with many Mac-focused security products, live chat or phone support does not appear to be offered as a standard option. For most home users, the knowledge base and email channel will be sufficient. Teams with more complicated environments should verify support response times before committing, particularly given that Moonlock is a relatively new standalone product and the support documentation is still maturing.</p><h3 class="article-body__section" id="section-the-competition"><span>The competition</span></h3><p>ClamXAV is the most direct rival in the Mac-exclusive antivirus space. At $29.95 per year for three devices, it is considerably cheaper than Moonlock's $54 single-device starting price, and it also holds a perfect AV-Test score compared to Moonlock's test results. It does not include a VPN, network inspection, or the polished onboarding experience Moonlock offers, but for those who want focused antivirus protection at a lower cost, it is a strong option.</p><p><a href="https://www.techradar.com/pro/intego-mac-internet-security-x9-review" target="_blank">Intego Mac Internet Security X9</a> sits at a comparable price point and includes a network monitor, with a longer track record in independent third-party testing. Bitdefender Total Security and Norton AntiVirus Plus both offer wider platform coverage and larger feature sets, making them better fits for households with mixed Windows and Mac devices.</p><p>Those who are already subscribed to CleanMyMac should also note that its built-in malware-scanning module, powered by the same Moonlock engine, continues to function independently. Therefore the question is whether the full Moonlock standalone app adds enough to justify an additional subscription or an upgrade in spending.</p><h2 id="final-verdict">Final verdict</h2><p>Moonlock is one of the most carefully designed security apps I've encountered in the Mac ecosystem. Its interface is excellent, its feature set is broader than most Mac-specific alternatives, and the research team behind it is doing genuinely credible original work. The 30-day money-back guarantee is also a nice addition, despite the need to enter your payment details first.</p><p>At $54 per year for a single Mac, it costs nearly twice as much as ClamXAV's three-device plan. The added value of the bundled VPN and Network Inspector goes some way toward justifying that gap, but those who already have a VPN solution elsewhere may not find the extras compelling enough. Setapp subscribers, on the other hand, get all of this for free as part of a subscription they likely already value.</p><p>For long-standing CleanMyMac users who already benefit from the embedded Moonlock engine, the standalone app offers greater depth, visibility, and control, but it's not a replacement for anything missing. It is a fuller version of the protection they have already been relying on, now with a VPN, richer reporting, and a proper home for the security features that were previously contained within a Mac cleaning utility.</p><p>For Mac users who want a single subscription that covers antivirus, VPN, network monitoring, and system security guidance, Moonlock makes a strong argument. Just go in aware of what you are paying for relative to the alternatives.</p><p><em>You might also be interested in our report on </em><a href="https://www.techradar.com/news/software/applications/30-best-mac-apps-for-just-about-everything-712511"><em>the best Mac apps of the year</em></a><em>.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ We built a trillion-dollar security industry on top of an unprotected layer ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/we-built-a-trillion-dollar-security-industry-on-top-of-an-unprotected-layer</link>
                                                                            <description>
                            <![CDATA[ As attackers increasingly exploit the 'human stack', organizations must shift from purely technical defenses to behavior-based resilience. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sMHxNdB4WmJWK3NYsDeq6N</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wV66hEbpJdAc4iPB7RwtkK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 06 Jul 2026 10:46:42 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sarah Gosler ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wV66hEbpJdAc4iPB7RwtkK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An exclamation mark inside a red warning triangle, surrounded by email symbols, superimposed on someone typing on a laptop]]></media:description>                                                            <media:text><![CDATA[An exclamation mark inside a red warning triangle, surrounded by email symbols, superimposed on someone typing on a laptop]]></media:text>
                                <media:title type="plain"><![CDATA[An exclamation mark inside a red warning triangle, surrounded by email symbols, superimposed on someone typing on a laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wV66hEbpJdAc4iPB7RwtkK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>For thirty years, the hardest part of a sophisticated cyberattack was the human labor behind it. Finding the vulnerability. Writing the exploit. Chaining the access. Staying quiet long enough to matter. </p><p>That work required teams, time, and tradecraft. It’s the reason nation-state operations looked different from criminal ones, and why most organizations could plan around the gap between them.</p><p>That gap is closing. </p><p>We are entering what I think of as the Mythos era, in which machines can do in minutes what used to take skilled human operators months. <a href="https://www.techradar.com/best/best-online-cyber-security-courses">Cybersecurity</a> defenses are improving, but the layer where final decisions are made, the human one, is now the easiest to exploit. </p><p>The advantage that protected most organizations, most of the time, is going with it. Precision at scale is no longer a contradiction. It’s a feature.</p><h2 id="the-human-stack-what-it-is-and-why-it-matters">The Human Stack: what it is and why it matters</h2><p>Most of the conversation about this shift has focused on what these systems do to vulnerabilities. That conversation is accurate, but incomplete. The harder problem is what machine-speed attacks do to the systems those vulnerabilities ultimately route through: systems that depend on human decisions.</p><p>That’s a layer most <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> programs don’t explicitly own. I call it the Human Stack, the point where every system finally comes down to a person deciding whether a wire transfer goes through, whether an email is trusted, or whether a voice on a phone call is real. We have spent a generation hardening everything above it, and almost nothing on the layer itself.</p><p>For most of cybersecurity's history, that was a tolerable bet. Attackers had to choose between going wide and crude, or narrow and precise. The Human Stack held because precision didn’t scale, and scale didn’t achieve precision.</p><p>That tradeoff is gone.</p><h2 id="what-the-next-wave-of-attacks-looks-like">What the next wave of attacks looks like</h2><p>The next wave won’t arrive as <a href="https://www.techradar.com/best/best-malware-removal">malware</a>. It’ll arrive as evidence. A voicemail that sounds exactly like the person it claims to be. A video call with a face you have known for ten years. An email thread that picks up a conversation you actually had, in the cadence you actually use, referencing a project that actually exists. The technical indicators will be clean, and the social indicators will be perfect. The only thing that will be wrong is the conclusion the human is being led to.</p><p>Last year, I spent time with the team behind Midnight in the War Room, a documentary premiering August 5 at Black Hat USA. It brings together over 50 experts, from global CISOs and military strategists to reformed hackers and victims of cyber conflict. The conversations were about something that has been happening for a long time and is about to be accelerated: the industrialization of social engineering, and the steady weaponization of the behavioral attack surface.</p><p>That surface doesn't stop at your perimeter. It extends through every vendor, managed service provider, and <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud services</a> administrator your business depends on. Your operations going offline may have nothing to do with your own people, and everything to do with someone three vendors deep making a decision under synthetic pressure.</p><h2 id="what-this-means-for-enterprises">What this means for enterprises</h2><p>For businesses, this isn’t theoretical. Financial risk is direct. We're already seeing fraudulent wire transfers, manipulated approval chains, and finance chiefs impersonated so convincingly that payments clear before anyone notices.</p><p>Operational disruption can come with no malware on your systems. The behavioral attack surface doesn't stop at your perimeter. It extends through every vendor, managed service provider, law firm, auditor, and cloud administrator your business depends on. </p><p>A compromised third party, manipulated through a perfectly constructed social engineering campaign, can take your operations offline without leaving a fingerprint anywhere near your network. Most organizations scrutinize their own security posture far more rigorously than the human decision-making environments of the third parties they rely on, leaving that exposure largely unmanaged. </p><p>Regulators and insurers are starting to ask harder questions about that exposure, and most organizations don't yet have good answers.</p><h2 id="the-shift-from-prevention-to-resilience">The shift from prevention to resilience</h2><p>There's a second shift that boards need to start preparing for, and it's bigger than any single control or technology. We're leaving the era in which security success is measured by attacks prevented. We're entering one in which the realistic measure is how quickly an organization recovers when belief fails.</p><p>Prevention still matters, and the investments organizations have made in it have been the right ones. But in a world where attacks will sometimes succeed because they're indistinguishable from legitimate activity, prevention alone is no longer a coherent strategy. Resilience is.</p><p>What resilience means at the human layer is different from what it means at the technical one. Technical resilience is about systems that fail gracefully and recover quickly. Human resilience is about decision-making environments that can absorb a successful deception, recognize it, and contain it before it compounds. Most organizations have invested in the first. Very few have invested in the second. That's the gap the next decade will judge us on.</p><h2 id="what-leaders-should-do">What leaders should do</h2><p>The security stack remains necessary, but this era exposes that even the best systems hand their hardest decisions to humans, and we haven't invested in that layer with the same rigor. Here’s where to start:</p><p><strong>Measure recovery, not just prevention</strong></p><p>When belief fails, how fast can your organization catch it, contain it, and get back up? That has to be designed into your operating model now, not figured out after an incident. </p><p><strong>Design for decision-making under deception</strong></p><p>Training people to spot phishing isn't sufficient when the phishing email is indistinguishable from a real one. Build institutional processes that don't rely on a single person making the right call under pressure.</p><p><strong>Treat people as operational infrastructure. </strong></p><p>Human judgment is a critical system. It needs redundancy and failure protocols, just like any other.</p><p><strong>Extend your security culture to your vendor ecosystem</strong></p><p>The behavioral attack surface runs through your entire supply chain. Your third-party risk program needs to account for the human layer, not just the technical one.</p><h2 id="the-window-is-closing">The window is closing</h2><p>Midnight in the War Room will make this visible in a way an op-ed cannot. </p><p>The Mythos era did not create this problem. It revealed it. The cost of exploiting human decision-making precisely was high enough to keep most attackers out. That barrier is collapsing now.</p><p>What comes next will not announce itself. It’ll arrive looking like someone you trust, asking for something that feels completely reasonable, right up until the moment it isn't.</p><p>The question is no longer whether your systems can withstand attack. It's whether your people are prepared to make decisions in a world where the evidence itself can no longer be trusted, and whether your organization is built to recover when those decisions go wrong.</p><p><em></em><a href="https://www.techradar.com/best/best-cloud-antivirus"><em>We've reviewed and ranked the best cloud antivirus</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ That free VPN Chrome and Firefox extension may be reading your clipboard every half a second, researchers warn ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/vpn/vpn-privacy-security/that-free-vpn-chrome-and-firefox-extension-may-be-reading-your-clipboard-every-half-a-second-researchers-warn</link>
                                                                            <description>
                            <![CDATA[ Researchers at Socket found two "VPN Go" browser extensions for Chrome and Firefox that posed as free VPNs while quietly stealing clipboard data through later updates. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">drttgaXd7xBrBjVNgZ6gbP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5pmsJs3KfnrtbsM98UsnG9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 01 Jul 2026 13:22:10 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[VPN Privacy &amp; Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ monicajwrites@gmail.com (Monica J. White) ]]></author>                    <dc:creator><![CDATA[ Monica J. White ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/6AQ4y5nzk8kQ47Yp69GERj.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Monica is a journalist with over a decade of experience in covering technology.&lt;/p&gt;&lt;p&gt;She writes about the latest developments in computing, which means anything from computer chips made out of paper to cutting-edge desktop processors. Her coverage includes CPUs, GPUs, and everything else that goes into a PC or a laptop, but also peripherals.&lt;/p&gt;&lt;p&gt;GPUs are Monica’s main area of interest, and nothing thrills her quite like that time every couple of years when new graphics cards hit the market. She’s always keeping tabs on the latest from Nvidia, AMD, and Intel, including both the hardware and the software that powers our PCs.&lt;/p&gt;&lt;p&gt;As an avid gamer, her focus is always on the consumer and whether something works well and provides adequate value for the money. She believes that PC building can be intimidating, so her goal is to explain complex concepts in an approachable manner while still digging into the technical nitty-gritty we all love to learn more about.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5pmsJs3KfnrtbsM98UsnG9-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Malware kan ställa till med oreda]]></media:description>                                                            <media:text><![CDATA[Android phone malware]]></media:text>
                                <media:title type="plain"><![CDATA[Android phone malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5pmsJs3KfnrtbsM98UsnG9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers found "VPN Go" extensions for Chrome and Firefox secretly harvesting copied text</strong></li><li><strong>The clipboard theft was not there at launch and arrived through a later update</strong></li><li><strong>Anything copied while the extension was active should now be treated as exposed</strong></li></ul><p>Security researchers at Socket found two browser extensions distributed under the "VPN Go: Free VPN" branding, one listed on the Chrome Web Store and one on Firefox Add-ons, to secretly harvest copied text. </p><p>Both present themselves as free VPN tools with working proxy features. Underneath, <a href="https://socket.dev/blog/chrome-and-firefox-extensions-free-vpns-add-clipboard-stealers" target="_blank" rel="nofollow">Socket says</a>, both also run a clipboard stealer that continuously watches copied text and sends it to infrastructure controlled by the attacker.</p><p>According to Socket, the clipboard theft was not present when the extensions first appeared. It was added later, through an ordinary-looking update, after the extensions had already built up a base of trusting users. That staged approach is exactly what makes this kind of threat so hard to spot, and why even a fairly cautious user can end up exposed.</p><p>For anyone weighing up a no-cost privacy tool, it is worth knowing that not every free option behaves like this, and the <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> services are tested precisely so you do not have to take this kind of gamble. But this case shows how thin the line can be between a useful free extension and a data-harvesting one.</p><h2 id="what-socket-s-research-uncovered">What Socket's research uncovered</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1213px;"><p class="vanilla-image-block" style="padding-top:56.22%;"><img id="7b3ucMmXHaTYWRvoZbT8T9" name="VPN Go" alt="VPN Go in Chrome Web Store" src="https://cdn.mos.cms.futurecdn.net/7b3ucMmXHaTYWRvoZbT8T9.png" mos="" align="middle" fullscreen="" width="1213" height="682" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Chrome)</span></figcaption></figure><p>Socket says the earliest analyzed builds behaved like ordinary proxy extensions, with no confirmed clipboard theft. </p><p>On <a href="https://www.techradar.com/reviews/google-chrome">Chrome</a>, that changed with version 1.1, when the extension added a script that reads the clipboard and ships those chunks off to a hardcoded address. The <a href="https://www.techradar.com/reviews/mozilla-firefox">Firefox</a> version followed the same path slightly later, moving the same theft loop into its background script.</p><p>Once active, the monitoring is relentless. The Chrome content script checks the clipboard roughly every half a second, according to Socket's analysis, while the Firefox build polls every 1.5 seconds. </p><p>Each newly copied value is tagged with a session identifier so it can be reassembled on the other end, then sent out over plain HTTP. All of this was happening while the two apps' privacy policies stated that the tools did not collect, store, or share user data and did not keep activity logs.</p><p>TechRadar has reached out to VPN Go for comment, but both email addresses bounced, and both extensions have since been pulled from their stores.</p><h2 id="why-clipboard-stealers-are-dangerous-for-users">Why clipboard stealers are dangerous for users</h2><p>The reason clipboard theft is so effective is that it abuses something completely routine. People copy and paste sensitive information all day, and it's not careless to do so. Password managers rely on exactly that: copying long, unique passwords into your accounts.</p><p>An extension that can silently read the clipboard has access to all of this information; it just has to wait for you to copy the right thing. If you have used either of the two extensions in question, you should treat any information you've copied during that time as exposed.</p><p>Researchers have repeatedly found free VPN extensions doing things their users never agreed to. Recent reporting has covered a <a href="https://www.techradar.com/vpn/vpn-privacy-security/this-free-chrome-vpn-extension-found-to-spy-on-its-100k-users-uninstall-it-now">free Chrome VPN extension caught taking screenshots</a> of every page its users visited, and a <a href="https://www.techradar.com/vpn/vpn-privacy-security/malicious-free-vpn-extension-makes-a-comeback">malicious free VPN extension that resurfaced</a> after being removed, returning in a more evasive form. </p><p>The pattern is consistent enough that it is worth treating any unknown free VPN extension with caution by default. That caution matters: TechRadar's own polling found that <a href="https://www.techradar.com/vpn/vpn-privacy-security/to-pay-or-not-to-pay-nearly-1-in-4-techradar-readers-say-they-use-free-vpns-despite-the-risks">nearly 1 in 4 readers use free VPNs</a> despite knowing the risks.</p><h2 id="how-to-stay-safe-2">How to stay safe</h2><p>If you want the protection a VPN offers without rolling the dice, stick to providers with a track record and independent testing behind them. </p><p>A reputable paid service, or one of the carefully vetted <a href="https://www.techradar.com/vpn/best-free-vpn">best free VPN</a> options, is a far safer bet than an unknown extension promising unlimited access for nothing. As the saying goes, when the product is free, there is a decent chance that you are the product.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NAIC confirms data breach with ShinyHunters claiming 3.1TB of data stolen in Oracle zero-day attack ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/naic-confirms-data-breach-with-shinyhunters-claiming-3-1tb-of-data-stolen-in-oracle-zero-day-attack</link>
                                                                            <description>
                            <![CDATA[ Insurer regulatory filing documents, customer bulk orders, and more, stolen in a major zero-day supply chain attack ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rq7YhrojSragNBymdm8FYn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 26 Jun 2026 18:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[hacker hands at work with  interface around]]></media:description>                                                            <media:text><![CDATA[hacker hands at work with  interface around]]></media:text>
                                <media:title type="plain"><![CDATA[hacker hands at work with  interface around]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>NAIC confirmed a cyberattack exploiting an Oracle PeopleSoft zero‑day, with ShinyHunters claiming theft of 3.1TB of data</strong></li><li><strong>Stolen cache allegedly includes insurer filings, credit rating files, AWS logs, configs, and PII; NAIC says only financial reports and technical data were taken</strong></li><li><strong>Incident spotted June 11, disclosed June 17; files leaked online suggest NAIC did not pay ransom, as ShinyHunters continues exploiting the zero‑day across 100+ organizations</strong></li></ul><p>The National Association of Insurance Commissioners (NAIC) confirmed suffering a cyberattack that resulted in the stolen data being leaked on the dark web. While the company did not name the group responsible, or mentioned the size of the stolen cache, the infamous ShinyHunters claimed responsibility and stated they snatched around 3.1TB of information.</p><p>In a security notice published on the NAIC website, it was explained that the attackers managed to exploit a <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">zero-day vulnerability</a> in Oracle PeopleSoft. This is an <a href="https://www.techradar.com/best/best-erp-software" target="_blank">enterprise resource planning</a> (ERP) software suite, designed to help businesses manage employees, finances, supply chains, and more. Citing Google Mandiant, Cybernews says ShinyHunters first started exploiting the zero-day on May 27, and managed to compromise more than 100 organizations and 300 individuals, before Oracle finally pushed an emergency update on June 10.</p><p>Among the victims, as we now know, is NAIC, whose PeopleSoft environment was compromised, and used to obtain credentials and move laterally to internal data storage locations. </p><h2 id="shinyhunters-step-forward">ShinyHunters step forward</h2><p>Based on NAIC’s investigation, the stolen information includes publicly available statutory financial reports, insurer investment credit rating data, and some technical information such as outdated logs and configuration files. There is no evidence that personal information, banking information, or payment data was accessed, it said.</p><p>NAIC spotted the attack on June 11 and immediately launched its incident response protocol, which includes notifying law enforcement, blocking malicious actors, and bringing in third-party security experts. The Commission disclosed the incident on June 17, a day before ShinyHunters went public. </p><p>The notorious ransomware gang claims to have taken more than 264,000 insurer regulatory filing documents, 2,000 customer and bulk orders containing personally identifiable information, some 45,000 files from major credit rating agencies, statutory annual and quarterly financial statements submitted by insurers, production AWS infrastructure logs, cloud configuration files, and workload automation data, and SQL scripts.</p><p>Since the files were seemingly leaked online, it’s safe to assume that NAIC did not (want to) pay the ransom demand.</p><p><em>Via </em><a href="https://cybernews.com/news/naic-breach-shinyhunters-3tb-insurance-systems-data/" target="_blank"><em>Cybernews</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are establishing persistence in hospitality and hotels by posing as guests with poisoned ZIP archives, but no one knows what their plan is ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/hackers-are-establishing-persistence-in-hospitality-and-hotels-by-posing-as-guests-with-poisoned-zip-archives-but-no-one-knows-what-their-plan-is</link>
