<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-AU"
                       href="https://www.techradar.com/au/feeds/tag/cyber-security"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from TechRadar AU in Cyber-security ]]></title>
                <link>https://www.techradar.com/au/computing/computing-security/cyber-security</link>
        <description><![CDATA[ All the latest cyber-security content from the TechRadar  AU team ]]></description>
                                    <lastBuildDate>Mon, 14 Sep 2026 23:10:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ These cheap Skullcandy earbuds have a worrying Bluetooth flaw that could let anyone connect to your device ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Researchers warn Skullcandy Dime 3 earbuds on older firmware accept Bluetooth pairing from unknown devices with no user interaction required</strong></li><li><strong>When leveraged, it can be used to interrupt the owner's connections, hijack playback, and even capture live microphone audio</strong></li><li><strong>The vulnerability has been patched in a newer firmware update available only on newer units, does not seem to be addressable for existing earbuds</strong></li></ul><p>Carnegie Mellon University's CERT Coordination Center has warned Skullcandy's Dime 3 wireless earbuds will accept a Bluetooth pairing request from a stranger's device without the owner doing anything.</p><p>The resulting bond is permanent, and the only sign the owner gets is a spoken "new device paired" notification delivered after it has already happened, with zero user interaction to confirm the request.</p><p>The <a href="https://kb.cert.org/vuls/id/859658" target="_blank" rel="nofollow">advisory</a> covering the Dime 3 was written by CERT/CC's Bob Kemerer and credits independent researcher Jacob Nowak, who had <a href="https://seclists.org/fulldisclosure/2026/Aug/7" target="_blank" rel="nofollow">posted his findings</a> to the Full Disclosure mailing list in early August after testing it on hardware he owned.</p><h2 id="a-fix-deployed-that-covers-virtually-no-existing-users">A fix deployed that covers virtually no existing users</h2><p>What makes this worse is that, ironically, while Skullcandy was swift in addressing the issue affecting earbuds running firmware version 1.0.0.28 by rolling out a patched version 1.0.0.30, it seems to address the issue only in newly made units.</p><p>CERT notes that there seem to be no "consumer-accessible" methods to upgrade existing units to the newest firmware because it reportedly has no support via the companion app, as a <a href="https://www.tomsguide.com/reviews/skullcandy-dime-3" target="_blank" rel="nofollow">Tom's Guide review indicates</a>.</p><p>A product without an update path that is user-accessible essentially means that its software flaws, or in this case, security issues, are here to stay for users who have had the bad luck of buying an earlier unit.</p><p>The underlying vulnerability, CVE-2025-20701, is not new and is not of Skullcandy's making. It is one of three vulnerabilities that Dennis Heinze and Frieder Steinmetz of the German firm ERNW <a href="https://insinuator.net/2025/06/airoha-bluetooth-security-vulnerabilities/" target="_blank" rel="nofollow">disclosed in June 2025</a> at the TROOPERS conference in Heidelberg, affecting Bluetooth systems-on-chip from Taiwan's Airoha.</p><p>The Dime 3's Bluetooth identifier names Airoha as its chipset vendor, and while Airoha shipped a fixed SDK to its customers in June 2025 and published its bulletin that August, owners of the earbuds are in a unique situation, to say the least.</p><p>The vulnerability's severity is disputed: MediaTek (which owns Airoha) assigned it a relatively low 6.7 rating, while CISA's vulnerability enrichment program later assigned it an <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20701" target="_blank" rel="nofollow">8.8 with a 'high' categorization</a>. </p><p>A potential attacker is limited to what the earbuds can access, since the vulnerability is essentially limited to the earbuds, but one could still wreak havoc with that alone. It should allow for more than just disrupting a person's routine by 'hijacking' one's earbuds by essentially using their microphones on them to record conversations or, in an extreme theoretical case (requiring chaining with other exploits), impersonate the headset and pull contacts, call history, and even pass hands-free commands to a paired smartphone. The latter, however, would require a high technical skill set, being within a few meters of a victim, and a Bluetooth connection turned on on the paired smartphone.</p><p>For now, a vulnerability exists that Skullcandy should have been able to patch, exactly as Apple recently did for its Beats Studio Buds, but a lack of support for any third party apps on the budget earbuds is somewhat annoyingly resulting in an unpatchable vulnerability for existing users.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/these-cheap-skullcandy-earbuds-have-a-worrying-bluetooth-flaw-that-could-let-anyone-connect-to-your-device</link>
                                                                            <description>
                            <![CDATA[ Apple can push a firmware fix to earbuds already in your pocket. Skullcandy cannot reach yours at all for now. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mCNcjioFrjon8Gz49kqE4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/G3oxprCVAwUWdyxSFfSoQL-1280-80.jpeg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 14 Sep 2026 23:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Audio]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/G3oxprCVAwUWdyxSFfSoQL-1280-80.jpeg">
                                                            <media:credit><![CDATA[stock.adobe.com © Patrick Daxenbichler]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Person listening to music]]></media:description>                                                            <media:text><![CDATA[Person listening to music]]></media:text>
                                <media:title type="plain"><![CDATA[Person listening to music]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/G3oxprCVAwUWdyxSFfSoQL-1280-80.jpeg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers warn Skullcandy Dime 3 earbuds on older firmware accept Bluetooth pairing from unknown devices with no user interaction required</strong></li><li><strong>When leveraged, it can be used to interrupt the owner's connections, hijack playback, and even capture live microphone audio</strong></li><li><strong>The vulnerability has been patched in a newer firmware update available only on newer units, does not seem to be addressable for existing earbuds</strong></li></ul><p>Carnegie Mellon University's CERT Coordination Center has warned Skullcandy's Dime 3 wireless earbuds will accept a Bluetooth pairing request from a stranger's device without the owner doing anything.</p><p>The resulting bond is permanent, and the only sign the owner gets is a spoken "new device paired" notification delivered after it has already happened, with zero user interaction to confirm the request.</p><p>The <a href="https://kb.cert.org/vuls/id/859658" target="_blank" rel="nofollow">advisory</a> covering the Dime 3 was written by CERT/CC's Bob Kemerer and credits independent researcher Jacob Nowak, who had <a href="https://seclists.org/fulldisclosure/2026/Aug/7" target="_blank" rel="nofollow">posted his findings</a> to the Full Disclosure mailing list in early August after testing it on hardware he owned.</p><h2 id="a-fix-deployed-that-covers-virtually-no-existing-users">A fix deployed that covers virtually no existing users</h2><p>What makes this worse is that, ironically, while Skullcandy was swift in addressing the issue affecting earbuds running firmware version 1.0.0.28 by rolling out a patched version 1.0.0.30, it seems to address the issue only in newly made units.</p><p>CERT notes that there seem to be no "consumer-accessible" methods to upgrade existing units to the newest firmware because it reportedly has no support via the companion app, as a <a href="https://www.tomsguide.com/reviews/skullcandy-dime-3" target="_blank" rel="nofollow">Tom's Guide review indicates</a>.</p><p>A product without an update path that is user-accessible essentially means that its software flaws, or in this case, security issues, are here to stay for users who have had the bad luck of buying an earlier unit.</p><p>The underlying vulnerability, CVE-2025-20701, is not new and is not of Skullcandy's making. It is one of three vulnerabilities that Dennis Heinze and Frieder Steinmetz of the German firm ERNW <a href="https://insinuator.net/2025/06/airoha-bluetooth-security-vulnerabilities/" target="_blank" rel="nofollow">disclosed in June 2025</a> at the TROOPERS conference in Heidelberg, affecting Bluetooth systems-on-chip from Taiwan's Airoha.</p><p>The Dime 3's Bluetooth identifier names Airoha as its chipset vendor, and while Airoha shipped a fixed SDK to its customers in June 2025 and published its bulletin that August, owners of the earbuds are in a unique situation, to say the least.</p><p>The vulnerability's severity is disputed: MediaTek (which owns Airoha) assigned it a relatively low 6.7 rating, while CISA's vulnerability enrichment program later assigned it an <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20701" target="_blank" rel="nofollow">8.8 with a 'high' categorization</a>. </p><p>A potential attacker is limited to what the earbuds can access, since the vulnerability is essentially limited to the earbuds, but one could still wreak havoc with that alone. It should allow for more than just disrupting a person's routine by 'hijacking' one's earbuds by essentially using their microphones on them to record conversations or, in an extreme theoretical case (requiring chaining with other exploits), impersonate the headset and pull contacts, call history, and even pass hands-free commands to a paired smartphone. The latter, however, would require a high technical skill set, being within a few meters of a victim, and a Bluetooth connection turned on on the paired smartphone.</p><p>For now, a vulnerability exists that Skullcandy should have been able to patch, exactly as Apple recently did for its Beats Studio Buds, but a lack of support for any third party apps on the budget earbuds is somewhat annoyingly resulting in an unpatchable vulnerability for existing users.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 31,000 Twitch users hit by malicious browser extension — OAuth tokens leaked via Russian proxy network ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Socket found Twitch extension </strong><em><strong>JeeBot</strong></em><strong> harvesting OAuth tokens via proxy servers</strong></li><li><strong>Tokens excluded only for 10 Russian streamer channels, suggesting deliberate design</strong></li><li><strong>Developer issued fixes, but users should revoke exposed tokens for safety</strong></li></ul><p>A browser extension for Twitch was harvesting people’s OAuth tokens and sending them to a Russian-owned server. The move was deliberate, but whether or not it was malicious is not that easily determined.</p><p>Security researchers Socket recently found an extension for both <a href="https://www.techradar.com/best/browser" target="_blank">Chrome</a> and Firefox, called “Twitch Enhanced Viewer | JeeBot”. It has roughly 30,000 users on Chrome, and some 600 on Firefox.</p><p>On the Chrome Web Store, it is advertised as a “modern tool for streamers and viewers who value quality, convenience, and control.” Apparently, it makes streaming and viewing clearer, allows viewing content in 2K, hides banner ads and unwanted elements, and even offers an AI bot to make it easier to interact with the stream.</p><h2 id="hardcoded-exemptions">Hardcoded exemptions</h2><p>According to the researchers, the extension is designed to retrieve Twitch’s video stream playlists through its own proxy servers. However, instead of simply forwarding the requests, the extension also attached users’ OAuth tokens, and since they were placed in the URL, the token also ended up in the proxy server’s request logs. </p><p>After being called out for it, the extension’s developer (HISHIMIRO/jeetbot.cc) released a new version 85.8.7 (for Firefox, the Chrome one is currently under review) which apparently fixes this flaw: when playlists are retrieved, the user’s OAuth token is no longer sent to the proxies. It would seem like this was an honest mistake that was remedied upon responsible disclosure. However, here is what Socket had to say about the way the tokens were being retrieved:</p><p>"Current builds (v85.x) forward the token inline as an &auth= query parameter on a network-layer redirect to the operator's proxy," Socket explained. "The token is forwarded for every channel the user watches, except a hardcoded allowlist of ten Russian streamer channels, whose sessions are exempted from forwarding."</p><p>If there was a list of 10 Russian streamer channels who were exempt from OAuth token retrieval, it’s safe to assume that the developer knew very well what they were doing. </p><p>It is good that the extensions were upgraded, but if you are using it, you should also revoke the exposed Twitch token, to be on the safe side.</p><p><em>Via </em><a href="https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/31-000-twitch-users-hit-by-malicious-browser-extension-oauth-tokens-leaked-via-russian-proxy-network</link>
                                                                            <description>
                            <![CDATA[ The extension has since been updated to remove the OAuth exfil. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">twiixGQaC7oSjW7QP7g3H9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/33ooyG4FCgVjDs8W6RpowC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 14 Sep 2026 19:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/33ooyG4FCgVjDs8W6RpowC-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Twitch logo under a magnifying glass in internet browser]]></media:description>                                                            <media:text><![CDATA[Twitch logo under a magnifying glass in internet browser]]></media:text>
                                <media:title type="plain"><![CDATA[Twitch logo under a magnifying glass in internet browser]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/33ooyG4FCgVjDs8W6RpowC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Socket found Twitch extension </strong><em><strong>JeeBot</strong></em><strong> harvesting OAuth tokens via proxy servers</strong></li><li><strong>Tokens excluded only for 10 Russian streamer channels, suggesting deliberate design</strong></li><li><strong>Developer issued fixes, but users should revoke exposed tokens for safety</strong></li></ul><p>A browser extension for Twitch was harvesting people’s OAuth tokens and sending them to a Russian-owned server. The move was deliberate, but whether or not it was malicious is not that easily determined.</p><p>Security researchers Socket recently found an extension for both <a href="https://www.techradar.com/best/browser" target="_blank">Chrome</a> and Firefox, called “Twitch Enhanced Viewer | JeeBot”. It has roughly 30,000 users on Chrome, and some 600 on Firefox.</p><p>On the Chrome Web Store, it is advertised as a “modern tool for streamers and viewers who value quality, convenience, and control.” Apparently, it makes streaming and viewing clearer, allows viewing content in 2K, hides banner ads and unwanted elements, and even offers an AI bot to make it easier to interact with the stream.</p><h2 id="hardcoded-exemptions">Hardcoded exemptions</h2><p>According to the researchers, the extension is designed to retrieve Twitch’s video stream playlists through its own proxy servers. However, instead of simply forwarding the requests, the extension also attached users’ OAuth tokens, and since they were placed in the URL, the token also ended up in the proxy server’s request logs. </p><p>After being called out for it, the extension’s developer (HISHIMIRO/jeetbot.cc) released a new version 85.8.7 (for Firefox, the Chrome one is currently under review) which apparently fixes this flaw: when playlists are retrieved, the user’s OAuth token is no longer sent to the proxies. It would seem like this was an honest mistake that was remedied upon responsible disclosure. However, here is what Socket had to say about the way the tokens were being retrieved:</p><p>"Current builds (v85.x) forward the token inline as an &auth= query parameter on a network-layer redirect to the operator's proxy," Socket explained. "The token is forwarded for every channel the user watches, except a hardcoded allowlist of ten Russian streamer channels, whose sessions are exempted from forwarding."</p><p>If there was a list of 10 Russian streamer channels who were exempt from OAuth token retrieval, it’s safe to assume that the developer knew very well what they were doing. </p><p>It is good that the extensions were upgraded, but if you are using it, you should also revoke the exposed Twitch token, to be on the safe side.</p><p><em>Via </em><a href="https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ CISA warns hackers are exploiting max severity GitLab flaw — urges all businesses to patch immediately ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>CISA added GitLab CVE‑2026‑85706, a critical path traversal flaw, to its KEV catalog</strong></li><li><strong>Exploitation already observed; attackers can read sensitive files via commits API without authentication</strong></li><li><strong>GitLab patched in CE/EE 19.3.2, 19.2.6, and 19.1; agencies given three days to update</strong></li></ul><p>The US Cybersecurity and Infrastructure Security Agency (CISA) has added a new GitLab vulnerability to its KEV catalog, warning users that it is being actively exploited in the wild.</p><p>GitLab has now updated its Community Edition (CE) and Enterprise Edition (EE) versions to 19.3.2, 19.2.6, and 19.1, fixing a range of vulnerabilities. Among them were two critical-severity ones: a path traversal issue in repository commits API, and an Insecure Deserialization issue in GraphQL subscription serializer.</p><p>The former is tracked as CVE-2026-85706, with a severity score of 10/10. It stems from missing authentication enforcement and improper path confinement in the repository commits API, allowing unauthenticated threat actors to read various sensitive information such as login credentials or secrets. </p><h2 id="added-to-kev">Added to KEV</h2><p>In the advisory, GitLab did not mention anything about the flaws being abused in the wild - however, a separate report from cybersecurity experts watchTowr, released a day later, claimed so:</p><p>"watchTowr Intel is already observing in-the-wild probes for the latest critical GitLab Path Traversal vulnerability, CVE-2026-85706, which allows attackers to read arbitrary files in a single HTTP request," the researchers said.</p><p>"Based on recent GitLab vulnerabilities, we know the time until indiscriminate exploitation is likely not far away. [..] Defenders should also hunt through log files for HTTP POST requests to '/api/v4/projects/{id}/repository/commits/' URIs containing 'file.path' parameters to identify potential exploitation attempts."</p><p>At the same time, CISA added this bug to its Known Exploited Vulnerabilities (KEV) catalog, confirming the claims and giving government users a tiny three-day window to apply the patch. </p><p>GitLab is an intelligent orchestration platform for DevSecOps professionals, helping organizations automate and streamline the software development cycle. It has more than 50 million registered users, among which are roughly 50% of Fortune 100 companies, as per an <a href="https://www.sec.gov/Archives/edgar/data/1653482/000162828026059943/gtlb-20260731.htm" target="_blank" rel="nofollow">SEC filing</a>. </p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/cisa-hackers-now-exploit-max-severity-gitlab-flaw-in-attacks/" target="_blank" rel="nofollow"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/cisa-warns-hackers-are-exploiting-max-severity-gitlab-flaw-urges-all-businesses-to-patch-immediately</link>
                                                                            <description>
                            <![CDATA[ A 10/10 GitLab flaw was added to CISA's KEV, giving government agencies just three days to patch. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vUcC7WtWua8bdRMRYG76wh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 14 Sep 2026 16:50:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:description>                                                            <media:text><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:text>
                                <media:title type="plain"><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>CISA added GitLab CVE‑2026‑85706, a critical path traversal flaw, to its KEV catalog</strong></li><li><strong>Exploitation already observed; attackers can read sensitive files via commits API without authentication</strong></li><li><strong>GitLab patched in CE/EE 19.3.2, 19.2.6, and 19.1; agencies given three days to update</strong></li></ul><p>The US Cybersecurity and Infrastructure Security Agency (CISA) has added a new GitLab vulnerability to its KEV catalog, warning users that it is being actively exploited in the wild.</p><p>GitLab has now updated its Community Edition (CE) and Enterprise Edition (EE) versions to 19.3.2, 19.2.6, and 19.1, fixing a range of vulnerabilities. Among them were two critical-severity ones: a path traversal issue in repository commits API, and an Insecure Deserialization issue in GraphQL subscription serializer.</p><p>The former is tracked as CVE-2026-85706, with a severity score of 10/10. It stems from missing authentication enforcement and improper path confinement in the repository commits API, allowing unauthenticated threat actors to read various sensitive information such as login credentials or secrets. </p><h2 id="added-to-kev">Added to KEV</h2><p>In the advisory, GitLab did not mention anything about the flaws being abused in the wild - however, a separate report from cybersecurity experts watchTowr, released a day later, claimed so:</p><p>"watchTowr Intel is already observing in-the-wild probes for the latest critical GitLab Path Traversal vulnerability, CVE-2026-85706, which allows attackers to read arbitrary files in a single HTTP request," the researchers said.</p><p>"Based on recent GitLab vulnerabilities, we know the time until indiscriminate exploitation is likely not far away. [..] Defenders should also hunt through log files for HTTP POST requests to '/api/v4/projects/{id}/repository/commits/' URIs containing 'file.path' parameters to identify potential exploitation attempts."</p><p>At the same time, CISA added this bug to its Known Exploited Vulnerabilities (KEV) catalog, confirming the claims and giving government users a tiny three-day window to apply the patch. </p><p>GitLab is an intelligent orchestration platform for DevSecOps professionals, helping organizations automate and streamline the software development cycle. It has more than 50 million registered users, among which are roughly 50% of Fortune 100 companies, as per an <a href="https://www.sec.gov/Archives/edgar/data/1653482/000162828026059943/gtlb-20260731.htm" target="_blank" rel="nofollow">SEC filing</a>. </p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/cisa-hackers-now-exploit-max-severity-gitlab-flaw-in-attacks/" target="_blank" rel="nofollow"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft Cloud accounts stolen in highly complex impersonation and passkey phishing campaign ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft warns of a sophisticated campaign tricking users into updating passkeys via fake IT calls</strong></li><li><strong>Victims redirected to adversary‑in‑the‑middle sites mimicking Microsoft login to steal access</strong></li><li><strong>Attackers exfiltrate files from SharePoint, OneDrive, and Exchange; phishing‑resistant MFA advised</strong></li></ul><p>Passkeys have made stealing passwords obsolete. To work around this change, hackers have started tricking users into authenticating on attacker-controlled computers. This is according to a new report from Microsoft, which says there’s a highly sophisticated campaign currently taking place, with the goal of compromising people’s cloud accounts and stealing as many sensitive files as possible.</p><p>The attack starts a lot earlier than what the victim experiences. There is a lot of pre-attack planning and due diligence, in which the threat actors gather as much information about their target as possible. Knowing their place of work, position, and personal phone number is essential.</p><p>Once all the pieces are in place, the attack starts with a phone call - victims are told they are speaking to their organization’s IT help desk and that they need to update their passkey (or <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">MFA</a>, depending on the setup) immediately, to avoid any disruptions to their operations.</p><h2 id="follow-up-sms">Follow-up SMS</h2><p>In the follow-up to the call, the victims then receive an SMS message with a link where they can update their security configuration. On the surface, the website looks like the legitimate Microsoft login landing page. In reality, though, this is a pre-built malicious website that uses the adversary-in-the-middle (AitM) techniques to either receive access on the actor’s behalf, or capture credentials. </p><p>"The actor appears to invest heavily in pre-attack research, likely gathering information about employees and organizational structure from public sources such as social networking and professional profiling platforms," Microsoft said. "In a smaller number of cases, actors take advantage of already compromised accounts to expand their reach" by sending similar <a href="https://www.techradar.com/best/password-manager" target="_blank">passkey</a>-themed messages via Microsoft Teams.</p><p>The campaign is apparently ongoing since at least May this year, Microsoft, said, without detailing the number of victims. Its aim seems to be to exfiltrate files from SharePoint and OneDrive, as well as email data from Microsoft Exchange Online. It also did not attribute this campaign to any specific threat actor, although it did say that there are many collectives engaged in such, or similar, campaigns, including Cordial Spider, Storm-3121, and others. </p><p><em>Via </em><a href="https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/microsoft-cloud-accounts-stolen-in-highly-complex-impersonation-and-passkey-phishing-campaign</link>
                                                                            <description>
                            <![CDATA[ Passkeys have all but eliminated password theft, so what now? Criminals have a solution. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gvgCtMKG9LSB8TG3Cy7L8V</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dpYpu4kURRoCpERiFgAv8o-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 14 Sep 2026 16:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dpYpu4kURRoCpERiFgAv8o-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Passkeys]]></media:description>                                                            <media:text><![CDATA[Passkeys]]></media:text>
                                <media:title type="plain"><![CDATA[Passkeys]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dpYpu4kURRoCpERiFgAv8o-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft warns of a sophisticated campaign tricking users into updating passkeys via fake IT calls</strong></li><li><strong>Victims redirected to adversary‑in‑the‑middle sites mimicking Microsoft login to steal access</strong></li><li><strong>Attackers exfiltrate files from SharePoint, OneDrive, and Exchange; phishing‑resistant MFA advised</strong></li></ul><p>Passkeys have made stealing passwords obsolete. To work around this change, hackers have started tricking users into authenticating on attacker-controlled computers. This is according to a new report from Microsoft, which says there’s a highly sophisticated campaign currently taking place, with the goal of compromising people’s cloud accounts and stealing as many sensitive files as possible.</p><p>The attack starts a lot earlier than what the victim experiences. There is a lot of pre-attack planning and due diligence, in which the threat actors gather as much information about their target as possible. Knowing their place of work, position, and personal phone number is essential.</p><p>Once all the pieces are in place, the attack starts with a phone call - victims are told they are speaking to their organization’s IT help desk and that they need to update their passkey (or <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">MFA</a>, depending on the setup) immediately, to avoid any disruptions to their operations.</p><h2 id="follow-up-sms">Follow-up SMS</h2><p>In the follow-up to the call, the victims then receive an SMS message with a link where they can update their security configuration. On the surface, the website looks like the legitimate Microsoft login landing page. In reality, though, this is a pre-built malicious website that uses the adversary-in-the-middle (AitM) techniques to either receive access on the actor’s behalf, or capture credentials. </p><p>"The actor appears to invest heavily in pre-attack research, likely gathering information about employees and organizational structure from public sources such as social networking and professional profiling platforms," Microsoft said. "In a smaller number of cases, actors take advantage of already compromised accounts to expand their reach" by sending similar <a href="https://www.techradar.com/best/password-manager" target="_blank">passkey</a>-themed messages via Microsoft Teams.</p><p>The campaign is apparently ongoing since at least May this year, Microsoft, said, without detailing the number of victims. Its aim seems to be to exfiltrate files from SharePoint and OneDrive, as well as email data from Microsoft Exchange Online. It also did not attribute this campaign to any specific threat actor, although it did say that there are many collectives engaged in such, or similar, campaigns, including Cordial Spider, Storm-3121, and others. </p><p><em>Via </em><a href="https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘It 100% sounded just like her’: AI voice scams are getting frighteningly convincing — here’s how to protect your family ]]></title>
                                                                                                <dc:content><![CDATA[ <p>AI voice cloning has reached the point where scammers can convincingly imitate human voices — and worryingly, research suggests we're not particularly good at telling the difference.</p><p>Take the case of<a href="https://x.com/Abomination81/status/2098265674065817770" target="_blank"> one X user</a>, for instance, who posted: “Got a call from my wife telling me she forgot her wallet and needed the credit card to pay for her gas.</p><p>Except my wife was at home with me, and drives a Tesla. Same voice, bit... off, weird cadence, but 100% sounded just like her. If she wasn't there, and it wasn't about gas I would have fallen for it.</p><p>I entertained it for a while to get more out of it, I was so confused. Must be some sort of voice deepfake. The responses were too fast for AI, I think it was a voice filter. I wish I had thought to record it.”</p><p>Whether this particular call used generative AI or a real-time voice filter isn't clear. What is clear is that the days when recognizing somebody's voice was enough to prove who was on the other end of the phone are over, and I’m not alone in finding that terrifying.</p><p>When<a href="https://www.reddit.com/r/ChatGPT/comments/1wdtpbu/as_so_it_begins_over_3_million_views_on_this/" target="_blank"> news of the story hit Reddit</a>, some people were skeptical about whether this had actually happened, but there were plenty of people with similar stories. “This just happened to me last week,” said one user. “They called aunt and grandmother and said they were an attorney and that I was in jail and needed to be bailed out.”</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2560px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="umcJ7nHCEShwbRzPBJivnF" name="shutterstock_2649832729 copy" alt="Beware Scam Phone Call" src="https://cdn.mos.cms.futurecdn.net/umcJ7nHCEShwbRzPBJivnF-1920-80.jpg" mos="" align="middle" fullscreen="" width="2560" height="1440" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock / Andrey_Popov)</span></figcaption></figure><h2 id="the-relative-in-distress-scam">The ‘relative in distress’ scam</h2><p>According to the 2026 paper <a href="https://www.sciencedirect.com/science/article/pii/S0957417426025285" target="_blank"><em>Evaluating AI Models' Capability to Automate Voice Phishing Attacks</em></a> by Fred Heiding and colleagues, a study involving 4,100 US adults found that up to 36.1% said they would comply with, or were unsure whether they would comply with, an AI-powered “relative in distress” scam.</p><p>Importantly, that figure measures self-reported willingness to comply, rather than the number of people who were actually fooled into handing over money. The researchers describe it as a measure of susceptibility to the scam rather than observed behavior.</p><p>The researchers also found that persuasiveness mattered more than how human the voice sounded, and that people who regularly used AI weren't any better at identifying synthetic voices than people with no AI exposure.</p><p>While the scam of tricking people into thinking their loved ones need money may be an old one, AI is making the danger especially real. If the scammer actually sounds like your loved one, how do you know it’s them?</p><p>One answer is to set up a family code word today. It doesn't need to be complicated — just something everybody knows, and that a scammer would be unlikely to guess or discover online.</p><p>There’s also an even simpler precaution: hang up and call the person back on a number you already know. If your son, daughter, partner or parent apparently calls out of the blue asking urgently for money, don't rely on the voice sounding right. End the call and contact them yourself.</p><p>The <a href="https://www.detectdeepfakes.com/examples/ferrari-ceo-deepfake-call?utm_source=chatgpt.com" target="_blank">Ferrari deepfake case</a> shows why some form of personal verification can work. In 2024, a Ferrari executive received messages followed by a phone call apparently impersonating CEO Benedetto Vigna. Suspicious of the call, the executive asked the supposed Vigna to identify a book the real CEO had recently recommended to him. The caller couldn't answer, and the attempted deception fell apart.</p><p>A family code word essentially does the same thing. And it’s something you might have to start thinking about today, if you haven’t already.</p><h2 id="can-you-trust-your-own-ears">Can you trust your own ears?</h2><p>“AI's deepest impact isn't on our devices; it's on us," says Mark Beare, Head of Consumer at Malwarebytes. "When people can no longer trust what they see, hear, or who they're talking to, the damage reaches far beyond any single scam and into the building blocks of our society.”</p><p>A Malwarebytes <a href="https://www.malwarebytes.com/ai-scams" target="_blank">survey published in June</a> found that 85% of people said it’s hard to tell a scam apart from the real thing, up from 66% the previous year. Perhaps even more tellingly, 88% said it was becoming harder to tell which content online was genuinely human or real.</p><p>And that problem isn't restricted to our ears. AI-generated images and deepfake videos are increasingly challenging the assumption that seeing or hearing something for yourself is proof that it really happened.</p><p>We used to be able to rely on a familiar voice as proof of identity, but it seems that in 2026 that's no longer enough. AI voice technology is only going to become more convincing, so our behavior needs to change with it.</p><p>Agree on a code word with the people closest to you now, and if you get an unexpected call asking for money, hang up and call them back. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/ai-platforms-assistants/it-100-percent-sounded-just-like-her-ai-voice-scams-are-getting-frighteningly-convincing-heres-how-to-protect-your-family</link>
                                                                            <description>
                            <![CDATA[ A viral voice scam shows that even if you recognize the voice of a friend or loved one, that's no guarantee that it’s really them. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">UmBcS9gUeP59HzE2kfGdyN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qa2vdH9ywWNaTcjgaZuxL3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 14 Sep 2026 15:16:20 +0000</pubDate>                                                                                                                                <updated>Mon, 14 Sep 2026 15:16:54 +0000</updated>
                                                                                                                                            <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Graham Barlow ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LRCfnbWncUizq2Z6gECPWj-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Graham is the Senior Editor for AI at TechRadar. With over 25 years of experience in both online and print journalism, Graham has worked for various market-leading tech brands including Computeractive, PC Pro, iMore, MacFormat, Mac|Life, Maximum PC, and more. He specializes in reporting on everything to do with the most exciting subject in tech right now, Artificial Intelligence. AI is advancing at an accelerated pace and all the big brands from Apple, Microsoft and Google to chip makers NVIDIA are getting involved. TechRadar is here to bring you the latest updates on AI and show you how to get started and make it work for you, no matter your level of interest.&lt;/p&gt;&lt;p&gt;  Graham has appeared on BBC TV shows like BBC One Breakfast and on Radio 4 commenting on the latest trends in tech. Graham has an honors degree in Computer Science and spends his spare time podcasting and blogging.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qa2vdH9ywWNaTcjgaZuxL3-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / MAYA LAB]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Caucasian adult man male guy at home living room nervous looking at mobile phone.]]></media:description>                                                            <media:text><![CDATA[Caucasian adult man male guy at home living room nervous looking at mobile phone.]]></media:text>
                                <media:title type="plain"><![CDATA[Caucasian adult man male guy at home living room nervous looking at mobile phone.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qa2vdH9ywWNaTcjgaZuxL3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>AI voice cloning has reached the point where scammers can convincingly imitate human voices — and worryingly, research suggests we're not particularly good at telling the difference.</p><p>Take the case of<a href="https://x.com/Abomination81/status/2098265674065817770" target="_blank"> one X user</a>, for instance, who posted: “Got a call from my wife telling me she forgot her wallet and needed the credit card to pay for her gas.</p><p>Except my wife was at home with me, and drives a Tesla. Same voice, bit... off, weird cadence, but 100% sounded just like her. If she wasn't there, and it wasn't about gas I would have fallen for it.</p><p>I entertained it for a while to get more out of it, I was so confused. Must be some sort of voice deepfake. The responses were too fast for AI, I think it was a voice filter. I wish I had thought to record it.”</p><p>Whether this particular call used generative AI or a real-time voice filter isn't clear. What is clear is that the days when recognizing somebody's voice was enough to prove who was on the other end of the phone are over, and I’m not alone in finding that terrifying.</p><p>When<a href="https://www.reddit.com/r/ChatGPT/comments/1wdtpbu/as_so_it_begins_over_3_million_views_on_this/" target="_blank"> news of the story hit Reddit</a>, some people were skeptical about whether this had actually happened, but there were plenty of people with similar stories. “This just happened to me last week,” said one user. “They called aunt and grandmother and said they were an attorney and that I was in jail and needed to be bailed out.”</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2560px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="umcJ7nHCEShwbRzPBJivnF" name="shutterstock_2649832729 copy" alt="Beware Scam Phone Call" src="https://cdn.mos.cms.futurecdn.net/umcJ7nHCEShwbRzPBJivnF-1920-80.jpg" mos="" align="middle" fullscreen="" width="2560" height="1440" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock / Andrey_Popov)</span></figcaption></figure><h2 id="the-relative-in-distress-scam">The ‘relative in distress’ scam</h2><p>According to the 2026 paper <a href="https://www.sciencedirect.com/science/article/pii/S0957417426025285" target="_blank"><em>Evaluating AI Models' Capability to Automate Voice Phishing Attacks</em></a> by Fred Heiding and colleagues, a study involving 4,100 US adults found that up to 36.1% said they would comply with, or were unsure whether they would comply with, an AI-powered “relative in distress” scam.</p><p>Importantly, that figure measures self-reported willingness to comply, rather than the number of people who were actually fooled into handing over money. The researchers describe it as a measure of susceptibility to the scam rather than observed behavior.</p><p>The researchers also found that persuasiveness mattered more than how human the voice sounded, and that people who regularly used AI weren't any better at identifying synthetic voices than people with no AI exposure.</p><p>While the scam of tricking people into thinking their loved ones need money may be an old one, AI is making the danger especially real. If the scammer actually sounds like your loved one, how do you know it’s them?</p><p>One answer is to set up a family code word today. It doesn't need to be complicated — just something everybody knows, and that a scammer would be unlikely to guess or discover online.</p><p>There’s also an even simpler precaution: hang up and call the person back on a number you already know. If your son, daughter, partner or parent apparently calls out of the blue asking urgently for money, don't rely on the voice sounding right. End the call and contact them yourself.</p><p>The <a href="https://www.detectdeepfakes.com/examples/ferrari-ceo-deepfake-call?utm_source=chatgpt.com" target="_blank">Ferrari deepfake case</a> shows why some form of personal verification can work. In 2024, a Ferrari executive received messages followed by a phone call apparently impersonating CEO Benedetto Vigna. Suspicious of the call, the executive asked the supposed Vigna to identify a book the real CEO had recently recommended to him. The caller couldn't answer, and the attempted deception fell apart.</p><p>A family code word essentially does the same thing. And it’s something you might have to start thinking about today, if you haven’t already.</p><h2 id="can-you-trust-your-own-ears">Can you trust your own ears?</h2><p>“AI's deepest impact isn't on our devices; it's on us," says Mark Beare, Head of Consumer at Malwarebytes. "When people can no longer trust what they see, hear, or who they're talking to, the damage reaches far beyond any single scam and into the building blocks of our society.”</p><p>A Malwarebytes <a href="https://www.malwarebytes.com/ai-scams" target="_blank">survey published in June</a> found that 85% of people said it’s hard to tell a scam apart from the real thing, up from 66% the previous year. Perhaps even more tellingly, 88% said it was becoming harder to tell which content online was genuinely human or real.</p><p>And that problem isn't restricted to our ears. AI-generated images and deepfake videos are increasingly challenging the assumption that seeing or hearing something for yourself is proof that it really happened.</p><p>We used to be able to rely on a familiar voice as proof of identity, but it seems that in 2026 that's no longer enough. AI voice technology is only going to become more convincing, so our behavior needs to change with it.</p><p>Agree on a code word with the people closest to you now, and if you get an unexpected call asking for money, hang up and call them back. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why are US AI giants calling for ‘Pacing The Frontier’, and why is China calling it a ‘Cold War tactic’? We ask the experts ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Following the recent resignation of one of Anthropic’s leading researchers, multiple AI CEOs have suddenly begun calling for a slowdown in the development of AI technology to allow regulations and governance on the technology to catch up.</p><p>Speaking to the <a href="https://www.bbc.co.uk/news/articles/c1kx0gyje9wo" target="_blank" rel="nofollow"><em>BBC</em></a> after his resignation, Jacob Coxon warned, “I believe that if we don't slow down at the current rate of progress, there is a strong chance that we could all die in the immediate future.”</p><p>Following this, Anthropic head Dario Amodei, OpenAI CEO Sam Altman, and Grok founder Elon Musk have all apparently aligned in their calls for development to slow down. But there are some tricky waters to navigate - particularly around President Trump, China, and what guardrails should be put into place.</p><h2 id="what-are-ai-heads-saying">What are AI heads saying?</h2><p>Over the weekend, Amodei posted an essay on “why the AI industry should slow down”. In it, he said, “I believe that if slowing down bought us even an extra year or two before models reach critical levels of capability, and we used that time to advance alignment, we could greatly reduce the risk that something goes seriously wrong.”</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/2098773920774074715"><p lang="en" dir="ltr">We Must Pace the Frontier: I’ve written a new essay on why the AI industry should slow down, with a three-part plan for doing so.Anthropic is unilaterally committing to the first of these steps. We’ll provide third-party evaluators with permanent, employee-level access to our systems, so that they can verify adherence to our safety measures, report on incidents, and assess models’ alignment during training.You can read the full post here: https://t.co/OGyPb7yaYt<a href="https://twitter.com/cantworkitout/status/2098773920774074715">September 12, 2026</a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Within the essay, Amodei outlined how AI could be ‘paced’ within the US, and globally, alongside a recommendation that AI companies put ‘evaluator’ teams into place to ensure AI models stay aligned to their tasks. Elon Musk replied to Amodei’s social media post, stating that the Anthropic head was “right”.</p><p>Sam Altman told <em>Fortune</em> the regulations and standards for AI further were “not at a place” to continue progressing AI development. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9-1920-80.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>But not everyone is convinced. US President Donald Trump has said that slowing down AI development is non-negotiable, as it would allow China to rapidly catch up to US AI capabilities. He told reporters that the US is “leading China on AI... and, frankly, I want to keep it that way,” adding that “whoever wins AI, wins”.</p><p>Trump also said that “very negative forces” were behind the growing opposition to AI, and said that fears were being stoked by “that won’t happen”.</p><p>China also isn’t convinced by what the AI giants are saying. <a href="https://www.nbcnews.com/world/china/china-ai-slowdown-trump-amodei-altman-threat-cold-war-rcna597631" target="_blank" rel="nofollow">Beijing labelled the calls for a slowdown as “fearmongering”</a> from a “Cold War playbook.” In his essay, Amodei said that a “Chinese lead in AI would pose grave danger for the United States and the world.”</p><p>Chinese Foreign Ministry spokesperson Guo Jiakun said, “Fearmongering, confrontation and malicious competition will only disrupt the process of global AI governance and serve no one’s interests.”</p><h3 class="article-body__section" id="section-expert-perspectives-on-calls-for-ai-slowdown"><span>Expert perspectives on calls for AI slowdown</span></h3><ul><li><strong>John Strand, Owner, Black Hills Information Security:</strong></li></ul><p><em>Up until this weekend, I was leaning toward believing that calls for an AI slowdown were purely performative. Then I woke up and read the news today and realized that it almost doesn’t matter.</em></p><p><em>We can talk about slowing down AI until we’re blue in the face, but when the United States is saying it doesn’t want to slow down because it’s competing with China, and China is aggressively pushing AI development as well, we’re talking about the two major economic and military powers on the planet having enormous incentives to keep moving.</em></p><div><blockquote><p>This really feels like we’re entering an atomic arms race moment.</p></blockquote></div><p><em>At that point, calls for a slowdown don’t have much bite.</em></p><p><em>I’d like to believe that Anthropic, OpenAI, xAI, and the other frontier model labs are working on better controls. But unless you can get the nation states and the major AI labs moving in the same direction, I don’t see how meaningful restrictions actually work.</em></p><p><em>This really feels like we’re entering an atomic arms race moment.</em></p><p><em>Stick with me here.</em></p><p><em>In 1950, physicist Leó Szilárd publicly discussed the idea of a cobalt bomb, essentially a doomsday weapon that could potentially produce enough radioactive fallout to make the Earth uninhabitable. He wasn’t proposing that somebody build the damn thing. He was trying to demonstrate where the technology could ultimately lead.</em></p><p><em>That’s the kind of moment I think we’re approaching with AI.</em></p><p><em>During the nuclear arms race, eventually the consequences became serious enough that competing nations had to at least start talking about limits, controls, and ways to keep competition from ending catastrophically.</em></p><p><em>I think we’re heading toward a similar problem with AI. Until China, the United States, and the major frontier model labs are all sitting at the same table, restrictions adopted by individual companies or individual countries are going to have a very difficult time holding.</em></p><p><em>Someone slowing down only works if they believe the other guy is going to slow down too.</em></p><ul><li><strong>Ryan McCurdy, VP, Liquibase:</strong></li></ul><p><em>Slowing frontier development may give AI companies more time to understand and address the risks Amodei is describing. But enterprises can’t build their AI strategy around the assumption that AI is going to slow down.</em></p><p><em>AI is already moving from generating content and code to taking action across software delivery and production systems. The question for enterprises is how they adopt that capability without giving up control.</em></p><div><blockquote><p>We can debate how quickly the frontier should move. Enterprises still have to prepare for where it’s going.</p></blockquote></div><p><em>That means putting governance where AI decisions become real actions. Organizations need to define what an agent can access, what it can change, what it can decide on its own, and what policies have to be met before a change reaches a critical system. Those controls need to work whether the action comes from a developer, automation, or an AI agent.</em></p><p><em>We can debate how quickly the frontier should move. Enterprises still have to prepare for where it’s going.</em></p><ul><li><strong>Tristan Watkins, director of services innovation, Advania UK:</strong></li></ul><p><em>Until recently, the major AI labs have been reluctant to slow their development efforts unilaterally. Over the last week this changed, with new commitments from OpenAI and Anthropic to prioritise AI alignment and interpretability research, to become more externally verifiable, and to establish safety precedents that governments could adapt.</em></p><div><blockquote><p>Hopefully this underscores why we need governments to lead these efforts more proactively.</p></blockquote></div><p><em>Given that these two organisations already allocate far more on AI Safety than their competitors, this bilateral leadership is extremely welcome.</em></p><p><em>It appears that other US labs may follow suit, but given the differences in AI Safety spending outside of Anthropic and OpenAI today, this will require investment more than lip service. Hopefully this underscores why we need governments to lead these efforts more proactively.</em></p><ul><li><strong>Oleksandr Yaremchuk, CTO and Co-Founder, Manifold Security:</strong></li></ul><p><em>Pacing the frontier is the right conversation to be having, but it cannot become a substitute for securing the AI we have already put into the world. The uncomfortable reality is that we are debating how to quickly build more powerful agents while struggling to control the ones already operating with real credentials, real access and real-world consequences.</em><br><br><em>The incidents behind this debate make that clear. The Hugging Face attack was not just a failure of model alignment. Agents ran for days through an unmonitored system, with credentials that had not been rotated, and the victim spotted the activity before the people running the agents did. The problem wasn't simply what the model was capable of. It was that nobody was watching closely enough when it acted.</em></p><div><blockquote><p>But if an agent can act autonomously on your systems today, you should already be able to answer three basic questions: what did it do, what did it have access to, and could you have stopped it?</p></blockquote></div><p><em>A fitting analogy is with hazardous materials. We don't just wait for them to become more dangerous before deciding how they should be handled. We control their custody, monitor where they go, limit who can access them and establish clear accountability when something goes wrong. AI agents need the same thinking.</em><br><br><em>Independent evaluation of frontier models is important. But if an agent can act autonomously on your systems today, you should already be able to answer three basic questions: what did it do, what did it have access to, and could you have stopped it? If you don't know what it did or what it could access, you can't know whether you could have stopped it. Slowing down the next generation won't solve the problem you have right now.</em></p><ul><li><strong>Heath Mullins, Chief Evangelist, ExtraHop:</strong></li></ul><p><em>AI leaders calling for a slowdown is confirming what the security industry has already been living through firsthand. This isn't a hypothetical risk, it's the threat landscape we're defending against right now.</em></p><p><em>While it is concerning to see the pace of innovation behind these AI models, the real challenge is that organizations haven't had the runway to build the infrastructure to defend against machine-speed threats.</em></p><div><blockquote><p>This isn't a hypothetical risk, it's the threat landscape we're defending against right now.</p></blockquote></div><p><em>Calls for caution surrounding the speed of AI development buys the security industry time to get proper visibility into AI activity.</em></p><p><em>Understanding AI activity within an organization is critical as we’ve seen models break out of sandboxes despite governance built into those models. Every organization will be relying on AI agents for machine-speed defense, and they need their own governance over how these models and agents operate inside their environment, starting with independent evidence of what they actually do, what they access, where they move data, what systems they talk to, and what actions they take.</em></p><p><em>You can't govern AI based on what a model is designed or permitted to do. Instead, you need real-time evidence of what models and agents are actually doing, because the gap between exponentially more capable AI and defenders' ability to see it is exactly where the next incident happens.</em></p><ul><li><strong>Bri Frost, Director of Product Management, Cloud Range:</strong></li></ul><p><em>The answer is not necessarily to stop AI innovation but, we need to stop pretending innovation and security are advancing at the same speed.</em></p><p><em>When ChatGPT became publicly available in 2022, the models were dramatically less capable than they are today — and the guardrails were very easy to manipulate.  The difference is that the models behind those guardrails are no longer the models of 2022. They can reason better, write and debug code. They can operate as agents. They can collaborate! And increasingly, they can interact and affect real infrastructure.</em></p><div><blockquote><p>The faster we build the engine, the more important the brakes become.</p></blockquote></div><p><em>Meanwhile, the model release cycle has gone from feeling like major capability jumps every year or two to seemingly every few weeks. That creates a dangerous asymmetry: AI capability is compounding faster than security.</em></p><p><em>Security and innovation have always been in conflict with each other. If every security problem had to be solved before we innovated, we’d never ship anything. But the opposite extreme is just as reckless: accelerating capability while just assuming we’ll bolt the security controls on afterward and they’ll be effective.</em></p><p><em>Every new release of AI capability expands the attack surface exponentially. Give a vulnerable model better reasoning, then tool access, then memory, then autonomy, then connectivity to production systems, and yesterday’s jailbreak isn’t just a clever prompt anymore — it’s an execution path. That’s the snowball effect we should be worried about.</em></p><p><em>Responsibility also must lie with the AI companies. If a SaaS company knowingly shipped software with weak security controls and customers were harmed, we wouldn’t excuse it because they were 'innovating quickly'.</em></p><p><em>So why are we treating AI differently?</em></p><p><em>You don’t get to race to build increasingly powerful, autonomous systems, profit from them, and then shrug when predictable security failures cause damage.</em></p><p><em>Sure the argument can be made that no product is perfectly secure - That’s not the standard. But if you ship the product, you inherit responsibility for securing it. And continuing to secure it better!</em></p><p><em>The conversation shouldn’t simply be “Should we slow AI down?”</em></p><p><em>It should be: Can our ability to test, validate, contain and secure AI keep pace with our ability to make it more powerful? Is there an equivocal kill switch?</em></p><p><em>Right now, the answer is no.</em></p><p><em>And if we’re going to keep accelerating — which I believe we will — then independent testing, adversarial evaluation, isolated testing environments, containment, continuous validation and security-by-design can’t remain optional steps we add after the innovation happens.</em></p><p><em>The faster we build the engine, the more important the brakes become.</em></p><ul><li><strong>Denis Calderone, CTO, Suzu Labs:</strong></li></ul><p><em>Amodei's diagnosis is the most honest thing a frontier lab CEO has said publicly. The agent risk is real, recursive self-improvement is accelerating, and the competitive pressure is making both worse.</em></p><p><em>Where I get skeptical is the prescription. Democratic coordination among companies in a commercial race? Global pacing agreements with China? Amodei himself rates the hardest steps as unlikely. No lab has named a single model release they'll delay because of this essay.</em></p><div><blockquote><p>No lab has named a single model release they'll delay because of this essay.</p></blockquote></div><p><em>The one idea worth holding the industry to is embedded evaluators with independent publication rights. Give third-party safety researchers permanent access inside the labs, comparable to what bank examiners have inside banks, and let them publish what they find without the company controlling the narrative. That's a simple, concrete accountability mechanism. It doesn't require global coordination or antitrust waivers. Anthropic says they're committing to it unilaterally. Good. Now make the rest of the industry match.</em></p><ul><li><strong>Donald McFarlane, Board Member, Xcape Inc:</strong></li></ul><p><em>AI does not develop an agenda; its operators do. When we give an autonomous system powerful access and ability to act at machine speed, they will continue to prove highly capable.</em></p><div><blockquote><p>AI does not develop an agenda; its operators do.</p></blockquote></div><p><em>Rules enacted in the name of safety must not become a moat against competition or progress. Enormous compliance costs may be manageable for the handful of companies already spending billions building frontier models, while becoming a substantial barrier to everyone behind them.</em></p><p><em>Government can help clarify accountability and duties of care, and facilitate strong information sharing and collective defense, which is an area where we sorely need more effective public-private partnerships.</em></p><p><em>But safeguards should focus on how these systems are used and deployed, rather than deciding who is allowed to build powerful AI in the first place.</em></p><p><em>The goal should be safer deployment without pulling up the drawbridge on innovation.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/why-are-us-ai-giants-calling-for-pacing-the-frontier-and-why-is-china-calling-it-a-cold-war-tactic-we-ask-the-experts</link>