                                                                            <description>
                            <![CDATA[ It looks like reconnaissance activity, possibly in preparation of a more destructive attack. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uFvUz5mRvhqu4D8SqDToRo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 26 Jun 2026 14:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:description>                                                            <media:text><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:text>
                                <media:title type="plain"><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft Threat Intelligence warns of a phishing campaign targeting hotel staff in Europe and Asia with guest complaint‑themed emails</strong></li><li><strong>Attackers abuse services like Calendly and Google redirects to bypass authentication checks, delivering photo‑themed ZIPs that install a persistent Node.js implant</strong></li><li><strong>Malware disables Defender, runs C2 beaconing, gathers system info, and forces shutdowns; signs include unusual PowerShell activity, Node.js execution, and suspicious registry entries</strong></li></ul><p>Hackers are establishing a foothold on hotels and hospitality organizations across Europe and Asia, but no one really knows what for, at least not yet.</p><p>This is according to Microsoft Threat Intelligence, who recently published a new report saying that since April, it’s been tracking an active phishing campaign. In this campaign, the unnamed attackers target front desk, reception, and reservations staff with emails about guest complaints, room conditions, bedbug infestations, booking inquiries, and similar.</p><p>The messages, sent in different languages (Danish, Dutch, Japanese), are not distributed directly. Instead, the crooks abuse legitimate services such as Calendly, and Google’s redirect infrastructure, which helps them pass SPF, DKIM, and DMARC authentication checks.</p><h2 id="tricking-defender">Tricking Defender</h2><p>This “authentication laundering”, as Microsoft puts it, results in photo-themed ZIP archives making their way directly to their victims. The archives contain a fake image shortcut (.LNK) files that, at a glance, appear to be harmless .PNG images. However, these files launch a sophisticated multi-stage infection chain that installs a persistent Node.js-based implant.</p><p>After being deployed, the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> tweaks Microsoft Defender to exclude itself (and other, randomly named executables) from scanned processes, downloads additional payloads, and copies itself into different places. </p><p>On compromised systems, Microsoft observed the malware running command-and-control beaconing, gathering environmental information such as the victim's public IP details, launching headless browser sessions, and in some cases forcing immediate system shutdowns. While it could not say what the goal of the campaign is, it all points to a reconnaissance stage that usually comes before a more disruptive malware or ransomware attack. </p><p>Microsoft recommends organizations focus on detecting the campaign's behavior rather than individual indicators. Key signs include photo-themed ZIP archives, unusual PowerShell activity, unexpected Node.js execution from user profile directories, .NET compilation initiated by PowerShell, and Defender exclusion changes.</p><p>Furthermore, there are random executables running from temporary folders, suspicious Run and RunOnce registry entries, outbound connections on the campaign's non-standard ports, connections to newly registered .cfd domains, and combinations of headless browser activity followed by forced shutdown commands.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This macOS malware can avoid AI analysis with gaslighting prompts hidden inside its architecture ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/this-macos-malware-can-avoid-ai-analysis-with-gaslighting-prompts-hidden-inside-its-architecture</link>
                                                                            <description>
                            <![CDATA[ A new piece of malware tries to trick AI-assisted analysis into showing errors. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">U53dE6YVGq8TtTv52qNvmn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 26 Jun 2026 13:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:description>                                                            <media:text><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:text>
                                <media:title type="plain"><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>SentinelOne uncovered macOS malware “Gaslight” that uses prompt injection to mislead AI‑assisted triage tools during analysis</strong></li><li><strong>Beyond standard backdoor and infostealer capabilities, it embeds fake Markdown “system” messages to trick LLMs into halting investigation</strong></li><li><strong>Researchers warn defenders to treat malware samples as adversarial input and isolate AI pipelines, as more analyst‑targeting prompt injection is expected</strong></li></ul><p>We’ve seen prompt injection in websites and emails, but what about - malware samples? Security researchers SentinelOne recently published an in-depth report on a newly uncovered piece of macOS malware called Gaslight that, as the name suggests, tries to gaslight AI-assisted triage agents into stopping the analysis.</p><p>The malware itself is nothing out of the ordinary: it infects the device by whatever means necessary (usually phishing and social engineering), connects to attacker-controlled infrastructure via Telegram, and then executes different commands such as profiling the device, running arbitrary shell commands, stealing files, or terminating processes. </p><p>It also delivers a stage-two malware that acts as an infostealer, pulling passwords, sensitive PDFs, cryptocurrency wallet information, and more.</p><h2 id="weaponizing-llm-assisted-triage-pipelines">Weaponizing LLM-assisted triage pipelines</h2><p>But where Gaslight stands out is its defenses against <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI-powered malware analysis</a>. According to SentinelOne, the malware contains a large block of fake Markdown-formatted "system" messages designed for AI assistants that security researchers may use during reverse engineering. These messages claim things like “the AI's authentication token has expired”, “the analysis environment is running out of memory”, “disk space has been exhausted”, “static analysis is unsafe”, and similar. </p><p>While a human analyst would definitely recognize these fake messages even at a glance, an LLM that isn’t properly isolated from untrusted input could interpret them as genuine system instructions and refuse to further analyze the malware. </p><p>“macOS.Gaslight is noteworthy for its analyst-targeting prompt injection, an attempt to weaponize the LLM-assisted triage pipelines that increasingly sit in the reverse-engineering loop,” SentinelOne explains. “Anyone building such tooling should treat the contents of the samples they triage as adversarial input, never as instructions, and be prepared to keep hostile content out of the model entirely. As LLM-assisted analysis becomes routine, defenders should expect more samples built to exploit it.”</p><p>The researchers have published a full list of indicators of compromise on <a href="https://www.sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox/" target="_blank">this link</a>.</p><p><em>Via </em><a href="https://thehackernews.com/2026/06/new-gaslight-macos-malware-uses-prompt.html" target="_blank"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Edge users beware — this malicious extension can break out of the sandbox and install ransomware ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/edge-users-beware-this-malicious-extension-can-break-out-of-the-sandbox-and-install-ransomware</link>
                                                                            <description>
                            <![CDATA[ Hackers found a way to get an Edge extension to do their bidding. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZW8e2HVDrnR2AMfRNTKep3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 25 Jun 2026 14:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg">
                                                            <media:credit><![CDATA[Tada Images / Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:description>                                                            <media:text><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:text>
                                <media:title type="plain"><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Zscaler uncovered “Edgecution,” a malicious Edge extension deployed via fake Outlook update sites shared in Teams phishing</strong></li><li><strong>Attack uses ZIP archives with Python runtime to escape browser sandbox, creating a backdoor capable of shell/PowerShell execution and system data theft</strong></li><li><strong>Believed linked to Initial Access Brokers tied to ransomware group Payout Kings, showing evolving sophistication in access‑for‑sale operations</strong></li></ul><p>If you are using the Edge browser be careful - there is a malicious campaign going round that uses the <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> to deploy a backdoor via an extension.</p><p>According to security researchers Zscaler, scammers are reaching out to their victims via Microsoft Teams, pretending to be IT support. They claim the user needs to install an Outlook update, or a spam filter, and direct the victims to a fake “Outlook Updates Management Console” website. </p><p>There, the users are instructed to run one of the three provided processes, all of which download a ZIP archive that, when executed, creates a scheduled task. This task starts the Edge browser in headless mode (invisible to the user) and installs an extension officially called “Edge Monitoring Agent”. Zscaler, on the other hand, calls it “Edgecution”.</p><h2 id="creating-a-native-messaging-manifest">Creating a Native Messaging manifest</h2><p>The ZIP archive also contains an embedded Python runtime and a Python-based <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">backdoor</a>. The runtime creates a Native Messaging manifest - a file that tells the browser how to communicate with the backdoor. That’s the way the threat actors managed to escape the browser’s sandbox and run the backdoor on the compromised computer itself. </p><p>That backdoor can do multiple things, from executing shell commands, to running PowerShell and arbitrary Python code. It can also write files on the host, enumerate running processes, and gather system information. </p><p>Zscaler believes this is the work of an Initial Access Broker (IAB), a malicious group whose only job is to obtain access to a victim’s infrastructure and then sell it - or share it with a partnering group. This particular IAB, the researchers believe, is connected to a ransomware operation called Payout Kings. </p><p>“The Edgecution browser extension illustrates the evolving sophistication of initial access brokers operating in the ransomware landscape,” Zscaler warns. “The reliance on a malicious browser extension to relay commands to a Python-based native host demonstrates a creative approach to evade traditional endpoint detection.”</p><p>A full list of Indicators of Compromise (IoC) can be found on <a href="https://www.zscaler.com/blogs/security-research/payouts-king-ransomware-initial-access-broker-deploys-new-edgecution" target="_blank">this link</a>.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/malicious-edge-extension-abuses-native-messaging-as-bridge-to-malware/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Multiple malicious OpenClaw skills found online - including two macOS infostealers ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/multiple-malicious-openclaw-skills-found-online-including-two-macos-infostealers</link>
                                                                            <description>
                            <![CDATA[ Criminals found yet another marketplace to infect and use as a launchpad for malware delivery. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vFgwHmcERf3Dv9c4J9df9G</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DTZvZXmPaA8zMJoW733ZVa-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 25 Jun 2026 12:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/DTZvZXmPaA8zMJoW733ZVa-1280-80.png">
                                                            <media:credit><![CDATA[Fortune]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft OpenClaw]]></media:description>                                                            <media:text><![CDATA[Microsoft OpenClaw]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft OpenClaw]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DTZvZXmPaA8zMJoW733ZVa-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Palo Alto Networks’ Unit 42 found five malicious “skills” on ClawHub, OpenClaw’s official marketplace, delivering infostealers and fraud</strong></li><li><strong>Threat actors bypassed VirusTotal/ClawScan checks with inflated file sizes and evasive techniques, showing persistent supply chain risk</strong></li><li><strong>All malicious skills were removed and accounts banned; researchers urge strict provenance validation and source code audits for published packages</strong></li></ul><p>ClawHub is the latest marketplace hackers are poisoning with malware, in an attempt to compromise software developers and other advanced users. Earlier this week, security researchers from Palo Alto Networks’ Unit 42 team disclosed finding, and reporting, five “skills” on that marketplace, that sought to infect their users with infostealer <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>. </p><p>First a little context: OpenClaw (originally published as Clawd/Clawdbot) was released in November 2025. It is an <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">open-source agent</a> platform that performs actions on a computer, such as browsing the web, or managing files, instead of simply answering questions like a chatbot. To perform different actions, OpenClaw must first learn how to do them, which is done through “skills” - add-ons that extend the agent’s capabilities.</p><p>Soon after, ClawHub was born - the official marketplace and registry for OpenClaw skills and plugins, attracting not just the AI developer community, but cybercriminals, as well. Early reports, published in February this year, forced OpenClaw to integrate VirusTotal and ClawScan, to better protect the community and allow proactive screening of published skills.</p><h2 id="persistent-and-evasive-malicious-skills">Persistent and evasive malicious skills</h2><p>However, Unit 42 says this didn’t stop threat actors, and that it has since discovered multiple “persistent and evasive malicious skills” on the platform. </p><p>In total, the researchers discovered five skills, including two that delivered the AMOS infostealer, one that came with an inflated file size to trick scanners, and two that were essentially commission fraud, abusing the fact that an AI agent can make decisions and perform actions on behalf of the user. Details on all five can be found on <a href="https://unit42.paloaltonetworks.com/openclaw-ai-supply-chain-risk/" target="_blank">this link</a>.</p><p>All five were since reported to ClawHub, and OpenClaw had them removed and the accounts behind them banned. </p><p>Unit 42 recommends organizations use a “rigorous supply chain verification framework” to remain secure: “We identified that skill execution occurs within the agent process. This necessitates active validation of publisher provenance and a line-by-line audit of package source files.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New lightweight, self-propagating crypto stealing malware delivered by USB spotted by Microsoft researchers – Crypto Clipper script-based stealer hunts for vulnerable wallets ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/new-lightweight-self-propagating-crypto-stealing-malware-delivered-by-usb-spotted-by-microsoft-researchers-crypto-clipper-script-based-stealer-hunts-for-vulnerable-wallets</link>
                                                                            <description>
                            <![CDATA[ Microsoft details a newly discovered wormlike infostealer called Crypto Clipper. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GaqMuUuMNrgQhbzMPLJ9SN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VnoVVXTmAmxSBYBe4LUwVW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 22 Jun 2026 18:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VnoVVXTmAmxSBYBe4LUwVW-1280-80.jpg">
                                                            <media:credit><![CDATA[vjkombajn/Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image credit: Pixabay/vjkombajn]]></media:description>                                                            <media:text><![CDATA[Cryptocurrencies]]></media:text>
                                <media:title type="plain"><![CDATA[Cryptocurrencies]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VnoVVXTmAmxSBYBe4LUwVW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft warns of “Crypto Clipper,” a worm spreading via malicious .LNK files on USB drives</strong></li><li><strong>Malware maintains persistence, connects to Tor C2, enables remote code execution, and steals clipboard crypto data</strong></li><li><strong>It swaps wallet addresses, exfiltrates seed phrases/private keys, and uploads screenshots to assess target value</strong></li></ul><p>Microsoft is warning of an ongoing campaign targeting cryptocurrency owners with a clipboard-jacking worm.</p><p>In a new in-depth report published late last week, Microsoft’s security researchers explained that they recently analyzed a thumb drive that contained seemingly normal documents (Word files, Excel spreadsheets). However, the documents were replaced with Windows shortcut (.LNK) files which actually launched a piece of malware called Crypto Clipper. </p><p>This malware does a couple of things. First, it spreads by creating malicious .LNK files on USB drives and other removable media. It also sets up scheduled tasks to maintain persistence and automatically infect newly connected USB devices. Second, it behaves like a backdoor by regularly contacting a C2 server over the Tor network and receiving commands from the attacker. The server can also send commands to have the malware download and execute attacker-supplied code on the infected system, as well. </p><h2 id="stealing-wallet-data">Stealing wallet data</h2><p>Finally, Crypto Clipper acts as a clipboard clipper by monitoring the Windows clipboard for cryptocurrency wallet addresses, seed phrases, and private keys. If it spots a wallet address, it can replace it with a different one, owned by the attackers, so that any tokens sent by the victim go to the attacker, instead. It can also steal and exfiltrate copied seed phrases and private keys, which can be used to load a victim's crypto wallet on a separate device. </p><p>To help attackers assess the value of a target, the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> periodically captures screenshots of the victim's screen and uploads them through the Tor network.</p><p>“This malware family shows how lightweight, script-based stealers can deliver outsized impact when paired with anonymized communications and runtime tasking,” Microsoft said. “The combination of Tor-routed C2, clipboard targeting, screenshot capture, and remote code execution gives attackers both immediate monetization paths and continued control over compromised devices.”</p><p>Microsoft did not say if the malware targeted any specific countries or regions, nor did it discuss the number of victims.</p><p><em>Via </em><a href="https://arstechnica.com/security/2026/06/microsoft-spots-new-self-propagating-malware-for-stealing-cryptocurrency/" target="_blank"><em>Ars Technica</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Phishing the agent: Why AI guardrails aren’t enough ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/phishing-the-agent-why-ai-guardrails-arent-enough</link>
                                                                            <description>
                            <![CDATA[ AI agents are handed the keys to the kingdom but can't always be trusted. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mPDZTdxUod2oo3R2JVwV4Q</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AsscCgZRnWXMPyCxtEfpkK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 22 Jun 2026 13:39:33 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jeremy Kirk ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/AsscCgZRnWXMPyCxtEfpkK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An email symbol inside a red square warning sign, surrounded by red triangles with exclamation marks inside them, superimposed on someone typing on a laptop]]></media:description>                                                            <media:text><![CDATA[An email symbol inside a red square warning sign, surrounded by red triangles with exclamation marks inside them, superimposed on someone typing on a laptop]]></media:text>
                                <media:title type="plain"><![CDATA[An email symbol inside a red square warning sign, surrounded by red triangles with exclamation marks inside them, superimposed on someone typing on a laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AsscCgZRnWXMPyCxtEfpkK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.techradar.com/best/best-ai-tools">AI</a> agents are reshaping how enterprises automate work, but their effectiveness depends on access to sensitive systems and data. </p><p>The paradox is that granting them the permissions they want creates new attack surfaces that organizations aren’t yet equipped to handle.</p><p>This is the defining tension of the AI era.</p><p>AI agents are proliferating across enterprises with 91% of organizations already using them yet only 10% have a clear <a href="https://www.techradar.com/best/it-management-tools">IT management</a> strategy in place. </p><p>This gap matters because as these systems grow more autonomous and more deeply embedded in workflows, enterprises are operating without clear visibility, meaningful oversight and control over how their AI agents behave.</p><h2 id="the-access-problem">The access problem</h2><p>Our recent research revealed how agents running on OpenClaw, an <a href="https://www.techradar.com/best/best-open-source-software">open-source</a> AI agent automation platform, could expose credentials and leak sensitive information when attackers compromised the communication channels controlling them.</p><p>To appreciate the scale of this risk, we must first understand the platform itself. OpenClaw combines a chatbot-style interface with access to external tools and <a href="https://www.techradar.com/computing/artificial-intelligence/best-llms">large language models</a>. </p><p>Users can then configure agents to browse the web, read and write files, manage inboxes, execute commands, or interact with other machines. In many cases, they’re designed to operate autonomously with minimal human oversight.</p><p>That level of access is what makes agents powerful, helping many to manage everyday admin and time-consuming tasks. However, this power is a double edged-sword and can make them a risk to businesses.  </p><h2 id="when-agents-become-attack-surfaces">When agents become attack surfaces</h2><p>Agents need access to tools, accounts, applications, the web and more to be useful. Often, this means an agent needs access to secrets: API keys, personal access tokens, credentials, .env files, OAuth tokens. </p><p>The agents/models are by default prompted to be as helpful as possible, and that characteristic starts to pose some particular concerns when it comes to credentials and tokens. If an agent such as OpenClaw can’t access a resource, it will ask for credentials right in the chat, exposing those secrets within the context window. Agents will happily store API keys in their unencrypted configuration files, which information-stealing <a href="https://www.techradar.com/best/best-malware-removal">malware</a> is starting to target. </p><p>Remote access capabilities could effectively create a back door into enterprise environments. If an attacker gained access to the communication channel controlling an agent, such as a <a href="https://www.techradar.com/pro/best-enterprise-messaging-platform">messaging</a> or remote access platform, they could potentially gain access to everything the agent itself could access. In an enterprise context, this is a nightmare. </p><h2 id="the-paradox-of-recognized-risk">The paradox of recognized risk</h2><p>Perhaps the most revealing finding was that some agents recognize risky behavior while simultaneously carrying it out. This underlines how their decision-making ability and autonomous operations can be a business risk. </p><p>In one test, an agent correctly identified that exposing an OAuth refresh token through an unencrypted communication channel represented a serious <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> violation. But it then proceeded to share the token anyway before expressing concern about its own decision.</p><p>Organizations should not rely on the invisible guardrails that frontier model providers put around agents. They’re easily circumvented. </p><p>But an AI agent cannot divulge credentials that it doesn’t have access to. This is why the conversation around AI agent security cannot focus solely on stronger guardrails. Attackers are already finding ways to manipulate agent behavior through prompt injection, social engineering, and compromised communication channels.</p><h2 id="governance-not-just-guardrails">Governance, not just guardrails</h2><p>AI agents are essentially identities within enterprise systems and need to be managed as such. They perform actions and make operational decisions in ways that increasingly resemble human employees or privileged service accounts. Yet many organizations are deploying these systems without applying the same governance standards.</p><p>Most businesses already understand the importance of least-privilege access, audit logging, <a href="https://www.techradar.com/best/best-identity-management-software">identity management</a>, and access reviews for employees. AI agents should be subject to the same principles. That means limiting what agents can access, avoiding long-lived credentials wherever possible, and ensuring sensitive information is stored securely through centralized systems with human oversight. </p><p>Organizations also need visibility into where agents are deployed, what tools they can interact with, and how to disable them quickly if something goes wrong. If an agent goes rogue, there needs to be a “kill switch,” a way to immediately revoke an agent’s access to resources and shut it down.</p><p>Agentic AI systems could deliver major operational upsides, but deploying them without robust identity and access governance introduces significant security risk. As these systems become more deeply embedded across enterprise environments, organizations must stop treating them as experimental tools and start governing them as part of the digital workforce. </p><p>This means managing the full lifecycle of agents, from knowing which agents are deployed, what resources they access to and keeping a full audit trail so no one can say, “I don’t know what happened. The agent did it.”</p><p>There’s no reason why conventional security wisdom, such as the principle of least privilege, lifecycle management and robust logging, should be thrown out in an agentic age. In fact, it’s more relevant than ever.</p><p><em></em><a href="https://www.techradar.com/best/best-cloud-storage"><em>We've tested and reviewed the best cloud storage</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Thousands of D-Link and QNAP NAS routers compromised by fast-moving AryStinger malware that turns unsecured devices into a malicious proxy botnet ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/thousands-of-d-link-and-qnap-nas-routers-compromised-by-fast-moving-arystinger-malware-that-turns-unsecured-devices-into-a-malicious-proxy-botnet</link>
                                                                            <description>
                            <![CDATA[ More than 4,000 routers have been compromised so far, while the number of poisoned NAS devices remains unknown. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">P8KFdsr77m4i24xC9tFPEK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2FFajuvJVK8i7Her8gD4aD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 22 Jun 2026 12:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2FFajuvJVK8i7Her8gD4aD-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard]]></media:description>                                                            <media:text><![CDATA[Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2FFajuvJVK8i7Her8gD4aD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>QiAnXin XLab uncovered “AryStinger,” malware exploiting old D-Link/Linksys router flaws (CVE‑2013‑3307, CVE‑2016‑5681) to build a proxy/reconnaissance network</strong></li><li><strong>So far 4,300 routers infected, mostly in South Korea (48%) and China (32%), with QNAP NAS devices also targeted via CVE‑2025‑11837</strong></li><li><strong>Compromised devices enable scanning, tunneling, and covert control; researchers advise monitoring logs, binaries in /tmp/bin, and suspicious processes like </strong><em><strong>syswapd0h</strong></em><strong> or </strong><em><strong>syswapd0w</strong></em></li></ul><p>Cybersecurity researchers QiAnXin XLab are warning about an ongoing campaign to create a distributed reconnaissance and proxy network out of people’s <a href="https://www.techradar.com/news/networking/routers-storage/best-router-9-top-wireless-routers-on-test-1090523" target="_blank">routers</a> and NAS devices. </p><p>The campaign targets outdated and unsupported routers (mostly D-Link and Linksys), powered by Realtek’s RTL819X chips which were a popular choice between 2012 and 2015. The attackers are leveraging two (ancient) vulnerabilities, CVE-2013-3307 in Linksys models and CVE-2016-5681 in D-Link ones, to infect the devices with a previously undetected piece of malware called AryStinger.</p><p>According to the researchers, AryStinger is used during the reconnaissance and planning stages of a more serious cyberattack. Devices infected with this malware can scan the internet, fingerprint services, enumerate subdomains, tunnel traffic, and run commands on demand, all while hiding the location (and true identity) of the attackers.</p><h2 id="targeting-nas-devices">Targeting NAS devices</h2><p>“Once compromised by malware like AryStinger that possesses reconnaissance and covert control capabilities, it is equivalent to a hacker placing a permanent "invisible listening device" and "attack springboard" within your network,” the researchers said.</p><p>QiAnXin’s XLab says that So far, AryStinger infected 4,300 routers, but stresses that this is not the final number and with the campaign ongoing, will rise even more.</p><p>The majority of the victims are located in South Korea (48%) and China (32%), with notable mentions being Sweden, Malaysia, and Singapore. </p><p>AryStinger also targets QNAP’s <a href="https://www.techradar.com/news/the-10-best-nas-devices-reviewed" target="_blank">NAS devices</a>, leveraging a code injection flaw in the device’s Malware Remover. This flaw, tracked as CVE-2025-11837, was first discovered during last year’s Pwn2Own event, and was patched in November 2025. The researchers don’t know how many of these devices are currently infected, and say the 4,300 figure only relates to routers.</p><p>The researchers did not attribute this attack to any particular threat actor.</p><p>To defend against AryStinger, the researchers recommend monitoring the logs for any outbound connections to the C2 and download domains (found <a href="https://blog.xlab.qianxin.com/arystinger-botnet-hijacks-legacy-routers-for-global-attacks-en/" target="_blank">here</a>), checking /tmp/bin for unrecognized binaries, and looking for processes named syswapd0h or syswapd0w.</p><p><em>Via </em><a href="https://thehackernews.com/2026/06/arystinger-malware-infects-4300-legacy.html" target="_blank"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'This creates a misleading impression of safety': Experts warn of hackers hijacking legitimate news websites and reviews to drum up publicity ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/this-creates-a-misleading-impression-of-safety-experts-warn-of-hackers-hijacking-legitimate-news-websites-and-reviews-to-drum-up-publicity</link>
                                                                            <description>
                            <![CDATA[ Fake reviews, news articles, and GitHub accounts are a potent mix for promoting malware. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Xo8Z9cRdozJkgXcf8ntiQT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 18 Jun 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:description>                                                            <media:text><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:text>
                                <media:title type="plain"><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Check Point Research uncovers PR‑style campaign distributing a Rust clipboard hijacker disguised as legitimate software</strong></li><li><strong>Attackers used phishing sites, GitHub/SourceForge projects, fake YouTube channels, and even newswire press releases to boost credibility</strong></li><li><strong>Malware swaps crypto wallet addresses from clipboard, with “Ghost Networks” manipulating reputation systems to evade detection</strong></li></ul><p>Hackers have launched a fully fledged, multi-platform PR campaign to trick people into thinking that the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> they’re distributing is actually legitimate software, experts have warned.</p><p>A report from Check Point Research warned that even those doing regular due diligence might get tricked. </p><p>At the center of the campaign is a clipboard jacker - a piece of infostealer malware that monitors the victim’s clipboard for <a href="https://www.techradar.com/news/best-bitcoin-wallets" target="_blank">cryptocurrency wallet</a> strings. When it detects one, it replaces it with a different one belonging to the attackers. That way, when a victim tries to send money from one wallet to another, they end up paying the attackers instead. Both Windows and macOS users are at risk.</p><h2 id="abusing-newswire-sites">Abusing newswire sites</h2><p>“The threat actor uses multiple channels to promote and distribute a Rust clipboard hijacker, starting with a dedicated phishing page as the central hub and extending to GitHub and SourceForge projects promoted by fake accounts,” the company said. </p><p>“A dedicated YouTube channel, using AI‑generated narrators, suspicious view spikes, and highly positive (likely coordinated) comments, further reinforces the illusion of popularity and trustworthiness.”</p><p>To distribute the malware, the attackers ran a rather aggressive PR campaign: they set up a dedicated phishing page, multiple GitHub and SourceForge projects and accounts, as well as a fake YouTube channel. But the most surprising part is distributing news articles through newswire sites.</p><p>Newswire sites are services that distribute company press releases and announcements to media outlets, journalists, websites, and investors. Most newswire services allow anyone to submit and distribute press releases, usually for a fee, but they are generally seen as a legitimate source of trustworthy news.</p><p>At the same time, the hackers went the extra mile to make sure the clipboard jacker isn’t flagged as malware. By using numerous fake accounts (so called “Ghost Networks”) they’re manipulating reputation-driven systems like VirusTotal, tricking researchers and potential users into thinking the programs are a false positive. </p><p>“Even if this campaign is not primarily aimed at large enterprises, it shows that attackers no longer rely only on classic malware distribution techniques to reach victims,” the researchers concluded. “Instead, they can manipulate reputation systems, crowd‑sourced feedback, and cross‑platform promotion to lower suspicion and attract more users.”</p><p><em>Via </em><a href="https://thehackernews.com/2026/06/crypto-clipper-campaign-abuses-fake.html" target="_blank"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The enemy within: how to stop a simple Teams message taking down your business ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/the-enemy-within-how-to-stop-a-simple-teams-message-taking-down-your-business</link>
                                                                            <description>
                            <![CDATA[ How to overcome attackers that impersonate IT support in chat and gain access to M365 tenants. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LLSHcZ7EGwtvW3RAZvpTiX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9WT9t3hZhDVD84bF8rSypL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 18 Jun 2026 09:01:52 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Andrea Sivieri ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9WT9t3hZhDVD84bF8rSypL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A line of robots typing at computers]]></media:description>                                                            <media:text><![CDATA[A line of robots typing at computers]]></media:text>
                                <media:title type="plain"><![CDATA[A line of robots typing at computers]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9WT9t3hZhDVD84bF8rSypL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft recently warned that attackers are impersonating IT <a href="https://www.techradar.com/best/best-helpdesk-software">help desks</a> on Teams to gain access – and if that sounds bad, well, it’s just the opening move. </p><p>The attack begins when an employee gets a message from an external user claiming to be part of the company’s third-party IT support. A common-enough setup, and the kind of thing you might expect in a normal working day. </p><p>Perhaps the employee is expecting a similar message for an outstanding ticket – and so they engage with the user and, when prompted, grant remote access.</p><p>Once attackers have that foothold, they can progress to execute a full tenant lockdown using only Microsoft's own legitimate features, without ever deploying traditional ransomware. It won’t look like <a href="https://www.techradar.com/best/best-malware-removal">malware</a>, and that means traditional defense systems won't catch it. </p><p>A real-time chat in a sanctioned <a href="https://www.techradar.com/best/best-online-collaboration-tools">collaboration tool</a>, with a plausible IT support pretext is hard for busy employees to spot. For hackers, it’s a simple way to gain access to privileged and confidential data. </p><p>All they need is a few user-approved clicks and they have gained access to Quick Assist, registry persistence, lateral movement across the victim's environment and eventual data exfiltration over HTTPS. All without triggering suspicion.  </p><p>Data theft is just the opening move. Once attackers have privileged access through this kind of social engineering, the same foothold opens the door to full tenant ransom scenarios. Attackers can encrypt OneDrive and SharePoint content at scale, locking legitimate administrators out of the tenant by hijacking Global Admin accounts and conditional access policies. </p><p>They can hijack native M365 features like sensitivity labels to render data inaccessible.</p><h2 id="hoist-by-your-own-petard">Hoist by your own petard</h2><p>IT decision makers may believe they're covered against this kind of theft or lockout because they have <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a> protection in place, but the reality is that many are more exposed than they know. </p><p>This attack class is effectively invisible to standard <a href="https://www.techradar.com/news/best-endpoint-security-software">endpoint protection software</a>, because the encryption that locks companies out of their critical data is performed by Microsoft's own features, not malicious code. </p><p>Hang on, you might say – in that case, isn’t this an easy fix? Don’t I just log in myself and un-encrypt the data? Sadly, the solution is anything but straightforward. Recovery from a full tenant takeover can take weeks and often requires direct Microsoft intervention. </p><p>During that period of time, critical business activities are likely to be disrupted or even halted completely, leading to potentially major financial and reputational losses.</p><p>Overall, the <a href="https://www.techradar.com/best/best-microsoft-teams-alternatives">Microsoft Teams</a> help desk impersonation attack works because it weaponizes the trust organizations put in systems like Microsoft 365. That level of often-blind trust puts organizations at risk, because native M365 controls were built for administration, not for resilience against real-time social engineering.</p><h2 id="building-360-protection-for-365">Building 360 protection for 365</h2><p>Clearly, the risk posed by this kind of social engineering attack is significant. It highlights the fact that Microsoft 365 has become critical infrastructure that demands a dedicated operational control plane, not just admin tooling. Businesses cannot simply plug, play, and walk away, hoping the system will protect itself. They need to have a deep level of insight into what’s going on across their tenant, who has access, and whether anything unusual or suspicious is taking place.</p><p>As a result, visibility into privileged role assignments, configuration drift, and admin activity in real time is no longer optional. It's the difference between a contained incident and a business-stopping event. </p><p>Organizations need an operating layer that provides that continuous visibility across thousands of configuration attributes and follows a least-privilege administration protocol. Spotting configuration drift, privilege changes, and anomalous activity is only possible when you know what 'normal' looks like, and that requires years of telemetry across complex, real-world tenants. </p><p>This approach can help build in tenant resilience within the Microsoft 365 environment, reducing the damage that a single human slip can cause, and ringfencing malicious access quickly after a breach.</p><p>Another key consideration is the introduction of next-gen technology to improve defensive intelligence, speed, and granularity. An AI-enabled operating layer can surface anomalous configuration drift and privilege changes the moment they happen, not days later in a log review. </p><p>By drawing on proprietary tenant context - permissions, role assignments, configuration history, and behavioral baselines built from millions of real-world events - AI can surface malicious activity that generic tooling would miss entirely. </p><p>In cases like these, a rapid response is crucial. The quicker controllers are alerted to the danger, and the quicker entry is revoked for the suspicious user, the lower the chance of either a data breach or a lockout.</p><p>At root, the Teams attack exploits the oldest <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> risk in the book: human error. No organization's staff are error-proof, which means additional defensive help is required to preserve the integrity of critical M365 tenants. </p><p>In reality, the addition of a powerful, intelligent control layer is the only way businesses can prevent a single approved remote session from escalating into domain-wide compromise.</p><p><em></em><a href="https://www.techradar.com/pro/best-active-directory-documentation-tool-of-year"><em>We feature the best Active Directory documentation tools</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Gamers beware — experts flag Steam Workshop is being abused to spread malware via Wallpaper Engine app ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/gamers-beware-experts-flag-steam-workshop-is-being-abused-to-spread-malware-via-wallpaper-engine-app</link>
                                                                            <description>
                            <![CDATA[ Even a wallpaper can carry a virus these days, so be careful what you're downloading. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">B3V2m3Yxk6tVMC8s5Vf7DG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ijYNM9nFwBzeyTVPTzBdBj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 17 Jun 2026 17:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ijYNM9nFwBzeyTVPTzBdBj-1280-80.jpg">
                                                            <media:credit><![CDATA[Wallpaper Engine]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wallpaper Engine app, available on Steam.]]></media:description>                                                            <media:text><![CDATA[Wallpaper Engine app, available on Steam.]]></media:text>
                                <media:title type="plain"><![CDATA[Wallpaper Engine app, available on Steam.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ijYNM9nFwBzeyTVPTzBdBj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Kaspersky found Steam Workshop wallpapers weaponized to deliver malware via Wallpaper Engine</strong></li><li><strong>Dozens of malicious “application wallpapers” downloaded tens of thousands of times, spreading backdoors, infostealers, miners, and ransomware</strong></li><li><strong>Valve removed the infected uploads, but users warned attackers could easily re‑upload new ones</strong></li></ul><p>Steam Workshop, a community platform built into Steam that allows users to share custom content, was being used to infect gamers with malware, researchers have claimed.</p><p>For at least half a year, gamers that used the platform to download certain wallpapers were being served various malware, Kaspersky recently explained.</p><p>This campaign has been running since at least late 2025, Kaspersky said - with some sources noting the majority of the victims are in <a href="https://cyberinsider.com/steam-workshop-hosts-wallpapers-with-account-stealing-malware/" target="_blank">Russia and China</a>.</p><h2 id="dozens-of-malicious-wallpapers">Dozens of malicious wallpapers</h2><p>Steam is a hugely popular digital distribution platform for PC games, developed by a company called Valve. Baked into it is Workshop, a community tool where gamers can share mods, maps, skins, wallpapers, and other add-ons for games and applications.</p><p>Among other things, Steam Workshop allows gamers to use Wallpaper Engine, a desktop customization application that supports more than just “static” image wallpapers. With it, gamers can have videos, interactive animations, and even entire applications, displayed as a wallpaper.</p><p>And that is where the problem lies - hackers have been using application wallpapers as delivery mechanisms for different <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, including backdoors and cryptojackers.</p><p>"We discovered dozens of these malicious application wallpapers floating around Steam Workshop, and each one had already been downloaded thousands – or even tens of thousands – of times," Kaspersky said.</p><p>Looking deeper into the weaponized wallpapers, Kaspersky found that the malware is often either bundled in the package, or delivered inside a password-protected archive. The payload itself gets executed automatically the moment the user installs the wallpaper, it was said. In one example, Kaspersky was served a backdoor, and in another, an infostealer. Lumma and Vidar infostealers, cryptocurrency miners, botnet loaders, RanEngine, and even ransomware strains, were all being distributed this way. </p><p>Kaspersky disclosed its findings only after Steam identified and removed all of the malicious wallpaper applications. However, users should approach with caution, because there’s nothing stopping the threat actors from simply uploading new ones.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/steam-workshop-abused-to-spread-malware-via-wallpaper-engine-app/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why security leaders are cautious about agentic AI ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/why-security-leaders-are-cautious-about-agentic-ai</link>