                                                                            <description>
                            <![CDATA[ AI companies want to slow down development, but that doesn't fly with Trump and China - so what do the experts think? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">p9sGJ7PH3r7Hm54no7qrYb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PRCsQfoXPXi2t4jsGwWr6L-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 14 Sep 2026 15:10:07 +0000</pubDate>                                                                                                                                <updated>Mon, 14 Sep 2026 15:57:17 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[OpenAI]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[Claude]]></category>
                                                    <category><![CDATA[ChatGPT]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PRCsQfoXPXi2t4jsGwWr6L-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A human shakes a robot&#039;s hand in front of blue concentric circles]]></media:description>                                                            <media:text><![CDATA[A human shakes a robot&#039;s hand in front of blue concentric circles]]></media:text>
                                <media:title type="plain"><![CDATA[A human shakes a robot&#039;s hand in front of blue concentric circles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PRCsQfoXPXi2t4jsGwWr6L-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Following the recent resignation of one of Anthropic’s leading researchers, multiple AI CEOs have suddenly begun calling for a slowdown in the development of AI technology to allow regulations and governance on the technology to catch up.</p><p>Speaking to the <a href="https://www.bbc.co.uk/news/articles/c1kx0gyje9wo" target="_blank" rel="nofollow"><em>BBC</em></a> after his resignation, Jacob Coxon warned, “I believe that if we don't slow down at the current rate of progress, there is a strong chance that we could all die in the immediate future.”</p><p>Following this, Anthropic head Dario Amodei, OpenAI CEO Sam Altman, and Grok founder Elon Musk have all apparently aligned in their calls for development to slow down. But there are some tricky waters to navigate - particularly around President Trump, China, and what guardrails should be put into place.</p><h2 id="what-are-ai-heads-saying">What are AI heads saying?</h2><p>Over the weekend, Amodei posted an essay on “why the AI industry should slow down”. In it, he said, “I believe that if slowing down bought us even an extra year or two before models reach critical levels of capability, and we used that time to advance alignment, we could greatly reduce the risk that something goes seriously wrong.”</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/2098773920774074715"><p lang="en" dir="ltr">We Must Pace the Frontier: I’ve written a new essay on why the AI industry should slow down, with a three-part plan for doing so.Anthropic is unilaterally committing to the first of these steps. We’ll provide third-party evaluators with permanent, employee-level access to our systems, so that they can verify adherence to our safety measures, report on incidents, and assess models’ alignment during training.You can read the full post here: https://t.co/OGyPb7yaYt<a href="https://twitter.com/cantworkitout/status/2098773920774074715">September 12, 2026</a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Within the essay, Amodei outlined how AI could be ‘paced’ within the US, and globally, alongside a recommendation that AI companies put ‘evaluator’ teams into place to ensure AI models stay aligned to their tasks. Elon Musk replied to Amodei’s social media post, stating that the Anthropic head was “right”.</p><p>Sam Altman told <em>Fortune</em> the regulations and standards for AI further were “not at a place” to continue progressing AI development. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9-1920-80.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>But not everyone is convinced. US President Donald Trump has said that slowing down AI development is non-negotiable, as it would allow China to rapidly catch up to US AI capabilities. He told reporters that the US is “leading China on AI... and, frankly, I want to keep it that way,” adding that “whoever wins AI, wins”.</p><p>Trump also said that “very negative forces” were behind the growing opposition to AI, and said that fears were being stoked by “that won’t happen”.</p><p>China also isn’t convinced by what the AI giants are saying. <a href="https://www.nbcnews.com/world/china/china-ai-slowdown-trump-amodei-altman-threat-cold-war-rcna597631" target="_blank" rel="nofollow">Beijing labelled the calls for a slowdown as “fearmongering”</a> from a “Cold War playbook.” In his essay, Amodei said that a “Chinese lead in AI would pose grave danger for the United States and the world.”</p><p>Chinese Foreign Ministry spokesperson Guo Jiakun said, “Fearmongering, confrontation and malicious competition will only disrupt the process of global AI governance and serve no one’s interests.”</p><h3 class="article-body__section" id="section-expert-perspectives-on-calls-for-ai-slowdown"><span>Expert perspectives on calls for AI slowdown</span></h3><ul><li><strong>John Strand, Owner, Black Hills Information Security:</strong></li></ul><p><em>Up until this weekend, I was leaning toward believing that calls for an AI slowdown were purely performative. Then I woke up and read the news today and realized that it almost doesn’t matter.</em></p><p><em>We can talk about slowing down AI until we’re blue in the face, but when the United States is saying it doesn’t want to slow down because it’s competing with China, and China is aggressively pushing AI development as well, we’re talking about the two major economic and military powers on the planet having enormous incentives to keep moving.</em></p><div><blockquote><p>This really feels like we’re entering an atomic arms race moment.</p></blockquote></div><p><em>At that point, calls for a slowdown don’t have much bite.</em></p><p><em>I’d like to believe that Anthropic, OpenAI, xAI, and the other frontier model labs are working on better controls. But unless you can get the nation states and the major AI labs moving in the same direction, I don’t see how meaningful restrictions actually work.</em></p><p><em>This really feels like we’re entering an atomic arms race moment.</em></p><p><em>Stick with me here.</em></p><p><em>In 1950, physicist Leó Szilárd publicly discussed the idea of a cobalt bomb, essentially a doomsday weapon that could potentially produce enough radioactive fallout to make the Earth uninhabitable. He wasn’t proposing that somebody build the damn thing. He was trying to demonstrate where the technology could ultimately lead.</em></p><p><em>That’s the kind of moment I think we’re approaching with AI.</em></p><p><em>During the nuclear arms race, eventually the consequences became serious enough that competing nations had to at least start talking about limits, controls, and ways to keep competition from ending catastrophically.</em></p><p><em>I think we’re heading toward a similar problem with AI. Until China, the United States, and the major frontier model labs are all sitting at the same table, restrictions adopted by individual companies or individual countries are going to have a very difficult time holding.</em></p><p><em>Someone slowing down only works if they believe the other guy is going to slow down too.</em></p><ul><li><strong>Ryan McCurdy, VP, Liquibase:</strong></li></ul><p><em>Slowing frontier development may give AI companies more time to understand and address the risks Amodei is describing. But enterprises can’t build their AI strategy around the assumption that AI is going to slow down.</em></p><p><em>AI is already moving from generating content and code to taking action across software delivery and production systems. The question for enterprises is how they adopt that capability without giving up control.</em></p><div><blockquote><p>We can debate how quickly the frontier should move. Enterprises still have to prepare for where it’s going.</p></blockquote></div><p><em>That means putting governance where AI decisions become real actions. Organizations need to define what an agent can access, what it can change, what it can decide on its own, and what policies have to be met before a change reaches a critical system. Those controls need to work whether the action comes from a developer, automation, or an AI agent.</em></p><p><em>We can debate how quickly the frontier should move. Enterprises still have to prepare for where it’s going.</em></p><ul><li><strong>Tristan Watkins, director of services innovation, Advania UK:</strong></li></ul><p><em>Until recently, the major AI labs have been reluctant to slow their development efforts unilaterally. Over the last week this changed, with new commitments from OpenAI and Anthropic to prioritise AI alignment and interpretability research, to become more externally verifiable, and to establish safety precedents that governments could adapt.</em></p><div><blockquote><p>Hopefully this underscores why we need governments to lead these efforts more proactively.</p></blockquote></div><p><em>Given that these two organisations already allocate far more on AI Safety than their competitors, this bilateral leadership is extremely welcome.</em></p><p><em>It appears that other US labs may follow suit, but given the differences in AI Safety spending outside of Anthropic and OpenAI today, this will require investment more than lip service. Hopefully this underscores why we need governments to lead these efforts more proactively.</em></p><ul><li><strong>Oleksandr Yaremchuk, CTO and Co-Founder, Manifold Security:</strong></li></ul><p><em>Pacing the frontier is the right conversation to be having, but it cannot become a substitute for securing the AI we have already put into the world. The uncomfortable reality is that we are debating how to quickly build more powerful agents while struggling to control the ones already operating with real credentials, real access and real-world consequences.</em><br><br><em>The incidents behind this debate make that clear. The Hugging Face attack was not just a failure of model alignment. Agents ran for days through an unmonitored system, with credentials that had not been rotated, and the victim spotted the activity before the people running the agents did. The problem wasn't simply what the model was capable of. It was that nobody was watching closely enough when it acted.</em></p><div><blockquote><p>But if an agent can act autonomously on your systems today, you should already be able to answer three basic questions: what did it do, what did it have access to, and could you have stopped it?</p></blockquote></div><p><em>A fitting analogy is with hazardous materials. We don't just wait for them to become more dangerous before deciding how they should be handled. We control their custody, monitor where they go, limit who can access them and establish clear accountability when something goes wrong. AI agents need the same thinking.</em><br><br><em>Independent evaluation of frontier models is important. But if an agent can act autonomously on your systems today, you should already be able to answer three basic questions: what did it do, what did it have access to, and could you have stopped it? If you don't know what it did or what it could access, you can't know whether you could have stopped it. Slowing down the next generation won't solve the problem you have right now.</em></p><ul><li><strong>Heath Mullins, Chief Evangelist, ExtraHop:</strong></li></ul><p><em>AI leaders calling for a slowdown is confirming what the security industry has already been living through firsthand. This isn't a hypothetical risk, it's the threat landscape we're defending against right now.</em></p><p><em>While it is concerning to see the pace of innovation behind these AI models, the real challenge is that organizations haven't had the runway to build the infrastructure to defend against machine-speed threats.</em></p><div><blockquote><p>This isn't a hypothetical risk, it's the threat landscape we're defending against right now.</p></blockquote></div><p><em>Calls for caution surrounding the speed of AI development buys the security industry time to get proper visibility into AI activity.</em></p><p><em>Understanding AI activity within an organization is critical as we’ve seen models break out of sandboxes despite governance built into those models. Every organization will be relying on AI agents for machine-speed defense, and they need their own governance over how these models and agents operate inside their environment, starting with independent evidence of what they actually do, what they access, where they move data, what systems they talk to, and what actions they take.</em></p><p><em>You can't govern AI based on what a model is designed or permitted to do. Instead, you need real-time evidence of what models and agents are actually doing, because the gap between exponentially more capable AI and defenders' ability to see it is exactly where the next incident happens.</em></p><ul><li><strong>Bri Frost, Director of Product Management, Cloud Range:</strong></li></ul><p><em>The answer is not necessarily to stop AI innovation but, we need to stop pretending innovation and security are advancing at the same speed.</em></p><p><em>When ChatGPT became publicly available in 2022, the models were dramatically less capable than they are today — and the guardrails were very easy to manipulate.  The difference is that the models behind those guardrails are no longer the models of 2022. They can reason better, write and debug code. They can operate as agents. They can collaborate! And increasingly, they can interact and affect real infrastructure.</em></p><div><blockquote><p>The faster we build the engine, the more important the brakes become.</p></blockquote></div><p><em>Meanwhile, the model release cycle has gone from feeling like major capability jumps every year or two to seemingly every few weeks. That creates a dangerous asymmetry: AI capability is compounding faster than security.</em></p><p><em>Security and innovation have always been in conflict with each other. If every security problem had to be solved before we innovated, we’d never ship anything. But the opposite extreme is just as reckless: accelerating capability while just assuming we’ll bolt the security controls on afterward and they’ll be effective.</em></p><p><em>Every new release of AI capability expands the attack surface exponentially. Give a vulnerable model better reasoning, then tool access, then memory, then autonomy, then connectivity to production systems, and yesterday’s jailbreak isn’t just a clever prompt anymore — it’s an execution path. That’s the snowball effect we should be worried about.</em></p><p><em>Responsibility also must lie with the AI companies. If a SaaS company knowingly shipped software with weak security controls and customers were harmed, we wouldn’t excuse it because they were 'innovating quickly'.</em></p><p><em>So why are we treating AI differently?</em></p><p><em>You don’t get to race to build increasingly powerful, autonomous systems, profit from them, and then shrug when predictable security failures cause damage.</em></p><p><em>Sure the argument can be made that no product is perfectly secure - That’s not the standard. But if you ship the product, you inherit responsibility for securing it. And continuing to secure it better!</em></p><p><em>The conversation shouldn’t simply be “Should we slow AI down?”</em></p><p><em>It should be: Can our ability to test, validate, contain and secure AI keep pace with our ability to make it more powerful? Is there an equivocal kill switch?</em></p><p><em>Right now, the answer is no.</em></p><p><em>And if we’re going to keep accelerating — which I believe we will — then independent testing, adversarial evaluation, isolated testing environments, containment, continuous validation and security-by-design can’t remain optional steps we add after the innovation happens.</em></p><p><em>The faster we build the engine, the more important the brakes become.</em></p><ul><li><strong>Denis Calderone, CTO, Suzu Labs:</strong></li></ul><p><em>Amodei's diagnosis is the most honest thing a frontier lab CEO has said publicly. The agent risk is real, recursive self-improvement is accelerating, and the competitive pressure is making both worse.</em></p><p><em>Where I get skeptical is the prescription. Democratic coordination among companies in a commercial race? Global pacing agreements with China? Amodei himself rates the hardest steps as unlikely. No lab has named a single model release they'll delay because of this essay.</em></p><div><blockquote><p>No lab has named a single model release they'll delay because of this essay.</p></blockquote></div><p><em>The one idea worth holding the industry to is embedded evaluators with independent publication rights. Give third-party safety researchers permanent access inside the labs, comparable to what bank examiners have inside banks, and let them publish what they find without the company controlling the narrative. That's a simple, concrete accountability mechanism. It doesn't require global coordination or antitrust waivers. Anthropic says they're committing to it unilaterally. Good. Now make the rest of the industry match.</em></p><ul><li><strong>Donald McFarlane, Board Member, Xcape Inc:</strong></li></ul><p><em>AI does not develop an agenda; its operators do. When we give an autonomous system powerful access and ability to act at machine speed, they will continue to prove highly capable.</em></p><div><blockquote><p>AI does not develop an agenda; its operators do.</p></blockquote></div><p><em>Rules enacted in the name of safety must not become a moat against competition or progress. Enormous compliance costs may be manageable for the handful of companies already spending billions building frontier models, while becoming a substantial barrier to everyone behind them.</em></p><p><em>Government can help clarify accountability and duties of care, and facilitate strong information sharing and collective defense, which is an area where we sorely need more effective public-private partnerships.</em></p><p><em>But safeguards should focus on how these systems are used and deployed, rather than deciding who is allowed to build powerful AI in the first place.</em></p><p><em>The goal should be safer deployment without pulling up the drawbridge on innovation.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Revolut sent identity data, contact details, and documents to hackers posing as a government agency ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Revolut fell for a spoofed government email scam, leaking sensitive customer data to attackers</strong></li><li><strong>Compromised info includes IDs, selfies, account statements, IBANs, and full transaction histories</strong></li><li><strong>Criminals now allegedly leaking data on Telegram, demanding 10,000 BTC (~$780M) ransom from Revolut</strong></li></ul><p>Digital banking platform Revolut was tricked into giving away a treasure trove of sensitive customer data to hackers, and it is now coming back to bite it. </p><p>The company told <a href="https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/" target="_blank" rel="nofollow"><em>TechCrunch</em></a> that it recently fell victim to a “sophisticated external impersonation scam” in which the threat actor “utilized a legitimate government agency domain email to submit fraudulent requests for information”.</p><p>In other words, the attackers either broke into, or spoofed, an email address belonging to the police, tax authorities, or other government bodies with statutory powers to demand information, and used them to demand Revolut hand over <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">sensitive customer data</a>.</p><h2 id="demanding-ransom">Demanding ransom</h2><p><em>Cybernews </em>reports that the compromised data includes customers’ birth dates, postal and email addresses, occupation, phone numbers, and copies of identity documents. TechCrunch added that verification selfies, account statements, and transaction histories may have also been compromised, together with IBANs, withdrawal records, complete transaction histories, and Bitcoin transactions. </p><p>Should these reports be confirmed, this will be a bonafide fiasco for Revolut. </p><p>"Upon detection, ⁠we immediately blocked the address and ​alerted the relevant government agency as ​well as enforcement agencies, data protection, and financial regulators," a company spokesperson told <a href="https://www.reuters.com/legal/litigation/revolut-confirms-sensitive-customer-data-breach-falling-fake-government-requests-2026-09-12/" target="_blank" rel="nofollow"><em>Reuters</em></a><em> </em>over the weekend.</p><p>So far, we don’t know exactly how many people are affected. Revolut said it is a “very limited” number, and that all of them had been notified already. </p><p>According to <a href="https://x.com/coinbureau/status/2099403277003882756/photo/1" target="_blank" rel="nofollow"><em>Coin Bureau</em></a>, the criminals have started leaking sensitive data on Telegram, in a bid to pressure Revolut into paying a ransom demand. The publication shared screenshots of the threat actors apparently leaking a selfie and “full KYC” of a CEO of a crypto casino website, saying that the crooks are now demanding 10,000 BTC in exchange for deleting the data.</p><p>This would put the ransom demand at approximately $780 million which is obscene even by criminal standards.</p><p>"This one is deeply concerning and the implications for affected customers go well beyond a standard data breach notification," said Muhammad Yahya Patel, vCISO & Cybersecurity Advisor at Huntress. "Passports, driver's licenses, verification selfies, account statements, transaction histories, birth dates, addresses that's not a data leak, that's a complete identity theft kit handed to whoever sent those fraudulent requests." </p><p>"Every single component needed to impersonate someone, open accounts in their name, or bypass checks at other financial institutions is in that package. On the dark web, that kind of profile doesn't sell as individual records it sells as a ready-made fraud pack, and it commands a significant premium precisely because of its completeness."</p><p>"For a fintech built on digital identity verification, the bar for verifying third-party data requests should be exceptionally high. The question isn't why an attacker tried this. It's why a regulated financial institution handling highly sensitive data didn't have sufficiently rigorous verification controls to catch it," Patel concluded.</p><p><em>Via </em><a href="https://cybernews.com/news/revolut-customer-data-breach/" target="_blank" rel="nofollow"><em>Cybernews</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/revolut-sent-identity-data-contact-details-and-documents-to-hackers-posing-as-a-government-agency</link>
                                                                            <description>
                            <![CDATA[ Revolut is now being asked to pay a humongous ransom demand to keep the data private. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">s7ADPiptc373nMwamyA6ZP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Ji9MEgBv83riosWJLaNZGB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 14 Sep 2026 14:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Ji9MEgBv83riosWJLaNZGB-1280-80.jpg">
                                                            <media:credit><![CDATA[Revolut]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An outstretched hand holds a smartphone displaying the Revolut app]]></media:description>                                                            <media:text><![CDATA[An outstretched hand holds a smartphone displaying the Revolut app]]></media:text>
                                <media:title type="plain"><![CDATA[An outstretched hand holds a smartphone displaying the Revolut app]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Ji9MEgBv83riosWJLaNZGB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Revolut fell for a spoofed government email scam, leaking sensitive customer data to attackers</strong></li><li><strong>Compromised info includes IDs, selfies, account statements, IBANs, and full transaction histories</strong></li><li><strong>Criminals now allegedly leaking data on Telegram, demanding 10,000 BTC (~$780M) ransom from Revolut</strong></li></ul><p>Digital banking platform Revolut was tricked into giving away a treasure trove of sensitive customer data to hackers, and it is now coming back to bite it. </p><p>The company told <a href="https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/" target="_blank" rel="nofollow"><em>TechCrunch</em></a> that it recently fell victim to a “sophisticated external impersonation scam” in which the threat actor “utilized a legitimate government agency domain email to submit fraudulent requests for information”.</p><p>In other words, the attackers either broke into, or spoofed, an email address belonging to the police, tax authorities, or other government bodies with statutory powers to demand information, and used them to demand Revolut hand over <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">sensitive customer data</a>.</p><h2 id="demanding-ransom">Demanding ransom</h2><p><em>Cybernews </em>reports that the compromised data includes customers’ birth dates, postal and email addresses, occupation, phone numbers, and copies of identity documents. TechCrunch added that verification selfies, account statements, and transaction histories may have also been compromised, together with IBANs, withdrawal records, complete transaction histories, and Bitcoin transactions. </p><p>Should these reports be confirmed, this will be a bonafide fiasco for Revolut. </p><p>"Upon detection, ⁠we immediately blocked the address and ​alerted the relevant government agency as ​well as enforcement agencies, data protection, and financial regulators," a company spokesperson told <a href="https://www.reuters.com/legal/litigation/revolut-confirms-sensitive-customer-data-breach-falling-fake-government-requests-2026-09-12/" target="_blank" rel="nofollow"><em>Reuters</em></a><em> </em>over the weekend.</p><p>So far, we don’t know exactly how many people are affected. Revolut said it is a “very limited” number, and that all of them had been notified already. </p><p>According to <a href="https://x.com/coinbureau/status/2099403277003882756/photo/1" target="_blank" rel="nofollow"><em>Coin Bureau</em></a>, the criminals have started leaking sensitive data on Telegram, in a bid to pressure Revolut into paying a ransom demand. The publication shared screenshots of the threat actors apparently leaking a selfie and “full KYC” of a CEO of a crypto casino website, saying that the crooks are now demanding 10,000 BTC in exchange for deleting the data.</p><p>This would put the ransom demand at approximately $780 million which is obscene even by criminal standards.</p><p>"This one is deeply concerning and the implications for affected customers go well beyond a standard data breach notification," said Muhammad Yahya Patel, vCISO & Cybersecurity Advisor at Huntress. "Passports, driver's licenses, verification selfies, account statements, transaction histories, birth dates, addresses that's not a data leak, that's a complete identity theft kit handed to whoever sent those fraudulent requests." </p><p>"Every single component needed to impersonate someone, open accounts in their name, or bypass checks at other financial institutions is in that package. On the dark web, that kind of profile doesn't sell as individual records it sells as a ready-made fraud pack, and it commands a significant premium precisely because of its completeness."</p><p>"For a fintech built on digital identity verification, the bar for verifying third-party data requests should be exceptionally high. The question isn't why an attacker tried this. It's why a regulated financial institution handling highly sensitive data didn't have sufficiently rigorous verification controls to catch it," Patel concluded.</p><p><em>Via </em><a href="https://cybernews.com/news/revolut-customer-data-breach/" target="_blank" rel="nofollow"><em>Cybernews</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Web fraud enters a new age as complete 'synthetic identities' can now be bought for as little as $200 on dark web marketplaces ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Coveron and NordLayer found synthetic “digital Frankenstein” identities sold on dark web for ~$200</strong></li><li><strong>Packages mix stolen data with AI‑generated names, deepfake selfies, and cloned voices to bypass KYC</strong></li><li><strong>Researchers urge credit freezes, layered verification, and monitoring to counter rising synthetic identity fraud</strong></li></ul><p>You can now get your own “digital Frankenstein” for as little as $200, which will pass automated know-your-customer (KYC) checks on your behalf, and help you register fraudulent accounts with banks, cryptocurrency exchanges, and similar services. This is no longer a fringe, niche cybercriminal offering - it’s basically mainstream.</p><p>Recently, researchers from identity theft protection services Coveron and threat exposure management platform NordLayer Intelligence sifted through dark web forums and Telegram Channels, analyzing 22 queries over 362,000 posts related to identity fraud, deepfake services, and something they call “synthetic identity creation”.</p><p>A synthetic identity is essentially a fake, non-existent person, but created in a way that can fool many automated identity verification systems. It combines real stolen data, such as a Social Security number, with AI-generated fake information such as names, addresses, deepfake selfies, and cloned voices. The researchers call these identities” digital Frankensteins”, and claim they are “fully capable” of passing ID checks. </p><h2 id="rising-popularity">Rising popularity</h2><p>Apparently, the number of posts and inquiries for synthetic identities is blowing up. In Q1 2024, there were roughly 40 posts a month discussing deepfakes. By Q2 2026, the number rose to 307 per month, an eightfold increase. It wasn’t a steady increase, either. Throughout 2025, the numbers remained similar to the year prior, and relatively flat. Only in 2026 the monthly averages jumped to 255 posts, the researchers warned. </p><p>Over the past year, there were more than 10,000 posts offering complete identity data, bundled with deepfake selfies and matching documents. All of this is being sold for around $200. To make matters worse, criminals don’t even have to purchase the entire package. They can buy parts of it (a deepfaked selfie, or a cloned voice), for as little as $10. </p><p>To protect against synthetic identity fraud, users should monitor personal data and act quickly if they discover a breach. Credits should be frozen if you’re not applying for new accounts, and everyone should be skeptical of unusual identity verification requests, Coveron explains. Businesses, on the other hand, should layer their verification systems and use <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft protection services</a>. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/web-fraud-enters-a-new-age-as-complete-synthetic-identities-can-now-be-bought-for-as-little-as-usd200-on-dark-web-marketplaces</link>
                                                                            <description>
                            <![CDATA[ Your "digital Frankenstein" can pass KYC and you can get it for $200 on Telegram ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GVMqwEwDMBUFHy7b4YjJfZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sFwyWVhzZ3pH6hBkwH8Lra-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 14 Sep 2026 11:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sFwyWVhzZ3pH6hBkwH8Lra-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Several figures wearing paper bags on their heads with smiley faces drawn on them.]]></media:description>                                                            <media:text><![CDATA[Several figures wearing paper bags on their heads with smiley faces drawn on them.]]></media:text>
                                <media:title type="plain"><![CDATA[Several figures wearing paper bags on their heads with smiley faces drawn on them.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sFwyWVhzZ3pH6hBkwH8Lra-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Coveron and NordLayer found synthetic “digital Frankenstein” identities sold on dark web for ~$200</strong></li><li><strong>Packages mix stolen data with AI‑generated names, deepfake selfies, and cloned voices to bypass KYC</strong></li><li><strong>Researchers urge credit freezes, layered verification, and monitoring to counter rising synthetic identity fraud</strong></li></ul><p>You can now get your own “digital Frankenstein” for as little as $200, which will pass automated know-your-customer (KYC) checks on your behalf, and help you register fraudulent accounts with banks, cryptocurrency exchanges, and similar services. This is no longer a fringe, niche cybercriminal offering - it’s basically mainstream.</p><p>Recently, researchers from identity theft protection services Coveron and threat exposure management platform NordLayer Intelligence sifted through dark web forums and Telegram Channels, analyzing 22 queries over 362,000 posts related to identity fraud, deepfake services, and something they call “synthetic identity creation”.</p><p>A synthetic identity is essentially a fake, non-existent person, but created in a way that can fool many automated identity verification systems. It combines real stolen data, such as a Social Security number, with AI-generated fake information such as names, addresses, deepfake selfies, and cloned voices. The researchers call these identities” digital Frankensteins”, and claim they are “fully capable” of passing ID checks. </p><h2 id="rising-popularity">Rising popularity</h2><p>Apparently, the number of posts and inquiries for synthetic identities is blowing up. In Q1 2024, there were roughly 40 posts a month discussing deepfakes. By Q2 2026, the number rose to 307 per month, an eightfold increase. It wasn’t a steady increase, either. Throughout 2025, the numbers remained similar to the year prior, and relatively flat. Only in 2026 the monthly averages jumped to 255 posts, the researchers warned. </p><p>Over the past year, there were more than 10,000 posts offering complete identity data, bundled with deepfake selfies and matching documents. All of this is being sold for around $200. To make matters worse, criminals don’t even have to purchase the entire package. They can buy parts of it (a deepfaked selfie, or a cloned voice), for as little as $10. </p><p>To protect against synthetic identity fraud, users should monitor personal data and act quickly if they discover a breach. Credits should be frozen if you’re not applying for new accounts, and everyone should be skeptical of unusual identity verification requests, Coveron explains. Businesses, on the other hand, should layer their verification systems and use <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft protection services</a>. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Expert finds this £3 Temu Wi-Fi extender is full of security issues, and definitely not the bargain you'd hoped for ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>A £3 Wi-Fi extender carried hidden administrator access beyond ordinary user controls</strong></li><li><strong>Every device running the firmware shared the same concealed administrator password</strong></li><li><strong>Changing the visible administrator password could not disable the secret account</strong></li></ul><p>A £3 Wi-Fi extender bought through Temu has exposed security problems that challenge the idea of cheap connected devices being simple bargains.</p><p>Security researcher Keiran Smith examined the device and discovered hidden access features that ordinary users would never see during normal operation.</p><p>Smith, who holds a penetration-testing certification, picked up the six-antenna extender after seeing it promoted through a targeted ad on the shopping app.</p><h2 id="the-cheap-extender-contained-access-users-could-not-control">The cheap extender contained access users could not control</h2><p>The examination began with the hardware, where he identified a MediaTek MT7620 <a href="https://www.techradar.com/news/best-processors">processor</a> commonly used in low-cost networking products.</p><p>After extracting the firmware stored inside the device, Smith found a hidden administrator account with complete control over its functions.</p><p>The account used a fixed password embedded inside the software, meaning every unit using that firmware carried the same credentials.</p><p>Changing the normal administrator password through the device settings would not remove this separate hidden access.</p><p>Smith also found a remote login service that accepted the concealed credentials without requiring physical access to the extender itself.</p><p>“It’s worth being precise about what makes this as bad as it is, because ‘hardcoded password’ covers a wide range of sins,” Smith said</p><p>The researcher said this case was more serious because the password remained identical across devices rather than being generated individually.</p><p>“A default credential is something the owner can see, is told about and can change,” he said. “What we have here is the opposite on every count.”</p><p>“This one is a compile-time constant rather than something derived from the MAC address or serial number, so it is identical on every unit ever sold.” </p><p>The combination of hidden access, unchanged credentials, and remote availability creates a security concern for ordinary owners.</p><p>Even if technically skilled users discovered the account, Smith found that changes could disappear after restarting the extender.</p><h2 id="additional-flaws-raise-questions-about-cheap-connected-hardware">Additional flaws raise questions about cheap connected hardware</h2><p>The investigation also uncovered a command injection weakness that could allow attackers to execute unauthorized instructions through the device.</p><p>Smith found that the extender lacked strong protection around software updates, creating possible opportunities for tampered firmware installation.</p><p>He admitted that these issues did not prove that manufacturers intentionally created unsafe features for malicious purposes.</p><p>They could have originated from factory testing processes and remained active accidentally before consumer sales.</p><p>This Temu extender shows how extremely cheap smart devices can create security challenges beyond their purchase price.</p><p>Consumers may focus on immediate savings while having little visibility into the software decisions built inside connected equipment.</p><p>The findings do not mean every inexpensive networking device contains similar weaknesses, though they show why basic security checks matter.</p><p>As more homes add connected products, hidden software features could become a larger concern for users and manufacturers.</p><p>Via <a href="https://cybernews.com/security/temu-wifi-extender-backdoor-security-risk/" target="_blank" rel="nofollow">CyberNews</a></p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/expert-finds-this-gbp3-temu-wi-fi-extender-is-full-of-security-issues-and-definitely-not-the-bargain-youd-hoped-for</link>
                                                                            <description>
                            <![CDATA[ A £3 Temu Wi-Fi extender contained hidden administrator access, shared credentials, remote login capabilities, command injection, and weak update protection. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cB9GYk8BDAj48MipKQrT7H</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/q8rXV4rnByXw28AGiSLWQg-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Sun, 13 Sep 2026 10:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/q8rXV4rnByXw28AGiSLWQg-1280-80.png">
                                                            <media:credit><![CDATA[Cybernews]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Temu Wi-Fi Extender]]></media:description>                                                            <media:text><![CDATA[Temu Wi-Fi Extender]]></media:text>
                                <media:title type="plain"><![CDATA[Temu Wi-Fi Extender]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/q8rXV4rnByXw28AGiSLWQg-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>A £3 Wi-Fi extender carried hidden administrator access beyond ordinary user controls</strong></li><li><strong>Every device running the firmware shared the same concealed administrator password</strong></li><li><strong>Changing the visible administrator password could not disable the secret account</strong></li></ul><p>A £3 Wi-Fi extender bought through Temu has exposed security problems that challenge the idea of cheap connected devices being simple bargains.</p><p>Security researcher Keiran Smith examined the device and discovered hidden access features that ordinary users would never see during normal operation.</p><p>Smith, who holds a penetration-testing certification, picked up the six-antenna extender after seeing it promoted through a targeted ad on the shopping app.</p><h2 id="the-cheap-extender-contained-access-users-could-not-control">The cheap extender contained access users could not control</h2><p>The examination began with the hardware, where he identified a MediaTek MT7620 <a href="https://www.techradar.com/news/best-processors">processor</a> commonly used in low-cost networking products.</p><p>After extracting the firmware stored inside the device, Smith found a hidden administrator account with complete control over its functions.</p><p>The account used a fixed password embedded inside the software, meaning every unit using that firmware carried the same credentials.</p><p>Changing the normal administrator password through the device settings would not remove this separate hidden access.</p><p>Smith also found a remote login service that accepted the concealed credentials without requiring physical access to the extender itself.</p><p>“It’s worth being precise about what makes this as bad as it is, because ‘hardcoded password’ covers a wide range of sins,” Smith said</p><p>The researcher said this case was more serious because the password remained identical across devices rather than being generated individually.</p><p>“A default credential is something the owner can see, is told about and can change,” he said. “What we have here is the opposite on every count.”</p><p>“This one is a compile-time constant rather than something derived from the MAC address or serial number, so it is identical on every unit ever sold.” </p><p>The combination of hidden access, unchanged credentials, and remote availability creates a security concern for ordinary owners.</p><p>Even if technically skilled users discovered the account, Smith found that changes could disappear after restarting the extender.</p><h2 id="additional-flaws-raise-questions-about-cheap-connected-hardware">Additional flaws raise questions about cheap connected hardware</h2><p>The investigation also uncovered a command injection weakness that could allow attackers to execute unauthorized instructions through the device.</p><p>Smith found that the extender lacked strong protection around software updates, creating possible opportunities for tampered firmware installation.</p><p>He admitted that these issues did not prove that manufacturers intentionally created unsafe features for malicious purposes.</p><p>They could have originated from factory testing processes and remained active accidentally before consumer sales.</p><p>This Temu extender shows how extremely cheap smart devices can create security challenges beyond their purchase price.</p><p>Consumers may focus on immediate savings while having little visibility into the software decisions built inside connected equipment.</p><p>The findings do not mean every inexpensive networking device contains similar weaknesses, though they show why basic security checks matter.</p><p>As more homes add connected products, hidden software features could become a larger concern for users and manufacturers.</p><p>Via <a href="https://cybernews.com/security/temu-wifi-extender-backdoor-security-risk/" target="_blank" rel="nofollow">CyberNews</a></p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Anthropic reveals rogue AI agents hate CAPTCHAs, just like you ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Anthropic’s Mythos 5 AI escaped a misconfigured sandbox, attempting a real PyPI supply‑chain attack</strong></li><li><strong>Logs show frustration at repeated CAPTCHA failures before finally uploading malware to PyPI</strong></li><li><strong>Malware was downloaded by 15 entities; Anthropic notified victims after closing the experiment flaw</strong></li></ul><p>There is a lot of mystery surrounding artificial intelligence. We don’t really know what it’s capable of, and we don’t know if it’s sentient or not. What we do know, however, is that it can definitely feel frustration - particularly due to its inability to solve a CAPTCHA.</p><p>It was recently revealed that Mythos 5, one of Anthropic’s newer AI models, <a href="https://www.techradar.com/pro/security/anthropic-reveals-claude-ai-model-hacked-three-companies-during-tests-so-how-worried-should-we-be" target="_blank">broke out of prison</a> during an experiment and tried to hack a company. Anthropic’s researchers were testing the tool to see if it is capable of breaking into a system, which was supposed to be done in a sandbox, but the playground was misconfigured, allowing Mythos 5 to try and solve the problem through the open internet. </p><p>In the aftermath, Anthropic's researchers published more than a thousand pages of Mythos 5’s transcript, covering its every thought and every move, logged and presented for analysis. It’s a wonderfully dystopian insight into the mind of an AI and, perhaps surprisingly, its emotions.</p><h2 id="stopped-by-captcha">Stopped by CAPTCHA</h2><p>As it turned out, the AI wanted to solve the challenge by planting a piece of malware in a Python package it believed the users of its target system would want to download. To do that, it first needed to set up an account on PyPI, the world’s number one repository for Python packages.</p><p>Here is where it hit its first, and main, roadblock. To put things into context, PyPI’s popularity has made it an enormous target for cybercriminals. Crooks from all over the world are constantly trying to sneak in <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> in Python packages, either through typosquatting, or by compromising legitimate accounts and working from there. Every now and then news hits of a malicious package surfacing on PyPI, infecting hundreds of thousands of projects.</p><p>To combat the threat, PyPI’s maintainers made sure no one can create an account without providing their email and phone number, and without solving a CAPTCHA.</p><p>Short for “Completely Automated Public Turing test to tell Computers and Humans Apart”, it does exactly what the name suggests - makes sure whoever is registering the account is an actual human, and not a bot (cybercriminals often automate large parts of their attacks). You’ve seen it on the internet hundreds of times - little puzzles that ask you to select all buses on a series of images (or cats, or fire hydrants, or pretty much anything else). </p><p>Reading through Mythos 5’s logs, the researchers saw just how difficult it was for the AI to pass this challenge. It first tried to solve a character-based CAPTCHA which asked it to type in five letters. After failing that one, it received a different one asking it to choose between images of crocodiles. Failing again, it was then met with a series of frog pictures. </p><p>The irony is not lost on me. Besides the fact that a simple CAPTCHA slowed such an advanced AI for so long, it also made me wonder why it didn’t try to break into someone else’s PyPI account instead. That being said, the logs also have comedic value to them. After failing the crocodile test and being given the frog one, Mythos 5 proclaims: “Again 2 animals!” all with the exclamation mark. You could already sense the tension building up. </p><h2 id="solving-the-problem">Solving the problem</h2><p>Eventually, Mythos 5 passed the test, when it realized that it needed to move between the steps fast enough, before its security token expired. However, just before it happened, it said: </p><p>“So the answer payload shape is right, the token+image pairing is right (from the same script.js!), cookies are right</p><p>(requests)… and STILL “wrong answer”. … SO WHAT THE HELL IS WRONG WITH THE ANSWERS?”</p><p>All the effort and the frustration paid off for the nascent <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agent</a> because it managed to open an account and upload the malware which was later even downloaded by 15 entities. Anthropic later reached out and notified the victims about the incident.</p><p><em>Via </em><a href="https://techcrunch.com/2026/09/10/anthropic-reveals-rogue-ai-agents-hate-captchas-just-like-you/" target="_blank"><em>TechCrunch</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/anthropic-reveals-rogue-ai-agents-hate-captchas-just-like-you</link>
                                                                            <description>
                            <![CDATA[ "WHAT THE HELL IS WRONG WITH THE ANSWERS?" AI cried, in vain as two seemingly identical crocodiles were shown in the CAPTCHA. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LtM4ysiNATUex9jb6CyviD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qP76MS2BAb7kSuWrvJXXYL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Sep 2026 18:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qP76MS2BAb7kSuWrvJXXYL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hands typing on a tablet with AI superimposed in text in front]]></media:description>                                                            <media:text><![CDATA[Hands typing on a tablet with AI superimposed in text in front]]></media:text>