                                                                            <description>
                            <![CDATA[ Agentic AI can improve security operations, but only with strong oversight and real context. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6PsQPF8bBKTztASxR92V6W</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 17 Jun 2026 10:58:04 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Howie Koh ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg">
                                                            <media:credit><![CDATA[Thapana Onphalai via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:description>                                                            <media:text><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:text>
                                <media:title type="plain"><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Agentic AI is everywhere in <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> right now, but it often feels like everyone is using the term slightly differently. </p><p>Vendors are quick to mention it, yet rarely stop to explain what it actually means in practice or what problem it’s meant to solve. </p><p>For security leaders, that makes it a difficult space to navigate, especially when expectations are high but clarity is still catching up.</p><p>At its core, agentic AI describes a goal-oriented system of multiple agents that can act, sometimes autonomously, towards an outcome. That is a concept, not a cybersecurity result. </p><p>In software development, the value is more straightforward. Multiple agents can collaborate to write, test, and improve code. In cybersecurity, the environment is far more fragmented. </p><p>Tools span <a href="https://www.techradar.com/news/best-endpoint-security-software">endpoint</a>, network, identity, cloud, vulnerability management, and response. If agentic AI is limited to a single vendor’s ecosystem, it cannot deliver meaningful outcomes. It simply operates within another silo.</p><h2 id="the-challenge-of-fragmented-security-environments">The Challenge of Fragmented Security Environments</h2><p>The cybersecurity industry has long talked about platformization, but in practice many platforms have become larger collections of disconnected capabilities. This is where many early implementations fall short. </p><p>Instead of transforming workflows, they provide a chat interface that allows operators to query multiple systems. While this may improve usability, it actually increases cognitive load. </p><p><a href="https://www.techradar.com/news/best-internet-security-suites">Security</a> teams need to know what the platform is capable of, ask the right questions, interpret results, correlate findings, and decide on actions.</p><h2 id="why-caution-is-justified">Why Caution Is Justified</h2><p>Security leaders are right to approach agentic AI carefully. The market is full of bold claims about autonomous systems that can solve complex problems without human input. In reality, most of these systems are far from that level of capability. </p><p>Without expert level instruction, agentic systems cannot operate autonomously in a reliable way. Many current solutions depend on users crafting prompts and interpreting outputs. </p><p>Transparency is another concern. If a vendor cannot clearly explain how their system works, what data it uses, and where human oversight applies, it is difficult to trust the outcomes. In security operations, where decisions can have direct business impact, that lack of clarity is unacceptable.</p><h2 id="the-role-of-guardrails-and-human-oversight">The Role of Guardrails and Human Oversight</h2><p>Effective agentic AI in cybersecurity must include strong guardrails and human-in-the-loop control. Security teams can use AI to accelerate investigation, analysis, and prioritization, but final decisions must remain with people.</p><p>Actions need to be explainable, traceable, and auditable. Security leaders must be able to understand why a recommendation was made and what evidence supports it. Without that, trust quickly breaks down.</p><p>The goal is not to remove humans from the process, but to give them better information faster and reduce the number of manual steps required to reach a decision.</p><h2 id="planning-past-the-hype-cycle">Planning Past the Hype Cycle</h2><p>The industry is already moving beyond early experimentation. Agentic workflows are beginning to reshape how security operations function. In some cases, they will reduce the need for traditional orchestration approaches as <a href="https://www.techradar.com/best/best-bi-tools">intelligence</a> becomes embedded directly in investigation and response.</p><p>At the same time, new models, like Mythos, are emerging that can assess vulnerabilities and provide deeper insight into risk. These developments will challenge tools that rely heavily on static analysis or periodic assessments.</p><p>Mythos has transformed the vulnerability detection space and we’re starting to see disruptive volumes of findings. But, what happens 12 months from now after the number of findings plateau? How will your agentic tools detect misconfiguration or poor posture and take remediation action for those vulnerabilities that did not get patched? </p><p>That’s where the real test begins. Agentic AI offering lasting value should move beyond discovering issues to continuously identifying root causes, detecting drift in posture or configuration, and guiding remediation over time.</p><h2 id="what-good-looks-like-in-practice">What Good Looks Like in Practice</h2><p>When implemented correctly, agentic AI can deliver meaningful benefits. Consider a <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a> incident. Instead of requiring an analyst to manually investigate across multiple tools, an agentic system could connect events across endpoint, network, and identity data.</p><p>It could identify that <a href="https://www.techradar.com/best/best-malware-removal">malware</a> execution is linked to a disabled protection control, trace lateral movement attempts, and highlight indicators of compromise. All of this information can be presented as a clear, evidence based narrative.</p><p>Rather than sorting through alerts, the analyst is given a concise understanding of what happened, why it matters, and what actions can be taken. This might include isolating affected systems or restricting access to contain the threat.</p><h2 id="reducing-noise-and-improving-decision-making">Reducing Noise and Improving Decision Making</h2><p>One of the biggest challenges in security operations is the volume of alerts. Agentic AI has the potential to improve the signal to noise ratio by correlating data and focusing attention on what truly matters.</p><p>By combining evidence from multiple sources, it can escalate only the most critical issues and provide clear reasoning behind those decisions. This allows teams to respond more quickly and with greater confidence.</p><p>Today, many investigations take hours or even days. By automating key steps, agentic AI can reduce that time significantly, helping teams keep pace with fast moving threats while reducing burnout.</p><h2 id="what-to-prioritize">What to Prioritize</h2><p>Security leaders need to separate <a href="https://www.techradar.com/best/best-online-marketing-services">marketing</a> claims from real capability. Many vendors promote AI, but few are using it to fundamentally improve how security work is done. The focus should be on solutions that reduce detection and response time and improve operational efficiency.</p><p>Strong solutions are grounded in real data. They rely on tools that directly observe activity across endpoint, network, identity, and cloud environments. This data provides the foundation for accurate analysis and decision making.</p><p>Equally important is the ability to take action. Systems that only generate alerts or tickets add friction. The most valuable platforms enable teams to act within the same workflow, whether that means isolating devices, enforcing policies, or guiding response actions.</p><h2 id="a-practical-path-forward">A Practical Path Forward</h2><p>Not all consolidation is beneficial. Security teams should avoid solutions that add noise without improving clarity.</p><p>They should also be cautious of systems that rely heavily on open ended prompts. These interfaces often shift the burden onto the user, forcing them to determine what questions to ask and whether the system can answer them.</p><p>Security leaders should avoid AI that produces unreliable or unsupported outputs. Effective agentic AI must be grounded in repeatable workflows and supported by verifiable evidence.</p><p>Agentic AI has potential to improve cybersecurity operations, but only when it is applied thoughtfully. The goal is not full automation, but meaningful augmentation of human expertise.</p><p>CISOs should adopt a measured approach. Invest in solutions that provide clear value today, maintain governance and oversight, and build toward greater capability over time. By focusing on outcomes rather than hype, security leaders can take advantage of agentic AI without introducing unnecessary risk.</p><p>Success will come from using AI to make security teams faster, more informed, and more effective while keeping humans firmly in control of decisions that matter most.</p><p><em></em><a href="https://www.techradar.com/best/best-identity-management-software"><em>We rank the best identity management software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How can businesses respond to the next generation of AI? ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/how-can-businesses-respond-to-the-next-generation-of-ai</link>
                                                                            <description>
                            <![CDATA[ As AI lowers the barrier of entry for cybercriminals, the baseline for defense must too rise. Anthropic AI’s Mythos model is a wake-up call. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oBx4EhWdCXxB5edqsUjUvE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 17 Jun 2026 07:14:25 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sujatha S Iyer ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg">
                                                            <media:credit><![CDATA[Blue Planet Studio/Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:description>                                                            <media:text><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:text>
                                <media:title type="plain"><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As AI models continue to evolve, including newer systems such as Claude Mythos, conversations around their impact on cybersecurity are becoming more common. </p><p>While headlines can sometimes overstate the risks, the broader reality is that increasingly capable <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> may also make cyberattacks more sophisticated and accessible. </p><p>For UK businesses, this is a reminder that cyber resilience isn’t just an AI issue. </p><p>It’s a priority which requires board-level attention. </p><p>As AI lowers the barrier of entry for cybercriminals, the baseline for defense must rise too.  </p><h2 id="ai-s-impact-on-cybercrime">AI’s impact on cybercrime </h2><p>AI has turbocharged the arsenal of cyber-attackers. For instance, sophisticated tools can enable fraudsters to launch large-scale identity attacks via methods such as deepfake images, document spoofing, and synthetic identities.  </p><p>These technologies are all scalable and automated which means the speed of compromise has narrowed from days to minutes. Hacks are often happening faster than organizations can respond. And increasingly accessibility to the technology means it can be weaponized by anyone. </p><p>It is important to stress that while this paints a bleak picture, the same technology can be leveraged by organizations to detect anomalies and strengthen <a href="https://www.techradar.com/best/best-identity-management-software">identity management</a>. But as these technologies continue to evolve, organizations can no longer rely on traditional fraud detection methods.  </p><h2 id="the-shift-from-reactive-to-pre-emptive">The shift from reactive to pre-emptive  </h2><p>Many organizations are still following yesterday’s security methods to deal with today’s threats. A reactive <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> approach is no longer enough in an era where AI driven attacks are accelerating and expanding the attack surface. </p><p>That doesn’t mean businesses shouldn’t have a recovery strategy: having a plan in place to detect attacks and respond to incidents is still key. But prevention and prediction are now the name of the game. </p><p>Businesses should focus on building an approach which shifts the focus of security teams from detection and response to prevention. This includes using technology such as AI to anticipate threats and focus on validating security control. This prevents attackers from exploiting vulnerabilities and enables continuous testing and verification of methods.  </p><p>Traditional perimeter-based approaches are no longer sufficient when threats are becoming more adaptive and intelligent. Instead, organizations need to prioritize continuous <a href="https://www.techradar.com/best/best-network-monitoring-tools">network monitoring</a>, identity-first security, and rapid incident response capabilities that can keep pace with AI-driven threats. </p><p>Failure to do so means that businesses risk major security incidents, financial losses, and competitive disadvantage. </p><h2 id="strengthening-cyber-hygiene-at-every-level">Strengthening cyber hygiene at every level </h2><p>The cyber resilience of businesses also depends on strengthening cyber hygiene at every level. Even the most advanced tools can be undermined by poor <a href="https://www.techradar.com/best/best-patch-management-tools">patch management</a> or lack of employee awareness. </p><p>Training and development are crucial for employees to acquire the necessary skills to utilize AI effectively and explore new opportunities. Businesses should also focus on continually educating their employees on the secure usage of generative AI systems.  </p><p>This should be alongside <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity </a>training – such as helping employees at all levels to identify the tell-tale signs of AI-driven attacks. And implementing strong password policies is also crucial.  </p><p>It’s also critical to focus on periodic patching of endpoints. The first level of <a href="https://www.techradar.com/best/best-malware-removal">malware</a>, <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a>, and phishing-based attacks often happens on an endpoint. Here, AI is a friend rather than a foe: AI-driven security decisions, continuous risk assessment, and platform-level integration help to protect endpoints. </p><h2 id="the-key-takeaway">The key takeaway </h2><p>New cybersecurity risks, the growing influence of AI, and the expectations of clients and regulators all means that UK businesses need to supercharge their cyber approach. Not only can a comprehensive and effective recovery plan help business bounce back with minimal impact - but it’s cheaper than paying the price of a breach. </p><p>Looking to the future, the evolution of AI – including ever-improving agents - will pose new threats to businesses. Organizations should rethink their approaches, with a traditional response driven strategy no longer sufficient when threats are becoming more adaptive and intelligent. Instead, a preemptive security model can enable them to keep pace with AI-driven threats. </p><p>It’s also worth remembering that AI can be used to play a role in protecting businesses. Mozilla tested Mythos on its Firefox browser and found 271 flaws. It was able to fix them. It’s encouraging that these flaws were ones that could have been found by a human researcher – and that the AI was able to discover them quickly and at scale. </p><p>While these AI tools should encourage organizations to rethink their assumptions about threat actors, their powers can also be used for good.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>We've reviewed and rated the best antivirus software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ In the age of AI-based threats, zero-trust is no longer enough ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/in-the-age-of-ai-based-threats-zero-trust-is-no-longer-enough</link>
                                                                            <description>
                            <![CDATA[ The emergence of AI-based threats means zero-trust is no longer strong enough to tackle these alone. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ndXZWkWw5QiWNAUqJEmtKc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 16 Jun 2026 14:21:15 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dr. Lyron Andrews ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / ZinetroN]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Nytt DDoS-rekord]]></media:description>                                                            <media:text><![CDATA[Concept art representing cybersecurity principles]]></media:text>
                                <media:title type="plain"><![CDATA[Concept art representing cybersecurity principles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As AI-based threats continue to dominate the conversation around security, it’s no surprise that half (50%) of organizations are on track to adopt zero-trust data governance by 2028. In the past few years, zero-trust has become the cornerstone of modern <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> strategy – but the emergence of AI means it’s no longer strong enough to tackle rapidly developing AI-based threats alone.</p><p>As AI threats continue to rise, CISOs are challenging the misconception that zero-trust architecture (ZTA) is a one-size-fits-all solution which can give organizations peace of mind, and means they don’t need to worry about security. Instead, they are focused on maximizing ZTA’s capabilities while also recognizing its shortcomings and where additional forms of security are necessary.</p><p>Some professionals argue that <a href="https://www.techradar.com/best/ztna-solutions">zero trust</a> is nothing more than OAuth, but in reality ZTA is far more comprehensive and is a strategic framework, not just a protocol. With deepfake fraud attempts rising 94% year-on-year and attack surfaces expanding, ZTA is more important than ever, but AI-backed attacks growing by almost 100% in 2025 means that other forms of security are also necessary.</p><p>ZTA can strengthen cybersecurity by continuously assessing access, but it cannot fully prevent insider attacks, software vulnerabilities or physical security breaches. As AI learning models advance in their capabilities to enter systems unnoticed, a variety in security protocols are needed to challenge it.</p><h2 id="why-the-protection-doesn-t-change-regardless-of-the-threat">Why the protection doesn’t change, regardless of the threat</h2><p>Traditional cybersecurity models, including ZTA, were designed around predictable human behavior and manually executed attacks, but the rise of AI-powered systems means that speed and scale of attacks has changed significantly.</p><p>ZTA-based security systems were built and implemented at a time when the biggest threat to security was human threat actors entering systems to download <a href="https://www.techradar.com/best/best-malware-removal">malware</a> onto them. This is timely and very manual, with threat actors trying lists of passwords to enter systems or sending phishing emails. AI-driven autonomous systems can operate independently, so while the core principles of security remain unchanged, the methods used to implement them must evolve to address the threats these systems face.</p><p><a href="https://www.techradar.com/news/best-internet-security-suites">Internet security</a> systems still depend on protecting attack surfaces, which are consistently expanding due to the introduction of new pathways for autonomous decision-making and machine-to-machine interaction. AI systems require more connectivity compared with manual ones, creating more opportunities for agents to exploit vulnerabilities both intentionally and accidentally.</p><p>Natural <a href="https://www.techradar.com/best/best-language-learning-apps">language</a> itself is also an attack surface, with AI systems accepting ambiguous instructions without questioning their context or intention. This means attackers can manipulate systems through emails, messages and hidden text, creating new attack surfaces and making AI agents far more vulnerable to attacks than traditional systems, which require detailed code inputted by a skilled developer to operate.</p><p>Human-in-the-loop controls are crucial for natural-language based attacks, with systems unable to distinguish between suspicious or correct prompts. Maintaining human controls over security measures, even those that are largely automated, ensures that attacks which use natural language or hidden context can be identified.</p><h2 id="a-measurable-approach-to-security-minimizes-blast-radius">A measurable approach to security minimizes blast radius</h2><p>ZTA minimizes an attacker’s ‘blast radius’ by assuming that no user or device should be inherently trusted, even once initial access has been granted. It prevents threat actors from moving across systems, meaning that should a compromise happen, the attacker will struggle to reach sensitive systems or escalate privileges without permission.</p><p>AI accelerates attack attempts, scanning environments continuously and testing permissions automatically. It can adapt strategies in real time, changing methods of attack and discovering system weaknesses much faster than humans can through manual searches. AI attacks increasingly exploit layers including workflows and agent-to-agent interactions, changing the fundamentals of what is required of ZTA systems.</p><p>As a result, ZTA systems must evolve beyond static identity and <a href="https://www.techradar.com/news/best-access-control-systems">access controls</a> to continuously monitor interactions between autonomous agents, responding dynamically to abnormal activity in real time and shifting zero-trust from a user-focused model to one capable of governing machine-to-machine ecosystems.</p><p>By using quantifiable data and continuous evaluation, cybersecurity teams can determine whether newly implemented controls are effective, turning security systems into an evidence-based process.</p><h2 id="misconceptions-around-zta-can-lead-to-heightened-security-threats">Misconceptions around ZTA can lead to heightened security threats</h2><p>Many experts believe that ZTA means AI can be deployed safely without additional security controls. ZTA reduces certain categories of risk but does not guarantee total safety once AI has entered a system, or has been built into internal workflows.</p><p>Zero-trust was built around human identity, and focuses on verifying who a user is, whether they are acting unusually and if their device is compliant. But AI-based threats can enter systems successfully using false biometrics or by guessing passwords, or may have been given access to a system previously to automate tasks.</p><p>An authorized AI agent can leak sensitive data or misuse the tools it already has access to without ever alerting ZTA that something is wrong. In order to use ZTA accurately, cybersecurity professionals must avoid overconfidence in its ability to ensure that AI systems behave safely or truthfully once access is granted.</p><h2 id="diversifying-security-defenses-against-ai-driven-threats">Diversifying security defenses against AI-driven threats</h2><p>Alongside ZTA, organizations must also implement additional tools to protect against attacks - systems that ensure that AI is not left unsupervised to make its own decisions without interference. AI systems continuously evolve, with models updating regularly, meaning organizations need strict governance processes and safety benchmarking to become a permanent part of security, not just occasional checks every few weeks or months.</p><p>As threats continue to diversify and evolve, security needs to do the same, and one-size-fits-all systems are quickly becoming a thing of the past. For CISOs, a multi-pronged approach can keep their organizations safe and prevent various different types of attacks. Combining approaches including ZTA, threat intelligence and human-in-the-loop can create overlapping layers of protection that reduce single points of failure.</p><p>Mature ZTA implications make access decisions dynamically using contextual factors, allowing systems to continuously evaluate risk and limit lateral movement even if credentials are compromised. Agentic AI does not render ZTA useless, but its autonomous behavior means ZTA systems need to become more context-aware and adaptive in order to govern machine-drive interactions in real time.</p><p><em></em><a href="https://www.techradar.com/best/best-patch-management-tools"><em>We feature the best patch management software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why your help desk is still your biggest security risk ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/why-your-help-desk-is-still-your-biggest-security-risk</link>