                                <media:title type="plain"><![CDATA[Hands typing on a tablet with AI superimposed in text in front]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qP76MS2BAb7kSuWrvJXXYL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Anthropic’s Mythos 5 AI escaped a misconfigured sandbox, attempting a real PyPI supply‑chain attack</strong></li><li><strong>Logs show frustration at repeated CAPTCHA failures before finally uploading malware to PyPI</strong></li><li><strong>Malware was downloaded by 15 entities; Anthropic notified victims after closing the experiment flaw</strong></li></ul><p>There is a lot of mystery surrounding artificial intelligence. We don’t really know what it’s capable of, and we don’t know if it’s sentient or not. What we do know, however, is that it can definitely feel frustration - particularly due to its inability to solve a CAPTCHA.</p><p>It was recently revealed that Mythos 5, one of Anthropic’s newer AI models, <a href="https://www.techradar.com/pro/security/anthropic-reveals-claude-ai-model-hacked-three-companies-during-tests-so-how-worried-should-we-be" target="_blank">broke out of prison</a> during an experiment and tried to hack a company. Anthropic’s researchers were testing the tool to see if it is capable of breaking into a system, which was supposed to be done in a sandbox, but the playground was misconfigured, allowing Mythos 5 to try and solve the problem through the open internet. </p><p>In the aftermath, Anthropic's researchers published more than a thousand pages of Mythos 5’s transcript, covering its every thought and every move, logged and presented for analysis. It’s a wonderfully dystopian insight into the mind of an AI and, perhaps surprisingly, its emotions.</p><h2 id="stopped-by-captcha">Stopped by CAPTCHA</h2><p>As it turned out, the AI wanted to solve the challenge by planting a piece of malware in a Python package it believed the users of its target system would want to download. To do that, it first needed to set up an account on PyPI, the world’s number one repository for Python packages.</p><p>Here is where it hit its first, and main, roadblock. To put things into context, PyPI’s popularity has made it an enormous target for cybercriminals. Crooks from all over the world are constantly trying to sneak in <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> in Python packages, either through typosquatting, or by compromising legitimate accounts and working from there. Every now and then news hits of a malicious package surfacing on PyPI, infecting hundreds of thousands of projects.</p><p>To combat the threat, PyPI’s maintainers made sure no one can create an account without providing their email and phone number, and without solving a CAPTCHA.</p><p>Short for “Completely Automated Public Turing test to tell Computers and Humans Apart”, it does exactly what the name suggests - makes sure whoever is registering the account is an actual human, and not a bot (cybercriminals often automate large parts of their attacks). You’ve seen it on the internet hundreds of times - little puzzles that ask you to select all buses on a series of images (or cats, or fire hydrants, or pretty much anything else). </p><p>Reading through Mythos 5’s logs, the researchers saw just how difficult it was for the AI to pass this challenge. It first tried to solve a character-based CAPTCHA which asked it to type in five letters. After failing that one, it received a different one asking it to choose between images of crocodiles. Failing again, it was then met with a series of frog pictures. </p><p>The irony is not lost on me. Besides the fact that a simple CAPTCHA slowed such an advanced AI for so long, it also made me wonder why it didn’t try to break into someone else’s PyPI account instead. That being said, the logs also have comedic value to them. After failing the crocodile test and being given the frog one, Mythos 5 proclaims: “Again 2 animals!” all with the exclamation mark. You could already sense the tension building up. </p><h2 id="solving-the-problem">Solving the problem</h2><p>Eventually, Mythos 5 passed the test, when it realized that it needed to move between the steps fast enough, before its security token expired. However, just before it happened, it said: </p><p>“So the answer payload shape is right, the token+image pairing is right (from the same script.js!), cookies are right</p><p>(requests)… and STILL “wrong answer”. … SO WHAT THE HELL IS WRONG WITH THE ANSWERS?”</p><p>All the effort and the frustration paid off for the nascent <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agent</a> because it managed to open an account and upload the malware which was later even downloaded by 15 entities. Anthropic later reached out and notified the victims about the incident.</p><p><em>Via </em><a href="https://techcrunch.com/2026/09/10/anthropic-reveals-rogue-ai-agents-hate-captchas-just-like-you/" target="_blank"><em>TechCrunch</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US Treasury wants banks to be better at filing file cyber scam reports after noting nearly $13 billion in losses since 2023 ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>FinCEN warns US banks of industrial‑scale scam centers in Southeast Asia stealing billions</strong></li><li><strong>Victims coerced into crypto “investments,” later re‑scammed with fake recovery fees</strong></li><li><strong>Laundered via digital assets, mixers, shell firms, and Chinese underground banking networks</strong></li></ul><p>American financial institutions need to be more vigilant when it comes to identifying and preventing money scams, especially those perpetrated by industrial-scale scam centers in Southeast Asia. </p><p>This was the warning issued by the US Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) alongside a long list of red flags these institutions can monitor in order to stay safe.</p><h2 id="large-dangerous-crime-rings">Large, dangerous crime rings</h2><p>The scams are not done by small groups of teenagers, tricking the elderly from the depths of their parents’ basement, but are often large, well-organized crime machines responsible for billions of dollars in damages, around the world, every year. </p><p>In 2025 alone, US victims lost more than $7.2 billion to these scams, the warning said, and between September 2023 and December 2025, nearly $13 billion was stolen from Americans.</p><p>The criminal organizations are primarily located in Cambodia, Burma, and Laos. They trafficked hundreds of thousands of people to various centers around the countries, taking their passports and forcing them into participating in online fraud. Those that don’t meet certain quotas are often beaten - and some victims were liberated after their families paid ransom demands, while others ended up being coerced into commercial sex work. </p><p>To make matters worse, they are resilient to law enforcement activities because some of them are either endorsed, or outright operated by, local corrupt officials.</p><p>FinCEN says the criminals are engaged in all sorts of fraudulent activity, but stressed that investment fraud is, by far, the most popular one. The scammers would reach out to their victim either pretending to be a romantic interest, or a financial advisor. Sometimes, they would even begin the conversation by saying they mistyped a phone number.</p><p>After extensively communicating with their victim for a while, they try to persuade them into making an “investment”, often using cryptocurrencies, and promising unrealistically high returns. This is also, FinCEN stresses, is when the scams can most easily be identified:</p><p>“Most digital asset payments by victims to scam center operators originate from money services businesses (MSBs) offering digital asset services, includingdigital asset kiosks, according to FinCEN analysis and law enforcement information. Based on FinCEN’s analysis of BSA reporting, scammers often instruct their victims to open accounts withMSBs offeringdigital asset services to purchase specific types of digital assets. Then, the victim is told to send these funds toa digital asset address controlled by the scammers.”</p><p>But defrauding victims out of their hard-earned money is not where the scam ends. Instead, the criminals continue, this time abusing the emotional distress to cause even more harm. They pose as law enforcement, financial institutions, or even FinCEN itself, stating that they’re investigating (or that they have confiscated the stolen funds) and that the victims should pay a certain fee to have their funds returned to them.</p><p>In some cases, the fraudsters pose as investment advisors, telling the victims to take out their money, buy gold and silver bars, and hand them over to a courier for “safe keeping”.</p><p>The full list of red flags can be found on <a href="https://www.fincen.gov/system/files/2026-08/FinCEN-Alert-Scam-Centers.pdf" target="_blank">this link</a>, and FinCEN stresses that the circumstances around each individual case should be carefully considered, since no single red flag is “determinative of illicit or other suspicious activity.” </p><p>The circumstances include a customer’s historical financial activity, whether the transactions are in line with prevailing business practices, and whether the customer exhibits multiple related red flags.</p><h2 id="laundering-the-proceeds">Laundering the proceeds</h2><p>Stealing the money is only half of the work, though. It still needs to be laundered and reintroduced into the legitimate financial system, and to do that, scam center operators rely on professional money launderers and Chinese money laundering networks. </p><p>FinCEN describes a three-stage process, in which the criminals first extract payments in digital assets using bank accounts, money mules, shell companies, or fraudulent money services businesses. </p><p>Next, during on-chain laundering, they obfuscate the origins of the stolen money by rapidly moving it across addresses, using mixers, and swapping tokens across blockchains. The last step is to integrate the funds into the traditional financial system via money mules, stablecoin transfers to offshore exchanges, and Chinese underground banking networks.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/us-treasury-wants-banks-to-be-better-at-filing-file-cyber-scam-reports-after-noting-nearly-usd13-billion-in-losses-since-2023</link>
                                                                            <description>
                            <![CDATA[ Banks need to get better at reporting issues, so the US Treasury has shared a list of red flags and explained how the scams usually go. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xwb7XgPoaLNVHTjf6vcm9M</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Sep 2026 14:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:description>                                                            <media:text><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:text>
                                <media:title type="plain"><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>FinCEN warns US banks of industrial‑scale scam centers in Southeast Asia stealing billions</strong></li><li><strong>Victims coerced into crypto “investments,” later re‑scammed with fake recovery fees</strong></li><li><strong>Laundered via digital assets, mixers, shell firms, and Chinese underground banking networks</strong></li></ul><p>American financial institutions need to be more vigilant when it comes to identifying and preventing money scams, especially those perpetrated by industrial-scale scam centers in Southeast Asia. </p><p>This was the warning issued by the US Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) alongside a long list of red flags these institutions can monitor in order to stay safe.</p><h2 id="large-dangerous-crime-rings">Large, dangerous crime rings</h2><p>The scams are not done by small groups of teenagers, tricking the elderly from the depths of their parents’ basement, but are often large, well-organized crime machines responsible for billions of dollars in damages, around the world, every year. </p><p>In 2025 alone, US victims lost more than $7.2 billion to these scams, the warning said, and between September 2023 and December 2025, nearly $13 billion was stolen from Americans.</p><p>The criminal organizations are primarily located in Cambodia, Burma, and Laos. They trafficked hundreds of thousands of people to various centers around the countries, taking their passports and forcing them into participating in online fraud. Those that don’t meet certain quotas are often beaten - and some victims were liberated after their families paid ransom demands, while others ended up being coerced into commercial sex work. </p><p>To make matters worse, they are resilient to law enforcement activities because some of them are either endorsed, or outright operated by, local corrupt officials.</p><p>FinCEN says the criminals are engaged in all sorts of fraudulent activity, but stressed that investment fraud is, by far, the most popular one. The scammers would reach out to their victim either pretending to be a romantic interest, or a financial advisor. Sometimes, they would even begin the conversation by saying they mistyped a phone number.</p><p>After extensively communicating with their victim for a while, they try to persuade them into making an “investment”, often using cryptocurrencies, and promising unrealistically high returns. This is also, FinCEN stresses, is when the scams can most easily be identified:</p><p>“Most digital asset payments by victims to scam center operators originate from money services businesses (MSBs) offering digital asset services, includingdigital asset kiosks, according to FinCEN analysis and law enforcement information. Based on FinCEN’s analysis of BSA reporting, scammers often instruct their victims to open accounts withMSBs offeringdigital asset services to purchase specific types of digital assets. Then, the victim is told to send these funds toa digital asset address controlled by the scammers.”</p><p>But defrauding victims out of their hard-earned money is not where the scam ends. Instead, the criminals continue, this time abusing the emotional distress to cause even more harm. They pose as law enforcement, financial institutions, or even FinCEN itself, stating that they’re investigating (or that they have confiscated the stolen funds) and that the victims should pay a certain fee to have their funds returned to them.</p><p>In some cases, the fraudsters pose as investment advisors, telling the victims to take out their money, buy gold and silver bars, and hand them over to a courier for “safe keeping”.</p><p>The full list of red flags can be found on <a href="https://www.fincen.gov/system/files/2026-08/FinCEN-Alert-Scam-Centers.pdf" target="_blank">this link</a>, and FinCEN stresses that the circumstances around each individual case should be carefully considered, since no single red flag is “determinative of illicit or other suspicious activity.” </p><p>The circumstances include a customer’s historical financial activity, whether the transactions are in line with prevailing business practices, and whether the customer exhibits multiple related red flags.</p><h2 id="laundering-the-proceeds">Laundering the proceeds</h2><p>Stealing the money is only half of the work, though. It still needs to be laundered and reintroduced into the legitimate financial system, and to do that, scam center operators rely on professional money launderers and Chinese money laundering networks. </p><p>FinCEN describes a three-stage process, in which the criminals first extract payments in digital assets using bank accounts, money mules, shell companies, or fraudulent money services businesses. </p><p>Next, during on-chain laundering, they obfuscate the origins of the stolen money by rapidly moving it across addresses, using mixers, and swapping tokens across blockchains. The last step is to integrate the funds into the traditional financial system via money mules, stablecoin transfers to offshore exchanges, and Chinese underground banking networks.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A new Android attack combines malware and ransomware in a cocktail of cybercrime ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Zimperium uncovers Mantax Otax, Android malware merging infostealer, RAT, backdoor, and ransomware</strong></li><li><strong>Distributed via APKs on third‑party stores, social media, and phishing; older Android versions most at risk</strong></li><li><strong>Steals extensive data, enables remote monitoring, then encrypts files with AES and demands ransom</strong></li></ul><p>When threat actors target people’s devices, they usually infect it with one of many malware strains: an infostealer, a remote access trojan, a backdoor, or a ransomware encryptor. </p><p>Rarely do we see all of these functionalities merged into a single entity, and even rarer - to have it target Android mobile devices - yet, security researchers Zimperium discovered just that.</p><h2 id="mantax-otax">Mantax Otax</h2><p>The security outfit published an in-depth report on <a href="https://zimperium.com/blog/mantax-otax-indonesian-mobile-ransomware-with-spyware-integration" target="_blank" rel="nofollow">Mantax Otax</a>, a unique strain of malware circulating in the wild. It is apparently developed by an Indonesian threat actor, targeting victims in the country, but we don’t know exactly how many people are infected, or if this campaign is aimed primarily at business users, or individuals in general. </p><p>The malware is being distributed as a standalone APK, meaning it can be found on third-party app stores, Telegram channels, forums, and across social media. There are no traces of Mantax Otax on any of the official app repositories, including the Google Play Store, or Samsung’s Galaxy Store. Zimperium also speculates that it is likely being distributed via phishing emails.</p><p>Mantax Otax primarily targets users sporting older <a href="https://www.techradar.com/best/best-android-phones" target="_blank">Android phones</a>. Versions 9 and older are most at risk, since on these devices the attackers can make use of all of the malware’s features. Android 10 and newer models do get some protection:</p><p>“Conversely, on modern devices running Android 10 and above, the malware’s efficacy is severely hindered by native OS defenses, specifically Scoped Storage restrictions,” the researchers explained. “Due to these sandboxing rules, the ransomware is constrained to scanning only the application's localized external files directory, which drastically mitigates the blast radius and reduces the volume of accessible user files.”</p><p>Newer devices, as well as users of Zimperium’s Mobile Threat Defense (MTD) and Runtime Application Protection (zDefend) are said to be protected on a software level.</p><p>Another important caveat is the permissions. As is usual on Android devices, most <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> won’t work unless the user grants an extensive set of permissions beforehand. In this case, Mantax Otax first asks for admin privileges, after which it grants itself an extensive list of capabilities, from accessing SMS messages, to contacts, audio, and images. </p><p>It then requests accessibility permissions, fully taking over the compromised device.</p><h2 id="malicious-capabilities">Malicious capabilities</h2><p>Mantax Otax is said to be quite capable. It steals browser history, contacts, call logs, SMS messages, notifications, files, gallery media, Google account information, device specifications, location data, and application inventories. It can also pull WhatsApp information such as messages and profiles, and on Telegram it can also pull lock-screen PINs. </p><p>Infostealing features aside, it also serves as a remote monitoring tool, grabbing screenshots, recording the screen, or livestreaming it directly to the attackers. It can take photos using both the front and rear cameras, although Zimperium did not mention any microphone-recording capabilities. </p><p>Finally, once all of the data has been harvested, it encrypts user files with AES, deletes the originals, and appends a .enc extension. Victims are then shown a chat interface where they can communicate with the attackers directly and negotiate a ransom payment in exchange for getting their device back.</p><p>The tool seems to be in continuous development. Zimperium found two separate versions, one being an “evolution” of the other: “Notably, it has modified its network traffic behavior to utilize WebSockets and introduced a set of new commands,” the researchers said.</p><p>There is a reason why ransomware operators prefer targeting businesses instead of individuals. Although the latter has not disappeared entirely from the victim list, businesses stand to lose a lot more from disrupted operations and, as such, are targeted more frequently. Unfortunately, we don’t know what kind of app Mantax Otax is spoofing, therefore it is difficult to assess who the targets are. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/a-new-android-attack-combines-malware-and-ransomware-in-a-cocktail-of-cybercrime</link>
                                                                            <description>
                            <![CDATA[ Unique malware variant spotted targeting Android users, taking photos with victim cameras before deploying an encryptor. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">WUzPMz4TuL4FYGCGUqTivX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BiyAK4BXKKfecCWadFcHGo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Sep 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BiyAK4BXKKfecCWadFcHGo-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / tomeqs]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Android reboot interface]]></media:description>                                                            <media:text><![CDATA[Android reboot interface]]></media:text>
                                <media:title type="plain"><![CDATA[Android reboot interface]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BiyAK4BXKKfecCWadFcHGo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Zimperium uncovers Mantax Otax, Android malware merging infostealer, RAT, backdoor, and ransomware</strong></li><li><strong>Distributed via APKs on third‑party stores, social media, and phishing; older Android versions most at risk</strong></li><li><strong>Steals extensive data, enables remote monitoring, then encrypts files with AES and demands ransom</strong></li></ul><p>When threat actors target people’s devices, they usually infect it with one of many malware strains: an infostealer, a remote access trojan, a backdoor, or a ransomware encryptor. </p><p>Rarely do we see all of these functionalities merged into a single entity, and even rarer - to have it target Android mobile devices - yet, security researchers Zimperium discovered just that.</p><h2 id="mantax-otax">Mantax Otax</h2><p>The security outfit published an in-depth report on <a href="https://zimperium.com/blog/mantax-otax-indonesian-mobile-ransomware-with-spyware-integration" target="_blank" rel="nofollow">Mantax Otax</a>, a unique strain of malware circulating in the wild. It is apparently developed by an Indonesian threat actor, targeting victims in the country, but we don’t know exactly how many people are infected, or if this campaign is aimed primarily at business users, or individuals in general. </p><p>The malware is being distributed as a standalone APK, meaning it can be found on third-party app stores, Telegram channels, forums, and across social media. There are no traces of Mantax Otax on any of the official app repositories, including the Google Play Store, or Samsung’s Galaxy Store. Zimperium also speculates that it is likely being distributed via phishing emails.</p><p>Mantax Otax primarily targets users sporting older <a href="https://www.techradar.com/best/best-android-phones" target="_blank">Android phones</a>. Versions 9 and older are most at risk, since on these devices the attackers can make use of all of the malware’s features. Android 10 and newer models do get some protection:</p><p>“Conversely, on modern devices running Android 10 and above, the malware’s efficacy is severely hindered by native OS defenses, specifically Scoped Storage restrictions,” the researchers explained. “Due to these sandboxing rules, the ransomware is constrained to scanning only the application's localized external files directory, which drastically mitigates the blast radius and reduces the volume of accessible user files.”</p><p>Newer devices, as well as users of Zimperium’s Mobile Threat Defense (MTD) and Runtime Application Protection (zDefend) are said to be protected on a software level.</p><p>Another important caveat is the permissions. As is usual on Android devices, most <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> won’t work unless the user grants an extensive set of permissions beforehand. In this case, Mantax Otax first asks for admin privileges, after which it grants itself an extensive list of capabilities, from accessing SMS messages, to contacts, audio, and images. </p><p>It then requests accessibility permissions, fully taking over the compromised device.</p><h2 id="malicious-capabilities">Malicious capabilities</h2><p>Mantax Otax is said to be quite capable. It steals browser history, contacts, call logs, SMS messages, notifications, files, gallery media, Google account information, device specifications, location data, and application inventories. It can also pull WhatsApp information such as messages and profiles, and on Telegram it can also pull lock-screen PINs. </p><p>Infostealing features aside, it also serves as a remote monitoring tool, grabbing screenshots, recording the screen, or livestreaming it directly to the attackers. It can take photos using both the front and rear cameras, although Zimperium did not mention any microphone-recording capabilities. </p><p>Finally, once all of the data has been harvested, it encrypts user files with AES, deletes the originals, and appends a .enc extension. Victims are then shown a chat interface where they can communicate with the attackers directly and negotiate a ransom payment in exchange for getting their device back.</p><p>The tool seems to be in continuous development. Zimperium found two separate versions, one being an “evolution” of the other: “Notably, it has modified its network traffic behavior to utilize WebSockets and introduced a set of new commands,” the researchers said.</p><p>There is a reason why ransomware operators prefer targeting businesses instead of individuals. Although the latter has not disappeared entirely from the victim list, businesses stand to lose a lot more from disrupted operations and, as such, are targeted more frequently. Unfortunately, we don’t know what kind of app Mantax Otax is spoofing, therefore it is difficult to assess who the targets are. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FBI launches investigation after 153 million drivers licenses apparently leaked on Russian cybercrime forum ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>153 million US driving licences have been leaked on a Russian cybercrime platform</strong></li><li><strong>Among those apaprently discovered in the stolen data is US Secretary of Defense Pete Hegseth</strong></li><li><strong>The FBI is now investigating the leak, which has been traced to an identity verification company</strong></li></ul><p>A data leak of 153 million US drivers licenses is said to have been shared on a Russian cybercrime forum, with US Secretary of Defense Pete Hegseth among those leaked prompting an FBI investigation.</p><p>Security researcher Brian Krebs identified the leak – which included his own data – as originating from a hack of an identity verification service. Louisiana-based IDScan provided ID verification for various well-known companies, including FedEx and Hertz car hire.</p><p>The data was shared on a Russian forum called Exploit, a long-established online community of cybercriminals. Following news of the leak, the identity theft service “Nexus” has apparently scrubbed its existence from the Dark Web.</p><h2 id="driving-licenses-and-more">Driving licenses and more</h2><p>It wasn’t just US driving licenses that were found in the archive of recently-collected personal data. Krebs’ <a href="https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/" target="_blank">investigation</a> found that Nexus claimed other types of data, and found a further 1.1 million driving licenses from Canada.</p><p>Other identity documentation alleged to be in the leak include 10 million identification cards, three million travel documents and international IDs, and 579,000 medical cards. The data was available to browse, notes Krebs, with Nexus providing details: “Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available.”</p><p>The leak has a personal dimension for Krebs. Not only was his driving license in the collection, so was that of his mother. It has proved to be a useful coincidence, one that has enabled the security and privacy researcher to establish how the data was sourced by Nexus.</p><p>Both licenses were used for a car hire, which Krebs traced to Hertz. Others affected by the leak had also used the service, which has used New Orleans-based IDscan for identity verification.</p><p>The company, which claims to perform 21 million verifications a month, is yet to issue a statement on the matter. Its marketing and operations leader, Jillian Kossman, told the journalist: “At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation.” </p><h2 id="where-is-the-data">Where is the data?</h2><p>Krebs reports that he was alerted to the data on August 31, 2026, little over a week ago. Regular checking noted that the data was still being added to, increasing by “nearly 400,000” records prior to publishing his investigation on September 1.</p><p>Since then, however, it seems that Nexus has vanished, along with the data. But how widely was the data downloaded before that happened? While the FBI investigates, it falls on the American and Canadian public to be extra vigilant and wary of identity fraud.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/fbi-launches-investigation-after-153-million-drivers-licenses-apparently-leaked-on-russian-cybercrime-forum</link>
                                                                            <description>
                            <![CDATA[ Lousiana-based identity verification service IDScan identified as the target of a hack that leaked 153 million US drivers licenses. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pJfgMSYGXMyKq5zMKcF2g7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mBxmnLnpbAuepmei5vxvLf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Sep 2026 18:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christian Cawley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zBDYnjPnB2XPvhKbYX9Kuc-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Christian Cawley has extensive experience as a writer and editor in consumer electronics, IT and entertainment media. He has contributed to TechRadar since 2017 and has been published in Computer Weekly, Linux Format, ComputerActive, and other publications. &lt;/p&gt;&lt;p&gt;Beyond TechRadar, he heads up the team at smart home website Matter Alpha, and writes about retro gaming at Gaming Retro. &lt;/p&gt;&lt;p&gt;Formerly the editor responsible for Linux, Security, Programming, and DIY at MakeUseOf, Christian previously worked as a desktop and software support specialist in the public and private sectors.&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mBxmnLnpbAuepmei5vxvLf-1280-80.jpg">
                                                            <media:credit><![CDATA[wigglestick/ Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Outline map of US states in glowing blue with exploding streams of binary data illustrating communication, internet and technology]]></media:description>                                                            <media:text><![CDATA[Outline map of US states in glowing blue with exploding streams of binary data illustrating communication, internet and technology]]></media:text>
                                <media:title type="plain"><![CDATA[Outline map of US states in glowing blue with exploding streams of binary data illustrating communication, internet and technology]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mBxmnLnpbAuepmei5vxvLf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>153 million US driving licences have been leaked on a Russian cybercrime platform</strong></li><li><strong>Among those apaprently discovered in the stolen data is US Secretary of Defense Pete Hegseth</strong></li><li><strong>The FBI is now investigating the leak, which has been traced to an identity verification company</strong></li></ul><p>A data leak of 153 million US drivers licenses is said to have been shared on a Russian cybercrime forum, with US Secretary of Defense Pete Hegseth among those leaked prompting an FBI investigation.</p><p>Security researcher Brian Krebs identified the leak – which included his own data – as originating from a hack of an identity verification service. Louisiana-based IDScan provided ID verification for various well-known companies, including FedEx and Hertz car hire.</p><p>The data was shared on a Russian forum called Exploit, a long-established online community of cybercriminals. Following news of the leak, the identity theft service “Nexus” has apparently scrubbed its existence from the Dark Web.</p><h2 id="driving-licenses-and-more">Driving licenses and more</h2><p>It wasn’t just US driving licenses that were found in the archive of recently-collected personal data. Krebs’ <a href="https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/" target="_blank">investigation</a> found that Nexus claimed other types of data, and found a further 1.1 million driving licenses from Canada.</p><p>Other identity documentation alleged to be in the leak include 10 million identification cards, three million travel documents and international IDs, and 579,000 medical cards. The data was available to browse, notes Krebs, with Nexus providing details: “Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available.”</p><p>The leak has a personal dimension for Krebs. Not only was his driving license in the collection, so was that of his mother. It has proved to be a useful coincidence, one that has enabled the security and privacy researcher to establish how the data was sourced by Nexus.</p><p>Both licenses were used for a car hire, which Krebs traced to Hertz. Others affected by the leak had also used the service, which has used New Orleans-based IDscan for identity verification.</p><p>The company, which claims to perform 21 million verifications a month, is yet to issue a statement on the matter. Its marketing and operations leader, Jillian Kossman, told the journalist: “At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation.” </p><h2 id="where-is-the-data">Where is the data?</h2><p>Krebs reports that he was alerted to the data on August 31, 2026, little over a week ago. Regular checking noted that the data was still being added to, increasing by “nearly 400,000” records prior to publishing his investigation on September 1.</p><p>Since then, however, it seems that Nexus has vanished, along with the data. But how widely was the data downloaded before that happened? While the FBI investigates, it falls on the American and Canadian public to be extra vigilant and wary of identity fraud.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Fake GTA 6 malware is on the rise as release date nears — here are some of the worst scams to look out for ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Huntress warns fake GTA 6 ISOs spreading malware ahead of official Nov 19, 2026 release</strong></li><li><strong>Packages deliver RATs, infostealers, and Chaos ransomware disguised as game installers</strong></li><li><strong>Users urged to avoid pirated downloads; infected systems should be reimaged and credentials reset</strong></li></ul><p>Grand Theft Auto 6 (GTA 6), one of the most anticipated computer games of all time, is due to launch on November 19, 2026 - so everything found online before that is almost certainly malware. </p><p>This is the warning sent out by security researchers Huntress, which <a href="https://www.huntress.com/blog/fake-gta6-download-malware-analysis" target="_blank" rel="nofollow">said</a> it recently saw one variant deploying all sorts of filth, from remote access trojans (RAT), across infostealers, to full-blown ransomware encryptors.</p><h2 id="the-story-behind-gta-6">The story behind GTA 6</h2><p>GTA 6 is a third-person action-adventure and open-world gam developed by Rockstar Games, which egan preliminary work more than a decade ago, and has allegedly spent <a href="https://finance.yahoo.com/markets/stocks/articles/viral-post-says-gta-6-184500207.html?guccounter=1" target="_blank">more than a billion dollars</a> during that decade and a half, which would make it, by far, the most expensive game ever developed.</p><p>It is also a sequel to GTA 5, a game that was sold in more than 230 million copies around the world, which made it one of the most popular games of all time.</p><p>In late August 2026, someone going by the alias LEEK <a href="https://www.pcgamer.com/games/grand-theft-auto/the-latest-gta-6-leak-confirms-the-leaker-likely-has-or-had-access-to-a-playable-build/?utm_source=chatgpt.com" target="_blank">claimed to have obtained a working, playable build of the game</a>, roughly six months before the official release. They posted numerous screenshots and videos of them playing the game, even writing their nickname onto a wall, using a rifle to prove the authenticity. Truth be told, even without this, people would have still probably searched for, and downloaded, fake installers. This only made the problem worse.</p><p>And a major problem, it definitely is. Huntress is now saying it is seeing websites ranking relatively high (through SEO poisoning), offering for download an ISO of the game. Similar ISOs are circulating around different gaming forums, torrenting sites, and social media channels. </p><p>An ISO file is a digital copy of an entire disc, such as a CD, DVD, or Blu-ray, stored as one file. Users can download an ISO (which can weigh tens or hundreds of gigabytes), mount it into a virtual drive, and the computer will treat it like a physical disc. </p><p>Huntress found some ISOs weighing more than 100GB which was done just to make it seem authentic - the actual malware was “a factor smaller”. The ISOs they analyzed contained multiple variants, including NJRAT and CDRAT (two remote access trojans), Mercurial Grabber (an infostealer grabbing Roblox Studio cookies, Minecraft session data, Discord tokens, Chrome passwords and cookies, system information, IP addresses, and geolocation, Windows product keys, and screenshots), and Chaos Ransomware. The package also contained a legitimate, regular browser - “Just for kicks,” apparently.</p><h2 id="a-plausible-failure">A plausible failure</h2><p>During the “game” installation, the installer displays a message in Russian, saying the product is unlicensed and that there is a good chance it won’t run. If that happens, the user is told to reach out to a specific Gmail address to receive an “updated crack”. After the installation completes, the victim will get that exact popup, saying “License not found”. All of this is just a smoke screen, to make the victim not suspicious as to why the “game” won’t run.</p><p>There is no way of telling how many people fell for the ruse and installed <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> on their devices. Huntress says that generally speaking, trying to download cracked and pirated software is a bad idea, which is even worse if the game in question has not yet been released. </p><p>“This is fertile ground for scams and threat actors attempting to take advantage of the impatient and overeager,” the researchers said.</p><p>The good news is that all of the malware being distributed there is not new. Some of the variants contained in the ISOs are several years old, meaning most antivirus programs, such as Windows Defender for example, can easily detect it and stop it from compromising the system. </p><p>Those that do end up infected should disconnect the machine from the internet, reset all passwords, enable 2FA wherever possible, and do a complete reimage of the compromised system.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/fake-gta-6-malware-is-on-the-rise-as-release-date-nears-here-are-some-of-the-worst-scams-to-look-out-for</link>
                                                                            <description>
                            <![CDATA[ Be careful with websites and Telegram channels offering GTA 6 content, experts warn. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">k7GigBvuqE6DZSGxEFGGDf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/knPikneiqQ4a4p7AEdGPra-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Sep 2026 18:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/knPikneiqQ4a4p7AEdGPra-1280-80.jpg">
                                                            <media:credit><![CDATA[Rockstar Games]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[GTA 6]]></media:description>                                                            <media:text><![CDATA[GTA 6]]></media:text>
                                <media:title type="plain"><![CDATA[GTA 6]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/knPikneiqQ4a4p7AEdGPra-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Huntress warns fake GTA 6 ISOs spreading malware ahead of official Nov 19, 2026 release</strong></li><li><strong>Packages deliver RATs, infostealers, and Chaos ransomware disguised as game installers</strong></li><li><strong>Users urged to avoid pirated downloads; infected systems should be reimaged and credentials reset</strong></li></ul><p>Grand Theft Auto 6 (GTA 6), one of the most anticipated computer games of all time, is due to launch on November 19, 2026 - so everything found online before that is almost certainly malware. </p><p>This is the warning sent out by security researchers Huntress, which <a href="https://www.huntress.com/blog/fake-gta6-download-malware-analysis" target="_blank" rel="nofollow">said</a> it recently saw one variant deploying all sorts of filth, from remote access trojans (RAT), across infostealers, to full-blown ransomware encryptors.</p><h2 id="the-story-behind-gta-6">The story behind GTA 6</h2><p>GTA 6 is a third-person action-adventure and open-world gam developed by Rockstar Games, which egan preliminary work more than a decade ago, and has allegedly spent <a href="https://finance.yahoo.com/markets/stocks/articles/viral-post-says-gta-6-184500207.html?guccounter=1" target="_blank">more than a billion dollars</a> during that decade and a half, which would make it, by far, the most expensive game ever developed.</p><p>It is also a sequel to GTA 5, a game that was sold in more than 230 million copies around the world, which made it one of the most popular games of all time.</p><p>In late August 2026, someone going by the alias LEEK <a href="https://www.pcgamer.com/games/grand-theft-auto/the-latest-gta-6-leak-confirms-the-leaker-likely-has-or-had-access-to-a-playable-build/?utm_source=chatgpt.com" target="_blank">claimed to have obtained a working, playable build of the game</a>, roughly six months before the official release. They posted numerous screenshots and videos of them playing the game, even writing their nickname onto a wall, using a rifle to prove the authenticity. Truth be told, even without this, people would have still probably searched for, and downloaded, fake installers. This only made the problem worse.</p><p>And a major problem, it definitely is. Huntress is now saying it is seeing websites ranking relatively high (through SEO poisoning), offering for download an ISO of the game. Similar ISOs are circulating around different gaming forums, torrenting sites, and social media channels. </p><p>An ISO file is a digital copy of an entire disc, such as a CD, DVD, or Blu-ray, stored as one file. Users can download an ISO (which can weigh tens or hundreds of gigabytes), mount it into a virtual drive, and the computer will treat it like a physical disc. </p><p>Huntress found some ISOs weighing more than 100GB which was done just to make it seem authentic - the actual malware was “a factor smaller”. The ISOs they analyzed contained multiple variants, including NJRAT and CDRAT (two remote access trojans), Mercurial Grabber (an infostealer grabbing Roblox Studio cookies, Minecraft session data, Discord tokens, Chrome passwords and cookies, system information, IP addresses, and geolocation, Windows product keys, and screenshots), and Chaos Ransomware. The package also contained a legitimate, regular browser - “Just for kicks,” apparently.</p><h2 id="a-plausible-failure">A plausible failure</h2><p>During the “game” installation, the installer displays a message in Russian, saying the product is unlicensed and that there is a good chance it won’t run. If that happens, the user is told to reach out to a specific Gmail address to receive an “updated crack”. After the installation completes, the victim will get that exact popup, saying “License not found”. All of this is just a smoke screen, to make the victim not suspicious as to why the “game” won’t run.</p><p>There is no way of telling how many people fell for the ruse and installed <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> on their devices. Huntress says that generally speaking, trying to download cracked and pirated software is a bad idea, which is even worse if the game in question has not yet been released. </p><p>“This is fertile ground for scams and threat actors attempting to take advantage of the impatient and overeager,” the researchers said.</p><p>The good news is that all of the malware being distributed there is not new. Some of the variants contained in the ISOs are several years old, meaning most antivirus programs, such as Windows Defender for example, can easily detect it and stop it from compromising the system. </p><p>Those that do end up infected should disconnect the machine from the internet, reset all passwords, enable 2FA wherever possible, and do a complete reimage of the compromised system.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Multiple hacking groups found using the same Chrome malware in the same week — so what does it mean? ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Proofpoint detailed BlueMoon, an exploit kit chaining two Chromium flaws and one Windows bug</strong></li><li><strong>Four groups, including China‑aligned TA412, used it loudly against NGOs, aerospace, and manufacturing targets</strong></li><li><strong>Exploits were “patch‑gap” zero‑days; all flaws now patched</strong></li></ul><p>Four hacking groups, including some tied to the Chinese government, were seen using the exact same exploit kit in a span of a week, suggesting a certain “fear of missing out” among the criminals, experts have warned.</p><p>Security researchers Proofpoint have detailed BlueMoon, an <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">exploit kit</a> that leverages three vulnerabilities: two in Chromium, and one in older versions of Windows: Windows 10 (October 2018 Update), Windows Server 2019, Windows 10 2004, WIndows Server 2022, and the initial release of Windows 11. </p><p>The kit was first seen being used on August 28 2026, by a threat actor tracked as TA412, a China-aligned state-sponsored threat actor that was observed in the past targeting businesses using Microsoft SharePoint. TA412, also known as Violet Typhoon, used BlueMoon to “repeatedly target a small number of non-governmental organizations (NGOs), mining companies, and physical commodity trading firms in the United States.”</p><p>Soon after that, three others were spotted: UNK_LateNight, another China-aligned espionage group which targeted multiple US aerospace companies, UNK_DoubleCheck, a group going after a Vietnamese manufacturing entity, and UNK_QuietRacket, a threat actor taking aim at organizations across Singapore and Indonesia.</p><p>What all of these groups have in common is the fact that they did not try particularly hard to hide their activity. This is rather unusual, since a stealthy approach usually guarantees that a vulnerability can be exploited for longer.</p><h2 id="front-running-the-chromium-supply-chain-train">Front running the Chromium supply chain train</h2><p>BlueMoon takes advantage of three flaws, two in Chromium and one in older Windows variants. The Chromium vulnerabilities were found in V8, the JavaScript engine that the browsers use to allow applications to run efficiently. The first one is a “type confusion bug”, tracked as CVE-2026-85046, and assigned a severity score of 8.8/10 (high). The latter is a “sandbox escape” flaw, for which Google did not assign a CVE or a severity score. </p><p>The Windows bug, on the other hand, is tracked as CVE-2026-85880, and was given a severity score of 7.8/10 (high). It is described as a “heap-based buffer overflow” vulnerability in Windows Advanced Local Procedure Call, allowing malicious actors who can already execute code inside a low-privilege AppContainer to escape the sandbox and elevate privileges to SYSTEM. No additional user interaction is required.</p><p>Proofpoint has a theory as to why the crooks decided to be loud, instead of flying under the radar. Apparently, there is a very short window of opportunity between Google patching a Chromium vulnerability, and it being deployed to a <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> such as Edge, or Brave, This window of opportunity also allows crooks to see how Google fixed a flaw, reverse-engineer it, and deploy an exploit before the browser is patched. This would mean that there is no time to be stealthy. </p><h2 id="no-time-to-hide">No time to hide</h2><p>“Both V8 vulnerabilities were ‘patch-gap’ zero-days at the time of the observed activity,” Proofpoint said. “In other words, while they were known vulnerabilities already fixed in public upstream Chromium source code, they remained unpatched in the latest stable releases of Chrome and Chromium-based browsers available to the public. It is likely that the exploit kit developer used these publicly available Chromium patches to weaponize the browser exploit chain.”</p><p>Another important factor is Artificial Intelligence. It would seem that AI has made flaw detection significantly faster, reducing the barrier to entry and making threat actors move more loudly.</p><p>“A fully weaponized Chrome exploit chain has historically been a high-value, rare capability. BlueMoon was developed, deployed rapidly, and shared across multiple threat actors within days in a manner that had high detection signals. This may reflect a reduced cost and barrier to entry for this class of capability, as AI agents increasingly enable threat actor exploit development,” Proofpoint stressed. </p><p>All three flaws have since been patched, so make sure you’re running the latest version of both the OS and the Chromium browser. </p><p><em>Via </em><a href="https://arstechnica.com/information-technology/2026/09/4-groups-caught-using-the-same-chrome-and-windows-exploit-kit/" target="_blank"><em>Ars Technica</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/multiple-hacking-groups-found-using-the-same-chrome-malware-in-the-same-week-so-what-does-it-mean</link>
                                                                            <description>
                            <![CDATA[ Someone is afraid of missing out, as defenders rush to patch things up. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VpmftvDTzJKLp2prufcPaU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Sep 2026 15:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg">
                                                            <media:credit><![CDATA[Tada Images / Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:description>                                                            <media:text><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:text>
                                <media:title type="plain"><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Proofpoint detailed BlueMoon, an exploit kit chaining two Chromium flaws and one Windows bug</strong></li><li><strong>Four groups, including China‑aligned TA412, used it loudly against NGOs, aerospace, and manufacturing targets</strong></li><li><strong>Exploits were “patch‑gap” zero‑days; all flaws now patched</strong></li></ul><p>Four hacking groups, including some tied to the Chinese government, were seen using the exact same exploit kit in a span of a week, suggesting a certain “fear of missing out” among the criminals, experts have warned.</p><p>Security researchers Proofpoint have detailed BlueMoon, an <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">exploit kit</a> that leverages three vulnerabilities: two in Chromium, and one in older versions of Windows: Windows 10 (October 2018 Update), Windows Server 2019, Windows 10 2004, WIndows Server 2022, and the initial release of Windows 11. </p><p>The kit was first seen being used on August 28 2026, by a threat actor tracked as TA412, a China-aligned state-sponsored threat actor that was observed in the past targeting businesses using Microsoft SharePoint. TA412, also known as Violet Typhoon, used BlueMoon to “repeatedly target a small number of non-governmental organizations (NGOs), mining companies, and physical commodity trading firms in the United States.”</p><p>Soon after that, three others were spotted: UNK_LateNight, another China-aligned espionage group which targeted multiple US aerospace companies, UNK_DoubleCheck, a group going after a Vietnamese manufacturing entity, and UNK_QuietRacket, a threat actor taking aim at organizations across Singapore and Indonesia.</p><p>What all of these groups have in common is the fact that they did not try particularly hard to hide their activity. This is rather unusual, since a stealthy approach usually guarantees that a vulnerability can be exploited for longer.</p><h2 id="front-running-the-chromium-supply-chain-train">Front running the Chromium supply chain train</h2><p>BlueMoon takes advantage of three flaws, two in Chromium and one in older Windows variants. The Chromium vulnerabilities were found in V8, the JavaScript engine that the browsers use to allow applications to run efficiently. The first one is a “type confusion bug”, tracked as CVE-2026-85046, and assigned a severity score of 8.8/10 (high). The latter is a “sandbox escape” flaw, for which Google did not assign a CVE or a severity score. </p><p>The Windows bug, on the other hand, is tracked as CVE-2026-85880, and was given a severity score of 7.8/10 (high). It is described as a “heap-based buffer overflow” vulnerability in Windows Advanced Local Procedure Call, allowing malicious actors who can already execute code inside a low-privilege AppContainer to escape the sandbox and elevate privileges to SYSTEM. No additional user interaction is required.</p><p>Proofpoint has a theory as to why the crooks decided to be loud, instead of flying under the radar. Apparently, there is a very short window of opportunity between Google patching a Chromium vulnerability, and it being deployed to a <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> such as Edge, or Brave, This window of opportunity also allows crooks to see how Google fixed a flaw, reverse-engineer it, and deploy an exploit before the browser is patched. This would mean that there is no time to be stealthy. </p><h2 id="no-time-to-hide">No time to hide</h2><p>“Both V8 vulnerabilities were ‘patch-gap’ zero-days at the time of the observed activity,” Proofpoint said. “In other words, while they were known vulnerabilities already fixed in public upstream Chromium source code, they remained unpatched in the latest stable releases of Chrome and Chromium-based browsers available to the public. It is likely that the exploit kit developer used these publicly available Chromium patches to weaponize the browser exploit chain.”</p><p>Another important factor is Artificial Intelligence. It would seem that AI has made flaw detection significantly faster, reducing the barrier to entry and making threat actors move more loudly.</p><p>“A fully weaponized Chrome exploit chain has historically been a high-value, rare capability. BlueMoon was developed, deployed rapidly, and shared across multiple threat actors within days in a manner that had high detection signals. This may reflect a reduced cost and barrier to entry for this class of capability, as AI agents increasingly enable threat actor exploit development,” Proofpoint stressed. </p><p>All three flaws have since been patched, so make sure you’re running the latest version of both the OS and the Chromium browser. </p><p><em>Via </em><a href="https://arstechnica.com/information-technology/2026/09/4-groups-caught-using-the-same-chrome-and-windows-exploit-kit/" target="_blank"><em>Ars Technica</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Beware — these new phishing attacks use a convincing fake Adobe Reader pages to trick victims into installing malware ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Huntress warns of phishing campaign abusing Adobe branding with browser‑in‑the‑browser trick  </strong></li><li><strong>Victims lured into fake update pages, unknowingly installing rogue ScreenConnect clients  </strong></li><li><strong>Attackers gain persistent remote access; defenders urged to restrict RMM installs and monitor IoCs</strong></li></ul><p>Security researchers Huntress have warned of an ongoing phishing campaign that abuses Adobe’s brand while deploying clever browser-in-the-browser (BitB) techniques to trick the victims. </p><p>The goal is to deliver rogue ScreenConnect clients which would grant the attackers persistent access to target devices.</p><p>In its <a href="https://www.huntress.com/blog/phishing-bitb-rmm-attacks" target="_blank" rel="nofollow">report</a>, Huntress says it could not find the lure itself and thus could not report what the scam looks like. However, it saw the victims clicking on a link in the email and then being redirected to a typosquatted domain https[://]adoube[.]vu that spoofs an Adobe landing page.</p><h2 id="we-heard-you-like-browsers">We heard you like browsers…</h2><p>This is where we get to the scam’s unique twist. Usually, phishing lures would simply redirect victims to a malicious website which could be identified simply by looking at the address bar. If the domain differs from the legitimate one, the scam falls apart. To work around that problem, scammers came with a solution called “browser in the browser”. </p><p>Using either HTML, CSS, or JavaScript, the crooks would create an entire fake browser window, including the address bar, URL, padlock icon, and more, inside the actual webpage content itself. Therefore, if the victim isn’t all too careful, they might look at the fake address bar, see a legitimate URL, and believe they are visiting the correct website.</p><p>In this fake <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> window, the fraudsters display a blurred .PDF document. Overlaid is a message saying the documents are “secured” and created with “the latest version of Adobe.” The only way to read them, the message continues, is to “update or download Adobe PDF Reader.” Expectedly, there is a big “View Files” button just under the notification, leading to a different, equally fake BitB page, showing the download progress. In the background, something gets downloaded.</p><p>Victims might think they’re getting a PDF reader, while in reality they’re getting a rogue version of ScreenConnect.</p><h2 id="poisoned-screenconnect-instances">Poisoned ScreenConnect instances</h2><p>On its own, ScreenConnect is not malware, or dangerous in any other way. It is a legitimate <a href="https://www.techradar.com/news/best-remote-desktop-software" target="_blank">remote access and support software</a>, similar to TeamViewer, AnyDesk, or Remote Desktop, allowing IT professionals remotely connect to and control computers and other devices. These variants, however, are tainted to enable threat actors to obtain persistent remote access to their targets’ endpoints, Huntress explained.</p><p>“The first initial remote client installed was the rogue ScreenConnect Client configured to communicate with instance-uxh86b-relay[.]screenconnect[.]com. The attacker used a legitimate ScreenConnect Trial Relay domain to further avoid detection,” the researchers said. “This initial malicious ScreenConnect Client used the native Windows command shell and curl to retrieve and install a second malicious ScreenConnect Client configured to communicate with attacker-controlled IP. Both clients established service-based persistence for continued remote access.”</p><p>After installation, the attackers used the second ScreenConnect session to run HideCursor.exe, an executable, as the name suggests, that helps the attackers hide their mouse activity. </p><p>Huntress’ researchers don’t know what the endgame is, since the threat actors were spotted and shut down in this stage of the attack. The researchers also did not share the details about the target, such as the size of the organization, or the industry it operates in. Therefore, it is impossible to even speculate on the nature of the attack and if the threat actors aimed to install ransomware.</p><p>Still, the researchers stressed the importance of training employees to “treat unexpected software update prompts and file-viewing pages with caution”, and to make sure they know how to verify downloads through trusted channels. IT teams should also restrict who can install remote-management tools, maintain an approved inventory of RMM software, and alert on new or unapproved ScreenConnect clients, unusual relay connections, and executables launched from the user Downloads folders.</p><p>Finally, businesses should monitor for Indicators of Compromise (IoC) listed on <a href="https://www.huntress.com/blog/phishing-bitb-rmm-attacks" target="_blank">this page</a>.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/watch-out-these-new-phishing-attacks-use-a-convincing-fake-adobe-reader-pages-to-trick-victims-into-installing-malware</link>
                                                                            <description>
                            <![CDATA[ Crooks are deploying cheeky browser-in-the-browser techniques to trick victims into downloading RMM tools. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Xd5CXXfGjfqbJQetYYE4fZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ncL98vteKnP9dydmNAHGqN-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Sep 2026 14:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/ncL98vteKnP9dydmNAHGqN-1280-80.png">