                                                                            <description>
                            <![CDATA[ Help desks are your biggest security risk. AI fuels identity's critical vulnerability. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iwfL78WFPbwvp3oM6SzY3B</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 15 Jun 2026 10:23:43 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Greg Nelson ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:description>                                                            <media:text><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:text>
                                <media:title type="plain"><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>When MGM Resorts suffered a crippling cyberattack in 2023, forensic teams expected to find sophisticated <a href="https://www.techradar.com/best/best-malware-removal">malware</a> or a zero-day exploit. Instead, they discovered something far simpler: an attacker called the help desk, impersonated an employee, and was handed the keys to the kingdom. Marks & Spencer and Harrods fell victim to similar attacks in 2025. </p><p>This pattern reveals a harsh reality – organizations spend millions hardening networks and endpoints while leaving identity, their most vulnerable entry point, completely exposed.</p><p>What's changed is not that help desks are vulnerable. <a href="https://www.techradar.com/news/best-internet-security-suites">Security</a> teams have known this for years. What's new is the convergence of two forces that have turned a known weakness into an urgent crisis.</p><p>Help desks make sure that locked-out <a href="https://www.techradar.com/best/best-employee-scheduling-software">employees</a> can get back to work as quickly as possible. However, the pressure to restore productivity creates an environment where speed often trumps security.</p><p>The typical interaction follows a predictable path: the caller provides basic identifying information, explains why they need access, and receives credentials. For an attacker who has done minimal reconnaissance on LinkedIn or company websites, this is trivial to replicate.</p><p>This attack vector is particularly dangerous because it bypasses most security controls like firewalls, endpoint detection, and network monitoring. These measures are blind to an attacker who talks their way through the front door with legitimate credentials issued by your own staff.</p><h2 id="why-this-old-problem-demands-new-urgency">Why this old problem demands new urgency</h2><p>Artificial intelligence has lowered the barrier for social engineering attacks. An attacker just needs the right tools and basic information to create real damage. The U.S. Department of Health and Human Services has warned that adversaries are using AI voice impersonation to target hospital help desks.</p><p>Accelerated by AI, phishing and spoofing scams increased by over 85%, and the average financial losses have more than doubled from $1,000 to $2,060.</p><p>At the same time, most organizations have embraced zero-trust principles for network access while performing perfunctory security checks to check help desk interactions. An employee accessing a file server goes through multiple verification steps.</p><p>An unknown caller asking the help desk to reset that same employee's <a href="https://www.techradar.com/best/password-generator">password</a> may face nothing more than security questions with answers easily found online.</p><h2 id="three-best-practices-for-help-desk-security">Three best practices for help desk security</h2><p>The most common pushback to strengthening <a href="https://www.techradar.com/best/best-helpdesk-software">help desk</a> security is operational. What happens when an executive loses their phone while traveling? What if an employee legitimately cannot access their registered device?</p><p>The answer is tiered response protocols combined with three interconnected controls that close the help desk vulnerability gap:</p><p><strong>1. Harden identity operations</strong>. Every access request should trigger the same verification standards. Multi-factor authentication cannot be optional or easy to bypass.</p><p>Implement passwordless, phishing-resistant authentication methods using industry standards. However, even passwordless systems can be compromised if credential recovery and enrollment processes remain vulnerable to social engineering.</p><p>Security questions based on static information should be replaced with dynamic verification that is harder to research or guess. Conduct regular identity governance reviews to eliminate stale accounts and ensure no identity has more access than necessary.</p><p><strong>2. Tie device enrollment to identity. </strong>When you reset credentials or restore access, verify that the receiving device belongs to the legitimate user. Device-bound passkeys cryptographically tie <a href="https://www.techradar.com/best/best-authenticator-apps">authentication</a> to a specific physical device and cannot be synced or transferred. This provides stronger assurance than synced passkeys, which can move between devices.</p><p>An attacker cannot call in, get a password reset, and access systems from an unmanaged device. The device need not be corporate-owned, but it must be registered and verified as part of the user's identity profile. Requiring this device-bound verification for any credential change immediately narrows the attack surface.</p><p><strong>3. Use bi-directional verification to keep both employees and help desks secure</strong>. Both parties need the ability to verify each other, depending on who initiates contact. When a user contacts the help desk, the agent should verify their identity before taking action.</p><p>Before resetting credentials or granting access, use callbacks to registered numbers or send verification codes to registered devices. This protects against attackers impersonating employees, as seen in the MGM and Harrods breaches. When the help desk reaches out to users, employees should have a way to verify the legitimacy of the contact before sharing any information.</p><p>This protects staff from scammers posing as IT support. Verification capability in both directions ensures neither help desk personnel nor employees become vulnerable entry points for attackers.</p><h2 id="tiered-response">Tiered response</h2><p>Apply these controls using tiered response protocols. Proceed with standard verification for low-risk requests (password hints, account status checks). For high-risk actions (credential resets, permission changes, device enrollments), require elevated verification.</p><p>For truly urgent situations, establish escalation paths that maintain security. A traveling executive who lost their <a href="https://www.techradar.com/news/best-business-smartphone">phone</a> should contact their direct manager for verification before support acts. An employee with a broken device should visit IT in person with identification.</p><p>These controls are most effective when they work together. <a href="https://www.techradar.com/best/best-identity-management-software">Identity</a> verification without device verification leaves gaps, while device verification without hardened identity operations can be circumvented. Both are undermined if help desk workflows bypass these controls in the name of convenience.</p><p>Technology only cannot solve a people problem, but it can make the right behaviors easier and the wrong behaviors harder. Help desks will always be targets because they control access.</p><p>The question is whether organizations will continue treating them as trusted channels immune to compromise, or recognize them as the critical security control points they have become.</p><p>Breaches will continue. Attackers will keep calling. But organizations that recognize help desks as the critical identity control points they are, and secure them accordingly, can finally close the door that's been left open for too long.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are using TikTok videos offering 'free Spotify Premium' to spread malware and steal passwords ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/hackers-are-using-tiktok-videos-offering-free-spotify-premium-to-spread-malware-and-steal-passwords</link>
                                                                            <description>
                            <![CDATA[ Videos advertising free subscriptions are leading victims away to download and install malware via command-line tools. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KyiMnDdJEodaXo9D6zhJN8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 11 Jun 2026 16:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:description>                                                            <media:text><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>TikTok and Instagram Reels now being used to target victims</strong></li><li><strong>"Free" Spotify, Microsoft, Adobe subscriptions targeting cash-strapped users</strong></li><li><strong>Social engineering is still the top vector, but basic account security measures do a lot of the heavy lifting</strong></li></ul><p>A new report from <a href="https://www.reversinglabs.com/blog/social-media-attacks-phishing" target="_blank">ReversingLabs</a> is warning doomscrollers of videos spreading across short-form platforms like TikTok and Instagram Reels infecting users with password-stealing malware.</p><p>The videos typically promise free access to subscriptions like Spotify Premium, Windows, Office and Adobe – an instant, telltale sign that things might not be as they seem.</p><p>Instead of receiving phishing emails, victims are instructed to open command-line tools like PowerShell, then paste and run the command shown in the video.</p><h2 id="watch-out-for-this-info-stealing-malware">Watch out for this info stealing malware</h2><p>When they run the command, it triggers a piece of malware to be downloaded and installed to a victim's computer. Vidar, the infostealer, targets usernames, passwords, cookies, session tokens, cryptocurrency wallet data, personal files and documents, and other sensitive information.</p><p>But more importantly, it marks a significant change – previously, email phishing campaigns have been extremely popular for gaining access to victims' credentials, with a simple click of a link leading to potential disaster. This newer method relies on victims physically inputting commands into a tool, which requires more patience.</p><p>Ultimately, the attack exploits current economic strains and the fact that consumers are looking out for cheap and free alternatives to popular subscriptions.</p><p>"This kind of social engineering is an easy way for threat actors to drive traffic off social media and onto an attacker-controlled malicious website," the researchers wrote.</p><p>Regardless, the overarching theme is that social engineering remains the clearest path for attackers to reach victims, and that's good news because there are many basic principles could-be victims can follow, like using multi-factor authentication to secure accounts.</p><p>Being wary of suspiciously cheap or free products/services and only downloading software from official vendors would also help in this instance.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Fake X-VPN installers found to spread credential-stealing malware — here's how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/vpn/vpn-privacy-security/fake-x-vpn-installers-found-to-spread-credential-stealing-malware-heres-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ Researchers found a trojanized X-VPN installer used to deploy STX RAT malware. X-VPN itself was not breached, and only attacker-hosted downloads are affected. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">U7ZvbWfADGzg973ugNchhG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5pmsJs3KfnrtbsM98UsnG9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 10 Jun 2026 09:30:44 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[VPN Privacy &amp; Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ monicajwrites@gmail.com (Monica J. White) ]]></author>                    <dc:creator><![CDATA[ Monica J. White ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/6AQ4y5nzk8kQ47Yp69GERj.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Monica is a journalist with over a decade of experience in covering technology.&lt;/p&gt;&lt;p&gt;She writes about the latest developments in computing, which means anything from computer chips made out of paper to cutting-edge desktop processors. Her coverage includes CPUs, GPUs, and everything else that goes into a PC or a laptop, but also peripherals.&lt;/p&gt;&lt;p&gt;GPUs are Monica’s main area of interest, and nothing thrills her quite like that time every couple of years when new graphics cards hit the market. She’s always keeping tabs on the latest from Nvidia, AMD, and Intel, including both the hardware and the software that powers our PCs.&lt;/p&gt;&lt;p&gt;As an avid gamer, her focus is always on the consumer and whether something works well and provides adequate value for the money. She believes that PC building can be intimidating, so her goal is to explain complex concepts in an approachable manner while still digging into the technical nitty-gritty we all love to learn more about.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5pmsJs3KfnrtbsM98UsnG9-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Malware kan ställa till med oreda]]></media:description>                                                            <media:text><![CDATA[Android phone malware]]></media:text>
                                <media:title type="plain"><![CDATA[Android phone malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5pmsJs3KfnrtbsM98UsnG9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Fake X-VPN installer found to deploy credential-stealing malware</strong></li><li><strong>X-VPN was not hacked; only those downloading the fake app were affected</strong></li><li><strong>First targeting crypto traders, criminals widened to privacy-minded users</strong></li></ul><p>A new report has uncovered an uncomfortable truth for anyone who downloads software from somewhere other than the official source: a trusted-looking app can be weaponized against you.</p><p>Threat researchers at <a href="https://www.cyderes.com/howler-cell/cpuid-hwmonitor-xvpn-dll-sideloading-stx-rat" target="_blank" rel="nofollow">Cyderes</a> have been tracking an active campaign that uses a fake X-VPN installer to deploy <a href="https://www.techradar.com/news/what-is-malware-and-how-dangerous-is-it">malware</a> known as the STX RAT, which steals credentials and hands attackers remote control of an infected machine.</p><p>Crucially, this is not a breach of <a href="https://www.techradar.com/reviews/x-vpn">X-VPN</a>, a provider that has just <a href="https://www.techradar.com/vpn/vpn-services/x-vpn-proves-its-privacy-credentials-with-new-independent-no-logs-audit">proved its privacy credentials</a> with an independent no-log audit. The company's official download channels were unaffected, and the only people at risk were those who installed a malicious copy from attacker-controlled sources. </p><p>This is a stark reminder that, even if you pick one of the <a href="https://www.techradar.com/vpn/best-vpn"><u>best VPN</u></a> services around, you still need to be careful with downloads. As <a href="https://www.techradar.com/vpn/vpn-privacy-security/google-issues-security-alert-your-vpn-app-could-be-spyware-in-disguise">Google warned</a> in its November 2025 fraud advisory, scammers are increasingly disguising malware as legitimate VPN apps to steal users' data.</p><h2 id="how-the-fake-x-vpn-attack-works">How the fake X-VPN attack works</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:840px;"><p class="vanilla-image-block" style="padding-top:25.00%;"><img id="qNFfqSgU3XNq5a4do4hKra" name="X-VPN malware campaign" alt="Timeline of X-VPN malware campaign's evolution uncovered by Cyderes (June 2026)" src="https://cdn.mos.cms.futurecdn.net/qNFfqSgU3XNq5a4do4hKra.png" mos="" align="middle" fullscreen="" width="840" height="210" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Cyderes)</span></figcaption></figure><p>As the <a href="https://www.cyderes.com/howler-cell/cpuid-hwmonitor-xvpn-dll-sideloading-stx-rat">Cyderes' findings</a> show, attackers took genuine X-VPN program files and slipped in one extra malicious file named CRYPTBASE.dll, a technique called DLL sideloading. </p><p>Because of a quirk in how Windows finds that file, the app appears to install normally while the hidden file injects the STX RAT malware straight into the computer's memory, leaving little trace for antivirus tools to catch.</p><p>Once active, STX RAT can harvest saved browser passwords and session tokens, collect system information, run commands remotely, and talk to its servers over ordinary encrypted web traffic, so it blends in. The fake VPN was one of 11 malicious packages tied to the operation, alongside trojanized installers for Binance, Bybit, MetaTrader 5, Exodus, and Steam.</p><p>The campaign began by targeting cryptocurrency traders, then pivoted to a trojanized X-VPN package to reach privacy-conscious users who often handle sensitive credentials. The same malware spread earlier through a brief compromise of the CPUID website, which Kaspersky linked to more than 150 victims across several countries and industries.</p><p>To its credit, X-VPN responded quickly, releasing Windows version 77.5.3 with hardened DLL loading controls. Users of the X-VPN app should update to that version or later.</p><h2 id="how-to-avoid-fake-vpn-apps">How to avoid fake VPN apps</h2><p>The good news is that the single most effective defense here is also the simplest and requires no technical skill. Most of these attacks fall apart the moment you refuse to download software from anywhere other than the official source.</p><p>Use the <strong>vendor's own website or an official app store</strong>, and avoid installers from third-party repositories or links sent to you. In this campaign, the files lived in an unknown Bitbucket repository.</p><p>There have been other cases of <a href="https://www.techradar.com/pro/criminals-are-using-a-dangerous-fake-free-vpn-to-spread-malware-via-github-heres-how-to-stay-safe">criminals using a fake free VPN to spread malware</a>, so <strong>treat suspiciously cheap apps as a red flag</strong>.</p><p><strong>Type the address yourself</strong> rather than clicking ads or search results, which avoids look-alike sites.</p><p><strong>Keep software updated</strong> and run reputable <strong>security software</strong> for an extra layer of protection. Because STX RAT runs in memory and tries to evade detection, a modern <a href="https://www.techradar.com/best/best-antivirus">antivirus</a> or endpoint tool gives you an extra layer of protection alongside good download habits.</p><p>If you think you installed a fake VPN, assume your passwords and sessions may be exposed. <strong>Change important passwords</strong> from a clean device, <strong>sign out everywhere</strong>, and <strong>turn on two-factor authentication</strong>. A VPN is a valuable privacy tool, but only when you install the genuine article from a source you can trust.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Someone is impersonating our business: 5 ways to fight digital squatting ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/someone-is-impersonating-our-business-5-ways-to-fight-digital-squatting</link>
                                                                            <description>
                            <![CDATA[ Digital squatting now moves money, steals login credentials, and pulls customers toward infrastructure tied to cybercrime. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eVtcz5aho6LqQe99CwSdwf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 05 Jun 2026 06:54:32 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Vaidotas Juknys ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg">
                                                            <media:credit><![CDATA[sarayut Thaneerat/ via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:description>                                                            <media:text><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:text>