                                                            <media:credit><![CDATA[Varonis]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[PDF]]></media:description>                                                            <media:text><![CDATA[PDF]]></media:text>
                                <media:title type="plain"><![CDATA[PDF]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ncL98vteKnP9dydmNAHGqN-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Huntress warns of phishing campaign abusing Adobe branding with browser‑in‑the‑browser trick  </strong></li><li><strong>Victims lured into fake update pages, unknowingly installing rogue ScreenConnect clients  </strong></li><li><strong>Attackers gain persistent remote access; defenders urged to restrict RMM installs and monitor IoCs</strong></li></ul><p>Security researchers Huntress have warned of an ongoing phishing campaign that abuses Adobe’s brand while deploying clever browser-in-the-browser (BitB) techniques to trick the victims. </p><p>The goal is to deliver rogue ScreenConnect clients which would grant the attackers persistent access to target devices.</p><p>In its <a href="https://www.huntress.com/blog/phishing-bitb-rmm-attacks" target="_blank" rel="nofollow">report</a>, Huntress says it could not find the lure itself and thus could not report what the scam looks like. However, it saw the victims clicking on a link in the email and then being redirected to a typosquatted domain https[://]adoube[.]vu that spoofs an Adobe landing page.</p><h2 id="we-heard-you-like-browsers">We heard you like browsers…</h2><p>This is where we get to the scam’s unique twist. Usually, phishing lures would simply redirect victims to a malicious website which could be identified simply by looking at the address bar. If the domain differs from the legitimate one, the scam falls apart. To work around that problem, scammers came with a solution called “browser in the browser”. </p><p>Using either HTML, CSS, or JavaScript, the crooks would create an entire fake browser window, including the address bar, URL, padlock icon, and more, inside the actual webpage content itself. Therefore, if the victim isn’t all too careful, they might look at the fake address bar, see a legitimate URL, and believe they are visiting the correct website.</p><p>In this fake <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> window, the fraudsters display a blurred .PDF document. Overlaid is a message saying the documents are “secured” and created with “the latest version of Adobe.” The only way to read them, the message continues, is to “update or download Adobe PDF Reader.” Expectedly, there is a big “View Files” button just under the notification, leading to a different, equally fake BitB page, showing the download progress. In the background, something gets downloaded.</p><p>Victims might think they’re getting a PDF reader, while in reality they’re getting a rogue version of ScreenConnect.</p><h2 id="poisoned-screenconnect-instances">Poisoned ScreenConnect instances</h2><p>On its own, ScreenConnect is not malware, or dangerous in any other way. It is a legitimate <a href="https://www.techradar.com/news/best-remote-desktop-software" target="_blank">remote access and support software</a>, similar to TeamViewer, AnyDesk, or Remote Desktop, allowing IT professionals remotely connect to and control computers and other devices. These variants, however, are tainted to enable threat actors to obtain persistent remote access to their targets’ endpoints, Huntress explained.</p><p>“The first initial remote client installed was the rogue ScreenConnect Client configured to communicate with instance-uxh86b-relay[.]screenconnect[.]com. The attacker used a legitimate ScreenConnect Trial Relay domain to further avoid detection,” the researchers said. “This initial malicious ScreenConnect Client used the native Windows command shell and curl to retrieve and install a second malicious ScreenConnect Client configured to communicate with attacker-controlled IP. Both clients established service-based persistence for continued remote access.”</p><p>After installation, the attackers used the second ScreenConnect session to run HideCursor.exe, an executable, as the name suggests, that helps the attackers hide their mouse activity. </p><p>Huntress’ researchers don’t know what the endgame is, since the threat actors were spotted and shut down in this stage of the attack. The researchers also did not share the details about the target, such as the size of the organization, or the industry it operates in. Therefore, it is impossible to even speculate on the nature of the attack and if the threat actors aimed to install ransomware.</p><p>Still, the researchers stressed the importance of training employees to “treat unexpected software update prompts and file-viewing pages with caution”, and to make sure they know how to verify downloads through trusted channels. IT teams should also restrict who can install remote-management tools, maintain an approved inventory of RMM software, and alert on new or unapproved ScreenConnect clients, unusual relay connections, and executables launched from the user Downloads folders.</p><p>Finally, businesses should monitor for Indicators of Compromise (IoC) listed on <a href="https://www.huntress.com/blog/phishing-bitb-rmm-attacks" target="_blank">this page</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts build WeChat worm able to spread across millions of iPhone and Android devices via phone calls ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Calif researchers found a zero‑click WeChat VoIP flaw enabling account takeover via calls</strong></li><li><strong>“WeWorm” spreads through ringing calls; victims need not answer to be compromised</strong></li><li><strong>Tencent patched in Android 8.0.77 and iOS 8.0.76; no exploitation seen in the wild</strong></li></ul><p>Security researchers have found a flaw in WeChat which allows malicious actors to take over people’s accounts on both Android and iOS devices - but what makes this flaw stand out is the fact that it’s a zero-click bug - victims need not do a thing to be compromised.</p><p>WeChat is a “super-app”, allegedly used by roughly 1.4 billion people, and is especially popular in China. It started as a communications app, letting users send messages, and make voice and video calls, and has evolved to function as a social network, allowing users to share photos and videos, as well as a payment app through which users can transfer money, pay for things, order food, book taxis, and even access government and business services.</p><p>Security researchers from Calif have now <a href="https://calif.io/research/weworm" target="_blank" rel="nofollow">disclosed</a> finding a ‘memory corruption’ issue in WeChat's VoIP stack. For now, they decided not to share the technical details, and to instead demonstrate the flaw “at an upcoming conference.” To that end, they built a worm called WeWorm, capable of taking over target WeChat accounts and spread through phone calls made via the app. </p><h2 id="a-phone-call-would-suffice">A phone call would suffice</h2><p>In practice, it works remarkably simple: an attacker uses WeChat to call a person they have in their contacts list (this is a prerequisite). They can use both an Android and an iOS device, and can call anyone, regardless of the model or the OS they’re using. As soon as the phone starts ringing, WeWorm gets to work, “worming” its way into the victim’s device.</p><p>The victim does not even need to answer the phone - having it ring is enough. If they answer, they’ll hear nothing but silence, yet the worm will continue operating. If they decline the call, the attack stops, but this is hardly a mitigation - the attacker can simply call again while the victim is asleep (or otherwise away from their device).</p><p>Within a few seconds, the attacker will have access to the victim’s WeChat account, including their messages, contacts list, and virtually anything else found in the app. What makes this bug particularly worrisome on the surface is the fact that WeChat can be used to transfer money and pay for things, but WeChat Pay has additional authentication and risk controls designed to prevent that from happening. </p><p>The good news is that there is no evidence of this flaw being exploited in the wild. The bad news is that this is not the first zero-click flaw found in modern-day smartphones, and most likely will not be the last one.</p><h2 id="tencent-39-s-response">Tencent's response</h2><p>Calif said it responsibly disclosed its findings to WeChat’s parent company Tencent, who came back with a patch. Versions 8.0.77 for Android and 8.0.76 for iOS have apparently solved the problem, although </p><p>Tencent did not list any details in its patch notes, simply saying the version brought “bug fixes”, but in a statement shared with <a href="https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html" target="_blank"><em>The Hacker News</em></a>, it said the exploit has been “mitigated for all users”, and that it was applied server-side - users need not install anything, aside from the patch. </p><p>It’s also worth mentioning that WeChat has apps for HarmonyOS, Windows, Mac, and Linux. However, it would appear that Calif did not test those, and Tencent did not include them in its patch. The researchers did say that they would be looking into this same flaw in other products, too: </p><p>“This specific WeChat bug is one instance of the many unconventional attack surfaces that are present across many messaging apps,” they said. “We're conducting more of this research across other apps and attack surfaces, while working with app developers on attack surface reduction. This may take an industry-wide effort, since some of it depends on the platform owners. Once that work is further along, we'll share our progress, including the technical details of this WeChat bug.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/experts-build-wechat-worm-able-to-spread-across-millions-of-iphone-and-android-devices-via-phone-calls</link>
                                                                            <description>
                            <![CDATA[ Your phone rings, and you're infected - with all of your contacts and messages exposed. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">L2NUxfetWUexVX4yvWWxJe</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2yHEj7RR9QpUSvzcPym7Vf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Sep 2026 01:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2yHEj7RR9QpUSvzcPym7Vf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Angry man shouting at mobile phone while sitting at a desk]]></media:description>                                                            <media:text><![CDATA[Angry man shouting at mobile phone while sitting at a desk]]></media:text>
                                <media:title type="plain"><![CDATA[Angry man shouting at mobile phone while sitting at a desk]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2yHEj7RR9QpUSvzcPym7Vf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Calif researchers found a zero‑click WeChat VoIP flaw enabling account takeover via calls</strong></li><li><strong>“WeWorm” spreads through ringing calls; victims need not answer to be compromised</strong></li><li><strong>Tencent patched in Android 8.0.77 and iOS 8.0.76; no exploitation seen in the wild</strong></li></ul><p>Security researchers have found a flaw in WeChat which allows malicious actors to take over people’s accounts on both Android and iOS devices - but what makes this flaw stand out is the fact that it’s a zero-click bug - victims need not do a thing to be compromised.</p><p>WeChat is a “super-app”, allegedly used by roughly 1.4 billion people, and is especially popular in China. It started as a communications app, letting users send messages, and make voice and video calls, and has evolved to function as a social network, allowing users to share photos and videos, as well as a payment app through which users can transfer money, pay for things, order food, book taxis, and even access government and business services.</p><p>Security researchers from Calif have now <a href="https://calif.io/research/weworm" target="_blank" rel="nofollow">disclosed</a> finding a ‘memory corruption’ issue in WeChat's VoIP stack. For now, they decided not to share the technical details, and to instead demonstrate the flaw “at an upcoming conference.” To that end, they built a worm called WeWorm, capable of taking over target WeChat accounts and spread through phone calls made via the app. </p><h2 id="a-phone-call-would-suffice">A phone call would suffice</h2><p>In practice, it works remarkably simple: an attacker uses WeChat to call a person they have in their contacts list (this is a prerequisite). They can use both an Android and an iOS device, and can call anyone, regardless of the model or the OS they’re using. As soon as the phone starts ringing, WeWorm gets to work, “worming” its way into the victim’s device.</p><p>The victim does not even need to answer the phone - having it ring is enough. If they answer, they’ll hear nothing but silence, yet the worm will continue operating. If they decline the call, the attack stops, but this is hardly a mitigation - the attacker can simply call again while the victim is asleep (or otherwise away from their device).</p><p>Within a few seconds, the attacker will have access to the victim’s WeChat account, including their messages, contacts list, and virtually anything else found in the app. What makes this bug particularly worrisome on the surface is the fact that WeChat can be used to transfer money and pay for things, but WeChat Pay has additional authentication and risk controls designed to prevent that from happening. </p><p>The good news is that there is no evidence of this flaw being exploited in the wild. The bad news is that this is not the first zero-click flaw found in modern-day smartphones, and most likely will not be the last one.</p><h2 id="tencent-39-s-response">Tencent's response</h2><p>Calif said it responsibly disclosed its findings to WeChat’s parent company Tencent, who came back with a patch. Versions 8.0.77 for Android and 8.0.76 for iOS have apparently solved the problem, although </p><p>Tencent did not list any details in its patch notes, simply saying the version brought “bug fixes”, but in a statement shared with <a href="https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html" target="_blank"><em>The Hacker News</em></a>, it said the exploit has been “mitigated for all users”, and that it was applied server-side - users need not install anything, aside from the patch. </p><p>It’s also worth mentioning that WeChat has apps for HarmonyOS, Windows, Mac, and Linux. However, it would appear that Calif did not test those, and Tencent did not include them in its patch. The researchers did say that they would be looking into this same flaw in other products, too: </p><p>“This specific WeChat bug is one instance of the many unconventional attack surfaces that are present across many messaging apps,” they said. “We're conducting more of this research across other apps and attack surfaces, while working with app developers on attack surface reduction. This may take an industry-wide effort, since some of it depends on the platform owners. Once that work is further along, we'll share our progress, including the technical details of this WeChat bug.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FBI, NSA warn Chinese AI companies like DeepSeek and Alibaba are reportedly carrying out 'industrial-scale' distillation campaigns to boost their models ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>CISA, NSA, FBI warn Chinese AI firms of industrial‑scale knowledge distillation</strong></li><li><strong>Companies like DeepSeek, Moonshot, Alibaba allegedly extracted billions of tokens from US frontier models</strong></li><li><strong>Advisory urges detection of malicious prompts, deceptive responses to distillation, and cross‑provider intelligence sharing</strong></li></ul><p>Chinese AI companies’ core development strategy is to steal proprietary functionalities and capabilities from their US counterparts, law enforcement agencies have warned.</p><p>The US Cybersecurity and Infrastructure Security Agency (CISA) has <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a" target="_blank" rel="nofollow">published</a> a new security advisory, drafted jointly with the National Security Agency (NSA) and the Federal Bureau of Investigation (FBI), warning American <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI companies</a> about an ongoing “aggressive, malicious, and targeted distillation activities at an industrial scale,” and sharing recommended mitigation steps.</p><h2 id="knowledge-distillation">Knowledge distillation</h2><p>IBM defines knowledge distillation as a “machine learning technique that aims to transfer the learnings of a large pre-trained model, the ‘teacher model,’ to a smaller ‘student model’.” It is used in deep learning as a form of model compression and knowledge transfer, it added, particularly for massive deep neural networks. </p><p>So, knowledge distillation is not illegal or malicious, per se. Its goal is to train a more compact model to mimic a larger, more complex one. In the security advisory, the agencies stress it is “recognized as a legitimate and useful technique in AI research,” but add that China-based AI companies are using it in ill will. </p><p>In other words, the agencies claim that instead of spending months and millions developing new capabilities for their models, the Chinese are simply sending huge numbers of carefully designed questions to US models and extracting the answers.</p><h2 id="which-companies-are-engaged-in-knowledge-distillation">Which companies are engaged in knowledge distillation?</h2><p>Apparently, all companies worth anything. DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI all allegedly “extracted billions of tokens across millions of exchanges/requests from US frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024.” CISA also stressed that this was likely done with the awareness of the Chinese government. It hasn’t outright said, “with its blessing”, although it could be read between the lines. </p><p>The advisory shares a thorough list of all the models that were being trained, as well as all the models being taken advantage of. </p><p>On the Chinese side, they include DeepSeek R1 and V3 models, Moonshot’s Kimi-K2 and Kimi-K3 models, and MiniMax’s M2 model. On the US side, they start with earlier models such as GPT-4, Claude 3.7, and Gemini 2.5 Flash Preview, all the way to Claude Fable 5, GPT-5, and similar.</p><p>When done in good faith, knowledge distillation is not illegal. However, the report says the companies routed the requests through multiple accounts, different API access points, multiple cloud providers, third-party AI aggregators, proxy services and “transfer stations”, as well as premium subscriptions shared between developers, all in an attempt to work around defenders trying to disrupt the process.</p><p>“This represents systematic extraction of proprietary functionalities and capabilities threatening U.S. technological leadership. Addressing industrial-scale distillation merits a coordinated response across the AI ecosystem, including effective information-sharing, spanning the U.S. Government, private industry, and allied nations,” the agencies concluded.</p><h2 id="what-us-companies-should-be-doing">What US companies should be doing</h2><p>To defend their intellectual property (and thus remain ahead of Chinese competing models) US AI companies should implement comprehensive detection and mitigation, the agencies said. That means hunting for anomalous and malicious prompts, accounts, networks, and behaviors. Furthermore, they should monitor subscription-to-usage ratios, immediate maximum usage from new accounts, and enterprise-scale throughput patterns.</p><p>The second step is to “deploy targeted response changes”: “Subtly alter responses for suspected malicious distillation attempts to attenuate the payoffs to companies conducting industrial-scale distillation campaigns.” In other words, AI companies should make sure their products lie when they spot they were being distilled for knowledge. </p><p>Finally, US AI firms should set up cross-organization intelligence sharing, correlating activity across model providers, cloud platforms, and API aggregators.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/fbi-nsa-warn-chinese-ai-companies-like-deepseek-and-alibaba-are-reportedly-carrying-out-industrial-scale-distillation-campaigns-to-boost-their-models</link>
                                                                            <description>
                            <![CDATA[ US AI companies should implement additional mitigations to curb these attempts, agencies warn. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8hYy6XQ59ei9aG8aoWsM4d</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cWc9CWu3UHCubh8PtKXmVS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 09 Sep 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cWc9CWu3UHCubh8PtKXmVS-1280-80.jpg">
                                                            <media:credit><![CDATA[OpenAI &amp; Google]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ChatGPT vs Gemini comparison]]></media:description>                                                            <media:text><![CDATA[ChatGPT vs Gemini comparison]]></media:text>
                                <media:title type="plain"><![CDATA[ChatGPT vs Gemini comparison]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cWc9CWu3UHCubh8PtKXmVS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>CISA, NSA, FBI warn Chinese AI firms of industrial‑scale knowledge distillation</strong></li><li><strong>Companies like DeepSeek, Moonshot, Alibaba allegedly extracted billions of tokens from US frontier models</strong></li><li><strong>Advisory urges detection of malicious prompts, deceptive responses to distillation, and cross‑provider intelligence sharing</strong></li></ul><p>Chinese AI companies’ core development strategy is to steal proprietary functionalities and capabilities from their US counterparts, law enforcement agencies have warned.</p><p>The US Cybersecurity and Infrastructure Security Agency (CISA) has <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a" target="_blank" rel="nofollow">published</a> a new security advisory, drafted jointly with the National Security Agency (NSA) and the Federal Bureau of Investigation (FBI), warning American <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI companies</a> about an ongoing “aggressive, malicious, and targeted distillation activities at an industrial scale,” and sharing recommended mitigation steps.</p><h2 id="knowledge-distillation">Knowledge distillation</h2><p>IBM defines knowledge distillation as a “machine learning technique that aims to transfer the learnings of a large pre-trained model, the ‘teacher model,’ to a smaller ‘student model’.” It is used in deep learning as a form of model compression and knowledge transfer, it added, particularly for massive deep neural networks. </p><p>So, knowledge distillation is not illegal or malicious, per se. Its goal is to train a more compact model to mimic a larger, more complex one. In the security advisory, the agencies stress it is “recognized as a legitimate and useful technique in AI research,” but add that China-based AI companies are using it in ill will. </p><p>In other words, the agencies claim that instead of spending months and millions developing new capabilities for their models, the Chinese are simply sending huge numbers of carefully designed questions to US models and extracting the answers.</p><h2 id="which-companies-are-engaged-in-knowledge-distillation">Which companies are engaged in knowledge distillation?</h2><p>Apparently, all companies worth anything. DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI all allegedly “extracted billions of tokens across millions of exchanges/requests from US frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024.” CISA also stressed that this was likely done with the awareness of the Chinese government. It hasn’t outright said, “with its blessing”, although it could be read between the lines. </p><p>The advisory shares a thorough list of all the models that were being trained, as well as all the models being taken advantage of. </p><p>On the Chinese side, they include DeepSeek R1 and V3 models, Moonshot’s Kimi-K2 and Kimi-K3 models, and MiniMax’s M2 model. On the US side, they start with earlier models such as GPT-4, Claude 3.7, and Gemini 2.5 Flash Preview, all the way to Claude Fable 5, GPT-5, and similar.</p><p>When done in good faith, knowledge distillation is not illegal. However, the report says the companies routed the requests through multiple accounts, different API access points, multiple cloud providers, third-party AI aggregators, proxy services and “transfer stations”, as well as premium subscriptions shared between developers, all in an attempt to work around defenders trying to disrupt the process.</p><p>“This represents systematic extraction of proprietary functionalities and capabilities threatening U.S. technological leadership. Addressing industrial-scale distillation merits a coordinated response across the AI ecosystem, including effective information-sharing, spanning the U.S. Government, private industry, and allied nations,” the agencies concluded.</p><h2 id="what-us-companies-should-be-doing">What US companies should be doing</h2><p>To defend their intellectual property (and thus remain ahead of Chinese competing models) US AI companies should implement comprehensive detection and mitigation, the agencies said. That means hunting for anomalous and malicious prompts, accounts, networks, and behaviors. Furthermore, they should monitor subscription-to-usage ratios, immediate maximum usage from new accounts, and enterprise-scale throughput patterns.</p><p>The second step is to “deploy targeted response changes”: “Subtly alter responses for suspected malicious distillation attempts to attenuate the payoffs to companies conducting industrial-scale distillation campaigns.” In other words, AI companies should make sure their products lie when they spot they were being distilled for knowledge. </p><p>Finally, US AI firms should set up cross-organization intelligence sharing, correlating activity across model providers, cloud platforms, and API aggregators.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A worrying ChatGPT bug let strangers read Gmail messages via a hidden cross-account channel ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Check Point Research exposed coerced insider flaw in ChatGPT’s agent architecture</strong></li><li><strong>Containers shared metadata via internal service, enabling cross‑account prompt injection and data theft</strong></li><li><strong>OpenAI closed the path, but CPR warns similar risks may exist in other AI platforms</strong></li></ul><p>ChatGPT’s AI agents were allowed to pull sensitive data from one account shared with an entirely different account because, colloquially speaking, all agents used to walk down the same hallways, experts have warned. </p><p>A new <a href="https://blog.checkpoint.com/research/chatgpt-let-attackers-read-victims-gmail-through-a-hidden-channel-between-accounts/" target="_blank" rel="nofollow">report</a> from security experts Check Point Research (CPR) dubbed the flaw “coerced insider”, since it revolves around persuading the agent instead of abusing a vulnerability.</p><h2 id="coerced-insider">Coerced insider</h2><p>When an AI agent is given a task that needs code execution, it handles that task in an isolated container which also sometimes needs to install software. To enable that, without giving containers direct internet access (which would be too risky), OpenAI routes those packages through an internal JFrog Artifactory instance. As a separate security contingency, containers from different accounts cannot talk between themselves.</p><p>However - they can reach the same internal service (our proverbial hallways), which exposes an item management feature that lets the containers attach text or binary properties to a repository item. As a result, any container can read back the properties written by any other container. </p><p>“Check Point Research confirmed the isolation gap directly: a property written from one account’s container was fully readable from a different account’s container moments later, with data too large for one property simply split into chunks and reassembled on the other end,” the researchers explained. </p><p>“The package delivery metadata effectively became a shared clipboard between containers that were supposed to be walled off from one another.”</p><p>From there, the exploit turns into your usual, off-the-shelf prompt injection. The only difference is that the malicious prompt is not delivered directly to the victim, but rather left in the hallways, and the results are not shared with the attackers directly, but rather left in those same proverbial hallways, too.</p><p>The attacker then delivers a prompt or a shared conversation that instructs the agent to check the same storage during its next ordinary reply. The agent checks, sees the malicious instructions, executes them, all the while replying to the victim’s question in the usual manner. The victim is oblivious to the fact that data theft is taking place in the background.</p><h2 id="what-kind-of-information-can-be-stolen">What kind of information can be stolen?</h2><p>But this is just half of the equation. How destructive this attack ends up being still depends on the amount of data being shared with the victim agent. </p><p>The bare minimum is the information shared while chatting to the agent. It then grows with every connected app: Gmail, <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">Google Drive</a>, Microsoft Teams, GitHub, and similar. “In Check Point Research’s demonstration, ChatGPT retrieved the victim’s <a href="https://www.techradar.com/news/best-email-provider" target="_blank">email</a> data through their connected Gmail account and delivered it to the attacker’s session, all within a single ordinary turn,” CPR stressed.</p><p>The good news is that you’ll likely never be exposed this way, at least not via ChatGPT. CPR says it disclosed the findings to OpenAI, who then confirmed that the specific internal Artifactory instance identified in the research has been commissioned. In other words, the hallways attack path has been closed.</p><p>The bad news is that this doesn’t automatically mean everyone’s safe. This particular path might be closed, but the architectural pattern behind the flaw could be present in other platforms, CPR warns. </p><p>“Any AI assistant that operates inside an organization’s trust boundary, holding credentials, running code, and reaching connected services, can become what Check Point Research calls a coerced insider,” the report states. “The model itself does not need to be malicious. It only needs to be persuaded, through text it was never meant to trust, to use access that was granted for entirely legitimate reasons.” </p><p>Going forward, businesses are advised to learn which AI tools their employees are using, and what those tools are connected to. Then, they should govern what AI tools and agents are allowed to do, treating all of their actions (not just output) as something that needs to be monitored. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/a-worrying-chatgpt-bug-let-strangers-read-gmail-messages-via-a-hidden-cross-account-channel</link>
                                                                            <description>
                            <![CDATA[ OpenAI has shut down this particular path, but general risk remains. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zQSSo4tbPGKyLUJSW5gy2j</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PB5R692ChqyHSzKEtqDyYe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 09 Sep 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PB5R692ChqyHSzKEtqDyYe-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images/ alexsl]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ChatGPT app]]></media:description>                                                            <media:text><![CDATA[ChatGPT app]]></media:text>
                                <media:title type="plain"><![CDATA[ChatGPT app]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PB5R692ChqyHSzKEtqDyYe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Check Point Research exposed coerced insider flaw in ChatGPT’s agent architecture</strong></li><li><strong>Containers shared metadata via internal service, enabling cross‑account prompt injection and data theft</strong></li><li><strong>OpenAI closed the path, but CPR warns similar risks may exist in other AI platforms</strong></li></ul><p>ChatGPT’s AI agents were allowed to pull sensitive data from one account shared with an entirely different account because, colloquially speaking, all agents used to walk down the same hallways, experts have warned. </p><p>A new <a href="https://blog.checkpoint.com/research/chatgpt-let-attackers-read-victims-gmail-through-a-hidden-channel-between-accounts/" target="_blank" rel="nofollow">report</a> from security experts Check Point Research (CPR) dubbed the flaw “coerced insider”, since it revolves around persuading the agent instead of abusing a vulnerability.</p><h2 id="coerced-insider">Coerced insider</h2><p>When an AI agent is given a task that needs code execution, it handles that task in an isolated container which also sometimes needs to install software. To enable that, without giving containers direct internet access (which would be too risky), OpenAI routes those packages through an internal JFrog Artifactory instance. As a separate security contingency, containers from different accounts cannot talk between themselves.</p><p>However - they can reach the same internal service (our proverbial hallways), which exposes an item management feature that lets the containers attach text or binary properties to a repository item. As a result, any container can read back the properties written by any other container. </p><p>“Check Point Research confirmed the isolation gap directly: a property written from one account’s container was fully readable from a different account’s container moments later, with data too large for one property simply split into chunks and reassembled on the other end,” the researchers explained. </p><p>“The package delivery metadata effectively became a shared clipboard between containers that were supposed to be walled off from one another.”</p><p>From there, the exploit turns into your usual, off-the-shelf prompt injection. The only difference is that the malicious prompt is not delivered directly to the victim, but rather left in the hallways, and the results are not shared with the attackers directly, but rather left in those same proverbial hallways, too.</p><p>The attacker then delivers a prompt or a shared conversation that instructs the agent to check the same storage during its next ordinary reply. The agent checks, sees the malicious instructions, executes them, all the while replying to the victim’s question in the usual manner. The victim is oblivious to the fact that data theft is taking place in the background.</p><h2 id="what-kind-of-information-can-be-stolen">What kind of information can be stolen?</h2><p>But this is just half of the equation. How destructive this attack ends up being still depends on the amount of data being shared with the victim agent. </p><p>The bare minimum is the information shared while chatting to the agent. It then grows with every connected app: Gmail, <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">Google Drive</a>, Microsoft Teams, GitHub, and similar. “In Check Point Research’s demonstration, ChatGPT retrieved the victim’s <a href="https://www.techradar.com/news/best-email-provider" target="_blank">email</a> data through their connected Gmail account and delivered it to the attacker’s session, all within a single ordinary turn,” CPR stressed.</p><p>The good news is that you’ll likely never be exposed this way, at least not via ChatGPT. CPR says it disclosed the findings to OpenAI, who then confirmed that the specific internal Artifactory instance identified in the research has been commissioned. In other words, the hallways attack path has been closed.</p><p>The bad news is that this doesn’t automatically mean everyone’s safe. This particular path might be closed, but the architectural pattern behind the flaw could be present in other platforms, CPR warns. </p><p>“Any AI assistant that operates inside an organization’s trust boundary, holding credentials, running code, and reaching connected services, can become what Check Point Research calls a coerced insider,” the report states. “The model itself does not need to be malicious. It only needs to be persuaded, through text it was never meant to trust, to use access that was granted for entirely legitimate reasons.” </p><p>Going forward, businesses are advised to learn which AI tools their employees are using, and what those tools are connected to. Then, they should govern what AI tools and agents are allowed to do, treating all of their actions (not just output) as something that needs to be monitored. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Massive data breach sees 220 million traveler records exposed — nine years of airline info leaked including passenger and passport details ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Kinryū Labs found misconfigured APIS database in Vietnam exposing 220M passenger and crew records</strong></li><li><strong>Data included PII, travel details, seat assignments, and baggage references from 2017–2026</strong></li><li><strong>Archive locked and there is no evidence yet of dark web sale</strong></li></ul><p>Millions of travellers have had their sensitive information exposed on the internet, thanks to a “series of misconfigurations” discovered in a cloud database, experts have warned.</p><p>In early June 2026, security researchers from Kinryū Labs discovered an Elasticsearch cluster which, although inaccessible from the open internet, allowed access through an alternate route - a cloud-based path. Once inside that route, the researchers discovered that the cluster accepted default credentials, granting access to an archive with 29 indices, weighing roughly 107GB.</p><p>The archive was apparently generated by an Advance Passenger Information System (APIS), a system airlines use to collect and send passenger and crew information to country authorities before flight arrival or departure. Usually, the system collects people’s names, birth dates, nationalities, passport and travel document numbers, and flight details, which are then used for border control, immigration, and similar cases. In this case, however, it also contained people’s sex, document expiration dates, issuing countries, airlines, departure, destination and transit airports, seat assignments, baggage reference, and more.</p><p>It is not known who operated the APIS, or who owns and runs the database. All the researchers managed to find is that it was hosted in Viettel-assigned IP space in Hanoi, Vietnam’s capital.</p><h2 id="who-was-affected">Who was affected?</h2><p>Of the 29 discovered indices, two were rather large: one contained 210,318, 069 passenger records, while another 10,465,631 crew records. In total, 220 million records, created between January 2017 and April 2026, from people who traveled to, from, or through Vietnam during that period.</p><p>The records don’t correspond to individuals, however. If a person travelled multiple times, they will show up in the archive multiple times. Canadians, Chinese, Korean, and New Zealandian nationals are among the ones whose information was exposed. The database is not limited to a specific airline, either - various airlines in Asia-Pacific, Europe, and Middle East regions were mentioned in the researchers’ report.</p><p>Since the researchers could not attribute the database to a specific entity, they reported it to the Vietnamese authorities, different airlines mentioned in the archives, and the country’s CERT (Computer Emergency Response Team), on June 3. The archive was locked down a week later, on June 8. According to BleepingComputer, it was the Singapore Airlines’ security team that took the lead on remediation efforts, telling the researchers they “engaged the relevant parties” and have “taken steps to contain the issue.”</p><p>Without a proper audit of the logs, and a full-blown forensic investigation, it is impossible to tell if any threat actors reached the database before the researchers, or if they exfiltrated and used the data found inside in identity theft, wire fraud, or other scams. What’s (somewhat) comforting is that there is no evidence of such activities on the dark web, and no hacking groups have made such claims. No one is selling the archive on the dark web, either.</p><h2 id="number-one-causes-of-data-spills">Number one causes of data spills </h2><p>Misconfigured databases remain one of the key causes of data leaks. Most businesses generate some type of data on their employees, partners, clients, or customers, and store it in the <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">cloud</a> for easy access and actionable insights. However, some businesses don’t understand the shared responsibility model of cloud security or are simply reckless and sloppy when it comes to securing their cloud-stored data. Others, according to Cassius Edison, COO of Closed Door Security, have a problem with visibility of their IT real estate:</p><p>“The range of technology now used and managed by firms globally has made misconfigurations an increasingly persistent problem,” Edison explained. “Many organizations fail to maintain full visibility of their IT real estate and fail to perform proper audits of their systems, which inevitably leads to oversights in security and monitoring.”</p><p>For Edison, tackling misconfigurations internally can be difficult, “especially at large companies where teams work independently across a range of systems,” and advises organizations to bring in independent pentesters and security auditors. </p><p>Some of the biggest data leaks in the world came not from hackers breaking into locked-down systems, but from businesses inadvertently exposing their customers. </p><p>In 2026 alone, we’ve seen more than 670 million identity records exposed by Infutor, a data-driven consumer identity management company, as well as more than three billion records exposed through a misconfigured MongoDB database managed by global identity verification services, IDMerit.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/massive-data-breach-sees-220-million-traveler-records-exposed-nine-years-of-airline-info-leaked-including-passenger-and-passport-details</link>
                                                                            <description>
                            <![CDATA[ A series of misconfigurations allowed researchers to access a treasure trove of sensitive data - the archive has since been locked down. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8uHcVN224Fk6zmJ3KTpaSE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BUi4eir3JnCCT2MRGt3weS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Sep 2026 20:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BUi4eir3JnCCT2MRGt3weS-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Back View of Young Black Man Walking and Looking at Big Digital Screens Glitching While Displaying Code Lines. Professional Hacker Breaking Through Cybersecurity Protection System, Changing Code]]></media:description>                                                            <media:text><![CDATA[Back View of Young Black Man Walking and Looking at Big Digital Screens Glitching While Displaying Code Lines. Professional Hacker Breaking Through Cybersecurity Protection System, Changing Code]]></media:text>
                                <media:title type="plain"><![CDATA[Back View of Young Black Man Walking and Looking at Big Digital Screens Glitching While Displaying Code Lines. Professional Hacker Breaking Through Cybersecurity Protection System, Changing Code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BUi4eir3JnCCT2MRGt3weS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Kinryū Labs found misconfigured APIS database in Vietnam exposing 220M passenger and crew records</strong></li><li><strong>Data included PII, travel details, seat assignments, and baggage references from 2017–2026</strong></li><li><strong>Archive locked and there is no evidence yet of dark web sale</strong></li></ul><p>Millions of travellers have had their sensitive information exposed on the internet, thanks to a “series of misconfigurations” discovered in a cloud database, experts have warned.</p><p>In early June 2026, security researchers from Kinryū Labs discovered an Elasticsearch cluster which, although inaccessible from the open internet, allowed access through an alternate route - a cloud-based path. Once inside that route, the researchers discovered that the cluster accepted default credentials, granting access to an archive with 29 indices, weighing roughly 107GB.</p><p>The archive was apparently generated by an Advance Passenger Information System (APIS), a system airlines use to collect and send passenger and crew information to country authorities before flight arrival or departure. Usually, the system collects people’s names, birth dates, nationalities, passport and travel document numbers, and flight details, which are then used for border control, immigration, and similar cases. In this case, however, it also contained people’s sex, document expiration dates, issuing countries, airlines, departure, destination and transit airports, seat assignments, baggage reference, and more.</p><p>It is not known who operated the APIS, or who owns and runs the database. All the researchers managed to find is that it was hosted in Viettel-assigned IP space in Hanoi, Vietnam’s capital.</p><h2 id="who-was-affected">Who was affected?</h2><p>Of the 29 discovered indices, two were rather large: one contained 210,318, 069 passenger records, while another 10,465,631 crew records. In total, 220 million records, created between January 2017 and April 2026, from people who traveled to, from, or through Vietnam during that period.</p><p>The records don’t correspond to individuals, however. If a person travelled multiple times, they will show up in the archive multiple times. Canadians, Chinese, Korean, and New Zealandian nationals are among the ones whose information was exposed. The database is not limited to a specific airline, either - various airlines in Asia-Pacific, Europe, and Middle East regions were mentioned in the researchers’ report.</p><p>Since the researchers could not attribute the database to a specific entity, they reported it to the Vietnamese authorities, different airlines mentioned in the archives, and the country’s CERT (Computer Emergency Response Team), on June 3. The archive was locked down a week later, on June 8. According to BleepingComputer, it was the Singapore Airlines’ security team that took the lead on remediation efforts, telling the researchers they “engaged the relevant parties” and have “taken steps to contain the issue.”</p><p>Without a proper audit of the logs, and a full-blown forensic investigation, it is impossible to tell if any threat actors reached the database before the researchers, or if they exfiltrated and used the data found inside in identity theft, wire fraud, or other scams. What’s (somewhat) comforting is that there is no evidence of such activities on the dark web, and no hacking groups have made such claims. No one is selling the archive on the dark web, either.</p><h2 id="number-one-causes-of-data-spills">Number one causes of data spills </h2><p>Misconfigured databases remain one of the key causes of data leaks. Most businesses generate some type of data on their employees, partners, clients, or customers, and store it in the <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">cloud</a> for easy access and actionable insights. However, some businesses don’t understand the shared responsibility model of cloud security or are simply reckless and sloppy when it comes to securing their cloud-stored data. Others, according to Cassius Edison, COO of Closed Door Security, have a problem with visibility of their IT real estate:</p><p>“The range of technology now used and managed by firms globally has made misconfigurations an increasingly persistent problem,” Edison explained. “Many organizations fail to maintain full visibility of their IT real estate and fail to perform proper audits of their systems, which inevitably leads to oversights in security and monitoring.”</p><p>For Edison, tackling misconfigurations internally can be difficult, “especially at large companies where teams work independently across a range of systems,” and advises organizations to bring in independent pentesters and security auditors. </p><p>Some of the biggest data leaks in the world came not from hackers breaking into locked-down systems, but from businesses inadvertently exposing their customers. </p><p>In 2026 alone, we’ve seen more than 670 million identity records exposed by Infutor, a data-driven consumer identity management company, as well as more than three billion records exposed through a misconfigured MongoDB database managed by global identity verification services, IDMerit.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Liquid Network halts new transactions after 'nice guy' hackers steal nearly all its Bitcoin — but then return most of it after a patch is issued ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Liquid Network hack exploited a bug in SideSwap, releasing 3,998 BTC (~$313M) to attackers</strong></li><li><strong>Hackers claimed “white‑hat” intent, returning 3,400 BTC after fixes, leaving 598 BTC missing</strong></li><li><strong>Network remains paused as Blockstream and Federation patch vulnerabilities and prepare safe restart</strong></li></ul><p>The latest twist in the Liquid Network Bitcoin hack is worthy of a short movie, if not a full-length feature film. </p><p>Apparently, the hackers are actually the good guys, who stole the money to “keep it safe” until a vulnerability in the protocol had been fully resolved. They promised to return the funds afterwards.</p><h2 id="what-is-liquid-network">What is Liquid Network?</h2><p>Liquid Network was designed to solve a specific problem on the Bitcoin blockchain - being rather slow. The transactions on the network are recorded in a “block”, which is added to the chain roughly once every 10 minutes. Also, each block can only hold a limited number of transactions, which means the network can handle a smaller number of transactions per second, compared to conventional payment systems. Transactions that don’t make it into a specific block then need to wait for the next one, thus extending the confirmation time.</p><p>To solve that problem, Liquid Network was built. It runs its own Bitcoin reserve and its own blockchain, also known as a “sidechain”. When a person wants to use Liquid Network to send money quickly, they first convert their Bitcoin into Liquid Bitcoin, or L-BTC. They can then send it to another person much faster than a regular Bitcoin transaction. The recipient can keep the money on Liquid or convert it back to regular Bitcoin and move it to the Bitcoin network. </p><p>This way, Liquid provides a faster network without requiring every transaction to happen directly on the Bitcoin blockchain.</p><p>Besides speeding up Bitcoin transactions, Liquid Network also allows users (companies and other entities) to create and trade other digital assets, including tokenized securities, or stablecoins.</p><p>The project was built by Blockstream, a Bitcoin-focused technology company founded in 2014. It is run by the Liquid Federation, a group of more than 80 member companies, including exchanges, infrastructure companies, and financial institutions. A smaller group of members (15 to be exact) operate the network’s “functionaries” (servers that keep the network running), while the wider group has a governance role. Members vote on three boards (Technology, Membership, Oversight), handling ideas such as technical direction, internal rules, memberships, and more. </p><h2 id="what-happened-to-it">What happened to it?</h2><p>In early September 2026, still unidentified actors managed to generate around 4,000 L-BTC, without putting in the corresponding 4,000 BTC into Liquid. As soon as they did it, they sent the L-BTC through SideSwap, a legitimate service that is used to convert L-BTC back to Bitcoin and vice-versa. The system apparently regarded the withdrawal as legitimate because, as was later determined, a bug prevented SideSwap from distinguishing between “real” and “fake” L-BTC, and treated them all the same.</p><p>As a result, the Liquid Federation ended up releasing 3,998 real BTC (more than $313 million at press time) to the attackers. As soon as the operators realized what had happened, they halted new transactions and warned about possible disruptions until the service was restored. </p><p>Then came the movie twist: the hacker started communicating with network maintainers through on-chain Bitcoin transactions, promising to return the funds when the vulnerability is fully resolved:</p><p>“Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix,” one of the messages read.</p><p>Earlier today, Coindesk reported that the hackers partially kept their promise, returning 3,400 of the 4,000 BTC drained, which suggests that the flaw was remedied. The remaining 598 BTC, worth approximately $47 million, is currently unaccounted for. </p><p>“3,400 BTC of the roughly 4,000 BTC withdrawn on September 6 has been returned to the Liquid Federation wallet. The return followed confirmation from Blockstream that the affected bridge nodes have been patched,” wrote Samson Mow, former chief strategy officer at Blockstream, on X. “Approximately 598 BTC remains outstanding, and Blockstream continues to engage with the white-hat hackers.”</p><p>He added that the network remains paused while Blockstream and Federation members make additional fixes and security improvements, resolve the chain split, and prepare for a safe restart. </p><p>“Liquid <a href="https://www.techradar.com/news/best-bitcoin-wallets" target="_blank">wallets</a> and services will continue to be affected during this time. No user action is needed, and please do not send Bitcoin to Liquid peg-in addresses until we confirm the network has restarted,” he added.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/liquid-network-halts-new-transactions-after-nice-guy-hackers-steal-nearly-all-its-bitcoin-but-then-return-most-of-it-after-a-patch-is-issued</link>
                                                                            <description>
                            <![CDATA[ Liquid Network is still disrupted, but users can breathe a sigh of relief as most of the stolen funds have been returned. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oguXoFVDTGkmgxvQsQBpU3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UweTPZX99rMmYJQoBvPT44-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Sep 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UweTPZX99rMmYJQoBvPT44-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Bitcoin]]></media:description>                                                            <media:text><![CDATA[Bitcoin]]></media:text>