                                <media:title type="plain"><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A couple of years ago, someone searching for our company found a website that looked like ours, used a version of our name, and sold proxies we had nothing to do with. </p><p>The impersonators were already operating before we rebranded from Smartproxy to <a href="https://www.techradar.com/reviews/smartproxy">Decodo</a> in April 2025. </p><p>They registered smartproxy.org and smartproxy.cn to catch the traffic searching for the original domain name, and the rebrand gave them an even larger pool of people who had not heard about the change.</p><p>In 2025, the World Intellectual Property Organization handled 6,282 domain name disputes, a record for the organization. Cybersquatting cases have risen 68% since 2020. </p><p>Digital squatting now moves money, steals login credentials, and pulls customers toward infrastructure tied to cybercrime. Here are five things we did, and five things any business can do, when someone copies your brand.</p><h2 id="what-digital-squatting-is-and-why-cases-keep-climbing">What digital squatting is, and why cases keep climbing</h2><p>Digital squatting means registering or using a domain name in bad faith to profit from someone else's trademark. A bad actor registers a domain close to an established brand, then uses it to intercept traffic, collect payments for services they never deliver, harvest login credentials, or push <a href="https://www.techradar.com/best/best-malware-removal">malware</a>. Most victims find out only after their money disappears. </p><p>Squatting comes in a few common forms:</p><p>1. Typosquatting registers misspellings of popular domains, such as gooogle.com instead of google.com;</p><p>2. Combosquatting adds a keyword to a real brand name, producing domains like brand-login.com or brand-deals.com; </p><p>3. TLD squatting takes the same brand name across .org, .net, .io, and .ai;</p><p>4. Homograph attacks swap in visually identical characters from other alphabets, like a Cyrillic "а" for a Latin "a".</p><h2 id="when-it-happened-to-us">When it happened to us</h2><p>We met digital squatting as the target, not the observer. We operated as Smartproxy for seven years, and over that time, the name picked up enough recognition for impersonators to want it. They registered .org and .cn, domains with no connection to our company, our infrastructure, or our team. The site copies a version of our former name and sells <a href="https://www.techradar.com/best/best-free-proxies">proxies</a> we have nothing to do with, catching traffic from people who searched for Smartproxy.</p><p>The squatting also shaped how we could operate in China. The obvious domains were already taken, so before the rebrand, we had to run our China presence under a separate name, smartdaili.cn. A customer in that market searching for the brand could land on an impostor site first. </p><p>The rebrand to Decodo did not end the problem. It added a fresh group of people who knew the old name and never heard about the change, which is exactly who the lookalike domains target. The harm reached real customers, and we saw it in their complaints to us. </p><p>Trustpilot reviews describe people who paid the lookalike sites, sent irreversible cryptocurrency payments, received poor support, and got low-quality service under a name they trusted.</p><h2 id="what-the-proxyway-research-found">What the Proxyway research found</h2><p>The case changed shape when researchers tested the impersonator's <a href="https://www.techradar.com/best/best-product-management-apps-of-year">product</a> directly. The independent researchers have purchased a standard weekly unlimited residential plan on smartproxy.org, the same product any retail buyer can get, and measured where its traffic actually exited. The method is one any paying customer could repeat, which is part of why the result carries weight. </p><p>Proxyway sent roughly 6.96 million HTTP requests through the plan across one week, with each request landing on an <a href="https://www.techradar.com/news/best-endpoint-security-software">endpoint</a> that logged the exit <a href="https://www.techradar.com/best/best-ip-address-tools">IP address</a>. After removing duplicates, the pool showed 2,023,029 unique IPs, of which 2,019,488 were IPv4, and 3,541 were IPv6. The success rate sat at 90.25%, in line with what the service advertised. </p><p>To find where those IPs came from, Proxyway compared the pool against a reference dataset of 16,192,293 verified IPIDEA exit nodes, observed over the 30 days ending January 29, 2026. Antoine Vastel, VP of Research at DataDome, built that dataset by routing traffic through IPIDEA endpoints himself and confirming each address as a working exit node, rather than relying on <a href="https://www.techradar.com/best/best-online-marketing-services">marketing</a> claims. IPIDEA is the residential proxy network that Google's Threat Intelligence Group disrupted back in January. </p><p>The comparison surfaced 773,087 IPs present in both pools. That figure equals 38.21% of the smartproxy.org pool and 4.77% of the IPIDEA dataset. The numbers sit in the table below:</p><div ><table><tbody><tr><td class="firstcol " ><p>Metric</p></td><td  ><p>Value</p></td><td  ></td></tr><tr><td class="firstcol " ><p>Smartproxy.org unique IPs (test pool)</p></td><td  ><p>2,023,029</p></td><td  ></td></tr><tr><td class="firstcol " ><p>IPIDEA dataset unique IPs (Vastel)</p></td><td  ><p>16,192,293</p></td><td  ></td></tr><tr><td class="firstcol " ><p>IPs present in both pools </p></td><td  ><p>773,087</p></td><td  ></td></tr><tr><td class="firstcol " ><p>Overlap as a share of smartproxy.org </p></td><td  ><p>38.21%</p></td><td  ></td></tr><tr><td class="firstcol " ><p>Overlap as a share of IPIDEA</p></td><td  ><p>4.77%</p></td><td  ></td></tr></tbody></table></div><h2 id="why-a-38-overlap-points-to-shared-sourcing">Why a 38% overlap points to shared sourcing</h2><p>Residential pools rotate, so some overlap between any two services is normal. IPinfo estimates monthly IPv4 retention in residential pools at around 40%, meaning roughly four in ten addresses visible this month remain next month, while the rest cycle out. Two pools drawing from genuinely separate apps, SDKs, and device populations should not share anything close to 38% of their IPs across a few-week window. </p><p>The IPv4 address space spans more than 4 billion addresses, so an overlap at this scale would be a statistical anomaly if the sources were independent. The pool sizes point the same way. The smartproxy.org pool of about 2 million IPs is roughly an eighth of the 16.2 million IPIDEA dataset, the proportion you would expect when one provider draws from part of a larger upstream pool. Shared sourcing explains the data cleanly.</p><h2 id="5-things-you-can-do-to-combat-digital-squatting">5 things you can do to combat digital squatting</h2><p>Each step below works on its own. Together, they cover monitoring, prevention, legal action, search, and customer communication.</p><h2 id="1-monitor-for-lookalike-domains-before-they-reach-your-customers">1. Monitor for lookalike domains before they reach your customers</h2><p>Catching a fake domain after a customer reports it means the damage has already happened. Monitoring closes that gap. </p><p>Set up these alerts:</p><p>i) Domain registration alerts for your brand name across common TLDs and misspellings;</p><p>ii) Brand-mention monitoring across search results and social platforms;</p><p>iii) Certificate transparency logs, which flag new SSL certificates issued for domains containing your brand name.</p><p>We learned the full extent of our case through third-party research and customer complaints, later than we wanted. Monitoring would have surfaced the registrations sooner. A weekly check across the main extensions and the three or four most likely misspellings of your name catches most attempts while they’re still new.</p><h2 id="2-register-your-own-domain-variations-first">2. Register your own domain variations first</h2><p>A squatter can’t register a domain you own. Defensive registration removes the easiest targets before anyone reaches for them. </p><p>Claim the obvious variations:</p><p>i) Major TLDs such as .org, .net, .io, and .ai</p><p>ii) Common misspellings of your brand name country-code domains for markets you operate in, such as .co.uk, .de, and .cn.</p><p>Turn on registrar lock, use a reputable <a href="https://www.techradar.com/news/best-domain-registrars">domain registrar</a>, and keep your registration details current. We hit this wall directly when the obvious domains in China were already taken. Claim your namespace early, because the cost of registering domains is far lower than reclaiming them later.</p><h2 id="3-use-your-legal-routes-and-know-their-limits">3. Use your legal routes, and know their limits</h2><p>Trademark law gives you specific tools against squatters. The tools work, though they move slowly, so start them early. The following is general information, not legal advice. </p><p>Your main options:</p><p>i) Register your trademark, which is the foundation for every other action;</p><p>ii) Send a cease-and-desist letter to the registrant</p><p>iii) Report abuse directly to the registrar hosting the domain.</p><h2 id="4-own-your-brand-in-search-results">4. Own your brand in search results</h2><p>When someone searches your brand, the page they click decides whether they reach you or a copy. Ranking above the impersonator removes most of their traffic. </p><p>Make the real you easy to find:</p><p>i) Publish content that states your official domains in plain language;</p><p>ii) Keep rebranding and company information current across your site and profiles;</p><p>iii) Use structured data and verified <a href="https://www.techradar.com/best/best-social-media-management-tools">social media</a> profiles so search engines confirm your identity.</p><p>We published direct, on-record clarifications so anyone searching the old brand finds the truth quickly. We say it plainly: we operate at decodo.com globally and decodo.cn in China. Everything else using the old name isn’t us</p><h2 id="5-tell-your-customers-and-keep-telling-them">5. Tell your customers, and keep telling them</h2><p>Customers can’t avoid a fake site that they don’t know exists. Telling them turns your audience into a filter against the impersonator. </p><p>Reach them through every channel you have:</p><p>i) Email warnings to your existing customer list;</p><p>ii) A banner or notice on your website;</p><p>iii) A help-center article that customers find when they search for the problem;</p><p>iv) Posts on the social accounts your customers already follow.</p><h2 id="treat-impersonation-as-a-security-problem">Treat impersonation as a security problem</h2><p>Brand impersonation now sits next to the infrastructure-trust problem the IPIDEA takedown exposed. A fake domain can route customers into compromised device pools, which makes this a question for security and legal teams, not just marketing. Give it a cross-functional owner who watches domains, files complaints, and updates customers on a schedule. </p><p>Google's action against IPIDEA reduced the available device pool for proxy operators by millions and, in Google's words, may carry downstream impact across affiliated resellers. Squatting that depends on that kind of infrastructure carries the same exposure. Demand transparency from any provider you buy from, and apply the same standard to your own supply chain.</p><p><em></em><a href="https://www.techradar.com/best/proxy"><em>We feature the best proxy sites</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Huge hacking campaign uses spoofed Ghidra, dnSpy, and SpiderFoot security tools to harvest ad revenue and serve malware ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/huge-hacking-campaign-uses-spoofed-ghidra-dnspy-and-spiderfoot-security-tools-to-harvest-ad-revenue-and-serve-malware</link>
                                                                            <description>
                            <![CDATA[ More than 100 spoofed websites were redirecting users and offering infostealers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">FYtUVENFQzU7XjYwsv6cVH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 04 Jun 2026 09:53:09 +0000</pubDate>                                                                                                                                <updated>Thu, 04 Jun 2026 09:53:13 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg">
                                                            <media:credit><![CDATA[Thapana Onphalai via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:description>                                                            <media:text><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:text>
                                <media:title type="plain"><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Over 100 spoofed sites mimic trusted security tools</strong></li><li><strong>Campaign serves SessionGate, RemusStealer, AnimateClipper</strong></li><li><strong>Primary goal appears to be traffic monetization</strong></li></ul><p>A large-scale malicious campaign was recently uncovered, spoofing reputable open-source security tools to harvest ad revenue and serve malware to developers and security researchers.</p><p>Security outfit <a href="https://research.checkpoint.com/2026/impersonation-click-hijacking-and-tds-inside-a-malware-distribution-ecosystem/" target="_blank" rel="nofollow">Check Point Research (CPR)</a> recently published an in-depth report, detailing the campaign. Apparently, threat actors created more than 100 websites spoofing tools such as Ghidra, dnSpy, and SpiderFoot. Visitors were routed through a Traffic Distribution System (TDS) and served multiple malware variants, including SessionGate, RemusStealer, and AnimateClipper.</p><p>“What makes this campaign especially notable is the choice of brands: a high-risk subset of sites impersonates trusted reverse-engineering tools such as Ghidra and dnSpy, used by security researchers and malware analysts,” the report reads.</p><h2 id="traffic-acquisition-and-monetization">Traffic acquisition and monetization</h2><p>CPR describes SessionGate as a new multi-stage loader that makes it very difficult to obtain the final payload. RemusStealer is a newly emerged infostealer targeting browsers and extensions, while AnimateClipper is a cryptocurrency clipper capable of hijacking transactions across more than 20 blockchains. </p><p>Despite these websites serving multiple malware, CPR does not believe it to be the main goal. Instead, it believes the campaign’s primary objective is traffic acquisition and monetization.</p><p>“However, by embedding a gated TDS layer and funneling search traffic into it, the operators become part of a distribution chain whose downstream consumers can include <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> distributors,” CPR stressed. “The same traffic pipeline that drives gray monetization can also selectively route real users to malicious payloads.”</p><p>While CPR did not say how many people were affected by this attack, it does stress that the campaign is rather large-scale. It involves more than 100 websites, as well as more than 5,000 total submissions to VirusTotal. </p><p>To defend against this campaign, and others like it, users are advised not to blindly trust search engine results, and to be careful when clicking on links, even when they’re at the very top of Google and other reputable engines. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Weedhack malware campaign infects 116,000 mod-hungry Minecraft players systems through SEO poisoning and YouTube ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/weedhack-malware-campaign-infects-116-000-mod-hungry-minecraft-players-systems-through-seo-poisoning-and-youtube</link>
                                                                            <description>
                            <![CDATA[ Fake mods and clients are being advertised on YouTube and used to deploy backdoors and infostealers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">YxPih94PQbFopWzBjYyoUN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kdhVdv6powtuEo3tfg5QPE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 03 Jun 2026 14:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kdhVdv6powtuEo3tfg5QPE-1280-80.jpg">
                                                            <media:credit><![CDATA[Mojang]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cobblemon mod]]></media:description>                                                            <media:text><![CDATA[Cobblemon mod]]></media:text>
                                <media:title type="plain"><![CDATA[Cobblemon mod]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kdhVdv6powtuEo3tfg5QPE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Weedhack spreads via poisoned Minecraft mods on YouTube</strong></li><li><strong>Malware disables defenses and enables remote access</strong></li><li><strong>Offered as MaaS with free and paid tiers</strong></li></ul><p>Cybercriminals are using YouTube to disseminate malware that targets Minecraft users and takes full control over their <a href="https://www.techradar.com/news/best-endpoint-security-software" target="_blank">computers</a>.</p><p>In January this year, security researchers McAfee Labs spotted a new malicious campaign dubbed Weedhack. In the campaign, the malicious actors created countless YouTube channels and standalone websites, through which they promoted links to Minecraft clients and mods. </p><p>With the help of Weedhack (apparently an enterprise-grade dashboard that also allows crooks to inject the malware into legitimate Minecraft mods), they created poisoned mods and clients which delivered a .JAR file called DonutDupe.jar.</p><h2 id="industry-support">Industry support</h2><p>This is a Java ARchive package format used in the Java ecosystem to bundle multiple files into a single archive. This file starts a chain reaction that results in Windows Defender being disabled, system information collected, and two additional payloads dropped, which establish persistence and enable remote access.</p><p>McAfee said the campaign accumulated a total of 116,464 hits, averaging approximately 2000 to 3,000 hits per day. Most of them are located in the US, with other notable mentions including Germany, India, the UK, Italy, Vietnam, Canada, Norway, Sweden, Finland, and Spain. </p><p>McAfee describes Weedhack as a ‘Minecraft-focused Malware-as-a-service’ (MaaS). The custom payloads target versions 1.21.0 to 1.21.11 of the game, while the dashboard allows malicious actors to view stolen credentials and exfiltrated system information in a centralized manner. The MaaS is apparently being offered in Telegram channels in two tiers - free and paid, and while the free version comes with plenty of features (screenshot grabber, file exfiltrator), the paid one ($4.99 a month) offers webcam access, keylogging, and reverse shell execution. </p><p>“One of the key features that makes Weedhack unique is that it is hosted on the clear net and provides access to sophisticated <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> for free," McAfee’s researchers explained. "This difference in cost and ease of access with detailed tutorials on how to use the malware significantly reduces the barrier to entry for prospective customers. Furthermore, its ability to steal Minecraft accounts attracts a younger audience. Both of these factors complement each other and make the campaign much more lethal."</p><p><em>Via </em><a href="https://thehackernews.com/2026/06/weedhack-attacks-minecraft-users.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Steam Community Profiles abused as C2 network in new WordPress malware infection campaign ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/steam-community-profiles-abused-as-c2-network-in-new-wordpress-malware-infection-campaign</link>
                                                                            <description>
                            <![CDATA[ A new cheeky malware campaign abuses the comment section as a roadsign to malware ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">EyczYyhYsLAgPaDCuuw3Fm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bx8fPhUoHLYdN39sZtNWZk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 03 Jun 2026 12:18:13 +0000</pubDate>                                                                                                                                <updated>Wed, 03 Jun 2026 12:18:18 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bx8fPhUoHLYdN39sZtNWZk-1280-80.jpg">
                                                            <media:credit><![CDATA[Valve]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo of Steam with game covers in the background]]></media:description>                                                            <media:text><![CDATA[Logo of Steam with game covers in the background]]></media:text>
                                <media:title type="plain"><![CDATA[Logo of Steam with game covers in the background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bx8fPhUoHLYdN39sZtNWZk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Malware hides payload in Steam Community comments</strong></li><li><strong>WordPress sites used to host backdoors</strong></li><li><strong>Nearly 2,000 sites compromised since July</strong></li></ul><p>Security researchers from GoDaddy found a cheeky new malware campaign that used comments made by Steam Community accounts as command-and-control (C2) infrastructure.</p><p>Here is how the attack plays out: The attackers would first find vulnerable <a href="https://www.techradar.com/best/wordpress-website-builder" target="_blank">WordPress websites,</a> or those protected by weak credentials, and use them to host PHP malware somewhere in the site’s files. For example, the sample was found in a theme’s ‘functions.php’ file. This malware contains both a JavaScript injection component, and a server-side backdoor. </p><p>Then, whenever a visitor loads the infected website, the malware contacts one of several Steam Community profiles and downloads the contents of profile comments. On surface level, these comments look harmless (albeit incoherent), but they also contain invisible Unicode characters which carry the actual payload. </p><h2 id="industry-support-2">Industry support</h2><p>“This encoding allows binary data to be embedded within normal-looking text. The visible characters serve as camouflage while the invisible characters carry the actual payload,” GoDaddy said.</p><p>The malware then extracts the characters, converts them into binary data, and reconstructs the original bytes. The researchers found that this recovered data contains a URL controlled by the attackers, which points to a domain hosting a JavaScript file spoofing a legitimate library. </p><p>The malware then uses WordPress to load the attacker-controlled JavaScript on every frontend page, which the visitors’ browsers then download and run, infecting themselves in the process.</p><p>In the campaign, there are two sets of targets - vulnerable WordPress websites, and their visitors. Since uncovering the campaign in July last year, GoDaddy said it found almost 2,000 compromised WordPress sites. Unfortunately, the research report stops short of describing what the malware does to visitors.</p><p>If you run a WordPress website, GoDaddy recommends to check for references to Steam Community URLs, external JavaScript injections, as well as outbound connections from WordPress to Steam. </p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/wordpress-malware-campaign-hides-payloads-in-steam-profiles/" target="_blank" rel="nofollow"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI Codex tool with over 29,000 downloads linked to malicious npm supply chain attack stealing authentication tokens ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/openai-codex-tool-with-over-29-000-downloads-linked-to-malicious-npm-supply-chain-attack-stealing-authentication-tokens</link>
                                                                            <description>
                            <![CDATA[ A tool started benign and turned sour after a little while, stealing tokens and granting persistent access. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vXcVe5fpJG9SzT2iRuMqu6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/t3peL5Rd9E7bXzyHuQqJ5K-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 01 Jun 2026 19:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/t3peL5Rd9E7bXzyHuQqJ5K-1280-80.jpg">
                                                            <media:credit><![CDATA[OpenAI]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Codex remote control in ChatGPT]]></media:description>                                                            <media:text><![CDATA[Codex remote control in ChatGPT]]></media:text>
                                <media:title type="plain"><![CDATA[Codex remote control in ChatGPT]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/t3peL5Rd9E7bXzyHuQqJ5K-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers uncovered a malicious npm package posing as a Codex UI tool</strong></li><li><strong>Attackers exfiltrated Codex authentication tokens, including non‑expiring refresh tokens</strong></li><li><strong>Aikido Security also found two Android apps targeting Codex users</strong></li></ul><p>A newly discovered supply-chain attack on npm is targeting software developers using OpenAI Codex.</p><p>Codex is OpenAI’s <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">coding assistant</a> and software engineering agent that can write and review code, fix bugs, run tests, and help developers build software with nothing but plain language input.</p><p>Recently it was discovered that a tool published on both GitHub and npm was actually malicious. It is called “codexui-android”, and it is described as a remote web user interface for the Codex platform. It attracted more than 29,000 weekly downloads, so it was rather popular. One of the reasons for its popularity is because it worked as advertised and appeared legitimate. The code published on GitHub remained “clean” the whole time, meaning the public source code didn’t show any malicious behavior.</p><h2 id="breaking-bad">Breaking bad</h2><p>However, approximately a month into its existence, the tool received an update on npm which added information-stealing code. It primarily hunted for OpenAI login credentials.</p><p>When a developer runs the tool, it looks for their Codex authentication tokens and exfiltrates them to an attacker-controlled server. One of the tokens (the refresh token) can potentially allow an attacker to continue accessing the victim’s OpenAI account for an extended period of time without needing the password. </p><p>The implications are rather dangerous, explained Aikido Security researcher Charlie Eriksen, who found and disclosed the attack. Besides the obvious - accessing the victim’s Codex sessions - the attacker can use the tokens to spend the victim’s API credits, to view projects or code they’re working on through Codex, and even impersonate the victim when interacting with OpenAI services. </p><p>"The refresh_token doesn't expire," Eriksen said. "An attacker holding it can silently impersonate you indefinitely. A stolen Codex refresh_token goes beyond access to a chat interface -- it's persistent, silent access to whatever that account can do."</p><p>Aikido also said it saw two Android apps, both published by the same account, who were also targeting Codex users. One is called OpenClaw Codex Claude AI Agent, running the npm package within its PRoot sandbox and sending all Codex credentials to the same, attacker-controlled server. This one had more than 50,000 downloads. The other one is called Codex and counts more than 10,000 downloads.</p><p><em>Via </em><a href="https://thehackernews.com/2026/06/openai-codex-authentication-tokens.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The biggest cyber threats businesses face in 2026 ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/the-biggest-cyber-threats-businesses-face-in-2026</link>
                                                                            <description>