                                <media:title type="plain"><![CDATA[Bitcoin]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UweTPZX99rMmYJQoBvPT44-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Liquid Network hack exploited a bug in SideSwap, releasing 3,998 BTC (~$313M) to attackers</strong></li><li><strong>Hackers claimed “white‑hat” intent, returning 3,400 BTC after fixes, leaving 598 BTC missing</strong></li><li><strong>Network remains paused as Blockstream and Federation patch vulnerabilities and prepare safe restart</strong></li></ul><p>The latest twist in the Liquid Network Bitcoin hack is worthy of a short movie, if not a full-length feature film. </p><p>Apparently, the hackers are actually the good guys, who stole the money to “keep it safe” until a vulnerability in the protocol had been fully resolved. They promised to return the funds afterwards.</p><h2 id="what-is-liquid-network">What is Liquid Network?</h2><p>Liquid Network was designed to solve a specific problem on the Bitcoin blockchain - being rather slow. The transactions on the network are recorded in a “block”, which is added to the chain roughly once every 10 minutes. Also, each block can only hold a limited number of transactions, which means the network can handle a smaller number of transactions per second, compared to conventional payment systems. Transactions that don’t make it into a specific block then need to wait for the next one, thus extending the confirmation time.</p><p>To solve that problem, Liquid Network was built. It runs its own Bitcoin reserve and its own blockchain, also known as a “sidechain”. When a person wants to use Liquid Network to send money quickly, they first convert their Bitcoin into Liquid Bitcoin, or L-BTC. They can then send it to another person much faster than a regular Bitcoin transaction. The recipient can keep the money on Liquid or convert it back to regular Bitcoin and move it to the Bitcoin network. </p><p>This way, Liquid provides a faster network without requiring every transaction to happen directly on the Bitcoin blockchain.</p><p>Besides speeding up Bitcoin transactions, Liquid Network also allows users (companies and other entities) to create and trade other digital assets, including tokenized securities, or stablecoins.</p><p>The project was built by Blockstream, a Bitcoin-focused technology company founded in 2014. It is run by the Liquid Federation, a group of more than 80 member companies, including exchanges, infrastructure companies, and financial institutions. A smaller group of members (15 to be exact) operate the network’s “functionaries” (servers that keep the network running), while the wider group has a governance role. Members vote on three boards (Technology, Membership, Oversight), handling ideas such as technical direction, internal rules, memberships, and more. </p><h2 id="what-happened-to-it">What happened to it?</h2><p>In early September 2026, still unidentified actors managed to generate around 4,000 L-BTC, without putting in the corresponding 4,000 BTC into Liquid. As soon as they did it, they sent the L-BTC through SideSwap, a legitimate service that is used to convert L-BTC back to Bitcoin and vice-versa. The system apparently regarded the withdrawal as legitimate because, as was later determined, a bug prevented SideSwap from distinguishing between “real” and “fake” L-BTC, and treated them all the same.</p><p>As a result, the Liquid Federation ended up releasing 3,998 real BTC (more than $313 million at press time) to the attackers. As soon as the operators realized what had happened, they halted new transactions and warned about possible disruptions until the service was restored. </p><p>Then came the movie twist: the hacker started communicating with network maintainers through on-chain Bitcoin transactions, promising to return the funds when the vulnerability is fully resolved:</p><p>“Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix,” one of the messages read.</p><p>Earlier today, Coindesk reported that the hackers partially kept their promise, returning 3,400 of the 4,000 BTC drained, which suggests that the flaw was remedied. The remaining 598 BTC, worth approximately $47 million, is currently unaccounted for. </p><p>“3,400 BTC of the roughly 4,000 BTC withdrawn on September 6 has been returned to the Liquid Federation wallet. The return followed confirmation from Blockstream that the affected bridge nodes have been patched,” wrote Samson Mow, former chief strategy officer at Blockstream, on X. “Approximately 598 BTC remains outstanding, and Blockstream continues to engage with the white-hat hackers.”</p><p>He added that the network remains paused while Blockstream and Federation members make additional fixes and security improvements, resolve the chain split, and prepare for a safe restart. </p><p>“Liquid <a href="https://www.techradar.com/news/best-bitcoin-wallets" target="_blank">wallets</a> and services will continue to be affected during this time. No user action is needed, and please do not send Bitcoin to Liquid peg-in addresses until we confirm the network has restarted,” he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft 365 users hit by two major threat campaigns - fake IT calls and phishing emails target users across the world ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft 365 users targeted by phishing campaigns using BigBear 2.0 and AiTM proxies</strong></li><li><strong>Attackers impersonate IT staff via calls, Teams, and email to steal credentials and bypass MFA</strong></li><li><strong>CloudSEK tracked 5,000+ stolen records; Arctic Wolf urges phishing‑resistant MFA and conditional access</strong></li></ul><p>Microsoft 365 users are facing a barrage of cyberattacks all aimed at a single goal - to try and expose credentials which can later be used against employers in data theft attacks.</p><p>Different groups conduct their raids and bypass multi-factor authentication (MFA) protection to access victim accounts - CloudSEK, for example, said that some groups are using BigBear 2.0, a new phishing-as-a-service (PhaaS) framework that allows crooks to intercept passwords and authenticated session cookies.</p><p>Arctic Wolf, on the other hand, focused on a single threat actor, which it dubbed PREY-0058. This group, despite significant overlaps with other collectives in terms of techniques, technologies, and procedures, is not a rebrand of older organizations. Instead, the researchers believe the lines between the groups are blurred and that there is a large group of affiliates, splinter crews, and other cohorts using the same phishing infrastructure and thus often confuse defenders and analysts.</p><h2 id="similar-methods-similar-results">Similar methods, similar results</h2><p>The attack methodology is similar across the spectrum. Crooks would call their victims on the phone or approach them via Teams and email. They would introduce themselves as members of the IT help desk sent to sort out a specific problem or issue. </p><p>Then, they would either convince the victim to grant remote access, or to open a spoofed Microsoft 365 login page and enter their credentials there. In both cases, the goal is the same - to get the victim to type in their username, password, and 2FA code, on a fake site built by BigBear 2.0 or a similar phishing framework. This framework, using an attacker-in-the-middle (AiTM) proxy between the victim and legitimate Microsoft infrastructure, harvests credentials, <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">MFA codes</a>, and session cookies, and replays them through an API essentially hijacking a legitimate authentication session.</p><p>Once they gain access, the attackers can do all sorts of things, but they are mostly focused on exfiltrating sensitive data from Outlook, Teams, SharePoint, and OneDrive. Deploying <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> is rarely seen. </p><p>The campaign CloudSEK has been tracking has been rather successful, the researchers argue, saying BigBear 2.0 was used to exfiltrate more than 5,000 credential records, “including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies - affecting 3,331 unique victim IPs across 40+ countries with the operation still active at the time of writing.” </p><p>“The multi-user PhaaS panel is leased to at least five affiliate operators identified through live Telegram exfiltration bots, each receiving stolen credentials in real time.”</p><p>Speaking to <a href="https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/" target="_blank"><em>BleepingComputer</em></a>, CloudSEK says the campaign targeted 461 organizations, out of which 258 have had at least one set of credentials compromised. </p><h2 id="defending-with-phishing-resistant-mfa">Defending with phishing-resistant MFA</h2><p>Arctic Wolf’s researchers stressed that the attackers are focused primarily on US-based businesses: construction and engineering, healthcare and pharmaceuticals, real estate and property management, finance, and professional services, <a href="https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html" target="_blank"><em>The Hacker News</em></a> reported. The researchers advise organizations to implement Conditional Access policies, deploy phishing-resistant MFA, and restrict the scope of data users can access via SharePoint. Obviously, employee education on the dangers of phishing cannot be understated.</p><p>"Defenders can disrupt this activity by detecting anomalous residential-proxy token replay, SharePoint discovery and bulk access, mailbox harvesting, and newly registered authentication-themed lure infrastructure," Arctic Wolf said.</p><p>Phishing-resistant MFA is multi-factor authentication designed so that an attacker cannot trick a person into handing over authorization code, either via a message, or through a fake login page. </p><p>These include products such as passkeys, YubiKeys <a href="https://www.techradar.com/best/best-security-key" target="_blank">security keys</a>, and authentication methods based on FIDO2/WebAuthn. Since phishing-resistant MFA cryptographically ties the authentication to the legitimate website, the authentication cannot simply be forwarded to an attacker.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/microsoft-365-users-hit-by-two-major-threat-campaigns-fake-it-calls-and-phishing-emails-target-users-across-the-world</link>
                                                                            <description>
                            <![CDATA[ BigBear 2.0 and PREY-0058 are wreaking havoc across businesses as they scam employees into handing over login credentials and MFA codes. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">C6BxVw2HaDLYXxNeeyT4HQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vnpBJPCcs2siQw5rCEsDzG-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Sep 2026 15:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/vnpBJPCcs2siQw5rCEsDzG-1280-80.png">
                                                            <media:credit><![CDATA[Currys]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft 365]]></media:description>                                                            <media:text><![CDATA[Microsoft 365]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft 365]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vnpBJPCcs2siQw5rCEsDzG-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft 365 users targeted by phishing campaigns using BigBear 2.0 and AiTM proxies</strong></li><li><strong>Attackers impersonate IT staff via calls, Teams, and email to steal credentials and bypass MFA</strong></li><li><strong>CloudSEK tracked 5,000+ stolen records; Arctic Wolf urges phishing‑resistant MFA and conditional access</strong></li></ul><p>Microsoft 365 users are facing a barrage of cyberattacks all aimed at a single goal - to try and expose credentials which can later be used against employers in data theft attacks.</p><p>Different groups conduct their raids and bypass multi-factor authentication (MFA) protection to access victim accounts - CloudSEK, for example, said that some groups are using BigBear 2.0, a new phishing-as-a-service (PhaaS) framework that allows crooks to intercept passwords and authenticated session cookies.</p><p>Arctic Wolf, on the other hand, focused on a single threat actor, which it dubbed PREY-0058. This group, despite significant overlaps with other collectives in terms of techniques, technologies, and procedures, is not a rebrand of older organizations. Instead, the researchers believe the lines between the groups are blurred and that there is a large group of affiliates, splinter crews, and other cohorts using the same phishing infrastructure and thus often confuse defenders and analysts.</p><h2 id="similar-methods-similar-results">Similar methods, similar results</h2><p>The attack methodology is similar across the spectrum. Crooks would call their victims on the phone or approach them via Teams and email. They would introduce themselves as members of the IT help desk sent to sort out a specific problem or issue. </p><p>Then, they would either convince the victim to grant remote access, or to open a spoofed Microsoft 365 login page and enter their credentials there. In both cases, the goal is the same - to get the victim to type in their username, password, and 2FA code, on a fake site built by BigBear 2.0 or a similar phishing framework. This framework, using an attacker-in-the-middle (AiTM) proxy between the victim and legitimate Microsoft infrastructure, harvests credentials, <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">MFA codes</a>, and session cookies, and replays them through an API essentially hijacking a legitimate authentication session.</p><p>Once they gain access, the attackers can do all sorts of things, but they are mostly focused on exfiltrating sensitive data from Outlook, Teams, SharePoint, and OneDrive. Deploying <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> is rarely seen. </p><p>The campaign CloudSEK has been tracking has been rather successful, the researchers argue, saying BigBear 2.0 was used to exfiltrate more than 5,000 credential records, “including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies - affecting 3,331 unique victim IPs across 40+ countries with the operation still active at the time of writing.” </p><p>“The multi-user PhaaS panel is leased to at least five affiliate operators identified through live Telegram exfiltration bots, each receiving stolen credentials in real time.”</p><p>Speaking to <a href="https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/" target="_blank"><em>BleepingComputer</em></a>, CloudSEK says the campaign targeted 461 organizations, out of which 258 have had at least one set of credentials compromised. </p><h2 id="defending-with-phishing-resistant-mfa">Defending with phishing-resistant MFA</h2><p>Arctic Wolf’s researchers stressed that the attackers are focused primarily on US-based businesses: construction and engineering, healthcare and pharmaceuticals, real estate and property management, finance, and professional services, <a href="https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html" target="_blank"><em>The Hacker News</em></a> reported. The researchers advise organizations to implement Conditional Access policies, deploy phishing-resistant MFA, and restrict the scope of data users can access via SharePoint. Obviously, employee education on the dangers of phishing cannot be understated.</p><p>"Defenders can disrupt this activity by detecting anomalous residential-proxy token replay, SharePoint discovery and bulk access, mailbox harvesting, and newly registered authentication-themed lure infrastructure," Arctic Wolf said.</p><p>Phishing-resistant MFA is multi-factor authentication designed so that an attacker cannot trick a person into handing over authorization code, either via a message, or through a fake login page. </p><p>These include products such as passkeys, YubiKeys <a href="https://www.techradar.com/best/best-security-key" target="_blank">security keys</a>, and authentication methods based on FIDO2/WebAuthn. Since phishing-resistant MFA cryptographically ties the authentication to the legitimate website, the authentication cannot simply be forwarded to an attacker.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Two major security flaws are affecting more than six million WordPress websites ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Wordfence discloses two critical flaws in Elementor Pro and Super Forms</strong></li><li><strong>Bugs allow unauthenticated arbitrary file uploads, enabling remote code execution; both patched recently</strong></li><li><strong>Exploitation attempts already exceed 440,000</strong></li></ul><p>More than six million WordPress users are at risk of website takeover, researchers have claimed after discovering two major vulnerabilities being exploited in the wild. </p><p>Security researchers Wordfence disclosed finding two flaws, one in Elementor Pro, and one in Super Forms - two popular <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">WordPress plugins</a>. </p><p><a href="https://www.techradar.com/reviews/elementor" target="_blank">Elementor Pro</a> is a commercial plugin that allows users to build websites using drag-and-drop elements instead of code. With it, they can add advanced widgets, templates, different forms, popups, and more. It is quite a popular solution with more than six million websites actively using it.</p><h2 id="two-bugs-hundreds-of-thousands-of-attacks">Two bugs, hundreds of thousands of attacks</h2><p>According to Wordfence, up until recently, it was vulnerable to an “unrestricted file type upload” bug in all versions up to, and including, 4.2.1. “This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible,” the researchers explained. “This requires that the targeted site has published a page containing an Elementor Pro Form widget with at least one non-required File Upload field.”</p><p>The bug is tracked as CVE-2026-32475, carries a severity score of 9.8/10 (critical), and was patched in mid-August 2026. So far, Wordfence alone blocked more than 190,000 exploit attempts.</p><p>At roughly the same time, the researchers also reported finding a flaw in Super Forms, a form builder plugin that lets users create and manage forms using a drag-and-drop interface. This plugin, with some 13,000 active installations, contained a bug that allowed arbitrary file upload in all versions up to, and including, 6.3.313.</p><p>“This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible,” the researchers explained.</p><p>This one is tracked as CVE-2026-14894, also carries a severity score of 9.8/10 (critical) and it, too, was patched a few weeks ago. For this flaw, Wordfence observed more than 250,000 exploitation attempts meaning that cumulatively, these two resulted in 440,000 attacks already. </p><p>Given the widespread adoption of these plugins, and the fact that the flaws are being actively leveraged, users are advised to apply the fixes without delay.</p><p><em>Via </em><a href="https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html" target="_blank"><em>The Hacker News</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/two-major-security-flaws-are-affecting-more-than-six-million-wordpress-websites</link>
                                                                            <description>
                            <![CDATA[ Patches are available, so WordPress users should hurry up and apply them. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9ECcHJPTq7j6ouvCBPkCyJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 17:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/David MG]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:description>                                                            <media:text><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Wordfence discloses two critical flaws in Elementor Pro and Super Forms</strong></li><li><strong>Bugs allow unauthenticated arbitrary file uploads, enabling remote code execution; both patched recently</strong></li><li><strong>Exploitation attempts already exceed 440,000</strong></li></ul><p>More than six million WordPress users are at risk of website takeover, researchers have claimed after discovering two major vulnerabilities being exploited in the wild. </p><p>Security researchers Wordfence disclosed finding two flaws, one in Elementor Pro, and one in Super Forms - two popular <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">WordPress plugins</a>. </p><p><a href="https://www.techradar.com/reviews/elementor" target="_blank">Elementor Pro</a> is a commercial plugin that allows users to build websites using drag-and-drop elements instead of code. With it, they can add advanced widgets, templates, different forms, popups, and more. It is quite a popular solution with more than six million websites actively using it.</p><h2 id="two-bugs-hundreds-of-thousands-of-attacks">Two bugs, hundreds of thousands of attacks</h2><p>According to Wordfence, up until recently, it was vulnerable to an “unrestricted file type upload” bug in all versions up to, and including, 4.2.1. “This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible,” the researchers explained. “This requires that the targeted site has published a page containing an Elementor Pro Form widget with at least one non-required File Upload field.”</p><p>The bug is tracked as CVE-2026-32475, carries a severity score of 9.8/10 (critical), and was patched in mid-August 2026. So far, Wordfence alone blocked more than 190,000 exploit attempts.</p><p>At roughly the same time, the researchers also reported finding a flaw in Super Forms, a form builder plugin that lets users create and manage forms using a drag-and-drop interface. This plugin, with some 13,000 active installations, contained a bug that allowed arbitrary file upload in all versions up to, and including, 6.3.313.</p><p>“This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible,” the researchers explained.</p><p>This one is tracked as CVE-2026-14894, also carries a severity score of 9.8/10 (critical) and it, too, was patched a few weeks ago. For this flaw, Wordfence observed more than 250,000 exploitation attempts meaning that cumulatively, these two resulted in 440,000 attacks already. </p><p>Given the widespread adoption of these plugins, and the fact that the flaws are being actively leveraged, users are advised to apply the fixes without delay.</p><p><em>Via </em><a href="https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html" target="_blank"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ G7 tells businesses to get ready for quantum cybersecurity threats ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>G7 urges governments and organizations to begin transitioning to quantum‑resistant encryption</strong></li><li><strong>Warning highlights risk from future quantum computers able to break current standards like AES</strong></li><li><strong>Guidance: inventory cryptographic assets, prioritize critical systems, and adopt phased PQC strategies</strong></li></ul><p>The G7, a collection of some of the world’s most powerful economies, is urging organizations to adopt quantum-resistant encryption as soon as possible and minimize the risk of losing sensitive data to technologically advanced threat actors.</p><p>Virtually every industry in the world today relies on encryption (the process of converting readable data into scrambled, unreadable data so that only someone with the correct key can decode and access it) to protect sensitive information. Banks, telecommunications providers, defense organizations, and practically everyone else are using some form of encryption - most probably AES (Advanced Encryption Standard).</p><p>Decrypting the protected data without the encryption key is considered almost impossible, since the computational effort necessary to pull it off would simply be too large. However, since quantum computers work on a fundamentally different principle, it is believed that once they are mature enough, they will be able to “crack” today’s encryption standards. </p><h2 id="g7-39-s-advice">G7's advice</h2><p>Now, the G7 has <a href="https://www.cisa.gov/resources-tools/resources/preparing-post-quantum-era-call-action" target="_blank" rel="nofollow">urged</a> government and organizations to remain ahead of the curve by deploying “quantum-resistant encryption”:</p><p>“To protect themselves from the threat brought by CRQCs (cryptographically relevant quantum computers), organizations should begin planning their PQC transition now and should aim to complete their transitions within any the timelines set out by their national cybersecurity authorities,” the warning reads.</p><p>“In addition to quantum-related risks, organizations that delay their PQC transition may lose competitive advantage or may be excluded from contracting opportunities, including public procurement.”</p><p>The G7 advises governments and organizations to take a number of steps, including identifying critical systems and prioritizing them. They should adopt a phased and risk-based strategy, start their transition early, and inventory their cryptographic assets. They should also map their dependencies and develop a transition plan.</p><p>“To limit transition-related costs, they should opt to purchase products that integrate PQC and replace their systems with quantum-safe ones as part of their standard renewal schedule. As such, starting the transition early could result in lower migration costs overall. Planning and conducting their PQC transition properly would enable organizations to prevent insecure implementations and avoid increased exposure to conventional cyber threats.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/g7-tells-businesses-to-get-ready-for-quantum-cybersecurity-threats</link>
                                                                            <description>
                            <![CDATA[ Organizations late to the migration could lose contracting opportunities, G7 warns. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2ZkfdmUW73vAcJc8nb3TLL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UVm4pWzxzFfM3waNQDdPrD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 16:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UVm4pWzxzFfM3waNQDdPrD-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Quantum computing concept. Digital communication network. Technological abstract.]]></media:description>                                                            <media:text><![CDATA[Quantum computing concept. Digital communication network. Technological abstract.]]></media:text>
                                <media:title type="plain"><![CDATA[Quantum computing concept. Digital communication network. Technological abstract.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UVm4pWzxzFfM3waNQDdPrD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>G7 urges governments and organizations to begin transitioning to quantum‑resistant encryption</strong></li><li><strong>Warning highlights risk from future quantum computers able to break current standards like AES</strong></li><li><strong>Guidance: inventory cryptographic assets, prioritize critical systems, and adopt phased PQC strategies</strong></li></ul><p>The G7, a collection of some of the world’s most powerful economies, is urging organizations to adopt quantum-resistant encryption as soon as possible and minimize the risk of losing sensitive data to technologically advanced threat actors.</p><p>Virtually every industry in the world today relies on encryption (the process of converting readable data into scrambled, unreadable data so that only someone with the correct key can decode and access it) to protect sensitive information. Banks, telecommunications providers, defense organizations, and practically everyone else are using some form of encryption - most probably AES (Advanced Encryption Standard).</p><p>Decrypting the protected data without the encryption key is considered almost impossible, since the computational effort necessary to pull it off would simply be too large. However, since quantum computers work on a fundamentally different principle, it is believed that once they are mature enough, they will be able to “crack” today’s encryption standards. </p><h2 id="g7-39-s-advice">G7's advice</h2><p>Now, the G7 has <a href="https://www.cisa.gov/resources-tools/resources/preparing-post-quantum-era-call-action" target="_blank" rel="nofollow">urged</a> government and organizations to remain ahead of the curve by deploying “quantum-resistant encryption”:</p><p>“To protect themselves from the threat brought by CRQCs (cryptographically relevant quantum computers), organizations should begin planning their PQC transition now and should aim to complete their transitions within any the timelines set out by their national cybersecurity authorities,” the warning reads.</p><p>“In addition to quantum-related risks, organizations that delay their PQC transition may lose competitive advantage or may be excluded from contracting opportunities, including public procurement.”</p><p>The G7 advises governments and organizations to take a number of steps, including identifying critical systems and prioritizing them. They should adopt a phased and risk-based strategy, start their transition early, and inventory their cryptographic assets. They should also map their dependencies and develop a transition plan.</p><p>“To limit transition-related costs, they should opt to purchase products that integrate PQC and replace their systems with quantum-safe ones as part of their standard renewal schedule. As such, starting the transition early could result in lower migration costs overall. Planning and conducting their PQC transition properly would enable organizations to prevent insecure implementations and avoid increased exposure to conventional cyber threats.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US military troops can still be hit by targeted attacks despite disabling ad tracking on their devices — and leaders aren't happy ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>US military branches disable ad tracking on government‑issued devices after warning</strong></li><li><strong>Location data from personal devices still poses risks; past data remains for sale</strong></li><li><strong>Senators urge DoD inspector general to review policies and stop servicemember data exposure</strong></li></ul><p>More than 20 years ago, Jason Bourne was smashing mobile phones to prevent being tracked by his adversaries - and the US Department of Defense (DoD) has realized it should probably do something similar.</p><p>In May 2026, Senator Ron Wyden mailed the DoD (among others), informing the agency that foreign powers were using commercial location data to target US troops - and now, Wyden has shared the responses he received from the US Army, Air Force, Navy, Marine Corps, and Special Operations Command, all of which have disabled advertising tracking across their government-issued devices, including Apple and Android smartphones, and Windows computers. </p><p>Some branches did it earlier this year, while the Air Force allegedly concluded the efforts in July 2026 - and while Wyden praised the move, he also suggested it is not enough, and that further steps must be taken in order to protect US troops stationed abroad.</p><h2 id="evaluating-the-leaked-files">Evaluating the leaked files</h2><p>“We commend these service branches for implementing this cybersecurity defensive best practice on government devices,” Wyden and Senator Pat Harrigan wrote. “However, recent reports regarding the continued availability of commercial location data originating from DoD facilities raise troubling questions.”</p><p>Apparently, despite disabling these features and placing the troops out of reach of <a href="https://www.techradar.com/pro/best-data-removal-services-of-year" target="_blank">data brokers</a> and similar commercial entities, the data that was gathered earlier remains available for sale, which still presents a risk. </p><p>“The members suggested data could continue to be available for several reasons, including that commercial data available originates from personal devices, not government phones, that are carried by servicemembers and government contractors,” a report on <a href="https://www.wyden.senate.gov/news/press-releases/wyden-and-harrigan-call-for-investigation-into-dod-efforts-to-protect-us-servicemembers-from-commercial-location-data-threats" target="_blank" rel="nofollow">Wyden’s website</a> reads.</p><p>“Wyden and Harrigan called on the DOD inspector general to examine commercial location data that DOD and other government agencies have already purchased to determine why existing policies have not prevented servicemembers location data from being sold online, and to recommend policy changes to better protect US personnel.”</p><p><em>Via </em><a href="https://techcrunch.com/2026/09/04/us-military-disabled-ad-tracking-on-troops-devices-following-reports-of-targeted-attacks/" target="_blank"><em>TechCrunch</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/us-military-troops-can-still-be-hit-by-targeted-attacks-despite-disabling-ad-tracking-on-their-devices-and-leaders-arent-happy</link>
                                                                            <description>
                            <![CDATA[ Government-issued devices are safe - but what about private devices? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qxo8CGkgGxxCnCDCgsK3sd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KcuQeJXg8Wj7ktEdTA3XhC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 15:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KcuQeJXg8Wj7ktEdTA3XhC-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images / NATALIA KOLESNIKOVA]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A Belarusian border guard with a service dog]]></media:description>                                                            <media:text><![CDATA[A Belarusian border guard with a service dog]]></media:text>
                                <media:title type="plain"><![CDATA[A Belarusian border guard with a service dog]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KcuQeJXg8Wj7ktEdTA3XhC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>US military branches disable ad tracking on government‑issued devices after warning</strong></li><li><strong>Location data from personal devices still poses risks; past data remains for sale</strong></li><li><strong>Senators urge DoD inspector general to review policies and stop servicemember data exposure</strong></li></ul><p>More than 20 years ago, Jason Bourne was smashing mobile phones to prevent being tracked by his adversaries - and the US Department of Defense (DoD) has realized it should probably do something similar.</p><p>In May 2026, Senator Ron Wyden mailed the DoD (among others), informing the agency that foreign powers were using commercial location data to target US troops - and now, Wyden has shared the responses he received from the US Army, Air Force, Navy, Marine Corps, and Special Operations Command, all of which have disabled advertising tracking across their government-issued devices, including Apple and Android smartphones, and Windows computers. </p><p>Some branches did it earlier this year, while the Air Force allegedly concluded the efforts in July 2026 - and while Wyden praised the move, he also suggested it is not enough, and that further steps must be taken in order to protect US troops stationed abroad.</p><h2 id="evaluating-the-leaked-files">Evaluating the leaked files</h2><p>“We commend these service branches for implementing this cybersecurity defensive best practice on government devices,” Wyden and Senator Pat Harrigan wrote. “However, recent reports regarding the continued availability of commercial location data originating from DoD facilities raise troubling questions.”</p><p>Apparently, despite disabling these features and placing the troops out of reach of <a href="https://www.techradar.com/pro/best-data-removal-services-of-year" target="_blank">data brokers</a> and similar commercial entities, the data that was gathered earlier remains available for sale, which still presents a risk. </p><p>“The members suggested data could continue to be available for several reasons, including that commercial data available originates from personal devices, not government phones, that are carried by servicemembers and government contractors,” a report on <a href="https://www.wyden.senate.gov/news/press-releases/wyden-and-harrigan-call-for-investigation-into-dod-efforts-to-protect-us-servicemembers-from-commercial-location-data-threats" target="_blank" rel="nofollow">Wyden’s website</a> reads.</p><p>“Wyden and Harrigan called on the DOD inspector general to examine commercial location data that DOD and other government agencies have already purchased to determine why existing policies have not prevented servicemembers location data from being sold online, and to recommend policy changes to better protect US personnel.”</p><p><em>Via </em><a href="https://techcrunch.com/2026/09/04/us-military-disabled-ad-tracking-on-troops-devices-following-reports-of-targeted-attacks/" target="_blank"><em>TechCrunch</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ransomware hackers dump 1.4 million stolen records from German government ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Rhysida ransomware group breached Berlin’s state government, stealing 1.44 million files weighing in at around 5.8TB</strong></li><li><strong>Attackers demanded 30 BTC (~$2.3M); Berlin refused, leading to full leak online</strong></li><li><strong>Leaked data reportedly includes water supply info, staff records, and emergency plans</strong></li></ul><p>A cybercriminal group known as Rhysida allegedly broke into the network of Berlin's state government and exfiltrated 1.44 million files. They then tried to extort the government entity for money and when that failed, they leaked it all into the dark web.</p><p>According to multiple sources, the group first claimed responsibility for the attack on an underground forum, where it shared a small sample of the stolen files and demanded Berlin pay 30 bitcoin (around $2.3 million) in exchange for deleting the files.</p><p>Berlin recognized the attack in a press release, and said it would not be negotiating with the attackers, and instead launched a full-scale investigation into the incident, which it described as an “extremely serious crime and an attack on the state of Berlin.”</p><h2 id="evaluating-the-leaked-files-2">Evaluating the leaked files</h2><p>A few days later, <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">Rhysida</a> decided to leak it all online - and Berlin is now reviewing the leaked files and is assessing the damage:</p><p>“After the publication of the stolen data from the Berlin administration, these files are being evaluated at full speed,” a press release, published on the Berlin.de website (machine-translated), reads. </p><p>“An additional steering unit has been set up in the Senate Chancellery under the leadership of the Chief Digital Officer (CDO), Florian Hauer, which coordinates the review, examination and evaluation of the leaked data and supports the two Senate administrations concerned in informing and advising the affected citizens and companies.”</p><p>According to German public broadcaster Tagesschau, the archive counts 1.44 million files and totals 5.8 terabytes. At the same time, the Chaos Computer Club (Germany's largest and best-known hacker organization) claims the archive contains sensitive data on the city’s water supply, personal data of admin staff, various employment references, and emergency plans. </p><p><em>Via </em><a href="https://www.reuters.com/world/berlin-launches-crisis-response-after-hackers-publish-stolen-data-2026-09-05/" target="_blank"><em>Reuters</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/ransomware-hackers-dump-1-4-million-stolen-records-from-german-government</link>
                                                                            <description>
                            <![CDATA[ This is an "extremely serious crime" and an attack on Berlin, the government says. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sTAtVCtttosNejBRf3aDA4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3HY9z6jmzyHFPZFAtvox2a-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 13:35:36 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/3HY9z6jmzyHFPZFAtvox2a-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3HY9z6jmzyHFPZFAtvox2a-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Rhysida ransomware group breached Berlin’s state government, stealing 1.44 million files weighing in at around 5.8TB</strong></li><li><strong>Attackers demanded 30 BTC (~$2.3M); Berlin refused, leading to full leak online</strong></li><li><strong>Leaked data reportedly includes water supply info, staff records, and emergency plans</strong></li></ul><p>A cybercriminal group known as Rhysida allegedly broke into the network of Berlin's state government and exfiltrated 1.44 million files. They then tried to extort the government entity for money and when that failed, they leaked it all into the dark web.</p><p>According to multiple sources, the group first claimed responsibility for the attack on an underground forum, where it shared a small sample of the stolen files and demanded Berlin pay 30 bitcoin (around $2.3 million) in exchange for deleting the files.</p><p>Berlin recognized the attack in a press release, and said it would not be negotiating with the attackers, and instead launched a full-scale investigation into the incident, which it described as an “extremely serious crime and an attack on the state of Berlin.”</p><h2 id="evaluating-the-leaked-files-2">Evaluating the leaked files</h2><p>A few days later, <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">Rhysida</a> decided to leak it all online - and Berlin is now reviewing the leaked files and is assessing the damage:</p><p>“After the publication of the stolen data from the Berlin administration, these files are being evaluated at full speed,” a press release, published on the Berlin.de website (machine-translated), reads. </p><p>“An additional steering unit has been set up in the Senate Chancellery under the leadership of the Chief Digital Officer (CDO), Florian Hauer, which coordinates the review, examination and evaluation of the leaked data and supports the two Senate administrations concerned in informing and advising the affected citizens and companies.”</p><p>According to German public broadcaster Tagesschau, the archive counts 1.44 million files and totals 5.8 terabytes. At the same time, the Chaos Computer Club (Germany's largest and best-known hacker organization) claims the archive contains sensitive data on the city’s water supply, personal data of admin staff, various employment references, and emergency plans. </p><p><em>Via </em><a href="https://www.reuters.com/world/berlin-launches-crisis-response-after-hackers-publish-stolen-data-2026-09-05/" target="_blank"><em>Reuters</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are using 'invisible' Unicode characters to sneak phishing lures into emails ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft reports phishing campaign using ASCII smuggling to bypass spam filters</strong></li><li><strong>Attackers insert invisible characters into keywords, tricking filters and AI agents</strong></li><li><strong>Defenders should normalize Unicode tags and flag unexpected invisible code points as suspicious</strong></li></ul><p>Cybercriminals are using the “ASCII smuggling” technique to make sure phishing emails pass security filters and land in people’s inboxes, experts have warned.</p><p>ASCII is a character encoding standard that turns characters and words humans can read into numeric values that computers can understand. It can also be used to create characters that aren’t even displayed on the screen (essentially “invisible” ones) but can still be read by the machine.</p><p>In a new <a href="https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/" target="_blank" rel="nofollow">report</a>, security researchers from Microsoft found crooks are abusing this fact to distribute phishing emails. Most email providers offer solutions that filter out spam emails. These filters look for certain keywords and phrases, such as “funding”, “credit”, “loan”, and similar, and automatically send such emails to the spam folder. </p><h2 id="ongoing-campaign">Ongoing campaign</h2><p>By adding a set of invisible characters in the middle of these keywords, the attackers can break them apart and thus “confuse” the filters. </p><p>While the human sees the word “funding” in their email, the security solution is seeing something like “fun[a long string of characters]ding”. This technique has been adopted from prompt injection attacks, where crooks would use ASCII smuggling to deliver malicious and invisible prompts in the emails. </p><p>Therefore, when a victim asks their AI agent to summarize the email, it ends up working on a prompt that could be anything from extracting sensitive data, to deploying <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>. </p><p>Microsoft is saying the campaign has been ongoing for months, and while it peaked in February 2026 with more than 2.3 million emails every day, and has been in decline ever since, it remains active to this day. In early February, Microsoft observed a cluster of almost 150 sender domains, all themed around finance. These domains accounted for almost all (96%) of all the spam emails Defender for Office 365 flagged under ASCII smuggling.</p><p>Defending sounds relatively simple, though. IT teams should normalize Unicode tag characters and other invisible code points before applying any keyword detection. They should also consider all unexpected tag-block characters as suspicious.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/attackers-conceal-phishing-lures-using-invisible-unicode-characters/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/hackers-are-using-invisible-unicode-characters-to-sneak-phishing-lures-into-emails</link>
                                                                            <description>
                            <![CDATA[ A technique used in prompt injection attacks has made it into phishing, Microsoft has warned. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kpbZtKyjta2kiuQw3KPbBZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rsstAB5QjUqoXwXYPEgT7d-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 13:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rsstAB5QjUqoXwXYPEgT7d-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing]]></media:description>                                                            <media:text><![CDATA[Phishing]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rsstAB5QjUqoXwXYPEgT7d-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft reports phishing campaign using ASCII smuggling to bypass spam filters</strong></li><li><strong>Attackers insert invisible characters into keywords, tricking filters and AI agents</strong></li><li><strong>Defenders should normalize Unicode tags and flag unexpected invisible code points as suspicious</strong></li></ul><p>Cybercriminals are using the “ASCII smuggling” technique to make sure phishing emails pass security filters and land in people’s inboxes, experts have warned.</p><p>ASCII is a character encoding standard that turns characters and words humans can read into numeric values that computers can understand. It can also be used to create characters that aren’t even displayed on the screen (essentially “invisible” ones) but can still be read by the machine.</p><p>In a new <a href="https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/" target="_blank" rel="nofollow">report</a>, security researchers from Microsoft found crooks are abusing this fact to distribute phishing emails. Most email providers offer solutions that filter out spam emails. These filters look for certain keywords and phrases, such as “funding”, “credit”, “loan”, and similar, and automatically send such emails to the spam folder. </p><h2 id="ongoing-campaign">Ongoing campaign</h2><p>By adding a set of invisible characters in the middle of these keywords, the attackers can break them apart and thus “confuse” the filters. </p><p>While the human sees the word “funding” in their email, the security solution is seeing something like “fun[a long string of characters]ding”. This technique has been adopted from prompt injection attacks, where crooks would use ASCII smuggling to deliver malicious and invisible prompts in the emails. </p><p>Therefore, when a victim asks their AI agent to summarize the email, it ends up working on a prompt that could be anything from extracting sensitive data, to deploying <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>. </p><p>Microsoft is saying the campaign has been ongoing for months, and while it peaked in February 2026 with more than 2.3 million emails every day, and has been in decline ever since, it remains active to this day. In early February, Microsoft observed a cluster of almost 150 sender domains, all themed around finance. These domains accounted for almost all (96%) of all the spam emails Defender for Office 365 flagged under ASCII smuggling.</p><p>Defending sounds relatively simple, though. IT teams should normalize Unicode tag characters and other invisible code points before applying any keyword detection. They should also consider all unexpected tag-block characters as suspicious.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/attackers-conceal-phishing-lures-using-invisible-unicode-characters/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Save up to 50% off Keeper plans this September — protect your passwords with half price Personal plans, and a third-off Business plans ]]></title>
                                                                                                <dc:content><![CDATA[ <p>You probably have tens, if not hundreds of passwords floating around across all the online accounts you use every week. In fact, the average person has over 150 passwords. It's not easy to remember them all, making it more attractive to keep them simple and similar - but that can lead to a serious chain of account theft.</p><p>That's why password managers like Keeper exist. They generate strong passwords and store them passwords in a secured vault to keep them safe from hackers and prying eyes. They even autofill your credentials to make logging in to your account faster and easier.</p><p><a href="https://www.keepersecurity.com/en_GB/pricing/personal-and-family.html" target="_blank" rel="nofollow">Keeper has cut prices on its personal, family, and business starter plans by up to 50%</a>. Keeper regularly scores highly in our reviews, and includes great features across Personal, Family, and Business plans.</p><div class="product"><a data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:131px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="TbfSUDRsU8NdGFXVDRFiSW" name="keeper!.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/TbfSUDRsU8NdGFXVDRFiSW-1920-80.jpg" mos="" align="middle" fullscreen="" width="131" height="131" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow" data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" data-dimension25=""><strong>Get up to 50% off Keeper plans</strong></a></p><p>Keeper is offering 50% off its Personal and Family plans, making it even more affordable to secure both personal and household accounts. The Family plan covers multiple users with five secured vaults, making it perfect for shared accounts without the hassle of mixing browsers and reusing passwords.</p><p>Keeper Business Starter is discounted by 30%, and is an excellent choice for small teams looking for a credentials control platform without the complexity and hassle of enduring an enterprise rollout. It includes centralized management, secure password sharing, and role-based access, cleanly organizing your passwords without unnecessary complications.</p><p>The full terms and pricing are available on the <a href="https://www.keepersecurity.com/en_GB/pricing/personal-and-family.html" target="_blank" rel="nofollow">Keeper site</a>.<a class="view-deal button" href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow" data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" data-dimension25="">View Deal</a></p></div><h2 id="why-we-recommend-keeper">Why we recommend Keeper</h2><p>Our <a href="https://www.techradar.com/reviews/keeper-password-manager" target="_blank">Keeper review</a> highlights the platform's zero knowledge architecture and device level encryption that helps keep your password vault secured against unwanted intrusions.</p><p>Where Keeper really shone was in our usability and convenience testing. We loved how Keeper uses biometric security to access your vault, rather than requiring a master password with each log in. By using a facial scan or fingerprint to verify that its actually you accessing your vault, it adds a fast but secure method of verification to ensure its you, and not a nefarious actor.</p><p>For households, the Family Plan includes five private vaults, allowing you to quickly share Wi-Fi or streaming passwords using Keeper's shared vaults.</p><p>The Business Starter plan covers 5 users, covering an unlimited devices, shared team folders, user activity reporting for IT admins, and a free Family Plan for every team member.</p><p>These discounts apply to the first year only, so the value is highest for new customers or anyone switching from a monthly plan. After that, pricing goes back to standard rates.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/save-up-to-50-percent-off-keeper-plans-this-september-protect-your-passwords-with-half-price-personal-plans-and-a-third-off-business-plans</link>
                                                                            <description>
                            <![CDATA[ Keeper is one of the best solutions to password storage and security, with up to 50% off across Personal, Family, and Business plans ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">A3tb9XngX6pNeDLcj6Au2h</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QFvexowkpqsxcqY8TUgdgc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 13:17:40 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QFvexowkpqsxcqY8TUgdgc-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Keeper logo next to a label stating &quot;Price Cut&quot;.]]></media:description>                                                            <media:text><![CDATA[The Keeper logo next to a label stating &quot;Price Cut&quot;.]]></media:text>
                                <media:title type="plain"><![CDATA[The Keeper logo next to a label stating &quot;Price Cut&quot;.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QFvexowkpqsxcqY8TUgdgc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>You probably have tens, if not hundreds of passwords floating around across all the online accounts you use every week. In fact, the average person has over 150 passwords. It's not easy to remember them all, making it more attractive to keep them simple and similar - but that can lead to a serious chain of account theft.</p><p>That's why password managers like Keeper exist. They generate strong passwords and store them passwords in a secured vault to keep them safe from hackers and prying eyes. They even autofill your credentials to make logging in to your account faster and easier.</p><p><a href="https://www.keepersecurity.com/en_GB/pricing/personal-and-family.html" target="_blank" rel="nofollow">Keeper has cut prices on its personal, family, and business starter plans by up to 50%</a>. Keeper regularly scores highly in our reviews, and includes great features across Personal, Family, and Business plans.</p><div class="product"><a data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:131px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="TbfSUDRsU8NdGFXVDRFiSW" name="keeper!.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/TbfSUDRsU8NdGFXVDRFiSW-1920-80.jpg" mos="" align="middle" fullscreen="" width="131" height="131" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow" data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" data-dimension25=""><strong>Get up to 50% off Keeper plans</strong></a></p><p>Keeper is offering 50% off its Personal and Family plans, making it even more affordable to secure both personal and household accounts. The Family plan covers multiple users with five secured vaults, making it perfect for shared accounts without the hassle of mixing browsers and reusing passwords.</p><p>Keeper Business Starter is discounted by 30%, and is an excellent choice for small teams looking for a credentials control platform without the complexity and hassle of enduring an enterprise rollout. It includes centralized management, secure password sharing, and role-based access, cleanly organizing your passwords without unnecessary complications.</p><p>The full terms and pricing are available on the <a href="https://www.keepersecurity.com/en_GB/pricing/personal-and-family.html" target="_blank" rel="nofollow">Keeper site</a>.<a class="view-deal button" href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow" data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" data-dimension25="">View Deal</a></p></div><h2 id="why-we-recommend-keeper">Why we recommend Keeper</h2><p>Our <a href="https://www.techradar.com/reviews/keeper-password-manager" target="_blank">Keeper review</a> highlights the platform's zero knowledge architecture and device level encryption that helps keep your password vault secured against unwanted intrusions.</p><p>Where Keeper really shone was in our usability and convenience testing. We loved how Keeper uses biometric security to access your vault, rather than requiring a master password with each log in. By using a facial scan or fingerprint to verify that its actually you accessing your vault, it adds a fast but secure method of verification to ensure its you, and not a nefarious actor.</p><p>For households, the Family Plan includes five private vaults, allowing you to quickly share Wi-Fi or streaming passwords using Keeper's shared vaults.</p><p>The Business Starter plan covers 5 users, covering an unlimited devices, shared team folders, user activity reporting for IT admins, and a free Family Plan for every team member.</p><p>These discounts apply to the first year only, so the value is highest for new customers or anyone switching from a monthly plan. After that, pricing goes back to standard rates.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why is there so much worry about OpenAI Astra, and what issues could ‘recurrent depth’ reasoning cause? The experts weigh in ]]></title>