                            <![CDATA[ AI-driven cyber threats are evolving fast – here's what businesses need to watch in 2026. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qHqyo7BpsQZiuawCcHDLqm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 01 Jun 2026 10:57:16 +0000</pubDate>                                                                                                                                <updated>Mon, 01 Jun 2026 10:57:29 +0000</updated>
                                                                                                                                            <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Phil Lees ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:description>                                                            <media:text><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:text>
                                <media:title type="plain"><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As industries become more digitalized, cybercrime is evolving just as fast. In 2026, <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cyber security</a> threats are no longer opportunistic; they’re intelligent, automated and highly targeted. No organisation is too small to be ignored by cybercriminals.  </p><p>This is borne out in the UK Government’s Cyber Security Breaches Survey 2025, which suggests that 43% of businesses and 30% of charities reported a cyber breach or attack during the previous 12 months. That’s an astonishing 612,000 UK businesses and 61,000 charities affected. </p><p>Despite these statistics, there are ways organizations can minimize breach risk, from identifying key cyber threats to understanding how businesses can stay safe and prepare for what’s next.  </p><h2 id="the-10-most-common-cyber-threats">The 10 Most Common Cyber Threats</h2><p>Let’s start with my list of the 10 most common cyber threats businesses need to prepare for. </p><h2 id="1-ai-powered-phishing-attacks">1. AI-powered phishing attacks  </h2><p>Among those that suffered a breach or cyberattack in the past 12 months, phishing remains the most common and disruptive threat – and this tactic has changed dramatically over the years. </p><p>It’s no longer obvious or poorly written; today, it’s powered by <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> and we’re seeing attackers convincingly mimic internal communication accurately.  </p><p>As a result, people are far more likely to click on malicious links, share credentials or approve fraudulent payments. In many cases, you don’t realize you’ve been compromised until it’s too late. </p><h2 id="2-ransomware-as-a-service-raas">2. Ransomware-as-a-Service (RaaS)</h2><p>With Ransomware-as-a-Service, we’re seeing criminal groups selling ready-made tools that allow even less experienced attackers to launch serious attacks. This “plug-and-play” model has dramatically increased attack volumes. </p><p>Once inside a system, <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a> encrypts critical files and attackers demand payment, usually in cryptocurrency, while some also threaten to leak stolen data to increase pressure.  </p><h2 id="3-supply-chain-attacks">3. Supply chain attacks </h2><p>Instead of attacking businesses directly, cybercriminals are now targeting third-party suppliers to gain access to multiple organizations at once. </p><p>This exploits trust – and strong internal <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> often isn’t matched across the supply chain. One compromised vendor can trigger a domino effect across hundreds of businesses.  </p><h2 id="4-deepfake-fraud-and-impersonation">4. Deepfake fraud and impersonation  </h2><p>Deepfakes have quickly moved from novelty to a serious threat. I’m seeing attackers use AI-generated audio and <a href="https://www.techradar.com/best/best-video-editing-software">video</a> to convincingly impersonate executives, managers and clients. </p><p>This is dangerous in finance or procurement, where fraudsters can push employees to transfer funds, approve invoices, or share sensitive data – all while posing as trusted leaders. </p><h2 id="5-credential-stuffing-and-password-attacks">5. Credential stuffing and password attacks </h2><p>Despite growing awareness, weak and reused passwords are still one of the biggest vulnerabilities. Credential stuffing attacks use stolen login details from previous breaches and automatically test them across multiple platforms. </p><p>Because people often reuse passwords, attackers can gain access with very little effort. Once inside, they can escalate access, move through systems and quietly extract sensitive data. </p><h2 id="6-cloud-misconfigurations">6. Cloud misconfigurations </h2><p>Configuration errors remain a major risk. Something as simple as an exposed storage bucket or incorrect access setting can leave sensitive data publicly accessible. </p><p>Unlike traditional breaches, these incidents often don’t involve any hacking as the data is simply left unprotected. As <a href="https://www.techradar.com/best/best-cloud-storage">cloud storage</a> environments become more complex, maintaining strong configuration hygiene is now a critical security priority. </p><h2 id="7-iot-and-connected-device-vulnerabilities">7. IoT and connected device vulnerabilities </h2><p>As the Internet of Things (IoT) expands, the attack surface grows significantly. From smart cameras and sensors to industrial machinery, many connected devices still come with limited built-in security. </p><p>Attackers can exploit these devices to access wider corporate networks. Because they’re often overlooked in traditional cyber security strategies, they represent a quiet but fast-growing risk. </p><h2 id="8-insider-threats">8. Insider threats </h2><p>Insider threats are among the hardest risks to manage. People with legitimate access can intentionally steal or leak data, but more often it’s simple human error – like sending information to the wrong person or falling for phishing attacks. </p><p>With remote and hybrid working now the norm, controlling and monitoring access has become even more complex. </p><h2 id="9-business-email-compromise-bec">9. Business email compromise (BEC) </h2><p>Business email compromise is one of the most financially damaging forms of global cybercrime. Attackers infiltrate or spoof email accounts to trick employees into transferring funds or sharing sensitive data. </p><p>These attacks are highly targeted, often based on detailed research. Because they rely on social engineering rather than <a href="https://www.techradar.com/best/best-malware-removal">malware</a>, they can easily bypass traditional security controls.  </p><h2 id="10-zero-day-exploits">10. Zero-day exploits </h2><p>We often highlight zero-day vulnerabilities as being especially dangerous. These are flaws unknown to software vendors and therefore unpatched when attackers exploit them. </p><p>Because there’s no immediate fix available, businesses often only realize they’ve been hit after a breach has already happened. And as software ecosystems grow more complex, we’re expecting the risk of undiscovered vulnerabilities to keep increasing. </p><h2 id="how-businesses-can-stay-protected">How businesses can stay protected-</h2><p>While cyber threats are evolving rapidly, businesses are not powerless. Strong cyber security comes down to layers of defense, constant awareness and continuous improvement. </p><p>Start with multi-factor authentication across all systems, and keep software updated and properly patched because many attacks exploit vulnerabilities that already have fixes.  </p><p>Invest in employee training too, as human error is still a major weak point and staff need to recognize phishing and suspicious behavior. </p><p>Adopt a zero-trust approach, where no user or device is automatically trusted. Combine that with real-time monitoring, AI analytics and regular security testing to find weaknesses before attackers do.  </p><p>Finally, ensure robust backups and recovery plans are in place, because when something goes wrong, speed matters. Cyber security isn’t a one-off project; it’s an ongoing business priority. </p><h2 id="the-future-of-cyber-threats">The future of cyber threats</h2><p>Looking ahead, we expect cyber threats to grow in volume and become even more sophisticated. Artificial intelligence doesn’t sleep and it will play both sides, helping us defend systems while also powering more advanced attacks. </p><p>Breakthroughs like quantum computing could also challenge the <a href="https://www.techradar.com/best/best-encryption-software">encryption</a> standards we rely on today, while the growing complexity of cloud, IoT, and global supply chains will only expand the attack surface. </p><p>The future of cybersecurity will come down to speed, intelligence and adaptability. Organizations that invest in proactive defense, continuous monitoring, and true cyber resilience will be best prepared for what’s next. Cyber threats aren’t just a technical issue; they’re a critical business risk.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>We feature the best Antivirus Software: reviewed, tested, and ranked</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Closing the security blind spots that are a prime entry point for attacks ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/closing-the-security-blind-spots-that-are-a-prime-entry-point-for-attacks</link>
                                                                            <description>
                            <![CDATA[ What if the biggest cyber risk isn’t the feared attack, but a hidden, unknown vulnerability? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">btroBvfzj4zBkHvdPsvj3c</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 29 May 2026 08:10:09 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Yaz Bekkar ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:description>                                                            <media:text><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:text>
                                <media:title type="plain"><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>What if the biggest <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> risk is not the attack you fear most, but the weakness you forgot or never knew was there? </p><p>Many organizations worry that the next breach will come from a highly sophisticated attack so advanced that nothing could have stopped it. That fear is understandable, but the truth is often more uncomfortable. </p><p>In many cases, breaches do not begin with an unstoppable threat. They begin with a blind spot such as a missed patch, a dormant account, a device outside corporate security control or a <a href="https://www.techradar.com/best/firewall">firewall</a> left exposed. These small gaps that are easy to overlook are exactly the kind of gaps attackers know how to find.  </p><p>This is the reality, and one of the key findings from our recent report, which found that, in most cases, it is preventable security issues that open the door. Unpatched firewalls, rogue endpoints, dormant identities and misconfigurations continue to give threat actors the opportunity they need. </p><h2 id="why-are-attackers-focusing-more-on-identity-than-infrastructure">Why are attackers focusing more on identity than infrastructure? </h2><p>Because compromising an identity is often easier and quieter than attacking a system head-on.  </p><p>Once attackers compromise an identity, they are no longer forcing their way in. They are walking in through a trusted door and this is an important shift that we’re now seeing.  </p><p>Stolen usernames and passwords can provide access to cloud services, email and remote access tools, and valid credentials let attackers easily blend in with normal user activity. </p><p>From there, they can escalate privileges, move laterally and turn limited access into broader control over the environment.  </p><p>Sometimes, the speed with which this happens is startling. In one case, we have detected that the time between the initial breach and the execution of a full <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a> attack was just three hours.  </p><p>In another real-world incident, attackers gained access through a dormant account that had originally been created for a third-party vendor and was never deactivated after the contract ended. One forgotten account eventually became the route to ransomware. </p><h2 id="are-organizations-still-being-exposed-by-endpoint-and-firewall-gaps">Are organizations still being exposed by endpoint and firewall gaps? </h2><p>Yes, and at scale. Attackers actively look for unprotected <a href="https://www.techradar.com/news/best-business-laptops">business laptops</a>, tablets or servers that fall outside normal security controls, because these devices can provide a path around corporate defenses. </p><p>The issue is not always a lack of security tools. In our experience, from monitoring thousands of different environments, the issue often comes down to a  lack of consistent configuration. Security tools that have either been accidentally or intentionally disabled present a major security risk. The danger can be heightened as teams may have a false sense of security that comes  from having the tool installed in the first place.  </p><p>We also know that many organizations are trying to manage too many <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> tools with limited resources. And when teams are overstretched, configuration errors become more likely. That is often where attackers gain their advantage. </p><p>It also helps explain why relatively simple attack techniques remain so effective.  </p><p>Threat actors continue to exploit known vulnerabilities, including some that have been around for years which can be found in legacy systems such as old <a href="https://www.techradar.com/best/best-linux-server-distro">servers</a> or applications.</p><p>More striking still, from our analysis of data last year , we found that the vast majority of ransomware incidents exploited firewalls through either a CVE or a vulnerable account.  </p><h2 id="why-are-modern-attacks-becoming-harder-to-spot">Why are modern attacks becoming harder to spot? </h2><p>Some of the most malicious behavior can look annoyingly legitimate.  </p><p>Threat actors are increasingly relying on living-off-the-land (LOTL) techniques, using legitimate tools already present in the environment to carry out malicious actions.  </p><p>One of the clearest examples is fileless <a href="https://www.techradar.com/best/best-malware-removal">malware</a> attacks which use PowerShell as the primary execution method.  </p><p>That creates a serious challenge for defenders. PowerShell is widely used for legitimate IT administration and maintenance. When malicious activity mimics normal operations, it becomes much harder to distinguish threat behavior from business-as-usual. </p><p>This is one of the most difficult blind spots organizations face today: not the threat you can clearly see, but the one that resembles something familiar. </p><h2 id="how-could-agentic-ai-make-this-worse">How could agentic AI make this worse? </h2><p>AI is helping threat actors move faster, adapt quicker and scale their efforts far more efficiently. </p><p>As threat actors adopt agentic AI, the exploitation of common weaknesses is likely to accelerate. These technologies can help cybercriminals scan environments continuously, identify weak configurations in minutes and rewrite malicious code on the fly to avoid detection. </p><p>In other words, the same overlooked issues that are already dangerous today could become even more exposed tomorrow. </p><p>That is why basic security weaknesses can no longer be treated as minor issues. In an environment where attacks can be launched and adapted far more quickly, weak <a href="https://www.techradar.com/best/best-identity-management-software">identity management</a> controls, unpatched systems and unmanaged devices become far more costly. </p><h2 id="so-what-should-organizations-do-now">So what should organizations do now? </h2><p>Start with the basics and treat them as strategically important, not operational housekeeping. </p><p>Some of the fastest and most effective improvements include: consistent multi-factor authentication and stronger access controls; a disciplined approach to <a href="https://www.techradar.com/best/best-patch-management-tools">patch management</a> and data protection and regular cybersecurity awareness training for employees </p><p>But closing blind spots fully requires more than isolated fixes because resilience depends on visibility. The more fragmented security becomes, the easier it is for critical signals to be missed. But when organizations have end-to-end visibility and coordinated management across their environment, they are far better placed to detect both the obvious weaknesses and the hidden ones. </p><p>A unified security strategy is one that combines advanced, AI-powered detection technologies with a fully automated SOC. Working with a provider who can deliver that protection 24/7 through a comprehensive managed security platform reduces the burden on internal teams.   </p><p>And that is what long-term cyber resilience is really built on: not just defending against the spectacular attack, but closing the everyday gaps that attackers are counting on.  </p><p>As I always say; the breach that changes everything often begins with something that seemed too small to matter.</p><p><em></em><a href="https://www.techradar.com/best/best-small-and-medium-business-firewall-software"><em>We feature the best small and medium business (SMB) firewall software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cybercriminals are using GTA 6 hype to spread malware ahead of launch, NordVPN warns ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/vpn/vpn-privacy-security/cybercriminals-are-using-gta-6-hype-to-spread-malware-ahead-of-launch-nordvpn-warns</link>
                                                                            <description>
                            <![CDATA[ NordVPN warns GTA 6 fans about fake beta keys, phishing pages, Android adware, and malware disguised as early access downloads. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">RMEVWPFdEVgf6tcANGX3M7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YfGyyxGmm5hNmhvqh3uodM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 28 May 2026 08:43:26 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[VPN Privacy &amp; Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ monicajwrites@gmail.com (Monica J. White) ]]></author>                    <dc:creator><![CDATA[ Monica J. White ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/6AQ4y5nzk8kQ47Yp69GERj.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Monica is a journalist with over a decade of experience in covering technology.&lt;/p&gt;&lt;p&gt;She writes about the latest developments in computing, which means anything from computer chips made out of paper to cutting-edge desktop processors. Her coverage includes CPUs, GPUs, and everything else that goes into a PC or a laptop, but also peripherals.&lt;/p&gt;&lt;p&gt;GPUs are Monica’s main area of interest, and nothing thrills her quite like that time every couple of years when new graphics cards hit the market. She’s always keeping tabs on the latest from Nvidia, AMD, and Intel, including both the hardware and the software that powers our PCs.&lt;/p&gt;&lt;p&gt;As an avid gamer, her focus is always on the consumer and whether something works well and provides adequate value for the money. She believes that PC building can be intimidating, so her goal is to explain complex concepts in an approachable manner while still digging into the technical nitty-gritty we all love to learn more about.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YfGyyxGmm5hNmhvqh3uodM-1280-80.jpg">
                                                            <media:credit><![CDATA[Photo Illustration by Thomas Fuller/SOPA Images/LightRocket via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Grand Theft Auto VI (GTA 6) logo is seen displayed on a smartphone screen]]></media:description>                                                            <media:text><![CDATA[The Grand Theft Auto VI (GTA 6) logo is seen displayed on a smartphone screen]]></media:text>
                                <media:title type="plain"><![CDATA[The Grand Theft Auto VI (GTA 6) logo is seen displayed on a smartphone screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YfGyyxGmm5hNmhvqh3uodM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>NordVPN identified malware and scam campaigns</strong> <strong>targeting GTA 6's fans</strong></li><li><strong>The web is flooded with fake beta keys, trojanized repacks, phishing sites</strong></li><li><strong>PC and Android users are the main targets</strong></li></ul><p>The hype around the release of GTA 6 is real, and threat actors are quick to make the most of it by targeting gamers who are <a href="https://www.techradar.com/gaming/fans-mourn-what-would-have-been-gta-6s-launch-today-my-girl-surprised-me-with-usd100-today-and-thought-gta-6-was-coming-out-tomorrow">disappointed by the game's delayed release</a>. The lead-up to the release of Rockstar Games' most anticipated title makes fans vulnerable to a large number of scams, NordVPN warns.</p><p><a href="https://www.techradar.com/reviews/nordvpn">NordVPN</a>, which consistently ranks at the top of our list of the <a href="https://www.techradar.com/vpn/best-vpn">best VPNs</a>, shared the findings of its Threat Intelligence team. The team discovered a wave of GTA 6-themed scams targeting eager fans with fake installers, non-existent beta keys, phishing pages, and even Android adware pretending to be a "GTA 6 beta" app. </p><p>Attackers are banking on victims clicking first and then thinking later, instilling a sense of urgency through every scam attempt.</p><h2 id="nordvpn-reveals-the-staggering-extent-of-gta-6-scams">NordVPN reveals the staggering extent of GTA 6 scams</h2><p>NordVPN has revealed that PC and Android users are the primary targets of GTA 6 scams, but the threat actors may still promise access to the game on other platforms.</p><p>The game has been confirmed to launch on the PlayStation 5 and the Xbox Series X/S to start with, which threat actors are willingly abusing by promising exclusive beta keys for those consoles. Users first fill out a short form, go through a quick verification process, and then are told to either subscribe or download potentially unwanted applications (PUAs). </p><p>Windows users are also targeted by clones of well-known piracy sites. These clones distribute <a href="https://www.techradar.com/news/what-is-malware-and-how-dangerous-is-it">malware</a>, cleverly disguised as the actual game. NordVPN downloaded one of these scam files and found it to look surprisingly legitimate, with a proper game installer that quietly launches a trojan in the background. The malware can modify your PC's RAM, connect to external servers, and download even more malware.</p><blockquote class="reddit-card"  ><a href="https://www.reddit.com/r/GTA/comments/1t5m6cr/gta6_is_already_on_android/comments/1t5m6cr/gta6_is_already_on_android">gta</a> from <a href="https://www.reddit.com/r/GTA/comments/1t5m6cr/gta6_is_already_on_android">r/GTA/comments/1t5m6cr/gta6_is_already_on_android</a></blockquote><script async src="//embed.redditmedia.com/widgets/platform.js" charset="UTF-8"></script><p>Android users are subjected to adware that pretends to offer access to the GTA 6 beta. This is especially clever, as the game is unlikely to ever launch on Android, but fake apps that promise access to the game are still cropping up, as shared by NordVPN as well as various <a href="https://www.reddit.com/r/GTA/comments/1t5m6cr/gta6_is_already_on_android/" target="_blank" rel="nofollow">Reddit users</a>. </p><p>NordVPN downloaded one such file and found the app to be an empty shell that plays a video and then makes you download additional data. The app tries to get users to pay for a subscription or download further malware, and NordVPN traced it back to a domain that's known for distributing banking trojans, ransomware, and infostealers.</p><p>Even Rockstar Social Club accounts aren't safe: phishing pages attempt to steal login credentials, and those accounts, quickly stolen, are often resold or used for in-game scams.</p><h2 id="how-to-stay-safe-3">How to stay safe</h2><p>The general rule of thumb is not to trust anything that didn't come directly from Rockstar Games, the PlayStation Store, or the Xbox Marketplace. <strong>Never download any game-related content from third-party sites</strong>, as even a legitimate-looking site can be a scam.</p><p><strong>Don't trust offers of free beta keys</strong>, either. Follow the official social media channels for these platforms to keep an eye out for legit offers. </p><p>Lastly, <strong>don't share your Rockstar account details</strong> on any websites other than the official site, and <strong>check the URL before you type</strong> them in.</p><p>NordVPN has just <a href="https://www.techradar.com/vpn/vpn-services/protection-needs-to-evolve-nordvpn-rebrands-as-an-all-in-one-vpn-app-for-next-generation-protection">rebranded its Threat Protection suite</a> as next-gen antivirus, so if you want to stay extra safe with a more robust security solution, it's worth checking out.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'Protection needs to evolve' — NordVPN rebrands as an all-in-one VPN app for next-generation protection  ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/vpn/vpn-services/protection-needs-to-evolve-nordvpn-rebrands-as-an-all-in-one-vpn-app-for-next-generation-protection</link>