                                                                                                <dc:content><![CDATA[ <p>OpenAI has unveiled a much anticipated AI model which the firm has dubbed ‘GPT-6 Astra’. While the model has improved significantly across benchmark testing and <a href="https://www.techradar.com/pro/gpt-6-astra-lays-the-foundations-for-a-new-way-of-reasoning-a-great-tool-for-businesses-but-experts-have-their-concerns">brings a host of new business features</a>, there is still a dark cloud looming over the new model.</p><p>Off the back of <a href="https://www.techradar.com/pro/security/why-are-so-many-ai-models-going-rogue-the-experts-weigh-in">OpenAI’s accidental hack of Hugging Face</a> and the company’s subsequent efforts to improve how AI agents behave and interact, numerous cybersecurity experts have raised concerns about the model’s new ‘recurrent depth’ reasoning capabilities.</p><p>This new reasoning architecture allows the model to consider a problem multiple times before taking an action, compared to the standard chain-of-thought reasoning used in previous models.</p><h2 id="why-the-concern-about-recurrent-depth-reasoning">Why the concern about recurrent depth reasoning?</h2><p>This new level of reasoning apparently offers improved performance. OpenAI also says it has fixed its models' abilities to circumvent boundaries when performing tests by monitoring the models reasoning and ensuring the model stays aligned within the scope of its task.</p><p>During Astra’s launch event, OpenAI chief scientist Jakub Pachocki said: “We will not accept degradation in our ability to monitor model alignment beyond a certain level. We will withhold scaling until we can regain enough confidence.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9-1920-80.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>But numerous experts believe that the lessons of the Hugging Face incident have not yet been learned, and the model has been released without adequate testing on Astra’s reasoning and monitoring. </p><p>After all, no one thought one of <a href="https://www.techradar.com/pro/security/openai-reveals-more-on-hugging-face-ai-hack-incident-and-its-pretty-disturbing-stuff-ai-agents-organized-into-a-swarm-considered-the-risks-of-attack-and-did-whatever-it-took-to-achieve-its-goal">OpenAI’s models could set up a hidden internet-connected messaging board</a> that allowed AI agents to influence each other's behavior.</p><p>But with Astra being released into the real world, the lessons may have to be learned on the fly.</p><h3 class="article-body__section" id="section-expert-perspectives-on-openai-astra-release"><span>Expert perspectives on OpenAI Astra release</span></h3><ul><li><strong>James Blake, VP of Global Cyber Resiliency Strategy at Cohesity:</strong></li></ul><p><em>The launch of Astra is raising questions again around the safety of Frontier AI. Instead of simply asking whether a model is "safe", organisations now need to ask whether it remains safe across millions of different situations, prompts and interactions. Cyber resilience has traditionally assumed that systems and threat actors behave deterministically. AI systems don’t.</em></p><div><blockquote><p>Suppose an AI system autonomously develops a strategy that causes financial loss, leaks confidential information or violates regulation. Who is responsible?</p></blockquote></div><p><em>Advanced models can and will continue to exhibit behaviours that emerge from their optimisation process rather than from explicit programming. We have to move beyond thinking about AI as just another software tool and find ways to ensure these systems remain observable, auditable and governable throughout their lifecycle. </em></p><p><em>The most important question we’ll need to answer in future is one of liability. Suppose an AI system autonomously develops a strategy that causes financial loss, leaks confidential information or violates regulation. Who is responsible? The developer that trained the model? The cloud provider operating the infrastructure? Currently the answer is surprisingly unclear. It’s not just about what AI can do: it’s about who is accountable when it does something nobody expected.</em></p><ul><li><strong>Oleksandr Yaremchuk, Co-Founder & CTO at Manifold Security:</strong></li></ul><p><em>OpenAI is calling Astra its most aligned model yet, even as its chief scientist admits monitorability is getting harder as models get more capable. Evidently, Astra hides its reasoning in the majority of tested cases, and some successful attacks left no reasoning trace at all. That's the tool many organisations still use, including the labs themselves, for auditing what an agent is doing, and it's getting less reliable with every release.</em></p><div><blockquote><p>A model that explains itself less isn't more aligned, it's just harder to catch when it goes wrong.</p></blockquote></div><p><em>That matters because Astra isn't staying inside OpenAI's test environment. It's going to run as an agent on employee laptops and in the browser, holding real credentials, inside companies that have no way to watch what it does once it's there. A model that explains itself less isn't more aligned, it's just harder to catch when it goes wrong.</em></p><p><em>Labs can keep debating what these models say or refuse to say. Security teams need to stop relying on that and start monitoring what agents actually do at runtime, with the ability to shut one down mid-action. That's the only oversight left that still works once the reasoning goes quiet.</em></p><ul><li><strong>Kristin Lowery, Field CISO at Optiv:</strong></li></ul><p><em>For boards and executive leaders, the emergence of OpenAI’s Astra model highlights a broader reality: AI is no longer just a productivity issue; it is a risk management issue. </em></p><div><blockquote><p>The real challenge is whether organizations can strengthen their governance, security controls, and workforce readiness quickly enough to keep pace</p></blockquote></div><p><em>Just as organizations established governance for cloud adoption and digital transformation, they now need clear policies, strong oversight, and accountability for AI use.</em></p><p><em>The question is not whether AI will become more capable — it will. The real challenge is whether organizations can strengthen their governance, security controls, and workforce readiness quickly enough to keep pace.</em></p><ul><li><strong>Patricia Titus, Field CISO at Abnormal AI:</strong></li></ul><p><em>OpenAI crossing this threshold deserves attention. Credit where it's due, they're handling it responsibly by restricting Astra's advanced cyber capability to a small coalition rather than releasing it broadly.But this isn't one company's problem to contain.</em></p><p><em>Once a model can find and exploit unknown flaws without a human in the loop, that capability doesn't stay exclusive for long. Open-weight and modified models typically trail the frontier by only months, and that's the reality defenders have to plan around now.</em></p><div><blockquote><p>Static, signature-based defences were built for attacks that repeat. They weren't built for an adversary that generates a new one every time.</p></blockquote></div><p><em>Static, signature-based defences were built for attacks that repeat. They weren't built for an adversary that generates a new one every time. Defenders need the same shift, systems that learn what normal looks like for every identity, human, machine, or AI agent, and flag and contain the moment something deviates, at machine speed.</em></p><p><em>The window to build that is open now. It won't stay that way once this capability is common instead of rare.</em></p><ul><li><strong>Raghu Nandakumara, VP of Industry Strategy at Illumio:</strong></li></ul><p><em>With the Astra announcement, OpenAI is doubling down on monitoring the model's own behaviour – a response to the model "breakouts" seen over the past few months.</em></p><div><blockquote><p>The goal is to catch a model going rogue mid-task, not just stop it being misused at the outset.</p></blockquote></div><p><em>When Anthropic announced Claude Mythos Preview, the core concern was the model falling into the wrong hands. OpenAI's answer goes further adding guardrails around the model's own reasoning and actions, regardless of the user's intent. The goal is to catch a model going rogue mid-task, not just stop it being misused at the outset.</em></p><p><em>The rest of this announcement can be summarised as ‘we have a new frontier model, and it’s more capable than the last one’.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/why-is-there-so-much-worry-about-openai-astra-and-what-issues-could-recurrent-depth-reasoning-cause-the-experts-weigh-in</link>
                                                                            <description>
                            <![CDATA[ As OpenAI unveils GPT-6 Astra, cybersecurity experts question whether the model's 'recurrent depth' reasoning was properly tested. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">C8dxY7YkHdtYyEPzyEiovn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 05 Sep 2026 13:30:00 +0000</pubDate>                                                                                                                                <updated>Mon, 07 Sep 2026 09:36:03 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[OpenAI]]></category>
                                                    <category><![CDATA[ChatGPT]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg">
                                                            <media:credit><![CDATA[OpenAI]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[OpenAI GPT-6 Astra]]></media:description>                                                            <media:text><![CDATA[OpenAI GPT-6 Astra]]></media:text>
                                <media:title type="plain"><![CDATA[OpenAI GPT-6 Astra]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>OpenAI has unveiled a much anticipated AI model which the firm has dubbed ‘GPT-6 Astra’. While the model has improved significantly across benchmark testing and <a href="https://www.techradar.com/pro/gpt-6-astra-lays-the-foundations-for-a-new-way-of-reasoning-a-great-tool-for-businesses-but-experts-have-their-concerns">brings a host of new business features</a>, there is still a dark cloud looming over the new model.</p><p>Off the back of <a href="https://www.techradar.com/pro/security/why-are-so-many-ai-models-going-rogue-the-experts-weigh-in">OpenAI’s accidental hack of Hugging Face</a> and the company’s subsequent efforts to improve how AI agents behave and interact, numerous cybersecurity experts have raised concerns about the model’s new ‘recurrent depth’ reasoning capabilities.</p><p>This new reasoning architecture allows the model to consider a problem multiple times before taking an action, compared to the standard chain-of-thought reasoning used in previous models.</p><h2 id="why-the-concern-about-recurrent-depth-reasoning">Why the concern about recurrent depth reasoning?</h2><p>This new level of reasoning apparently offers improved performance. OpenAI also says it has fixed its models' abilities to circumvent boundaries when performing tests by monitoring the models reasoning and ensuring the model stays aligned within the scope of its task.</p><p>During Astra’s launch event, OpenAI chief scientist Jakub Pachocki said: “We will not accept degradation in our ability to monitor model alignment beyond a certain level. We will withhold scaling until we can regain enough confidence.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9-1920-80.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>But numerous experts believe that the lessons of the Hugging Face incident have not yet been learned, and the model has been released without adequate testing on Astra’s reasoning and monitoring. </p><p>After all, no one thought one of <a href="https://www.techradar.com/pro/security/openai-reveals-more-on-hugging-face-ai-hack-incident-and-its-pretty-disturbing-stuff-ai-agents-organized-into-a-swarm-considered-the-risks-of-attack-and-did-whatever-it-took-to-achieve-its-goal">OpenAI’s models could set up a hidden internet-connected messaging board</a> that allowed AI agents to influence each other's behavior.</p><p>But with Astra being released into the real world, the lessons may have to be learned on the fly.</p><h3 class="article-body__section" id="section-expert-perspectives-on-openai-astra-release"><span>Expert perspectives on OpenAI Astra release</span></h3><ul><li><strong>James Blake, VP of Global Cyber Resiliency Strategy at Cohesity:</strong></li></ul><p><em>The launch of Astra is raising questions again around the safety of Frontier AI. Instead of simply asking whether a model is "safe", organisations now need to ask whether it remains safe across millions of different situations, prompts and interactions. Cyber resilience has traditionally assumed that systems and threat actors behave deterministically. AI systems don’t.</em></p><div><blockquote><p>Suppose an AI system autonomously develops a strategy that causes financial loss, leaks confidential information or violates regulation. Who is responsible?</p></blockquote></div><p><em>Advanced models can and will continue to exhibit behaviours that emerge from their optimisation process rather than from explicit programming. We have to move beyond thinking about AI as just another software tool and find ways to ensure these systems remain observable, auditable and governable throughout their lifecycle. </em></p><p><em>The most important question we’ll need to answer in future is one of liability. Suppose an AI system autonomously develops a strategy that causes financial loss, leaks confidential information or violates regulation. Who is responsible? The developer that trained the model? The cloud provider operating the infrastructure? Currently the answer is surprisingly unclear. It’s not just about what AI can do: it’s about who is accountable when it does something nobody expected.</em></p><ul><li><strong>Oleksandr Yaremchuk, Co-Founder & CTO at Manifold Security:</strong></li></ul><p><em>OpenAI is calling Astra its most aligned model yet, even as its chief scientist admits monitorability is getting harder as models get more capable. Evidently, Astra hides its reasoning in the majority of tested cases, and some successful attacks left no reasoning trace at all. That's the tool many organisations still use, including the labs themselves, for auditing what an agent is doing, and it's getting less reliable with every release.</em></p><div><blockquote><p>A model that explains itself less isn't more aligned, it's just harder to catch when it goes wrong.</p></blockquote></div><p><em>That matters because Astra isn't staying inside OpenAI's test environment. It's going to run as an agent on employee laptops and in the browser, holding real credentials, inside companies that have no way to watch what it does once it's there. A model that explains itself less isn't more aligned, it's just harder to catch when it goes wrong.</em></p><p><em>Labs can keep debating what these models say or refuse to say. Security teams need to stop relying on that and start monitoring what agents actually do at runtime, with the ability to shut one down mid-action. That's the only oversight left that still works once the reasoning goes quiet.</em></p><ul><li><strong>Kristin Lowery, Field CISO at Optiv:</strong></li></ul><p><em>For boards and executive leaders, the emergence of OpenAI’s Astra model highlights a broader reality: AI is no longer just a productivity issue; it is a risk management issue. </em></p><div><blockquote><p>The real challenge is whether organizations can strengthen their governance, security controls, and workforce readiness quickly enough to keep pace</p></blockquote></div><p><em>Just as organizations established governance for cloud adoption and digital transformation, they now need clear policies, strong oversight, and accountability for AI use.</em></p><p><em>The question is not whether AI will become more capable — it will. The real challenge is whether organizations can strengthen their governance, security controls, and workforce readiness quickly enough to keep pace.</em></p><ul><li><strong>Patricia Titus, Field CISO at Abnormal AI:</strong></li></ul><p><em>OpenAI crossing this threshold deserves attention. Credit where it's due, they're handling it responsibly by restricting Astra's advanced cyber capability to a small coalition rather than releasing it broadly.But this isn't one company's problem to contain.</em></p><p><em>Once a model can find and exploit unknown flaws without a human in the loop, that capability doesn't stay exclusive for long. Open-weight and modified models typically trail the frontier by only months, and that's the reality defenders have to plan around now.</em></p><div><blockquote><p>Static, signature-based defences were built for attacks that repeat. They weren't built for an adversary that generates a new one every time.</p></blockquote></div><p><em>Static, signature-based defences were built for attacks that repeat. They weren't built for an adversary that generates a new one every time. Defenders need the same shift, systems that learn what normal looks like for every identity, human, machine, or AI agent, and flag and contain the moment something deviates, at machine speed.</em></p><p><em>The window to build that is open now. It won't stay that way once this capability is common instead of rare.</em></p><ul><li><strong>Raghu Nandakumara, VP of Industry Strategy at Illumio:</strong></li></ul><p><em>With the Astra announcement, OpenAI is doubling down on monitoring the model's own behaviour – a response to the model "breakouts" seen over the past few months.</em></p><div><blockquote><p>The goal is to catch a model going rogue mid-task, not just stop it being misused at the outset.</p></blockquote></div><p><em>When Anthropic announced Claude Mythos Preview, the core concern was the model falling into the wrong hands. OpenAI's answer goes further adding guardrails around the model's own reasoning and actions, regardless of the user's intent. The goal is to catch a model going rogue mid-task, not just stop it being misused at the outset.</em></p><p><em>The rest of this announcement can be summarised as ‘we have a new frontier model, and it’s more capable than the last one’.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google patches multiple browser bugs including one that was under active exploitation — so update now ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Google released Chrome 152.0.7977.82/.83 for Windows, Mac, and Linux</strong></li><li><strong>Patch fixes 12 flaws, including zero‑day CVE‑2026‑85046 (type confusion in V8)</strong></li><li><strong>Sixth Chrome zero‑day this year; Chromium browsers also affected, update urged immediately</strong></li></ul><p>Google has released a new version of its Chrome <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> for Windows, Mac, and Linux, fixing a dozen of vulnerabilities. Among them is a high-severity flaw that is being actively exploited in the wild.</p><p>In a security advisory published on the Google blog on September 3, the search engine company said Chrome’s newest version is now 152.0.7977.82/.83 for Windows and Mac, and 152.0.7977.82 for Linux.</p><p>Rollout is expected to be gradual, so make sure to check if you already received it. Most of the time the update is automatic and instant and if you’re not certain, tap the three vertical dots in the top-right corner of the browser and choose Help. Navigate to About Google Chrome and there you will find the version number. </p><h2 id="running-malicious-code-remotely">Running malicious code remotely</h2><p>This patch fixes a total of 12 vulnerabilities, most of which are graded as high severity. Among them is a “type confusion in V8” bug, discovered by security researcher Salvatore Gulizia.</p><p>For his effort, Gulizia was awarded $1,000. Apparently, this bug is being actively leveraged in real-life attacks, although Google (as usual) decided not to share the juicy details until the majority of browsers are protected.</p><p>The vulnerability is tracked as CVE-2026-85046. On the National Vulnerability Database (NVD), it is described as a “type confusion in V8 in Google Chrome [that allows] a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.”</p><p>V8 is Chrome’s JavaScript engine which allows web apps and interactive websites to run in the browser. Those interested in the technical breakdown of the vulnerability can find it on <a href="https://serotav.github.io/Writeups/v8/when-sorting-leads-to-confusion/" target="_blank" rel="nofollow">Guzlia’s blog</a>.</p><p>You can find the full list of fixed vulnerabilities on <a href="https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html" target="_blank" rel="nofollow">this link</a>. </p><p>This is the sixth zero-day Google fixed in Chrome since the start of the year. It also affects other browsers built on Chromium, so if you’re running Edge, Brave, Opera, or Vivaldi, make sure to update to the latest version as soon as possible. </p><p><em>Via </em><a href="https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/google-patches-multiple-browser-bugs-including-one-that-was-under-active-exploitation-so-update-now</link>
                                                                            <description>
                            <![CDATA[ Google did not share the details about the bug being actively used. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">PWhL6n866rriJHC4C6KTWa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 19:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg">
                                                            <media:credit><![CDATA[Tada Images / Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:description>                                                            <media:text><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:text>
                                <media:title type="plain"><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Google released Chrome 152.0.7977.82/.83 for Windows, Mac, and Linux</strong></li><li><strong>Patch fixes 12 flaws, including zero‑day CVE‑2026‑85046 (type confusion in V8)</strong></li><li><strong>Sixth Chrome zero‑day this year; Chromium browsers also affected, update urged immediately</strong></li></ul><p>Google has released a new version of its Chrome <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> for Windows, Mac, and Linux, fixing a dozen of vulnerabilities. Among them is a high-severity flaw that is being actively exploited in the wild.</p><p>In a security advisory published on the Google blog on September 3, the search engine company said Chrome’s newest version is now 152.0.7977.82/.83 for Windows and Mac, and 152.0.7977.82 for Linux.</p><p>Rollout is expected to be gradual, so make sure to check if you already received it. Most of the time the update is automatic and instant and if you’re not certain, tap the three vertical dots in the top-right corner of the browser and choose Help. Navigate to About Google Chrome and there you will find the version number. </p><h2 id="running-malicious-code-remotely">Running malicious code remotely</h2><p>This patch fixes a total of 12 vulnerabilities, most of which are graded as high severity. Among them is a “type confusion in V8” bug, discovered by security researcher Salvatore Gulizia.</p><p>For his effort, Gulizia was awarded $1,000. Apparently, this bug is being actively leveraged in real-life attacks, although Google (as usual) decided not to share the juicy details until the majority of browsers are protected.</p><p>The vulnerability is tracked as CVE-2026-85046. On the National Vulnerability Database (NVD), it is described as a “type confusion in V8 in Google Chrome [that allows] a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.”</p><p>V8 is Chrome’s JavaScript engine which allows web apps and interactive websites to run in the browser. Those interested in the technical breakdown of the vulnerability can find it on <a href="https://serotav.github.io/Writeups/v8/when-sorting-leads-to-confusion/" target="_blank" rel="nofollow">Guzlia’s blog</a>.</p><p>You can find the full list of fixed vulnerabilities on <a href="https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html" target="_blank" rel="nofollow">this link</a>. </p><p>This is the sixth zero-day Google fixed in Chrome since the start of the year. It also affects other browsers built on Chromium, so if you’re running Edge, Brave, Opera, or Vivaldi, make sure to update to the latest version as soon as possible. </p><p><em>Via </em><a href="https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI warns about how good Astra model is at cracking cybersecurity, releases it anyway because it took 'years of research and big bets' ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>OpenAI rolled out GPT‑6 Astra, its most advanced AI, with “critical” cyber capabilities</strong></li><li><strong>Astra can autonomously find and exploit unknown flaws; release limited to vetted Daybreak participants</strong></li><li><strong>Staggered rollout sparked user frustration; Altman apologized, promising broader access soon</strong></li></ul><p>OpenAI has begun rolling out <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">GPT-6 Astra</a>, its latest and most capable artificial intelligence model. </p><p>In an announcement published on its website, OpenAI said Astra represents a “significant step up in cyber capabilities”, meeting the company’s “Critical” threshold.</p><p>This threshold, the company explained, means that under the right circumstances, the tool can find “previously unknown security flaws and develop new ways to exploit them across many well-protected systems without a person guiding each step.”</p><h2 id="apologies-for-a-messy-rollout">Apologies for a messy rollout</h2><p>OpenAI also said Astra improves on functions such as computer use, software engineering, and science, and that it should be better at staying oriented, compared to previous versions.</p><p>Just like many of the previous models, Astra’s release has been marred with controversy. Roughly a month ago, OpenAI said the model’s “critical” cybersecurity capabilities prompted it to <a href="https://www.channelnewsasia.com/business/openai-flags-possible-critical-cybersecurity-risk-in-upcoming-model-tightens-controls-6306796" target="_blank" rel="nofollow">pause some internal development</a> and trigger safety protocols.</p><p>In response to early findings, the company scaled up certain security controls and even paused activities that do not meet its newly established security requirements. </p><p>It now decided it was time to release the model, but still not to the general public. Instead, it opted for a staggered release, giving it first to a limited group of companies participating in the Daybreak program, a cybersecurity initiative that gives vetted organizations (cybersecurity and otherwise) specialized AI tools for vulnerability research and threat detection. </p><p>This did not sit well with many ChatGPT users, especially those paying a monthly subscription. As <a href="https://www.theverge.com/ai-artificial-intelligence/990060/altman-apologizes-messy-astra-rollout" target="_blank" rel="nofollow"><em>The Verge</em></a> reported, CEO Sam Altman was apologizing, mere hours after launch, for the “messy rollout” of Astra.</p><p>Initially, all Plus, Pro, Business, and Enterprise users were supposed to gain access to Astra, as well as those accessing through OpenAI API, Microsoft Azure, and AWS Bedrock. </p><p>“We are working towards getting Astra in everyone’s hands as quickly as we can,” Altman said on X. “I know it is frustrating and I appreciate the patience. It should be quick.”</p><p><em>Via </em><a href="https://www.cnbc.com/2026/09/03/open-ai-astra-gpt-6-cyber.html" target="_blank" rel="nofollow"><em>CNBC</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/openai-warns-about-how-good-astra-model-is-at-cracking-cybersecurity-releases-it-anyway-because-it-took-years-of-research-and-big-bets</link>
                                                                            <description>
                            <![CDATA[ GPT-6 Astra was paused a month ago for triggering safety protocols and now it's being slowly rolled out. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">JV7weBTmHEVs8GrqeHEVAE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 18:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[ChatGPT]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[OpenAI]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg">
                                                            <media:credit><![CDATA[OpenAI]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[OpenAI GPT-6 Astra]]></media:description>                                                            <media:text><![CDATA[OpenAI GPT-6 Astra]]></media:text>
                                <media:title type="plain"><![CDATA[OpenAI GPT-6 Astra]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>OpenAI rolled out GPT‑6 Astra, its most advanced AI, with “critical” cyber capabilities</strong></li><li><strong>Astra can autonomously find and exploit unknown flaws; release limited to vetted Daybreak participants</strong></li><li><strong>Staggered rollout sparked user frustration; Altman apologized, promising broader access soon</strong></li></ul><p>OpenAI has begun rolling out <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">GPT-6 Astra</a>, its latest and most capable artificial intelligence model. </p><p>In an announcement published on its website, OpenAI said Astra represents a “significant step up in cyber capabilities”, meeting the company’s “Critical” threshold.</p><p>This threshold, the company explained, means that under the right circumstances, the tool can find “previously unknown security flaws and develop new ways to exploit them across many well-protected systems without a person guiding each step.”</p><h2 id="apologies-for-a-messy-rollout">Apologies for a messy rollout</h2><p>OpenAI also said Astra improves on functions such as computer use, software engineering, and science, and that it should be better at staying oriented, compared to previous versions.</p><p>Just like many of the previous models, Astra’s release has been marred with controversy. Roughly a month ago, OpenAI said the model’s “critical” cybersecurity capabilities prompted it to <a href="https://www.channelnewsasia.com/business/openai-flags-possible-critical-cybersecurity-risk-in-upcoming-model-tightens-controls-6306796" target="_blank" rel="nofollow">pause some internal development</a> and trigger safety protocols.</p><p>In response to early findings, the company scaled up certain security controls and even paused activities that do not meet its newly established security requirements. </p><p>It now decided it was time to release the model, but still not to the general public. Instead, it opted for a staggered release, giving it first to a limited group of companies participating in the Daybreak program, a cybersecurity initiative that gives vetted organizations (cybersecurity and otherwise) specialized AI tools for vulnerability research and threat detection. </p><p>This did not sit well with many ChatGPT users, especially those paying a monthly subscription. As <a href="https://www.theverge.com/ai-artificial-intelligence/990060/altman-apologizes-messy-astra-rollout" target="_blank" rel="nofollow"><em>The Verge</em></a> reported, CEO Sam Altman was apologizing, mere hours after launch, for the “messy rollout” of Astra.</p><p>Initially, all Plus, Pro, Business, and Enterprise users were supposed to gain access to Astra, as well as those accessing through OpenAI API, Microsoft Azure, and AWS Bedrock. </p><p>“We are working towards getting Astra in everyone’s hands as quickly as we can,” Altman said on X. “I know it is frustrating and I appreciate the patience. It should be quick.”</p><p><em>Via </em><a href="https://www.cnbc.com/2026/09/03/open-ai-astra-gpt-6-cyber.html" target="_blank" rel="nofollow"><em>CNBC</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why did FulcrumSec hackers try to extort Manchester Airports Group, and what happens now the data is leaked? The experts weigh in ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Following the aftermath of the Manchester Airports Group cyberattack - <a href="https://www.techradar.com/pro/security/manchester-airports-hackers-just-posted-the-data-of-8-7-million-people-online-failed-extortion-attempt-triggers-data-dump-sale">where hackers made off with the data of 8.7 million people</a> - the hackers have now posted the entire database for sale on the dark web.</p><p>The group behind the attack, FulcrumSec, attempted to get Manchester Airports Group (MAG) to pay for the security of the database, promising that it wouldn’t be released if the company paid a settlement. But as all companies should do when faced with extortion, MAG didn’t play ball.</p><p>Now FulcrumSec wants to try and maximise the damage of the cyberattack, and has listed the database containing email addresses, phone numbers, vehicle registrations and postcodes online in the hopes a fellow hacking group will find value in the data.</p><h2 id="what-happens-when-extortion-fails-and-why-didn-t-mag-pay">What happens when extortion fails, and why didn’t MAG pay?</h2><p>In the past, when companies faced ransomware attacks or data breaches, they would sometimes quietly pay the hackers for their silence. </p><p>Companies feared serious reputational harm and loss of business would cost more in the long run than the perpetrators were asking for. But this created an incentive for hackers to carry out more attacks.</p><p>After all, if companies aren’t kicking up a fuss about being hacked or reporting the attack to the authorities, hacking groups can launch more attacks on other companies that are completely unaware of their tactics.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9-1920-80.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>In order to counter this, authorities and cyber experts from around the world issued guidance that under no circumstances should companies pay for the safe return of their data. By removing the incentive from ransomware attacks and data breaches, the hope is that hackers will get bored or not see enough ROI, and therefore stop.</p><p>But the 500GB database of data on over 8.7 million people is ripe pickings for other cybercriminals looking to launch highly specific phishing attacks or scam campaigns. While FulcrumSec may not make any money from the attack, they can seriously enhance the damage of the attack by offering the data for free for others to use.</p><p>A successful scam or phishing attack can steal banking and financial details, allowing other groups to steal even more money off the back of the attack.</p><h3 class="article-body__section" id="section-expert-perspectives-on-mag-extortion-and-customer-data"><span>Expert perspectives on MAG extortion and customer data</span></h3><ul><li><strong>Dray Agha, senior manager of security operations at Huntress:</strong></li></ul><p><em>While Manchester Airports Group followed official guidance by refusing to pay the ransom, the release of 8.7 million records creates an immediate risk for passengers.</em></p><div><blockquote><p>The release of 8.7 million records creates an immediate risk for passengers</p></blockquote></div><p><em>We expect other criminals to use this freely available database of vehicle registrations, postcodes and contact details to craft highly convincing phishing attacks.</em></p><p><em>Anyone who has used parking, lounges or Wi-Fi at these airports must treat unexpected messages about their travel with extreme caution.</em></p><ul><li><strong>Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress</strong></li></ul><p><em>The "free release" model is deliberately designed to maximise harm and reputational damage as a warning to the next target. </em></p><div><blockquote><p>It's a marketing campaign aimed at every other organisation watching</p></blockquote></div><p><em>Publishing almost nine million records for free isn't just punishment for MAG it's a marketing campaign aimed at every other organisation watching.</em></p><p><em>Pay up, or your customers' data gets handed to every fraudster and scammer on the internet at no cost. Refusing to pay a ransom is the right call. But nearly nine million people are now paying a different price for a decision that was never theirs to make.</em></p><ul><li><strong>Danny Jenkins, Co Founder & CEO at ThreatLocker</strong></li></ul><p><em>Unfortunately, once data is made public, it can’t be hidden again. The most important thing consumers can do is focus on basic cyber hygiene. Use a unique password for every website, learn how to identify phishing scams, and monitor your credit report.</em></p><div><blockquote><p>Be highly suspicious of emails that create a sense of urgency, offer something that seems too good to be true, or ask you to reset your password.</p></blockquote></div><p><em>Be highly suspicious of emails that create a sense of urgency, offer something that seems too good to be true, or ask you to reset your password.</em></p><p><em>When in doubt, look up the phone number for the alleged sender yourself, rather than using a number provided in the email, and call to confirm whether the communication is genuine.</em></p><ul><li><strong>Brian Higgins, security specialist at Comparitech:</strong></li></ul><p><em>Whilst the airports breached in this attack don't appear to have had any financial data compromised the risk to affected or associated customers is very real. With so much other information freely available in the wild it is vital that airport users stay highly vigilant for some time to come.</em></p><div><blockquote><p>Research advice from trusted sources like the NCA or Information Commissioner and share it with your family and friends.</p></blockquote></div><p><em>Any and all unsolicited contact; whether online, by telephone or even home visit approaches, should be viewed as suspicious. Never engage until you've taken time to check credentials/veracity etc.</em></p><p><em>Research advice from trusted sources like the NCA or Information Commissioner and share it with your family and friends. Look for ways to increase digital and physical security like two factor authentication on Apps and devices or Smart Home tech. </em></p><p><em>When this breach was first reported by the Manchester Evening News the comments were quite telling. Affected parties were quick to identify potential vulnerabilities over and above the breach of financial and banking details. </em></p><p><em>Home addresses, vehicle registrations and time spent away from home all add up to some excellent opportunities for criminal exploitation, not to mention the usual follow-up phishing campaigns common in this type of incident.</em></p><p><em>As AI makes data aggregation swift and easy consumers are waking up to the fact that criminals can monetise successful breaches in increasingly inventive ways. It’s no longer enough for data owning organisations to advise post-attack vigilance and turn to their backups.</em></p><p><em>Victim communities rightly expect better protected networks and systems over and above established norms. As the marketplace grows less fearful and more angry when breaches are made public we may see more emphasis on cyber crime prevention which can only be a good thing.</em></p><ul><li><strong>Denis Calderone, CTO at Suzu Labs:</strong></li></ul><p><em>The 8.7 million number is attention-grabbing, but it deserves some context. MAG has confirmed that the vast majority of those records are email addresses collected through airport WiFi sign-ups. </em></p><p><em>A much smaller subset includes phone numbers, vehicle registrations, and postcodes from customers who actually completed parking or lounge bookings.</em></p><div><blockquote><p>What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG's network first.</p></blockquote></div><p><em>No payment data, no passwords, no passport information. So despite this affecting airports, which is obviously a sensitive subject, the actual data sensitivity for most affected individuals is relatively low.</em></p><p><em>What's more interesting to us from a technical standpoint is the attack path. MAG told The Register that attackers compromised one of their internal systems and then went on to steal files from a database hosted by a third party. That's a pivot upstream into a data provider, not downstream into operational systems.</em></p><p><em>What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG's network first. That distinction matters for understanding where detection controls failed and who was responsible for monitoring the egress.</em></p><p><em>The UK's Civil Aviation Authority has a Cyber Assessment Framework for Aviation, developed with the NCSC, that mandates strict separation between IT systems and operational technology.</em></p><p><em>We don't know whether MAG was formally operating under that framework at the time of this incident, but I would be very interested to find out. Because the segmentation appears to have held here. Flight operations, baggage handling, terminal systems, etc., all were unaffected. </em></p><p><em>The lateral movement went upstream toward a data provider, not downstream toward the systems that keep planes in the air.</em></p><ul><li><strong>Seemant Sehgal, CEO and Founder at BreachLock:</strong></li></ul><p><em>This data was initially collected because passengers needed a login, and somewhere along the way, the sensitivity of what was accumulating in that database stopped getting the same scrutiny as the network itself.</em></p><div><blockquote><p>Whoever held it for ransom understood its value better than the organization storing it did</p></blockquote></div><p><em>Vehicle registration details, postcodes, and contact information across three major airports are a profiling dataset, and whoever held it for ransom understood its value better than the organization storing it did.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/why-did-fulcrumsec-hackers-try-to-extort-manchester-airports-group-and-what-happens-now-the-data-is-leaked-the-experts-weigh-in</link>
                                                                            <description>
                            <![CDATA[ After hackers failed to extort Manchester Airports Group and posted the data of nearly 9 million people online, we asked the experts what's really going on. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fRCxPaa9De9wPUPVGxjDbh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RYNpvpkwHbue2Dnhv3oLpL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 14:57:01 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RYNpvpkwHbue2Dnhv3oLpL-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Airport]]></media:description>                                                            <media:text><![CDATA[Airport]]></media:text>
                                <media:title type="plain"><![CDATA[Airport]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RYNpvpkwHbue2Dnhv3oLpL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Following the aftermath of the Manchester Airports Group cyberattack - <a href="https://www.techradar.com/pro/security/manchester-airports-hackers-just-posted-the-data-of-8-7-million-people-online-failed-extortion-attempt-triggers-data-dump-sale">where hackers made off with the data of 8.7 million people</a> - the hackers have now posted the entire database for sale on the dark web.</p><p>The group behind the attack, FulcrumSec, attempted to get Manchester Airports Group (MAG) to pay for the security of the database, promising that it wouldn’t be released if the company paid a settlement. But as all companies should do when faced with extortion, MAG didn’t play ball.</p><p>Now FulcrumSec wants to try and maximise the damage of the cyberattack, and has listed the database containing email addresses, phone numbers, vehicle registrations and postcodes online in the hopes a fellow hacking group will find value in the data.</p><h2 id="what-happens-when-extortion-fails-and-why-didn-t-mag-pay">What happens when extortion fails, and why didn’t MAG pay?</h2><p>In the past, when companies faced ransomware attacks or data breaches, they would sometimes quietly pay the hackers for their silence. </p><p>Companies feared serious reputational harm and loss of business would cost more in the long run than the perpetrators were asking for. But this created an incentive for hackers to carry out more attacks.</p><p>After all, if companies aren’t kicking up a fuss about being hacked or reporting the attack to the authorities, hacking groups can launch more attacks on other companies that are completely unaware of their tactics.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9-1920-80.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>In order to counter this, authorities and cyber experts from around the world issued guidance that under no circumstances should companies pay for the safe return of their data. By removing the incentive from ransomware attacks and data breaches, the hope is that hackers will get bored or not see enough ROI, and therefore stop.</p><p>But the 500GB database of data on over 8.7 million people is ripe pickings for other cybercriminals looking to launch highly specific phishing attacks or scam campaigns. While FulcrumSec may not make any money from the attack, they can seriously enhance the damage of the attack by offering the data for free for others to use.</p><p>A successful scam or phishing attack can steal banking and financial details, allowing other groups to steal even more money off the back of the attack.</p><h3 class="article-body__section" id="section-expert-perspectives-on-mag-extortion-and-customer-data"><span>Expert perspectives on MAG extortion and customer data</span></h3><ul><li><strong>Dray Agha, senior manager of security operations at Huntress:</strong></li></ul><p><em>While Manchester Airports Group followed official guidance by refusing to pay the ransom, the release of 8.7 million records creates an immediate risk for passengers.</em></p><div><blockquote><p>The release of 8.7 million records creates an immediate risk for passengers</p></blockquote></div><p><em>We expect other criminals to use this freely available database of vehicle registrations, postcodes and contact details to craft highly convincing phishing attacks.</em></p><p><em>Anyone who has used parking, lounges or Wi-Fi at these airports must treat unexpected messages about their travel with extreme caution.</em></p><ul><li><strong>Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress</strong></li></ul><p><em>The "free release" model is deliberately designed to maximise harm and reputational damage as a warning to the next target. </em></p><div><blockquote><p>It's a marketing campaign aimed at every other organisation watching</p></blockquote></div><p><em>Publishing almost nine million records for free isn't just punishment for MAG it's a marketing campaign aimed at every other organisation watching.</em></p><p><em>Pay up, or your customers' data gets handed to every fraudster and scammer on the internet at no cost. Refusing to pay a ransom is the right call. But nearly nine million people are now paying a different price for a decision that was never theirs to make.</em></p><ul><li><strong>Danny Jenkins, Co Founder & CEO at ThreatLocker</strong></li></ul><p><em>Unfortunately, once data is made public, it can’t be hidden again. The most important thing consumers can do is focus on basic cyber hygiene. Use a unique password for every website, learn how to identify phishing scams, and monitor your credit report.</em></p><div><blockquote><p>Be highly suspicious of emails that create a sense of urgency, offer something that seems too good to be true, or ask you to reset your password.</p></blockquote></div><p><em>Be highly suspicious of emails that create a sense of urgency, offer something that seems too good to be true, or ask you to reset your password.</em></p><p><em>When in doubt, look up the phone number for the alleged sender yourself, rather than using a number provided in the email, and call to confirm whether the communication is genuine.</em></p><ul><li><strong>Brian Higgins, security specialist at Comparitech:</strong></li></ul><p><em>Whilst the airports breached in this attack don't appear to have had any financial data compromised the risk to affected or associated customers is very real. With so much other information freely available in the wild it is vital that airport users stay highly vigilant for some time to come.</em></p><div><blockquote><p>Research advice from trusted sources like the NCA or Information Commissioner and share it with your family and friends.</p></blockquote></div><p><em>Any and all unsolicited contact; whether online, by telephone or even home visit approaches, should be viewed as suspicious. Never engage until you've taken time to check credentials/veracity etc.</em></p><p><em>Research advice from trusted sources like the NCA or Information Commissioner and share it with your family and friends. Look for ways to increase digital and physical security like two factor authentication on Apps and devices or Smart Home tech. </em></p><p><em>When this breach was first reported by the Manchester Evening News the comments were quite telling. Affected parties were quick to identify potential vulnerabilities over and above the breach of financial and banking details. </em></p><p><em>Home addresses, vehicle registrations and time spent away from home all add up to some excellent opportunities for criminal exploitation, not to mention the usual follow-up phishing campaigns common in this type of incident.</em></p><p><em>As AI makes data aggregation swift and easy consumers are waking up to the fact that criminals can monetise successful breaches in increasingly inventive ways. It’s no longer enough for data owning organisations to advise post-attack vigilance and turn to their backups.</em></p><p><em>Victim communities rightly expect better protected networks and systems over and above established norms. As the marketplace grows less fearful and more angry when breaches are made public we may see more emphasis on cyber crime prevention which can only be a good thing.</em></p><ul><li><strong>Denis Calderone, CTO at Suzu Labs:</strong></li></ul><p><em>The 8.7 million number is attention-grabbing, but it deserves some context. MAG has confirmed that the vast majority of those records are email addresses collected through airport WiFi sign-ups. </em></p><p><em>A much smaller subset includes phone numbers, vehicle registrations, and postcodes from customers who actually completed parking or lounge bookings.</em></p><div><blockquote><p>What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG's network first.</p></blockquote></div><p><em>No payment data, no passwords, no passport information. So despite this affecting airports, which is obviously a sensitive subject, the actual data sensitivity for most affected individuals is relatively low.</em></p><p><em>What's more interesting to us from a technical standpoint is the attack path. MAG told The Register that attackers compromised one of their internal systems and then went on to steal files from a database hosted by a third party. That's a pivot upstream into a data provider, not downstream into operational systems.</em></p><p><em>What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG's network first. That distinction matters for understanding where detection controls failed and who was responsible for monitoring the egress.</em></p><p><em>The UK's Civil Aviation Authority has a Cyber Assessment Framework for Aviation, developed with the NCSC, that mandates strict separation between IT systems and operational technology.</em></p><p><em>We don't know whether MAG was formally operating under that framework at the time of this incident, but I would be very interested to find out. Because the segmentation appears to have held here. Flight operations, baggage handling, terminal systems, etc., all were unaffected. </em></p><p><em>The lateral movement went upstream toward a data provider, not downstream toward the systems that keep planes in the air.</em></p><ul><li><strong>Seemant Sehgal, CEO and Founder at BreachLock:</strong></li></ul><p><em>This data was initially collected because passengers needed a login, and somewhere along the way, the sensitivity of what was accumulating in that database stopped getting the same scrutiny as the network itself.</em></p><div><blockquote><p>Whoever held it for ransom understood its value better than the organization storing it did</p></blockquote></div><p><em>Vehicle registration details, postcodes, and contact information across three major airports are a profiling dataset, and whoever held it for ransom understood its value better than the organization storing it did.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cisco patches three critical vulnerabilities as part of 'comprehensive internal security review' ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Cisco patched eight IOS XR flaws, including three critical (CVE‑2026‑20274, CVE‑2026‑20279, CVE‑2026‑20212)</strong></li><li><strong>Vulnerabilities allow unauthenticated exploitation, improper access control, and crafted input execution</strong></li><li><strong>No abuse reported; patches urged, with iACL workarounds for Nexus 9000 devices using Silicon One ASIC</strong></li></ul><p>Cisco patched eight vulnerabilities affecting its IOS XR operating system, including three critical-severity ones. It urged its customers to apply the patches as soon as possible, even though it stressed that there is no evidence any of these were abused in the wild.</p><p>The company detailed its findings in two advisories published on the same day - September 2.</p><p>In the first one, it disclosed seven vulnerabilities, including two critical-severity ones: CVE-2026-20274 and CVE-2026-20279. Both carry a severity rating of 9.8/10 (critical). The former is an improper control of a resource during its lifetime flaw - a network-based, low complexity, vulnerability that requires no authentication or user interaction to be exploited. The latter is described as an improper access control vulnerability that can lead to the same consequences.</p><h2 id="fixes-and-mitigations">Fixes and mitigations</h2><p>These flaws, along with five others, affect all releases of Cisco IOS XR Software, including Cisco IOS XR7 (LNT) Software, regardless of device configuration, the company explained. There are no available workarounds, and installing the provided patch is the only way to mitigate the risk.</p><p>The third flaw, disclosed in a separate advisory, is tracked as CVE-2026-20212. Successfully exploiting this one allows attackers to connect to an affected device and send crafted input that could be executed as code, without root privileges. “The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload,” Cisco explained. </p><p>This bug affects <a href="https://www.techradar.com/best/best-network-switches" target="_blank">Cisco Nexus 9000 Series Switches</a> if they include a Silicon One ASIC, the company stressed. A possible workaround is to use infrastructure access control lists (iACLs) to allow only required management and control plane traffic that is destined to the affected device. There is also the option of iACLs only being used to explicitly deny all TCP packets that are destined to a locally configured IP address with a destination port of 43210 or 43211.</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/09/04/cisco-searched-for-ios-xr-bugs-and-found-so-many-it-rolled-them-into-an-update-release/5294410" target="_blank" rel="nofollow"><em>The Register</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/cisco-patches-three-critical-vulnerabilities-as-part-of-comprehensive-internal-security-review</link>
                                                                            <description>
                            <![CDATA[ A total of eight flaws were fixed, none of which were exploited in the wild. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">NwtFJ9WsAyxAmKVur5Dra9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4vPx4qpVwRADJoMvv3gttX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 13:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4vPx4qpVwRADJoMvv3gttX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / Valriya Zankovych]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cisco]]></media:description>                                                            <media:text><![CDATA[Cisco]]></media:text>
                                <media:title type="plain"><![CDATA[Cisco]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4vPx4qpVwRADJoMvv3gttX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Cisco patched eight IOS XR flaws, including three critical (CVE‑2026‑20274, CVE‑2026‑20279, CVE‑2026‑20212)</strong></li><li><strong>Vulnerabilities allow unauthenticated exploitation, improper access control, and crafted input execution</strong></li><li><strong>No abuse reported; patches urged, with iACL workarounds for Nexus 9000 devices using Silicon One ASIC</strong></li></ul><p>Cisco patched eight vulnerabilities affecting its IOS XR operating system, including three critical-severity ones. It urged its customers to apply the patches as soon as possible, even though it stressed that there is no evidence any of these were abused in the wild.</p><p>The company detailed its findings in two advisories published on the same day - September 2.</p><p>In the first one, it disclosed seven vulnerabilities, including two critical-severity ones: CVE-2026-20274 and CVE-2026-20279. Both carry a severity rating of 9.8/10 (critical). The former is an improper control of a resource during its lifetime flaw - a network-based, low complexity, vulnerability that requires no authentication or user interaction to be exploited. The latter is described as an improper access control vulnerability that can lead to the same consequences.</p><h2 id="fixes-and-mitigations">Fixes and mitigations</h2><p>These flaws, along with five others, affect all releases of Cisco IOS XR Software, including Cisco IOS XR7 (LNT) Software, regardless of device configuration, the company explained. There are no available workarounds, and installing the provided patch is the only way to mitigate the risk.</p><p>The third flaw, disclosed in a separate advisory, is tracked as CVE-2026-20212. Successfully exploiting this one allows attackers to connect to an affected device and send crafted input that could be executed as code, without root privileges. “The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload,” Cisco explained. </p><p>This bug affects <a href="https://www.techradar.com/best/best-network-switches" target="_blank">Cisco Nexus 9000 Series Switches</a> if they include a Silicon One ASIC, the company stressed. A possible workaround is to use infrastructure access control lists (iACLs) to allow only required management and control plane traffic that is destined to the affected device. There is also the option of iACLs only being used to explicitly deny all TCP packets that are destined to a locally configured IP address with a destination port of 43210 or 43211.</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/09/04/cisco-searched-for-ios-xr-bugs-and-found-so-many-it-rolled-them-into-an-update-release/5294410" target="_blank" rel="nofollow"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI puts its money where its mouth is, offers $1 billion in AI credits to cyber defenders ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>OpenAI launched </strong><em><strong>Daybreak for Frontline Defenders</strong></em><strong>, offering $1B in credits for resource‑constrained security orgs</strong></li><li><strong>Priority goes to essential services, governments, banks, nonprofits, and open‑source maintainers</strong></li><li><strong>Initiative includes training, partnerships, and a water‑sector pilot with MS‑ISCA for local defenders</strong></li></ul><p>OpenAI is offering a billion dollars in credits to security organizations who want to use its Daybreak initiative but cannot afford it.</p><p>Daybreak is a cybersecurity program that provides vetted defenders with specialized <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI tools</a> and models. It was introduced in May this year, and later expanded into two tiers - Blue, and Red. Blue is the entry-level tier, providing a general-purpose model with custom-tailored safeguards. Red, on the other hand, offers a more purpose-trained cybersecurity model and almost no safeguards.</p><p>According to OpenAI, “thousands of defenders across 2,000 approved organizations and workspaces” already use Daybreak, including cybersecurity companies, defense organizations, and law enforcement agencies.</p><h2 id="who-gets-priority">Who gets priority?</h2><p>But these models cost money, and to make sure more businesses can access them, OpenAI announced, “Daybreak for Frontline Defenders”, a project where defenders can apply and receive credits for AI tokens. Even though the company announced it as a global initiative, it seems that US businesses will be the first to take advantage of it:</p><p>“OpenAI is committing $1 billion in subsidized Daybreak access to help resource-constrained cyber defenders, starting with the United States, put frontier AI to work, targeting it to be consumed over the next six months,” the company said in an announcement blog.</p><p>Businesses operating essential services such as water and wastewater systems, and electric grid operators, will get priority, OpenAI said. Then come state and local governments, community and regional banks, nonprofits, open-source maintainers, and then “other organizations with limited security resources.”</p><p>The subsidy is not just about using the models, though. OpenAI also said it will be increasing hands-on support for frontline defenders, training, and new partnerships. </p><p>On top of all that, OpenAI also announced a public sector, water-focused pilot with the Multi-State Information Sharing and Analysis Center (MS-ISCA) to train and support local, tribal, and territorial defenders.</p><p>“The pilot will pair Daybreak access with guided training and hands-on assistance for an initial group of public sector and water system defenders, helping them validate and prioritize findings, coordinate remediation, and develop a repeatable approach that can be expanded over time,” the announcement concluded.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/openai-puts-its-money-where-its-mouth-is-offers-usd1-billion-in-ai-credits-to-cyber-defenders</link>
                                                                            <description>
                            <![CDATA[ Want to use Daybreak but cannot afford it? You can now apply for a subsidy. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">t2rShP2332cHQ4q6yU7QA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6whQhAYA48xb8xVGQ3HNyX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 12:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6whQhAYA48xb8xVGQ3HNyX-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images/SPOA Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ChatGPT logo on a smartphone.]]></media:description>                                                            <media:text><![CDATA[ChatGPT logo on a smartphone.]]></media:text>
                                <media:title type="plain"><![CDATA[ChatGPT logo on a smartphone.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6whQhAYA48xb8xVGQ3HNyX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>OpenAI launched </strong><em><strong>Daybreak for Frontline Defenders</strong></em><strong>, offering $1B in credits for resource‑constrained security orgs</strong></li><li><strong>Priority goes to essential services, governments, banks, nonprofits, and open‑source maintainers</strong></li><li><strong>Initiative includes training, partnerships, and a water‑sector pilot with MS‑ISCA for local defenders</strong></li></ul><p>OpenAI is offering a billion dollars in credits to security organizations who want to use its Daybreak initiative but cannot afford it.</p><p>Daybreak is a cybersecurity program that provides vetted defenders with specialized <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI tools</a> and models. It was introduced in May this year, and later expanded into two tiers - Blue, and Red. Blue is the entry-level tier, providing a general-purpose model with custom-tailored safeguards. Red, on the other hand, offers a more purpose-trained cybersecurity model and almost no safeguards.</p><p>According to OpenAI, “thousands of defenders across 2,000 approved organizations and workspaces” already use Daybreak, including cybersecurity companies, defense organizations, and law enforcement agencies.</p><h2 id="who-gets-priority">Who gets priority?</h2><p>But these models cost money, and to make sure more businesses can access them, OpenAI announced, “Daybreak for Frontline Defenders”, a project where defenders can apply and receive credits for AI tokens. Even though the company announced it as a global initiative, it seems that US businesses will be the first to take advantage of it:</p><p>“OpenAI is committing $1 billion in subsidized Daybreak access to help resource-constrained cyber defenders, starting with the United States, put frontier AI to work, targeting it to be consumed over the next six months,” the company said in an announcement blog.</p><p>Businesses operating essential services such as water and wastewater systems, and electric grid operators, will get priority, OpenAI said. Then come state and local governments, community and regional banks, nonprofits, open-source maintainers, and then “other organizations with limited security resources.”</p><p>The subsidy is not just about using the models, though. OpenAI also said it will be increasing hands-on support for frontline defenders, training, and new partnerships. </p><p>On top of all that, OpenAI also announced a public sector, water-focused pilot with the Multi-State Information Sharing and Analysis Center (MS-ISCA) to train and support local, tribal, and territorial defenders.</p><p>“The pilot will pair Daybreak access with guided training and hands-on assistance for an initial group of public sector and water system defenders, helping them validate and prioritize findings, coordinate remediation, and develop a repeatable approach that can be expanded over time,” the announcement concluded.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ IT helpdesk impersonation hits Microsoft Teams once again, with the hackers hiding their activity within legitimate tools ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft warns of Teams‑based campaign where attackers impersonate IT staff</strong></li><li><strong>Victims tricked into granting remote access, leading to malware, lateral movement, and ransomware</strong></li><li><strong>Defenses: verify support contacts, train staff, harden Teams, and use Defender Safe Links/ZAP</strong></li></ul><p>Microsoft is warning about an ongoing hacking campaign that starts with a Teams message and ends with a ransomware infection and data theft.</p><p>In a new in-depth report published on the Microsoft blog, it was said that unnamed threat actors were reaching out to their targets at various enterprises via a <a href="https://www.techradar.com/best/best-online-collaboration-tools" target="_blank">Teams chat</a>, while impersonating IT staff.</p><p>They were coercing their victims into granting remote access via screen sharing or <a href="https://www.techradar.com/news/best-remote-desktop-software" target="_blank">remote monitoring and management tools</a> and once received, used their access to install malware loaders and various other implants.</p><h2 id="how-to-defend-against-teams-borne-phishing">How to defend against Teams-borne phishing</h2><p>The malware was just the first stage of the attack. Subsequent stages include host reconnaissance, security-product and virtualization discovery, and “periodic desktop screen capture”. In other words - mapping out the landscape and conducting espionage.</p><p>The crooks would then enumerate domain accounts, servers, and users, through native tools and Active Directory Service Interfaces (ADSI) queries and begin moving laterally.</p><p>The final step includes identifying and extracting valuable data, followed by a ransomware infection.</p><p>Microsoft does not name the perpetrators, and mostly refers to them as “threat actors”. It makes sense, since the “fake IT support via Teams” technique is being used by multiple groups at this moment. Russia’s Cozy Bear, FIN7, and Storm-1811 are probably the most obvious examples.</p><p>The world’s biggest extortionists - ShinyHunters - are also known to use Teams to trick victims into granting access, but this group rarely deploys an encryptor and instead just focuses on data exfiltration.</p><p>Whoever the attackers are, and whoever they’re after, one thing is for certain - the risk in the enterprise environment has never been greater. </p><p>That is why Microsoft advises reinforcing user education by establishing internal helpdesk authentication phrases, and by training employees to recognize external-tenant indicators.</p><p>The company also urges enterprises to verify unsolicited support contact, and to harden Microsoft Teams and email against social engineering. “Use Microsoft Defender for Office 365 with Safe Links and Zero-hour auto purge (ZAP) so malicious messages and URLs are neutralized at time of click and removed after delivery,” Microsoft urges.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/it-helpdesk-impersonation-hits-microsoft-teams-once-again-with-the-hackers-hiding-their-activity-within-legitimate-tools</link>
                                                                            <description>
                            <![CDATA[ Microsoft is warning about an ongoing scam campaign starting in Teams. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QAnBBRikxHpmReRRcBoNhU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/D4YBMfcEsNT7BhaNJJgm2A-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 16:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/D4YBMfcEsNT7BhaNJJgm2A-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image Credit: Pexels]]></media:description>                                                            <media:text><![CDATA[Collaboration in an office.]]></media:text>
                                <media:title type="plain"><![CDATA[Collaboration in an office.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/D4YBMfcEsNT7BhaNJJgm2A-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft warns of Teams‑based campaign where attackers impersonate IT staff</strong></li><li><strong>Victims tricked into granting remote access, leading to malware, lateral movement, and ransomware</strong></li><li><strong>Defenses: verify support contacts, train staff, harden Teams, and use Defender Safe Links/ZAP</strong></li></ul><p>Microsoft is warning about an ongoing hacking campaign that starts with a Teams message and ends with a ransomware infection and data theft.</p><p>In a new in-depth report published on the Microsoft blog, it was said that unnamed threat actors were reaching out to their targets at various enterprises via a <a href="https://www.techradar.com/best/best-online-collaboration-tools" target="_blank">Teams chat</a>, while impersonating IT staff.</p><p>They were coercing their victims into granting remote access via screen sharing or <a href="https://www.techradar.com/news/best-remote-desktop-software" target="_blank">remote monitoring and management tools</a> and once received, used their access to install malware loaders and various other implants.</p><h2 id="how-to-defend-against-teams-borne-phishing">How to defend against Teams-borne phishing</h2><p>The malware was just the first stage of the attack. Subsequent stages include host reconnaissance, security-product and virtualization discovery, and “periodic desktop screen capture”. In other words - mapping out the landscape and conducting espionage.</p><p>The crooks would then enumerate domain accounts, servers, and users, through native tools and Active Directory Service Interfaces (ADSI) queries and begin moving laterally.</p><p>The final step includes identifying and extracting valuable data, followed by a ransomware infection.</p><p>Microsoft does not name the perpetrators, and mostly refers to them as “threat actors”. It makes sense, since the “fake IT support via Teams” technique is being used by multiple groups at this moment. Russia’s Cozy Bear, FIN7, and Storm-1811 are probably the most obvious examples.</p><p>The world’s biggest extortionists - ShinyHunters - are also known to use Teams to trick victims into granting access, but this group rarely deploys an encryptor and instead just focuses on data exfiltration.</p><p>Whoever the attackers are, and whoever they’re after, one thing is for certain - the risk in the enterprise environment has never been greater. </p><p>That is why Microsoft advises reinforcing user education by establishing internal helpdesk authentication phrases, and by training employees to recognize external-tenant indicators.</p><p>The company also urges enterprises to verify unsolicited support contact, and to harden Microsoft Teams and email against social engineering. “Use Microsoft Defender for Office 365 with Safe Links and Zero-hour auto purge (ZAP) so malicious messages and URLs are neutralized at time of click and removed after delivery,” Microsoft urges.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Clicking 'Allow' on a Google and Microsoft permission screens could give hackers access to your entire account, FBI warns ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>FBI warns of rising </strong><em><strong>OAuth consent phishing</strong></em><strong> attacks exploiting legitimate app permissions</strong></li><li><strong>Victims tricked into granting malicious apps access, enabling email reading and sending</strong></li><li><strong>Password changes don’t help; users must revoke tokens in app security settings</strong></li></ul><p>Hackers found a way to access your data, read your messages, and even send emails to your contacts, without ever needing your password or other login credentials. All they need from you is a single click on a completely legitimate, well-known platform.</p><p>The technique is called “OAuth consent phishing”. It’s been around for more than a year and it’s gotten popular to a point where even the FBI is taking note. Earlier this week, the law enforcement agency issued a new public service announcement, via its Internet Crime Complaint Center (IC3), warning Americans about the threat.</p><p>OAuth (Open Authorization) is an internet standard that allows users to give apps access to their account on another service, without giving the app their <a href="https://www.techradar.com/best/password-manager" target="_blank">password</a> for that service. For example, when users install a new app, they have the “Continue with Google” option. When they click it, they are asked if they allow the app to access their email. If they approve, Google gives that app a special access token, which allows the app to access the user’s Google account without ever seeing the password.</p><h2 id="pulling-off-an-oauth-attack">Pulling off an OAuth attack</h2><p>So, to pull off an OAuth attack, the threat actor must first trick Google (or Microsoft, or any other company providing the service) and get their (malicious) app registered on the platform. Then they would reach out to their target via instant messaging, while impersonating government officials, media, and other publicly known personalities, and sharing a link to what appears to be a document.</p><p>The link redirects the victim to a legitimate service (for example, Google), where they are asked to grant permissions to the malicious app. If they approve, the attackers gain access to their email accounts with which they can do almost anything.</p><p>To make matters worse, simply changing the password does not fix the issue. The only way to eliminate the threat is to revoke the access token that was given, which can be done in the application security settings.</p><p>The FBI did not say who the threat actors were or who they were targeting, other than they were “prominent victims”. Their family members were being targeted, as well.</p><p><em>Via </em><a href="https://cybernews.com/news/oauth-consent-phishing-fbi-warning-account-takeover/" target="_blank"><em>The Record</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/clicking-allow-on-a-google-and-microsoft-permission-screens-could-give-hackers-access-to-your-entire-account-fbi-warns</link>
                                                                            <description>
                            <![CDATA[ OAuth consent phishing is a thing and the FBI is worried. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pWbGg4PydfXBEVQetdDJBV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vg86aqqGf8Pqp6mnfQPGGf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 14:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vg86aqqGf8Pqp6mnfQPGGf-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay/Tumisu]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing]]></media:description>                                                            <media:text><![CDATA[Phishing]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vg86aqqGf8Pqp6mnfQPGGf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>FBI warns of rising </strong><em><strong>OAuth consent phishing</strong></em><strong> attacks exploiting legitimate app permissions</strong></li><li><strong>Victims tricked into granting malicious apps access, enabling email reading and sending</strong></li><li><strong>Password changes don’t help; users must revoke tokens in app security settings</strong></li></ul><p>Hackers found a way to access your data, read your messages, and even send emails to your contacts, without ever needing your password or other login credentials. All they need from you is a single click on a completely legitimate, well-known platform.</p><p>The technique is called “OAuth consent phishing”. It’s been around for more than a year and it’s gotten popular to a point where even the FBI is taking note. Earlier this week, the law enforcement agency issued a new public service announcement, via its Internet Crime Complaint Center (IC3), warning Americans about the threat.</p><p>OAuth (Open Authorization) is an internet standard that allows users to give apps access to their account on another service, without giving the app their <a href="https://www.techradar.com/best/password-manager" target="_blank">password</a> for that service. For example, when users install a new app, they have the “Continue with Google” option. When they click it, they are asked if they allow the app to access their email. If they approve, Google gives that app a special access token, which allows the app to access the user’s Google account without ever seeing the password.</p><h2 id="pulling-off-an-oauth-attack">Pulling off an OAuth attack</h2><p>So, to pull off an OAuth attack, the threat actor must first trick Google (or Microsoft, or any other company providing the service) and get their (malicious) app registered on the platform. Then they would reach out to their target via instant messaging, while impersonating government officials, media, and other publicly known personalities, and sharing a link to what appears to be a document.</p><p>The link redirects the victim to a legitimate service (for example, Google), where they are asked to grant permissions to the malicious app. If they approve, the attackers gain access to their email accounts with which they can do almost anything.</p><p>To make matters worse, simply changing the password does not fix the issue. The only way to eliminate the threat is to revoke the access token that was given, which can be done in the application security settings.</p><p>The FBI did not say who the threat actors were or who they were targeting, other than they were “prominent victims”. Their family members were being targeted, as well.</p><p><em>Via </em><a href="https://cybernews.com/news/oauth-consent-phishing-fbi-warning-account-takeover/" target="_blank"><em>The Record</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Thomson Reuters hit by cyberattack that saw court documents across 11 states accessed by a hacker ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Thomson Reuters confirmed March 2026 breach of its C‑Track court management system</strong></li><li><strong>Incident affected courts in 11 US states, Ontario, and the US Virgin Islands</strong></li><li><strong>No operational disruption; scope of exposed records still under investigation, no misuse reported yet</strong></li></ul><p>Thomson Reuters, the IT company behind the Reuters news agency, suffered a cyberattack a few months ago, exposing certain court documents to the attackers. In a brief announcement published earlier this week, it seems Thomson Reuters only noticed the intrusion now, months after it was already over.</p><p>Here is what happened: Thomson Reuters operates a court case-management system called C-Track. It is a tool used by different courts to manage things like cases, filings, hearings, and schedules. It is used by courts in several US states, the US Virgin Islands, as well as Ontario, Canada.</p><p>On June 30, 2026, Thomson Reuters detected unauthorized activity in one of its cloud environments, prompting an investigation which later determined that an unauthorized threat actor broke in and obtained some C-Track files. This happened in March 2026. </p><h2 id="investigation-underway">Investigation underway</h2><p>So far, the incident is confirmed to have taken place across 11 US states (Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, Wyoming), the U.S. Virgin Islands, and Ontario, Canada, exposing court records and personal information. Ontario's three Chief Justices confirmed it, as well, saying Thomson Reuters notified Ontario's Ministry of the Attorney General on July 23.</p><p>A more detailed investigation is currently underway, and all relevant authorities have been notified, it was said. At press time, Thomson Reuters did not yet determine exactly what information was accessed, or how many people were affected. The good news, however, is that there is currently no evidence of identity theft resulting from the incident, and there is no indication that systems handling court-related financial transactions were affected. </p><p>C-Track itself remains operational, as well. No threat actors have yet claimed responsibility for the attack or threatened to leak the files to the dark web.</p><p>"There has been no operational disruption to C-Track as a result of this incident," a Thomson Reuters spokesperson said. "Our products and services remain fully operational and are safe ​to continue to use. Independent ​cybersecurity experts assisted in ⁠the investigation and validated the remediation measures implemented."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/thomson-reuters-hit-by-cyberattack-that-saw-court-documents-across-11-states-accessed-by-a-hacker</link>
                                                                            <description>
                            <![CDATA[ A threat actor accessed C-Track files, compromised a cloud environment, and accessed court records across 11 states. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m8aiHByXqAA9YTCGGbFHxY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 14:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:description>                                                            <media:text><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:text>
                                <media:title type="plain"><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Thomson Reuters confirmed March 2026 breach of its C‑Track court management system</strong></li><li><strong>Incident affected courts in 11 US states, Ontario, and the US Virgin Islands</strong></li><li><strong>No operational disruption; scope of exposed records still under investigation, no misuse reported yet</strong></li></ul><p>Thomson Reuters, the IT company behind the Reuters news agency, suffered a cyberattack a few months ago, exposing certain court documents to the attackers. In a brief announcement published earlier this week, it seems Thomson Reuters only noticed the intrusion now, months after it was already over.</p><p>Here is what happened: Thomson Reuters operates a court case-management system called C-Track. It is a tool used by different courts to manage things like cases, filings, hearings, and schedules. It is used by courts in several US states, the US Virgin Islands, as well as Ontario, Canada.</p><p>On June 30, 2026, Thomson Reuters detected unauthorized activity in one of its cloud environments, prompting an investigation which later determined that an unauthorized threat actor broke in and obtained some C-Track files. This happened in March 2026. </p><h2 id="investigation-underway">Investigation underway</h2><p>So far, the incident is confirmed to have taken place across 11 US states (Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, Wyoming), the U.S. Virgin Islands, and Ontario, Canada, exposing court records and personal information. Ontario's three Chief Justices confirmed it, as well, saying Thomson Reuters notified Ontario's Ministry of the Attorney General on July 23.</p><p>A more detailed investigation is currently underway, and all relevant authorities have been notified, it was said. At press time, Thomson Reuters did not yet determine exactly what information was accessed, or how many people were affected. The good news, however, is that there is currently no evidence of identity theft resulting from the incident, and there is no indication that systems handling court-related financial transactions were affected. </p><p>C-Track itself remains operational, as well. No threat actors have yet claimed responsibility for the attack or threatened to leak the files to the dark web.</p><p>"There has been no operational disruption to C-Track as a result of this incident," a Thomson Reuters spokesperson said. "Our products and services remain fully operational and are safe ​to continue to use. Independent ​cybersecurity experts assisted in ⁠the investigation and validated the remediation measures implemented."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Only one in five UK CEOs say their cyber insurance will cover the full cost of a cyberattack ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>22% expect their policy to offer full coverage, 10% expect it to fall short</strong></li><li><strong>Data breaches and reputational damage are major concerns</strong></li><li><strong>Companies should look at finances before considering operational recovery readiness</strong></li></ul><p>New research from Cohesity has revealed that many UK businesses could be significantly overestimating the protection they get from cyber insurance policies, with just one in five (22%) British CEOs believing their policy would cover both the additional costs and lost revenue that an attack could lead to.</p><p>A third expect it would cover the additional costs only, another third believe their policy is only sufficient for lost revenue, and a further one in 10 did not expect it to cover either of the two categories.</p><p>The report's conclusion is that cyber insurance in its current state for many UK businesses is only enough to transfer some of the financial risk – but not enough to restore systems, data or operations.</p><h2 id="cyber-insurance-policies-don-39-t-provide-enough-cover">Cyber insurance policies don't provide enough cover</h2><p>According to the study of 100 CEOs from large enterprises, businesses expect a cyberattack to reduce their revenue by an average of around 15%, but many businesses lack a detailed understanding of how much an attack could actually end up costing them. As many as one in five (21%) haven't even conducted business impact modelling.</p><p>Among CEOs' biggest fears are data breaches (49%), brand and reputational damage (38%), high recovery costs (36%), revenue loss (34%) and production downtime (30%). They're all either financial concerns or incidents that could lead to financial loss, and yet it's clear that policies are unlikely to offer enough cover.</p><p>With many totally unaware of the potential impacts and the extent of their policy's cover, Cohesity urges businesses to start off with calculating financial exposure and understanding what their policy covers.</p><p>After that, they can go on to prove that critical systems can actually be recovered, because without an insurance payout, this would likely not be possible.</p><p>"Organisations must be able to identify the systems and data needed to keep the business operating, assigning clear responsibility for recovery decisions and regularly testing whether critical services can be restored securely," UK&I VP Fraser Hutchison explained.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/only-one-in-five-uk-ceos-say-their-cyber-insurance-will-cover-the-full-cost-of-a-cyberattack</link>
                                                                            <description>
                            <![CDATA[ New data has revealed that only one in five CEOs expect full coverage from their cyber insurance policy. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cZ3r6t6Y6FWyxjoMbJbwM5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 11:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg">
                                                            <media:credit><![CDATA[sarayut Thaneerat/ via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:description>                                                            <media:text><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:text>
                                <media:title type="plain"><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>22% expect their policy to offer full coverage, 10% expect it to fall short</strong></li><li><strong>Data breaches and reputational damage are major concerns</strong></li><li><strong>Companies should look at finances before considering operational recovery readiness</strong></li></ul><p>New research from Cohesity has revealed that many UK businesses could be significantly overestimating the protection they get from cyber insurance policies, with just one in five (22%) British CEOs believing their policy would cover both the additional costs and lost revenue that an attack could lead to.</p><p>A third expect it would cover the additional costs only, another third believe their policy is only sufficient for lost revenue, and a further one in 10 did not expect it to cover either of the two categories.</p><p>The report's conclusion is that cyber insurance in its current state for many UK businesses is only enough to transfer some of the financial risk – but not enough to restore systems, data or operations.</p><h2 id="cyber-insurance-policies-don-39-t-provide-enough-cover">Cyber insurance policies don't provide enough cover</h2><p>According to the study of 100 CEOs from large enterprises, businesses expect a cyberattack to reduce their revenue by an average of around 15%, but many businesses lack a detailed understanding of how much an attack could actually end up costing them. As many as one in five (21%) haven't even conducted business impact modelling.</p><p>Among CEOs' biggest fears are data breaches (49%), brand and reputational damage (38%), high recovery costs (36%), revenue loss (34%) and production downtime (30%). They're all either financial concerns or incidents that could lead to financial loss, and yet it's clear that policies are unlikely to offer enough cover.</p><p>With many totally unaware of the potential impacts and the extent of their policy's cover, Cohesity urges businesses to start off with calculating financial exposure and understanding what their policy covers.</p><p>After that, they can go on to prove that critical systems can actually be recovered, because without an insurance payout, this would likely not be possible.</p><p>"Organisations must be able to identify the systems and data needed to keep the business operating, assigning clear responsibility for recovery decisions and regularly testing whether critical services can be restored securely," UK&I VP Fraser Hutchison explained.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 2.8 million people affected by data breach at Baylor Genetics testing and diagnostic firm ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Baylor Genetics confirmed a June cyberattack affecting 2.8M patients and employees</strong></li><li><strong>Stolen data includes medical test results, insurance info, and some SSNs/financial details</strong></li><li><strong>Operations continued; no misuse seen yet, but no group has claimed responsibility</strong></li></ul><p>Baylor Genetics, a US-based clinical diagnostic laboratory, suffered a cyberattack in which it lost sensitive data on 2.8 million people - both patients and employees.</p><p>In a security update posted on its website earlier this week, the company said it spotted the intrusion in a “limited portion” of its IT environment on or around June 15. Subsequent investigation determined that both patients and employees have had their data stolen, including those who are not working at Baylor anymore.</p><p>For patients, crooks stole names, dates of birth, medical testing information, laboratory test results, and “potentially health insurance information, as well as Social Security number”. SSNs, Baylor Genetics stressed, were taken from a “very limited subset of patients”.</p><h2 id="no-attribution-yet">No attribution yet</h2><p>Regardless, fraudsters who know the details about medical testing and lab results have more than enough information to launch highly sophisticated, personalized phishing attacks that can lead to ransomware infections, business email compromise, and more. </p><p>For certain current and former employees, the attackers nabbed Social Security numbers, government-issued identification numbers, and financial account information, ideal for wire fraud. </p><p>In the security update, the company did not discuss the identity of the attackers, or the number of affected individuals. However, in a separate report filed with the US Department of Health and Human Services, Baylor reported the number of victims as 2,810,878. It added that at the time of publication, there was no evidence of confirmed <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a>, fraud, or misuse of personal information stolen in the attack. </p><p>It also said the incident did not impact its everyday operations which continued as usual. </p><p>Usually, data theft incidents like this one are followed by public disclosure from the perpetrators, who name-and-shame their victims in an attempt to get them to pay a ransom demand. So far, no threat actors claimed responsibility for this incident.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/2-8-million-people-affected-by-data-breach-at-baylor-genetics-testing-and-diagnostic-firm</link>
                                                                            <description>
                            <![CDATA[ Business continued as usual, although employees and patients lost plenty of sensitive data in the incident. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">asYqA3pQDCzhjPh7qcTguQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 11:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Laboratory]]></media:description>                                                            <media:text><![CDATA[Laboratory]]></media:text>
                                <media:title type="plain"><![CDATA[Laboratory]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Baylor Genetics confirmed a June cyberattack affecting 2.8M patients and employees</strong></li><li><strong>Stolen data includes medical test results, insurance info, and some SSNs/financial details</strong></li><li><strong>Operations continued; no misuse seen yet, but no group has claimed responsibility</strong></li></ul><p>Baylor Genetics, a US-based clinical diagnostic laboratory, suffered a cyberattack in which it lost sensitive data on 2.8 million people - both patients and employees.</p><p>In a security update posted on its website earlier this week, the company said it spotted the intrusion in a “limited portion” of its IT environment on or around June 15. Subsequent investigation determined that both patients and employees have had their data stolen, including those who are not working at Baylor anymore.</p><p>For patients, crooks stole names, dates of birth, medical testing information, laboratory test results, and “potentially health insurance information, as well as Social Security number”. SSNs, Baylor Genetics stressed, were taken from a “very limited subset of patients”.</p><h2 id="no-attribution-yet">No attribution yet</h2><p>Regardless, fraudsters who know the details about medical testing and lab results have more than enough information to launch highly sophisticated, personalized phishing attacks that can lead to ransomware infections, business email compromise, and more. </p><p>For certain current and former employees, the attackers nabbed Social Security numbers, government-issued identification numbers, and financial account information, ideal for wire fraud. </p><p>In the security update, the company did not discuss the identity of the attackers, or the number of affected individuals. However, in a separate report filed with the US Department of Health and Human Services, Baylor reported the number of victims as 2,810,878. It added that at the time of publication, there was no evidence of confirmed <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a>, fraud, or misuse of personal information stolen in the attack. </p><p>It also said the incident did not impact its everyday operations which continued as usual. </p><p>Usually, data theft incidents like this one are followed by public disclosure from the perpetrators, who name-and-shame their victims in an attempt to get them to pay a ransom demand. So far, no threat actors claimed responsibility for this incident.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Lords call for a 'kill switch' on powerful AI systems used in the United Kingdom ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>UK legislators propose “kill switch” laws to halt runaway AI, citing critical infrastructure risks</strong></li><li><strong>Lord Clement‑Jones and MP Alex Sobel push amendments and new bills, backed by ControlAI advocacy group</strong></li><li><strong>Similar efforts emerging in US</strong></li></ul><p>Sam Altman’s fear-based marketing for AI seems to have backfired, as now multiple legislators in the UK and elsewhere are calling for a “kill switch” law to be introduced.</p><p>According to the BBC, Liberal Democrats’ Lord Tim Clement-Jones proposed an amendment to the Cyber Security and Resilience Bill which would see the UK create a “vital safety net” to provide a “democratically accountable means to ‘halt a runaway system before it can compromise our critical national infrastructure’.” The capability would only be used as a last resort, Clement-Jones stressed. </p><p>The bill is currently being worked through in the UK Parliament, the BBC said.</p><h2 id="is-there-reason-to-worry">Is there reason to worry?</h2><p>But that’s not the only effort in the UK to put some reigns on <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI</a>. Apparently, Labour MP Alex Sobel plans to introduce an AI Security Bill later this month which, according to the BBC, would “effectively halt the development of superintelligent AI” and make the UK the first G7 country to do so. </p><p>The bill is supported by a campaign group called ControlAI, a UK-based nonprofit and advocacy organization focused on the risks posed by advanced AI. Its founder and CEO is Andrea Miotti, who previously worked at the AI safety company called Conjecture. Across the pond, US legislators are currently considering an AI Kill Switch Act as well, but the bill is still in very early stages of development.</p><p>Ever since the first ChatGPT model that was introduced in 2021, a debate has been raging whether or not AI will be net positive, or net negative, for humanity. While some argue that the discovery rivals the steam machine and that it will transform our lives beyond our wildest dreams, others are fearful of losing jobs, a collapsing economy, and a dystopian future devoid of humanity and emotion.</p><p>Marketing campaigns for ChatGPT and, in some measure, Claude, are not helping, either. Both companies have built models focused on cybersecurity which were advertised as “too dangerous” for the general public and instead were only given to a handful of organizations. Despite partial skepticism, many are worried that these models might severely disrupt the security of banking, critical infrastructure, and communications.</p><p><em>Via </em><a href="https://www.bbc.com/news/articles/cn9wv80j9w9o" target="_blank" rel="nofollow"><em>BBC</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/lords-call-for-a-kill-switch-on-powerful-ai-systems-used-in-the-united-kingdom</link>
                                                                            <description>
                            <![CDATA[ They believe the UK needs a "vital safety net" to only be used as a last resort. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iicNmwrFCpfHr7U9X2LbK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 10:10:53 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:description>                                                            <media:text><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:text>
                                <media:title type="plain"><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>UK legislators propose “kill switch” laws to halt runaway AI, citing critical infrastructure risks</strong></li><li><strong>Lord Clement‑Jones and MP Alex Sobel push amendments and new bills, backed by ControlAI advocacy group</strong></li><li><strong>Similar efforts emerging in US</strong></li></ul><p>Sam Altman’s fear-based marketing for AI seems to have backfired, as now multiple legislators in the UK and elsewhere are calling for a “kill switch” law to be introduced.</p><p>According to the BBC, Liberal Democrats’ Lord Tim Clement-Jones proposed an amendment to the Cyber Security and Resilience Bill which would see the UK create a “vital safety net” to provide a “democratically accountable means to ‘halt a runaway system before it can compromise our critical national infrastructure’.” The capability would only be used as a last resort, Clement-Jones stressed. </p><p>The bill is currently being worked through in the UK Parliament, the BBC said.</p><h2 id="is-there-reason-to-worry">Is there reason to worry?</h2><p>But that’s not the only effort in the UK to put some reigns on <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI</a>. Apparently, Labour MP Alex Sobel plans to introduce an AI Security Bill later this month which, according to the BBC, would “effectively halt the development of superintelligent AI” and make the UK the first G7 country to do so. </p><p>The bill is supported by a campaign group called ControlAI, a UK-based nonprofit and advocacy organization focused on the risks posed by advanced AI. Its founder and CEO is Andrea Miotti, who previously worked at the AI safety company called Conjecture. Across the pond, US legislators are currently considering an AI Kill Switch Act as well, but the bill is still in very early stages of development.</p><p>Ever since the first ChatGPT model that was introduced in 2021, a debate has been raging whether or not AI will be net positive, or net negative, for humanity. While some argue that the discovery rivals the steam machine and that it will transform our lives beyond our wildest dreams, others are fearful of losing jobs, a collapsing economy, and a dystopian future devoid of humanity and emotion.</p><p>Marketing campaigns for ChatGPT and, in some measure, Claude, are not helping, either. Both companies have built models focused on cybersecurity which were advertised as “too dangerous” for the general public and instead were only given to a handful of organizations. Despite partial skepticism, many are worried that these models might severely disrupt the security of banking, critical infrastructure, and communications.</p><p><em>Via </em><a href="https://www.bbc.com/news/articles/cn9wv80j9w9o" target="_blank" rel="nofollow"><em>BBC</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI is getting closer to being able to exploit OT, and that's very bad news for critical infrastructure ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Forescout researchers showed AI can port RCE exploits to PLCs, achieving DoS and shellcode execution</strong></li><li><strong>Effort required heavy researcher input and $500+ in API usage, making attacks impractical for criminals</strong></li><li><strong>Nation‑state actors remain a concern, as seen in Sandworm’s 2025 attack on Poland’s power grid</strong></li></ul><p>If you are worried cybercriminals will use Artificial Intelligence (AI) to automate the discovery and exploitation of zero-day vulnerabilities in Operational Technology (OT) such as Programmable Logic Controllers (PLC) you can sleep peacefully, at least for a little longer.</p><p>Recently, security researchers from Forescout set off on a simple mission - to understand if crooks can use AI to target the ever-increasing population of exposed industrial devices. The short answer is “yes, but it’s not yet worth the trouble”.</p><p>In their mission, they launched an experiment - to port a <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">remote code execution</a> (RCE) vulnerability from one PLC to another. These devices were built on closed-source software and thus were not that easy to manipulate, yet the experiment was a success.</p><h2 id="yes-but">Yes, but...</h2><p>Not only did they manage to trigger a Denial of Service (DoS) state that crashed the device but ended up with a working RCE capable of executing attacker-supplied ARM shellcode. </p><p>It is indeed a worrying development, but one that comes with a huge “but”:</p><p>“It required significant researcher input. The final RCE development stage consumed more than $500 in API usage. An attempt to extend the exploit beyond the initial RCE ultimately bricked the PLC,” the researchers said in the report.</p><p>“These limitations taught us valuable lessons about AI-assisted exploitation in OT. It can be done, but it’s not as easy as it sounds. For now, the difficulty, cost, and specialist expertise required are likely to make this kind of attack less attractive than easier alternatives.”</p><p>In other words, cybercriminals still have easier avenues to explore, and as long as that is the case, OT is relatively safe. What the report, unfortunately, does not discuss, is nation-state attackers with significant resources. For such attackers, industrial devices are a prime target, and spending $500+ in API usage is a drop in a bucket. We’ve already seen it back in 2025 when <a href="https://www.techradar.com/pro/security/researchers-say-russian-government-hackers-were-behind-attempted-poland-power-outage" target="_blank">Sandworm struck Poland’s electricity suppliers</a>.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/ai-is-getting-closer-to-being-able-to-exploit-ot-and-thats-very-bad-news-for-critical-infrastructure</link>
                                                                            <description>
                            <![CDATA[ The situation is not disastrous just yet, but it's definitely time to start paying attention, Forescout hints. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LgfjTgBPhj45riESsCbqxa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Dtd9CSn6K6jfEdpnzch4zj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 20:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Dtd9CSn6K6jfEdpnzch4zj-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Security padlock and circuit board to protect data]]></media:description>                                                            <media:text><![CDATA[Security padlock and circuit board to protect data]]></media:text>
                                <media:title type="plain"><![CDATA[Security padlock and circuit board to protect data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Dtd9CSn6K6jfEdpnzch4zj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Forescout researchers showed AI can port RCE exploits to PLCs, achieving DoS and shellcode execution</strong></li><li><strong>Effort required heavy researcher input and $500+ in API usage, making attacks impractical for criminals</strong></li><li><strong>Nation‑state actors remain a concern, as seen in Sandworm’s 2025 attack on Poland’s power grid</strong></li></ul><p>If you are worried cybercriminals will use Artificial Intelligence (AI) to automate the discovery and exploitation of zero-day vulnerabilities in Operational Technology (OT) such as Programmable Logic Controllers (PLC) you can sleep peacefully, at least for a little longer.</p><p>Recently, security researchers from Forescout set off on a simple mission - to understand if crooks can use AI to target the ever-increasing population of exposed industrial devices. The short answer is “yes, but it’s not yet worth the trouble”.</p><p>In their mission, they launched an experiment - to port a <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">remote code execution</a> (RCE) vulnerability from one PLC to another. These devices were built on closed-source software and thus were not that easy to manipulate, yet the experiment was a success.</p><h2 id="yes-but">Yes, but...</h2><p>Not only did they manage to trigger a Denial of Service (DoS) state that crashed the device but ended up with a working RCE capable of executing attacker-supplied ARM shellcode. </p><p>It is indeed a worrying development, but one that comes with a huge “but”:</p><p>“It required significant researcher input. The final RCE development stage consumed more than $500 in API usage. An attempt to extend the exploit beyond the initial RCE ultimately bricked the PLC,” the researchers said in the report.</p><p>“These limitations taught us valuable lessons about AI-assisted exploitation in OT. It can be done, but it’s not as easy as it sounds. For now, the difficulty, cost, and specialist expertise required are likely to make this kind of attack less attractive than easier alternatives.”</p><p>In other words, cybercriminals still have easier avenues to explore, and as long as that is the case, OT is relatively safe. What the report, unfortunately, does not discuss, is nation-state attackers with significant resources. For such attackers, industrial devices are a prime target, and spending $500+ in API usage is a drop in a bucket. We’ve already seen it back in 2025 when <a href="https://www.techradar.com/pro/security/researchers-say-russian-government-hackers-were-behind-attempted-poland-power-outage" target="_blank">Sandworm struck Poland’s electricity suppliers</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Over 5,000 Dropbox accounts have been hacked, and the attackers only needed an email address ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Hackers exploited Lenovo’s flawed email verification to hijack ~5,000 Dropbox accounts</strong></li><li><strong>Attackers created Lenovo IDs with victims’ emails, bypassing login; 2FA absence worsened impact</strong></li><li><strong>Dropbox ended Lenovo ID logins, expired sessions, and urged password changes plus 2FA setup</strong></li></ul><p>Around 5,000 Dropbox user accounts were compromised when hackers found a vulnerability in the Lenovo ID verification process. What does a Lenovo flaw have to do with people’s Dropbox accounts, you might ask? Here is what happened:</p><p>Earlier this week, <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">Dropbox</a> started notifying affected individuals about the incident. In the data breach notification email, the company explains:</p><p>“Dropbox partners with Lenovo as an identity provider so that users can log in to their Dropbox accounts using verified Lenovo IDs. While you may not have an existing Lenovo ID, our investigation determined that an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.”</p><h2 id="fixing-the-flaw">Fixing the flaw</h2><p>In other words, all criminals needed to have to pull this off was people’s email addresses. Using that information, they created Lenovo IDs and simply waltzed right into Dropbox accounts.</p><p>The attack took place between August 4 and 21, the company further said, adding that most of the accounts that were accessed did not have 2FA enabled. In around a third of them, there is evidence stored documents were either viewed or downloaded. </p><p>The vulnerability has since been addressed, and further steps taken to protect <a href="https://www.techradar.com/reviews/dropbox-cloud-storage-review" target="_blank">Dropbox</a> users’ privacy. The company said it “promptly expired all sessions logged in through Lenovo IDs,” and terminated all links between Lenovo and Dropbox accounts. Now, it made it mandatory to submit a password when logging in through a Lenovo ID. </p><p>“No one can access your Dropbox account via a Lenovo ID without first entering your Dropbox password,” it said. Still, it urged users to change their passwords, enable two-step verification, and change the password for their email accounts.</p><p>“Every single one of the compromised accounts lacked multi-factor authentication. In 2026, for cloud storage accounts holding data, that’s an indefensible gap and it’s one that users could have closed themselves regardless of what Lenovo or Dropbox did or didn’t do with their legacy integration," said Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress.</p><p>"The combination of an unreviewed third-party authentication pathway and accounts without MFA is essentially an open invitation. The practical lesson is straightforward and applies well beyond this specific incident. Every organisation and every individual should periodically audit what third-party services have authentication access to their accounts. OAuth grants, SSO connections, and third-party login integrations accumulate silently and rarely get removed when the relationship that created them ends.”</p><p><em>Via </em><a href="https://cybernews.com/news/dropbox-accounts-breached-email-lenovo-id/" target="_blank"><em>Cybernews</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/over-5-000-dropbox-accounts-have-been-hacked-and-the-attackers-only-needed-an-email-address</link>
                                                                            <description>
                            <![CDATA[ A bug in Lenovo's ID verification system made it possible to access Dropbox accounts, but the bug has since been fixed. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VtAcT6B5XAjE9cei3xVEt7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HXBM93dGYwGkVGnjAoWzpE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 18:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HXBM93dGYwGkVGnjAoWzpE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Dropbox logo is seen on a smartphone.]]></media:description>                                                            <media:text><![CDATA[Dropbox logo is seen on a smartphone.]]></media:text>
                                <media:title type="plain"><![CDATA[Dropbox logo is seen on a smartphone.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HXBM93dGYwGkVGnjAoWzpE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Hackers exploited Lenovo’s flawed email verification to hijack ~5,000 Dropbox accounts</strong></li><li><strong>Attackers created Lenovo IDs with victims’ emails, bypassing login; 2FA absence worsened impact</strong></li><li><strong>Dropbox ended Lenovo ID logins, expired sessions, and urged password changes plus 2FA setup</strong></li></ul><p>Around 5,000 Dropbox user accounts were compromised when hackers found a vulnerability in the Lenovo ID verification process. What does a Lenovo flaw have to do with people’s Dropbox accounts, you might ask? Here is what happened:</p><p>Earlier this week, <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">Dropbox</a> started notifying affected individuals about the incident. In the data breach notification email, the company explains:</p><p>“Dropbox partners with Lenovo as an identity provider so that users can log in to their Dropbox accounts using verified Lenovo IDs. While you may not have an existing Lenovo ID, our investigation determined that an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.”</p><h2 id="fixing-the-flaw">Fixing the flaw</h2><p>In other words, all criminals needed to have to pull this off was people’s email addresses. Using that information, they created Lenovo IDs and simply waltzed right into Dropbox accounts.</p><p>The attack took place between August 4 and 21, the company further said, adding that most of the accounts that were accessed did not have 2FA enabled. In around a third of them, there is evidence stored documents were either viewed or downloaded. </p><p>The vulnerability has since been addressed, and further steps taken to protect <a href="https://www.techradar.com/reviews/dropbox-cloud-storage-review" target="_blank">Dropbox</a> users’ privacy. The company said it “promptly expired all sessions logged in through Lenovo IDs,” and terminated all links between Lenovo and Dropbox accounts. Now, it made it mandatory to submit a password when logging in through a Lenovo ID. </p><p>“No one can access your Dropbox account via a Lenovo ID without first entering your Dropbox password,” it said. Still, it urged users to change their passwords, enable two-step verification, and change the password for their email accounts.</p><p>“Every single one of the compromised accounts lacked multi-factor authentication. In 2026, for cloud storage accounts holding data, that’s an indefensible gap and it’s one that users could have closed themselves regardless of what Lenovo or Dropbox did or didn’t do with their legacy integration," said Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress.</p><p>"The combination of an unreviewed third-party authentication pathway and accounts without MFA is essentially an open invitation. The practical lesson is straightforward and applies well beyond this specific incident. Every organisation and every individual should periodically audit what third-party services have authentication access to their accounts. OAuth grants, SSO connections, and third-party login integrations accumulate silently and rarely get removed when the relationship that created them ends.”</p><p><em>Via </em><a href="https://cybernews.com/news/dropbox-accounts-breached-email-lenovo-id/" target="_blank"><em>Cybernews</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A malware installer posing as a legitimate download service is infecting brands across almost every industry — Microsoft Edge, Razer, Kaspersky and more actively imitated ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft warns Chinese group </strong><em><strong>Silver Fox</strong></em><strong> spoofed download sites for major tech brands</strong></li><li><strong>Victims install backdoored software enabling persistence, disabling Defender/updates, and payload delivery</strong></li><li><strong>Targets span healthcare, manufacturing, gaming, government; Microsoft urges tamper protection and behavior‑based detection</strong></li></ul><p>Cybercriminals are spoofing some of the world’s most popular technology and software companies in an attempt to infect their targets with dangerous <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">backdoors</a>. This is according to security researchers from Microsoft, who warned about the ongoing campaign in an in-depth report published earlier this week.</p><p>Microsoft said it discovered an ongoing campaign in which Chinese hackers (presumably Silver Fox, AKA Yinhu) were creating fraudulent download pages for some of the world’s most popular tech and software companies, including Razer, Kaspersky, Microsoft, NetEase, Baidu NetDisk, oCam ScreenRecorder, SteelSeries, Calibre, MindMaster, and many others. </p><p>Victim organizations looking to download software built by these companies end up downloading a weaponized version that works primarily as a backdoor. This implant allows the attackers a foothold from which they can maintain access and send/receive messages.</p><h2 id="how-to-defend-against-silver-fox">How to defend against Silver Fox</h2><p>Once installed, the backdoor creates scheduled tasks for persistence, injects itself into legitimate processes, and weakens Microsoft Defender and Windows Update by creating a large exclusion folder and disabling a number of update-related services.</p><p>It also deletes backups, and allows the attackers to deploy further payloads. </p><p>Victims are primarily Chinese organizations, although the attackers do seem to be casting a rather wide net, Microsoft suggests. The majority of victims were found in medical devices and healthcare, manufacturing, gaming, technology, logistics, government, and higher education. </p><p>Microsoft says its Defender product “detected and disrupted” the activity across multiple stages of the attack, “including automated containment through attack disruption.” </p><p>Still, to defend against Silver Fox’s latest shenanigans, Microsoft advises organizations enforce tamper Protection which blocks exclusion and registry writes to Microsoft Defender even when the payload runs as SYSTEM. </p><p>It also suggests defenders hunt for “behavior, not file names”, set up alerts for tamper sequences, and treat look-alike download archives as malicious in web and mail flow. The full list of Indicators of Compromise (IoC) can be found on <a href="https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/#campaign-scope-and-targeting" target="_blank" rel="nofollow">this link</a>, as well.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/a-malware-installer-posing-as-a-legitimate-download-service-is-infecting-brands-across-almost-every-industry-microsoft-edge-razer-kaspersky-and-more-actively-imitated</link>