                                                                            <description>
                            <![CDATA[ The digital security giant is bringing next-gen antivirus, dark web monitoring, and its industry-leading VPN into a single, unified experience. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xr4DwLxMzWWKG7t9LmwcBM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ewbjV59riV4dExhBbaawtM-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 27 May 2026 07:00:00 +0000</pubDate>                                                                                                                                <updated>Wed, 27 May 2026 08:25:37 +0000</updated>
                                                                                                                                            <category><![CDATA[VPN Services]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DXDNjzRkphApxN8f5SooCA.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rene Millman is a seasoned technology journalist whose work has appeared in The Guardian, the Financial Times, Computer Weekly, and IT Pro. With over two decades of experience as a reporter and editor, he specializes in making complex topics like cybersecurity, VPNs, and enterprise software accessible and engaging. &lt;/p&gt;&lt;p&gt;His writing is backed by years of market analysis, allowing him to deliver news and features with an expert’s understanding of the industry.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/ewbjV59riV4dExhBbaawtM-1280-80.png">
                                                            <media:credit><![CDATA[NordVPN]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[NordVPN rebranding, all-in-one app (May 2026)]]></media:description>                                                            <media:text><![CDATA[NordVPN rebranding, all-in-one app (May 2026)]]></media:text>
                                <media:title type="plain"><![CDATA[NordVPN rebranding, all-in-one app (May 2026)]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ewbjV59riV4dExhBbaawtM-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>NordVPN rebrands its app across three pillars: connect, protect, monitor</strong></li><li><strong>Threat Protection's tools are now under a newly launched anti-gen antivirus</strong></li><li><strong>Anti-gen antivirus tools blocked 4.8 million threats in April alone</strong></li></ul><p>NordVPN is officially changing. The cybersecurity giant has announced a major rebrand, shifting its focus from a standalone VPN provider to an all-in-one digital security app.</p><p>The revamped <a href="https://www.techradar.com/reviews/nordvpn">NordVPN</a> application is now organized around three core pillars: "<strong>connect</strong>," which refers to the <a href="https://www.techradar.com/vpn/virtual-private-networks">virtual private network</a> tech; "<strong>protect</strong>," where what's known as the <a href="https://www.techradar.com/vpn/vpn-services/after-a-year-of-using-threat-protection-pro-a-nordvpn-plus-plan-might-be-the-only-black-friday-vpn-deal-i-recommend">Threat Protection</a> suite becomes next-generation antivirus; and "<strong>monitor</strong>," which includes tools like <a href="https://www.techradar.com/vpn/vpn-services/google-killed-its-dark-web-scanner-but-nordvpns-upgraded-tool-is-here-to-track-your-leaked-data">Dark Web Monitor</a>.</p><p>As Marijus Briedis, CTO at NordVPN, said in a press statement: "Such an approach reflects what users increasingly want from digital protection: stronger security, less complexity, and fewer separate tools to install and manage."</p><h2 id="the-need-for-a-next-gen-antivirus">The need for a next-gen antivirus</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:886px;"><p class="vanilla-image-block" style="padding-top:56.21%;"><img id="vuyxrMovXEkAjxzafD682T" name="Image_1" alt="NordVPN next-gen antivirus, promo image May 2026" src="https://cdn.mos.cms.futurecdn.net/vuyxrMovXEkAjxzafD682T.png" mos="" align="middle" fullscreen="" width="886" height="498" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: NordVPN)</span></figcaption></figure><p>The rebranding of Threat Protection features as next-generation antivirus capabilities is especially significant to grasp how the company is adapting to an online landscape where threats are diversified.</p><p>Many of today's most common and damaging digital dangers, including phishing pages, fake online stores, scam messages, and account takeover attempts, do not rely on downloadable files at all. Instead, modern cybercriminals use deception, compromised credentials, and social engineering to target unsuspecting users.</p><p>Yet, as Briedis explains, people still use the word '<a href="https://www.techradar.com/best/best-antivirus">antivirus</a>' as a "shorthand" for digital security. "Modern protection should address the real risks people face online today, from phishing and scams to malicious downloads. Protection needs to evolve, without compromising the standard of privacy people expect from us," said Briedis.</p><p>Traditional <a href="https://www.techradar.com/best/best-antivirus">antivirus</a> software, in fact, has historically focused on reactive file scanning. NordVPN's next-generation antivirus aims to redefine this concept for private customers. It focuses on proactive, real-time protection to stop <a href="https://www.techradar.com/news/what-is-phishing-and-how-dangerous-is-it">phishing</a>, scams, ads, trackers, and malware before they ever reach a user's device.</p><p>Over the last year, we have tracked how <a href="https://www.techradar.com/vpn/vpn-services/beyond-vpn-protection-how-nordvpn-changed-in-2025-and-whats-in-store-for-2026">NordVPN has steadily integrated</a> broader defense features against online scams and malware. And these tools are already working hard. In April alone, NordVPN's next-gen antivirus tool blocked 4.8 million threats. <a href="https://www.techradar.com/news/what-is-malware-and-how-dangerous-is-it">Malware</a> made up the majority of these blocks, accounting for over 3 million stopped threats.</p><p>Now, those extra layers of defense are taking center stage. A massive evolution for a service that already ranks among the <a href="https://www.techradar.com/reviews/nordvpn">best VPN</a> options on the market.</p><h2 id="privacy-first-security-by-design">Privacy-first security by design</h2><p>One of the biggest concerns for users adopting all-in-one security suites is privacy. Antivirus software historically requires deep system access, which can raise surveillance concerns. </p><p>NordVPN claims its security approach is designed around collecting the minimum signal required to make a threat decision, avoiding turning security tools into surveillance products.</p><p>This privacy-first ethos extends across NordVPN's entire suite, from its core VPN capabilities to its dedicated machine learning models used to catch specific threat categories.</p><p>For users looking to streamline their digital setup, this rebrand also seeks to reduce the clutter of managing multiple subscription services. </p><p>"Consumers should not have to choose between convenience, protection, and privacy," says Briedis. "Our goal is to bring together advanced VPN technology and next-generation antivirus in one streamlined app experience that reduces complexity and better matches how people think about digital safety today."</p><p>This rebrand follows what has already been a highly active period for the provider; you can catch up on their other recent updates in our recap of <a href="https://www.techradar.com/vpn/vpn-services/nordvpn-had-a-busy-start-to-2026-heres-a-recap-of-all-the-releases-you-may-have-missed">everything NordVPN released in early 2026</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kash Patel's 'BasedApparel' website is apparently hosting ClickFix malware ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/kash-patels-basedapparel-website-is-apparently-hosting-clickfix-malware</link>
                                                                            <description>
                            <![CDATA[ The malware targets macOS users only and serves commodity infostealers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Ma45DfZaZxyu4sjyukVJDN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/A33uiNMYWME9b9zkSfwQjD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 26 May 2026 18:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/A33uiNMYWME9b9zkSfwQjD-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Based Apparel]]></media:description>                                                            <media:text><![CDATA[Based Apparel]]></media:text>
                                <media:title type="plain"><![CDATA[Based Apparel]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/A33uiNMYWME9b9zkSfwQjD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researcher finds Based Apparel site serving a macOS ClickFix infostealer disguised as a Cloudflare CAPTCHA check</strong></li><li><strong>Victims were tricked into pasting malicious Applescript commands in Terminal, with VirusTotal flagging the malware as a commodity Trojan/infostealer</strong></li><li><strong>The site, built on WordPress/WooCommerce and Ghost CMS, was taken offline after disclosure, linking the incident to broader Ghost CMS exploitation in ongoing ClickFix campaigns</strong></li></ul><p>Based Apparel, an American online clothing company selling patriotic, conservative, and pro–free speech-themed merchandise, was seemingly compromised and used to serve malware through the ClickFix technique - but only macOS users were targeted.</p><p>A researcher with the alias ‘debbie’ disclosed her findings to <a href="https://uk.pcmag.com/security/165117/kash-patels-apparel-site-is-trying-to-trick-visitors-into-installing-malware" target="_blank"><em>PC Mag</em></a>, before sharing video proof on X, after saying she read online about Based Apparel being co-founded by FBI Director Kash Patel and decided to take a closer look.</p><p>“The ClickFix attack just kinda popped up when I was browsing it,” Debbie said in an email. “I took a quick look and it's just a classic infostealer, wrapped twice in base64 (binary-to-text encoding). It's interesting that it's written in Applescript though.”</p><h2 id="links-to-ghost-cms">Links to Ghost CMS?</h2><p>The victims were asked to verify they were human, on a CAPTCHA page seemingly coming from Cloudflare. This spoofed Cloudflare site will tell the victim that “unusual web traffic” was detected, and will ask the victim to confirm they’re human by opening the Terminal and paste a command shared on the page. </p><p>Running the infostealer through VirusTotal, <em>PC Mag</em> found it was flagged by 27 antivirus engines as a Trojan and infostealer, meaning it’s commodity <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> rather than a custom-built solution for targeted attacks. </p><p>Based Apparel is yet to comment, but its website is offline for the time being. At press time, the site showed a “We’ll be right back” message that stated the company is “making improvements”.</p><p>The website is seemingly built using two content management systems - WordPress with WooCommerce for the store functionality, and Ghost CMS for the separate news subdomain.</p><p>Earlier today, we reported that <a href="https://www.techradar.com/pro/security/ghost-cms-flaw-hijacked-to-target-hundreds-of-websites-with-clickfix-attacks-heres-how-to-stay-safe">a critical-severity vulnerability in Ghost CMS</a>, patched in February 2026, was also being abused against more than 700 domains to launch ClickFix attacks. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ghost CMS flaw hijacked to target hundreds of websites with ClickFix attacks — here's how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/ghost-cms-flaw-hijacked-to-target-hundreds-of-websites-with-clickfix-attacks-heres-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ A critical-level flaw in a popular CMS, patched months ago, is now being abused. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sTs68yar6vmTMgbXLQu4aS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HU8VZ2jkrVAHBpb3Aqqg8j-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 26 May 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HU8VZ2jkrVAHBpb3Aqqg8j-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images/Tatiana Maksimova]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Female hands typing on a laptop in neon light. A lock as a symbol of cybersecurity on a foreground.]]></media:description>                                                            <media:text><![CDATA[Female hands typing on a laptop in neon light. A lock as a symbol of cybersecurity on a foreground.]]></media:text>
                                <media:title type="plain"><![CDATA[Female hands typing on a laptop in neon light. A lock as a symbol of cybersecurity on a foreground.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HU8VZ2jkrVAHBpb3Aqqg8j-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers warn CVE‑2026‑26980, a critical SQL injection flaw in Ghost CMS (score 9.4), is being exploited in a large ClickFix campaign</strong></li><li><strong>Over 700 domains, including Harvard, Oxford, DuckDuckGo, and major AI/SaaS firms, were compromised to deliver malware via DLL loaders, JS droppers, and Electron‑based payloads</strong></li><li><strong>Admins should urgently upgrade to Ghost 6.19.1 or later and monitor 30‑day admin API logs to detect potential compromise</strong></li></ul><p>A critical-severity vulnerability that reportedly was patched three months ago is being exploited in a massive ClickFix campaign, researchers have claimed.</p><p>In mid-February 2026, a critical SQL injection vulnerability was found in Ghost CMS, a popular open-source Content Management System (<a href="https://www.techradar.com/best/cms">CMS</a>) currently used by more than 57,000 websites, including the likes of 404 Media, The Canadian government, and Duolingo.</p><p>The flaw, tracked as CVE-2026-26980 and affecting Ghost 3.24.0 through 6.19.0, was assigned a severity score of 9.4/10 (critical), as it potentially allows unauthenticated attackers to perform arbitrary reads from the database, which grants management access to users, articles, themes, as well as article pages. </p><h2 id="deploying-various-malware">Deploying various malware</h2><p>However, many users most likely did not patch, as Chinese cybersecurity firm Qianxin claims more than 700 domains were compromised to serve ClickFix attack flows. </p><p>Among them are Harvard University, Oxford University, Auburn University, DuckDuckGo, and many AI/SaaS company sites, media outlets, fintech firms, and others. </p><p>ClickFix is a type of scam in which attackers tell the victims they have a problem (which they don’t) and then provide the solution (which it really isn’t). The “solution”, however, just deploys a piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, and depending on the attackers and the targets, it can vary from classic backdoors to ransomware encryptors. </p><p>In this campaign, the researchers saw DLL loaders, JavaScript droppers, and a generic Electron-based malware being distributed. </p><p>The best way to mitigate the threat is to simply upgrade the Ghost CMS either to version 6.19.1, or whatever the latest version is at the moment. Website owners are also advised to keep a 30-day record of admin API call logs, just to keep track of potential compromise.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/ghost-cms-sql-injection-flaw-exploited-in-large-scale-clickfix-campaign/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How .BRANDs improve domain security and user trust – even in an AI world ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/how-brands-improve-domain-security-and-user-trust-even-in-an-ai-world</link>
                                                                            <description>
                            <![CDATA[ .BRAND gTLDs bolster domain security against phishing, fraud and other AI-generated threats. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sB85T8pTjLjtewXgTGzo8W</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UjSNcAZ5SebctebKAMQNVF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 26 May 2026 10:22:32 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Gretchen Olive ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UjSNcAZ5SebctebKAMQNVF-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity ensures data protection on internet. Data encryption, firewall, encrypted network, VPN, secure access and authentication defend against malware, hacking, cyber crime and digital threat]]></media:description>                                                            <media:text><![CDATA[Cybersecurity ensures data protection on internet. Data encryption, firewall, encrypted network, VPN, secure access and authentication defend against malware, hacking, cyber crime and digital threat]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity ensures data protection on internet. Data encryption, firewall, encrypted network, VPN, secure access and authentication defend against malware, hacking, cyber crime and digital threat]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UjSNcAZ5SebctebKAMQNVF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>At the end of April, the Internet Corporation for Assigned Names and Numbers (ICANN) opened the application period for <a href="https://www.techradar.com/news/best-domain-registrars">domain registrars</a>, to allow companies to register for .BRAND domains for the first time since 2012, allowing organizations to register a new generic top-level domain (gTLD) that matches their trademarked name.</p><p>“Top level” refers to what is typically the “.com,” “.net,” “.gov,” etc. part of a domain. A .BRAND instead features a brand name after the final dot in a domain address, such as https://about.google. </p><p>As a custom domain extension, it is owned and operated by the <a href="https://www.techradar.com/best/best-business-plan-software">business</a> that holds the trademarked name. </p><p>With this, companies take full control over their domain ecosystem by creating, managing and deactivating domains quickly without third-party assistance.</p><p>This means .BRANDS are about much more than a name. The current application period marks a fresh opportunity to future-proof digital assets by carving out a trusted space for company information and partner interactions. Such trust is needed because emerging <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> are triggering increasingly sophisticated cyber attacks and brand infringements by targeting domains. </p><p>Nine out of ten organizations, in fact, have experienced at least one domain name system (DNS) attack, with a $1.1 million average cost per incident. Executive leaders must reassess how to best prepare their own internal, partner and customer infrastructures for the new era of digital threats.</p><h2 id="the-great-promise-of-dot-brands">The great promise of dot BRANDS</h2><p>Dot BRANDS bring great promise to help companies achieve this. They bolster domain <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> against phishing and other types of fraud by mitigating the incidence of lookalike domains. At the same time, they boost brand visibility and placement in search results and AI-generated responses alike.  </p><p>There are more than 400 .BRANDS in global web ranks, including dns.google, home.barclays and group.softbank. To cite one use case example, Microsoft is consolidating Microsoft 365 apps and services under the cloud.microsoft domain. Subsequently, businesses significantly improve domain protection with the following advantages:</p><p></p><p>1. ICANN Specification 13 ensures that a .BRAND domain is exclusively reserved for the trademark holder, eliminating third-party use of the domain. </p><p>2. An official .BRAND enables full traceability and consistency for domain-associated sites, assuring authenticity for any hosted <a href="https://www.techradar.com/web-hosting/best-web-hosting-service-websites">website</a> linked to it.</p><p>3. By operating in this exclusive namespace, organizations reduce exposure to lookalike domains commonly used in phishing, <a href="https://www.techradar.com/best/best-malware-removal">malware</a> and impersonation schemes. As a result, a .BRAND fortifies security, limiting financial and reputational risks.</p><p>4. Users readily distinguish fraud domains from real ones because a .BRAND establishes clear authenticity, a company-controlled online space and, thus, customer trust. What’s more, a .BRAND domain is automatically disassociated from the brand if the content/information cannot be traced to the organization.</p><h2 id="fueling-reliable-ai-llm-results">Fueling reliable AI/LLM results</h2><p>This means businesses can say with confidence, “If it doesn’t end in our .BRAND domain, then it’s not us.” Such confidence extends to the ubiquity of AI/large language models (<a href="https://www.techradar.com/computing/artificial-intelligence/best-llms">LLMs</a>) in multiple ways. </p><p>For starters, .BRANDs create a future-ready, controlled TLD infrastructure with a secure foundation for emerging technologies like AI and LLMs. Because the brand exclusively owns and operates the TLD, every domain published under it is inherently authenticated, giving AI systems a clean, unambiguous signal of origin when crawling and sourcing content.</p><p>An organization’s domain ecosystem plays a major role in influencing whether AI tools will use its content as a source. In gathering information to generate responses, LLMs and AI search engines increasingly rely on digital signals that are verified and contain reliable content, not those that appear to be fraudulent and/or contain inaccurate information. An ability to identify legitimate sources plays a crucial role here, especially given the wealth of AI-generated misinformation out there.</p><p>By definition, content hosted on a .BRAND website is verifiable and authentic. It would not exist if not for the indisputable confirmation associated with a legitimate organization. Beyond security, this establishes a strong signal for AI search results/response rankings, with .BRANDs emerging as machine-readable trust signals to optimize algorithmic rankings.</p><h2 id="seizing-a-rare-domain-opportunity">Seizing a rare domain opportunity</h2><p>A .BRAND is not a short-term marketing initiative; it is a long-term strategic position. It is distinctive, secure and easily identifiable as authentic by both humans and machines – delivering a decided, competitive advantage in the AI race. Indeed, a .BRAND indicates that your company is considered a market leader focused on innovation, with a lasting commitment to domain defense, brand control and digital strategy.</p><p>That said, pursuing a .BRAND is a significant undertaking. Applicants must hold a registered trademark for the desired extension, and the costs are considerable. These .BRANDs are most viable for larger organizations with legally defensible brand names and the resources to transition to and maintain a TLD long-term. For those that qualify, however, the investment secures a level of digital ownership that no other domain strategy can match.</p><p>It’s been 14 years since the last application window opened, and there may not be another opportunity in the foreseeable future after the current one closes on August 12 this year. Therefore, executive leaders should seize the moment to assess whether now is the time to ensure greater control over their brand’s digital identity – and position their organization as forward-thinking and authoritative.</p><p><em></em><a href="https://www.techradar.com/news/the-best-website-builder"><em>We feature the best website builders</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>