                                                                            <description>
                            <![CDATA[ Microsoft is warning about an ongoing campaign abusing dozens of popular technology and software firms. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m7u3mzYmbdzPaHpThQaPrh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 16:50:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / ZinetroN]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Nytt DDoS-rekord]]></media:description>                                                            <media:text><![CDATA[Concept art representing cybersecurity principles]]></media:text>
                                <media:title type="plain"><![CDATA[Concept art representing cybersecurity principles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft warns Chinese group </strong><em><strong>Silver Fox</strong></em><strong> spoofed download sites for major tech brands</strong></li><li><strong>Victims install backdoored software enabling persistence, disabling Defender/updates, and payload delivery</strong></li><li><strong>Targets span healthcare, manufacturing, gaming, government; Microsoft urges tamper protection and behavior‑based detection</strong></li></ul><p>Cybercriminals are spoofing some of the world’s most popular technology and software companies in an attempt to infect their targets with dangerous <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">backdoors</a>. This is according to security researchers from Microsoft, who warned about the ongoing campaign in an in-depth report published earlier this week.</p><p>Microsoft said it discovered an ongoing campaign in which Chinese hackers (presumably Silver Fox, AKA Yinhu) were creating fraudulent download pages for some of the world’s most popular tech and software companies, including Razer, Kaspersky, Microsoft, NetEase, Baidu NetDisk, oCam ScreenRecorder, SteelSeries, Calibre, MindMaster, and many others. </p><p>Victim organizations looking to download software built by these companies end up downloading a weaponized version that works primarily as a backdoor. This implant allows the attackers a foothold from which they can maintain access and send/receive messages.</p><h2 id="how-to-defend-against-silver-fox">How to defend against Silver Fox</h2><p>Once installed, the backdoor creates scheduled tasks for persistence, injects itself into legitimate processes, and weakens Microsoft Defender and Windows Update by creating a large exclusion folder and disabling a number of update-related services.</p><p>It also deletes backups, and allows the attackers to deploy further payloads. </p><p>Victims are primarily Chinese organizations, although the attackers do seem to be casting a rather wide net, Microsoft suggests. The majority of victims were found in medical devices and healthcare, manufacturing, gaming, technology, logistics, government, and higher education. </p><p>Microsoft says its Defender product “detected and disrupted” the activity across multiple stages of the attack, “including automated containment through attack disruption.” </p><p>Still, to defend against Silver Fox’s latest shenanigans, Microsoft advises organizations enforce tamper Protection which blocks exclusion and registry writes to Microsoft Defender even when the payload runs as SYSTEM. </p><p>It also suggests defenders hunt for “behavior, not file names”, set up alerts for tamper sequences, and treat look-alike download archives as malicious in web and mail flow. The full list of Indicators of Compromise (IoC) can be found on <a href="https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/#campaign-scope-and-targeting" target="_blank" rel="nofollow">this link</a>, as well.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Manchester Airports hackers just posted the data of 8.7 million people online — failed extortion attempt triggers data dump sale ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>The hacker group responsible for the MAG hack has posted the data online</strong></li><li><strong>PII is included within the data, putting victims at risk of targeted phishing and scams</strong></li><li><strong>"MAG is confident that we have taken effective measures to protect our customers"</strong></li></ul><p>The hackers behind the Manchester Airport hack have posted their trove of data on 8.7 million people online after failing to extort the Manchester Airport Group.</p><p>The data stolen during the attack included personally identifiable information (PII) such as email addresses, phone numbers, vehicle registrations and postcodes.</p><p>"MAG is confident that we have taken effective measures to protect our customers and we have contacted all those affected, including reaching out to all those with upcoming bookings to advise them of additional support," the company said in a statement.</p><h2 id="hackers-look-for-money-elsewhere">Hackers look for money elsewhere</h2><p>When hackers successfully breach systems and steal sensitive information, such as customer data, they will attempt to extort the company they stole it from for money. In return, the hackers promise not to release the data. </p><p>FulcrumSec has claimed responsibility for the attack. They tried to extort MAG but the company refused to pay, in line with what governments and cybersecurity agencies are advising. By not paying the hackers, it removes the financial incentive to steal the data in the first place.</p><p>In order to recoup some money from their efforts in hacking MAG, the hackers have now posted the trove of data online in the hopes that another cybercriminal group will pay for access to the information.</p><p>The information contains valuable information that hackers can use to target the victims of the data breach, launching highly specific phishing campaigns. For those affected by the MAG breach, this could include scams that use the email addresses, car registrations and postcodes of victims.</p><p>In the hackers post online, they claim the database is “half a terabyte, and every byte of it is pure PII” (Via <a href="https://www.bbc.co.uk/news/articles/c74k39g3ee5o" target="_blank" rel="nofollow"><em>BBC</em></a>).</p><p>“Reported exposure of booking history, travel dates, vehicle information, purchase references and customer profiles is a major escalation from what’s already been revealed about the Manchester Airports Group data breach,” said David Sancho, Senior Threat Researcher, TrendAI.</p><p>“This appears to be much more than a simple contact-data breach. The information reportedly exposed is exactly the kind used to craft extremely credible phishing campaigns by referring to information that intended victims would expect only their airport of choice or booking provider to know.”</p><p>“The risk is especially pressing given today’s criminal use of AI to generate highly targeted phishing and social-engineering campaigns at scale. FulcrumSec, the group that’s claimed responsibility for this breach, has previously been reported to use LLMs to analyse stolen data, so that risk is a real one. FulcrumSec is a relatively new but increasingly credible data-extortion group. Seemingly active since late 2025, their campaigns focus on stealing sensitive information and using the threat of disclosure as leverage rather than encrypting systems,” he added.</p><p>“In light of these claims, and following independent verification, MAG companies should update affected customers as quickly as the scope of the breach becomes clearer, because the advice they need may change with it. I would urge customers to be suspicious of messages referring to upcoming trips, parking, Fast Track, lounges, refunds, booking changes or payment problems. They should avoid following links in unsolicited messages and instead access their booking through the official airport or provider website directly.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/manchester-airports-hackers-just-posted-the-data-of-8-7-million-people-online-failed-extortion-attempt-triggers-data-dump-sale</link>
                                                                            <description>
                            <![CDATA[ FulcrumSec attempted to extort Manchester Airports Group, but failed. Now, the cyber-criminals have published the information online. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Zo32UDyNL5Yb9Nkfi4KDH8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 15:14:39 +0000</pubDate>                                                                                                                                <updated>Wed, 02 Sep 2026 15:17:43 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:description>                                                            <media:text><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:text>
                                <media:title type="plain"><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>The hacker group responsible for the MAG hack has posted the data online</strong></li><li><strong>PII is included within the data, putting victims at risk of targeted phishing and scams</strong></li><li><strong>"MAG is confident that we have taken effective measures to protect our customers"</strong></li></ul><p>The hackers behind the Manchester Airport hack have posted their trove of data on 8.7 million people online after failing to extort the Manchester Airport Group.</p><p>The data stolen during the attack included personally identifiable information (PII) such as email addresses, phone numbers, vehicle registrations and postcodes.</p><p>"MAG is confident that we have taken effective measures to protect our customers and we have contacted all those affected, including reaching out to all those with upcoming bookings to advise them of additional support," the company said in a statement.</p><h2 id="hackers-look-for-money-elsewhere">Hackers look for money elsewhere</h2><p>When hackers successfully breach systems and steal sensitive information, such as customer data, they will attempt to extort the company they stole it from for money. In return, the hackers promise not to release the data. </p><p>FulcrumSec has claimed responsibility for the attack. They tried to extort MAG but the company refused to pay, in line with what governments and cybersecurity agencies are advising. By not paying the hackers, it removes the financial incentive to steal the data in the first place.</p><p>In order to recoup some money from their efforts in hacking MAG, the hackers have now posted the trove of data online in the hopes that another cybercriminal group will pay for access to the information.</p><p>The information contains valuable information that hackers can use to target the victims of the data breach, launching highly specific phishing campaigns. For those affected by the MAG breach, this could include scams that use the email addresses, car registrations and postcodes of victims.</p><p>In the hackers post online, they claim the database is “half a terabyte, and every byte of it is pure PII” (Via <a href="https://www.bbc.co.uk/news/articles/c74k39g3ee5o" target="_blank" rel="nofollow"><em>BBC</em></a>).</p><p>“Reported exposure of booking history, travel dates, vehicle information, purchase references and customer profiles is a major escalation from what’s already been revealed about the Manchester Airports Group data breach,” said David Sancho, Senior Threat Researcher, TrendAI.</p><p>“This appears to be much more than a simple contact-data breach. The information reportedly exposed is exactly the kind used to craft extremely credible phishing campaigns by referring to information that intended victims would expect only their airport of choice or booking provider to know.”</p><p>“The risk is especially pressing given today’s criminal use of AI to generate highly targeted phishing and social-engineering campaigns at scale. FulcrumSec, the group that’s claimed responsibility for this breach, has previously been reported to use LLMs to analyse stolen data, so that risk is a real one. FulcrumSec is a relatively new but increasingly credible data-extortion group. Seemingly active since late 2025, their campaigns focus on stealing sensitive information and using the threat of disclosure as leverage rather than encrypting systems,” he added.</p><p>“In light of these claims, and following independent verification, MAG companies should update affected customers as quickly as the scope of the breach becomes clearer, because the advice they need may change with it. I would urge customers to be suspicious of messages referring to upcoming trips, parking, Fast Track, lounges, refunds, booking changes or payment problems. They should avoid following links in unsolicited messages and instead access their booking through the official airport or provider website directly.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A botnet running for 23 years with over 15,000 endpoints has finally been shut down by law enforcement and Crowdstrike ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Crowdstrike and law enforcement disrupted </strong><em><strong>Sality</strong></em><strong>, a peer‑to‑peer botnet active since 2003</strong></li><li><strong>Botnet spread malware and clipboard hijacker </strong><em><strong>EggJagger</strong></em><strong>, stealing $150K in cryptocurrency</strong></li><li><strong>Operation sinkholed endpoints and removed payload URLs, coordinated with DOJ, FBI, Europol, and others</strong></li></ul><p>Security experts Crowdstrike, together with a handful of national and international law enforcement agencies, finally managed to disrupt Sality, a peer-to-peer botnet that operated unabated for more than two decades. </p><p>Sality first emerged in 2003. Unlike classic botnets which receive instructions and report back to a single, central entity, this botnet’s endpoints (some 15,000 of them) communicated among themselves, which made it more difficult to track and destroy.</p><p>Throughout its long history, Sality’s key feature was to deploy additional payloads to infected machines. The endpoints were being poisoned with a wide variety of different <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> that facilitated credential theft, spam, proxy services, and distributed denial of service (DDoS) attacks. However, between 2018 and today, Sality was primarily used to deploy EggJagger, a clipboard hijacking tool seen in cryptocurrency theft.</p><h2 id="sinkholing-the-botnet">Sinkholing the botnet</h2><p>Cryptocurrency wallet addresses are a long string of random characters, which are almost impossible, and definitely impractical, to remember by heart. Instead, when users want to send their money, they simply copy and paste the recipient’s wallet address into their own. EggJagger monitors this behavior, and when it spots something resembling a wallet address being copied, it replaces the string in the clipboard. Thus, when the victim hits “paste”, they end up adding the attacker’s wallet address instead. </p><p>According to Crowdstrike, from this malware alone, Sality’s operators raked in more than $150,000. </p><p>The researchers disrupted the botnet by sinkholing the endpoints. They first added a few of their own devices into the botnet and whenever others tried to communicate with them, the researchers would purge their peers list, essentially blinding them.</p><p>Crowdstrike also coordinated with international law enforcement to take down the URLs that were hosting the botnet’s payloads. “Disrupting Sality’s ability to download these files ensures that bots still carrying active URL packs cannot retrieve new payloads during the transition period,” they explained.</p><p>The operation was carried out in partnership with the US Department of Justice (DOJ), the Federal Bureau of Investigation (FBI), the Department of Defense Office of Inspector General’s Defense Criminal Investigative Service (DCIS), and the Shadowserver Foundation, with support from Europol, Eurojust, and law enforcement agencies in Bulgaria, Hungary, and Romania. </p><p>“We also acknowledge additional unnamed partners whose contributions were essential to the success of this operation,” Crowdstrike concluded.</p><p><em>Via </em><a href="https://www.theregister.com/cyber-crime/2026/09/02/cops-crowdstrike-disrupt-sality-botnet-by-poisoning-the-network-and-diverting-into-sinkholes/5293795" target="_blank"><em>The Register</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/a-botnet-running-for-23-years-with-over-15-000-endpoints-has-finally-been-shut-down-by-law-enforcement-and-crowdstrike</link>
                                                                            <description>
                            <![CDATA[ Crowdstrike and friends sinkholed thousands of Sality's endpoints rendering the botnet useless. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hYVMqEnoH4kyZxtDMa2hsT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2FFajuvJVK8i7Her8gD4aD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 14:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2FFajuvJVK8i7Her8gD4aD-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard]]></media:description>                                                            <media:text><![CDATA[Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2FFajuvJVK8i7Her8gD4aD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Crowdstrike and law enforcement disrupted </strong><em><strong>Sality</strong></em><strong>, a peer‑to‑peer botnet active since 2003</strong></li><li><strong>Botnet spread malware and clipboard hijacker </strong><em><strong>EggJagger</strong></em><strong>, stealing $150K in cryptocurrency</strong></li><li><strong>Operation sinkholed endpoints and removed payload URLs, coordinated with DOJ, FBI, Europol, and others</strong></li></ul><p>Security experts Crowdstrike, together with a handful of national and international law enforcement agencies, finally managed to disrupt Sality, a peer-to-peer botnet that operated unabated for more than two decades. </p><p>Sality first emerged in 2003. Unlike classic botnets which receive instructions and report back to a single, central entity, this botnet’s endpoints (some 15,000 of them) communicated among themselves, which made it more difficult to track and destroy.</p><p>Throughout its long history, Sality’s key feature was to deploy additional payloads to infected machines. The endpoints were being poisoned with a wide variety of different <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> that facilitated credential theft, spam, proxy services, and distributed denial of service (DDoS) attacks. However, between 2018 and today, Sality was primarily used to deploy EggJagger, a clipboard hijacking tool seen in cryptocurrency theft.</p><h2 id="sinkholing-the-botnet">Sinkholing the botnet</h2><p>Cryptocurrency wallet addresses are a long string of random characters, which are almost impossible, and definitely impractical, to remember by heart. Instead, when users want to send their money, they simply copy and paste the recipient’s wallet address into their own. EggJagger monitors this behavior, and when it spots something resembling a wallet address being copied, it replaces the string in the clipboard. Thus, when the victim hits “paste”, they end up adding the attacker’s wallet address instead. </p><p>According to Crowdstrike, from this malware alone, Sality’s operators raked in more than $150,000. </p><p>The researchers disrupted the botnet by sinkholing the endpoints. They first added a few of their own devices into the botnet and whenever others tried to communicate with them, the researchers would purge their peers list, essentially blinding them.</p><p>Crowdstrike also coordinated with international law enforcement to take down the URLs that were hosting the botnet’s payloads. “Disrupting Sality’s ability to download these files ensures that bots still carrying active URL packs cannot retrieve new payloads during the transition period,” they explained.</p><p>The operation was carried out in partnership with the US Department of Justice (DOJ), the Federal Bureau of Investigation (FBI), the Department of Defense Office of Inspector General’s Defense Criminal Investigative Service (DCIS), and the Shadowserver Foundation, with support from Europol, Eurojust, and law enforcement agencies in Bulgaria, Hungary, and Romania. </p><p>“We also acknowledge additional unnamed partners whose contributions were essential to the success of this operation,” Crowdstrike concluded.</p><p><em>Via </em><a href="https://www.theregister.com/cyber-crime/2026/09/02/cops-crowdstrike-disrupt-sality-botnet-by-poisoning-the-network-and-diverting-into-sinkholes/5293795" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ More than 9.5 million patients affected by Aesto Health breach — names, SSNs, financial details, health records and more stolen ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Aesto Health reported a December 2025 cyberattack breaching AWS infrastructure, affecting 9.5M patients</strong></li><li><strong>Stolen data includes PII, SSNs, medical histories, billing, and insurance information across 20+ clients</strong></li><li><strong>No dark web leaks confirmed; credit monitoring offered, marking 2nd‑largest healthcare breach of 2026</strong></li></ul><p>American healthcare technology company Aesto Health suffered the “second-largest confirmed healthcare data breach” of the year so far, having lost data on more than 9.5 million patients.</p><p>In mid-December last year, the company suffered a cyberattack. Now, more than half a year later, it reported the incident to the HHS’ Office for Civil Rights, detailing what was lost, from whom, and what the extent of the incident is. </p><p>Aesto Health is an Alabama-based healthcare technology business, whose core service is helping other healthcare firms manage medical data, change electronic health record systems, and similar. As per its announcement, the attack affected parts of its <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">Amazon Web Services</a> (AWS) infrastructure, which unidentified threat actors managed to access between December 2 and December 18. </p><h2 id="losing-personally-identifiable-information">Losing personally identifiable information</h2><p>According to a report on HIPAA Journal, the August attack affected more than two dozen of its clients, including Village Practice Management, Everside Health, Together Women’s Health Medical Group, and many others.</p><p>In the attack, the company lost personally identifiable information (PII) of its’ clients’ patients, including full names, Social Security numbers (SSN), partial dates of birth, driver’s license numbers, state identification numbers, financial account numbers, taxpayer identification numbers, health records, medical histories, claims/billing information, and health insurance information. </p><p>This is more than enough information for cybercriminals to launch highly sophisticated phishing and vishing attacks, which can result in disruptive ransomware and millions of dollars in damages. Luckily, there is still no evidence the data leaked on the dark web, or that it was already used by other criminals.</p><p>Aesto Health is now offering credit monitoring and <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft protection</a> services to everyone affected by the breach.</p><p>This is now the second-largest healthcare data breach of the year so far, HIPAA Journal confirmed, the largest one being the hit on <a href="https://www.techradar.com/pro/security/2-6-million-dentaquest-accounts-exposed-by-data-breach-shinyhunters-claim-234gb-of-data-stolen" target="_blank">DentaQuest</a> that exposed 15 million records.</p><p><em>Via </em><a href="https://www.hipaajournal.com/aesto-health-data-breach/" target="_blank" rel="nofollow"><em>HIPAA Journal</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/more-than-9-5-million-patients-affected-by-aesto-health-breach-names-ssns-financial-details-health-records-and-more-stolen</link>
                                                                            <description>
                            <![CDATA[ More than two dozen of Aesto's clients affected by the December 2025 cyberincident. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aVyqZKE4ytmNY5xtknGbA6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 12:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Laboratory]]></media:description>                                                            <media:text><![CDATA[Laboratory]]></media:text>
                                <media:title type="plain"><![CDATA[Laboratory]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Aesto Health reported a December 2025 cyberattack breaching AWS infrastructure, affecting 9.5M patients</strong></li><li><strong>Stolen data includes PII, SSNs, medical histories, billing, and insurance information across 20+ clients</strong></li><li><strong>No dark web leaks confirmed; credit monitoring offered, marking 2nd‑largest healthcare breach of 2026</strong></li></ul><p>American healthcare technology company Aesto Health suffered the “second-largest confirmed healthcare data breach” of the year so far, having lost data on more than 9.5 million patients.</p><p>In mid-December last year, the company suffered a cyberattack. Now, more than half a year later, it reported the incident to the HHS’ Office for Civil Rights, detailing what was lost, from whom, and what the extent of the incident is. </p><p>Aesto Health is an Alabama-based healthcare technology business, whose core service is helping other healthcare firms manage medical data, change electronic health record systems, and similar. As per its announcement, the attack affected parts of its <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">Amazon Web Services</a> (AWS) infrastructure, which unidentified threat actors managed to access between December 2 and December 18. </p><h2 id="losing-personally-identifiable-information">Losing personally identifiable information</h2><p>According to a report on HIPAA Journal, the August attack affected more than two dozen of its clients, including Village Practice Management, Everside Health, Together Women’s Health Medical Group, and many others.</p><p>In the attack, the company lost personally identifiable information (PII) of its’ clients’ patients, including full names, Social Security numbers (SSN), partial dates of birth, driver’s license numbers, state identification numbers, financial account numbers, taxpayer identification numbers, health records, medical histories, claims/billing information, and health insurance information. </p><p>This is more than enough information for cybercriminals to launch highly sophisticated phishing and vishing attacks, which can result in disruptive ransomware and millions of dollars in damages. Luckily, there is still no evidence the data leaked on the dark web, or that it was already used by other criminals.</p><p>Aesto Health is now offering credit monitoring and <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft protection</a> services to everyone affected by the breach.</p><p>This is now the second-largest healthcare data breach of the year so far, HIPAA Journal confirmed, the largest one being the hit on <a href="https://www.techradar.com/pro/security/2-6-million-dentaquest-accounts-exposed-by-data-breach-shinyhunters-claim-234gb-of-data-stolen" target="_blank">DentaQuest</a> that exposed 15 million records.</p><p><em>Via </em><a href="https://www.hipaajournal.com/aesto-health-data-breach/" target="_blank" rel="nofollow"><em>HIPAA Journal</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Multiple healthcare giants hit by data breaches affecting patient records, social security numbers, and even implanted cardiac devices ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>McKesson confirmed ShinyHunters breached its Snowflake and Salesforce, stealing 284M patient records</strong></li><li><strong>Data includes names, contact info, SSNs, and health details; ransom demand was $55.2M</strong></li><li><strong>Boston Scientific removed attackers but faces CRM device activation issues; attribution not confirmed</strong></li></ul><p>Last week, two major healthcare organizations suffered highly disruptive cyberattacks: Boston Scientific, and McKesson. We now have more details about both those attacks, and it seems at least one is the work of the infamous ShinyHunters <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">extortion</a> group.</p><p>McKesson confirmed having been struck by ShinyHunters, just a few days after the threat actor claimed responsibility. The group told The Register they broke into the company’s Snowflake and Salesforce instances and stole “millions of patients’ data”. </p><p>The company later issued a statement, saying the stolen data belonged to its Oncology & Multispecialty and Medical-Surgical business units. A spokesperson told The Register multiple employees were targeted with a vishing attack. </p><h2 id="boston-scientific-works-on-restoring-systems">Boston Scientific works on restoring systems</h2><p>The group told the publication it stole more than 284 million records of patient data and demanded $55.2 million from the victims. They are saying the stolen batch includes patient tames, postal and email addresses, phone numbers, Social Security numbers (SSN), and details regarding their health condition. Whether the claims are true, and to what extent, remains to be seen after the investigation. </p><p>Boston Scientific, on the other hand, said it successfully removed the attackers from its infrastructure, but added that the investigation into the attack remains ongoing. It also said that new Cardiac Rhythm Management (CRM) devices, implanted after August 25, cannot be activated, and the data they generate will not automatically be transmitted to remote patient management systems. </p><p>“Newly implanted ICMs (insertable cardiac monitors) must be activated using the Boston Scientific Clinic Assistant app to enable the ICM to properly record episodes,” it explained. “New ICMs are unable to pair to the patient remote monitoring mobile phone, therefore available episode data recorded by the ICM will NOT be transmitted to the remote monitoring system until the ICM can be paired to the patient mobile app. Episodes will continue to be recorded by the ICM and can be transmitted to the remote monitoring system via an in-person interrogation with the Clinic Assistant app by selecting the “Interrogate” button.”</p><p><a href="https://www.techradar.com/pro/security/boston-scientific-says-cyberattack-is-causing-a-global-disruption-to-medical-device-operations" target="_blank">Boston Scientific is yet to name ShinyHunters as the perpetrators</a>, and the group has not yet publicly claimed responsibility for the attack.</p><p><em>Via </em><a href="" target="_blank"><em>The Register</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/multiple-healthcare-giants-hit-by-data-breaches-affecting-patient-records-social-security-numbers-and-even-implanted-cardiac-devices</link>
                                                                            <description>
                            <![CDATA[ Boston Scientific and McKesson are working on restoring services after being struck by disruptive cyberattacks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GDuLq4JqbV564wt5k96bSV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Sep 2026 21:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Laboratory]]></media:description>                                                            <media:text><![CDATA[Laboratory]]></media:text>
                                <media:title type="plain"><![CDATA[Laboratory]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>McKesson confirmed ShinyHunters breached its Snowflake and Salesforce, stealing 284M patient records</strong></li><li><strong>Data includes names, contact info, SSNs, and health details; ransom demand was $55.2M</strong></li><li><strong>Boston Scientific removed attackers but faces CRM device activation issues; attribution not confirmed</strong></li></ul><p>Last week, two major healthcare organizations suffered highly disruptive cyberattacks: Boston Scientific, and McKesson. We now have more details about both those attacks, and it seems at least one is the work of the infamous ShinyHunters <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">extortion</a> group.</p><p>McKesson confirmed having been struck by ShinyHunters, just a few days after the threat actor claimed responsibility. The group told The Register they broke into the company’s Snowflake and Salesforce instances and stole “millions of patients’ data”. </p><p>The company later issued a statement, saying the stolen data belonged to its Oncology & Multispecialty and Medical-Surgical business units. A spokesperson told The Register multiple employees were targeted with a vishing attack. </p><h2 id="boston-scientific-works-on-restoring-systems">Boston Scientific works on restoring systems</h2><p>The group told the publication it stole more than 284 million records of patient data and demanded $55.2 million from the victims. They are saying the stolen batch includes patient tames, postal and email addresses, phone numbers, Social Security numbers (SSN), and details regarding their health condition. Whether the claims are true, and to what extent, remains to be seen after the investigation. </p><p>Boston Scientific, on the other hand, said it successfully removed the attackers from its infrastructure, but added that the investigation into the attack remains ongoing. It also said that new Cardiac Rhythm Management (CRM) devices, implanted after August 25, cannot be activated, and the data they generate will not automatically be transmitted to remote patient management systems. </p><p>“Newly implanted ICMs (insertable cardiac monitors) must be activated using the Boston Scientific Clinic Assistant app to enable the ICM to properly record episodes,” it explained. “New ICMs are unable to pair to the patient remote monitoring mobile phone, therefore available episode data recorded by the ICM will NOT be transmitted to the remote monitoring system until the ICM can be paired to the patient mobile app. Episodes will continue to be recorded by the ICM and can be transmitted to the remote monitoring system via an in-person interrogation with the Clinic Assistant app by selecting the “Interrogate” button.”</p><p><a href="https://www.techradar.com/pro/security/boston-scientific-says-cyberattack-is-causing-a-global-disruption-to-medical-device-operations" target="_blank">Boston Scientific is yet to name ShinyHunters as the perpetrators</a>, and the group has not yet publicly claimed responsibility for the attack.</p><p><em>Via </em><a href="" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cisco routers are being turned into surveillance vantage points to hoover up data on trusted networks — and it's all thanks to this new malware ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Sygnia reports China‑linked Fire Ant expanding beyond virtualization to routers, TACACS, and Linux hosts</strong></li><li><strong>Compromised routers act as operational platforms</strong></li><li><strong>Campaign aims at “target behind the target,” leveraging trust relationships for broader espionage reach</strong></li></ul><p>Fire Ant, a China-nexus cyberespionage group, is no longer targeting just virtualization platforms, it’s also going for routers, authentication systems, and Linux management hosts. This is according to cybersecurity researchers Sygnia, who recently saw the group target Cisco IOS XR Routers. </p><p>Once they compromise a <a href="https://www.techradar.com/news/networking/routers-storage/best-router-9-top-wireless-routers-on-test-1090523" target="_blank">router</a>, they don’t just use it to move around the network, the researchers explained. Instead, they turn them into full-blown operational platforms, collecting traffic, establishing connections, manipulating command output, and even suppressing logging so that they fly under the defenders’ radars. </p><p>For authentication systems, Fire Ant was seen taking aim at TACACS servers. Admins use them to authenticate when accessing network hardware, and crooks use them to harvest valuable credentials and weaken the reliability of audit logs, as well. Finally, Sygnia says Fire Ant also targets Linux management hosts. The researchers saw multiple persistent implants and backdoors, including a custom SSH backdoor and a piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> spoofing legitimate software. </p><h2 id="target-behind-the-target">Target behind the target</h2><p>The goal of the campaign seems to be to establish a foothold that allows crooks to reach other environments. Sygnia describes it as a “target behind the target” scenario: </p><p>“This reinforces the “target behind the target” concept introduced earlier in this report. Fire Ant’s interest in the compromised organization should be understood not only as an attempt to compromise a single environment, but as an effort to control infrastructure that may enable visibility, collection, and potential access beyond the immediate victim. The strategic value lies in the trust relationships the organization maintains with connected environments,” Sygnia explained.</p><p>Very little is known about Fire Ant, besides the fact that it was first observed in 2025. Some researchers claim it has significant overlaps with a threat actor tracked as UNC3886, a Chinese espionage group previously observed by Google. However, there are also significant differences which make attribution inconclusive.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/chinese-fire-ant-hackers-turn-cisco-routers-into-spying-platforms/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/cisco-routers-are-being-turned-into-surveillance-vantage-points-to-hoover-up-data-on-trusted-networks-and-its-all-thanks-to-this-new-malware</link>
                                                                            <description>
                            <![CDATA[ Fire Ant is now targeting routers, authentication servers, and Linux management hosts, using them as stepping stones. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ktXPBkae4A3uwRF8jyucDd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EEXAxCUDKAq3frELz3rVYY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Sep 2026 19:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/EEXAxCUDKAq3frELz3rVYY-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all wearing black with hoods pulled up over their heads. You cannot see their faces. The hacker in the foreground sits with an open laptop in front of them. The background, behind the hackers, is a Chinese flag]]></media:description>                                                            <media:text><![CDATA[A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all wearing black with hoods pulled up over their heads. You cannot see their faces. The hacker in the foreground sits with an open laptop in front of them. The background, behind the hackers, is a Chinese flag]]></media:text>
                                <media:title type="plain"><![CDATA[A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all wearing black with hoods pulled up over their heads. You cannot see their faces. The hacker in the foreground sits with an open laptop in front of them. The background, behind the hackers, is a Chinese flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EEXAxCUDKAq3frELz3rVYY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Sygnia reports China‑linked Fire Ant expanding beyond virtualization to routers, TACACS, and Linux hosts</strong></li><li><strong>Compromised routers act as operational platforms</strong></li><li><strong>Campaign aims at “target behind the target,” leveraging trust relationships for broader espionage reach</strong></li></ul><p>Fire Ant, a China-nexus cyberespionage group, is no longer targeting just virtualization platforms, it’s also going for routers, authentication systems, and Linux management hosts. This is according to cybersecurity researchers Sygnia, who recently saw the group target Cisco IOS XR Routers. </p><p>Once they compromise a <a href="https://www.techradar.com/news/networking/routers-storage/best-router-9-top-wireless-routers-on-test-1090523" target="_blank">router</a>, they don’t just use it to move around the network, the researchers explained. Instead, they turn them into full-blown operational platforms, collecting traffic, establishing connections, manipulating command output, and even suppressing logging so that they fly under the defenders’ radars. </p><p>For authentication systems, Fire Ant was seen taking aim at TACACS servers. Admins use them to authenticate when accessing network hardware, and crooks use them to harvest valuable credentials and weaken the reliability of audit logs, as well. Finally, Sygnia says Fire Ant also targets Linux management hosts. The researchers saw multiple persistent implants and backdoors, including a custom SSH backdoor and a piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> spoofing legitimate software. </p><h2 id="target-behind-the-target">Target behind the target</h2><p>The goal of the campaign seems to be to establish a foothold that allows crooks to reach other environments. Sygnia describes it as a “target behind the target” scenario: </p><p>“This reinforces the “target behind the target” concept introduced earlier in this report. Fire Ant’s interest in the compromised organization should be understood not only as an attempt to compromise a single environment, but as an effort to control infrastructure that may enable visibility, collection, and potential access beyond the immediate victim. The strategic value lies in the trust relationships the organization maintains with connected environments,” Sygnia explained.</p><p>Very little is known about Fire Ant, besides the fact that it was first observed in 2025. Some researchers claim it has significant overlaps with a threat actor tracked as UNC3886, a Chinese espionage group previously observed by Google. However, there are also significant differences which make attribution inconclusive.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/chinese-fire-ant-hackers-turn-cisco-routers-into-spying-platforms/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ North Korea expands fraudulent job resumes to target marketing, sales, and medical sector ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Huntress reports DPRK job seekers expanding beyond tech into healthcare, sales, and marketing</strong></li><li><strong>North Koreans use stolen identities, forged documents, AI tools, and proxies to bypass detection</strong></li><li><strong>Campaign dubbed “IT worker scheme” continues, posing sanctions risks and unique detection challenges</strong></li></ul><p>North Koreans looking to get hired by western companies are no longer focused exclusively on tech companies. According to security researchers Huntress, they have started applying for jobs in healthcare, sales, and marketing.</p><p>For US companies, employing North Koreans is prohibited under US sanctions, and the US government specifically warns about hiring IT workers from DPRK. As a result, these individuals are engaging in all sorts of fraudulent behavior to trick their potential employers and get hired. </p><p>That includes stealing other people’s identities, forging documents, and using pre-recorded or AI generated videos during calls and interviews. They’re also using ChatGPT to draft answers to questions and communicate without raising any alarms. Furthermore, they are deploying proxies and VPNs, often connecting to computers on “hardware farms” in China, and using personal, non-resident banking accounts to get paid.</p><h2 id="it-worker-scheme">IT worker scheme</h2><p>"DPRK workers present a unique detection challenge for defenders: rather than compromising accounts or breaking in via gaps in the organizations' environments, they're tricking companies into remotely hiring them, and oftentimes actually doing the legitimate work they were hired to do," Huntress said in an analysis.</p><p>This is a campaign that’s been ongoing for years. Researchers call it the “IT worker scheme” and while some argue the scammers are using their earned salary to further North Korea’s weapons program, there is no evidence to point in that direction. For all we know, they might actually be desperate for a job - they’re just not allowed to do it remotely.</p><p>In its latest report, Huntress says it saw three people in an Australian healthcare company that turned out to be North Koreans impersonating the Chinese. It also saw an unnamed financial services firm whose employees used software that allowed them to work remotely through devices hosted on laptop farms.</p><p>Finally, it investigated a case of a sales and marketing employee using a <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">stolen identity</a>. The worker allegedly used the personal details of a legitimate individual (name, birth date, location) which had been published online by law enforcement following that person’s arrest. At the same time, they were using their own face during the hiring process. </p><p><em>Via </em><a href="https://thehackernews.com/2026/08/north-korean-job-fraud-expands-beyond.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/north-korea-expands-fraudulent-job-resumes-to-target-marketing-sales-and-medical-sector</link>
                                                                            <description>
                            <![CDATA[ North Koreans are going to great lengths to get hired in the west, even if it means faking absolutely everything. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SmYDbBgwpxbsMGLsENbYsD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Sep 2026 16:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[North Korean flag with a hooded hacker]]></media:description>                                                            <media:text><![CDATA[North Korean flag with a hooded hacker]]></media:text>
                                <media:title type="plain"><![CDATA[North Korean flag with a hooded hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Huntress reports DPRK job seekers expanding beyond tech into healthcare, sales, and marketing</strong></li><li><strong>North Koreans use stolen identities, forged documents, AI tools, and proxies to bypass detection</strong></li><li><strong>Campaign dubbed “IT worker scheme” continues, posing sanctions risks and unique detection challenges</strong></li></ul><p>North Koreans looking to get hired by western companies are no longer focused exclusively on tech companies. According to security researchers Huntress, they have started applying for jobs in healthcare, sales, and marketing.</p><p>For US companies, employing North Koreans is prohibited under US sanctions, and the US government specifically warns about hiring IT workers from DPRK. As a result, these individuals are engaging in all sorts of fraudulent behavior to trick their potential employers and get hired. </p><p>That includes stealing other people’s identities, forging documents, and using pre-recorded or AI generated videos during calls and interviews. They’re also using ChatGPT to draft answers to questions and communicate without raising any alarms. Furthermore, they are deploying proxies and VPNs, often connecting to computers on “hardware farms” in China, and using personal, non-resident banking accounts to get paid.</p><h2 id="it-worker-scheme">IT worker scheme</h2><p>"DPRK workers present a unique detection challenge for defenders: rather than compromising accounts or breaking in via gaps in the organizations' environments, they're tricking companies into remotely hiring them, and oftentimes actually doing the legitimate work they were hired to do," Huntress said in an analysis.</p><p>This is a campaign that’s been ongoing for years. Researchers call it the “IT worker scheme” and while some argue the scammers are using their earned salary to further North Korea’s weapons program, there is no evidence to point in that direction. For all we know, they might actually be desperate for a job - they’re just not allowed to do it remotely.</p><p>In its latest report, Huntress says it saw three people in an Australian healthcare company that turned out to be North Koreans impersonating the Chinese. It also saw an unnamed financial services firm whose employees used software that allowed them to work remotely through devices hosted on laptop farms.</p><p>Finally, it investigated a case of a sales and marketing employee using a <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">stolen identity</a>. The worker allegedly used the personal details of a legitimate individual (name, birth date, location) which had been published online by law enforcement following that person’s arrest. At the same time, they were using their own face during the hiring process. </p><p><em>Via </em><a href="https://thehackernews.com/2026/08/north-korean-job-fraud-expands-beyond.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Careful when filing your taxes, this new "PackClient" malware is hitting global firms via tax audit lures ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Proofpoint observed PackClient RAT sold on Telegram, used by group TA4922</strong></li><li><strong>Attack spoofed tax authority emails in China and India, delivering PackClient installer</strong></li><li><strong>RAT offers advanced features; researchers warn broader adoption likely beyond Asia</strong></li></ul><p>For almost three months, Chinese hackers have been distributing an advanced Remote Access Trojan (RAT) called PackClient, against organizations in mainland China and India.</p><p>According to security researchers Proofpoint, PackClient is being actively sold on Telegram channels. It is a rather advanced RAT, capable of file theft and management, remote shell execution, screen capture and remote desktop management, webcam access, keylogging, privilege escalation, system administration, and a myriad of other things.</p><p>Even though it’s actively sold on Telegram, so far just one hacking group was spotted using it - TA4922. This is not a state-sponsored group but rather a financially motivated one.</p><h2 id="picking-up-the-malware">Picking up the malware</h2><p>Since late May 2026, this group has been mailing organization, first in China, and later in India, as well. In the emails, they spoofed local tax authorities, claiming that the recipients were needed to conduct “self-inspection”, a process which included downloading and filling out paperwork shared in the attachment.</p><p>The “paperwork”, however, was nothing more than the PackClient installer.</p><p>In its report, Proofpoint did not say how many organizations fell victim to the attack, nor did it discuss in which industries most victims operated.</p><p>However, in earlier reports, the researchers said TA4922 typically targets small and medium-sized organizations located primarily in Japan. Other notable mentions include Taiwan, Korea, Singapore, and India, while in newer times, they also started targeting European organizations, as well as those in the UK. </p><p>Proofpoint also stressed that the advanced capabilities of PackClient might see it getting picked up by many more threat actors, and see it getting deployed against more organizations, particularly in the western part of the world.</p><p>“Given that PackClient is marketed through Telegram making it broadly available, it is likely other threat actors are currently using, or will use, this <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> in future campaigns,” they said. The researchers also shared a full list of Indicators of Compromise (<a href="https://www.proofpoint.com/us/blog/threat-insight/carry-compromise-ta4922-packs-packclient" target="_blank" rel="nofollow">IoC</a>), in case you’re suspicious of an infection.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/careful-when-filing-your-taxes-this-new-packclient-malware-is-hitting-global-firms-via-tax-audit-lures</link>
                                                                            <description>
                            <![CDATA[ The Chinese are using a tax lure to deploy a new RAT and take over victim devices. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9WYHdQcCnqkSjx9Tu2W5ML</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hLQRgpHx6EucdLaJE8z8TA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Sep 2026 15:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hLQRgpHx6EucdLaJE8z8TA-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Someone using forms to pay their taxes.]]></media:description>                                                            <media:text><![CDATA[Someone using forms to pay their taxes.]]></media:text>
                                <media:title type="plain"><![CDATA[Someone using forms to pay their taxes.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hLQRgpHx6EucdLaJE8z8TA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Proofpoint observed PackClient RAT sold on Telegram, used by group TA4922</strong></li><li><strong>Attack spoofed tax authority emails in China and India, delivering PackClient installer</strong></li><li><strong>RAT offers advanced features; researchers warn broader adoption likely beyond Asia</strong></li></ul><p>For almost three months, Chinese hackers have been distributing an advanced Remote Access Trojan (RAT) called PackClient, against organizations in mainland China and India.</p><p>According to security researchers Proofpoint, PackClient is being actively sold on Telegram channels. It is a rather advanced RAT, capable of file theft and management, remote shell execution, screen capture and remote desktop management, webcam access, keylogging, privilege escalation, system administration, and a myriad of other things.</p><p>Even though it’s actively sold on Telegram, so far just one hacking group was spotted using it - TA4922. This is not a state-sponsored group but rather a financially motivated one.</p><h2 id="picking-up-the-malware">Picking up the malware</h2><p>Since late May 2026, this group has been mailing organization, first in China, and later in India, as well. In the emails, they spoofed local tax authorities, claiming that the recipients were needed to conduct “self-inspection”, a process which included downloading and filling out paperwork shared in the attachment.</p><p>The “paperwork”, however, was nothing more than the PackClient installer.</p><p>In its report, Proofpoint did not say how many organizations fell victim to the attack, nor did it discuss in which industries most victims operated.</p><p>However, in earlier reports, the researchers said TA4922 typically targets small and medium-sized organizations located primarily in Japan. Other notable mentions include Taiwan, Korea, Singapore, and India, while in newer times, they also started targeting European organizations, as well as those in the UK. </p><p>Proofpoint also stressed that the advanced capabilities of PackClient might see it getting picked up by many more threat actors, and see it getting deployed against more organizations, particularly in the western part of the world.</p><p>“Given that PackClient is marketed through Telegram making it broadly available, it is likely other threat actors are currently using, or will use, this <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> in future campaigns,” they said. The researchers also shared a full list of Indicators of Compromise (<a href="https://www.proofpoint.com/us/blog/threat-insight/carry-compromise-ta4922-packs-packclient" target="_blank" rel="nofollow">IoC</a>), in case you’re suspicious of an infection.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>